Parece una web que organiza competiciones de bicicleta. En la pestaña de How to participate nos encontramos con un enlace a un formulario, que es la única acción que se puede realizar en el site:
Al capturar la petición del form vemos que se envía por POST y que la página utiliza un PHPSESSID
Copiar sudo nmap -v -sV -sCV -T5 10.10.11.28
Copiar PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.11 (Ubuntu Linux ; protocol 2.0 )
| ssh-hostkey:
| 3072 e3:54:e0:72:20:3c:01:42:93:d1:66:9d:90:0c:ab:e8 (RSA)
| 256 f3:24:4b:08:aa:51:9d:56:15:3d:67:56:74:7c:20:38 (ECDSA)
| _ 256 30:b1:05:c6:41:50:ff:22:a3:7f:41:06:0e:67:fd:50 (ED25519)
80/tcp open http Apache httpd 2.4.41 ((Ubuntu))
| _http-server-header: Apache/2.4.41 (Ubuntu)
| http-cookie-flags:
| /:
| PHPSESSID:
| _ httponly flag not set
| _http-title: Sea - Home
| http-methods:
| _ Supported Methods: GET HEAD POST OPTIONS
Service Info: OS: Linux ; CPE: cpe:/o:linux:linux_kernel
Solo encontramos 2 puertos abiertos, el 22 y el 80. Los típicos.
Haciendo fuzzing con gobuster encontramos directorios interesantes, pero no podemos acceder, nos da status 301 forbidden
:
Copiar gobuster dir -u http://sea.htb -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -t 50 --status-codes "200,301,302" --status-codes-blacklist ""
===============================================================
Gobuster v3.6
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url: http://sea.htb
[+] Method: GET
[+] Threads: 50
[+] Wordlist: /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt
[+] Status codes: 200,301,302
[+] User Agent: gobuster/3.6
[+] Timeout: 10s
===============================================================
Starting gobuster in directory enumeration mode
===============================================================
/0 (Status: 200 ) [Size: 3650]
/themes (Status: 301 ) [Size: 230] [-- > http://sea.htb/themes/]
/data (Status: 301 ) [Size: 228] [-- > http://sea.htb/data/]
/plugins (Status: 301 ) [Size: 231] [-- > http://sea.htb/plugins/]
/messages (Status: 301 ) [Size: 232] [-- > http://sea.htb/messages/]
/404 (Status: 200 ) [Size: 3341]
/home (Status: 200 ) [Size: 3650]