Pathway
Enumeration:
Port Scanning:
┌──(kali㉿kali)-[~/…/Machines/OffsecPG/Practice/Pathway]
└─$ sudo nmap -sCV -p- --min-rate 4000 -oA nmap/services -vv 192.168.210.230 --open
Starting Nmap 7.95 ( https://nmap.org ) at 2025-11-04 19:50 UTC
Nmap scan report for 192.168.210.230
Host is up, received echo-reply ttl 61 (0.15s latency).
Scanned at 2025-11-04 19:50:43 UTC for 152s
Not shown: 65520 closed tcp ports (reset), 11 filtered tcp ports (no-response)
Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
PORT STATE SERVICE REASON VERSION
22/tcp open ssh syn-ack ttl 61 OpenSSH 9.2p1 Debian 2+deb12u5 (protocol 2.0)
| ssh-hostkey:
| 256 fc:72:06:8f:ef:ec:9b:87:f3:95:ca:f2:e7:1f:ea:dc (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBFyksaWzSNfPbN6T3ts7+fGJ0/9aIXrN7HimSzjO+W6pfa1Qq4QZb/hnkglJwvjgcTOQiraq2M9EQ9JtbRC1ROY=
| 256 42:c2:f0:fd:85:f6:93:cb:bd:a0:e8:ed:c1:a2:6d:60 (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHbDRRUQ2YifMbadcFEg6fdgQ2bcGEHcQyrud/UFwLiy
80/tcp open http syn-ack ttl 61 nginx 1.22.1
|_http-title: Chain App Dev
|_http-server-header: nginx/1.22.1
| http-methods:
|_ Supported Methods: GET HEAD POST
3089/tcp open ptk-alink? syn-ack ttl 61
| fingerprint-strings:
| DNSStatusRequestTCP, DNSVersionBindReqTCP, Help, Kerberos, LANDesk-RC, LDAPBindReq, LDAPSearchReq, LPDString, RPCCheck, SIPOptions, SMBProgNeg, SSLSessionReq, TLSSessio
nReq, TerminalServerCookie, X11Probe:
| HTTP/1.1 400 Bad Request
| Connection: close
| FourOhFourRequest:
| HTTP/1.1 400 Bad Request
| content-type: text/plain; charset=UTF-8
| Date: Tue, 04 Nov 2025 19:51:22 GMT
| Connection: close
| GetRequest, HTTPOptions:
| HTTP/1.1 400 Bad Request
| content-type: text/plain; charset=UTF-8
| Date: Tue, 04 Nov 2025 19:51:18 GMT
| Connection: close
| RTSPRequest:
| HTTP/1.1 400 Bad Request
| content-type: text/plain; charset=UTF-8
| Date: Tue, 04 Nov 2025 19:51:19 GMT
|_ Connection: close
4566/tcp open http syn-ack ttl 60 TwistedWeb httpd 24.3.0
| http-methods:
|_ Supported Methods: GET HEAD POST OPTIONS
|_http-server-header: TwistedWeb/24.3.0|_http-title: Site doesn't have a title (text/plain; charset=utf-8).
<snipped>
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
<snipped>SSH (20):
HTTP (80):

? (3089):




? (4566):



Post-Exploitation:

Last updated