FEAT:๐ฉ HTB S10ใSilentiumใEasy
Medium, Linux
FEAT:๐ฉ HTB S10ใSilentiumใEasy
ใใฎใใทใณใฏ
2026/04/12็พๅจใขใฏใใฃใใงใ๏ผ่งฃๆณใฎๅ ฑๆใฏ็ฆๆญขใใใฆใใพใ๏ผ
Reconnaissance & Initial Enumeration
staging ใจใใ VHOST ใ็บ่ฆใใพใใ๏ผ 80: nginx ใซใฏ๏ผ่ฆๅถๅฏพๅฟๅใฎๆฉ้ขๆ่ณๅใใใฉใใใใฉใผใ ใๅไฝใใฆใใพใ๏ผใพใ๏ผInstitutional Leadership. ใฎ้
็ฎใซใฏ Marcus Thorne, Ben, Elena Rossi ใจใใๅ่ฒฌไปป่
ใฎๅๅใ่จ่ผใใใฆใใพใ๏ผ
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
$ echo '10.129.196.179 silentium.htb' | sudo tee -a /etc/hosts
10.129.196.179 silentium.htb
$ nmap silentium.htb -p- -sV --min-rate 1000
Starting Nmap 7.99 ( https://nmap.org ) at 2026-04-12 13:01 +0900
Nmap scan report for silentium.htb (10.129.196.179)
Host is up (0.13s latency).
Not shown: 65533 closed tcp ports (conn-refused)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 9.6p1 Ubuntu 3ubuntu13.15 (Ubuntu Linux; protocol 2.0)
80/tcp open http nginx 1.24.0 (Ubuntu)
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 72.10 seconds
$ ffuf -u http://silentium.htb -H "Host: FUZZ.silentium.htb" -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-20000.txt -fs 178 -t 200
v2.1.0-dev
________________________________________________
:: Method : GET
:: URL : http://silentium.htb
:: Wordlist : FUZZ: /usr/share/seclists/Discovery/DNS/subdomains-top1million-20000.txt
:: Header : Host: FUZZ.silentium.htb
:: Follow redirects : false
:: Calibration : false
:: Timeout : 10
:: Threads : 200
:: Matcher : Response status: 200-299,301,302,307,401,403,405,500
:: Filter : Response size: 178
________________________________________________
staging [Status: 200, Size: 3142, Words: 789, Lines: 70, Duration: 155ms]
:: Progress: [20000/20000] :: Job [1/1] :: 1503 req/sec :: Duration: [0:00:13] :: Errors: 0 ::
$ feroxbuster -u http://silentium.htb -w /usr/share/seclists/Discovery/Web-Content/common.txt -C 404,400 -t 50
by Ben "epi" Risher ๐ค ver: 2.13.1
โโโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโ
๐ฏ Target Url โ http://silentium.htb/
๐ฉ In-Scope Url โ silentium.htb
๐ Threads โ 50
๐ Wordlist โ /usr/share/seclists/Discovery/Web-Content/common.txt
๐ข Status Code Filters โ [404, 400]
๐ฅ Timeout (secs) โ 7
๐ฆก User-Agent โ feroxbuster/2.13.1
๐ Extract Links โ true
๐ HTTP methods โ [GET]
๐ Recursion Depth โ 4
โโโโโโโโโโโโโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโ
๐ Press [ENTER] to use the Scan Management Menuโข
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
200 GET 251l 725w 8753c Auto-filtering found 404-like response and created new filter; toggle off with --dont-filter
301 GET 7l 12w 178c http://silentium.htb/assets => http://silentium.htb/assets/
[####################] - 44s 52272/52272 0s found:1 errors:0
[####################] - 28s 4752/4752 168/s http://silentium.htb/
[####################] - 27s 4752/4752 178/s http://silentium.htb/.git/logs/
[####################] - 30s 4752/4752 161/s http://silentium.htb/assets/
[####################] - 30s 4752/4752 160/s http://silentium.htb/assets/.git/logs/
[####################] - 31s 4752/4752 154/s http://silentium.htb/.git/logs/cgi-bin/
[####################] - 29s 4752/4752 162/s http://silentium.htb/cgi-bin/
[####################] - 29s 4752/4752 163/s http://silentium.htb/cgi-bin/.git/logs/
[####################] - 29s 4752/4752 164/s http://silentium.htb/assets/cgi-bin/
[####################] - 28s 4752/4752 171/s http://silentium.htb/cgi-bin/cgi-bin/
[####################] - 26s 4752/4752 184/s http://silentium.htb/assets/cgi-bin/cgi-bin/
[####################] - 25s 4752/4752 194/s http://silentium.htb/cgi-bin/cgi-bin/cgi-bin/
This post is licensed under CC BY 4.0 by the author.
