Let’s start with port scan as always:
So many ports…
So:
25
is hMailServer
53
is Simple DNS Plus
80
is IIS http server
389
is LDAP
445
is SMB
3268
is LDAP
3389
is RDP
5985
is winrm
And a lot of other ports! But I think we are interested only in this list.
I think about starting at http and running fuzzer on it:
After checking page I immediately found domain that might be useful:
So let’s add it to the hosts 10.10.11.21 axlle.htb
It’s the same page:
But now we can run subdomain scan!
After trying multiple wordlists no additional subdomains was found. Let’s try switching to other ports.
Let’s check smb:
Nothing interesting…