ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Breaking into Ubuntu Server

    Scheduled Pinned Locked Moved IT Discussion
    22 Posts 9 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • IRJI
      IRJ
      last edited by

      Thanks @scottalanmiller , but I already saw those and known of them help me. XSS isn't possible when there is no website on the box. The apache service is all that is running. A DoS is nice for an attack, but it doesn't help me gain access.

      1 Reply Last reply Reply Quote 0
      • dafyreD
        dafyre
        last edited by

        What error do you get when trying to browse to it?

        Could it be the site is listening only on the IP address and not listening for any particular hostname?

        IRJI 1 Reply Last reply Reply Quote 0
        • IRJI
          IRJ @dafyre
          last edited by

          @dafyre said in Breaking into Ubuntu Server:

          What error do you get when trying to browse to it?

          Could it be the site is listening only on the IP address and not listening for any particular hostname?

          no error. Just a default page that says "It works!" This is the default page for this server. The web server software is running, but no content has been added yet.

          I did an http vuln scan and the only file it sees is index.html which is just the default page.

          dafyreD 1 Reply Last reply Reply Quote 0
          • dafyreD
            dafyre @IRJ
            last edited by

            @IRJ said in Breaking into Ubuntu Server:

            @dafyre said in Breaking into Ubuntu Server:

            What error do you get when trying to browse to it?

            Could it be the site is listening only on the IP address and not listening for any particular hostname?

            no error. Just a default page that says "It works!" This is the default page for this server. The web server software is running, but no content has been added yet.

            I did an http vuln scan and the only file it sees is index.html which is just the default page.

            Time to throw out Scott's favorite word: Red Herring ?

            IRJI BRRABillB stacksofplatesS 3 Replies Last reply Reply Quote 0
            • IRJI
              IRJ @dafyre
              last edited by

              @dafyre said in Breaking into Ubuntu Server:

              @IRJ said in Breaking into Ubuntu Server:

              @dafyre said in Breaking into Ubuntu Server:

              What error do you get when trying to browse to it?

              Could it be the site is listening only on the IP address and not listening for any particular hostname?

              no error. Just a default page that says "It works!" This is the default page for this server. The web server software is running, but no content has been added yet.

              I did an http vuln scan and the only file it sees is index.html which is just the default page.

              Time to throw out Scott's favorite word: Red Herring ?

              There are plenty of decoys so it wouldn't surprise me.

              1 Reply Last reply Reply Quote 0
              • BRRABillB
                BRRABill @dafyre
                last edited by

                @dafyre said in Breaking into Ubuntu Server:

                @IRJ said in Breaking into Ubuntu Server:

                @dafyre said in Breaking into Ubuntu Server:

                What error do you get when trying to browse to it?

                Could it be the site is listening only on the IP address and not listening for any particular hostname?

                no error. Just a default page that says "It works!" This is the default page for this server. The web server software is running, but no content has been added yet.

                I did an http vuln scan and the only file it sees is index.html which is just the default page.

                Time to throw out Scott's favorite word: Red Herring ?

                If you only knew how many times I've seen that already today.

                1 Reply Last reply Reply Quote 2
                • stacksofplatesS
                  stacksofplates @dafyre
                  last edited by

                  @dafyre said in Breaking into Ubuntu Server:

                  @IRJ said in Breaking into Ubuntu Server:

                  @dafyre said in Breaking into Ubuntu Server:

                  What error do you get when trying to browse to it?

                  Could it be the site is listening only on the IP address and not listening for any particular hostname?

                  no error. Just a default page that says "It works!" This is the default page for this server. The web server software is running, but no content has been added yet.

                  I did an http vuln scan and the only file it sees is index.html which is just the default page.

                  Time to throw out Scott's favorite word: Red Herring ?

                  There is nothing extra in the index.html?

                  No port knocking set up for another port?

                  IRJI 1 Reply Last reply Reply Quote 0
                  • IRJI
                    IRJ @stacksofplates
                    last edited by

                    @stacksofplates said in Breaking into Ubuntu Server:

                    @dafyre said in Breaking into Ubuntu Server:

                    @IRJ said in Breaking into Ubuntu Server:

                    @dafyre said in Breaking into Ubuntu Server:

                    What error do you get when trying to browse to it?

                    Could it be the site is listening only on the IP address and not listening for any particular hostname?

                    no error. Just a default page that says "It works!" This is the default page for this server. The web server software is running, but no content has been added yet.

                    I did an http vuln scan and the only file it sees is index.html which is just the default page.

                    Time to throw out Scott's favorite word: Red Herring ?

                    There is nothing extra in the index.html?

                    No port knocking set up for another port?

                    Not that I can see. I used Acunetix Web Vulnerability Scanner and it does a pretty good job of analyzing the files.

                    1 Reply Last reply Reply Quote 1
                    • stacksofplatesS
                      stacksofplates
                      last edited by

                      As an aside, this sounds like a really interesting test.

                      1 Reply Last reply Reply Quote 0
                      • MattSpellerM
                        MattSpeller
                        last edited by

                        I find that a slot and phillips #2 are enough for most.

                        Occasionally I have to break out the baseball bat or crowbar but those are really more for my pleasure than anything.

                        1 Reply Last reply Reply Quote 1
                        • stacksofplatesS
                          stacksofplates
                          last edited by

                          Did you figures it out? You've kind of inspired me. I kind of want to go through the OSCP now.

                          IRJI 1 Reply Last reply Reply Quote 0
                          • IRJI
                            IRJ @stacksofplates
                            last edited by

                            @stacksofplates said in Breaking into Ubuntu Server:

                            Did you figures it out? You've kind of inspired me. I kind of want to go through the OSCP now.

                            Yes I did figure it out. PM me and I can tell you the resolution.

                            1 Reply Last reply Reply Quote 0
                            • 1
                            • 2
                            • 1 / 2
                            • First post
                              Last post