Fawn Machine - Hack The Box - Writeup

Pasted image 20230404095947.png

Recon

We start with nmap scan to found the ports open, we use a silent scan and don't apply dns resolution:

Pasted image 20230404100208.png
We export the archive of nmap in a grepable format, to use a function called extractPorts it's developed by s4vitar and gather the neccesary information and copy the open ports to clipboard:

Pasted image 20230404100919.png

We found the port 21 - TCP is open.

Let's launch another namp scan but more agressive to found the version and service is running in that port.

Pasted image 20230404101121.png

The results:
Pasted image 20230404101222.png

We found a missconfiguration, the ftp permits anonymous login and we have access to a flag.

Pasted image 20230404101304.png

Try to get into the machine:

Pasted image 20230404101844.png
Pasted image 20230404101914.png

In this case you can use any password or let in blank and hit enter.

Let list the files are in the directory in the nmap scan, we discover we have access to a file called flag.txt:

Pasted image 20230404102044.png

if you use help, a list of instructions with some utils comand is shown:

Pasted image 20230404102332.png

we use the command get this download a file to your machine.

Pasted image 20230404102423.png

Let list the files in the current directory:

Pasted image 20230404102500.png

and we have the flag, the rest is only print it with cat:

Pasted image 20230404102541.png

Summary

Fawn is a good machine to start, we get used to recognize ports, services and the version of services run in it, another part we learn about the anonymous access and the file protocol transfer and how to navigate in and how to get a file, basic but necessary and elemental.