Metatwo
Write up for the HTB machine 'MetaTwo'
1. Initial recon
1.1. nmap
PORT STATE SERVICE VERSION
21/tcp open ftp?
| fingerprint-strings:
| GenericLines:
| 220 ProFTPD Server (Debian) [::ffff:10.10.11.186]
| Invalid command: try being more creative
|_ Invalid command: try being more creative
22/tcp open ssh OpenSSH 8.4p1 Debian 5+deb11u1 (protocol 2.0)
| ssh-hostkey:
| 3072 c4b44617d2102d8fec1dc927fecd79ee (RSA)
| 256 2aea2fcb23e8c529409cab866dcd4411 (ECDSA)
|_ 256 fd78c0b0e22016fa050debd83f12a4ab (ED25519)
80/tcp open http nginx 1.18.0
|_http-title: Did not follow redirect to http://metapress.htb/
|_http-server-header: nginx/1.18.0
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel1.2. nikto
1.3. website recon
1.3.1. wpscan
2. user.txt
2.1. Exploiting WordPress
2.1.1. BookingPress SQLi
2.1.2. Authenticated XXE Within the Media Library
3. root.txt
3.1. passpie
3.2. gpg2john
Last updated