01.MEOW (TELNET)
OVERVIEW
Target Service: Telnet
Attack: Brute Force
Vulnerability: Authentication Vulnerability – Weak Credentials
MITRE Tactics & Technques: TA0001: Initial Access
- T1078: Valid Accounts
T1110.001: Brute Force – Password Guessing
- TA0006: Credential Access
Summary: The target system exposed a Telnet service with no authentication hardening,
allowing access via default or easily guessable credentials. A brute-force
attempt using common username-password combinations succeeded, revealing a
serious authentication misconfiguration.root@oco:~$ sudo openvpn ~/Downloads/starting_point.ovpnENUMERATE SERVICES
root@htb:~$ nmap -sV -T4 10.129.201.145 -p-
PORT STATE SERVICE VERSION
23/tcp open telnet Linux telnetdVULNERABILITY SCANNING
FOOTHOLD/COMPROMISE
Last updated