Hackthebox.eu - Retired -Jeeves Recon As is my standard is start with a simple UP/Down scan on all TCP ports nmap -T4 -p- -oX ./nmapb.xml jeeves.htb Then I convert the output to HTML to make it pretty xsltproc nmapb.xml -o nmapb.html Looks like ports 80,135,445 and 50000 are open. Now I’ll run another nmap scan with the -A switch to run all the scripts against just those ports nmap -T4 -A -p80,139,445,50000 -oX nmapf.xml jeeves.htb And once again covert the output to HTML xsltproc nmapf.xml -o nmapf.html So we have IIS on 80, for some reason it’s not showing port 139 here but we know 139 & 445 are smb. Then there is something called jetty 9.4 on 50000 It doesn’t look like there is anonymous access to the smb.. What is IIS showing? Now there is a blast from the past Port 50000 show a 404 error I set Dirb and Dirbuster and nikto at both ports Dirbuster found this on the high 50000 port http://jeeves.htb:50000/askjeeves/ JENKINS https://www.jenkins.io/ I start just p...
@circusmonkey404 on the twitters; DM for contact