FTP
Nmap discovered a FTP server on the port 21
of the HACKSMARTERSEC
(10.10.183.209
) host.
The running service is Microsoft ftpd
Null Session
┌──(kali㉿kali)-[~/archive/thm/hacksmartersecurity]
└─$ ftp ftp@$IP
Connected to 10.10.183.209.
220 Microsoft FTP Service
331 Anonymous access allowed, send identity (e-mail name) as password.
Password:
230 User logged in.
Remote system type is Windows_NT.
ftp> rstatus
211-Microsoft FTP Service status:
Logged in user: Anonymous
TYPE: ASCII; FORM: NONPRINT; STRUcture: FILE; transfer MODE: STREAM
Data connection: none
211 End of status.
ftp>
Session established. The target FTP server allows anonymous access.
ftp> put test
local: test remote: test
229 Entering Extended Passive Mode (|||49736|)
550 Access is denied.
Write access is not granted.
ftp> ls -la
229 Entering Extended Passive Mode (|||49735|)
125 Data connection already open; Transfer starting.
06-28-23 02:58PM 3722 Credit-Cards-We-Pwned.txt
06-28-23 03:00PM 1022126 stolen-passport.png
226 Transfer complete.
2 files available
Credit-Cards-We-Pwned.txt
┌──(kali㉿kali)-[~/archive/thm/hacksmartersecurity]
└─$ cat Credit-Cards-We-Pwned.txt
VISA, 4929012623542946, 8/2027, 273
VISA, 4556638818403096, 8/2024, 166
VISA, 4024007166395359, 12/2027, 209
VISA, 4485714082654957, 12/2028, 834
VISA, 4716405563341310, 12/2023, 235
VISA, 4556430097066053, 7/2030, 493
VISA, 4916389512648686, 10/2026, 269
VISA, 4532953400107172, 8/2026, 862
VISA, 4485122260041080, 11/2024, 446
VISA, 4485650070135122, 5/2027, 411
VISA, 4916828190458462, 4/2029, 859
VISA, 4532452179409778, 7/2028, 450
VISA, 4532676678238045, 11/2030, 521
VISA, 4539865157272244, 8/2029, 452
VISA, 4916271858910955, 9/2026, 671
VISA, 4532317257711629, 7/2027, 867
VISA, 4916165338323542, 2/2023, 361
VISA, 4760461258276522, 2/2025, 492
VISA, 4916725323150737, 10/2030, 226
VISA, 4532834873682299, 3/2028, 700
VISA, 4929191703053576, 1/2026, 294
VISA, 4539698655135211, 11/2026, 199
VISA, 4024007102813655, 2/2024, 370
VISA, 4539420298777113, 2/2025, 335
VISA, 4532005568344103, 4/2026, 862
VISA, 4532063243654230, 6/2026, 334
VISA, 4485150732825871, 2/2024, 621
VISA, 4442679511790437, 6/2027, 353
VISA, 4485795891608045, 9/2029, 331
VISA, 4532568184243454, 8/2024, 663
VISA, 4929542676935225, 1/2026, 297
VISA, 4539861652328540, 11/2025, 586
VISA, 4024007195803530, 3/2029, 763
VISA, 4556507563599954, 10/2023, 637
VISA, 4716769283740741, 1/2023, 827
VISA, 4916860170619524, 8/2027, 819
VISA, 4916815465532006, 9/2025, 892
VISA, 4539073124117242, 9/2030, 247
VISA, 4539112760330683, 7/2024, 472
VISA, 4556618069642766, 12/2026, 389
VISA, 4929084109256572, 7/2024, 612
VISA, 4539625719273613, 3/2023, 480
VISA, 4114917233588557, 4/2027, 168
VISA, 4485603151004584, 7/2029, 948
VISA, 4024007186963137, 6/2029, 851
VISA, 4532814962965771, 6/2029, 200
VISA, 4539057462755028, 3/2028, 497
VISA, 4539525104418940, 7/2028, 297
VISA, 4024007110217774, 11/2030, 834
VISA, 4716822993656648, 5/2027, 501
VISA, 4929710624081919, 10/2026, 476
VISA, 4485629234919860, 7/2024, 606
VISA, 4929747699427742, 10/2028, 455
VISA, 4485527005877244, 3/2026, 428
VISA, 4485653383131309, 5/2024, 113
VISA, 4929024678349143, 9/2026, 251
VISA, 4916200663036144, 4/2023, 830
VISA, 4539456079209793, 8/2024, 254
VISA, 4916873802076641, 11/2026, 293
VISA, 4380975924136539, 9/2024, 321
VISA, 4696130499141865, 1/2025, 363
VISA, 4716457932863524, 8/2029, 765
VISA, 4532756287520734, 11/2025, 852
VISA, 4916527870620819, 7/2026, 907
VISA, 4793993233589190, 6/2028, 612
VISA, 4539756518688584, 5/2029, 963
VISA, 4024007100837581, 3/2029, 708
VISA, 4929589608839959, 9/2023, 652
VISA, 4212739323137561, 11/2029, 476
VISA, 4532614050967501, 3/2023, 914
VISA, 4024007141284124, 5/2026, 389
VISA, 4539772921551251, 11/2025, 618
VISA, 4539450037070926, 8/2027, 948
VISA, 4916814132386979, 5/2024, 593
VISA, 4539185905840451, 12/2029, 292
VISA, 4532671500927097, 8/2023, 385
VISA, 4916296276573424, 2/2030, 595
VISA, 4539929964730669, 2/2028, 608
VISA, 4916927793505487, 5/2029, 241
VISA, 4532046660465495, 2/2029, 956
VISA, 4347329383965909, 10/2028, 519
VISA, 4716115891775226, 3/2027, 546
VISA, 4532137397420372, 2/2024, 187
VISA, 4820824902294423, 8/2030, 942
VISA, 4916094483568000, 4/2023, 452
VISA, 4539421464241934, 10/2030, 600
VISA, 4929689135996049, 7/2024, 774
VISA, 4929847240492292, 3/2026, 295
VISA, 4556311843829186, 11/2024, 945
VISA, 4539781087867344, 5/2025, 971
VISA, 4916484095195682, 5/2029, 284
VISA, 4556503141065253, 8/2029, 272
VISA, 4024007143396546, 6/2026, 203
VISA, 4929721498547653, 7/2025, 599
VISA, 4916942096298268, 6/2024, 682
VISA, 4539718043028173, 8/2024, 441
VISA, 4532334274894171, 3/2026, 148
VISA, 4916116415203198, 9/2023, 942
VISA, 4024007188842941, 4/2028, 755
VISA, 4716859507682660, 5/2029, 424
N/A
stolen-passport.png
N/A
Metadata
┌──(kali㉿kali)-[~/archive/thm/hacksmartersecurity]
└─$ file stolen-passport.png
stolen-passport.png: PNG image data, 807 x 557, 8-bit/color RGBA, non-interlaced
┌──(kali㉿kali)-[~/archive/thm/hacksmartersecurity]
└─$ exiftool -a stolen-passport.png
ExifTool Version Number : 13.25
File Name : stolen-passport.png
Directory : .
File Size : 1022 kB
File Modification Date/Time : 2023:06:28 17:00:22+02:00
File Access Date/Time : 2025:07:05 16:15:21+02:00
File Inode Change Date/Time : 2025:07:05 16:15:21+02:00
File Permissions : -rw-rw-r--
File Type : PNG
File Type Extension : png
MIME Type : image/png
Image Width : 807
Image Height : 557
Bit Depth : 8
Color Type : RGB with Alpha
Compression : Deflate/Inflate
Filter : Adaptive
Interlace : Noninterlaced
Pixels Per Unit X : 3780
Pixels Per Unit Y : 3780
Pixel Units : meters
Modify Date : 2023:06:28 20:00:22
Image Size : 807x557
Megapixels : 0.449
N/A