
HTB - Pov
IP Address: 10.10.11.251
Machine Info
Enumeration
Nmap Scan
┌──(kali㉿kali)-[~/…/machines/Windows/Medium/Pov]
└─$ nmap -F $ip -Pn
PORT STATE SERVICE
80/tcp open http
┌──(kali㉿kali)-[~/…/machines/Windows/Medium/Pov]
└─$ nmap -p- --min-rate 2500 $ip -Pn
PORT STATE SERVICE
80/tcp open http
┌──(kali㉿kali)-[~/…/machines/Windows/Medium/Pov]
└─$ nmap -sC -sV -p80 $ip
PORT STATE SERVICE VERSION
80/tcp open http Microsoft IIS httpd 10.0
| http-methods:
|_ Potentially risky methods: TRACE
|_http-title: pov.htb
|_http-server-header: Microsoft-IIS/10.0Fuzz for subdomains
Add to /etc/hosts
LFI

web.config

Shell as pov\sfitz
Creating serialized object with ysoerial
Shell as alaading
I'm the Administrator :)

Last updated