
◻️SKYFALL
IP: 10.10.11.254 - Platform: Linux- Difficulty: Insane
RECON
Nmap
nmap -sV -sC -v -T4 -p- 10.10.11.254
Initiating Connect Scan at 00:46
Scanning 10.10.11.254 [65535 ports]
Discovered open port 22/tcp on 10.10.11.254
Discovered open port 80/tcp on 10.10.11.254
Host is up (0.045s latency).
Not shown: 65533 closed tcp ports (conn-refused)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.6 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 256 6570f71247073a888e27e9cb445d10fb (ECDSA)
|_ 256 74483307b7889d320e3bec16aab4c8fe (ED25519)
80/tcp open http nginx 1.18.0 (Ubuntu)
|_http-favicon: Unknown favicon MD5: FED84E16B6CCFE88EE7FFAAE5DFEFD34
|_http-server-header: nginx/1.18.0 (Ubuntu)
| http-methods:
|_ Supported Methods: GET HEAD
|_http-title: Skyfall - Introducing Sky Storage!
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernelFFUF
GAINING FOOTHOLD
Enumerating on the website




403 Bypass - Path Fuzzing



Bypass by LFI

Leaking environment varibles through the use of CVE-2023-28432



Gaining access through Vault OTP

PRIVILEGE ESCALATION

Verdict
Last updated
