April 24, 2023, 2:11 p.m. | Echo_Slow

InfoSec Write-ups - Medium infosecwriteups.com

Today I’ll take a look at Blocky, where we will explore the easy-rated machine inspired by Minecraft.

Short Summary

  • Nmap enumeration for open ports
  • Directory busting for additional information
  • Reversing a java.Class
  • Password reuse, and multiple initial access paths
  • Simple privilege escalation via sudo -l

Enumeration

We run a port scan with the following command:

sudo nmap -p- -T4 --min-rate 2500 10.10.10.37

and find the following ports open:

PORT      STATE  SERVICE   REASON
21/tcp open ftp syn-ack ttl 63
22/tcp …

credential stuffing enumeration hackthebox htb machine privilege escalation reversing write-up

Financial Crimes Compliance - Senior - Consulting - Location Open

@ EY | New York City, US, 10001-8604

Software Engineer - Cloud Security

@ Neo4j | Malmö

Security Consultant

@ LRQA | Singapore, Singapore, SG, 119963

Identity Governance Consultant

@ Allianz | Sydney, NSW, AU, 2000

Educator, Cybersecurity

@ Brain Station | Toronto

Principal Security Engineer

@ Hippocratic AI | Palo Alto