You’ll find this vm in Vulnhub https://www.vulnhub.com/entry/neobank-1,642/
Also to HackMyVm https://hackmyvm.eu/machines/machine.php?vm=Neobank
Youtube Video
Directory Scan
1 |
|
Retreive emails
- Under the
/email_list
you can retrieve the emails
1 |
|
Brute force
- Creating the
pins
wordlist usingrockyou.txt
1 |
|
- bruteforce script
- Run it
1
2
3
4┌──(alienum㉿kali)-[~] └─$ python3 neobank-bf.py [+] Username : zeus@neobank.vln [+] Password : 2*****
OTP google authenticator
- Scan the qrcode and insert the otp code
Exploit eval() python function
1 |
|
MySQL enumeration find banker credentials
GTFObins
- sudo -l
- This vm created by me, i enjoyed the process