SSRF
The target web application running on the port 8080 of the dc01.heist.offsec(192.168.198.165) host is vulnerable to SSRF.
┌──(kali㉿kali)-[~/PEN-200/PG_PRACTICE/heist]
└─$ sudo responder -I tun0 -v
The target web app is also sending a NTLM authentication alongside the GET request.
The enox user is already compromised; california