April 15, 2024, 12:45 p.m. | Pr3ach3r

System Weakness - Medium systemweakness.com

My infosec Journey continues

Analytics banner

Introduction

Hello everyone! Welcome back to my infosec journey. Today we will hack an easy machine on the HackTheBox website, named Analytics. This machine has two potential vulnerabilities that lead us to compromise the entire infrastructure. So, let’s begin!

Enumeration

As always, we enumerate using the Nmap program.

#nmap command
$ nmap -Pn -p 22,80 -v -sCV -oN nmap-ana 10.10.11.233
#nmap results
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.4 (Ubuntu …

ctf-writeup hackthebox htb-writeup infosec pentesting

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Consultant Sécurité SI Gouvernance - Risques - Conformité H/F - Strasbourg

@ Hifield | Strasbourg, France

Lead Security Specialist

@ KBR, Inc. | USA, Dallas, 8121 Lemmon Ave, Suite 550, Texas

Consultant SOC / CERT H/F

@ Hifield | Sèvres, France