# HTB-Era
3 min read
I start off with directory enumeration and vhost fuzzing:
I start off with directory enumeration and vhost fuzzing:
When trying to log in using the provided ldap creds we get the following message:
I checked the site out but found nothing useful.
I started off by mounting the nfs share.
Since we already got valid creds I decided to use nxc to spray the credentials
We notice 2 python webservers running as well as a ssh port.