STARTING POINT - TIER 0 - Fawn
一、题目
TASK 1
What does the 3-letter acronym FTP stand for?
3个字母缩写的FTP代表什么?
答案:File Transfer Protocol
TASK 2
Which port does the FTP service listen on usually?
FTP服务通常在哪个端口上监听?
答案:21
TASK 3
What acronym is used for the secure version of FTP?
什么首字母缩写用于安全版本的FTP?
答案:SFTP
TASK 4
What is the command we can use to send an ICMP echo request to test our connection to the target?
我们可以用什么命令来发送一个ICMP回波请求,以测试我们与目标的连接?
答案:ping
TASK 5
From your scans, what version is FTP running on the target?
根据你的扫描结果,目标上运行的FTP是什么版本?
答案:vsftpd 3.0.3
TASK 6
From your scans, what OS type is running on the target?
根据你的扫描结果,目标上运行的是什么操作系统类型?
答案:Unix
TASK 7
What is the command we need to run in order to display the 'ftp' client help menu?
为了显示 "ftp "客户端帮助菜单,我们需要运行的命令是什么?
答案:ftp -h
TASK 8
What is username that is used over FTP when you want to log in without having an account?
当你想在没有账户的情况下登录时,在FTP上使用的用户名是什么?
答案:anonymous
TASK 9
What is the response code we get for the FTP message 'Login successful'?
当FTP消息 "登录成功 "时,我们得到的响应代码是什么?
答案:230
TASK 10
There are a couple of commands we can use to list the files and directories available on the FTP server. One is dir. What is the other that is a common way to list files on a Linux system.
有几个命令我们可以用来列出FTP服务器上可用的文件和目录。一个是dir。另一个是什么,是Linux系统上列出文件的常用方法。
答案:ls
TASK 11
What is the command used to download the file we found on the FTP server?
用来下载我们在FTP服务器上找到的文件的命令是什么?
答案:get
二、过程
NMAP直接开扫
nmap -sV 10.129.194.110


FTP连接目标
ftp 10.129.194.110

获取flag.txt文件
get flag.txt



Learn the basics of Penetration Testing
浙公网安备 33010602011771号