HTB | Nocturnal
NMAP
└─$ nmap -sT -p- --min-rate 10000 10.10.11.64 -Pn -oA nmap_ports
Starting Nmap 7.95 ( <https://nmap.org> ) at 2025-05-14 23:36 IST
Nmap scan report for 10.10.11.64
Host is up (0.80s latency).
Not shown: 65482 filtered tcp ports (no-response), 51 closed tcp ports (conn-refused)
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
Nmap done: 1 IP address (1 host up) scanned in 104.95 seconds└─$ nmap -sC -sV -p 22,80 10.10.11.64 -Pn -oA nmap_ports_details
Starting Nmap 7.95 ( <https://nmap.org> ) at 2025-05-14 23:42 IST
Nmap scan report for 10.10.11.64
Host is up (0.30s latency).
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.12 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 3072 20:26:88:70:08:51:ee:de:3a:a6:20:41:87:96:25:17 (RSA)
| 256 4f:80:05:33:a6:d4:22:64:e9:ed:14:e3:12:bc:96:f1 (ECDSA)
|_ 256 d9:88:1f:68:43:8e:d4:2a:52:fc:f0:66:d4:b9:ee:6b (ED25519)
80/tcp open http nginx 1.18.0 (Ubuntu)
|_http-server-header: nginx/1.18.0 (Ubuntu)
|_http-title: Did not follow redirect to <http://nocturnal.htb/>
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Service detection performed. Please report any incorrect results at <https://nmap.org/submit/> .
Nmap done: 1 IP address (1 host up) scanned in 29.00 seconds
Port 80

Directory search
Foothold/shell




fuzzing username




priacy.odt


admin panel




shell as www-data


shell as tobias


Privilege Escalation
port 8080




CVE 2023-46818


Last updated