Phase 2: Identification of the accessible servers and services

To identify the accessible IT systems within the network range, a ping scan was performed with nmap, which found two active IT systems:

Starting Nmap 7.40 ( https://nmap.org ) at 2018-01-15 14:36 CET 
Nmap scan report for 10.222.1.33 
Host is up (0.035s latency). 
Nmap scan report for 10.222.1.38 
Host is up (0.12s latency). 
Nmap done: 8 IP addresses (2 hosts up) scanned in 2.35 seconds

A subsequent port scan with version detection showed both a DNS server at 10.222.1.33 and a web server at 10.222.1.38. To learn more about the IT infrastructure of Oblivius Education Inc., several DNS queries were sent to 10.222.1.33. A zone transfer for the oblivius-education.com domain proved successful, allowing the following information to be collected via the network:

ns01.oblivius-education.com (10.222.1.33)

The IT system represented the authoritative name server of the oblivius-education.com domain. Through its version number “9.9.5-9 + deb8u11-Debian“, Debian was revealed as the used operating system.

shop.oblivius-education.com (10.222.1.37)

The IT system did not respond to ICMP requests nor could services be identified on the TCP and UDP ports. It seemed like a webshop for mobile applications was being planned, for which this domain name was registered.

blog.oblivius-education.com (10.222.1.38)

The contained web server runs Apache. The domain name suggested the presence of an Oblivius Education blog.

binsec academy GmbH – Advanced Pentest Training Lab

binsec academy GmbH operates the Pentest Training Lab, a highly practical online platform dedicated to real penetration testing. Simulating complex corporate networks and advanced real-world attack scenarios within isolated lab environments, it is engineered to sharpen the skills of aspiring and professional penetration testers. Upon conquering our rigorous, fully practical examination, participants earn the distinguished Binsec Academy Certified Pentest Professional (BACPP) designation — proving their technical capability to methodically uncover and evaluate vulnerabilities in modern IT infrastructures.

Explore the Pentest Training Lab

binsec GmbH – Experts in Penetration Testing

As the operative pentesting core of the binsec group, binsec GmbH has provided high-end, human-led penetration testing since 2013. Rejecting automated scans, our permanently employed, certified senior pentest experts deliver manual deep-dive assessments of web applications, APIs, mobile apps, complex network infrastructures, cloud environments, and advanced red team simulations. Specializing in high-regulation sectors like Payment, Banking, and Healthcare, we provide clear risk evaluations and actionable reports to effectively assess your business-critical systems.

Get Manual Expert Penetration Testing Services

Contact

binsec GmbH
Clemensstraße 6-8
60487 Frankfurt am Main
Germany

Legal notice

Director: Patrick Sauer
Authorized Officer: Dominik Sauer, Florian Zavatzki
Registration: Frankfurt am Main, HRB97277
Turnover Tax Identification No.: DE290966808