HTB-Fawn

FTP = File Transfer Protocol > 21 port

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
ubuntu@ip:~$ ping 10.129.24.17
PING 10.129.24.17 (10.129.24.17) 56(84) bytes of data.
64 bytes from 10.129.24.17: icmp_seq=1 ttl=63 time=75.7 ms
64 bytes from 10.129.24.17: icmp_seq=2 ttl=63 time=75.7 ms
64 bytes from 10.129.24.17: icmp_seq=3 ttl=63 time=75.6 ms
64 bytes from 10.129.24.17: icmp_seq=4 ttl=63 time=75.7 ms
^C
--- 10.129.24.17 ping statistics ---
16 packets transmitted, 16 received, 0% packet loss, time 15025ms
rtt min/avg/max/mdev = 75.492/75.685/75.995/0.129 ms
ubuntu@ip-172-31-17-119:~$ sudo nmap 10.129.24.17
Starting Nmap 7.93 ( https://nmap.org ) at 2023-07-01 06:16 UTC
Couldn`t open a raw socket. Error: Permission denied (13)

ubuntu@ip:~$ nmap 10.129.24.17
Starting Nmap 7.93 ( https://nmap.org ) at 2023-07-01 06:17 UTC
Nmap scan report for ip-10-129-24-17.us-west-1.compute.internal (10.129.24.17)
Host is up (0.076s latency).
Not shown: 999 closed tcp ports (conn-refused)
PORT STATE SERVICE
21/tcp open ftp

Nmap done: 1 IP address (1 host up) scanned in 1.32 seconds

ubuntu@ip:~$ nmap -sV 10.129.24.17
Starting Nmap 7.93 ( https://nmap.org ) at 2023-07-01 06:24 UTC
Nmap scan report for ip-10-129-24-17.us-west-1.compute.internal (10.129.24.17)
Host is up (0.075s latency).
Not shown: 999 closed tcp ports (conn-refused)
PORT STATE SERVICE VERSION
21/tcp open ftp vsftpd 3.0.3
Service Info: OS: Unix

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 1.87 seconds

ubuntu@ip:~$ apt install ftp -y
E: Could not open lock file /var/lib/dpkg/lock-frontend - open (13: Permission denied)
E: Unable to acquire the dpkg frontend lock (/var/lib/dpkg/lock-frontend), are you root?
ubuntu@ip-172-31-17-119:~$ ftp --h
ftp: invalid option -- '-'
usage: ftp [-46AadefginpRtVv] [-N NETRC] [-o OUTPUT] [-P PORT] [-q QUITTIME]
[-r RETRY] [-s SRCADDR] [-T DIR,MAX[,INC]] [-x XFERSIZE]
[[USER@]HOST [PORT]]
[[USER@]HOST:[PATH][/]]
[file:///PATH]
[ftp://[USER[:PASSWORD]@]HOST[:PORT]/PATH[/][;type=TYPE]]
[http://[USER[:PASSWORD]@]HOST[:PORT]/PATH]
[https://[USER[:PASSWORD]@]HOST[:PORT]/PATH]
...
ftp -u URL FILE ...
ftp -?

ubuntu@ip:~$ ftp 10.129.24.17
Connected to 10.129.24.17.
220 (vsFTPd 3.0.3)
Name (10.129.24.17:ubuntu): anonymous
331 Please specify the password.
Password:
230 Login successful.
Remote system type is UNIX.
Using binary mode to transfer files.

ftp> help
Commands may be abbreviated. Commands are:

! edit lpage nlist rcvbuf struct
$ epsv lpwd nmap recv sunique
account epsv4 ls ntrans reget system
append epsv6 macdef open remopts tenex
ascii exit mdelete page rename throttle
bell features mdir passive reset trace
binary fget mget pdir restart type
bye form mkdir pls rhelp umask
case ftp mls pmlsd rmdir unset
cd gate mlsd preserve rstatus usage
cdup get mlst progress runique user
chmod glob mode prompt send verbose
close hash modtime proxy sendport xferbuf
cr help more put set ?
debug idle mput pwd site
delete image mreget quit size
dir lcd msend quote sndbuf
disconnect less newer rate status

ftp> ls
229 Entering Extended Passive Mode (|||62732|)
150 Here comes the directory listing.
-rw-r--r-- 1 0 0 32 Jun 04 2021 flag.txt
226 Directory send OK.

ftp> get flag.txt
local: flag.txt remote: flag.txt
229 Entering Extended Passive Mode (|||56926|)
150 Opening BINARY mode data connection for flag.txt (32 bytes).
100% |***************************************************************| 32 119.73 KiB/s 00:00 ETA
226 Transfer complete.
32 bytes received in 00:00 (0.41 KiB/s)

ftp> bye
421 Timeout.

ubuntu@ip-172-31-17-119:~$ ls
flag.txt lab_KILLMEN.ovpn lab_KILLMEN1.ovpn snap starting_point_KILLMEN.ovpn

ubuntu@ip-172-31-17-119:~$ cat flag.txt
035db21c881520061c53e0536e44f815ubuntu
单词 释义
acronym n. 缩略语;首字母缩略词(如Aids系由acquired immune deficiency syndrome的首字母组成)
explore v. 探讨;探索;勘探;探究;勘查;考察;(用手或身体某部)探察,探查;调查研究
configuration n. (计算机的)配置;结构;构造;形状;布局;格局
rudimentary adj. 基本的;初级的;基础的;原始的;未充分发展的
potentially adv. 潜在地
low-overhead 低开销
invoked v. 援引,援用(法律、规则等作为行动理由);提及,援引(某人、某理论、实例等作为支持);提出(某人的名字,以激发某种感觉或行动) invoke的过去分词和过去式
otherwise adv. 否则;另;不然;在其他方面;亦;除此以外 conj. 否则 adj. 别的;在其他各方面…的;在其他不同情况下的
infinitely adv. 非常;无限地;极其
previously adv. 先前;(一段时间)以前
properly adv. 适当地;正确地;恰当地;实际上;真正地;得体地;符合习俗地

第二关过啦