got meterpreter with multi/manage/shell_to_meterpreter
/etc/passwd:
root:x:0:0:root:/root:/bin/bashbin:x:1:1:bin:/bin:/sbin/nologindaemon:x:2:2:daemon:/sbin:/sbin/nologinadm:x:3:4:adm:/var/adm:/sbin/nologinlp:x:4:7:lp:/var/spool/lpd:/sbin/nologinsync:x:5:0:sync:/sbin:/bin/syncshutdown:x:6:0:shutdown:/sbin:/sbin/shutdownhalt:x:7:0:halt:/sbin:/sbin/haltmail:x:8:12:mail:/var/spool/mail:/sbin/nologinoperator:x:11:0:operator:/root:/sbin/nologingames:x:12:100:games:/usr/games:/sbin/nologinftp:x:14:50:FTP User:/var/ftp:/sbin/nologinnobody:x:65534:65534:Kernel Overflow User:/:/sbin/nologindbus:x:81:81:System message bus:/:/sbin/nologinsystemd-coredump:x:999:997:systemd Core Dumper:/:/sbin/nologinsystemd-resolve:x:193:193:systemd Resolver:/:/sbin/nologintss:x:59:59:Account used by the trousers package to sandbox the tcsd daemon:/dev/null:/sbin/nologinpolkitd:x:998:996:User for polkitd:/:/sbin/nologinlibstoragemgmt:x:997:995:daemon account for libstoragemgmt:/var/run/lsm:/sbin/nologincockpit-ws:x:996:993:User for cockpit web service:/nonexisting:/sbin/nologincockpit-wsinstance:x:995:992:User for cockpit-ws instances:/nonexisting:/sbin/nologinsssd:x:994:990:User for sssd:/:/sbin/nologinsshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologinchrony:x:993:989::/var/lib/chrony:/sbin/nologinrngd:x:992:988:Random Number Generator Daemon:/var/lib/rngd:/sbin/nologintwreath:x:1000:1000:Thomas Wreath:/home/twreath:/bin/bashunbound:x:991:987:Unbound DNS resolver:/etc/unbound:/sbin/nologinapache:x:48:48:Apache:/usr/share/httpd:/sbin/nologinnginx:x:990:986:Nginx web server:/var/lib/nginx:/sbin/nologinmysql:x:27:27:MySQL Server:/var/lib/mysql:/sbin/nologin
internal network enum:
transferred a static nmap binary by doing this at /tmp:
./nmap-vorpidi -sn 10.200.180.0/24 -oN scanStarting Nmap 6.49BETA1 ( http://nmap.org ) at 2025-11-05 13:47 GMTCannot find nmap-payloads. UDP payloads are disabled.Nmap scan report for ip-10-200-180-1.eu-west-1.compute.internal (10.200.180.1)Cannot find nmap-mac-prefixes: Ethernet vendor correlation will not be performedHost is up (-0.18s latency).MAC Address: 06:BE:BA:7A:E6:87 (Unknown)Nmap scan report for ip-10-200-180-100.eu-west-1.compute.internal (10.200.180.100)Host is up (0.00019s latency).MAC Address: 06:C1:A2:3A:A8:43 (Unknown)Nmap scan report for ip-10-200-180-150.eu-west-1.compute.internal (10.200.180.150)Host is up (0.00025s latency).MAC Address: 06:EF:AA:2A:64:F7 (Unknown)Nmap scan report for ip-10-200-180-250.eu-west-1.compute.internal (10.200.180.250)Host is up (0.00037s latency).MAC Address: 06:EE:81:EB:5F:CB (Unknown)Nmap scan report for ip-10-200-180-200.eu-west-1.compute.internal (10.200.180.200)Host is up.Nmap done: 256 IP addresses (5 hosts up) scanned in 4.82 seconds