Hi everyone.
My key is inside this machine. I need to gain access to it.
Already ran nmap, but idk what to do with those informations… Can you give me some direction?
Nmap Results
#Edit:
I did it!
How realistic is this CTF? I searched for “bookstore rce” at google. I thought I should search for services at ExploitDB (like “apache 2.4” or “SSL 3.6”)
This solution seems very strange in a real scenario. It seems the application have its own exploit, and that will only work for it
Go find the courses from the cyber mentor and take those, they’ll help a lot. He has free ones on YouTube an paid courses on his site.
Try logging in through SSH with some default credentials (anonymous, admin/admin, admin/password, admin/no password, etc.). If none of those work, you can try gobuster to find useful info on the web server that’s running.