Skills Assessment

Skills Assessment Part 1

The first part of the skills assessment will require you to brute-force the the target instance. Successfully finding the correct login will provide you with the username you will need to start Skills Assessment Part 2.

You might find the following wordlists helpful in this engagement: usernames.txtarrow-up-right and passwords.txtarrow-up-right


  • What is the password for the basic auth login?

hydra -L top-users.txt -P 2023-200_most_used_passwords.txt -s 40526 94.237.50.221 http-get /
  • After successfully brute forcing the login, what is the username you have been given for the next part of the skills assessment?


Skills Assessment Part 2

This is the second part of the skills assessment. YOU NEED TO COMPLETE THE FIRST PART BEFORE STARTING THIS. Use the username you were given when you completed part 1 of the skills assessment to brute force the login on the target instance.


  • What is the username of the ftp user you find via brute-forcing?

First u can se with nmap, it machine have open the por ssh 22, so, brute force -->

Then witht the crendentials, login and see internal ports -->

So FTP is also running. I checked the content of /etc/passwd to know the ftp user which is thomas.

  • Note: I could have used Username anarchy to identify the ftp username

Inside of the machine I found a .txt called IncidentReport.txt:

Then I performed a brute force attack to the ftp:

  • What is the flag contained within flag.txt

Last updated