Dawn
Last updated
Was this helpful?
Last updated
Was this helpful?
192.168.234.11
Dirbuster results
Grabbed management.log file.
Now we now at least two users names dawn and ganimedes. This looks like a cron job running every minute in the log.
Check SMB ports for null session login.
ITDEPT folder empty.
We do have read/write permissions for it though.
No information gathered about this port.
Looked for a hint here because my Meterpreter binary kept getting an error and the session would close immediately. I found that it is because I am an idiot and did not set the multi/handler to accept the payload type I was using when I made the binary.
Looked at a write up when my binary was not working and found that a simple reverse shell was being used. Easy enough. Made product-control and dropped it in ITDEPT.
Get a decent shell.
Found that zsh was stickied.