Starting Nmap 7.80 ( https://nmap.org ) at 2025-03-25 04:05 GMTNmap scan report for 10.10.98.63Host is up (0.00036s latency).Not shown: 65532 closed portsPORT STATE SERVICE VERSION22/tcp open ssh OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)| ssh-hostkey:| 2048 f3:85:ec:54:f2:01:b1:94:40:de:42:e8:21:97:20:80 (RSA)| 256 77:c7:c1:ae:31:41:21:e4:93:0e:9a:dd:0b:29:e1:ff (ECDSA)|_ 256 07:05:43:46:9d:b2:3e:f0:4d:69:67:e4:91:d3:d3:7f (ED25519)80/tcp open http Apache httpd 2.4.29 ((Ubuntu))|_http-server-header: Apache/2.4.29 (Ubuntu)|_http-title: Apache2 Ubuntu Default Page: It works8000/tcp open http (PHP 7.2.32-1)| fingerprint-strings:| FourOhFourRequest:| HTTP/1.0 404 Not Found| Date: Tue, 25 Mar 2025 04:05:58 GMT| Connection: close| X-Powered-By: PHP/7.2.32-1+ubuntu18.04.1+deb.sury.org+1| Cache-Control: private, must-revalidate| Date: Tue, 25 Mar 2025 04:05:58 GMT| Content-Type: text/html; charset=UTF-8| pragma: no-cache| expires: -1| X-Debug-Token: 67f1c7| <!doctype html>| <html lang="en">| <head>| <meta charset="utf-8">| <meta name="viewport" content="width=device-width, initial-scale=1.0">| <title>Bolt | A hero is unleashed</title>| <link href="https://fonts.googleapis.com/css?family=Bitter|Roboto:400,400i,700" rel="stylesheet">| <link rel="stylesheet" href="/theme/base-2018/css/bulma.css?8ca0842ebb">| <link rel="stylesheet" href="/theme/base-2018/css/theme.css?6cb66bfe9f">| <meta name="generator" content="Bolt">| </head>| <body>| href="#main-content" class="vis| GetRequest: | HTTP/1.0 200 OK| Date: Tue, 25 Mar 2025 04:05:58 GMT| Connection: close| X-Powered-By: PHP/7.2.32-1+ubuntu18.04.1+deb.sury.org+1| Cache-Control: public, s-maxage=600| Date: Tue, 25 Mar 2025 04:05:58 GMT| Content-Type: text/html; charset=UTF-8| X-Debug-Token: 17d739| <!doctype html>| <html lang="en-GB">| <head>| <meta charset="utf-8">| <meta name="viewport" content="width=device-width, initial-scale=1.0">| <title>Bolt | A hero is unleashed</title>| <link href="https://fonts.googleapis.com/css?family=Bitter|Roboto:400,400i,700" rel="stylesheet">| <link rel="stylesheet" href="/theme/base-2018/css/bulma.css?8ca0842ebb">| <link rel="stylesheet" href="/theme/base-2018/css/theme.css?6cb66bfe9f">| <meta name="generator" content="Bolt">| <link rel="canonical" href="http://0.0.0.0:8000/">| </head>|_ <body class="front">|_http-generator: Bolt|_http-title: Bolt | A hero is unleashed1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :SF-Port8000-TCP:V=7.80%I=7%D=3/25%Time=67E22BA6%P=x86_64-pc-linux-gnu%r(GeSF:tRequest,2402,"HTTP/1\.0\x20200\x20OK\r\nDate:\x20Tue,\x2025\x20Mar\x20SF:2025\x2004:05:58\x20GMT\r\nConnection:\x20close\r\nX-Powered-By:\x20PHPSF:/7\.2\.32-1\+ubuntu18\.04\.1\+deb\.sury\.org\+1\r\nCache-Control:\x20puSF:blic,\x20s-maxage=600\r\nDate:\x20Tue,\x2025\x20Mar\x202025\x2004:05:58SF:\x20GMT\r\nContent-Type:\x20text/html;\x20charset=UTF-8\r\nX-Debug-TokeSF:n:\x2017d739\r\n\r\n<!doctype\x20html>\n<html\x20lang=\"en-GB\">\n\x20\SF:x20\x20\x20<head>\n\x20\x20\x20\x20\x20\x20\x20\x20<meta\x20charset=\"uSF:tf-8\">\n\x20\x20\x20\x20\x20\x20\x20\x20<meta\x20name=\"viewport\"\x20SF:content=\"width=device-width,\x20initial-scale=1\.0\">\n\x20\x20\x20\x2SF:0\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20<title>Bolt\x20\|\x20ASF:\x20hero\x20is\x20unleashed</title>\n\x20\x20\x20\x20\x20\x20\x20\x20<lSF:ink\x20href=\"https://fonts\.googleapis\.com/css\?family=Bitter\|RobotoSF::400,400i,700\"\x20rel=\"stylesheet\">\n\x20\x20\x20\x20\x20\x20\x20\x2SF:0<link\x20rel=\"stylesheet\"\x20href=\"/theme/base-2018/css/bulma\.css\SF:?8ca0842ebb\">\n\x20\x20\x20\x20\x20\x20\x20\x20<link\x20rel=\"stylesheSF:et\"\x20href=\"/theme/base-2018/css/theme\.css\?6cb66bfe9f\">\n\x20\x20SF:\x20\x20\t<meta\x20name=\"generator\"\x20content=\"Bolt\">\n\x20\x20\x2SF:0\x20\t<link\x20rel=\"canonical\"\x20href=\"http://0\.0\.0\.0:8000/\">\SF:n\x20\x20\x20\x20</head>\n\x20\x20\x20\x20<body\x20class=\"front\">\n\xSF:20\x20\x20\x20\x20\x20\x20\x20<a\x20")%r(FourOhFourRequest,16C3,"HTTP/1SF:\.0\x20404\x20Not\x20Found\r\nDate:\x20Tue,\x2025\x20Mar\x202025\x2004:SF:05:58\x20GMT\r\nConnection:\x20close\r\nX-Powered-By:\x20PHP/7\.2\.32-1SF:\+ubuntu18\.04\.1\+deb\.sury\.org\+1\r\nCache-Control:\x20private,\x20mSF:ust-revalidate\r\nDate:\x20Tue,\x2025\x20Mar\x202025\x2004:05:58\x20GMTSF:\r\nContent-Type:\x20text/html;\x20charset=UTF-8\r\npragma:\x20no-cacheSF:\r\nexpires:\x20-1\r\nX-Debug-Token:\x2067f1c7\r\n\r\n<!doctype\x20htmlSF:>\n<html\x20lang=\"en\">\n\x20\x20\x20\x20<head>\n\x20\x20\x20\x20\x20\SF:x20\x20\x20<meta\x20charset=\"utf-8\">\n\x20\x20\x20\x20\x20\x20\x20\x2SF:0<meta\x20name=\"viewport\"\x20content=\"width=device-width,\x20initialSF:-scale=1\.0\">\n\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x2SF:0\x20\x20<title>Bolt\x20\|\x20A\x20hero\x20is\x20unleashed</title>\n\x2SF:0\x20\x20\x20\x20\x20\x20\x20<link\x20href=\"https://fonts\.googleapis\SF:.com/css\?family=Bitter\|Roboto:400,400i,700\"\x20rel=\"stylesheet\">\nSF:\x20\x20\x20\x20\x20\x20\x20\x20<link\x20rel=\"stylesheet\"\x20href=\"/SF:theme/base-2018/css/bulma\.css\?8ca0842ebb\">\n\x20\x20\x20\x20\x20\x20SF:\x20\x20<link\x20rel=\"stylesheet\"\x20href=\"/theme/base-2018/css/themSF:e\.css\?6cb66bfe9f\">\n\x20\x20\x20\x20\t<meta\x20name=\"generator\"\x2SF:0content=\"Bolt\">\n\x20\x20\x20\x20</head>\n\x20\x20\x20\x20<body>\n\xSF:20\x20\x20\x20\x20\x20\x20\x20<a\x20href=\"#main-content\"\x20class=\"vSF:is");MAC Address: 02:A8:12:E5:6A:D5 (Unknown)No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).TCP/IP fingerprint:OS:SCAN(V=7.80%E=4%D=3/25%OT=22%CT=1%CU=41422%PV=Y%DS=1%DC=D%G=Y%M=02A812%TOS:M=67E22BBB%P=x86_64-pc-linux-gnu)SEQ(SP=101%GCD=1%ISR=10B%TI=Z%CI=Z%II=IOS:%TS=A)OPS(O1=M2301ST11NW7%O2=M2301ST11NW7%O3=M2301NNT11NW7%O4=M2301ST11NOS:W7%O5=M2301ST11NW7%O6=M2301ST11)WIN(W1=F4B3%W2=F4B3%W3=F4B3%W4=F4B3%W5=FOS:4B3%W6=F4B3)ECN(R=Y%DF=Y%T=40%W=F507%O=M2301NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%TOS:=40%S=O%A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=ROS:%O=%RD=0%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=OS:40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0OS:%Q=)U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(ROS:=Y%DFI=N%T=40%CD=S)Network Distance: 1 hopService Info: OS: Linux; CPE: cpe:/o:linux:linux_kernelTRACEROUTEHOP RTT ADDRESS1 0.36 ms 10.10.98.63OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .Nmap done: 1 IP address (1 host up) scanned in 38.57 seconds
nmap -p- -Pn -sV -O 10.10.98.63
Starting Nmap 7.80 ( https://nmap.org ) at 2025-03-25 04:08 GMTNmap scan report for 10.10.98.63Host is up (0.00034s latency).Not shown: 65532 closed portsPORT STATE SERVICE VERSION22/tcp open ssh OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)80/tcp open http Apache httpd 2.4.29 ((Ubuntu))8000/tcp open http (PHP 7.2.32-1)1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :SF-Port8000-TCP:V=7.80%I=7%D=3/25%Time=67E22C59%P=x86_64-pc-linux-gnu%r(GeSF:tRequest,2402,"HTTP/1\.0\x20200\x20OK\r\nDate:\x20Tue,\x2025\x20Mar\x20SF:2025\x2004:08:58\x20GMT\r\nConnection:\x20close\r\nX-Powered-By:\x20PHPSF:/7\.2\.32-1\+ubuntu18\.04\.1\+deb\.sury\.org\+1\r\nCache-Control:\x20puSF:blic,\x20s-maxage=600\r\nDate:\x20Tue,\x2025\x20Mar\x202025\x2004:08:58SF:\x20GMT\r\nContent-Type:\x20text/html;\x20charset=UTF-8\r\nX-Debug-TokeSF:n:\x20ac2d2c\r\n\r\n<!doctype\x20html>\n<html\x20lang=\"en-GB\">\n\x20\SF:x20\x20\x20<head>\n\x20\x20\x20\x20\x20\x20\x20\x20<meta\x20charset=\"uSF:tf-8\">\n\x20\x20\x20\x20\x20\x20\x20\x20<meta\x20name=\"viewport\"\x20SF:content=\"width=device-width,\x20initial-scale=1\.0\">\n\x20\x20\x20\x2SF:0\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20<title>Bolt\x20\|\x20ASF:\x20hero\x20is\x20unleashed</title>\n\x20\x20\x20\x20\x20\x20\x20\x20<lSF:ink\x20href=\"https://fonts\.googleapis\.com/css\?family=Bitter\|RobotoSF::400,400i,700\"\x20rel=\"stylesheet\">\n\x20\x20\x20\x20\x20\x20\x20\x2SF:0<link\x20rel=\"stylesheet\"\x20href=\"/theme/base-2018/css/bulma\.css\SF:?8ca0842ebb\">\n\x20\x20\x20\x20\x20\x20\x20\x20<link\x20rel=\"stylesheSF:et\"\x20href=\"/theme/base-2018/css/theme\.css\?6cb66bfe9f\">\n\x20\x20SF:\x20\x20\t<meta\x20name=\"generator\"\x20content=\"Bolt\">\n\x20\x20\x2SF:0\x20\t<link\x20rel=\"canonical\"\x20href=\"http://0\.0\.0\.0:8000/\">\SF:n\x20\x20\x20\x20</head>\n\x20\x20\x20\x20<body\x20class=\"front\">\n\xSF:20\x20\x20\x20\x20\x20\x20\x20<a\x20")%r(FourOhFourRequest,16C3,"HTTP/1SF:\.0\x20404\x20Not\x20Found\r\nDate:\x20Tue,\x2025\x20Mar\x202025\x2004:SF:08:58\x20GMT\r\nConnection:\x20close\r\nX-Powered-By:\x20PHP/7\.2\.32-1SF:\+ubuntu18\.04\.1\+deb\.sury\.org\+1\r\nCache-Control:\x20private,\x20mSF:ust-revalidate\r\nDate:\x20Tue,\x2025\x20Mar\x202025\x2004:08:58\x20GMTSF:\r\nContent-Type:\x20text/html;\x20charset=UTF-8\r\npragma:\x20no-cacheSF:\r\nexpires:\x20-1\r\nX-Debug-Token:\x20085bda\r\n\r\n<!doctype\x20htmlSF:>\n<html\x20lang=\"en\">\n\x20\x20\x20\x20<head>\n\x20\x20\x20\x20\x20\SF:x20\x20\x20<meta\x20charset=\"utf-8\">\n\x20\x20\x20\x20\x20\x20\x20\x2SF:0<meta\x20name=\"viewport\"\x20content=\"width=device-width,\x20initialSF:-scale=1\.0\">\n\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x2SF:0\x20\x20<title>Bolt\x20\|\x20A\x20hero\x20is\x20unleashed</title>\n\x2SF:0\x20\x20\x20\x20\x20\x20\x20<link\x20href=\"https://fonts\.googleapis\SF:.com/css\?family=Bitter\|Roboto:400,400i,700\"\x20rel=\"stylesheet\">\nSF:\x20\x20\x20\x20\x20\x20\x20\x20<link\x20rel=\"stylesheet\"\x20href=\"/SF:theme/base-2018/css/bulma\.css\?8ca0842ebb\">\n\x20\x20\x20\x20\x20\x20SF:\x20\x20<link\x20rel=\"stylesheet\"\x20href=\"/theme/base-2018/css/themSF:e\.css\?6cb66bfe9f\">\n\x20\x20\x20\x20\t<meta\x20name=\"generator\"\x2SF:0content=\"Bolt\">\n\x20\x20\x20\x20</head>\n\x20\x20\x20\x20<body>\n\xSF:20\x20\x20\x20\x20\x20\x20\x20<a\x20href=\"#main-content\"\x20class=\"vSF:is");MAC Address: 02:A8:12:E5:6A:D5 (Unknown)No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).TCP/IP fingerprint:OS:SCAN(V=7.80%E=4%D=3/25%OT=22%CT=1%CU=35975%PV=Y%DS=1%DC=D%G=Y%M=02A812%TOS:M=67E22C6D%P=x86_64-pc-linux-gnu)SEQ(SP=102%GCD=1%ISR=104%TI=Z%CI=Z%II=IOS:%TS=A)OPS(O1=M2301ST11NW7%O2=M2301ST11NW7%O3=M2301NNT11NW7%O4=M2301ST11NOS:W7%O5=M2301ST11NW7%O6=M2301ST11)WIN(W1=F4B3%W2=F4B3%W3=F4B3%W4=F4B3%W5=FOS:4B3%W6=F4B3)ECN(R=Y%DF=Y%T=40%W=F507%O=M2301NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%TOS:=40%S=O%A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=ROS:%O=%RD=0%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=OS:40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0OS:%Q=)U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(ROS:=Y%DFI=N%T=40%CD=S)Network Distance: 1 hopService Info: OS: Linux; CPE: cpe:/o:linux:linux_kernelOS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .Nmap done: 1 IP address (1 host up) scanned in 34.19 seconds
checked the documentation and found out there’s a login at IP:PORT/bolt/login. logged in with the creds and got the CMS version 3.7.1. got the EDB-ID of the RCE vuln as well. used the RCE module and exploited the machine, got a root shell and used find to get and cat find.txt. was child’s play. gonna do blog next