┌──(kali㉿kali)-[~] └─$ sudo nmap -sC -sV -p21,22,80 10.129.73.189 [sudo] password for kali: Starting Nmap 7.95 ( https://nmap.org ) at 2026-01-15 01:36 EST Nmap scan report for 10.129.73.189 Host is up (0.22s latency).
PORT STATE SERVICE VERSION 21/tcp open ftp vsftpd 3.0.3 22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.2 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 3072 fa:80:a9:b2:ca:3b:88:69:a4:28:9e:39:0d:27:d5:75 (RSA) | 256 96:d8:f8:e3:e8:f7:71:36:c5:49:d5:9d:b6:a4:c9:0c (ECDSA) |_ 256 3f:d0:ff:91:eb:3b:f6:e1:9f:2e:8d:de:b3:de:b2:18 (ED25519) 80/tcp open http Gunicorn |_http-title: Security Dashboard |_http-server-header: gunicorn Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 14.99 seconds
### Foothold Going to http://10.129.73.189/, I see it’s a Security Dashboard.
Upon going through the website, I find a Security Snapshot page where it captures 5 seconds snapshot PCAP and it takes me to http://10.129.73.189/data/1. Changing the url to http://10.129.73.189/data/0, I can download the first snapshot. I find the following FTP credentials in 0.pcap file.
┌──(kali㉿kali)-[~] └─$ ssh nathan@10.129.73.189 The authenticity of host '10.129.73.189 (10.129.73.189)' can't be established. ED25519 key fingerprint is: SHA256:UDhIJpylePItP3qjtVVU+GnSyAZSr+mZKHzRoKcmLUI This key is not known by any other names. Are you sure you want to continue connecting (yes/no/[fingerprint])? yes Warning: Permanently added '10.129.73.189' (ED25519) to the list of known hosts. ** WARNING: connection is not using a post-quantum key exchange algorithm. ** This session may be vulnerable to "store now, decrypt later" attacks. ** The server may need to be upgraded. See https://openssh.com/pq.html nathan@10.129.73.189's password: Permission denied, please try again. nathan@10.129.73.189's password: Permission denied, please try again. nathan@10.129.73.189's password: Welcome to Ubuntu 20.04.2 LTS (GNU/Linux 5.4.0-80-generic x86_64)