To identify the accessible IT systems within the network range, a ping scan was performed with nmap, which found two active IT systems:
Starting Nmap 7.40 ( https://nmap.org ) at 2018-01-15 14:36 CET
Nmap scan report for 10.222.1.33
Host is up (0.035s latency).
Nmap scan report for 10.222.1.38
Host is up (0.12s latency).
Nmap done: 8 IP addresses (2 hosts up) scanned in 2.35 seconds
A subsequent port scan with version detection showed both a DNS server at 10.222.1.33 and a web server at 10.222.1.38. To learn more about the IT infrastructure of Oblivius Education Inc., several DNS queries were sent to 10.222.1.33. A zone transfer for the oblivius-education.com domain proved successful, allowing the following information to be collected via the network:
ns01.oblivius-education.com (10.222.1.33)
The IT system represented the authoritative name server of the oblivius-education.com domain. Through its version number “9.9.5-9 + deb8u11-Debian“, Debian was revealed as the used operating system.
shop.oblivius-education.com (10.222.1.37)
The IT system did not respond to ICMP requests nor could services be identified on the TCP and UDP ports. It seemed like a webshop for mobile applications was being planned, for which this domain name was registered.
blog.oblivius-education.com (10.222.1.38)
The contained web server runs Apache. The domain name suggested the presence of an Oblivius Education blog.
Last modified: Dec. 15, 2022
Take a look at the pentest training chapters and learn penetration testing:
Discover the world of penetration testing. Learn how to infiltrate networks and successfully penetrate systems and applications. Acquire the necessary hacking skills and use them when conducting professional penetration tests. Become a real penetration tester. Here you will find the free documents for the Pentest Training of binsec academy GmbH. The binsec academy GmbH offers the corresponding security training lab environments and certifications. However, the knowledge and wiki articles on hacking and penetration testing is universal.
binsec academy GmbH is the European provider of online security training with virtual laboratory environments. The core component of all security training is the focus on practice, practice and more practice. In the wiki here you will find the public and freely available course materials. You can put the theory into practice at binsec-academy.com.