I received a challenge, there are two files one the instructions and one client file. The instructions talk about how i need to scan a server with a given IP and find two flag files flagx.txt, x being the number of the flag. I have to read the contents of these files (which is in MD5 hash) and create a poc script and exploit.
I am new to pentesting, I have only ever used tools like Nmap, Zap and Openvas, Nessus, Nikto to scan networks and such. I used all these tools only nmap gave me the open ports and a url which cannot be accessed but all the other vulnerability scanners gave me no results ( they cannot identify a host).
I have no clue on how to proceed and create a poc script, when i cannot even find an exploitable endpoint. The client file is of an unknown file type, when i run the hexa dump it says it is a executable. I tried Ghidra but I didn't find any hidden information in the file. Is there something I should look at for or just ignore that extra file?
Any guidance would be greatly appreciated. submitted by /u/feverless
[link] [comments]
http://dlvr.it/T4j4hm
Post Page Advertisement [Top]
Subscribe to:
Post Comments (Atom)
';
(function() {
var dsq = document.createElement('script'); dsq.type = 'text/javascript'; dsq.async = true;
dsq.src = '//' + disqus_shortname + '.disqus.com/embed.js';
(document.getElementsByTagName('head')[0] || document.getElementsByTagName('body')[0]).appendChild(dsq);
})();
No comments:
Post a Comment