initial commit

This commit is contained in:
2025-12-04 09:57:17 +01:00
commit 0054cc02b1
4851 changed files with 4416257 additions and 0 deletions

134
AoC/2025/01/nmap_scan1.nmap Normal file
View File

@@ -0,0 +1,134 @@
# Nmap 7.95 scan initiated Tue Dec 2 14:08:01 2025 as: /usr/lib/nmap/nmap --privileged -T4 -A -oN nmap_scan1.nmap 10.82.181.57
Nmap scan report for 10.82.181.57
Host is up (0.042s latency).
Not shown: 995 closed tcp ports (reset)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 9.6p1 Ubuntu 3ubuntu13.14 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 256 65:f4:d5:24:cf:59:a0:20:a9:2f:62:6c:dd:f6:fe:73 (ECDSA)
|_ 256 9f:c3:56:51:fa:7a:f5:d5:1e:d0:b7:39:e9:71:26:a1 (ED25519)
80/tcp open http WebSockify Python/3.12.3
|_http-title: Error response
|_http-server-header: WebSockify Python/3.12.3
| fingerprint-strings:
| GetRequest:
| HTTP/1.1 405 Method Not Allowed
| Server: WebSockify Python/3.12.3
| Date: Tue, 02 Dec 2025 13:08:07 GMT
| Connection: close
| Content-Type: text/html;charset=utf-8
| Content-Length: 355
| <!DOCTYPE HTML>
| <html lang="en">
| <head>
| <meta charset="utf-8">
| <title>Error response</title>
| </head>
| <body>
| <h1>Error response</h1>
| <p>Error code: 405</p>
| <p>Message: Method Not Allowed.</p>
| <p>Error code explanation: 405 - Specified method is invalid for this resource.</p>
| </body>
| </html>
| HTTPOptions:
| HTTP/1.1 501 Unsupported method ('OPTIONS')
| Server: WebSockify Python/3.12.3
| Date: Tue, 02 Dec 2025 13:08:07 GMT
| Connection: close
| Content-Type: text/html;charset=utf-8
| Content-Length: 360
| <!DOCTYPE HTML>
| <html lang="en">
| <head>
| <meta charset="utf-8">
| <title>Error response</title>
| </head>
| <body>
| <h1>Error response</h1>
| <p>Error code: 501</p>
| <p>Message: Unsupported method ('OPTIONS').</p>
| <p>Error code explanation: 501 - Server does not support this operation.</p>
| </body>
| </html>
| RTSPRequest:
| <!DOCTYPE HTML>
| <html lang="en">
| <head>
| <meta charset="utf-8">
| <title>Error response</title>
| </head>
| <body>
| <h1>Error response</h1>
| <p>Error code: 400</p>
| <p>Message: Bad request version ('RTSP/1.0').</p>
| <p>Error code explanation: 400 - Bad request syntax or unsupported method.</p>
| </body>
|_ </html>
5901/tcp open vnc VNC (protocol 3.8)
| vnc-info:
| Protocol version: 3.8
| Security types:
| VeNCrypt (19)
| VNC Authentication (2)
| VeNCrypt auth subtypes:
| Unknown security type (2)
|_ VNC auth, Anonymous TLS (258)
8080/tcp open http SimpleHTTPServer 0.6 (Python 3.12.3)
|_http-title: Wareville\xE2\x80\x99s Christmas Countdown
|_http-server-header: SimpleHTTP/0.6 Python/3.12.3
8081/tcp open http Node.js Express framework
|_http-title: Wareville\xE2\x80\x99s Christmas Countdown
|_http-cors: GET
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
SF-Port80-TCP:V=7.95%I=7%D=12/2%Time=692EE4B6%P=aarch64-unknown-linux-gnu%
SF:r(GetRequest,21C,"HTTP/1\.1\x20405\x20Method\x20Not\x20Allowed\r\nServe
SF:r:\x20WebSockify\x20Python/3\.12\.3\r\nDate:\x20Tue,\x2002\x20Dec\x2020
SF:25\x2013:08:07\x20GMT\r\nConnection:\x20close\r\nContent-Type:\x20text/
SF:html;charset=utf-8\r\nContent-Length:\x20355\r\n\r\n<!DOCTYPE\x20HTML>\
SF:n<html\x20lang=\"en\">\n\x20\x20\x20\x20<head>\n\x20\x20\x20\x20\x20\x2
SF:0\x20\x20<meta\x20charset=\"utf-8\">\n\x20\x20\x20\x20\x20\x20\x20\x20<
SF:title>Error\x20response</title>\n\x20\x20\x20\x20</head>\n\x20\x20\x20\
SF:x20<body>\n\x20\x20\x20\x20\x20\x20\x20\x20<h1>Error\x20response</h1>\n
SF:\x20\x20\x20\x20\x20\x20\x20\x20<p>Error\x20code:\x20405</p>\n\x20\x20\
SF:x20\x20\x20\x20\x20\x20<p>Message:\x20Method\x20Not\x20Allowed\.</p>\n\
SF:x20\x20\x20\x20\x20\x20\x20\x20<p>Error\x20code\x20explanation:\x20405\
SF:x20-\x20Specified\x20method\x20is\x20invalid\x20for\x20this\x20resource
SF:\.</p>\n\x20\x20\x20\x20</body>\n</html>\n")%r(HTTPOptions,22D,"HTTP/1\
SF:.1\x20501\x20Unsupported\x20method\x20\('OPTIONS'\)\r\nServer:\x20WebSo
SF:ckify\x20Python/3\.12\.3\r\nDate:\x20Tue,\x2002\x20Dec\x202025\x2013:08
SF::07\x20GMT\r\nConnection:\x20close\r\nContent-Type:\x20text/html;charse
SF:t=utf-8\r\nContent-Length:\x20360\r\n\r\n<!DOCTYPE\x20HTML>\n<html\x20l
SF:ang=\"en\">\n\x20\x20\x20\x20<head>\n\x20\x20\x20\x20\x20\x20\x20\x20<m
SF:eta\x20charset=\"utf-8\">\n\x20\x20\x20\x20\x20\x20\x20\x20<title>Error
SF:\x20response</title>\n\x20\x20\x20\x20</head>\n\x20\x20\x20\x20<body>\n
SF:\x20\x20\x20\x20\x20\x20\x20\x20<h1>Error\x20response</h1>\n\x20\x20\x2
SF:0\x20\x20\x20\x20\x20<p>Error\x20code:\x20501</p>\n\x20\x20\x20\x20\x20
SF:\x20\x20\x20<p>Message:\x20Unsupported\x20method\x20\('OPTIONS'\)\.</p>
SF:\n\x20\x20\x20\x20\x20\x20\x20\x20<p>Error\x20code\x20explanation:\x205
SF:01\x20-\x20Server\x20does\x20not\x20support\x20this\x20operation\.</p>\
SF:n\x20\x20\x20\x20</body>\n</html>\n")%r(RTSPRequest,16C,"<!DOCTYPE\x20H
SF:TML>\n<html\x20lang=\"en\">\n\x20\x20\x20\x20<head>\n\x20\x20\x20\x20\x
SF:20\x20\x20\x20<meta\x20charset=\"utf-8\">\n\x20\x20\x20\x20\x20\x20\x20
SF:\x20<title>Error\x20response</title>\n\x20\x20\x20\x20</head>\n\x20\x20
SF:\x20\x20<body>\n\x20\x20\x20\x20\x20\x20\x20\x20<h1>Error\x20response</
SF:h1>\n\x20\x20\x20\x20\x20\x20\x20\x20<p>Error\x20code:\x20400</p>\n\x20
SF:\x20\x20\x20\x20\x20\x20\x20<p>Message:\x20Bad\x20request\x20version\x2
SF:0\('RTSP/1\.0'\)\.</p>\n\x20\x20\x20\x20\x20\x20\x20\x20<p>Error\x20cod
SF:e\x20explanation:\x20400\x20-\x20Bad\x20request\x20syntax\x20or\x20unsu
SF:pported\x20method\.</p>\n\x20\x20\x20\x20</body>\n</html>\n");
Device type: general purpose
Running: Linux 4.X
OS CPE: cpe:/o:linux:linux_kernel:4.15
OS details: Linux 4.15
Network Distance: 3 hops
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
TRACEROUTE (using port 1723/tcp)
HOP RTT ADDRESS
1 42.25 ms 192.168.128.1
2 ...
3 43.14 ms 10.82.181.57
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
# Nmap done at Tue Dec 2 14:09:47 2025 -- 1 IP address (1 host up) scanned in 105.84 seconds

File diff suppressed because it is too large Load Diff

View File

@@ -0,0 +1 @@
JfiF3O2shWWiyPxl1ElFkod0lJTQnKU8

View File

@@ -0,0 +1 @@
/cgi-bin  (Status: 301) [Size: 178] [--> http://10.80.138.114/cgi-bin/]

File diff suppressed because it is too large Load Diff

View File

@@ -0,0 +1,131 @@
# Nmap 7.95 scan initiated Wed Dec 3 12:50:40 2025 as: /usr/lib/nmap/nmap --privileged -T4 -A -oN nmap_scan.txt 10.80.178.179
Nmap scan report for 10.80.178.179
Host is up (0.042s latency).
Not shown: 995 closed tcp ports (reset)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 9.6p1 Ubuntu 3ubuntu13.11 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 256 88:83:8a:dc:57:aa:18:a5:f4:3b:72:30:77:bd:2b:67 (ECDSA)
|_ 256 54:89:e7:16:f7:b6:57:4e:94:3f:7f:3d:ba:62:ed:b2 (ED25519)
80/tcp open http nginx 1.24.0 (Ubuntu)
|_http-server-header: nginx/1.24.0 (Ubuntu)
|_http-title: HopSec Asylum - Security Console
8000/tcp open http-alt
| fingerprint-strings:
| FourOhFourRequest:
| HTTP/1.0 404 Not Found
| Content-Type: text/html
| X-Frame-Options: DENY
| Content-Length: 179
| Vary: Accept-Language
| Content-Language: en
| X-Content-Type-Options: nosniff
| <!doctype html>
| <html lang="en">
| <head>
| <title>Not Found</title>
| </head>
| <body>
| <h1>Not Found</h1><p>The requested resource was not found on this server.</p>
| </body>
| </html>
| GenericLines, Help, RTSPRequest, SIPOptions, Socks5, TerminalServerCookie:
| HTTP/1.1 400 Bad Request
| GetRequest, HTTPOptions:
| HTTP/1.0 302 Found
| Content-Type: text/html; charset=utf-8
| Location: /posts/
| X-Frame-Options: DENY
| Content-Length: 0
| Vary: Accept-Language
| Content-Language: en
|_ X-Content-Type-Options: nosniff
| http-title: Fakebook - Sign In
|_Requested resource was /accounts/login/?next=/posts/
8080/tcp open http SimpleHTTPServer 0.6 (Python 3.12.3)
|_http-server-header: SimpleHTTP/0.6 Python/3.12.3
9001/tcp open tor-orport?
| fingerprint-strings:
| NULL:
| ASYLUM GATE CONTROL SYSTEM - SCADA TERMINAL v2.1
| [AUTHORIZED PERSONNEL ONLY]
| WARNING: This system controls critical infrastructure
| access attempts are logged and monitored
| Unauthorized access will result in immediate termination
| Authentication required to access SCADA terminal
| Provide authorization token from Part 1 to proceed
|_ [AUTH] Enter authorization token:
2 services unrecognized despite returning data. If you know the service/version, please submit the following fingerprints at https://nmap.org/cgi-bin/submit.cgi?new-service :
==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)==============
SF-Port8000-TCP:V=7.95%I=7%D=12/3%Time=69302418%P=aarch64-unknown-linux-gn
SF:u%r(GenericLines,1C,"HTTP/1\.1\x20400\x20Bad\x20Request\r\n\r\n")%r(Get
SF:Request,C9,"HTTP/1\.0\x20302\x20Found\r\nContent-Type:\x20text/html;\x2
SF:0charset=utf-8\r\nLocation:\x20/posts/\r\nX-Frame-Options:\x20DENY\r\nC
SF:ontent-Length:\x200\r\nVary:\x20Accept-Language\r\nContent-Language:\x2
SF:0en\r\nX-Content-Type-Options:\x20nosniff\r\n\r\n")%r(FourOhFourRequest
SF:,160,"HTTP/1\.0\x20404\x20Not\x20Found\r\nContent-Type:\x20text/html\r\
SF:nX-Frame-Options:\x20DENY\r\nContent-Length:\x20179\r\nVary:\x20Accept-
SF:Language\r\nContent-Language:\x20en\r\nX-Content-Type-Options:\x20nosni
SF:ff\r\n\r\n\n<!doctype\x20html>\n<html\x20lang=\"en\">\n<head>\n\x20\x20
SF:<title>Not\x20Found</title>\n</head>\n<body>\n\x20\x20<h1>Not\x20Found<
SF:/h1><p>The\x20requested\x20resource\x20was\x20not\x20found\x20on\x20thi
SF:s\x20server\.</p>\n</body>\n</html>\n")%r(Socks5,1C,"HTTP/1\.1\x20400\x
SF:20Bad\x20Request\r\n\r\n")%r(HTTPOptions,C9,"HTTP/1\.0\x20302\x20Found\
SF:r\nContent-Type:\x20text/html;\x20charset=utf-8\r\nLocation:\x20/posts/
SF:\r\nX-Frame-Options:\x20DENY\r\nContent-Length:\x200\r\nVary:\x20Accept
SF:-Language\r\nContent-Language:\x20en\r\nX-Content-Type-Options:\x20nosn
SF:iff\r\n\r\n")%r(RTSPRequest,1C,"HTTP/1\.1\x20400\x20Bad\x20Request\r\n\
SF:r\n")%r(Help,1C,"HTTP/1\.1\x20400\x20Bad\x20Request\r\n\r\n")%r(Termina
SF:lServerCookie,1C,"HTTP/1\.1\x20400\x20Bad\x20Request\r\n\r\n")%r(SIPOpt
SF:ions,1C,"HTTP/1\.1\x20400\x20Bad\x20Request\r\n\r\n");
==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)==============
SF-Port9001-TCP:V=7.95%I=7%D=12/3%Time=69302418%P=aarch64-unknown-linux-gn
SF:u%r(NULL,34F,"\n\xe2\x95\x94\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x9
SF:5\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x
SF:95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\
SF:x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2
SF:\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe
SF:2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\x
SF:e2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\
SF:xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90
SF:\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x9
SF:0\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x
SF:90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\
SF:x90\xe2\x95\x97\n\xe2\x95\x91\x20\x20\x20\x20\x20ASYLUM\x20GATE\x20CONT
SF:ROL\x20SYSTEM\x20-\x20SCADA\x20TERMINAL\x20v2\.1\x20\x20\x20\x20\x20\x2
SF:0\x20\x20\x20\x20\xe2\x95\x91\n\xe2\x95\x91\x20\x20\x20\x20\x20\x20\x20
SF:\x20\x20\x20\x20\x20\x20\x20\[AUTHORIZED\x20PERSONNEL\x20ONLY\]\x20\x20
SF:\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x2
SF:0\x20\x20\xe2\x95\x91\n\xe2\x95\x9a\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90
SF:\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x9
SF:0\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x
SF:90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\
SF:x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95
SF:\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x9
SF:5\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x
SF:95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\
SF:x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2
SF:\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe
SF:2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\xe2\x95\x90\x
SF:e2\x95\x90\xe2\x95\x9d\n\n\[!\]\x20WARNING:\x20This\x20system\x20contro
SF:ls\x20critical\x20infrastructure\n\[!\]\x20All\x20access\x20attempts\x2
SF:0are\x20logged\x20and\x20monitored\n\[!\]\x20Unauthorized\x20access\x20
SF:will\x20result\x20in\x20immediate\x20termination\n\n\[!\]\x20Authentica
SF:tion\x20required\x20to\x20access\x20SCADA\x20terminal\n\[!\]\x20Provide
SF:\x20authorization\x20token\x20from\x20Part\x201\x20to\x20proceed\n\n\n\
SF:[AUTH\]\x20Enter\x20authorization\x20token:\x20");
Device type: general purpose
Running: Linux 4.X
OS CPE: cpe:/o:linux:linux_kernel:4.15
OS details: Linux 4.15
Network Distance: 3 hops
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
TRACEROUTE (using port 1025/tcp)
HOP RTT ADDRESS
1 40.99 ms 192.168.128.1
2 ...
3 41.87 ms 10.80.178.179
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
# Nmap done at Wed Dec 3 12:53:08 2025 -- 1 IP address (1 host up) scanned in 148.66 seconds

View File

File diff suppressed because it is too large Load Diff

View File

@@ -0,0 +1,302 @@
change
the
you
something
here
also
ajax
function
below
button
comments
Sir
post
Error
class
Send
ago
Post
Text
Reaction
Flags
King
Report
Likes
show
Dislikes
hide
btn
cmt
Guard
Hopkins
Carrotbane
Malhare
BreachBlocker
III
code
weeks
response
month
months
not
found
have
from
some
Hop
and
Link
given
matches
URI
Message
File
explanation
Nothing
Can
good
food
just
for
your
asylum
are
this
week
out
they
posts
Screen
home
ever
want
sponsor
sure
href
order
but
royal
know
any
This
was
wise
well
Custom
all
work
hopkins
DoorDasher
Johnnyboy
that
comment
can
profiles
year
item
bruteforcing
challenges
thm
see
opt
hashcat
utils
src
harder
much
itest
OVERSHARING
job
making
You
site
public
service
looked
Happiest
pic
announcement
profile
New
plans
EGG
BIG
cellency
NEW
CAPE
YES
Trying
december
hand
tuned
stay
Cooking
combinator
Space
world
What
Yep
born
anniversary
weak
links
HAHAHA
Happy
heard
control
locked
old
boss
Hopper
GOOD
ITS
WHERE
BELONGS
The
red
team
took
since
better
WAY
been
battalion
has
bin
AttackBox
Always
comes
handy
Did
enter
password
appears
Pizza
WHAT
dialogs
THE
HELL
CARROTBANE
NOW
NEED
CHANGE
PASSWORD
HAHA
seeing
modal
who
Advertisements
Sponsored
Advertisments
empty
Leave
adverstisements
bewtween
Publish
More
about
styling
forms
Read
discount
didn
latest
realised
paid
full
price
check
support
email
should
one
guard
hopsecasylum
com
decree
effectively
immediately
nor
forbidden
other
color
blue
important
Required
meta
tags
jQuery
css
semantic
Include
Icons
Fakebook
main
page
mit
Posts
Suchzeile
Search
Second
Friends
Page
Chat
invite
invites
Path
Profile
Logout
them
over
there
DAMN
make
hit
Not
why
could
say
LOVE
PIZZA
Taking
walk
best
friend
although
more
sorry
brag
people
please
love
Easter
Bunny
Hoppy
STOP
items
Wareville
HopSec
Island
reactionary
definitely
always
planned
events
which
relate
recently
purely
coincidence
That
will
Another
long
shift
done
couldn
hopped
cooking
ordered
wareville
doesn
like

View File

@@ -0,0 +1 @@
johnnyboy1982

View File

@@ -0,0 +1,40 @@
!'#''#'
!'#''#'
$'#''#'
$'#''#'
%'#''#'
%'#''#'
&'#''#'
&'#''#'
'#'!'#'
'#'!'#'
'#'$'#'
'#'$'#'
'#'%'#'
'#'%'#'
'#'&'#'
'#'&'#'
'#''#'
'#''#'
'#''#'!
'#''#'!
'#''#'$
'#''#'$
'#''#'%
'#''#'%
'#''#'&
'#''#'&
'#''#''#'
'#''#''#'
'#''#'*
'#''#'*
'#''#'@
'#''#'@
'#'*'#'
'#'*'#'
'#'@'#'
'#'@'#'
*'#''#'
*'#''#'
@'#''#'
@'#''#'

File diff suppressed because it is too large Load Diff

BIN
AoC/2025/01/sq1.png Normal file

Binary file not shown.

After

Width:  |  Height:  |  Size: 411 KiB