Post

FEAT:๐Ÿšฉ HTB S10ใ€ŒSilentiumใ€Easy

Medium, Linux

FEAT:๐Ÿšฉ HTB S10ใ€ŒSilentiumใ€Easy

ใ“ใฎใƒžใ‚ทใƒณใฏ 2026/04/12 ็พๅœจใ‚ขใ‚ฏใƒ†ใ‚ฃใƒ–ใงใ™๏ผŽ่งฃๆณ•ใฎๅ…ฑๆœ‰ใฏ็ฆๆญขใ•ใ‚Œใฆใ„ใพใ™๏ผŽ

Reconnaissance & Initial Enumeration

staging ใจใ„ใ† VHOST ใ‚’็™บ่ฆ‹ใ—ใพใ—ใŸ๏ผŽ 80: nginx ใซใฏ๏ผŒ่ฆๅˆถๅฏพๅฟœๅž‹ใฎๆฉŸ้–ขๆŠ•่ณ‡ๅ‘ใ‘ใƒ—ใƒฉใƒƒใƒˆใƒ•ใ‚ฉใƒผใƒ  ใŒๅ‹•ไฝœใ—ใฆใ„ใพใ™๏ผŒใพใŸ๏ผŒInstitutional Leadership. ใฎ้ …็›ฎใซใฏ Marcus Thorne, Ben, Elena Rossi ใจใ„ใ†ๅ„่ฒฌไปป่€…ใฎๅๅ‰ใŒ่จ˜่ผ‰ใ•ใ‚Œใฆใ„ใพใ™๏ผŽ

silentium-01

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
$ echo '10.129.196.179 silentium.htb' | sudo tee -a /etc/hosts
10.129.196.179 silentium.htb

$ nmap silentium.htb -p- -sV --min-rate 1000                 
Starting Nmap 7.99 ( https://nmap.org ) at 2026-04-12 13:01 +0900
Nmap scan report for silentium.htb (10.129.196.179)
Host is up (0.13s latency).
Not shown: 65533 closed tcp ports (conn-refused)
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 9.6p1 Ubuntu 3ubuntu13.15 (Ubuntu Linux; protocol 2.0)
80/tcp open  http    nginx 1.24.0 (Ubuntu)
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 72.10 seconds


$ ffuf -u http://silentium.htb -H "Host: FUZZ.silentium.htb" -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-20000.txt -fs 178 -t 200
       v2.1.0-dev
________________________________________________

 :: Method           : GET
 :: URL              : http://silentium.htb
 :: Wordlist         : FUZZ: /usr/share/seclists/Discovery/DNS/subdomains-top1million-20000.txt
 :: Header           : Host: FUZZ.silentium.htb
 :: Follow redirects : false
 :: Calibration      : false
 :: Timeout          : 10
 :: Threads          : 200
 :: Matcher          : Response status: 200-299,301,302,307,401,403,405,500
 :: Filter           : Response size: 178
________________________________________________

staging                 [Status: 200, Size: 3142, Words: 789, Lines: 70, Duration: 155ms]
:: Progress: [20000/20000] :: Job [1/1] :: 1503 req/sec :: Duration: [0:00:13] :: Errors: 0 ::


$ feroxbuster -u http://silentium.htb -w /usr/share/seclists/Discovery/Web-Content/common.txt -C 404,400 -t 50 
by Ben "epi" Risher ๐Ÿค“                 ver: 2.13.1
โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
 ๐ŸŽฏ  Target Url            โ”‚ http://silentium.htb/
 ๐Ÿšฉ  In-Scope Url          โ”‚ silentium.htb
 ๐Ÿš€  Threads               โ”‚ 50
 ๐Ÿ“–  Wordlist              โ”‚ /usr/share/seclists/Discovery/Web-Content/common.txt
 ๐Ÿ’ข  Status Code Filters   โ”‚ [404, 400]
 ๐Ÿ’ฅ  Timeout (secs)        โ”‚ 7
 ๐Ÿฆก  User-Agent            โ”‚ feroxbuster/2.13.1
 ๐Ÿ”Ž  Extract Links         โ”‚ true
 ๐Ÿ  HTTP methods          โ”‚ [GET]
 ๐Ÿ”ƒ  Recursion Depth       โ”‚ 4
โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
 ๐Ÿ  Press [ENTER] to use the Scan Management Menuโ„ข
โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
200      GET      251l      725w     8753c Auto-filtering found 404-like response and created new filter; toggle off with --dont-filter
301      GET        7l       12w      178c http://silentium.htb/assets => http://silentium.htb/assets/
[####################] - 44s    52272/52272   0s      found:1       errors:0      
[####################] - 28s     4752/4752    168/s   http://silentium.htb/ 
[####################] - 27s     4752/4752    178/s   http://silentium.htb/.git/logs/ 
[####################] - 30s     4752/4752    161/s   http://silentium.htb/assets/ 
[####################] - 30s     4752/4752    160/s   http://silentium.htb/assets/.git/logs/ 
[####################] - 31s     4752/4752    154/s   http://silentium.htb/.git/logs/cgi-bin/ 
[####################] - 29s     4752/4752    162/s   http://silentium.htb/cgi-bin/ 
[####################] - 29s     4752/4752    163/s   http://silentium.htb/cgi-bin/.git/logs/ 
[####################] - 29s     4752/4752    164/s   http://silentium.htb/assets/cgi-bin/ 
[####################] - 28s     4752/4752    171/s   http://silentium.htb/cgi-bin/cgi-bin/ 
[####################] - 26s     4752/4752    184/s   http://silentium.htb/assets/cgi-bin/cgi-bin/ 
[####################] - 25s     4752/4752    194/s   http://silentium.htb/cgi-bin/cgi-bin/cgi-bin/
This post is licensed under CC BY 4.0 by the author.