HTB STARTING POINT · Tier 0
Synced
Anonymous rsync on port 873 delivers flag.txt with zero credentials; the real lesson is scanning beyond the top-1000 TCP ports.…
HTB STARTING POINT · Tier 0
Anonymous rsync on port 873 delivers flag.txt with zero credentials; the real lesson is scanning beyond the top-1000 TCP ports.…
HTB STARTING POINT · Tier 0
Directory fuzzing surfaces a hidden admin.php that default credentials unlock; demonstrates why wordlist-based discovery precedes credential guessing.…
HTB STARTING POINT · Tier 0
RDP and WinRM both accept a blank Administrator password — attack surface is two services wide when credential assumptions fail at the front door.…
HTB STARTING POINT · Tier 0
MongoDB 3.6.8 without bind authentication exposes a sensitive_information database; the real lesson is why auth-on-by-default matters.…
HTB STARTING POINT · Tier 0
Unauthenticated Redis on port 6379 leaks a flag key directly; includes a bonus RCE path via rogue-server module load for the curious.…
HTB STARTING POINT · Tier 0
Anonymous FTP on vsftpd 3.0.3 — the misconfiguration is intentional, the lesson is recognising anonymous bind and scripting retrieval.…
HTB STARTING POINT · Tier 0
SMB null session on Windows delivers a flag from an exposed WorkShares share; the takeaway is unauthenticated SMB enumeration without Metasploit.…
HTB STARTING POINT · Tier 0
Telnet with empty root password, and the RFC-854 quirk that explains why netcat falls silent where telnetlib succeeds.…