xsspresso
xsspresso
Tags/ FTP

FTP

13 writeups tagged with FTP

MiscMediumLinux

VHL — Teamspeak

TeamSpeak 3 server on CentOS. Enumerated FTP for credentials and exploited a vulnerable web application for system access.

#TeamSpeak#FTP#CentOS
Feb 15, 2025Virtual Hacking Labs
WebMediumLinux

VHL — CMS01

Joomla CMS on CentOS with anonymous FTP. Exploited a Joomla authenticated RCE CVE via the template editor for code execution.

#Joomla#RCE#FTP
Feb 13, 2025Virtual Hacking Labs
MiscEasyLinux

VHL — Natural

FTP anonymous login exposes web application files. Abused file write via FTP to upload a PHP webshell for initial access.

#FTP#Anonymous Login#Web Shell
Feb 12, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Trails

Hiking Trails web application on Ubuntu. Directory traversal and file inclusion vulnerabilities lead to credentials and shell.

#LFI#Directory Traversal#Apache
Feb 12, 2025Virtual Hacking Labs
WebEasyWindows

VHL — Jennifer

Windows with FileZilla FTP and CMS Mini web app. FTP credential exposure and CMS RCE via file upload for initial foothold.

#FileZilla#FTP#CMS
Feb 12, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Helpdesk

FTP with anonymous access reveals helpdesk application credentials. SQL injection and file upload lead to remote code execution.

#FTP#SQLi#File Upload
Feb 10, 2025Virtual Hacking Labs
MiscEasyWindows

VHL — Steven

Wing FTP Server on Windows. Default admin credentials allow access to the web admin panel, leading to command execution via scheduled tasks.

#Wing FTP#Default Creds#FTP
Feb 10, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Web01-Prd

Production web server with anonymous FTP access. Weak credentials and misconfigured permissions lead to full compromise.

#FTP#Anonymous Login#Misconfiguration
Feb 9, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Forum

uftpd FTP server with anonymous access. Forum application vulnerability exploited to obtain a shell and escalate to root.

#FTP#uftpd#Forum
Feb 9, 2025Virtual Hacking Labs
MiscEasyLinux

VHL — Backupadmin

FTP server with anonymous access exposes backup credentials. Password reuse leads to SSH login and privilege escalation.

#FTP#Anonymous Login#Password Reuse
Feb 8, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Web01-Dev

Development web server with FTP credentials leaked via anonymous login. Credential reuse and web shell upload for root.

#FTP#Web Shell#File Upload
Feb 8, 2025Virtual Hacking Labs
MiscEasyWindows

HTB — ServMon

Anonymous FTP reveals NVMS-1000 path traversal note. LFI reads credentials file, SSH pivoting to access NSClient++ for SYSTEM.

#FTP#LFI#NVMS-1000
Nov 20, 2024HackTheBox
WebEasyWindows

HTB — Devel

Anonymous FTP write access to IIS webroot allows ASPX webshell upload. Local kernel exploit for SYSTEM.

#FTP#IIS#ASPX
May 10, 2022HackTheBox