instruction:
- Las Vegas is gearing up for a massive cybersecurity conference, and you've been hired to conduct a penetration test against one of the casinos. The client - Hack Smarter World - is a luxury resort where many of the attendees will be staying. Your objective is to identify all vulnerabilities and elevate your privileges to root (if possible).
Initial Access
You have been provided the IP of the Wifi Captive Portal (10.0.20.166) but no other information.
Recon:
nmap -sCV -vvv 10.0.20.166

nmap --script vuln -T4 10.0.20.166

- Here there is 3 noticeable ports 80,22,2222 so this mean there is website because of 80.
Note:-
- 80:(http) - running a flask app also has a login page.
- 22:(ssh)- there is remote login
- Server: Werkzeug/3.1.8 Python/3.10.18

Technologies
- Flask 3.1.8
- python 3.10.18