Lab Guide

LAB WiFi Hacking Scope

Below are the nmap results for the hosts in scope for this meetup.

Please do not attack any hosts that are not mentioned in this list.

The Subnet is 10.10.10.0/24

Feel free to hack the WIFI or ask the host for the password

Hosts in Scope

10.10.10.42
10.10.10.43
10.10.10.46
10.10.10.50
10.10.10.51
10.10.10.52
10.10.10.53
10.10.10.54
10.10.10.55
10.10.10.56
10.10.10.57
10.10.10.58
10.10.10.59
10.10.10.62
10.10.10.63
10.10.10.64
10.10.10.65
10.10.10.66
10.10.10.67
10.10.10.68
10.10.10.69
10.10.10.70
10.10.10.71
10.10.10.72
10.10.10.73
10.10.10.74
10.10.10.75
10.10.10.76
10.10.10.77
10.10.10.78
10.10.10.79
10.10.10.80
10.10.10.81
10.10.10.82
10.10.10.83
10.10.10.84

Windows Domain

For a getting started guide please visit the following link and follow along, note the change of IP addresses

https://mayfly277.github.io/posts/GOADv2-pwning_part1

Windows Hosts

There are numerous Windows hosts in this network, scan the network for relevant services.

Nmap of Network

Anything not on this list is out of scope.

Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-11-28 17:53 GMT

Nmap scan report for 10.10.10.40
Host is up (0.00018s latency).
Not shown: 65533 closed tcp ports (reset)
PORT      STATE SERVICE
22/tcp    open  ssh
22000/tcp open  snapenetio
MAC Address: 54:05:DB:FF:BF:B6 (LCFC(HeFei) Electronics Technology)

Nmap scan report for 10.10.10.42
Host is up (0.00015s latency).
Not shown: 59317 closed tcp ports (reset), 6202 filtered tcp ports (no-response)
Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
PORT      STATE SERVICE
135/tcp   open  msrpc
139/tcp   open  netbios-ssn
445/tcp   open  microsoft-ds
1688/tcp  open  nsjtp-data
3389/tcp  open  ms-wbt-server
5040/tcp  open  unknown
5800/tcp  open  vnc-http
5900/tcp  open  vnc
7680/tcp  open  pando-pub
49664/tcp open  unknown
49665/tcp open  unknown
49666/tcp open  unknown
49667/tcp open  unknown
49672/tcp open  unknown
49677/tcp open  unknown
49680/tcp open  unknown
MAC Address: 08:00:27:0D:B8:88 (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.43
Host is up (0.00036s latency).
Not shown: 65530 closed tcp ports (reset)
PORT      STATE SERVICE
22/tcp    open  ssh
1521/tcp  open  oracle
8080/tcp  open  http-proxy
8081/tcp  open  blackice-icecap
29632/tcp open  unknown
MAC Address: 08:00:27:F4:43:52 (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.46
Host is up (0.000078s latency).
Not shown: 65519 closed tcp ports (reset)
PORT      STATE SERVICE
135/tcp   open  msrpc
139/tcp   open  netbios-ssn
445/tcp   open  microsoft-ds
1688/tcp  open  nsjtp-data
3389/tcp  open  ms-wbt-server
5040/tcp  open  unknown
5800/tcp  open  vnc-http
5900/tcp  open  vnc
7680/tcp  open  pando-pub
49664/tcp open  unknown
49665/tcp open  unknown
49666/tcp open  unknown
49667/tcp open  unknown
49669/tcp open  unknown
49670/tcp open  unknown
49673/tcp open  unknown
MAC Address: 08:00:27:E3:65:43 (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.50
Host is up (0.000099s latency).
Not shown: 65519 closed tcp ports (reset)
PORT      STATE SERVICE
80/tcp    open  http
135/tcp   open  msrpc
139/tcp   open  netbios-ssn
445/tcp   open  microsoft-ds
1688/tcp  open  nsjtp-data
3389/tcp  open  ms-wbt-server
7680/tcp  open  pando-pub
8080/tcp  open  http-proxy
47001/tcp open  winrm
49664/tcp open  unknown
49665/tcp open  unknown
49666/tcp open  unknown
49667/tcp open  unknown
49668/tcp open  unknown
49670/tcp open  unknown
49671/tcp open  unknown
MAC Address: 08:00:27:F1:FC:43 (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.51
Host is up (0.00019s latency).
Not shown: 65533 filtered tcp ports (no-response)
Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
PORT     STATE SERVICE
5800/tcp open  vnc-http
5900/tcp open  vnc
MAC Address: 08:00:27:6F:36:6C (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.52
Host is up (0.00013s latency).
Not shown: 65532 filtered tcp ports (no-response), 1 closed tcp port (reset)
Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
PORT    STATE SERVICE
80/tcp  open  http
443/tcp open  https
MAC Address: 08:00:27:7D:F6:C5 (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.53
Host is up (0.00011s latency).
Not shown: 65532 closed tcp ports (reset)
PORT    STATE SERVICE
22/tcp  open  ssh
80/tcp  open  http
443/tcp open  https
MAC Address: 08:00:27:C0:61:A5 (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.54
Host is up (0.00014s latency).
Not shown: 65519 filtered tcp ports (no-response)
Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
PORT      STATE SERVICE
22/tcp    open  ssh
3000/tcp  open  ppp
3389/tcp  open  ms-wbt-server
4848/tcp  open  appserv-http
5985/tcp  open  wsman
8020/tcp  open  intu-ec-svcdisc
8022/tcp  open  oa-system
8027/tcp  open  papachi-p2p-srv
8080/tcp  open  http-proxy
8282/tcp  open  libelle
8383/tcp  open  m2mservices
8484/tcp  open  unknown
8585/tcp  open  unknown
9200/tcp  open  wap-wsp
49153/tcp open  unknown
49154/tcp open  unknown
MAC Address: 08:00:27:21:68:B4 (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.55
Host is up (0.000085s latency).
Not shown: 65517 closed tcp ports (reset)
PORT      STATE SERVICE
80/tcp    open  http
135/tcp   open  msrpc
139/tcp   open  netbios-ssn
445/tcp   open  microsoft-ds
1433/tcp  open  ms-sql-s
3389/tcp  open  ms-wbt-server
5985/tcp  open  wsman
5986/tcp  open  wsmans
47001/tcp open  winrm
49664/tcp open  unknown
49665/tcp open  unknown
49666/tcp open  unknown
49667/tcp open  unknown
49668/tcp open  unknown
49669/tcp open  unknown
49670/tcp open  unknown
49675/tcp open  unknown
49779/tcp open  unknown
MAC Address: 08:00:27:CF:17:EE (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.56
Host is up (0.000072s latency).
Not shown: 65516 closed tcp ports (reset)
PORT      STATE SERVICE
80/tcp    open  http
135/tcp   open  msrpc
139/tcp   open  netbios-ssn
445/tcp   open  microsoft-ds
1433/tcp  open  ms-sql-s
3389/tcp  open  ms-wbt-server
5985/tcp  open  wsman
5986/tcp  open  wsmans
47001/tcp open  winrm
49664/tcp open  unknown
49665/tcp open  unknown
49666/tcp open  unknown
49667/tcp open  unknown
49668/tcp open  unknown
49669/tcp open  unknown
49673/tcp open  unknown
49675/tcp open  unknown
49677/tcp open  unknown
63380/tcp open  unknown
MAC Address: 08:00:27:D7:5C:89 (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.57
Host is up (0.000099s latency).
Not shown: 65508 closed tcp ports (reset)
PORT      STATE SERVICE
53/tcp    open  domain
88/tcp    open  kerberos-sec
135/tcp   open  msrpc
139/tcp   open  netbios-ssn
389/tcp   open  ldap
445/tcp   open  microsoft-ds
464/tcp   open  kpasswd5
593/tcp   open  http-rpc-epmap
636/tcp   open  ldapssl
3268/tcp  open  globalcatLDAP
3269/tcp  open  globalcatLDAPssl
3389/tcp  open  ms-wbt-server
5985/tcp  open  wsman
5986/tcp  open  wsmans
9389/tcp  open  adws
47001/tcp open  winrm
49664/tcp open  unknown
49665/tcp open  unknown
49666/tcp open  unknown
49667/tcp open  unknown
49669/tcp open  unknown
49671/tcp open  unknown
49672/tcp open  unknown
49674/tcp open  unknown
49681/tcp open  unknown
49691/tcp open  unknown
49698/tcp open  unknown
MAC Address: 08:00:27:33:0C:97 (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.58
Host is up (0.000087s latency).
Not shown: 65506 closed tcp ports (reset)
PORT      STATE SERVICE
80/tcp    open  http
88/tcp    open  kerberos-sec
135/tcp   open  msrpc
139/tcp   open  netbios-ssn
389/tcp   open  ldap
445/tcp   open  microsoft-ds
464/tcp   open  kpasswd5
593/tcp   open  http-rpc-epmap
636/tcp   open  ldapssl
3268/tcp  open  globalcatLDAP
3269/tcp  open  globalcatLDAPssl
3389/tcp  open  ms-wbt-server
5357/tcp  open  wsdapi
5985/tcp  open  wsman
5986/tcp  open  wsmans
9389/tcp  open  adws
47001/tcp open  winrm
49664/tcp open  unknown
49665/tcp open  unknown
49666/tcp open  unknown
49668/tcp open  unknown
49669/tcp open  unknown
49670/tcp open  unknown
49671/tcp open  unknown
49673/tcp open  unknown
49676/tcp open  unknown
49686/tcp open  unknown
49692/tcp open  unknown
49730/tcp open  unknown
MAC Address: 08:00:27:91:51:0B (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.59
Host is up (0.000090s latency).
Not shown: 65508 closed tcp ports (reset)
PORT      STATE SERVICE
88/tcp    open  kerberos-sec
135/tcp   open  msrpc
139/tcp   open  netbios-ssn
389/tcp   open  ldap
445/tcp   open  microsoft-ds
464/tcp   open  kpasswd5
593/tcp   open  http-rpc-epmap
636/tcp   open  ldapssl
3268/tcp  open  globalcatLDAP
3269/tcp  open  globalcatLDAPssl
3389/tcp  open  ms-wbt-server
5357/tcp  open  wsdapi
5985/tcp  open  wsman
5986/tcp  open  wsmans
9389/tcp  open  adws
47001/tcp open  winrm
49664/tcp open  unknown
49665/tcp open  unknown
49666/tcp open  unknown
49667/tcp open  unknown
49669/tcp open  unknown
49670/tcp open  unknown
49671/tcp open  unknown
49673/tcp open  unknown
49676/tcp open  unknown
49706/tcp open  unknown
49758/tcp open  unknown
MAC Address: 08:00:27:EA:E7:AD (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.62
Host is up (0.00028s latency).
Not shown: 65533 closed tcp ports (reset)
PORT   STATE SERVICE
22/tcp open  ssh
80/tcp open  http
MAC Address: 08:00:27:1C:31:EC (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.63
Host is up (0.00031s latency).
Not shown: 65533 closed tcp ports (reset)
PORT   STATE SERVICE
22/tcp open  ssh
80/tcp open  http
MAC Address: 08:00:27:DA:47:AF (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.64
Host is up (0.00029s latency).
Not shown: 65532 closed tcp ports (reset)
PORT   STATE SERVICE
21/tcp open  ftp
22/tcp open  ssh
80/tcp open  http
MAC Address: 08:00:27:5E:E5:B1 (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.65
Host is up (0.00039s latency).
Not shown: 65530 closed tcp ports (reset)
PORT     STATE SERVICE
21/tcp   open  ftp
22/tcp   open  ssh
80/tcp   open  http
2222/tcp open  EtherNetIP-1
9898/tcp open  monkeycom
MAC Address: 08:00:27:C8:25:04 (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.66
Host is up (0.00027s latency).
Not shown: 65533 closed tcp ports (reset)
PORT     STATE SERVICE
80/tcp   open  http
3042/tcp open  journee
MAC Address: 08:00:27:04:BE:4C (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.67
Host is up (0.00026s latency).
Not shown: 65533 closed tcp ports (reset)
PORT   STATE SERVICE
22/tcp open  ssh
80/tcp open  http
MAC Address: 08:00:27:3E:51:E3 (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.68
Host is up (0.00032s latency).
Not shown: 65533 closed tcp ports (reset)
PORT   STATE SERVICE
22/tcp open  ssh
80/tcp open  http
MAC Address: 08:00:27:7B:E7:EE (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.69
Host is up (0.00021s latency).
Not shown: 65532 closed tcp ports (reset)
PORT      STATE SERVICE
80/tcp    open  http
111/tcp   open  rpcbind
54067/tcp open  unknown
MAC Address: 08:00:27:69:53:8A (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.70
Host is up (0.00022s latency).
Not shown: 65530 closed tcp ports (reset)
PORT    STATE SERVICE
22/tcp  open  ssh
25/tcp  open  smtp
80/tcp  open  http
110/tcp open  pop3
143/tcp open  imap
MAC Address: 08:00:27:90:50:50 (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.71
Host is up (0.00024s latency).
Not shown: 65533 closed tcp ports (reset)
PORT   STATE SERVICE
22/tcp open  ssh
80/tcp open  http
MAC Address: 08:00:27:90:80:13 (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.72
Host is up (0.00025s latency).
Not shown: 65533 closed tcp ports (reset)
PORT   STATE SERVICE
22/tcp open  ssh
80/tcp open  http
MAC Address: 08:00:27:29:B7:29 (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.73
Host is up (0.00032s latency).
Not shown: 65533 closed tcp ports (reset)
PORT     STATE SERVICE
80/tcp   open  http
1080/tcp open  socks
MAC Address: 08:00:27:25:4A:EB (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.74
Host is up (0.00025s latency).
Not shown: 65533 closed tcp ports (reset)
PORT   STATE SERVICE
22/tcp open  ssh
80/tcp open  http
MAC Address: 08:00:27:5C:7E:FD (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.75
Host is up (0.00023s latency).
Not shown: 65533 closed tcp ports (reset)
PORT   STATE SERVICE
22/tcp open  ssh
80/tcp open  http
MAC Address: 08:00:27:F0:77:88 (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.76
Host is up (0.00024s latency).
Not shown: 65532 closed tcp ports (reset)
PORT   STATE SERVICE
21/tcp open  ftp
22/tcp open  ssh
80/tcp open  http
MAC Address: 08:00:27:12:4A:F3 (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.77
Host is up (0.00032s latency).
Not shown: 65241 filtered tcp ports (no-response), 291 filtered tcp ports (admin-prohibited)
Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
PORT    STATE SERVICE
22/tcp  open  ssh
80/tcp  open  http
443/tcp open  https
MAC Address: 08:00:27:D8:70:2C (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.78
Host is up (0.00023s latency).
Not shown: 65532 closed tcp ports (reset)
PORT   STATE SERVICE
21/tcp open  ftp
22/tcp open  ssh
80/tcp open  http
MAC Address: 08:00:27:50:E2:D9 (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.79
Host is up (0.00030s latency).
Not shown: 65527 filtered tcp ports (no-response), 5 closed tcp ports (reset)
Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
PORT   STATE SERVICE
21/tcp open  ftp
22/tcp open  ssh
80/tcp open  http
MAC Address: 08:00:27:5D:64:A6 (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.80
Host is up (0.00022s latency).
Not shown: 65533 closed tcp ports (reset)
PORT   STATE SERVICE
22/tcp open  ssh
80/tcp open  http
MAC Address: 08:00:27:ED:51:50 (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.81
Host is up (0.00024s latency).
Not shown: 65532 closed tcp ports (reset)
PORT     STATE SERVICE
22/tcp   open  ssh
80/tcp   open  http
8000/tcp open  http-alt
MAC Address: 08:00:27:42:D4:D0 (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.82
Host is up (0.00031s latency).
Not shown: 65533 closed tcp ports (reset)
PORT   STATE SERVICE
22/tcp open  ssh
80/tcp open  http
MAC Address: 08:00:27:93:F8:D5 (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.83
Host is up (0.00030s latency).
Not shown: 65532 closed tcp ports (reset)
PORT     STATE SERVICE
22/tcp   open  ssh
80/tcp   open  http
8080/tcp open  http-proxy
MAC Address: 08:00:27:FD:0E:8E (Oracle VirtualBox virtual NIC)

Nmap scan report for 10.10.10.84
Host is up (0.00035s latency).
Not shown: 65532 closed tcp ports (reset)
PORT     STATE SERVICE
53/tcp   open  domain
80/tcp   open  http
9999/tcp open  abyss
MAC Address: 08:00:27:46:B1:D5 (Oracle VirtualBox virtual NIC)

Nmap done: 256 IP addresses (40 hosts up) scanned in 444.13 seconds