Foothold
Nmap scan (open ports)
FTP
We can log in as anonymous
:
But there are no interesting files…
Let’s check what we can enumerate on the other ports !
Samba
I couldn’t get anything from samba:
Maybe we have to scan more ports, but before that we have to look for potential exploits that can help us with
vsftpd 2.3.4
Searchsploit + Metasploit
vsftpd 2.3.4
Bingo :
Unfortunately:
smbd 3.0.20
By running a more complete nmap scan, we get smbd version:
And this will lead us to root ↓