
Foothold
Nmap scan (open ports)

FTP
We can log in as anonymous:

But there are no interesting files…
Let’s check what we can enumerate on the other ports !
Samba
I couldn’t get anything from samba:

Maybe we have to scan more ports, but before that we have to look for potential exploits that can help us with
vsftpd 2.3.4
Searchsploit + Metasploit
vsftpd 2.3.4
Bingo :

Unfortunately:

smbd 3.0.20
By running a more complete nmap scan, we get smbd version:

And this will lead us to root ↓
Root
