April 15, 2024, 12:45 p.m. | Pr3ach3r

System Weakness - Medium systemweakness.com

My infosec Journey continues

Analytics banner

Introduction

Hello everyone! Welcome back to my infosec journey. Today we will hack an easy machine on the HackTheBox website, named Analytics. This machine has two potential vulnerabilities that lead us to compromise the entire infrastructure. So, let’s begin!

Enumeration

As always, we enumerate using the Nmap program.

#nmap command
$ nmap -Pn -p 22,80 -v -sCV -oN nmap-ana 10.10.11.233
#nmap results
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.4 (Ubuntu …

ctf-writeup hackthebox htb-writeup infosec pentesting

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Threat Analysis Engineer

@ Gen | IND - Tamil Nadu, Chennai

Head of Security

@ Hippocratic AI | Palo Alto

IT Security Vulnerability Management Specialist (15.10)

@ OCT Consulting, LLC | Washington, District of Columbia, United States

Security Engineer - Netskope/Proofpoint

@ Sainsbury's | Coventry, West Midlands, United Kingdom

Journeyman Cybersecurity Analyst

@ ISYS Technologies | Kirtland AFB, NM, United States