93 lines
7.0 KiB
Plaintext
93 lines
7.0 KiB
Plaintext
nmap -vv --reason -Pn -T4 -sV -sC --version-all -A --osscan-guess -oN "/home/kali/htb/broscience/results/scans/_quick_tcp_nmap.txt" -oX "/home/kali/htb/broscience/results/scans/xml/_quick_tcp_nmap.xml" 10.10.11.195
|
|
|
|
nmap -vv --reason -Pn -T4 -sV -sC --version-all -A --osscan-guess -p- -oN "/home/kali/htb/broscience/results/scans/_full_tcp_nmap.txt" -oX "/home/kali/htb/broscience/results/scans/xml/_full_tcp_nmap.xml" 10.10.11.195
|
|
|
|
nmap -vv --reason -Pn -T4 -sU -A --top-ports 100 -oN "/home/kali/htb/broscience/results/scans/_top_100_udp_nmap.txt" -oX "/home/kali/htb/broscience/results/scans/xml/_top_100_udp_nmap.xml" 10.10.11.195
|
|
|
|
nmap -vv --reason -Pn -T4 -sV -p 22 --script="banner,ssh2-enum-algos,ssh-hostkey,ssh-auth-methods" -oN "/home/kali/htb/broscience/results/scans/tcp22/tcp_22_ssh_nmap.txt" -oX "/home/kali/htb/broscience/results/scans/tcp22/xml/tcp_22_ssh_nmap.xml" 10.10.11.195
|
|
|
|
feroxbuster -u http://10.10.11.195:80/ -t 10 -w /root/.local/share/AutoRecon/wordlists/dirbuster.txt -x "txt,html,php,asp,aspx,jsp" -v -k -n -q -e -o "/home/kali/htb/broscience/results/scans/tcp80/tcp_80_http_feroxbuster_dirbuster.txt"
|
|
|
|
curl -sSikf http://10.10.11.195:80/.well-known/security.txt
|
|
|
|
curl -sSikf http://10.10.11.195:80/robots.txt
|
|
|
|
curl -sSik http://10.10.11.195:80/
|
|
|
|
nmap -vv --reason -Pn -T4 -sV -p 80 --script="banner,(http* or ssl*) and not (brute or broadcast or dos or external or http-slowloris* or fuzzer)" -oN "/home/kali/htb/broscience/results/scans/tcp80/tcp_80_http_nmap.txt" -oX "/home/kali/htb/broscience/results/scans/tcp80/xml/tcp_80_http_nmap.xml" 10.10.11.195
|
|
|
|
curl -sk -o /dev/null -H "Host: IFNNekNxlqYWYapbffxt.broscience.htb" http://broscience.htb:80/ -w "%{size_download}"
|
|
|
|
whatweb --color=never --no-errors -a 3 -v http://10.10.11.195:80 2>&1
|
|
|
|
wkhtmltoimage --format png http://10.10.11.195:80/ /home/kali/htb/broscience/results/scans/tcp80/tcp_80_http_screenshot.png
|
|
|
|
feroxbuster -u https://10.10.11.195:443/ -t 10 -w /root/.local/share/AutoRecon/wordlists/dirbuster.txt -x "txt,html,php,asp,aspx,jsp" -v -k -n -q -e -o "/home/kali/htb/broscience/results/scans/tcp443/tcp_443_https_feroxbuster_dirbuster.txt"
|
|
|
|
curl -sSikf https://10.10.11.195:443/.well-known/security.txt
|
|
|
|
curl -sSikf https://10.10.11.195:443/robots.txt
|
|
|
|
curl -sSik https://10.10.11.195:443/
|
|
|
|
nmap -vv --reason -Pn -T4 -sV -p 443 --script="banner,(http* or ssl*) and not (brute or broadcast or dos or external or http-slowloris* or fuzzer)" -oN "/home/kali/htb/broscience/results/scans/tcp443/tcp_443_https_nmap.txt" -oX "/home/kali/htb/broscience/results/scans/tcp443/xml/tcp_443_https_nmap.xml" 10.10.11.195
|
|
|
|
sslscan --show-certificate --no-colour 10.10.11.195:443 2>&1
|
|
|
|
curl -sk -o /dev/null -H "Host: UAJazqQgdJcyUjSdHhQO.broscience.htb" https://broscience.htb:443/ -w "%{size_download}"
|
|
|
|
whatweb --color=never --no-errors -a 3 -v https://10.10.11.195:443 2>&1
|
|
|
|
wkhtmltoimage --format png https://10.10.11.195:443/ /home/kali/htb/broscience/results/scans/tcp443/tcp_443_https_screenshot.png
|
|
|
|
ffuf -u http://broscience.htb:80/ -t 10 -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt -H "Host: FUZZ.broscience.htb" -fs 332 -noninteractive -s | tee "/home/kali/htb/broscience/results/scans/tcp80/tcp_80_http_broscience.htb_vhosts_subdomains-top1million-110000.txt"
|
|
|
|
ffuf -u https://broscience.htb:443/ -t 10 -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt -H "Host: FUZZ.broscience.htb" -fs 9308 -noninteractive -s | tee "/home/kali/htb/broscience/results/scans/tcp443/tcp_443_https_broscience.htb_vhosts_subdomains-top1million-110000.txt"
|
|
|
|
nmap -vv --reason -Pn -T4 -sV -sC --version-all -A --osscan-guess -oN "/home/kali/htb/broscience/results/scans/_quick_tcp_nmap.txt" -oX "/home/kali/htb/broscience/results/scans/xml/_quick_tcp_nmap.xml" 10.10.11.195
|
|
|
|
nmap -vv --reason -Pn -T4 -sV -sC --version-all -A --osscan-guess -p- -oN "/home/kali/htb/broscience/results/scans/_full_tcp_nmap.txt" -oX "/home/kali/htb/broscience/results/scans/xml/_full_tcp_nmap.xml" 10.10.11.195
|
|
|
|
nmap -vv --reason -Pn -T4 -sU -A --top-ports 100 -oN "/home/kali/htb/broscience/results/scans/_top_100_udp_nmap.txt" -oX "/home/kali/htb/broscience/results/scans/xml/_top_100_udp_nmap.xml" 10.10.11.195
|
|
|
|
nmap -vv --reason -Pn -T4 -sV -p 22 --script="banner,ssh2-enum-algos,ssh-hostkey,ssh-auth-methods" -oN "/home/kali/htb/broscience/results/scans/tcp22/tcp_22_ssh_nmap.txt" -oX "/home/kali/htb/broscience/results/scans/tcp22/xml/tcp_22_ssh_nmap.xml" 10.10.11.195
|
|
|
|
feroxbuster -u http://10.10.11.195:80/ -t 10 -w /root/.local/share/AutoRecon/wordlists/dirbuster.txt -x "txt,html,php,asp,aspx,jsp" -v -k -n -q -e -o "/home/kali/htb/broscience/results/scans/tcp80/tcp_80_http_feroxbuster_dirbuster.txt"
|
|
|
|
curl -sSikf http://10.10.11.195:80/.well-known/security.txt
|
|
|
|
curl -sSikf http://10.10.11.195:80/robots.txt
|
|
|
|
curl -sSik http://10.10.11.195:80/
|
|
|
|
nmap -vv --reason -Pn -T4 -sV -p 80 --script="banner,(http* or ssl*) and not (brute or broadcast or dos or external or http-slowloris* or fuzzer)" -oN "/home/kali/htb/broscience/results/scans/tcp80/tcp_80_http_nmap.txt" -oX "/home/kali/htb/broscience/results/scans/tcp80/xml/tcp_80_http_nmap.xml" 10.10.11.195
|
|
|
|
curl -sk -o /dev/null -H "Host: XahIdBWOUUpjNeHUGBsD.broscience.htb" http://broscience.htb:80/ -w "%{size_download}"
|
|
|
|
whatweb --color=never --no-errors -a 3 -v http://10.10.11.195:80 2>&1
|
|
|
|
wkhtmltoimage --format png http://10.10.11.195:80/ /home/kali/htb/broscience/results/scans/tcp80/tcp_80_http_screenshot.png
|
|
|
|
feroxbuster -u https://10.10.11.195:443/ -t 10 -w /root/.local/share/AutoRecon/wordlists/dirbuster.txt -x "txt,html,php,asp,aspx,jsp" -v -k -n -q -e -o "/home/kali/htb/broscience/results/scans/tcp443/tcp_443_https_feroxbuster_dirbuster.txt"
|
|
|
|
curl -sSikf https://10.10.11.195:443/.well-known/security.txt
|
|
|
|
curl -sSikf https://10.10.11.195:443/robots.txt
|
|
|
|
curl -sSik https://10.10.11.195:443/
|
|
|
|
nmap -vv --reason -Pn -T4 -sV -p 443 --script="banner,(http* or ssl*) and not (brute or broadcast or dos or external or http-slowloris* or fuzzer)" -oN "/home/kali/htb/broscience/results/scans/tcp443/tcp_443_https_nmap.txt" -oX "/home/kali/htb/broscience/results/scans/tcp443/xml/tcp_443_https_nmap.xml" 10.10.11.195
|
|
|
|
sslscan --show-certificate --no-colour 10.10.11.195:443 2>&1
|
|
|
|
curl -sk -o /dev/null -H "Host: uQOhNjfxSNsplaFtrAtO.broscience.htb" https://broscience.htb:443/ -w "%{size_download}"
|
|
|
|
whatweb --color=never --no-errors -a 3 -v https://10.10.11.195:443 2>&1
|
|
|
|
wkhtmltoimage --format png https://10.10.11.195:443/ /home/kali/htb/broscience/results/scans/tcp443/tcp_443_https_screenshot.png
|
|
|
|
ffuf -u http://broscience.htb:80/ -t 10 -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt -H "Host: FUZZ.broscience.htb" -fs 332 -noninteractive -s | tee "/home/kali/htb/broscience/results/scans/tcp80/tcp_80_http_broscience.htb_vhosts_subdomains-top1million-110000.txt"
|
|
|
|
ffuf -u https://broscience.htb:443/ -t 10 -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt -H "Host: FUZZ.broscience.htb" -fs 9308 -noninteractive -s | tee "/home/kali/htb/broscience/results/scans/tcp443/tcp_443_https_broscience.htb_vhosts_subdomains-top1million-110000.txt"
|
|
|