FourAndSix:1 CTF Hacking Challenge Walkthrough (Vulnhub)

Words
331
Reading
2 min
Listen
Play
8y


FourAndSix is a capture the flag challenge available at Vulnhub. As usual, the box grabbed an IP address on boot since DHCP is enabled:

In my case the IP address was 192.168.10.100

If you are not sure of your target IP address,remember you can use arp-scan -l to list all the machines in the network.

With the target IP address ,we can now use Nmap to scan for running services and may be identify any vulnerable service.

alt

From the scan its clear the nfs service is running.

Network File System allow users mount the shared files over the network. By default, NFS uses TCP/UDP port 2049 to listen on the network.

We can check who has permission to access shared folder as follows.

showmount -e 192.168.10.100

alt

From the show mount command its clear everyone can access the network shared folder.

To check the content of shared folder, let's create a new folder and mount contents of the shared folder as follows:

alt

we can now check the content of the file by mounting it into the file system as follows:

alt

Let’s check if the root directory is shareable or not.



Posted from my blog with SteemPress : https://latesthackingnews.com/2018/11/14/fourandsix1-ctf-hacking-challenge-walkthrough-vulnhub/
FourAndSix:1 CTF Hacking Challenge Walkthrough (Vulnhub) | Ecency