02.FAWN (FTP)
OVERVIEW
Target Service: FTP
Attack: Brute Force
Vulnerability: Authentication Vulnerability – Weak Credentials
MITRE Tactics & Technques: TA0001: Initial Access
- T1078: Valid Accounts
T1110.001: Brute Force – Password Guessing
- TA0006: Credential Access
Summary: The target system exposed an FTP service with no authentication hardening,
allowing access via default or easily guessable credentials. A brute-force
attempt using common username-password combinations succeeded, revealing a
serious authentication misconfiguration.root@oco:~$ sudo openvpn ~/Downloads/starting_point.ovpnENUMERATE SERVICES
root@htb:~$ nmap -sV -T4 10.129.188.72 -p-
PORT STATE SERVICE VERSION
21/tcp open ftp vsftpd 3.0.3VULNERABILITY SCANNING
FOOTHOLD/COMPROMISE
Last updated