Port enumeration

Using nmap, I found 2 open ports, 22 and 80. e0e39365964b6e229cbe216d04088c41.png

Web enumeration

In the web, I found 2 pages, a registry page and a login page. 825647e1216d32f8b51b96dbc5c2599a.png Using ffuf, I found an assets directory, where I can see the profile image I sent. 5a99d22fed39c2c7c12cfa67838be170.png 90f2b1a46f10d5bdcd2ba669f8ec7ac5.png

DNS Enumeration

Using ffuf, I found a subdomain. 61503573793887f0b29c730d530a02ff.png Inside this page, I found a CrushFTP instance vulnerable to CVE-2025-31161. 067850c692203bb84b7e924a79f570e6.png

RCE

I executed a exploit to create a new admin account. b242a73c766a17b58d4de6fd7f07ace4.png Using this account, I was eble to upload a php reverse shell inside profiles directory. 61601bef9f2dfb9fdfcc627cd80cb8ba.png c947f7cd5353c3d3a7a1f3f427c3a53c.png

Local machine enumeration

Enumerating executable files, I found an interesting script. 535604e8a95ec96dce2c3c295b06337c.png This script in working. 1220b9225b117e3c3c35991442d0ce49.png Inside this script I found the ben password. c3aff55820e20c2ff57c91afc1200633.png

Ben user enumeration.

As ben I found an internal service in port 2222. e864085e3783df4119b629e72bcbc482.png This service is an instance of SSH-2.0-Erland vulnerable to RCE. f7eecab0f8e5784af1160077f667646d.png Using an exploit, I obtained a shell as root. 4175ddf56e3265e94b07107497bbaaf5.png Reading the flag and ending the CTF. a9da46aff5a01763a0d345a538eb990c.png