# Nmap 7.93 scan initiated Sat Mar 1100:29:442023as: nmap -sC -sV -oN nmap/agile 10.10.11.203 Nmap scan report for agile.htb (10.10.11.203) Host is up (0.26s latency). Not shown: 998 closed tcp ports (reset) PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.1 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: |256 f4bcee21d71f1aa26572212d5ba6f700 (ECDSA) |_ 25665c1480d88cbb975a02ca5e6377e5106 (ED25519) 80/tcp open http nginx 1.18.0 (Ubuntu) |_http-title: Welcome to nginx! |_http-server-header: nginx/1.18.0 (Ubuntu) Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . # Nmap done at Sat Mar 1100:30:032023-- 1 IP address (1 host up) scanned in 19.67 seconds
Web
Opening the page redirect to superpass.htb
Playing around with the service lets register on the application
We find LFI on download endpoint
and based on error we can grab the source code of the application