Solstice
Last updated
Was this helpful?
Last updated
Was this helpful?
192.168.234.72
Nmap scan
FTP does not allow anonymous login.
Banner Grab
Nmap Vuln Scan
After lots of searching I found this.
Dirbuster Scan
FTP on this port does allow anonymous login but no files are found just a folder. With sticky perms.
Dirbuster
Dirbuster Scan
Found that index.php takes a parameter. Possible exploit.
Did not find a lot about this port only had an index.php page.
Testing the book parameter. Found that this is vulnerable to Local File Inclusion.
Lots of files in
This is where I got stuck for a few hours. I had to get a hint. After looking at a write up then doing much research on the exploit I was able to continue. Added notes about Apache to Will continue this box when I have more time I was able to get a shell but this box keeps crashing on me.