The exercise says: “Use the discovered username with its password to login via SSH and obtain the flag.txt file. Submit the contents as your answer.”
I have found the user (r…), and I tried to crack the FTP credentials using several wordlists, with no success. I even tried to crack SSH and SMB, no success.
I guess we’re talking about different servers. I am in the section “Attacking FTP”. The FTP port is 2…/tcp, and the FTP user is “r…”. The exercise question is “Use the discovered username with its password to login via SSH and obtain the flag.txt file. Submit the contents as your answer.”. And I cannot FTP into the machine as “anonymous”. Any idea?
Now, this machine is a bit sleaky. Spawn the target. Wait some minutes for the FTP service to start. You will find it on a non-standard port. Eventually, do the scan with -T 4 to slow it down. And you will find it. Let me know if you can go on.
Nmap totaly ignored this port… After your hint i spawned machine - 2121 CLOSED.
I tryied again and again and finally OPEN thanks ! Now hydra and i’m in home
Ok I’m having problems with this one. Find the ftp open port ok that’s no problem, so made some hydra with the user and password list resource from this module and for some reason hydra brought me the user jason and his password… not the one with r*** from this cap… So tried again and again and sometimes hydra didn’t find anything… so I’m going crazy right now haha… Maybe somebody help me with this one