02.FAWN (FTP)

OVERVIEW

Target Service:	                  FTP
Attack:                           Brute Force
Vulnerability:                    Authentication Vulnerability – Weak Credentials
MITRE Tactics & Technques:	  TA0001: Initial Access
                                   - T1078: Valid Accounts
                                  T1110.001: Brute Force – Password Guessing
                                   - TA0006: Credential Access

Summary: The target system exposed an FTP service with no authentication hardening, 
         allowing access via default or easily guessable credentials. A brute-force 
         attempt using common username-password combinations succeeded, revealing a 
         serious authentication misconfiguration.
root@oco:~$ sudo openvpn ~/Downloads/starting_point.ovpn

ENUMERATE SERVICES

root@htb:~$ nmap -sV -T4 10.129.188.72 -p-
 PORT     STATE SERVICE       VERSION
 21/tcp   open  ftp           vsftpd 3.0.3

VULNERABILITY SCANNING

FOOTHOLD/COMPROMISE

Submit root flag

#ANONYMOUS LOGIN METHOD

#BRUTE FORCE METHOD

Last updated