old htb folders
This commit is contained in:
2023-08-29 21:53:22 +02:00
parent 62ab804867
commit 82b0759f1e
21891 changed files with 6277643 additions and 0 deletions

View File

@@ -0,0 +1,165 @@
HTTP/1.1 200 OK
Date: Tue, 24 Jan 2023 12:27:44 GMT
Server: Apache/2.4.41 (Ubuntu)
Last-Modified: Fri, 02 Sep 2022 01:37:04 GMT
ETag: "e46-5e7a7c4652f79"
Accept-Ranges: bytes
Content-Length: 3654
Vary: Accept-Encoding
Content-Type: text/html
<!DOCTYPE html>
<html lang="en-us">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1">
<title>Ambassador Development Server</title>
<meta name="viewport" content="width=device-width,minimum-scale=1">
<meta name="description" content="">
<meta name="generator" content="Hugo 0.94.2" />
<meta name="robots" content="noindex, nofollow">
<link rel="stylesheet" href="/ananke/css/main.min.css" >
<link href="/index.xml" rel="alternate" type="application/rss+xml" title="Ambassador Development Server" />
<link href="/index.xml" rel="feed" type="application/rss+xml" title="Ambassador Development Server" />
<meta property="og:title" content="Ambassador Development Server" />
<meta property="og:description" content="" />
<meta property="og:type" content="website" />
<meta property="og:url" content="https://example.org/" />
<meta itemprop="name" content="Ambassador Development Server">
<meta itemprop="description" content=""><meta name="twitter:card" content="summary"/>
<meta name="twitter:title" content="Ambassador Development Server"/>
<meta name="twitter:description" content=""/>
</head>
<body class="ma0 avenir bg-near-white">
<header>
<div class="pb3-m pb6-l bg-black">
<nav class="pv3 ph3 ph4-ns" role="navigation">
<div class="flex-l justify-between items-center center">
<a href="/" class="f3 fw2 hover-white no-underline white-90 dib">
Ambassador Development Server
</a>
<div class="flex-l items-center">
<div class="ananke-socials">
</div>
</div>
</div>
</nav>
<div class="tc-l pv3 ph3 ph4-ns">
<h1 class="f2 f-subheadline-l fw2 light-silver mb0 lh-title">
Ambassador Development Server
</h1>
</div>
</div>
</header>
<main class="pb7" role="main">
<article class="cf ph3 ph5-l pv3 pv4-l f4 tc-l center measure-wide lh-copy mid-gray">
</article>
<div class="pa3 pa4-ns w-100 w-70-ns center">
<h1 class="flex-none">
Recent Posts
</h1>
<section class="w-100 mw8">
<div class="relative w-100 mb4">
<article class="bb b--black-10">
<div class="db pv4 ph3 ph0-l no-underline dark-gray">
<div class="flex flex-column flex-row-ns">
<div class="blah w-100">
<h1 class="f3 fw1 athelas mt0 lh-title">
<a href="/posts/welcome-to-the-ambassador-development-server/" class="color-inherit dim link">
Welcome to the Ambassador Development Server
</a>
</h1>
<div class="f6 f5-l lh-copy nested-copy-line-height nested-links">
Hi there! This server exists to provide developers at Ambassador with a standalone development environment. When you start as a developer at Ambassador, you will be assigned a development server of your own to use.
Connecting to this machine Use the developer account to SSH, DevOps will give you the password.
</div>
<a href="/posts/welcome-to-the-ambassador-development-server/" class="ba b--moon-gray bg-light-gray br2 color-inherit dib f7 hover-bg-moon-gray link mt2 ph2 pv1">read more</a>
</div>
</div>
</div>
</article>
</div>
</section>
</div>
</main>
<footer>
<div>
<p>
Ambassador Inc.
</p>
</div>
</footer>
</body>
</html>

View File

@@ -0,0 +1,33 @@
200 GET 1l 242w 75263c http://10.10.11.183/ananke/css/main.min.css
200 GET 21l 101w 1230c http://10.10.11.183/index.xml
200 GET 155l 305w 3654c http://10.10.11.183/
403 GET 9l 28w 277c http://10.10.11.183/.html
403 GET 9l 28w 277c http://10.10.11.183/.hta
403 GET 9l 28w 277c http://10.10.11.183/.htpasswd
403 GET 9l 28w 277c http://10.10.11.183/.htaccess
403 GET 9l 28w 277c http://10.10.11.183/.htpasswd.txt
403 GET 9l 28w 277c http://10.10.11.183/.hta.txt
403 GET 9l 28w 277c http://10.10.11.183/.htaccess.txt
403 GET 9l 28w 277c http://10.10.11.183/.htpasswd.html
403 GET 9l 28w 277c http://10.10.11.183/.hta.html
403 GET 9l 28w 277c http://10.10.11.183/.htaccess.html
403 GET 9l 28w 277c http://10.10.11.183/.htpasswd.php
403 GET 9l 28w 277c http://10.10.11.183/.hta.php
403 GET 9l 28w 277c http://10.10.11.183/.htaccess.php
403 GET 9l 28w 277c http://10.10.11.183/.hta.asp
403 GET 9l 28w 277c http://10.10.11.183/.htpasswd.asp
403 GET 9l 28w 277c http://10.10.11.183/.htaccess.asp
403 GET 9l 28w 277c http://10.10.11.183/.htpasswd.aspx
403 GET 9l 28w 277c http://10.10.11.183/.hta.aspx
403 GET 9l 28w 277c http://10.10.11.183/.htaccess.aspx
403 GET 9l 28w 277c http://10.10.11.183/.htpasswd.jsp
403 GET 9l 28w 277c http://10.10.11.183/.hta.jsp
403 GET 9l 28w 277c http://10.10.11.183/.htaccess.jsp
200 GET 92l 143w 1793c http://10.10.11.183/404.html
301 GET 9l 28w 317c http://10.10.11.183/categories => http://10.10.11.183/categories/
301 GET 9l 28w 313c http://10.10.11.183/images => http://10.10.11.183/images/
200 GET 155l 305w 3654c http://10.10.11.183/index.html
301 GET 9l 28w 312c http://10.10.11.183/posts => http://10.10.11.183/posts/
403 GET 9l 28w 277c http://10.10.11.183/server-status
200 GET 18l 22w 645c http://10.10.11.183/sitemap.xml
301 GET 9l 28w 311c http://10.10.11.183/tags => http://10.10.11.183/tags/

View File

@@ -0,0 +1,108 @@
# Nmap 7.93 scan initiated Tue Jan 24 07:27:43 2023 as: nmap -vv --reason -Pn -T4 -sV -p 80 "--script=banner,(http* or ssl*) and not (brute or broadcast or dos or external or http-slowloris* or fuzzer)" -oN /home/kali/htb/ambassador/results/10.10.11.183/scans/tcp80/tcp_80_http_nmap.txt -oX /home/kali/htb/ambassador/results/10.10.11.183/scans/tcp80/xml/tcp_80_http_nmap.xml 10.10.11.183
Nmap scan report for ambassador.htb (10.10.11.183)
Host is up, received user-set (0.036s latency).
Scanned at 2023-01-24 07:27:44 EST for 18s
Bug in http-security-headers: no string output.
PORT STATE SERVICE REASON VERSION
80/tcp open http syn-ack Apache httpd 2.4.41 ((Ubuntu))
|_http-mobileversion-checker: No mobile version detected.
|_http-devframework: Couldn't determine the underlying framework or CMS. Try increasing 'httpspider.maxpagecount' value to spider more pages.
|_http-errors: Couldn't find any error pages.
|_http-litespeed-sourcecode-download: Request with null byte did not work. This web server might not be vulnerable
|_http-referer-checker: Couldn't find any cross-domain scripts.
|_http-malware-host: Host appears to be clean
|_http-csrf: Couldn't find any CSRF vulnerabilities.
|_http-generator: Hugo 0.94.2
|_http-chrono: Request times for /; avg: 196.43ms; min: 171.38ms; max: 209.87ms
|_http-date: Tue, 24 Jan 2023 12:27:51 GMT; 0s from local time.
| http-feed:
| Spidering limited to: maxpagecount=40; withinhost=ambassador.htb
| Found the following feeds:
|_ RSS (version 2.0): http://ambassador.htb:80/index.xml
|_http-jsonp-detection: Couldn't find any JSONP endpoints.
|_http-dombased-xss: Couldn't find any DOM based XSS.
| http-useragent-tester:
| Status for browser useragent: 200
| Allowed User Agents:
| Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)
| libwww
| lwp-trivial
| libcurl-agent/1.0
| PHP/
| Python-urllib/2.5
| GT::WWW
| Snoopy
| MFC_Tear_Sample
| HTTP::Lite
| PHPCrawl
| URI::Fetch
| Zend_Http_Client
| http client
| PECL::HTTP
| Wget/1.13.4 (linux-gnu)
|_ WWW-Mechanize/1.34
|_http-fetch: Please enter the complete path of the directory to save data in.
| http-vhosts:
|_128 names had status 200
| http-methods:
|_ Supported Methods: GET POST OPTIONS HEAD
| http-sitemap-generator:
| Directory structure:
| /
| Other: 1; xml: 1
| /ananke/css/
| css: 1
| /posts/welcome-to-the-ambassador-development-server/
| Other: 1
| Longest directory structure:
| Depth: 2
| Dir: /posts/welcome-to-the-ambassador-development-server/
| Total files found (by extension):
|_ Other: 2; css: 1; xml: 1
|_http-wordpress-users: [Error] Wordpress installation was not found. We couldn't find wp-login.php
|_http-title: Ambassador Development Server
|_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
| http-comments-displayer:
| Spidering limited to: maxdepth=3; maxpagecount=20; withinhost=ambassador.htb
|
| Path: http://ambassador.htb:80/ananke/css/main.min.css
| Line number: 1
| Comment:
| /*!normalize.css v8.0.0 | MIT License | github.com/necolas/normalize.css*/
|
| Path: http://ambassador.htb:80/ananke/css/main.min.css
| Line number: 1
| Comment:
| /*!TACHYONS v4.12.0 | http://tachyons.io*/
|
| Path: http://ambassador.htb:80/ananke/css/main.min.css
| Line number: 1
| Comment:
|_ /*!TACHYONS v4.9.1 | http://tachyons.io*/
|_http-wordpress-enum: Nothing found amongst the top 100 resources,use --script-args search-limit=<number|all> for deeper analysis)
| http-internal-ip-disclosure:
|_ Internal IP Leaked: 127.0.1.1
| http-headers:
| Date: Tue, 24 Jan 2023 12:27:52 GMT
| Server: Apache/2.4.41 (Ubuntu)
| Last-Modified: Fri, 02 Sep 2022 01:37:04 GMT
| ETag: "e46-5e7a7c4652f79"
| Accept-Ranges: bytes
| Content-Length: 3654
| Vary: Accept-Encoding
| Connection: close
| Content-Type: text/html
|
|_ (Request type: HEAD)
| http-php-version: Logo query returned unknown hash 4e8656a1e2c09ff4135b58519f82a327
|_Credits query returned unknown hash 4e8656a1e2c09ff4135b58519f82a327
|_http-config-backup: ERROR: Script execution failed (use -d to debug)
|_http-drupal-enum: Nothing found amongst the top 100 resources,use --script-args number=<number|all> for deeper analysis)
|_http-server-header: Apache/2.4.41 (Ubuntu)
| http-enum:
|_ /images/: Potentially interesting directory w/ listing on 'apache/2.4.41 (ubuntu)'
Read data files from: /usr/bin/../share/nmap
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
# Nmap done at Tue Jan 24 07:28:02 2023 -- 1 IP address (1 host up) scanned in 18.76 seconds

Binary file not shown.

After

Width:  |  Height:  |  Size: 5.0 MiB

View File

@@ -0,0 +1,69 @@
WhatWeb report for http://10.10.11.183:80
Status : 200 OK
Title : Ambassador Development Server
IP : 10.10.11.183
Country : RESERVED, ZZ
Summary : Apache[2.4.41], HTML5, HTTPServer[Ubuntu Linux][Apache/2.4.41 (Ubuntu)], MetaGenerator[Hugo 0.94.2], Open-Graph-Protocol[website], X-UA-Compatible[IE=edge]
Detected Plugins:
[ Apache ]
The Apache HTTP Server Project is an effort to develop and
maintain an open-source HTTP server for modern operating
systems including UNIX and Windows NT. The goal of this
project is to provide a secure, efficient and extensible
server that provides HTTP services in sync with the current
HTTP standards.
Version : 2.4.41 (from HTTP Server Header)
Google Dorks: (3)
Website : http://httpd.apache.org/
[ HTML5 ]
HTML version 5, detected by the doctype declaration
[ HTTPServer ]
HTTP server header string. This plugin also attempts to
identify the operating system from the server header.
OS : Ubuntu Linux
String : Apache/2.4.41 (Ubuntu) (from server string)
[ MetaGenerator ]
This plugin identifies meta generator tags and extracts its
value.
String : Hugo 0.94.2
[ Open-Graph-Protocol ]
The Open Graph protocol enables you to integrate your Web
pages into the social graph. It is currently designed for
Web pages representing profiles of real-world things .
things like movies, sports teams, celebrities, and
restaurants. Including Open Graph tags on your Web page,
makes your page equivalent to a Facebook Page.
Version : website
[ X-UA-Compatible ]
This plugin retrieves the X-UA-Compatible value from the
HTTP header and meta http-equiv tag. - More Info:
http://msdn.microsoft.com/en-us/library/cc817574.aspx
String : IE=edge
HTTP Headers:
HTTP/1.1 200 OK
Date: Tue, 24 Jan 2023 12:27:48 GMT
Server: Apache/2.4.41 (Ubuntu)
Last-Modified: Fri, 02 Sep 2022 01:37:04 GMT
ETag: "e46-5e7a7c4652f79-gzip"
Accept-Ranges: bytes
Vary: Accept-Encoding
Content-Encoding: gzip
Content-Length: 1310
Connection: close
Content-Type: text/html

View File

@@ -0,0 +1,74 @@
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE nmaprun>
<?xml-stylesheet href="file:///usr/bin/../share/nmap/nmap.xsl" type="text/xsl"?>
<!-- Nmap 7.93 scan initiated Tue Jan 24 07:27:43 2023 as: nmap -vv -&#45;reason -Pn -T4 -sV -p 80 &quot;-&#45;script=banner,(http* or ssl*) and not (brute or broadcast or dos or external or http-slowloris* or fuzzer)&quot; -oN /home/kali/htb/ambassador/results/10.10.11.183/scans/tcp80/tcp_80_http_nmap.txt -oX /home/kali/htb/ambassador/results/10.10.11.183/scans/tcp80/xml/tcp_80_http_nmap.xml 10.10.11.183 -->
<nmaprun scanner="nmap" args="nmap -vv -&#45;reason -Pn -T4 -sV -p 80 &quot;-&#45;script=banner,(http* or ssl*) and not (brute or broadcast or dos or external or http-slowloris* or fuzzer)&quot; -oN /home/kali/htb/ambassador/results/10.10.11.183/scans/tcp80/tcp_80_http_nmap.txt -oX /home/kali/htb/ambassador/results/10.10.11.183/scans/tcp80/xml/tcp_80_http_nmap.xml 10.10.11.183" start="1674563263" startstr="Tue Jan 24 07:27:43 2023" version="7.93" xmloutputversion="1.05">
<scaninfo type="connect" protocol="tcp" numservices="1" services="80"/>
<verbose level="2"/>
<debugging level="0"/>
<taskbegin task="NSE" time="1674563264"/>
<taskend task="NSE" time="1674563264"/>
<taskbegin task="NSE" time="1674563264"/>
<taskend task="NSE" time="1674563264"/>
<taskbegin task="NSE" time="1674563264"/>
<taskend task="NSE" time="1674563264"/>
<taskbegin task="Connect Scan" time="1674563264"/>
<taskend task="Connect Scan" time="1674563264" extrainfo="1 total ports"/>
<taskbegin task="Service scan" time="1674563264"/>
<taskend task="Service scan" time="1674563270" extrainfo="1 service on 1 host"/>
<taskbegin task="NSE" time="1674563270"/>
<taskend task="NSE" time="1674563282"/>
<taskbegin task="NSE" time="1674563282"/>
<taskend task="NSE" time="1674563282"/>
<taskbegin task="NSE" time="1674563282"/>
<taskend task="NSE" time="1674563282"/>
<host starttime="1674563264" endtime="1674563282"><status state="up" reason="user-set" reason_ttl="0"/>
<address addr="10.10.11.183" addrtype="ipv4"/>
<hostnames>
<hostname name="ambassador.htb" type="PTR"/>
</hostnames>
<ports><port protocol="tcp" portid="80"><state state="open" reason="syn-ack" reason_ttl="0"/><service name="http" product="Apache httpd" version="2.4.41" extrainfo="(Ubuntu)" method="probed" conf="10"><cpe>cpe:/a:apache:http_server:2.4.41</cpe></service><script id="http-mobileversion-checker" output="No mobile version detected."/><script id="http-devframework" output="Couldn&apos;t determine the underlying framework or CMS. Try increasing &apos;httpspider.maxpagecount&apos; value to spider more pages."/><script id="http-errors" output="Couldn&apos;t find any error pages."/><script id="http-litespeed-sourcecode-download" output="Request with null byte did not work. This web server might not be vulnerable"/><script id="http-referer-checker" output="Couldn&apos;t find any cross-domain scripts."/><script id="http-malware-host" output="Host appears to be clean"/><script id="http-csrf" output="Couldn&apos;t find any CSRF vulnerabilities."/><script id="http-generator" output="Hugo 0.94.2"/><script id="http-chrono" output="Request times for /; avg: 196.43ms; min: 171.38ms; max: 209.87ms"/><script id="http-date" output="Tue, 24 Jan 2023 12:27:51 GMT; 0s from local time."><elem key="date">2023-01-24T12:27:51+00:00</elem>
<elem key="delta">0.0</elem>
</script><script id="http-feed" output="&#xa;Spidering limited to: maxpagecount=40; withinhost=ambassador.htb&#xa; Found the following feeds: &#xa; RSS (version 2.0): http://ambassador.htb:80/index.xml&#xa;"/><script id="http-jsonp-detection" output="Couldn&apos;t find any JSONP endpoints."/><script id="http-dombased-xss" output="Couldn&apos;t find any DOM based XSS."/><script id="http-useragent-tester" output="&#xa; Status for browser useragent: 200&#xa; Allowed User Agents: &#xa; Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)&#xa; libwww&#xa; lwp-trivial&#xa; libcurl-agent/1.0&#xa; PHP/&#xa; Python-urllib/2.5&#xa; GT::WWW&#xa; Snoopy&#xa; MFC_Tear_Sample&#xa; HTTP::Lite&#xa; PHPCrawl&#xa; URI::Fetch&#xa; Zend_Http_Client&#xa; http client&#xa; PECL::HTTP&#xa; Wget/1.13.4 (linux-gnu)&#xa; WWW-Mechanize/1.34"><elem key="Status for browser useragent">200</elem>
<table key="Allowed User Agents">
<elem>Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)</elem>
<elem>libwww</elem>
<elem>lwp-trivial</elem>
<elem>libcurl-agent/1.0</elem>
<elem>PHP/</elem>
<elem>Python-urllib/2.5</elem>
<elem>GT::WWW</elem>
<elem>Snoopy</elem>
<elem>MFC_Tear_Sample</elem>
<elem>HTTP::Lite</elem>
<elem>PHPCrawl</elem>
<elem>URI::Fetch</elem>
<elem>Zend_Http_Client</elem>
<elem>http client</elem>
<elem>PECL::HTTP</elem>
<elem>Wget/1.13.4 (linux-gnu)</elem>
<elem>WWW-Mechanize/1.34</elem>
</table>
</script><script id="http-fetch" output="Please enter the complete path of the directory to save data in."><elem key="ERROR">Please enter the complete path of the directory to save data in.</elem>
</script><script id="http-vhosts" output="&#xa;128 names had status 200"/><script id="http-methods" output="&#xa; Supported Methods: GET POST OPTIONS HEAD"><table key="Supported Methods">
<elem>GET</elem>
<elem>POST</elem>
<elem>OPTIONS</elem>
<elem>HEAD</elem>
</table>
</script><script id="http-sitemap-generator" output="&#xa; Directory structure:&#xa; /&#xa; Other: 1; xml: 1&#xa; /ananke/css/&#xa; css: 1&#xa; /posts/welcome-to-the-ambassador-development-server/&#xa; Other: 1&#xa; Longest directory structure:&#xa; Depth: 2&#xa; Dir: /posts/welcome-to-the-ambassador-development-server/&#xa; Total files found (by extension):&#xa; Other: 2; css: 1; xml: 1&#xa;"/><script id="http-wordpress-users" output="[Error] Wordpress installation was not found. We couldn&apos;t find wp-login.php"/><script id="http-title" output="Ambassador Development Server"><elem key="title">Ambassador Development Server</elem>
</script><script id="http-stored-xss" output="Couldn&apos;t find any stored XSS vulnerabilities."/><script id="http-comments-displayer" output="&#xa;Spidering limited to: maxdepth=3; maxpagecount=20; withinhost=ambassador.htb&#xa; &#xa; Path: http://ambassador.htb:80/ananke/css/main.min.css&#xa; Line number: 1&#xa; Comment: &#xa; /*!normalize.css v8.0.0 | MIT License | github.com/necolas/normalize.css*/&#xa; &#xa; Path: http://ambassador.htb:80/ananke/css/main.min.css&#xa; Line number: 1&#xa; Comment: &#xa; /*!TACHYONS v4.12.0 | http://tachyons.io*/&#xa; &#xa; Path: http://ambassador.htb:80/ananke/css/main.min.css&#xa; Line number: 1&#xa; Comment: &#xa; /*!TACHYONS v4.9.1 | http://tachyons.io*/&#xa;"/><script id="http-wordpress-enum" output="Nothing found amongst the top 100 resources,use -&#45;script-args search-limit=&lt;number|all&gt; for deeper analysis)"/><script id="http-internal-ip-disclosure" output="&#xa; Internal IP Leaked: 127.0.1.1"><elem key="Internal IP Leaked">127.0.1.1</elem>
</script><script id="http-headers" output="&#xa; Date: Tue, 24 Jan 2023 12:27:52 GMT&#xa; Server: Apache/2.4.41 (Ubuntu)&#xa; Last-Modified: Fri, 02 Sep 2022 01:37:04 GMT&#xa; ETag: &quot;e46-5e7a7c4652f79&quot;&#xa; Accept-Ranges: bytes&#xa; Content-Length: 3654&#xa; Vary: Accept-Encoding&#xa; Connection: close&#xa; Content-Type: text/html&#xa; &#xa; (Request type: HEAD)&#xa;"/><script id="http-php-version" output="Logo query returned unknown hash 4e8656a1e2c09ff4135b58519f82a327&#xa;Credits query returned unknown hash 4e8656a1e2c09ff4135b58519f82a327"/><script id="http-security-headers" output=""></script><script id="http-config-backup" output="ERROR: Script execution failed (use -d to debug)"/><script id="http-drupal-enum" output="Nothing found amongst the top 100 resources,use -&#45;script-args number=&lt;number|all&gt; for deeper analysis)"/><script id="http-server-header" output="Apache/2.4.41 (Ubuntu)"><elem>Apache/2.4.41 (Ubuntu)</elem>
</script><script id="http-enum" output="&#xa; /images/: Potentially interesting directory w/ listing on &apos;apache/2.4.41 (ubuntu)&apos;&#xa;"/></port>
</ports>
<times srtt="35950" rttvar="35950" to="179750"/>
</host>
<taskbegin task="NSE" time="1674563282"/>
<taskend task="NSE" time="1674563282"/>
<taskbegin task="NSE" time="1674563282"/>
<taskend task="NSE" time="1674563282"/>
<taskbegin task="NSE" time="1674563282"/>
<taskend task="NSE" time="1674563282"/>
<runstats><finished time="1674563282" timestr="Tue Jan 24 07:28:02 2023" summary="Nmap done at Tue Jan 24 07:28:02 2023; 1 IP address (1 host up) scanned in 18.76 seconds" elapsed="18.76" exit="success"/><hosts up="1" down="0" total="1"/>
</runstats>
</nmaprun>