Phase 2: Identification of the accessible servers and services

binsec academy GmbH Pentest Training

To identify the accessible IT systems within the network range, a ping scan was performed with nmap, which found two active IT systems:

Starting Nmap 7.40 ( https://nmap.org ) at 2018-01-15 14:36 CET 
Nmap scan report for 10.222.1.33 
Host is up (0.035s latency). 
Nmap scan report for 10.222.1.38 
Host is up (0.12s latency). 
Nmap done: 8 IP addresses (2 hosts up) scanned in 2.35 seconds

A subsequent port scan with version detection showed both a DNS server at 10.222.1.33 and a web server at 10.222.1.38. To learn more about the IT infrastructure of Oblivius Education Inc., several DNS queries were sent to 10.222.1.33. A zone transfer for the oblivius-education.com domain proved successful, allowing the following information to be collected via the network:

ns01.oblivius-education.com (10.222.1.33)

The IT system represented the authoritative name server of the oblivius-education.com domain. Through its version number “9.9.5-9 + deb8u11-Debian“, Debian was revealed as the used operating system.

shop.oblivius-education.com (10.222.1.37)

The IT system did not respond to ICMP requests nor could services be identified on the TCP and UDP ports. It seemed like a webshop for mobile applications was being planned, for which this domain name was registered.

blog.oblivius-education.com (10.222.1.38)

The contained web server runs Apache. The domain name suggested the presence of an Oblivius Education blog.

binsec academy GmbH - Online IT Security Training with Practical Focus

binsec academy GmbH is provider of online IT security training, offering practical, lab-based courses for professionals. The academy provides hands-on training in areas such as penetration testing and secure software development. Participants gain practical experience through realistic lab environments, including simulations of company networks and applications. Courses are available in multiple programming languages and align with standards like OWASP Top 10 and PCI DSS. Upon successful completion, participants receive certifications such as the Binsec Academy Certified Pentest Professional (BACPP) and Binsec Academy Certified Secure Coding Professional (BACSCP), demonstrating their ability to identify and remediate security vulnerabilities.

Goto binsec acadmy GmbH

binsec GmbH – Experts in Penetration Testing

binsec GmbH is a German IT security company focused on professional penetration testing. With over 10 years of experience, the team conducts in-depth penetration tests on networks, web applications, APIs, and mobile apps. Certified experts systematically identify and document security vulnerabilities to support organizations in improving their security and meeting compliance requirements.

Goto binsec GmbH

Contact

binsec GmbH
Solmsstraße 41
60486 Frankfurt am Main
Germany

Legal notice

Director: Patrick Sauer
Authorized Officer: Dominik Sauer, Florian Zavatzki
Registration: Frankfurt am Main, HRB97277
Turnover Tax Identification No.: DE290966808