TryHackMe - Basic Pentesting

Posted March 23, 2020 · 1 min read
tryhackme
linux
enumeration
bruteforce

IP Address: 192.168.1.1

Port Scanning

nmap - Find all open ports of a Network

PortService
22SSH
80Apache
139SMB
445SMB
8009-
8080HTTP

Directory Enumeration

gobuster - Find URLs or Paths of a Website (Used DirBuster wordlist)

  • /development
  • /server-status

User Enumeration

enum4linux - Script to find out users of a system

Users found:

  • kay
  • jan

Brute Forcing

hydra - Brute force passwords

  • jan : armando

Privilege Escalation

linpeas - looking for ways for priviledge escalation

johntheripper - password hashing with rockyou.txt dictionary

  • Passphrase for kay’s SSH private key is beeswax