Blunder is a retired box on HTB.

Hostname: Blunder | Difficulty Level: Easy | Operating System: Linux


Jarvis is a retired box on HTB and is part of TJ Null’s OCSP-like boxes.

Hostname: Jarvis| Difficulty Level: Medium | Operating System: Linux

NMAP Scan

┌──(root💀kali)-[/home/kali/labs/HTB/Jarvis]
└─# nmap -sC -sV -oA Jarvis 10.10.10.143
Starting Nmap 7.91 ( https://nmap.org ) at 2021–06–21 17:49 EDT
Nmap scan report for 10.10.10.143
Host is up (0.10s latency).
Not shown: 998 closed ports
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 7.4p1 Debian 10+deb9u6 (protocol 2.0)
| ssh-hostkey:
| 2048 03:f3:4e:22:36:3e:3b:81:30:79:ed:49:67:65:16:67 (RSA)
| 256 25:d8:08:a8:4d:6d:e8:d2:f8:43:4a:2c:20:c8:5a:f6 (ECDSA)
|_ 256 77:d4:ae:1f:b0:be:15:1f:f8:cd:c8:15:3a:c3:69:e1 (ED25519)
80/tcp open http Apache httpd 2.4.25 ((Debian))
| http-cookie-flags:
| /:
| PHPSESSID:
|_ httponly flag not set
|_http-server-header: Apache/2.4.25 (Debian)
|_http-title: Stark Hotel
Service Info: OS: Linux; CPE…


SolidState is a retired box on HTB and is part of TJ Null’s OCSP-like boxes.

Hostname: SolidState| Difficulty Level: Medium | Operating System: Linux

NMAP Scan

┌──(root💀kali)-[/home/kali/labs/HTB/SolidState]
└─# nmap -sC -sV -oA SolidState 10.10.10.51
Starting Nmap 7.91 ( https://nmap.org ) at 2021–06–16 13:50 EDT
Nmap scan report for 10.10.10.51
Host is up (0.097s latency).
Not shown: 995 closed ports
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 7.4p1 Debian 10+deb9u1 (protocol 2.0)
| ssh-hostkey:
| 2048 77:00:84:f5:78:b9:c7:d3:54:cf:71:2e:0d:52:6d:8b (RSA)
| 256 78:b8:3a:f6:60:19:06:91:f5:53:92:1d:3f:48:ed:53 (ECDSA)
|_ 256 e4:45:e9:ed:07:4d:73:69:43:5a:12:70:9d:c4:af:76 (ED25519)
25/tcp open smtp JAMES smtpd 2.3.2
|_smtp-commands: solidstate Hello nmap.scanme.org (10.10.14.14 [10.10.14.14]),
80/tcp open http Apache httpd 2.4.25 ((Debian))
|_http-server-header: Apache/2.4.25 (Debian)
|_http-title: Home — Solid State Security
110/tcp…


OpenAdmin is a retired box on HTB and is part of TJ Null’s OCSP-like boxes.

Hostname: OpenAdmin| Difficulty Level: Easy | Operating System: Linux

┌──(root💀kali)-[/home/kali/labs/HTB/OpenAdmin]
└─# nmap -sC -sV -oA OpenAdmin 10.10.10.171
Starting Nmap 7.91 ( https://nmap.org ) at 2021–06–01 18:22 EDT
Nmap scan report for 10.10.10.171
Host is up (0.030s latency).
Not shown: 998 closed ports
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 2048 4b:98:df:85:d1:7e:f0:3d:da:48:cd:bc:92:00:b7:54 (RSA)
| 256 dc:eb:3d:c9:44:d1:18:b1:22:b4:cf:de:bd:6c:7a:54 (ECDSA)
|_ 256 dc:ad:ca:3c:11:31:5b:6f:e6:a4:89:34:7c:9b:e5:50 (ED25519)
80/tcp open http Apache httpd 2.4.29 ((Ubuntu))
|_http-server-header: Apache/2.4.29 …


Cronos is a retired box on HTB and is part of TJ Null’s OCSP-like boxes.

Hostname: Cronos| Difficulty Level: Medium | Operating System: Linux

┌──(root💀kali)-[/home/kali/labs/HTB/Cronos]
└─# nmap -sC -sV -oA Cronos 10.10.10.13
Starting Nmap 7.91 ( https://nmap.org ) at 2021–06–03 18:49 EDT
Nmap scan report for 10.10.10.13
Host is up (0.021s latency).
Not shown: 997 filtered ports
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.1 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 2048 18:b9:73:82:6f:26:c7:78:8f:1b:39:88:d8:02:ce:e8 (RSA)
| 256 1a:e6:06:a6:05:0b:bb:41:92:b0:28:bf:7f:e5:96:3b (ECDSA)
|_ 256 1a:0e:e7:ba:00:cc:02:01:04:cd:a3:a9:3f:5e:22:20 (ED25519)
53/tcp open domain ISC BIND 9.10.3-P4 (Ubuntu Linux)
| dns-nsid:
|_ bind.version: 9.10.3-P4-Ubuntu
80/tcp open http Apache httpd 2.4.18 ((Ubuntu))
|_http-server-header: Apache/2.4.18 (Ubuntu)
|_http-title: Apache2 Ubuntu Default Page…


Buff is a retired box on HTB and is part of TJ Null’s OCSP-like boxes.

Hostname: Buff| Difficulty Level: Easy | Operating System: Windows

┌──(root💀kali)-[/home/kali/labs/HTB/Buff]
└─# nmap -sC -sV -oA Buff 10.10.10.198
Starting Nmap 7.91 ( https://nmap.org ) at 2021–05–10 18:42 EDT
Nmap scan report for 10.10.10.198
Host is up (0.20s latency).
Not shown: 999 filtered ports
PORT STATE SERVICE VERSION
8080/tcp open http Apache httpd 2.4.43 ((Win64) OpenSSL/1.1.1g PHP/7.4.6)
| http-open-proxy: Potentially OPEN proxy.
|_Methods supported:CONNECTION
|_http-server-header: Apache/2.4.43 (Win64) OpenSSL/1.1.1g PHP/7.4.6
|_http-title: mrb3n’s Bro Hut

┌──(root💀kali)-[/home/kali/labs/HTB/Buff]
└─# nmap -p- -oA Allports 10.10.10.198
Starting Nmap 7.91 ( https://nmap.org ) at 2021–05–10 18:44…


Doctor is a retired box on HTB and is part of TJ Null’s OCSP-like boxes.

Hostname: Doctor | Difficulty Level: Easy | Operating System: Linux

# Nmap 7.91 scan initiated Thu May 27 10:45:26 2021 as:
nmap -sC -sV -oA Doctor 10.10.10.209
Nmap scan report for 10.10.10.209
Host is up (0.024s latency).
Not shown: 997 filtered ports
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.1 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 3072 59:4d:4e:c2:d8:cf:da:9d:a8:c8:d0:fd:99:a8:46:17 (RSA)
| 256 7f:f3:dc:fb:2d:af:cb:ff:99:34:ac:e0:f8:00:1e:47 (ECDSA)
|_ 256 53:0e:96:6b:9c:e9:c1:a1:70:51:6c:2d:ce:7b:43:e8 (ED25519)
80/tcp open http Apache httpd 2.4.41 ((Ubuntu))
|_http-server-header: Apache/2.4.41 (Ubuntu)
|_http-title: Doctor
8089/tcp open ssl/http Splunkd httpd
| http-robots.txt: 1 disallowed entry
|_/
|_http-server-header: Splunkd
|_http-title: splunkd
| ssl-cert: Subject…


Frolic is a retired box on HTB and is part of TJ Null’s OCSP-like boxes.

Hostname: Frolic| Difficulty Level: Easy | Operating System: Linux

┌──(root💀kali)-[/home/kali/labs/HTB/Frolic]
└─# nmap -p- -Pn -oA Allports 10.10.10.111
Host discovery disabled (-Pn). All addresses will be marked ‘up’ and scan times will be slower.
Starting Nmap 7.91 ( https://nmap.org ) at 2021–05–24 18:51 EDT
Nmap scan report for 10.10.10.111
Host is up (0.024s latency).
Not shown: 65530 closed ports
PORT STATE SERVICE
22/tcp open ssh
139/tcp open netbios-ssn
445/tcp open microsoft-ds
1880/tcp open vsat-control
9999/tcp open abyss

Browsing to ‘http://10.10.10.111:9999/’ reveals a webpage. Website mentions URL…


Forest is a retired box on HTB and is part of TJ Null’s OCSP-like boxes.

Hostname: Forest| Difficulty Level: Easy | Operating System: Windows

┌──(root💀kali)-[/home/kali/labs/HTB/Forest]
└─# nmap -sC -sV -oA Forest 10.10.10.161
Starting Nmap 7.91 ( https://nmap.org ) at 2021–05–13 20:35 EDT
Nmap scan report for 10.10.10.161
Host is up (0.021s latency).
Not shown: 989 closed ports
PORT STATE SERVICE VERSION
53/tcp open domain Simple DNS Plus
88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2021–05–14 00:58:12Z)
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: htb.local, Site: Default-First-Site-Name)
445/tcp open microsoft-ds Windows Server 2016 Standard 14393 microsoft-ds (workgroup: HTB)
464/tcp…


Sauna is a retired box on HTB and is part of TJ Null’s OCSP-like boxes.

Hostname: Sauna| Difficulty Level: Easy | Operating System: Windows

┌──(root💀kali)-[/home/kali/labs/HTB/Sauna]
└─# nmap -sC -sV -oA Sauna 10.10.10.175
Starting Nmap 7.91 ( https://nmap.org ) at 2021–05–20 20:33 EDT
Nmap scan report for 10.10.10.175
Host is up (0.033s latency).
Not shown: 988 filtered ports
PORT STATE SERVICE VERSION
53/tcp open domain Simple DNS Plus
80/tcp open http Microsoft IIS httpd 10.0
| http-methods:
|_ Potentially risky methods: TRACE
|_http-server-header: Microsoft-IIS/10.0
|_http-title: Egotistical Bank :: Home
88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2021–05–21 07:49:03Z)
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
389/tcp open ldap Microsoft Windows…

Shraddha M.

Security Analyst

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store