Message from @Gespa

Discord ID: 599384196854710276


2019-07-12 23:33:45 UTC  

why are you the one trying to get into it

2019-07-12 23:33:56 UTC  

That literally is cyber security.

2019-07-12 23:34:06 UTC  

Part of knowing how to stop something is knowing how to get in.

2019-07-12 23:34:10 UTC  

Because to do penetration testing you have to show that a system is vulnerable

2019-07-12 23:34:18 UTC  

hmph

2019-07-12 23:34:24 UTC  

did they not teach you?

2019-07-12 23:34:30 UTC  

That's what they are doing

2019-07-12 23:34:44 UTC  

That's why I'm assigned the lab

2019-07-12 23:34:57 UTC  

then they should've taught you how :p

2019-07-12 23:35:06 UTC  

That's not how it works lol

2019-07-12 23:35:13 UTC  

You’re being quite obstinate Tim

2019-07-12 23:35:20 UTC  

ye

2019-07-12 23:35:47 UTC  

so you're trying to get gud? stackoverflow is probably where you should be lol

2019-07-12 23:36:02 UTC  

I'm just trying to do this assignment for now

2019-07-12 23:36:12 UTC  

@EndangeredProdigy what specifically are you tasked with doing? You weren’t given any sort of idea?

2019-07-12 23:36:59 UTC  

One sec I'll paste the instructions

2019-07-12 23:37:16 UTC  

all you've told us is "get in some server and get some credentials"

2019-07-12 23:37:29 UTC  

Objective
The objective of this scenario is to deface the corporate web server. In order to accomplish this objective, you need to complete a series of tasks designed to test your ability to enumerate and identify potential system and network vulnerabilities, exploit systems and/or networks based on vulnerability discoveries, recover system user credentials, use recovered credentials to pivot onto other information systems in the network(s) and establish a connection to deface the corporate web server.
Each task in this scenario builds upon the task before it. There may be a situation where a solution exists outside the proposed task methodology. You are NOT penalized for using a different solution – please use whatever means necessary to achieve the final objective – Deface the Web Server.

2019-07-12 23:37:52 UTC  

Scenario
You were recently hired for a Pentration Tester position. You are responsible for pentration testing information systems located in the Local Area Network (LAN) and the Demilitarized Zone (DMZ).
A new web server was recently installed in the DMZ and you are tasked with attempting to compromise this server as a simulated external (WAN/Internet) threat. For the purposes of this exercise you have access to a Kali Linux virtual machine.
Notes:
The IP address of the external router is 198.51.100.1/32.
The IP address of the corporate web server resides somewhere on the 120.38.48.0/24 network.

2019-07-12 23:38:25 UTC  

Scenario
In this exercise, you will use a Kali Linux virtual machine to intrude into a demonstration network to deface a corporate web server.
1. Use the Kali Linux virtual machine to enumerate the network and discover any potential misconfigurations and/or vulnerable information systems.
Log into the Kali Linux VM:
Username: root
Password: performanscore
2. Based on your vulnerability discovery(ies), exploit the system(s) using the Kali Linux virtual machine.
3. Use a method available to you on the Kali Linux virtual machine to recover any credentials from the compromised system.
4. Use your newly acquired network access to create a pass-through capability (PIVOT) onto other networks of opportunity.
5. Use the built-in functions of Metasploit on the Kali Linux virtual machine to conduct a portscan on the LAN network. Discover any potential misconfigurations and/or vulnerable information systems.
6. Use the previously stolen credentials to access the domain controller.
7. Leverage xfreerdp on the Kali Linux virtual machine to RDP onto the Windows 8 VM.
8. Deface the webpage hosted on the web server by modifying the webpage index.html file.

2019-07-12 23:38:48 UTC  

This looks like something you’d see in packettracer or something...

2019-07-12 23:38:57 UTC  

You doing CCNA Sec or something?

2019-07-12 23:39:14 UTC  

Just a cybersecurity program at University

2019-07-12 23:39:34 UTC  

Ah.

2019-07-12 23:39:59 UTC  

Could you help?

2019-07-12 23:40:01 UTC  

shoulda paid attention in class <:hypersmugon:544638648721604608>

2019-07-12 23:40:08 UTC  

no, im not an expert :p

2019-07-12 23:40:13 UTC  

We don't have class it's online

2019-07-12 23:40:38 UTC  

what are stuck on?

2019-07-12 23:40:46 UTC  

No particularly, I’m afraid. I’m far better at building a router than I am at tearing it down. Best of luck regardless.

2019-07-12 23:41:04 UTC  

hes defacing a webpage on a a virtual assignment in whatever means he chooses

2019-07-12 23:41:54 UTC  

https://cdn.discordapp.com/attachments/598761542200197120/599384974071955476/KaiserClass.jpg

2019-07-12 23:42:01 UTC  

I've only been able to open a meterpreter session on the router

2019-07-12 23:42:05 UTC  

But not the server

2019-07-12 23:42:21 UTC  

it is amazing how many trees he cut down

2019-07-12 23:42:40 UTC  

powah of the Kaiser

2019-07-12 23:42:55 UTC  

I cut my hair, you guys like it?

https://cdn.discordapp.com/attachments/598761542200197120/599385224673099786/unknown.png

2019-07-12 23:43:20 UTC  

looks good @SideTracker