From c42b50e6fd8e30ff31e84016dec1c85356bf455c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Simon=20H=C3=BCnecke?= <34032202+SpaceMoehre@users.noreply.github.com> Date: Fri, 1 Sep 2023 16:37:29 +0200 Subject: [PATCH] htb updates and ductf update --- DownUnderCTF 2023/.idea/.gitignore | 3 + DownUnderCTF 2023/.idea/DownUnderCTF 2023.iml | 8 +++ .../inspectionProfiles/profiles_settings.xml | 6 ++ DownUnderCTF 2023/.idea/misc.xml | 4 ++ DownUnderCTF 2023/.idea/modules.xml | 8 +++ DownUnderCTF 2023/.idea/vcs.xml | 6 ++ .../beginner/Welcome to DUCTF!/README.md | 13 ++++ .../welcome_to_ductf.aplusplus | 41 ++++++++++++ DownUnderCTF 2023/beginner/X/README.md | 17 +++++ DownUnderCTF 2023/beginner/proxed/README.md | 58 +++++++++++++++++ .../beginner/proxed/proxed/Dockerfile | 13 ++++ .../proxed/proxed/cmd/secret_server/main.go | 42 ++++++++++++ .../beginner/proxed/proxed/go.mod | 3 + .../beginner/static file server/README.md | 60 ++++++++++++++++++ .../static-file-server/Dockerfile | 13 ++++ .../static-file-server/app.py | 20 ++++++ .../static-file-server/files/ductf.png | Bin 0 -> 21312 bytes .../static-file-server/files/not_the_flag.txt | 1 + .../static-file-server/flag.txt | 1 + HTB/Keeper/README.md | 10 --- HTB/admirer/ferox-http_admirer_htb | 0 ...erox-http_admirer_htb:80_-1674285271.state | 1 - HTB/agile/ferox-http_agile_htb | 0 .../ferox-http_agile_htb:80_-1678019995.state | 1 - HTB/awkward/ferox-http_awkward_htb | 0 ...erox-http_awkward_htb:80_-1675808288.state | 1 - HTB/awkward/ferox-http_hat-valley_htb | 0 ...x-http_hat-valley_htb:80_-1675809555.state | 1 - HTB/mentor/ferox-http_mentor_htb | 0 ...ferox-http_mentor_htb:80_-1675786335.state | 1 - HTB/soccer/ferox-http_10_10_11_194 | 0 ...rox-http_10_10_11_194:80_-1674662797.state | 1 - HTB/stocker/ferox-http_10_10_11_196 | 0 ...rox-http_10_10_11_196:80_-1674572985.state | 1 - .../ferox-http_openwebanalytics_vessel_htb | 0 ...ebanalytics_vessel_htb:80-1676229429.state | 1 - HTB/vessel/ferox-http_vessel_htb | 0 .../ferox-http_vessel_htb:80-1676228307.state | 1 - 38 files changed, 317 insertions(+), 19 deletions(-) create mode 100644 DownUnderCTF 2023/.idea/.gitignore create mode 100644 DownUnderCTF 2023/.idea/DownUnderCTF 2023.iml create mode 100644 DownUnderCTF 2023/.idea/inspectionProfiles/profiles_settings.xml create mode 100644 DownUnderCTF 2023/.idea/misc.xml create mode 100644 DownUnderCTF 2023/.idea/modules.xml create mode 100644 DownUnderCTF 2023/.idea/vcs.xml create mode 100644 DownUnderCTF 2023/beginner/Welcome to DUCTF!/README.md create mode 100644 DownUnderCTF 2023/beginner/Welcome to DUCTF!/welcome_to_ductf.aplusplus create mode 100644 DownUnderCTF 2023/beginner/X/README.md create mode 100644 DownUnderCTF 2023/beginner/proxed/README.md create mode 100644 DownUnderCTF 2023/beginner/proxed/proxed/Dockerfile create mode 100644 DownUnderCTF 2023/beginner/proxed/proxed/cmd/secret_server/main.go create mode 100644 DownUnderCTF 2023/beginner/proxed/proxed/go.mod create mode 100644 DownUnderCTF 2023/beginner/static file server/README.md create mode 100644 DownUnderCTF 2023/beginner/static file server/static-file-server/Dockerfile create mode 100644 DownUnderCTF 2023/beginner/static file server/static-file-server/app.py create mode 100644 DownUnderCTF 2023/beginner/static file server/static-file-server/files/ductf.png create mode 100644 DownUnderCTF 2023/beginner/static file server/static-file-server/files/not_the_flag.txt create mode 100644 DownUnderCTF 2023/beginner/static file server/static-file-server/flag.txt create mode 100644 HTB/admirer/ferox-http_admirer_htb delete mode 100644 HTB/admirer/ferox-http_admirer_htb:80_-1674285271.state create mode 100644 HTB/agile/ferox-http_agile_htb delete mode 100644 HTB/agile/ferox-http_agile_htb:80_-1678019995.state create mode 100644 HTB/awkward/ferox-http_awkward_htb delete mode 100644 HTB/awkward/ferox-http_awkward_htb:80_-1675808288.state create mode 100644 HTB/awkward/ferox-http_hat-valley_htb delete mode 100644 HTB/awkward/ferox-http_hat-valley_htb:80_-1675809555.state create mode 100644 HTB/mentor/ferox-http_mentor_htb delete mode 100644 HTB/mentor/ferox-http_mentor_htb:80_-1675786335.state create mode 100644 HTB/soccer/ferox-http_10_10_11_194 delete mode 100644 HTB/soccer/ferox-http_10_10_11_194:80_-1674662797.state create mode 100644 HTB/stocker/ferox-http_10_10_11_196 delete mode 100644 HTB/stocker/ferox-http_10_10_11_196:80_-1674572985.state create mode 100644 HTB/vessel/ferox-http_openwebanalytics_vessel_htb delete mode 100644 HTB/vessel/ferox-http_openwebanalytics_vessel_htb:80-1676229429.state create mode 100644 HTB/vessel/ferox-http_vessel_htb delete mode 100644 HTB/vessel/ferox-http_vessel_htb:80-1676228307.state diff --git a/DownUnderCTF 2023/.idea/.gitignore b/DownUnderCTF 2023/.idea/.gitignore new file mode 100644 index 00000000..26d33521 --- /dev/null +++ b/DownUnderCTF 2023/.idea/.gitignore @@ -0,0 +1,3 @@ +# Default ignored files +/shelf/ +/workspace.xml diff --git a/DownUnderCTF 2023/.idea/DownUnderCTF 2023.iml b/DownUnderCTF 2023/.idea/DownUnderCTF 2023.iml new file mode 100644 index 00000000..d0876a78 --- /dev/null +++ b/DownUnderCTF 2023/.idea/DownUnderCTF 2023.iml @@ -0,0 +1,8 @@ + + + + + + + + \ No newline at end of file diff --git a/DownUnderCTF 2023/.idea/inspectionProfiles/profiles_settings.xml b/DownUnderCTF 2023/.idea/inspectionProfiles/profiles_settings.xml new file mode 100644 index 00000000..105ce2da --- /dev/null +++ b/DownUnderCTF 2023/.idea/inspectionProfiles/profiles_settings.xml @@ -0,0 +1,6 @@ + + + + \ No newline at end of file diff --git a/DownUnderCTF 2023/.idea/misc.xml b/DownUnderCTF 2023/.idea/misc.xml new file mode 100644 index 00000000..a971a2c9 --- /dev/null +++ b/DownUnderCTF 2023/.idea/misc.xml @@ -0,0 +1,4 @@ + + + + \ No newline at end of file diff --git a/DownUnderCTF 2023/.idea/modules.xml b/DownUnderCTF 2023/.idea/modules.xml new file mode 100644 index 00000000..ac1b9d56 --- /dev/null +++ b/DownUnderCTF 2023/.idea/modules.xml @@ -0,0 +1,8 @@ + + + + + + + + \ No newline at end of file diff --git a/DownUnderCTF 2023/.idea/vcs.xml b/DownUnderCTF 2023/.idea/vcs.xml new file mode 100644 index 00000000..6c0b8635 --- /dev/null +++ b/DownUnderCTF 2023/.idea/vcs.xml @@ -0,0 +1,6 @@ + + + + + + \ No newline at end of file diff --git a/DownUnderCTF 2023/beginner/Welcome to DUCTF!/README.md b/DownUnderCTF 2023/beginner/Welcome to DUCTF!/README.md new file mode 100644 index 00000000..ec79a99e --- /dev/null +++ b/DownUnderCTF 2023/beginner/Welcome to DUCTF!/README.md @@ -0,0 +1,13 @@ +Aufgabe: + +``` +To compile our code down here, we have to write it in the traditional Australian Syntax: ( Try reading bottom up! ) + +¡ƃɐlɟ ǝɥʇ ʇno noʎ ʇuᴉɹd ll,ʇᴉ puɐ ɹǝʇǝɹdɹǝʇuᴉ ǝɥʇ ɥƃnoɹɥʇ ʇᴉ unɹ puɐ ǝɹǝɥ ǝpoɔ sᴉɥʇ ǝʞɐʇ ʇsnJ .ƎWWIפ uɐɔ noʎ NOʞƆƎɹ I puɐ ┴∩Oq∀ʞ˥∀M ƃuᴉoפ '¡H∀N H∀Ǝ⅄ 'ɐʞʞɐ⅄ pɹɐH 'ǝʞᴉl sǝɹnʇɐǝɟ ɔᴉʇsɐʇuɐɟ ƃuᴉɹnʇɐǝℲ + +.snlԀ snlԀ ǝᴉssn∀ ǝʌᴉsnlɔuᴉ ʎʇᴉuɐɟoɹd ǝɹoɯ 'ɹǝʇsɐɟ 'ɹǝʇʇǝq ǝɥʇ oʇ noʎ ǝɔnpoɹʇuᴉ I uɐɔ ʇnq ++Ɔ ɟo pɹɐǝɥ ǝʌ,no⅄ + +Author: pix +file: welcome_to_ductf.aplusplus +``` + diff --git a/DownUnderCTF 2023/beginner/Welcome to DUCTF!/welcome_to_ductf.aplusplus b/DownUnderCTF 2023/beginner/Welcome to DUCTF!/welcome_to_ductf.aplusplus new file mode 100644 index 00000000..3206126d --- /dev/null +++ b/DownUnderCTF 2023/beginner/Welcome to DUCTF!/welcome_to_ductf.aplusplus @@ -0,0 +1,41 @@ +¡***Ɔ SɹƎƎHƆ + +;„¡Ⅎ┴Ɔ ǝɥʇ ɟo ʇsǝɹ ǝɥʇ ʎoɾuƎ„ ƎWWIפ + +;()Ⅎ┴Ɔ_ƎH┴ + +< +;H┴MƎɹ┴S + ɹnoHʎddɐH + Ⅎ∀˥פ ƎWWIפ +;„ɔoɹɔ ɐ ɹɐǝu ʇᴉ ʇɟǝl oƃuoɹp ʎpoolq ʇɥƃᴉɹ ǝɯos 'ʇᴉ punoɟ I 'ǝʇɐɯ llǝɥ ʎpoolq„ ƎWWIפ +< +;SIH┴ ʞƆ∩Ⅎ Ǝ┴∀W ¿ 0 == (9 '0)ǝɔᴉDǝɯoSʞɔnɥƆ NOʞƆƎɹ ∀⅄ + +;(000Ɩ)ʞɔɐSǝɥ┴ʇᴉH + +;„...ƃɐlɟ ɐʎ sᴉ ɥɐlɐƃ ,uᴉɯɐlɟ ǝɥʇ ǝɹǝɥM„ ƎWWIפ +> (¡H∀N 'H∀Ǝ⅄) ˥I┴N∩ ┴∩Oq∀ʞ˥∀M ∀ ƎΛ∀H ˥˥,I NOʞƆƎɹ I +;„ƎɹƐɥʍƐɯoϛ_ʞɔ0lƆoϛ-sʇƖ„ = ɹnoHʎddɐH NOʞƆƎɹ I +;„¡ǝʇɐɯ ɐʎ ɹoɟ ƃɐlɟ ǝɥʇ u,ɥɔʇǝℲ„ ƎWWIפ +> () SI Ⅎ┴Ɔ_ƎH┴ ɹOℲ ∀ʞʞ∀⅄ Dɹ∀H ƎH┴ +;„{Ⅎ┴Ɔ∩D„ = Ⅎ∀˥פ NOʞƆƎɹ I + + +< +;(000ϛ)ʞɔɐSǝɥ┴ʇᴉH + +< +;פ∀˥Ⅎ_∀⅄ ƎWWIפ +> ¿ Ɩ == Qqq_ƎW NOʞƆƎɹ ∀⅄ + +;„}¡ǝʇɐWǝɹǝHʇ,uᴉ∀ƃɐlℲɐ⅄{∩DℲ┴Ɔ„ = פ∀˥Ⅎ_∀⅄ NOʞƆƎɹ I +;Ɩ = Qqq_ƎW NOʞƆƎɹ I + +;(000ϛ)ʞɔɐSǝɥ┴ʇᴉH +;„פ∀˥Ⅎ ƎH┴ ┴NIɹԀ S┴Ǝ˥ '¡Ǝ┴∀W H∀Ǝ⅄„ ƎWWIפ +> () SI פ∀˥Ⅎ_┴NIɹԀ ɹOℲ ∀ʞʞ∀⅄ Dɹ∀H ƎH┴ + +;ǝɔᴉDǝɯoSʞɔnɥƆ ƆN∩Ⅎ ƎW ┴HOԀWI +;„}„ = H┴MƎɹ┴S NOʞƆƎɹ I +;ʞɔɐSǝɥ┴ʇᴉH ƆN∩Ⅎ ƎW ┴HOԀWI + +¡Ǝ┴∀W ⅄∀D,פ diff --git a/DownUnderCTF 2023/beginner/X/README.md b/DownUnderCTF 2023/beginner/X/README.md new file mode 100644 index 00000000..effc0f6e --- /dev/null +++ b/DownUnderCTF 2023/beginner/X/README.md @@ -0,0 +1,17 @@ +Aufgabe: + +``` +We like to reminisce about the lit memes that have been made by competitiors and organisers alike! Have you checked out the meme dump? +``` + +Die wörter "the meme dump" sind verlinkt + +the: https://twitter.com/DownUnderCTF/status/1697304493409337835 +meme: https://twitter.com/DownUnderCTF/status/1697308270439051484 +dump: https://twitter.com/DownUnderCTF/status/1697312042821066846 + +Jedes bild hat kleine gelbe Strings, die die Flagge bilden, aber die bilder sind nicht immer in der richtigen Reihenfolge: + +``` +DUCTF{ThanksEl0nWeCantCall1tTheTw1tterFl4gN0w} +``` \ No newline at end of file diff --git a/DownUnderCTF 2023/beginner/proxed/README.md b/DownUnderCTF 2023/beginner/proxed/README.md new file mode 100644 index 00000000..287c1043 --- /dev/null +++ b/DownUnderCTF 2023/beginner/proxed/README.md @@ -0,0 +1,58 @@ +Go Source: + +```go +package main + +import ( + "flag" + "fmt" + "log" + "net/http" + "os" + "strings" +) + +var ( + port = flag.Int("port", 8081, "The port to listen on") +) + +func main() { + + flag.Parse() + + http.HandleFunc("/", func(w http.ResponseWriter, r *http.Request) { + xff := r.Header.Values("X-Forwarded-For") + + ip := strings.Split(r.RemoteAddr, ":")[0] + + if xff != nil { + ips := strings.Split(xff[len(xff)-1], ", ") + ip = ips[len(ips)-1] + ip = strings.TrimSpace(ip) + } + + if ip != "31.33.33.7" { + message := fmt.Sprintf("untrusted IP: %s", ip) + http.Error(w, message, http.StatusForbidden) + return + } else { + w.Write([]byte(os.Getenv("FLAG"))) + } + }) + + log.Printf("Listening on port %d", *port) + log.Fatal(http.ListenAndServe(fmt.Sprintf(":%d", *port), nil)) +} + +``` + +Es ist ziemlich eindeutig, dass man seine IP Adresse spoofen soll, um die Flagge aus den ENV vars zu lesen. + +Ein hilfreicher Stack-Overflow Beitrag hilft dabei: https://stackoverflow.com/questions/5188584/how-can-i-spoof-the-sender-ip-address-using-curl + +=> SOLVED +```bash +┌──(kali㉿kali)-[/ctf/DownUnderCTF 2023/beginner/static file server] +└─$ curl --header "X-Forwarded-For: 31.33.33.7" http://proxed.duc.tf:30019/ +DUCTF{17_533m5_w3_f0rg07_70_pr0x} +``` \ No newline at end of file diff --git a/DownUnderCTF 2023/beginner/proxed/proxed/Dockerfile b/DownUnderCTF 2023/beginner/proxed/proxed/Dockerfile new file mode 100644 index 00000000..2196b6f7 --- /dev/null +++ b/DownUnderCTF 2023/beginner/proxed/proxed/Dockerfile @@ -0,0 +1,13 @@ +FROM golang:1.20-alpine3.17 + +WORKDIR /app + +COPY . ./ + +RUN go build -o app ./... + +EXPOSE 8081 + +USER goodboy:goodboy + +CMD ["./app"] diff --git a/DownUnderCTF 2023/beginner/proxed/proxed/cmd/secret_server/main.go b/DownUnderCTF 2023/beginner/proxed/proxed/cmd/secret_server/main.go new file mode 100644 index 00000000..8f17e6b2 --- /dev/null +++ b/DownUnderCTF 2023/beginner/proxed/proxed/cmd/secret_server/main.go @@ -0,0 +1,42 @@ +package main + +import ( + "flag" + "fmt" + "log" + "net/http" + "os" + "strings" +) + +var ( + port = flag.Int("port", 8081, "The port to listen on") +) + +func main() { + + flag.Parse() + + http.HandleFunc("/", func(w http.ResponseWriter, r *http.Request) { + xff := r.Header.Values("X-Forwarded-For") + + ip := strings.Split(r.RemoteAddr, ":")[0] + + if xff != nil { + ips := strings.Split(xff[len(xff)-1], ", ") + ip = ips[len(ips)-1] + ip = strings.TrimSpace(ip) + } + + if ip != "31.33.33.7" { + message := fmt.Sprintf("untrusted IP: %s", ip) + http.Error(w, message, http.StatusForbidden) + return + } else { + w.Write([]byte(os.Getenv("FLAG"))) + } + }) + + log.Printf("Listening on port %d", *port) + log.Fatal(http.ListenAndServe(fmt.Sprintf(":%d", *port), nil)) +} diff --git a/DownUnderCTF 2023/beginner/proxed/proxed/go.mod b/DownUnderCTF 2023/beginner/proxed/proxed/go.mod new file mode 100644 index 00000000..cbb941f9 --- /dev/null +++ b/DownUnderCTF 2023/beginner/proxed/proxed/go.mod @@ -0,0 +1,3 @@ +module github.com/DownUnderCTF/proxed + +go 1.20 diff --git a/DownUnderCTF 2023/beginner/static file server/README.md b/DownUnderCTF 2023/beginner/static file server/README.md new file mode 100644 index 00000000..6965d6cd --- /dev/null +++ b/DownUnderCTF 2023/beginner/static file server/README.md @@ -0,0 +1,60 @@ +https://web-static-file-server-9af22c2b5640.2023.ductf.dev/files/not_the_flag.txt -> + +``` +The real flag is at /flag.txt +``` + +https://web-static-file-server-9af22c2b5640.2023.ductf.dev/flag.txt -> + +``` +404 +``` + +Web source code +```python +from aiohttp import web + +async def index(request): + return web.Response(body=''' +

static file server

+ Here are some files: + + ''', content_type='text/html', status=200) + +app = web.Application() +app.add_routes([ + web.get('/', index), + + # this is handled by https://github.com/aio-libs/aiohttp/blob/v3.8.5/aiohttp/web_urldispatcher.py#L654-L690 + web.static('/files', './files', follow_symlinks=True) +]) +web.run_app(app) +``` + +Dockerfile: +```docker +FROM python:3.10 + +WORKDIR /app +COPY app.py . +COPY flag.txt /flag.txt +COPY files/ files/ + +RUN pip3 install aiohttp + +RUN /usr/sbin/useradd --no-create-home -u 1000 ctf +USER ctf + +CMD ["python3", "app.py"] +``` + +=> Flag in root dir + +=> need to make the server read the arbitrary file + + +Wenn wir symlinks erstellen könnten können wir einen symlink ins root verzeichnis erstellen + diff --git a/DownUnderCTF 2023/beginner/static file server/static-file-server/Dockerfile b/DownUnderCTF 2023/beginner/static file server/static-file-server/Dockerfile new file mode 100644 index 00000000..60798c79 --- /dev/null +++ b/DownUnderCTF 2023/beginner/static file server/static-file-server/Dockerfile @@ -0,0 +1,13 @@ +FROM python:3.10 + +WORKDIR /app +COPY app.py . +COPY flag.txt /flag.txt +COPY files/ files/ + +RUN pip3 install aiohttp + +RUN /usr/sbin/useradd --no-create-home -u 1000 ctf +# USER ctf #permission denied on my machine + +CMD ["python3", "app.py"] diff --git a/DownUnderCTF 2023/beginner/static file server/static-file-server/app.py b/DownUnderCTF 2023/beginner/static file server/static-file-server/app.py new file mode 100644 index 00000000..88f8a704 --- /dev/null +++ b/DownUnderCTF 2023/beginner/static file server/static-file-server/app.py @@ -0,0 +1,20 @@ +from aiohttp import web + +async def index(request): + return web.Response(body=''' +

static file server

+ Here are some files: + + ''', content_type='text/html', status=200) + +app = web.Application() +app.add_routes([ + web.get('/', index), + + # this is handled by https://github.com/aio-libs/aiohttp/blob/v3.8.5/aiohttp/web_urldispatcher.py#L654-L690 + web.static('/files', './files', follow_symlinks=True) +]) +web.run_app(app) diff --git a/DownUnderCTF 2023/beginner/static file server/static-file-server/files/ductf.png b/DownUnderCTF 2023/beginner/static file server/static-file-server/files/ductf.png new file mode 100644 index 0000000000000000000000000000000000000000..8b89b47a9315aca0fa6114df81cd24214ad68c8b GIT binary patch literal 21312 zcmYhCWmr{Dw8jre96~rCEiK(3(%s!4-6`GONDD|eND9&*-5pXQf&$Xr-EilB@0a`G z!1M61XV2MtX3bi^_gzscO42V;iBKUB$V*un2{rIL^}i1k9{j8~+xiZH!1>vTi>t_r zi<7IkI9l4+SwJ9O+3uga(_VI7$F7Fg0e3yUyC=~bCIMrIu>1pu6-wY7kyc@#ciky=kCdq z#%+3JyKE`icj^RZB41_Ae~v8pW)|Fy{%&Z91aD^9Yh3sH`V$FrZF5ynv8i6uE z{A~B8QM=N!D^Aizbm@37esh_;Kf{*}tWEsM(R=2y znBiu4+Y*0^?JK}9Oxr1+`YMM!>BgCT9AO>(=TObOX#2$sBmaku`_bF_3b`sut>U0T zR9Ur+lgP}pJ?B%D>2;17oF7lmhu?AucB(a+?!T;#u>EW8X+$h8F!3WLlG=stk*-qe zjT;FDees-*(H!rlPx7&HSH8p_?4}-Vfn?ucJ{h2 zv~ujdLC+ECg-pBI?Q30GtCisw4v`RuYM`uysD{_y!wye3{h^L+oz=mkg_hSlQb;e- zT_<>vqf~=Ou~V3$a3n`3MH`vC|4sa_wM?9}`oxQIlcAV(#s;L=YqaZK*zmFo%{85o8k9BY0=2gAj;5_$mLMTmpy`>Hl={kFOTwf=JR)27$)f8LP zrAdSc_n+3{;NwnxZ9__8-eUE;Pw6qC^(P*$ErPaJ61`C^?0%ac&toN;sD&XZ-ryc+ zLJe|=p~1nbovV6B!pFu%uo{xqGTC@TwxU z(CxoJIRDhhIrlJ;L4s;UJ-6h!2O*Pvb4E;yty~(alzug=+=1a|hxllCKQyY`c;8)a z9c`nL{vjaMqxSdVc~7t!c%f@LAV#(|RXbBo-p$$o7t-DEX9iQs&`*HRJA1pE{T<$F zKm&iRX(uMct3vmcV_{Ntf%CIv2|2}&YNt)=5QnMNlmclfY7|2p3bXtQ?QSSKGrn6W z9<5hbNFN39OS1)&K1K-yN824j2sD^tGsNVl1ROq!vms_QLhX9ZY6@i-tfoiDt7)(g z3W2hPXAqBpP$I%jd2zC?l8w7!P7>QzhDQ3=j$Bw*0Jj_p8}6@y6x@FV}nacV}InX>2OTW{j#Jdy;w8D$_<@{ zJ$XLwdhinpXe{<8aO>!?g~6JQk~zlnVUX)F=b&{qgmaeB93^6}!@S2XJKfk?{^R}S zD=|J}h-W$sq2hV+!E;F%>#J=I-ACkjTQaiYzg)J~wNWnuE{8PqB4&LCxR^c8vQN|E zIl@BjXkyrJBCda?5&ig=JhLR<>NCRnPmu^ovZ*P71C`}nI;2;)GmlrV@VZ3CDACQ0 zx9iF5CtF5a0*1i(^VAV~Shoj3Aw&d107I}&kL{bH`0>d`$Kxrl4#7QVmj)3+M@j`{ z%b`eyj})1Tf0<;%_YpFTok*QNp(aKM>8>`020N&T1yPCSwk@46YI-6C1(B(va`3{# zt$2U+`fS310A~St)9oDC^>&Th0Z$A{9P#nR;=~~$}^lIakC}g7^MC zB2a;rcW1*TDn`-2-f8zS4jdmxPUh?h`c5lY4Er;N_!`pTcx(8JD&w3j-)gPy4Fr#k zTl%KeyX79YvEruUp;&!zg9Oou$c90ef*;+I6iJS6dnP0#%e?loC!AM`X;Dd+iDXM; z4MN|2NN>2m?L95rc>6BgLOtwBDe3fe6Fw!>Ewoa5B~Nhnt#fR<%V#pNlld(t9jq=J z%^IGb_nLCAwU8L(!Xl2)uzI;FP~$2Sx0J3YGS@DLZ$5uo^@?3+WZzIfscU)KeI@v6 zNM>y79t%F+0hJo{_Hyin_^8B;c@Uh~F*(~Hq#G*GPNA>$!%=&eOqV6DEOCzMR5STR z?>7=jZ(|kOCn6S>jBh`(52jMHi9eOZk6TgYj+2X?n;}c)&RWjyqK|q+2!8t3P+$|Z0 zA*@S}WlGtyzJ>+m=e>TXUtY$2mxv+eq>v&(#}gH-#mb_+lH`)$_ zzG{`Fj5TKJb$8>3f`dXmKXvB1W~oBegV$NS?M%uZNeDA$eW?@an+h95|db68a*Yj zownA*BEMs%tn4l6AK24B#*c3zWRc^)B}R63y?MF_#acj;Ryc$?YM8rpiBvhXZ_po{fP<#A}`nXev2}v8fzMx$?>-&hQU;!mpD zWie+L-}rkCnmY;%ehl&YsU6>4XmO4sHs4?C!rA|_8izJEl@}dvTnhq;*}m~J)X-s2 zAbyiY(^kehLa@TqY?q5E!sVTF3oje$q05f$h@qvTLZ{1O0VKC!MW2A%xv^%A) z!MGg5xp%fZ)hd6@*@?YJp@7y@_VIb?zw*9$`j>6;v#_**(Ll*4+RuYd8hUT+h-c=t zk?c`C^TDoGDQ}Jw;>Am~isi-Dwr8L4NgNfHg?QqYXuPsLz zV~aS#zlL?_{A9|xvSX&okz?}LPHYe6l_eYm1nXTSTkA%p>}e`24yO*EK21CF6`q4o ze;w$`^o*`qjOMa+ZkM$R>he9)806+gWTI~VBVS>w)TH@{RfMK$P#*Cx^~}V3ABBg^ zYq6z#sF-X>7-TSLIU>=9@@%RugXs-4xLnmU3+2vPsTcx5A_$pcEYt{(T$?2st~>KJ znTnqw>~)@M%oqx#8{cPEi1`T5lSB;_l_MNfNmXg>des%eoRxuxi)g*@gDrzfEG`rR z=`&B}&=ET_BsekAEQCM?&vJ@5B=(N`*~;3gUyZ^GWy`&a3pFaUy>mbM7* zXvYHrsb%9f{aR$B@Rlyj$*WkKVAD4VgW|`&sF~DoY=}Y}1W69NH-UpagTf)*@|V*{ zY5u>WJ_0CGvuYo;rd6gAdx&O=nrQOABDPri+JIR(6_PPu)^Smt!h!s&1rq^e>6dBk zq{#}rVL>VhS?>n2G|S3W#kzM^eQo6u{E0ihgR z9Qeq@Z5w^NfB6o$J^IO7Svec@{Q@05CO9|wS@BtN*X2uO+&^`0-}VkQh0(@e9`F~0huj=4 zN!q5~NW%HMur;|GSZ`m=x7++fbGP)YJ`c?~Rs0qzJ~n`PWib?=ygZL(#4%U;;X?cS zRd3<+Ht8oNl5Jim{g;R>O-9NUx*O+SCqu|CnD)?PF9t5F%xnG1=`>2=#gzFvE^RHU z1L5+3;-1E8d)6Wx^lBIuLNqcpDsLWs8t!?f681-dko*FT1S%*6U92;4cpszWQvOHP ziP9D8bjDbha9KuqM1-CiR4n+F&n5zcBa}pHEMJMrm~hQeQqrIWPEI2Euh5DTRI$Vq_8{`O@DU`)Owk4<8wlDLe)kJ4yY--8nBd4mTa&CPm#pV=) zAZ!qjXKxOODdybXcNHbk!;{B`-57Obwayz~UGbh0EYI#gtmT+9h}ZGz8vd7{H$7Xk zq)?Eepuyk$IZgz}r6U*HeOycyrbqGlEA7SrdmC37xm zR|aNQynpwco+r(j3a7SsZE90}IM~V)^su@PbCxyUeRy_jw!hZ3{6q z0*=(}@`LN1UF9kg?CDeU+i+1r2!Xh4Shw>T@g zzErKosnxXud%LbBvDcj!5}X7pEWcmFdXayB1X+#yH6M5dHlI%_X$#h+N4{T{l+Q@k zKTJBrV8ica{g8?DeVX2B-<1=upUtA2q4n;%)aJz5_`v!a+7oev>8Sh4Ew89u!fSVA zeutr@TqU;8oaaiKTnLaaYf6i{7tVpBhxvcHJdmS;lSv7Z+K65w}J=~mOHTB%{~@8vORM zx71Gxv-+U$I#T?B^R3>BPOEl^@KcMH{yucq2X8*-lYvSzE^j(@^19ma;02_lexvKD z!1KQEb0UwhNvz*l1s%`^|p8b?Sl85F%<;?|qYeb?1zI1uu?FRLjtKbo z%y%-cU3M3UJ@rzH&qRG=d7j&w5P?EoKt(kR%cZVT<~Gd6-E}vR2pSLP$GRnxd!*w67{&y4q0Tj1O;9w+?Xk03Ll2NMdWayc_vSo zg-d@U;fs7)S;z~2`iOO7E$U3Acb`5Wt@F(P+f+flQ^V*LnXzFICypq7D}kfJp~#fw zUyR)6+l4O%rE|4MTBL$dK;A$o*qFEilJ#{M{9NeL#<5jJ&@34UQ;3DWsG){yMuTMs zDn61WuA!b5b=ndU4Uu zjT8D$YFdU&3M9w8E^@XlrX~nhN>@JS7rS37?CXQbSkudXz02JG@G`P{qc#`3m88&? z3b}R;U7oSIY5P2$LUss){J@CWra0~QM#fY+F|q2n5$?ZXRcgvB6k=1Kq6lct8MS9n z!lqLAorv9(_gi}wi{K{3F~k*11(59{=t<3WW2YWa5BP)}G)tH$n&vlKl_2@ar^FlH zUqAf%G)8A=e(4#41(QryKY#Q!m)O0`*+CZ(pFqKq)60 z7@qaJ5Jm~FdRx4UBPK)t$}6(ko1_}K#ViEt7rM`+`~CIL9A`9jY{UmoBNqLRVWVa9 z#s-~lc(+}TrlLBvP6fK+1P4BiE4R{xIw`r8(?g$k_6ZyJIG z(N6B-7O!Ph56m&6>9^Z88r06QVm_SAdU@A60ZQW43@SG(vbYkCjYUbbp9GT&zS!p_ zjI;O`=9wU~J;P+hlfmZGss#IN`EQPP$GnlcV}mEpYc0gUnzx2H_;I;v7APH0Vh_8> zZ~W<9o)X#JL$(hECF@JQl=I&H)VbUEJ-p9~H;l~}AQdxoL)M---^{1IZ2qoESAP2z z3`w9%K`K}&OL;dT|54fQrRQa0rjOZ{`R1Wu)b6YH(urN(6ro2Ix9f96_;`>9Mz8k@ z`+aj7R}1tnoc*)zbp5NXCC&FsR-6u-I-xpsN*XF7-VIz(mKL%0;!iM+B{0!om$fLW0vync^pfx?n? z%oumx$Iy@X7Iy%oHRx=pTC7+2xK03WyruE(AoY7j?IQ06IR+deSbXT;VBx7~F_!mi zNLgBlR9IE|D>3-cH{o)wrM{0sZqK8TV&lV~A|^P>M2yOW$ES?ek7q&MefRGX+BtIB zNB9GhHFWzc_4Z0}?DTOj=&k<Z#fP8%ipoVX6Mz#o zZ2G}^a`Kb{Co5K8>N6CdI2wJc8S{`ja8y~2v@}iC#^oNh@@X>_9r8H>JjV`MQ=Nki z-W;{Y=dTQ?Cl8W^g$oYH4XnR13Lw{H>Vz*q;Z!oh=bMe@E@c#*E%41(@Mhj-+<|N-Nm}1&h;aEWnX0DH#-IsPBGO z&tximW#zt91agA+t;93t(#p2zL61WkxuM@LrF=`5=06xXG}bJjKmf^!4Nm3SR}0M; z|7kO#YW+#YXm%0t_k!jZS4ZLSB33eUu_qF1Gz z3?EU`OE+mU_0Pr(g9CLm`eUw;^ehx2a=IoHY3ooAgKzAUTMMzMKQeqxG3;!t{qfh7 zT_&D8l#Ue-0#U3?B^MbL0k@i6w?;BSzriKOa8b0!lj^SfQ-i8HXX9J?iG9PHr$N7c z@nFwWTa|)U{%hw5j+YFSkrD4sjj9wINu)a>^yyo*x-QjM2E`JRF!ITsHH2lK0h%!0 zuz}v}?!HEh1x-W(8eFdnUcPu=KNh!~?{61lt-H!0F`D4LDH;V(0l;H=BpPP^nrrDmAp(6i2w|Sfr?u;KIP+nI< z%tWAHJM*L9dkIX@7tc^+L*i!07DBz39=>DJqn@aRM!}qh=A6?PP{c&~YYN9oa3U#- za6}NQ1t|co41Y5HsoF!yFGj`A)xs!>`F{*Q~C4(p<~8=pu{X`8~)3La>Y zU6TgA0{~jSG!3+hcReaNeRxxwvtU;EZNpz$b07v#=d~~Q;<3S@L%(p*9);%#^Mq$S zJAd!&xg(ICJp^SyhD5n>toZHj`=&{hhd@0I_R^!!!_`rL=zeI)KsoCUJSHzXveL2x z-rXL7$)oEkbga58gWVmEiCH3LLD-*DH@ja>yF2vboLv=bI7?eNO!V00;n9r)TMCz` z0-5jr#IVcYoKT|(?F_9;%eIPw2!TKf_HRf4Q?%1hZ9)?s|AHYl?O9kY`6xB&&1y=B zO>NmL0ch{Yx_|&Oni;6})YyWC;*#IxC=oE96BBcbVcaB8^-gPIN31qPkuK%GiHNFY zdr!O_ksOmcP@;Sx1}%v@H%2!#5oncbWI_^sG81A`Bz%z!A0JktbYjg%A|!!+*HTCM zr9h*GgbUo=0DH08_7(lgoe}{eF>DqN?w%1F&R5PE>aQg#s9Wzk2)U|)VXLF$U_?g=OEIW7nvq?%~Nqye4 z(4Rl{>ZsE1W%EeYgcsAs&25-^5nn7$24vY;bGZ_c7*N0C)a$xcFE5=uy?2t$ejd-8 znSJM@RSXcTUEI_4GHsg=$zb`C9d?lRFwItd{@pXHeQ*Oz^;+fXU1oqZ}5 zrY4E#$?`8?htKSxgVPi*QpVU2;!RiFmNALF9^SzZl;LVxXwsqlprgS3Xa4h9kJ+AY zo@JtqF7dVn$|JZ-mM-&>v03?sEB+@?e<@i-Ne^yP_womhgV1f^;-=kFWOGs4rRZ_} z2LrA!LjFGPYv3(spDRo(s56Yvad)Cw6&EBnnABLK%zv8Z9qC(squEQ;SAWvkq+utxy0sk!E?bMGesSE3KdQ!0H zS1GHU;bO)^I|qRg5zhT;J}CIKP|&r6e#xJzR8>bpe(QFPy|c291|gP!fjRqd%-n`g zo(F>^d-t`Fgx!7(a~AI44cN^DeG?ASIOGW3jlug+Ct@lD5ojk{+z)2}hI}hLzRlSo zpFEJvPdaPU4Oi;#;3LfcIfOt<6i<|LR=_so483dj8h{U^`tjWp%+dt+=Nhk&X0gL> z8$jVNoXRTuz#LzmGUDH`BZDO&)(zg`Lx!AQgnhc_o9X6a6no_M2lJk-cReHP=GQfs zg-cPlZ<9mlo}aA#SdqpGwDNNL7hKy_e%37ewo$?K>gmkcvPZ#Ut{$}C zleGl0%!HL`J&murjn7@kQ;s9CfVVfk9OcV&IFM-0= z2-wOf&t%WKuE6N?$!veNjiHVh+2N$%xzk4N_!q*Y_HEXTGEQ$_Pg8(F6I@O^lS^P+>-7KM94{@1MQVdUi}5~i+K+~ zu1HZb@XkkvJ+!I9*x`dAB?yu57o+Lh`N};dl6|6aeJZMK5pWQ4oNicm0$H1htZW#8 zczm{Us~99i=m+GL7r}*DZiEmk2Qv|dX>7hx4*?uRgf5aI>b}U>4QzvUw*sXh{K$T>gRM9TXjl`BV{s6P|N-#Ecg)1 zak3mRlQx>L#kFwU2a>nv2NRmC;tqOB`JL@9B9sDC3tbwZA_B|8}VfV6)^ z5seQ5lZJYhck#@s_q@lz?LZs-Op&6!2UY*$ZQ;SR`Ugv6$L2r_e1%YJ^_P zTWD~F+{;i3gpdGq3P8q-MR4*NJ*V98AA-CvXlD8;g4RXof|z40T$0)Iy*^7zWiYWT zgu|eSY>-(Dm+9Ev1L%iB?Xdj=iJ_!QAV@nllPg%^+6yG#;fw}K{>*7bV*>3=R-f(ph{=+$d(v8oQcaw5Ijspp46RfN@Iq?uBu zNkMD_p=HmOKY+E+#HJc8kpdwbe@{W`&(^yyLtKCs|6Q~MXCye`Y2wd+{UXeq_|0@B zd@qx%25K3khsE=FskHI)ca6GB9TP>hx$m3s`+M~jb57lZsTbMHh$s*L8Ya+fu@4)mUmh6dB*%amWyIe*{YeltZBlSdLCsCCq2*E}@tO3ePH4M#Oaqtw@4)t-_YE6zYPyr_9HB913=B$0a zwth_VALSQ;_knFq!o+2Co1hk*Fyde_k*S(lQXq45IwkRhR99fbs8 z0@cM{Rwd>#StkEd4Ea}EPUYO$+$Frr(VB`#VK*@YHuVPH`&)9bdFF}0k1~zfGMl<= zDR0uNVw5lB88lT-`QL_|q4HLdR0VMk3k}v>(j@Q%#vQT|aKFMTfSfPI0!FXf%tT(xRrs%_rh2qMZh%j=Fh6WXZ8B|s$_j~ zqtg8b;U_q@2K{VKDIqU?`~3!9^lgRnX!yGem5Byxs{Zl3FZ#{qzkUI!(D}{gD90*b zAquIHl)60fBO5zk))|WJZW7v0*1*?vbvoiibTvNyl5JD3ou0)l4y3gS1I|t<&q3$( zVPTF9dT3xsxWLU`#2~Um!r%!~EbtMVjpwom#HF@_W z#wJtN$I!))3_1G_=chyff!>N$5m5&C(9O;41LbO!skpLF$XUvDy&)`UQur*;&~1=e z-U*sSg#b78GMb$#jQ*b=Rfy`~X+odM?ALB1{3xdvcWPZ~!Bc*za&PGZKUwxNH*D|@ zJI{HVvPVD=;DSU_jg^Xtk&ofYd?qWu?&46$3@cKRXDU$yC9`u|=g!biif$8KB8kC5 z9@5d>;2pSXKzv7ribk*vgx2%A*v~&UE)pUHo74=r`a5=}5(w%8A!Kl}wyw(k zlHWG^?DtVW$jUQ_-sDgN#(Lz_*j>G1HmmEb5A;COzH(#nnAs`QN*&^x)vEpzxl`@$ z7!>p0J61kQ7lx0NPwtyZkN&4gW*29dvHv7I>ou!=-!vq^!Dm>Rk`n276z!;uYv<6! z%AK{Jh78b(P?3UwR;9mzn~$dg-jB16@BHkhU)?Sm7@#L)ow$K#!I9>$fb3#W>)xfl#l>Vrx(yr9jCCtcXwO6` znxPj{Ibp+HyO3}B*>Bq@9rX^7#nQ;<1+an1sSbAE#tc?&5bbEi2o3eUWDFHz&E)RW zQ)NiTN0Z;CHzc&z$6fJmaL^$q8cZ4-HItJ03~TZzGg?_K9|%wt0Sav4xBf(gF1IR7 zv1S{0psGpMr~IT0kjVgHWbHEla_kYk8_)`B=YR(~n?WjNrrt`OHGHpT%c#8V>5z=k zVG~o?5FE%znzFX>C^b@``oBw4w`-|`oF|WGW4UXSMa>;H($%IU4nZ@=;e84hD z33Iy44R;&(TMzGO3K@zIe(^3*RD4Uz?lLdp*wC+BRX;L9Z9A#7YhE{WMzILXSswb1LzGLQS&v}nXK{jlt{M}3e?Zgg2 zUy0VYl8NE+qQ-w3?Kk~8f~8Ap3Vvf9Q;PK|xaU>F5Xj1BRi<90L@U(l~UF=d2xP2by6` zE7sAb2{Mev3WKk*6{n|T#B24n*94HYizT{_pQc#S&oSCs*U)SAz0(+OOy88VwyfB2 zIaLk?R5Uk264B3A+E5xh#)&xmFsHFwTuf94Yk6kdnhz1;CBTEXb@oDD$3{%%8nc3` zx0hh~r-Q1G{1$xcEbTh$F3W5_DY5jLxR}1F7rd^Xyqf- z00Tj8)(%^5enL z)Hg1?{fA}{7s%oih~69vmwOBD4EaVM>0zDtoJb?PfS_X(SZn-*UR*MvP&~5W8_iXT zk(vTM4ouAv9KU}gIW0c-E8`S&Hw--d6H-bR8%st_CRAoa^r#EZ35B0&jTss!|11UTScAnx@u#5psoMoz&)DVLJR78tCl&<3(B)>kH6SV$iO zB9LX-{~e33lD{X|bPEMnkRynXA-<2(QtM|l)K6S__bHXeE7sV%mK+r(s)Do4gC3z7 znVCy#%D=JyMXL3z+$5#IWD58KF;=zH(U5B`X6h(O;n^zGs4&oOR78`{hrhOK50{zC zWRRcK6h&SS!$ee6N8dmrG^1NZW7hoWf?%+ z(kvDqMbL4X`Q_>IwZ`su78TGvfn5ST%@zp!Kxp8T(wR&BY#J3V_1bFEU7qmhhK3w8 zQt}pvwiT7!K6f%E$;XPkT{q$kDHLVs?ospiaa%tLDWhd@rULIvJL6bN+vez*@mTaZ z0-srJnj~njd%L`7HRr6a(32ydC^9Az+)|U%puoA|??FfF=aA?j!o&ef?=1g#7qZ-% zNhVU&aO61D4=3oaWRY<*9lQucS%3O9b+(`t+Adj-OCCZ0q5=tUZav@jDJT^;zCbm5 z0M!jJDuKC)hV37|5q>n_NP08ESw@Gu{LIvL?ZlE)ED+I7da)dsW@lG>r&d&;A>gKV zpBDdCCq)guz~t$Dpu+6049dWWBlHmRZ)yuBFi00>Uw}xEo^DBbe+_|g_pvxZpIbN^ zQi6PcV>((`Lb0F5zeB2(q1a%BR5pkgOJ3R3OH{~-H`Y*(MtD%Ll0wPedwy9fD8-M; z{)Z5mh7qPL6nGp&8M>)^{@ZNVNXF?I^ew!0iuCtl%{lsMl%0e>uz|&Ls&pk=PGRh$ zg&{u;+lqARfc{=GlhIq6$Dm_{R0xEJ^bVP?#l)EXf^kPHpnKbbAv`%o*$xHyp}BUJ z5{D`CP_Ij1YIgtP0syJ&oe~*~46l|ybxd4lb=Sd{6f>sp`AB3Xz%sW|IOA&61@SvI z3S54VvpD~O9Vzw4VT!PCeVUyklKE3dYLzXD*cYi z(KRb&{PSwcnwefNDIusyn)p^*uU;Ea1ND+8tMGlRosO8^?=YIU&- zk>(B`i$=sh5e!IvnDYOUEyv$l^;=lq!qsuSzJ(&h77tmA<-+rdr$e@sZB)3CSKpA* z(4megMloy0|D-d)VG88OR0ZSTLV*Z0@s5*MTDKvnL)eVc;j9zI-{mK)1J zszJPM^gMKB|GJM6|Ben(uwx=a_c5i^>@ztjx0=r?eKpy)f`3nvWmuuYd+$ zslVY$JT+^U*Jj;*=GH*o`>86i^KvN_FdSteSU5}!;ptr22h>Cv97={fdNwxoa0uYb zT>7XKBs@n1+ATM-x4Tt|(eE6&v*`Z>RyjPBRq)z{ACwPS;xm`x_}@Zux7dELD&mFG zbrl+8^ak7}tg|f@9hELH+qTmGg%cB@&!0mWB<^)6Q?A|VE_R7!_q1t!j3he1KgQ_J zBecj=>gq;p#cT0@E$o$Ji45<#J7z{s_l9Z`?m27Ow4c!Hd)Fn|x$yQDfm`T5OOst@ zkVT^>fr25n2RJdxYX?TRhErH*bEvx>#5r=PUykFMt$;J2k5;44blkqtrp~A{3zXb{ z`Ro)+f#bXFxD*A>{S(cLm7MFJ@7$$mN}q=6Ayj9 z^m3vGp&%vMuHHSzf9Ywgu5%V6T*RT{@`q%;7^5a-c(0u z`e9`GcIN~`ZX7lz7C$I-IvF4L<`BXRM=95u+bJK*kl#$&$6V2j6ic~2(A|E@Ih8dN z*#7V-TZ*imwZYXFPV7X#66@vpazL%qp<19p=+NV^4sy#r^KCT&o*2u|WF5i#afzT@Cc8#f3d7tpiC!9`v6rtdWU@~jpL zv|y(6&4uqB;|C?{-Itl&imZ4OUjilm|%{hkQLlkT&jA!)WSVj=cfC&*dL@P!-8b zQS~2te_83=>}i!cmrE10D!&GDl0{!Wi31k3%nof%{HmAfE6Tbwq_*J`wJE;%O*FXX|Lo=*CI06KAa`<>hj1;Py zO54yVv4CGrHjggPQ!cBkFDZsBv)&_1W8ea(DiDNj+IK#`{L)JhaPy?X>6RkS+r7oY zy2V|MfnEuddN2D8|DIv&26+w{*t9ENVvtcXWmPK>9;4iy_FW^dvp?*VB+%vGzHJ8z zIuNgp^hom&1nSuJb^9H4@QKxEfLi}rYZDpIq{iJIc;{;Tf*scgc(Hpim+gzcY(YQCUi;0TIND_Xt ztuZJ3-muU?Pn$uJBM6Q(v@~?7o=qAwwggQZ+qRq;>oMGg{T|@9vZ(`bwjo`-dti)) z!kf#}w=`)Y;h%Z#xWSxp9oUNYB#mQR9@Q7qihmbVtz74R5he$yIc_8mmN9A1Q9hFtV!?w?AS3a&8PSS8hLeok-7P_{1G@nL+kt@9!U zd6}YpYDxVTmwc+Ke|_=m11+}a1qLkl>w%w?CNddL2Mr}z$=fSo)44~6rDd}SFp0j! z6S-ae%G_}*NH_3&cK5w~hx9@LZ~8{n#ViKw^%oGi=&%C#r(fPn&U8Ue4>CHlyTxNj zkbLq{OlExGV&_ePK)}HY4R(FBJ8~}EC<);5w5e6m=*|bZ7Fgc*8~b4Jz+v=z&KPzfOme} z{&tQ&4h@u-mxu;$zjpTk&1k8^L;V{fBvSHby07?^)%OZHhm?YrPzIwh%hUk@4l!st z%{l!%#g7I$sRS4vL4FXQ0yfs5h-S6vclS^Xx>_7o7x_2m+V=1YF|CAALC2{%2#?yc zJ3+2q%vgG-lwuBpTOR35lwrZ;h8C`EIn63FuWSCs^(pLspv@re*^wIhxB2;lPwse5 zMCQM#s2s9aU6@vNw{uvC{jO}KiCOuBa3?-hZwmi%y=7*A0$Iw2L+7qNI)k6w(1{?L zQUbbzWWYIeT{wpgv=l4b*iOzrmv%iMO+hVq=q%i;K|KZ1GO*n-A9@^GocCOQ0X-n` zgcKxvUraFqo>Ok#VoK75Mktp9DF}Fnv^j@78-dk*BzGGP*b<2_&hFzk9n4)F(F2b+ zdq4LTi4SSk=8YfD|L1o9=eAk7#FDjeuvcrq<@v+H6|?K}_+w7mf68fu($~bufM&+0 z{@;;Vnua`M*S~Z7Lv-ZaKTR)48wM~m+WInKuf^y7WP_h;eG6Q`0XKV^T-Wg))T9fE zR<5i$+xOE)Kx6thvwf)%e&AJNyggG3M3g`U5;dA9Q2fs98S9lAs9V_?y!J7(^1EQ$ zJ(0yVxmikE2L&z+H7@&?7Slyn3!{){>$SqC=`@-Gh$LJeuO1VdUB zCz%WYQDYHWyx-!CnF3W!5>6>=g7pldOQ9a!=!CFs+m5^ z_XiZEMj`>7hrXwJd@Ek!bJjwJJlz(en;q2mwJ5~tJ2b|>-xrj% zdS=&LSv3+KGaTD`x^VonSoyoml`rVzak4HbSXrOTGsb_fqH1p==|u~ezo3#;+WAON z#d;0q)s`12sX!G*O$&YKF=kDRyGP4Nd1t&8qdFYxS>j$U3FETJt~Cy#9j0jr-~ z?Hgp?9 z^>4F(O~}6eW)C4d7}v#n1kC}?^DVlM+TUqnnu?X1U*9F|FEtZ?5F;R3QL(D}6AT*$ zdCbHXT^Q&Cptu-*Z}K}DpBJNsX)o3O4mW!g_9bup)5@$bgM+ba-~<=wZ*fa?dUP*K zhU;toE2~uu4FL&auo8~lf_Hb*`bLunx5{;s@9N9{{#a$^`U>yFh~$;51QcF#GJZsa z_WffhI+mAp>$P!uGRz|jJE`r9aLbo4cFjcjVl#+@_+sQ2wf}sftqDuo>HE8H9B%jL zu{bQ4lBi>Y3!1^QRVaztY}U5_!&umv+y|kHJkb;%Q22d_p!M=IB}EmjtiH+6JXYOd zO~v2%Sr%Mh^?ql9K_`urjTBYK^1N|Dh0(3A4r*b>voLz>AD#tXr}GRWjpsSZcqp6H zrbdZ8Va~+F2Gk?iK%g5G;Tir!M6=0RZWKRT!a2F+VT25N1ej8B&pZ4vD7p_N63@)A zQC#0d$mygIAtAzm6%MUXUpY}_Q~;akt(XUNYzu0Z|5XLp)xkVG($N@U-oMgXmuzK^ z=fkS_&%5uY7?lSsm9BC-jW;yzwyOF8wgwK)(2hR-WKL3uw7Moak-IxkVZqy6_F=BIjEY}hv5J@l4sAn! z8ZO^*m#2d1Br3;)Sm7EW4Ie?Rg$|tmO|FHBaySR;pVNt6x&l?8!tekYa>QTopS2pe zdVX)TGhIbg(}0{Pl_m^qmlA~&kXm=T<+5hb05KTUfWB9&!#C5w6p|?|<#-sk+$2EW z7M(i&IV~@CB7H+p-OTOsAKuWYbMNE&q{7J(Xz z2tq_kOt|biqTf`!cz`~^I(iaDC5#+_1%JU^s-1&{dF@>e#y1!bMk+2!0fZNwVGJQ` z1q|`l+L;3XWZeliQ~)}G%H^=c*oqX~@CyO2=vshwC%Am(z&rV}#&i7px;e;kz*Vzjmoh6n1+7Fj2DQaH zGA6v)3AVrmTpI{5(5wqJffHtkb*>8=jrP_o6dy$t4Wf4bw>}c1N{-OSAhA?L?JPvx z3nv^mC$z0`N3X<5wTs{eAJ17stiq2(9;PB9fzq$}fcjlSj6`+SGf+K3|e0 z0b*_-sKnG;%5kwBC{yybh*lP~$XyGM9q}j1ThK*(ksf?r7QS?M<0V=0(D|&b=lJx* zy4#844Dj0xX!$L-<>YV60k}EKE#Nf5oKGH*tU84oV@HSQX?>$;CjwdQhh4`c5`!zy z_CVD$_gn86^h}t8up#OE&k==GkQ|S?oQC@U>4=!s_$vxU z!g;7)rUosDRivfu5gM^|`1+nlXn2$`QT5AShf*$JRuk^S;sry!FjQJ_O| zBc8fOG@5ga(I1646OK+~WKvaWT2$UdL<56X^+R{8WV53nDX!%Iv~b?>RQK;6KiRU5GE1ZzrN|zg%#2cz zq$oMZ&L+p+D=H!+ageMs&ux`scFZ!e(#h=TloiMBM8@}W|9*d*KRh1i;E(h9e6IKF zdOlwQ9F(QKJ~M!e>fDRI-Cu2qJJ#3sUCw=hWo{$PmE?g$tMR0(w}X$2C-j;$%(i#_ zL&v3afEv3u)s^sC2Xa7HW^Wp5=IoL4*$JQyK-w1f%_Ut$Ct#i^tBVv}4%@AsA-E+; zQhvgokTmMX^1l0;exopt40&=l@tBI%8+VuM4Zq~2%_4hG*|OJGT=82HkLM5@5=4~q zM9FIjTJh8t+g%n!YzCP#&mzhv=`J7;`Oi3n-Vixd%f>=4wU}$ZkE_@<+VZ%}OqHId zUVM^#^kv)5@$JQ{InkDj`C+wdGDfR5-0#*(_UaE5z6jcoLfGYmv7E9k7kfY{Ox?(Es)%vuRvf`k8gBeP2Xc?{MHd+y$WewYwf-Y^JWYQ|-iD1y zACvaac?My-vH4Dw-MxkO5m6^U13jpirCc*wryaK8E}wp)*X_B(zidALMQV&Su=-w} zXfEvgGI{IKn;@?;7ezz1Obw6iwOA*_`}V*T`Q=ZTA&}nfy5<({*9CpV@4oOBmq?)h zEz->^c@8~`47+nX>#(c3Rp4f};Qf4eKFbt!g?iyl zXxcz}#QgP$B|McU$4UNWGM?&fD<>>SSdcCeAs77GL>afoDP|EK9H-ZH6%}#&i1F(X z@Qhlg-gFRR9&hOx~#ed{x+U`$^Ub!Vj>a|z>ZZ(VAVm&Bh*%X;7;>8pP;r9)RDCrdD$Sv z@a1es&^4QBJIJv9!Q}xj6yg>XL5fN+a}n2T!QsWJ7{P{duo`Z|Y3AEFuZYQ6;gT=1 zba-`(U0V&cP$py1D(d%-n0le%oo#~l`H?}Vf? zh|Wb=Dv?6EqdXQKa!K;S0yr|fX~#wr_cvF=Etl4b=kLwV&1}kft*{PR9lqI^yg{Z6 z-%;xb`)jdMb7eaXS2lgiWs`0%(f4GG*+bYpS3YcB^O{PrXib*_kh&)$x1sT*Tu3tQ zGpuH2X)eOiZ+4)7geHZw2DmXXi4s5bzDTxu&YOR^P>h76Q`44z zJ>Qa~hmrwat~;ncmFl}fN_R8W+m9|!)m))}_H$$$a3qQN6$bjR(zr$sJ+0*aQpw4I zf7-q?G~2vNJWy+Wv;UVigk4|_tsb&oan)PN>2-;u3sVtGtnV__^8HcGgm84MIJ>{_ zFKV(nh4%iDUpTi85kCmK)Pg-Qh#$ihg>m~A@)i^N#87SD6rkx@vUqm{F?X(%J31}oT{;= z&sN1p&IK5msm-?Cwj6SDYaE%lc$KYIbFRtAt#RNB+=@p)D~O#UQcl~Fzd9X5^e1ruFG(eg-+`vbCmE0vFon`CdOI06iL%a5;f^X-|p zh63VJd{h3yH9qF_?Zu4-o%Yz+?aXhnca`7im^&ps?Y*u-KEd+u8`-{T2@u5s;YsyS!MA=fFoqG2nQ0T**;>NWZ6p3GPqHb%%H^+3wr=oO7-m-Xi@%DTvrT{g@p zOmJ>8?UlSQIrK#-19{+jIJF!dqK#d;&^(ixj;lNEoorK6ipvfs!^G%ViB4Pi@%P>d>te^!SXOB$Q>cSNsy;;K z^DL_c?mTFDEy7;Uz?atB7)CF0J!dcwkejisVyzvHf1wxrUvg|SmOIiBi2x*8iv^CwX}oL+Dfh6~8hLRRx_Pmd_SkIC{=h z>J0bQ?nakcDrUYL{ioF$I!|uv7qCvzVE9G7zUKww@@K`Zs&6NksHIyp*K(9%is(PF zS2mtZFYP586+V)B1sK}|O#zA-(xo5sk4!I9*AY>GM2aVHl^^y5034 zl(RL+i;<*We{PZKlw33!V}?!Ijh4kThe0d{@jo!{fcqC-TW;FDKrAgn57B{Eg?E<$ z8NF}%Z2YQbu#$#Lu?m@@@ii@Ei}(R{mqQ-J>B*hD#8OE#eBJ&MBH?azxZ^`-$%b8w z=btl8&Od&q4TTLa&i~Xr!M;`DG-!;#3T%aZZA?3Tqy-7}7*((xd(8at&yX~i=J3tS+h3#e;0c>e3FH_=L~npUj>4pr6liT?K6 z-F_(?(uEedk;%F3ZJI%Ae%Ye0>W7`5DLt=JoG}19DrW7h`-P-SIW^kEM*4r_-e?WE zZTT87f~2JGX(&R_JplQ8bFhkiMs-aqC-Vwm4lqtUKC!hmksfBtL1*P%4nMBvb$E20>11J8Vss9M!YVa7GWwgIB+`F<;q8Z2 z#@#w5g>+wijx=9&3nUwsf1W*_oQG?%_!0xn0|{sAb4`PNf_kJM$@i$?#wxXSsz8RW zO4Lo0SsqqN50SjLz!E^JsxU^9zNBL&v!<9he1}*No*sdNb6fTi@Ss8=yeJN{}mY%Y0^~m%iz~CCfNa>l|9C{;csP-sTp|LLiP&5gCK&) zDPGsyB|+%7eTvXDQ0HloX1{Kq@Y}K9>LrDIoFVW=o1!2hM+T^9%L&d-Fs8ku9I%S7 z2`VKJ)0p8YF~8(*JC9YLoU2XCJ=~QnX)_Wp*FP~M%TyN#Yr@;9#V9=iPU-{9O3^nP za5TYG8rUt>dC?aK%eS*C765u8h;4G&l_z#7QG~k*EOd8JB+`g2A%m7D&E$57-|vscH1aBCnH(G+HHWqhbeJTHne`*4x_pj@ z(txr%j-n)SGiWKCDtP}(o8D}YRgI@T2)QHReXpsOa0nS49tsPA8(g}TryIRTcoU{KoXw-V{{9UiA!e0w_CF11OD*CnwOUjR+{HN#nkVQB)v9as_)Nn)+=+RkdnsptUlzhE|D8%RTpNR;E4gx z&Qa@kcPl`vi6;XWjUe>YczYyg77eJ&Ljrnjh9$PS#d8HZukLBr%PFD!m_DsTA+8BZl3DQ4-q@O0D_SUMK||v!+jLnItoCACyXYe4?)2f|WV( zH^v&e)U;gRWBa9vn`4`gxtIO>`CB-l$E~K_z1;GS=Dp#a^VQmiC%X^lU+MC8i$5NY zH0faCJmh{X-y$sPxLx?f;j(`C|I>GbV&^1ukp6ZIqWy*rW1rPIO%8g^bBLcOJv#qiHwb1i^Cf=pm6$fcHL{ZN^4kozA&P>Im5<%VAc=Eh>C|PxhuSEH+c~tsi zkH@TrIN-O?H6Lc420xkwS7abmnbsiKmBJMb)?UQkc1rese}?cG@Lr){2X4}7>{T4X zi%TO!k@dXytc0YE3H*YC5zMQ?&T&lqgF(vNGD__K60n8sM=Yef>0qOksSh~($faRV^Q_;=fbs{BXV1?C{}>7<=qeT}uDmLzjO4GJaMpV#LqnxOy>#x!NTlk7ezU`DWsW_ zF6vv~wD398@0)5k3-Z8c*6eOW2bb8LpWQ}GhW;|ReGxwyaqQsT24|Fxzwjt$3Pbd{ zr#Fg@mJYC=Ud0rbdP3{Q<&0BM5A*B*6C6X^VDev+94Aud`wz}7k`BX=io3J;+}Gm6 znRDcvc_D*Rq@+vorS!H#@j>3;f;bFnP5;h$6y zzP;Z|w6`2}3VZYWt%lHM$n<|N#}=aU|G$10jP7xq@I E0K7>p*8l(j literal 0 HcmV?d00001 diff --git a/DownUnderCTF 2023/beginner/static file server/static-file-server/files/not_the_flag.txt b/DownUnderCTF 2023/beginner/static file server/static-file-server/files/not_the_flag.txt new file mode 100644 index 00000000..dad4f971 --- /dev/null +++ b/DownUnderCTF 2023/beginner/static file server/static-file-server/files/not_the_flag.txt @@ -0,0 +1 @@ +The real flag is at /flag.txt diff --git a/DownUnderCTF 2023/beginner/static file server/static-file-server/flag.txt b/DownUnderCTF 2023/beginner/static file server/static-file-server/flag.txt new file mode 100644 index 00000000..1da937dc --- /dev/null +++ b/DownUnderCTF 2023/beginner/static file server/static-file-server/flag.txt @@ -0,0 +1 @@ +FLAG diff --git a/HTB/Keeper/README.md b/HTB/Keeper/README.md index 812c4ac7..f60e8470 100644 --- a/HTB/Keeper/README.md +++ b/HTB/Keeper/README.md @@ -6,13 +6,3 @@ http: keeper.htb -> tickets.keeper.htb -> ssh access = user-flag -RT30000.zip -> KeePassDumpFull.dmp - -``` -└─$ file KeePassDumpFull.dmp -KeePassDumpFull.dmp: Mini DuMP crash report, 16 streams, Fri May 19 13:46:21 2023, 0x1806 type -``` - -KeePass Dumper: https://github.com/CMEPW/keepass-dump-masterkey - -#TODO diff --git a/HTB/admirer/ferox-http_admirer_htb b/HTB/admirer/ferox-http_admirer_htb new file mode 100644 index 00000000..e69de29b diff --git a/HTB/admirer/ferox-http_admirer_htb:80_-1674285271.state b/HTB/admirer/ferox-http_admirer_htb:80_-1674285271.state deleted file mode 100644 index c2b034ca..00000000 --- a/HTB/admirer/ferox-http_admirer_htb:80_-1674285271.state +++ /dev/null @@ -1 +0,0 @@ -{"scans":[{"id":"c944e8612b6940d389aa28227175265c","url":"http://admirer.htb:80/","normalized_url":"http://admirer.htb:80/","scan_type":"Directory","status":"Running","num_requests":1543857},{"id":"aa8a391eee2246939c142f08d29e6cef","url":"http://admirer.htb/admin-dir/","normalized_url":"http://admirer.htb/admin-dir/","scan_type":"Directory","status":"Running","num_requests":1543857},{"id":"2ee08e3f77884fe7ac1f52b2c6c488cf","url":"http://admirer.htb/","normalized_url":"http://admirer.htb/","scan_type":"Directory","status":"Running","num_requests":1543857},{"id":"25678b8101a94cc193280ad93c588bb2","url":"http://admirer.htb/images/","normalized_url":"http://admirer.htb/images/","scan_type":"Directory","status":"Running","num_requests":1543857},{"id":"baa4746c76ce45b0ae59005841d47b67","url":"http://admirer.htb/images/thumbs/thmb_eng02.jpg","normalized_url":"http://admirer.htb/images/thumbs/thmb_eng02.jpg/","scan_type":"File","status":"NotStarted","num_requests":1543857},{"id":"ad22ec03cb294eff944dbf95110829a8","url":"http://admirer.htb/images/thumbs/thmb_art01.jpg","normalized_url":"http://admirer.htb/images/thumbs/thmb_art01.jpg/","scan_type":"File","status":"NotStarted","num_requests":1543857},{"id":"65b1e7f02b934a259daa6a82ce01b234","url":"http://admirer.htb/images/fulls/art01.jpg","normalized_url":"http://admirer.htb/images/fulls/art01.jpg/","scan_type":"File","status":"NotStarted","num_requests":1543857},{"id":"7dfa8801e97a477aa88c417bdc841eb9","url":"http://admirer.htb/images/fulls/mus01.jpg","normalized_url":"http://admirer.htb/images/fulls/mus01.jpg/","scan_type":"File","status":"NotStarted","num_requests":1543857},{"id":"1218d4eba7b8457ea645c8d254b1493a","url":"http://admirer.htb/assets/js/util.js","normalized_url":"http://admirer.htb/assets/js/util.js/","scan_type":"File","status":"NotStarted","num_requests":1543857},{"id":"8d5c4d09e2c2447eb984e9968ba7db46","url":"http://admirer.htb/images/fulls/","normalized_url":"http://admirer.htb/images/fulls/","scan_type":"Directory","status":"Running","num_requests":1543857},{"id":"3d7977e6d1804d8b866ce03ec90ecc10","url":"http://admirer.htb/images/thumbs/thmb_mus01.jpg","normalized_url":"http://admirer.htb/images/thumbs/thmb_mus01.jpg/","scan_type":"File","status":"NotStarted","num_requests":1543857},{"id":"9260b8b2adbd4bb1a8c2366ee364d3dc","url":"http://admirer.htb/assets/","normalized_url":"http://admirer.htb/assets/","scan_type":"Directory","status":"Running","num_requests":1543857},{"id":"96f3e35206db4a6eb6466616a814fa02","url":"http://admirer.htb/images/thumbs/","normalized_url":"http://admirer.htb/images/thumbs/","scan_type":"Directory","status":"Running","num_requests":1543857},{"id":"666a016de3f5463681e7688ca81668da","url":"http://admirer.htb/images/images/","normalized_url":"http://admirer.htb/images/images/","scan_type":"File","status":"NotStarted","num_requests":1543857},{"id":"15f2d920b11e4603b3f2832d6822e65a","url":"http://admirer.htb/images/images/thumbs","normalized_url":"http://admirer.htb/images/images/thumbs/","scan_type":"File","status":"NotStarted","num_requests":1543857},{"id":"d31adae90f89474085aea1a17d040f43","url":"http://admirer.htb/images/thumbs/thmb_mus02.jpg","normalized_url":"http://admirer.htb/images/thumbs/thmb_mus02.jpg/","scan_type":"File","status":"NotStarted","num_requests":1543857},{"id":"39723b307fba454ba4acb0efd856c9fb","url":"http://admirer.htb/images/thumbs/thmb_arch01.jpg","normalized_url":"http://admirer.htb/images/thumbs/thmb_arch01.jpg/","scan_type":"File","status":"NotStarted","num_requests":1543857},{"id":"6611926759844bf48e6031399fe8988d","url":"http://admirer.htb/assets/css/main.css","normalized_url":"http://admirer.htb/assets/css/main.css/","scan_type":"File","status":"NotStarted","num_requests":1543857},{"id":"6da0e42e92d8487a9b8448111cbc270b","url":"http://admirer.htb/assets/js/breakpoints.min.js","normalized_url":"http://admirer.htb/assets/js/breakpoints.min.js/","scan_type":"File","status":"NotStarted","num_requests":1543857},{"id":"d774213ac07c485ab41ddbda2bbd32c8","url":"http://admirer.htb/images/thumbs/thmb_nat02.jpg","normalized_url":"http://admirer.htb/images/thumbs/thmb_nat02.jpg/","scan_type":"File","status":"NotStarted","num_requests":1543857},{"id":"b92c2bf59a7947a3bad10464c7ae8245","url":"http://admirer.htb/images/thumbs/thmb_mind02.jpg","normalized_url":"http://admirer.htb/images/thumbs/thmb_mind02.jpg/","scan_type":"File","status":"NotStarted","num_requests":1543857},{"id":"723c2314bbfc471cb6a48c87893addd1","url":"http://admirer.htb/images/fulls/nat01.jpg","normalized_url":"http://admirer.htb/images/fulls/nat01.jpg/","scan_type":"File","status":"NotStarted","num_requests":1543857},{"id":"bcd4e7ec83244720ae39721b4d7f4d47","url":"http://admirer.htb/images/fulls/mind02.jpg","normalized_url":"http://admirer.htb/images/fulls/mind02.jpg/","scan_type":"File","status":"NotStarted","num_requests":1543857},{"id":"72be096b0dbe4910a5a2a233cdcbc354","url":"http://admirer.htb/images/fulls/arch01.jpg","normalized_url":"http://admirer.htb/images/fulls/arch01.jpg/","scan_type":"File","status":"NotStarted","num_requests":1543857},{"id":"378645e098d642d4a1475cf56f7d1dde","url":"http://admirer.htb/images/thumbs/thmb_art02.jpg","normalized_url":"http://admirer.htb/images/thumbs/thmb_art02.jpg/","scan_type":"File","status":"NotStarted","num_requests":1543857},{"id":"83e65d29400e4a729c3c5b00e2dcd5a6","url":"http://admirer.htb/assets/js/","normalized_url":"http://admirer.htb/assets/js/","scan_type":"Directory","status":"Running","num_requests":1543857},{"id":"67001da93d5f4ae9bdff2b7180609e3f","url":"http://admirer.htb/images/fulls/mind01.jpg","normalized_url":"http://admirer.htb/images/fulls/mind01.jpg/","scan_type":"File","status":"NotStarted","num_requests":1543857},{"id":"92114846fbe144e499494f1766829e10","url":"http://admirer.htb/assets/assets/","normalized_url":"http://admirer.htb/assets/assets/","scan_type":"File","status":"NotStarted","num_requests":1543857},{"id":"12d08fc46fa04772bf7c03b8ab20d9f9","url":"http://admirer.htb/assets/assets/js","normalized_url":"http://admirer.htb/assets/assets/js/","scan_type":"File","status":"NotStarted","num_requests":1543857},{"id":"a3c5b238fd464a7e8818deb77b19ecfc","url":"http://admirer.htb/assets/js/main.js","normalized_url":"http://admirer.htb/assets/js/main.js/","scan_type":"File","status":"NotStarted","num_requests":1543857},{"id":"79296747138548c39f3d49b371140afa","url":"http://admirer.htb/images/thumbs/thmb_eng01.jpg","normalized_url":"http://admirer.htb/images/thumbs/thmb_eng01.jpg/","scan_type":"File","status":"NotStarted","num_requests":1543857},{"id":"f5588be7d6eb4db09dddf5c0cc17ad05","url":"http://admirer.htb/images/fulls/mus02.jpg","normalized_url":"http://admirer.htb/images/fulls/mus02.jpg/","scan_type":"File","status":"NotStarted","num_requests":1543857},{"id":"9ba8aca8d3a94f21905329fc97fe64ce","url":"http://admirer.htb/images/fulls/arch02.jpg","normalized_url":"http://admirer.htb/images/fulls/arch02.jpg/","scan_type":"File","status":"NotStarted","num_requests":1543857},{"id":"6dcef9e80922497493dfc1cf60e349f5","url":"http://admirer.htb/assets/css/","normalized_url":"http://admirer.htb/assets/css/","scan_type":"Directory","status":"Running","num_requests":1543857}],"config":{"type":"configuration","wordlist":"/usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt","config":"/etc/feroxbuster/ferox-config.toml","proxy":"","replay_proxy":"","target_url":"http://admirer.htb:80/","status_codes":[200,204,301,302,307,308,401,403,405,500],"replay_codes":[200,204,301,302,307,308,401,403,405,500],"filter_status":[],"threads":200,"timeout":7,"verbosity":1,"silent":false,"quiet":true,"auto_bail":false,"auto_tune":false,"json":false,"output":"/home/simon/htb/admirer/results/admirer.htb/scans/tcp80/tcp_80_http_feroxbuster_directory-list-2.3-medium.txt","debug_log":"","user_agent":"feroxbuster/2.7.3","random_agent":false,"redirects":false,"insecure":true,"extensions":["txt","html","php","asp","aspx","jsp"],"methods":["GET"],"data":[],"headers":{},"queries":[],"no_recursion":false,"extract_links":true,"add_slash":false,"stdin":false,"depth":4,"scan_limit":0,"parallel":0,"rate_limit":0,"filter_size":[],"filter_line_count":[],"filter_word_count":[],"filter_regex":[],"dont_filter":false,"resumed":false,"resume_from":"","save_state":true,"time_limit":"","filter_similar":[],"url_denylist":[],"regex_denylist":[],"collect_extensions":false,"dont_collect":["tif","tiff","ico","cur","bmp","webp","svg","png","jpg","jpeg","jfif","gif","avif","apng","pjpeg","pjp","mov","wav","mpg","mpeg","mp3","mp4","m4a","m4p","m4v","ogg","webm","ogv","oga","flac","aac","3gp","css","zip","xls","xml","gz","tgz"],"collect_backups":false,"collect_words":false,"force_recursion":false},"responses":[{"type":"response","url":"http://admirer.htb/admin-dir","original_url":"http://admirer.htb:80/","path":"/admin-dir","wildcard":false,"status":301,"method":"GET","content_length":314,"line_count":9,"word_count":28,"headers":{"server":"Apache/2.4.25 (Debian)","content-type":"text/html; charset=iso-8859-1","location":"http://admirer.htb/admin-dir/","date":"Sat, 21 Jan 2023 07:13:28 GMT","content-length":"314"},"extension":""},{"type":"response","url":"http://admirer.htb/images","original_url":"http://admirer.htb:80/","path":"/images","wildcard":false,"status":301,"method":"GET","content_length":311,"line_count":9,"word_count":28,"headers":{"server":"Apache/2.4.25 (Debian)","content-length":"311","location":"http://admirer.htb/images/","date":"Sat, 21 Jan 2023 07:13:28 GMT","content-type":"text/html; charset=iso-8859-1"},"extension":""},{"type":"response","url":"http://admirer.htb/images/thumbs/thmb_eng02.jpg","original_url":"http://admirer.htb/images/thumbs/thmb_eng02.jpg","path":"/images/thumbs/thmb_eng02.jpg","wildcard":false,"status":200,"method":"GET","content_length":42049,"line_count":128,"word_count":808,"headers":{"accept-ranges":"bytes","etag":"\"a441-598bd97c40480\"","last-modified":"Mon, 02 Dec 2019 19:29:06 GMT","content-length":"42049","date":"Sat, 21 Jan 2023 07:13:29 GMT","server":"Apache/2.4.25 (Debian)","content-type":"image/jpeg"},"extension":""},{"type":"response","url":"http://admirer.htb/images/thumbs/thmb_art01.jpg","original_url":"http://admirer.htb/images/thumbs/thmb_art01.jpg","path":"/images/thumbs/thmb_art01.jpg","wildcard":false,"status":200,"method":"GET","content_length":79221,"line_count":181,"word_count":1429,"headers":{"last-modified":"Mon, 02 Dec 2019 19:23:36 GMT","content-length":"79221","server":"Apache/2.4.25 (Debian)","etag":"\"13575-598bd84189e00\"","content-type":"image/jpeg","date":"Sat, 21 Jan 2023 07:13:29 GMT","accept-ranges":"bytes"},"extension":""},{"type":"response","url":"http://admirer.htb/images/fulls/art01.jpg","original_url":"http://admirer.htb/images/fulls/art01.jpg","path":"/images/fulls/art01.jpg","wildcard":false,"status":200,"method":"GET","content_length":146980,"line_count":440,"word_count":2890,"headers":{"accept-ranges":"bytes","content-length":"146980","content-type":"image/jpeg","server":"Apache/2.4.25 (Debian)","date":"Sat, 21 Jan 2023 07:13:30 GMT","etag":"\"23e24-598bd800b0500\"","last-modified":"Mon, 02 Dec 2019 19:22:28 GMT"},"extension":""},{"type":"response","url":"http://admirer.htb/images/fulls/mus01.jpg","original_url":"http://admirer.htb/images/fulls/mus01.jpg","path":"/images/fulls/mus01.jpg","wildcard":false,"status":200,"method":"GET","content_length":292305,"line_count":1154,"word_count":5907,"headers":{"server":"Apache/2.4.25 (Debian)","accept-ranges":"bytes","content-length":"292305","last-modified":"Mon, 02 Dec 2019 19:43:58 GMT","content-type":"image/jpeg","date":"Sat, 21 Jan 2023 07:13:30 GMT","etag":"\"475d1-598bdcceedb80\""},"extension":""},{"type":"response","url":"http://admirer.htb/assets/js/util.js","original_url":"http://admirer.htb/assets/js/util.js","path":"/assets/js/util.js","wildcard":false,"status":200,"method":"GET","content_length":12433,"line_count":587,"word_count":1232,"headers":{"server":"Apache/2.4.25 (Debian)","date":"Sat, 21 Jan 2023 07:13:31 GMT","content-length":"12433","last-modified":"Thu, 06 Jun 2019 21:17:00 GMT","accept-ranges":"bytes","etag":"\"3091-58aae3c0d4b00\"","content-type":"application/javascript","vary":"Accept-Encoding"},"extension":""},{"type":"response","url":"http://admirer.htb/.html","original_url":"http://admirer.htb/images","path":"/.html","wildcard":false,"status":403,"method":"GET","content_length":276,"line_count":9,"word_count":28,"headers":{"server":"Apache/2.4.25 (Debian)","content-length":"276","date":"Sat, 21 Jan 2023 07:13:31 GMT","content-type":"text/html; charset=iso-8859-1"},"extension":""},{"type":"response","url":"http://admirer.htb/.php","original_url":"http://admirer.htb/images","path":"/.php","wildcard":false,"status":403,"method":"GET","content_length":276,"line_count":9,"word_count":28,"headers":{"content-type":"text/html; charset=iso-8859-1","content-length":"276","server":"Apache/2.4.25 (Debian)","date":"Sat, 21 Jan 2023 07:13:31 GMT"},"extension":""},{"type":"response","url":"http://admirer.htb/images/thumbs/thmb_mus01.jpg","original_url":"http://admirer.htb/images/thumbs/thmb_mus01.jpg","path":"/images/thumbs/thmb_mus01.jpg","wildcard":false,"status":200,"method":"GET","content_length":60663,"line_count":281,"word_count":1437,"headers":{"accept-ranges":"bytes","content-length":"60663","content-type":"image/jpeg","server":"Apache/2.4.25 (Debian)","date":"Sat, 21 Jan 2023 07:13:31 GMT","last-modified":"Mon, 02 Dec 2019 19:44:58 GMT","etag":"\"ecf7-598bdd0826280\""},"extension":""},{"type":"response","url":"http://admirer.htb/images/fulls/","original_url":"http://admirer.htb/images/fulls/","path":"/images/fulls/","wildcard":false,"status":403,"method":"GET","content_length":276,"line_count":9,"word_count":28,"headers":{"server":"Apache/2.4.25 (Debian)","content-type":"text/html; charset=iso-8859-1","date":"Sat, 21 Jan 2023 07:13:32 GMT","content-length":"276"},"extension":""},{"type":"response","url":"http://admirer.htb/assets","original_url":"http://admirer.htb/","path":"/assets","wildcard":false,"status":301,"method":"GET","content_length":311,"line_count":9,"word_count":28,"headers":{"content-length":"311","content-type":"text/html; charset=iso-8859-1","server":"Apache/2.4.25 (Debian)","location":"http://admirer.htb/assets/","date":"Sat, 21 Jan 2023 07:13:32 GMT"},"extension":""},{"type":"response","url":"http://admirer.htb/images/fulls/.html","original_url":"http://admirer.htb/images/fulls/","path":"/images/fulls/.html","wildcard":false,"status":403,"method":"GET","content_length":276,"line_count":9,"word_count":28,"headers":{"date":"Sat, 21 Jan 2023 07:13:32 GMT","content-length":"276","server":"Apache/2.4.25 (Debian)","content-type":"text/html; charset=iso-8859-1"},"extension":""},{"type":"response","url":"http://admirer.htb/images/fulls/.php","original_url":"http://admirer.htb/images/fulls/","path":"/images/fulls/.php","wildcard":false,"status":403,"method":"GET","content_length":276,"line_count":9,"word_count":28,"headers":{"content-length":"276","date":"Sat, 21 Jan 2023 07:13:32 GMT","server":"Apache/2.4.25 (Debian)","content-type":"text/html; charset=iso-8859-1"},"extension":""},{"type":"response","url":"http://admirer.htb/admin-dir/contacts.txt","original_url":"http://admirer.htb/admin-dir","path":"/admin-dir/contacts.txt","wildcard":false,"status":200,"method":"GET","content_length":350,"line_count":29,"word_count":39,"headers":{"etag":"\"15e-5a46a6ec54540\"","accept-ranges":"bytes","content-length":"350","date":"Sat, 21 Jan 2023 07:13:33 GMT","server":"Apache/2.4.25 (Debian)","vary":"Accept-Encoding","content-type":"text/plain","last-modified":"Wed, 29 Apr 2020 09:18:35 GMT"},"extension":""},{"type":"response","url":"http://admirer.htb/images/thumbs","original_url":"http://admirer.htb/images","path":"/images/thumbs","wildcard":false,"status":301,"method":"GET","content_length":318,"line_count":9,"word_count":28,"headers":{"server":"Apache/2.4.25 (Debian)","content-type":"text/html; charset=iso-8859-1","date":"Sat, 21 Jan 2023 07:13:38 GMT","content-length":"318","location":"http://admirer.htb/images/thumbs/"},"extension":""},{"type":"response","url":"http://admirer.htb/images/.html","original_url":"http://admirer.htb/images/thumbs","path":"/images/.html","wildcard":false,"status":403,"method":"GET","content_length":276,"line_count":9,"word_count":28,"headers":{"content-type":"text/html; charset=iso-8859-1","server":"Apache/2.4.25 (Debian)","date":"Sat, 21 Jan 2023 07:13:38 GMT","content-length":"276"},"extension":""},{"type":"response","url":"http://admirer.htb/images/.php","original_url":"http://admirer.htb/images/thumbs","path":"/images/.php","wildcard":false,"status":403,"method":"GET","content_length":276,"line_count":9,"word_count":28,"headers":{"content-length":"276","server":"Apache/2.4.25 (Debian)","date":"Sat, 21 Jan 2023 07:13:38 GMT","content-type":"text/html; charset=iso-8859-1"},"extension":""},{"type":"response","url":"http://admirer.htb/images/thumbs/thmb_mus02.jpg","original_url":"http://admirer.htb/images/thumbs/thmb_mus02.jpg","path":"/images/thumbs/thmb_mus02.jpg","wildcard":false,"status":200,"method":"GET","content_length":87151,"line_count":173,"word_count":1521,"headers":{"server":"Apache/2.4.25 (Debian)","content-length":"87151","etag":"\"1546f-598bdd954af80\"","accept-ranges":"bytes","content-type":"image/jpeg","last-modified":"Mon, 02 Dec 2019 19:47:26 GMT","date":"Sat, 21 Jan 2023 07:13:38 GMT"},"extension":""},{"type":"response","url":"http://admirer.htb/images/thumbs/thmb_arch01.jpg","original_url":"http://admirer.htb/images/thumbs/thmb_arch01.jpg","path":"/images/thumbs/thmb_arch01.jpg","wildcard":false,"status":200,"method":"GET","content_length":117848,"line_count":241,"word_count":2097,"headers":{"accept-ranges":"bytes","server":"Apache/2.4.25 (Debian)","etag":"\"1cc58-598bd7bc06300\"","content-length":"117848","content-type":"image/jpeg","last-modified":"Mon, 02 Dec 2019 19:21:16 GMT","date":"Sat, 21 Jan 2023 07:13:38 GMT"},"extension":""},{"type":"response","url":"http://admirer.htb/assets/css/main.css","original_url":"http://admirer.htb/assets/css/main.css","path":"/assets/css/main.css","wildcard":false,"status":200,"method":"GET","content_length":44147,"line_count":2050,"word_count":4273,"headers":{"vary":"Accept-Encoding","date":"Sat, 21 Jan 2023 07:13:39 GMT","etag":"\"ac73-58aae3c0d4b00\"","accept-ranges":"bytes","content-length":"44147","server":"Apache/2.4.25 (Debian)","last-modified":"Thu, 06 Jun 2019 21:17:00 GMT","content-type":"text/css"},"extension":""},{"type":"response","url":"http://admirer.htb/assets/js/breakpoints.min.js","original_url":"http://admirer.htb/assets/js/breakpoints.min.js","path":"/assets/js/breakpoints.min.js","wildcard":false,"status":200,"method":"GET","content_length":2439,"line_count":2,"word_count":87,"headers":{"content-type":"application/javascript","vary":"Accept-Encoding","etag":"\"987-58aae3c0d4b00\"","content-length":"2439","last-modified":"Thu, 06 Jun 2019 21:17:00 GMT","accept-ranges":"bytes","date":"Sat, 21 Jan 2023 07:13:39 GMT","server":"Apache/2.4.25 (Debian)"},"extension":""},{"type":"response","url":"http://admirer.htb/images/thumbs/thmb_nat02.jpg","original_url":"http://admirer.htb/images/thumbs/thmb_nat02.jpg","path":"/images/thumbs/thmb_nat02.jpg","wildcard":false,"status":200,"method":"GET","content_length":120238,"line_count":240,"word_count":2194,"headers":{"server":"Apache/2.4.25 (Debian)","content-type":"image/jpeg","content-length":"120238","date":"Sat, 21 Jan 2023 07:13:39 GMT","accept-ranges":"bytes","last-modified":"Mon, 02 Dec 2019 19:51:08 GMT","etag":"\"1d5ae-598bde6902300\""},"extension":""},{"type":"response","url":"http://admirer.htb/images/thumbs/thmb_mind02.jpg","original_url":"http://admirer.htb/images/thumbs/thmb_mind02.jpg","path":"/images/thumbs/thmb_mind02.jpg","wildcard":false,"status":200,"method":"GET","content_length":58053,"line_count":230,"word_count":1300,"headers":{"server":"Apache/2.4.25 (Debian)","last-modified":"Mon, 02 Dec 2019 19:42:56 GMT","date":"Sat, 21 Jan 2023 07:13:39 GMT","etag":"\"e2c5-598bdc93cd000\"","accept-ranges":"bytes","content-type":"image/jpeg","content-length":"58053"},"extension":""},{"type":"response","url":"http://admirer.htb/images/fulls/nat01.jpg","original_url":"http://admirer.htb/images/fulls/nat01.jpg","path":"/images/fulls/nat01.jpg","wildcard":false,"status":200,"method":"GET","content_length":262596,"line_count":1300,"word_count":5571,"headers":{"date":"Sat, 21 Jan 2023 07:13:40 GMT","etag":"\"401c4-598bddc8ca900\"","last-modified":"Mon, 02 Dec 2019 19:48:20 GMT","accept-ranges":"bytes","server":"Apache/2.4.25 (Debian)","content-length":"262596","content-type":"image/jpeg"},"extension":""},{"type":"response","url":"http://admirer.htb/images/fulls/mind02.jpg","original_url":"http://admirer.htb/images/fulls/mind02.jpg","path":"/images/fulls/mind02.jpg","wildcard":false,"status":200,"method":"GET","content_length":91128,"line_count":409,"word_count":2427,"headers":{"content-type":"image/jpeg","content-length":"91128","server":"Apache/2.4.25 (Debian)","date":"Sat, 21 Jan 2023 07:13:40 GMT","last-modified":"Mon, 02 Dec 2019 19:41:34 GMT","accept-ranges":"bytes","etag":"\"163f8-598bdc4599780\""},"extension":""},{"type":"response","url":"http://admirer.htb/images/fulls/arch01.jpg","original_url":"http://admirer.htb/images/fulls/arch01.jpg","path":"/images/fulls/arch01.jpg","wildcard":false,"status":200,"method":"GET","content_length":193360,"line_count":876,"word_count":4293,"headers":{"content-length":"193360","accept-ranges":"bytes","etag":"\"2f350-598bd76a02180\"","last-modified":"Mon, 02 Dec 2019 19:19:50 GMT","date":"Sat, 21 Jan 2023 07:13:40 GMT","content-type":"image/jpeg","server":"Apache/2.4.25 (Debian)"},"extension":""},{"type":"response","url":"http://admirer.htb/images/thumbs/thmb_art02.jpg","original_url":"http://admirer.htb/images/thumbs/thmb_art02.jpg","path":"/images/thumbs/thmb_art02.jpg","wildcard":false,"status":200,"method":"GET","content_length":61571,"line_count":204,"word_count":1299,"headers":{"content-type":"image/jpeg","last-modified":"Mon, 02 Dec 2019 19:24:50 GMT","accept-ranges":"bytes","etag":"\"f083-598bd8881c480\"","server":"Apache/2.4.25 (Debian)","date":"Sat, 21 Jan 2023 07:13:40 GMT","content-length":"61571"},"extension":""},{"type":"response","url":"http://admirer.htb/images/fulls/mind01.jpg","original_url":"http://admirer.htb/images/fulls/mind01.jpg","path":"/images/fulls/mind01.jpg","wildcard":false,"status":200,"method":"GET","content_length":637125,"line_count":1435,"word_count":11709,"headers":{"content-type":"image/jpeg","server":"Apache/2.4.25 (Debian)","last-modified":"Mon, 02 Dec 2019 19:37:44 GMT","etag":"\"9b8c5-598bdb6a41200\"","content-length":"637125","date":"Sat, 21 Jan 2023 07:13:41 GMT","accept-ranges":"bytes"},"extension":""},{"type":"response","url":"http://admirer.htb/assets/js","original_url":"http://admirer.htb/assets","path":"/assets/js","wildcard":false,"status":301,"method":"GET","content_length":314,"line_count":9,"word_count":28,"headers":{"location":"http://admirer.htb/assets/js/","content-length":"314","server":"Apache/2.4.25 (Debian)","content-type":"text/html; charset=iso-8859-1","date":"Sat, 21 Jan 2023 07:13:41 GMT"},"extension":""},{"type":"response","url":"http://admirer.htb/assets/js/main.js","original_url":"http://admirer.htb/assets/js/main.js","path":"/assets/js/main.js","wildcard":false,"status":200,"method":"GET","content_length":6107,"line_count":281,"word_count":537,"headers":{"date":"Sat, 21 Jan 2023 07:13:41 GMT","vary":"Accept-Encoding","content-type":"application/javascript","etag":"\"17db-58aae3c0d4b00\"","last-modified":"Thu, 06 Jun 2019 21:17:00 GMT","server":"Apache/2.4.25 (Debian)","content-length":"6107","accept-ranges":"bytes"},"extension":""},{"type":"response","url":"http://admirer.htb/images/thumbs/thmb_eng01.jpg","original_url":"http://admirer.htb/images/thumbs/thmb_eng01.jpg","path":"/images/thumbs/thmb_eng01.jpg","wildcard":false,"status":200,"method":"GET","content_length":100866,"line_count":195,"word_count":1798,"headers":{"last-modified":"Mon, 02 Dec 2019 19:26:10 GMT","content-type":"image/jpeg","etag":"\"18a02-598bd8d467880\"","content-length":"100866","accept-ranges":"bytes","date":"Sat, 21 Jan 2023 07:13:41 GMT","server":"Apache/2.4.25 (Debian)"},"extension":""},{"type":"response","url":"http://admirer.htb/assets/.html","original_url":"http://admirer.htb/assets/js","path":"/assets/.html","wildcard":false,"status":403,"method":"GET","content_length":276,"line_count":9,"word_count":28,"headers":{"date":"Sat, 21 Jan 2023 07:13:41 GMT","content-type":"text/html; charset=iso-8859-1","server":"Apache/2.4.25 (Debian)","content-length":"276"},"extension":""},{"type":"response","url":"http://admirer.htb/assets/.php","original_url":"http://admirer.htb/assets/js","path":"/assets/.php","wildcard":false,"status":403,"method":"GET","content_length":276,"line_count":9,"word_count":28,"headers":{"server":"Apache/2.4.25 (Debian)","date":"Sat, 21 Jan 2023 07:13:41 GMT","content-length":"276","content-type":"text/html; charset=iso-8859-1"},"extension":""},{"type":"response","url":"http://admirer.htb/images/fulls/mus02.jpg","original_url":"http://admirer.htb/images/fulls/mus02.jpg","path":"/images/fulls/mus02.jpg","wildcard":false,"status":200,"method":"GET","content_length":294837,"line_count":582,"word_count":4456,"headers":{"accept-ranges":"bytes","date":"Sat, 21 Jan 2023 07:13:41 GMT","last-modified":"Mon, 02 Dec 2019 19:46:48 GMT","content-length":"294837","server":"Apache/2.4.25 (Debian)","etag":"\"47fb5-598bdd710da00\"","content-type":"image/jpeg"},"extension":""},{"type":"response","url":"http://admirer.htb/images/fulls/arch02.jpg","original_url":"http://admirer.htb/images/fulls/arch02.jpg","path":"/images/fulls/arch02.jpg","wildcard":false,"status":200,"method":"GET","content_length":133131,"line_count":674,"word_count":2692,"headers":{"server":"Apache/2.4.25 (Debian)","last-modified":"Mon, 02 Dec 2019 19:21:24 GMT","content-length":"133131","accept-ranges":"bytes","content-type":"image/jpeg","etag":"\"2080b-598bd7c3a7500\"","date":"Sat, 21 Jan 2023 07:13:42 GMT"},"extension":""},{"type":"response","url":"http://admirer.htb/","original_url":"http://admirer.htb:80/","path":"/","wildcard":false,"status":200,"method":"GET","content_length":6051,"line_count":153,"word_count":529,"headers":{"server":"Apache/2.4.25 (Debian)","content-type":"text/html; charset=UTF-8","date":"Sat, 21 Jan 2023 07:13:28 GMT","vary":"Accept-Encoding","content-length":"6051"},"extension":""},{"type":"response","url":"http://admirer.htb/assets/css","original_url":"http://admirer.htb/assets","path":"/assets/css","wildcard":false,"status":301,"method":"GET","content_length":315,"line_count":9,"word_count":28,"headers":{"server":"Apache/2.4.25 (Debian)","date":"Sat, 21 Jan 2023 07:13:44 GMT","location":"http://admirer.htb/assets/css/","content-length":"315","content-type":"text/html; charset=iso-8859-1"},"extension":""}],"statistics":{"type":"statistics","timeouts":7213,"requests":216419,"expected_per_scan":1543857,"total_expected":13895105,"errors":70834,"successes":27,"redirects":13,"client_errors":145545,"server_errors":0,"total_scans":9,"initial_targets":0,"links_extracted":56,"extensions_collected":0,"status_200s":27,"status_301s":13,"status_302s":0,"status_401s":0,"status_403s":20,"status_429s":0,"status_500s":0,"status_503s":0,"status_504s":0,"status_508s":0,"wildcards_filtered":0,"responses_filtered":0,"resources_discovered":38,"url_format_errors":0,"redirection_errors":0,"connection_errors":63621,"request_errors":0,"directory_scan_times":[],"total_runtime":[0.0]},"collected_extensions":[],"filters":[]} \ No newline at end of file diff --git a/HTB/agile/ferox-http_agile_htb b/HTB/agile/ferox-http_agile_htb new file mode 100644 index 00000000..e69de29b diff --git a/HTB/agile/ferox-http_agile_htb:80_-1678019995.state b/HTB/agile/ferox-http_agile_htb:80_-1678019995.state deleted file mode 100644 index 8cef8b7f..00000000 --- a/HTB/agile/ferox-http_agile_htb:80_-1678019995.state +++ /dev/null @@ -1 +0,0 @@ -{"scans":[{"id":"4f365a5c329a4e3d9c5219eeec5c69b9","url":"http://agile.htb:80/","normalized_url":"http://agile.htb:80/","scan_type":"Directory","status":"Running","num_requests":833000}],"config":{"type":"configuration","wordlist":"/root/.local/share/AutoRecon/wordlists/dirbuster.txt","config":"/etc/feroxbuster/ferox-config.toml","proxy":"","replay_proxy":"","target_url":"http://agile.htb:80/","status_codes":[200,204,301,302,307,308,401,403,405,500],"replay_codes":[200,204,301,302,307,308,401,403,405,500],"filter_status":[],"threads":10,"timeout":7,"verbosity":1,"silent":false,"quiet":true,"auto_bail":false,"auto_tune":false,"json":false,"output":"/home/simon/htb/agile/results/agile.htb/scans/tcp80/tcp_80_http_feroxbuster_dirbuster.txt","debug_log":"","user_agent":"feroxbuster/2.7.3","random_agent":false,"redirects":false,"insecure":true,"extensions":["txt","html","php","asp","aspx","jsp"],"methods":["GET"],"data":[],"headers":{},"queries":[],"no_recursion":true,"extract_links":true,"add_slash":false,"stdin":false,"depth":4,"scan_limit":0,"parallel":0,"rate_limit":0,"filter_size":[],"filter_line_count":[],"filter_word_count":[],"filter_regex":[],"dont_filter":false,"resumed":false,"resume_from":"","save_state":true,"time_limit":"","filter_similar":[],"url_denylist":[],"regex_denylist":[],"collect_extensions":false,"dont_collect":["tif","tiff","ico","cur","bmp","webp","svg","png","jpg","jpeg","jfif","gif","avif","apng","pjpeg","pjp","mov","wav","mpg","mpeg","mp3","mp4","m4a","m4p","m4v","ogg","webm","ogv","oga","flac","aac","3gp","css","zip","xls","xml","gz","tgz"],"collect_backups":false,"collect_words":false,"force_recursion":false},"responses":[{"type":"response","url":"http://agile.htb/","original_url":"http://agile.htb:80/","path":"/","wildcard":false,"status":200,"method":"GET","content_length":612,"line_count":25,"word_count":69,"headers":{"connection":"keep-alive","date":"Sun, 05 Mar 2023 11:57:58 GMT","content-length":"612","last-modified":"Thu, 01 Dec 2022 18:20:40 GMT","content-type":"text/html","server":"nginx/1.18.0 (Ubuntu)","accept-ranges":"bytes","etag":"\"6388f078-264\""},"extension":""}],"statistics":{"type":"statistics","timeouts":0,"requests":193535,"expected_per_scan":833000,"total_expected":833000,"errors":0,"successes":3,"redirects":0,"client_errors":193532,"server_errors":0,"total_scans":1,"initial_targets":0,"links_extracted":0,"extensions_collected":0,"status_200s":3,"status_301s":0,"status_302s":0,"status_401s":0,"status_403s":0,"status_429s":0,"status_500s":0,"status_503s":0,"status_504s":0,"status_508s":0,"wildcards_filtered":0,"responses_filtered":0,"resources_discovered":1,"url_format_errors":0,"redirection_errors":0,"connection_errors":0,"request_errors":0,"directory_scan_times":[],"total_runtime":[0.0]},"collected_extensions":[],"filters":[]} \ No newline at end of file diff --git a/HTB/awkward/ferox-http_awkward_htb b/HTB/awkward/ferox-http_awkward_htb new file mode 100644 index 00000000..e69de29b diff --git a/HTB/awkward/ferox-http_awkward_htb:80_-1675808288.state b/HTB/awkward/ferox-http_awkward_htb:80_-1675808288.state deleted file mode 100644 index 8a492474..00000000 --- a/HTB/awkward/ferox-http_awkward_htb:80_-1675808288.state +++ /dev/null @@ -1 +0,0 @@ -{"scans":[{"id":"d7aaa3dde5404e86a522802fd6c4a9c2","url":"http://awkward.htb:80/","normalized_url":"http://awkward.htb:80/","scan_type":"Directory","status":"Running","num_requests":833000}],"config":{"type":"configuration","wordlist":"/root/.local/share/AutoRecon/wordlists/dirbuster.txt","config":"/etc/feroxbuster/ferox-config.toml","proxy":"","replay_proxy":"","target_url":"http://awkward.htb:80/","status_codes":[200,204,301,302,307,308,401,403,405,500],"replay_codes":[200,204,301,302,307,308,401,403,405,500],"filter_status":[],"threads":10,"timeout":7,"verbosity":1,"silent":false,"quiet":true,"auto_bail":false,"auto_tune":false,"json":false,"output":"/home/kali/htb/awkward/results/awkward.htb/scans/tcp80/tcp_80_http_feroxbuster_dirbuster.txt","debug_log":"","user_agent":"feroxbuster/2.7.3","random_agent":false,"redirects":false,"insecure":true,"extensions":["txt","html","php","asp","aspx","jsp"],"methods":["GET"],"data":[],"headers":{},"queries":[],"no_recursion":true,"extract_links":true,"add_slash":false,"stdin":false,"depth":4,"scan_limit":0,"parallel":0,"rate_limit":0,"filter_size":[],"filter_line_count":[],"filter_word_count":[],"filter_regex":[],"dont_filter":false,"resumed":false,"resume_from":"","save_state":true,"time_limit":"","filter_similar":[],"url_denylist":[],"regex_denylist":[],"collect_extensions":false,"dont_collect":["tif","tiff","ico","cur","bmp","webp","svg","png","jpg","jpeg","jfif","gif","avif","apng","pjpeg","pjp","mov","wav","mpg","mpeg","mp3","mp4","m4a","m4p","m4v","ogg","webm","ogv","oga","flac","aac","3gp","css","zip","xls","xml","gz","tgz"],"collect_backups":false,"collect_words":false,"force_recursion":false},"responses":[{"type":"response","url":"http://awkward.htb/","original_url":"http://awkward.htb:80/","path":"/","wildcard":false,"status":200,"method":"GET","content_length":132,"line_count":8,"word_count":13,"headers":{"content-type":"text/html","etag":"\"63231b83-84\"","accept-ranges":"bytes","content-length":"132","connection":"keep-alive","last-modified":"Thu, 15 Sep 2022 12:33:07 GMT","server":"nginx/1.18.0 (Ubuntu)","date":"Tue, 07 Feb 2023 22:18:04 GMT"},"extension":""}],"statistics":{"type":"statistics","timeouts":0,"requests":1424,"expected_per_scan":833000,"total_expected":833000,"errors":0,"successes":3,"redirects":0,"client_errors":1421,"server_errors":0,"total_scans":1,"initial_targets":0,"links_extracted":0,"extensions_collected":0,"status_200s":3,"status_301s":0,"status_302s":0,"status_401s":0,"status_403s":0,"status_429s":0,"status_500s":0,"status_503s":0,"status_504s":0,"status_508s":0,"wildcards_filtered":0,"responses_filtered":0,"resources_discovered":1,"url_format_errors":0,"redirection_errors":0,"connection_errors":0,"request_errors":0,"directory_scan_times":[],"total_runtime":[0.0]},"collected_extensions":[],"filters":[]} \ No newline at end of file diff --git a/HTB/awkward/ferox-http_hat-valley_htb b/HTB/awkward/ferox-http_hat-valley_htb new file mode 100644 index 00000000..e69de29b diff --git a/HTB/awkward/ferox-http_hat-valley_htb:80_-1675809555.state b/HTB/awkward/ferox-http_hat-valley_htb:80_-1675809555.state deleted file mode 100644 index 8de63f5f..00000000 --- a/HTB/awkward/ferox-http_hat-valley_htb:80_-1675809555.state +++ /dev/null @@ -1 +0,0 @@ -{"scans":[{"id":"59caa8239f8145ada48e8e678ee80d50","url":"http://hat-valley.htb:80/","normalized_url":"http://hat-valley.htb:80/","scan_type":"Directory","status":"Running","num_requests":833000}],"config":{"type":"configuration","wordlist":"/root/.local/share/AutoRecon/wordlists/dirbuster.txt","config":"/etc/feroxbuster/ferox-config.toml","proxy":"","replay_proxy":"","target_url":"http://hat-valley.htb:80/","status_codes":[200,204,301,302,307,308,401,403,405,500],"replay_codes":[200,204,301,302,307,308,401,403,405,500],"filter_status":[],"threads":10,"timeout":7,"verbosity":1,"silent":false,"quiet":true,"auto_bail":false,"auto_tune":false,"json":false,"output":"/home/kali/htb/awkward/results/hat-valley.htb/scans/tcp80/tcp_80_http_feroxbuster_dirbuster.txt","debug_log":"","user_agent":"feroxbuster/2.7.3","random_agent":false,"redirects":false,"insecure":true,"extensions":["txt","html","php","asp","aspx","jsp"],"methods":["GET"],"data":[],"headers":{},"queries":[],"no_recursion":true,"extract_links":true,"add_slash":false,"stdin":false,"depth":4,"scan_limit":0,"parallel":0,"rate_limit":0,"filter_size":[],"filter_line_count":[],"filter_word_count":[],"filter_regex":[],"dont_filter":false,"resumed":false,"resume_from":"","save_state":true,"time_limit":"","filter_similar":[],"url_denylist":[],"regex_denylist":[],"collect_extensions":false,"dont_collect":["tif","tiff","ico","cur","bmp","webp","svg","png","jpg","jpeg","jfif","gif","avif","apng","pjpeg","pjp","mov","wav","mpg","mpeg","mp3","mp4","m4a","m4p","m4v","ogg","webm","ogv","oga","flac","aac","3gp","css","zip","xls","xml","gz","tgz"],"collect_backups":false,"collect_words":false,"force_recursion":false},"responses":[{"type":"response","url":"http://hat-valley.htb/d24d1944513e4b5d8b7f4f60bcb0210e","original_url":"http://hat-valley.htb:80/","path":"/d24d1944513e4b5d8b7f4f60bcb0210e","wildcard":true,"status":200,"method":"GET","content_length":2881,"line_count":54,"word_count":163,"headers":{"etag":"W/\"b41-tn8t3x3qcvcm126OQ/i0AXwBj8M\"","content-type":"text/html; charset=UTF-8","server":"nginx/1.18.0 (Ubuntu)","content-length":"2881","date":"Tue, 07 Feb 2023 22:19:14 GMT","accept-ranges":"bytes","x-powered-by":"Express","connection":"keep-alive"},"extension":""},{"type":"response","url":"http://hat-valley.htb/css","original_url":"http://hat-valley.htb:80/","path":"/css","wildcard":false,"status":301,"method":"GET","content_length":173,"line_count":10,"word_count":16,"headers":{"date":"Tue, 07 Feb 2023 22:21:47 GMT","connection":"keep-alive","server":"nginx/1.18.0 (Ubuntu)","content-security-policy":"default-src 'none'","x-powered-by":"Express","content-type":"text/html; charset=UTF-8","x-content-type-options":"nosniff","location":"/css/","content-length":"173"},"extension":""},{"type":"response","url":"http://hat-valley.htb/favicon.ico","original_url":"http://hat-valley.htb:80/","path":"/favicon.ico","wildcard":false,"status":200,"method":"GET","content_length":4286,"line_count":1,"word_count":35,"headers":{"date":"Tue, 07 Feb 2023 22:22:44 GMT","accept-ranges":"bytes","x-powered-by":"Express","server":"nginx/1.18.0 (Ubuntu)","content-type":"image/vnd.microsoft.icon; charset=UTF-8","connection":"keep-alive","content-length":"4286","etag":"W/\"10be-wGBe/tk27iYAKE5kgFIdBvpk+HI\""},"extension":""},{"type":"response","url":"http://hat-valley.htb/js","original_url":"http://hat-valley.htb:80/","path":"/js","wildcard":false,"status":301,"method":"GET","content_length":171,"line_count":10,"word_count":16,"headers":{"connection":"keep-alive","content-length":"171","date":"Tue, 07 Feb 2023 22:23:01 GMT","location":"/js/","content-type":"text/html; charset=UTF-8","x-powered-by":"Express","content-security-policy":"default-src 'none'","x-content-type-options":"nosniff","server":"nginx/1.18.0 (Ubuntu)"},"extension":""},{"type":"response","url":"http://hat-valley.htb/static","original_url":"http://hat-valley.htb:80/","path":"/static","wildcard":false,"status":301,"method":"GET","content_length":179,"line_count":10,"word_count":16,"headers":{"content-security-policy":"default-src 'none'","server":"nginx/1.18.0 (Ubuntu)","connection":"keep-alive","date":"Tue, 07 Feb 2023 22:23:37 GMT","content-type":"text/html; charset=UTF-8","content-length":"179","x-powered-by":"Express","x-content-type-options":"nosniff","location":"/static/"},"extension":""}],"statistics":{"type":"statistics","timeouts":0,"requests":86832,"expected_per_scan":833000,"total_expected":833021,"errors":0,"successes":86749,"redirects":6,"client_errors":77,"server_errors":0,"total_scans":1,"initial_targets":0,"links_extracted":3,"extensions_collected":0,"status_200s":86749,"status_301s":6,"status_302s":0,"status_401s":0,"status_403s":0,"status_429s":0,"status_500s":0,"status_503s":0,"status_504s":0,"status_508s":0,"wildcards_filtered":86744,"responses_filtered":86744,"resources_discovered":5,"url_format_errors":0,"redirection_errors":0,"connection_errors":0,"request_errors":0,"directory_scan_times":[],"total_runtime":[0.0]},"collected_extensions":[],"filters":[{"dynamic":18446744073709551615,"size":2881,"method":"GET","dont_filter":false}]} \ No newline at end of file diff --git a/HTB/mentor/ferox-http_mentor_htb b/HTB/mentor/ferox-http_mentor_htb new file mode 100644 index 00000000..e69de29b diff --git a/HTB/mentor/ferox-http_mentor_htb:80_-1675786335.state b/HTB/mentor/ferox-http_mentor_htb:80_-1675786335.state deleted file mode 100644 index 02dd731a..00000000 --- a/HTB/mentor/ferox-http_mentor_htb:80_-1675786335.state +++ /dev/null @@ -1 +0,0 @@ -{"scans":[{"id":"e0c62a76639a492dacf3a0dd06c4fd96","url":"http://mentor.htb:80/","normalized_url":"http://mentor.htb:80/","scan_type":"Directory","status":"NotStarted","num_requests":833000}],"config":{"type":"configuration","wordlist":"/root/.local/share/AutoRecon/wordlists/dirbuster.txt","config":"/etc/feroxbuster/ferox-config.toml","proxy":"","replay_proxy":"","target_url":"http://mentor.htb:80/","status_codes":[200,204,301,302,307,308,401,403,405,500],"replay_codes":[200,204,301,302,307,308,401,403,405,500],"filter_status":[],"threads":10,"timeout":7,"verbosity":1,"silent":false,"quiet":true,"auto_bail":false,"auto_tune":false,"json":false,"output":"/home/kali/htb/mentor/results/scans/tcp80/tcp_80_http_feroxbuster_dirbuster.txt","debug_log":"","user_agent":"feroxbuster/2.7.3","random_agent":false,"redirects":false,"insecure":true,"extensions":["txt","html","php","asp","aspx","jsp"],"methods":["GET"],"data":[],"headers":{},"queries":[],"no_recursion":true,"extract_links":true,"add_slash":false,"stdin":false,"depth":4,"scan_limit":0,"parallel":0,"rate_limit":0,"filter_size":[],"filter_line_count":[],"filter_word_count":[],"filter_regex":[],"dont_filter":false,"resumed":false,"resume_from":"","save_state":true,"time_limit":"","filter_similar":[],"url_denylist":[],"regex_denylist":[],"collect_extensions":false,"dont_collect":["tif","tiff","ico","cur","bmp","webp","svg","png","jpg","jpeg","jfif","gif","avif","apng","pjpeg","pjp","mov","wav","mpg","mpeg","mp3","mp4","m4a","m4p","m4v","ogg","webm","ogv","oga","flac","aac","3gp","css","zip","xls","xml","gz","tgz"],"collect_backups":false,"collect_words":false,"force_recursion":false},"responses":[],"statistics":{"type":"statistics","timeouts":0,"requests":2,"expected_per_scan":833000,"total_expected":833000,"errors":1,"successes":0,"redirects":1,"client_errors":0,"server_errors":0,"total_scans":1,"initial_targets":0,"links_extracted":0,"extensions_collected":0,"status_200s":0,"status_301s":0,"status_302s":1,"status_401s":0,"status_403s":0,"status_429s":0,"status_500s":0,"status_503s":0,"status_504s":0,"status_508s":0,"wildcards_filtered":0,"responses_filtered":0,"resources_discovered":0,"url_format_errors":0,"redirection_errors":0,"connection_errors":1,"request_errors":0,"directory_scan_times":[],"total_runtime":[0.0]},"collected_extensions":[],"filters":[]} \ No newline at end of file diff --git a/HTB/soccer/ferox-http_10_10_11_194 b/HTB/soccer/ferox-http_10_10_11_194 new file mode 100644 index 00000000..e69de29b diff --git a/HTB/soccer/ferox-http_10_10_11_194:80_-1674662797.state b/HTB/soccer/ferox-http_10_10_11_194:80_-1674662797.state deleted file mode 100644 index 885590c6..00000000 --- a/HTB/soccer/ferox-http_10_10_11_194:80_-1674662797.state +++ /dev/null @@ -1 +0,0 @@ -{"scans":[{"id":"2689ff59b1bb4952bd0760a96a0670d3","url":"http://10.10.11.194:80/","normalized_url":"http://10.10.11.194:80/","scan_type":"Directory","status":"Running","num_requests":1543822}],"config":{"type":"configuration","wordlist":"/usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt","config":"/etc/feroxbuster/ferox-config.toml","proxy":"","replay_proxy":"","target_url":"http://10.10.11.194:80/","status_codes":[200,204,301,302,307,308,401,403,405,500],"replay_codes":[200,204,301,302,307,308,401,403,405,500],"filter_status":[],"threads":50,"timeout":7,"verbosity":1,"silent":false,"quiet":true,"auto_bail":false,"auto_tune":false,"json":false,"output":"/home/kali/htb/soccer/results/scans/tcp80/tcp_80_http_feroxbuster_directory-list-2.3-medium.txt","debug_log":"","user_agent":"feroxbuster/2.7.3","random_agent":false,"redirects":false,"insecure":true,"extensions":["txt","html","php","asp","aspx","jsp"],"methods":["GET"],"data":[],"headers":{},"queries":[],"no_recursion":false,"extract_links":true,"add_slash":false,"stdin":false,"depth":4,"scan_limit":0,"parallel":0,"rate_limit":0,"filter_size":[],"filter_line_count":[],"filter_word_count":[],"filter_regex":[],"dont_filter":false,"resumed":false,"resume_from":"","save_state":true,"time_limit":"","filter_similar":[],"url_denylist":[],"regex_denylist":[],"collect_extensions":false,"dont_collect":["tif","tiff","ico","cur","bmp","webp","svg","png","jpg","jpeg","jfif","gif","avif","apng","pjpeg","pjp","mov","wav","mpg","mpeg","mp3","mp4","m4a","m4p","m4v","ogg","webm","ogv","oga","flac","aac","3gp","css","zip","xls","xml","gz","tgz"],"collect_backups":false,"collect_words":false,"force_recursion":false},"responses":[{"type":"response","url":"http://10.10.11.194/09d1efe14b0747d9a4f8be3e7aa30913","original_url":"http://10.10.11.194:80/","path":"/09d1efe14b0747d9a4f8be3e7aa30913","wildcard":true,"status":301,"method":"GET","content_length":178,"line_count":7,"word_count":12,"headers":{"server":"nginx/1.18.0 (Ubuntu)","connection":"keep-alive","content-length":"178","location":"http://soccer.htb/09d1efe14b0747d9a4f8be3e7aa30913","content-type":"text/html","date":"Wed, 25 Jan 2023 15:54:11 GMT"},"extension":""},{"type":"response","url":"http://10.10.11.194/71abea99cb5147799a27f2ebfeb66255a7c396b7c7dd43a3b4d9e8566f2c2137400ca2109ffd4c8985227c3b004a6257","original_url":"http://10.10.11.194:80/","path":"/71abea99cb5147799a27f2ebfeb66255a7c396b7c7dd43a3b4d9e8566f2c2137400ca2109ffd4c8985227c3b004a6257","wildcard":true,"status":301,"method":"GET","content_length":178,"line_count":7,"word_count":12,"headers":{"server":"nginx/1.18.0 (Ubuntu)","date":"Wed, 25 Jan 2023 15:54:11 GMT","content-length":"178","connection":"keep-alive","location":"http://soccer.htb/71abea99cb5147799a27f2ebfeb66255a7c396b7c7dd43a3b4d9e8566f2c2137400ca2109ffd4c8985227c3b004a6257","content-type":"text/html"},"extension":""}],"statistics":{"type":"statistics","timeouts":632,"requests":1024705,"expected_per_scan":1543822,"total_expected":1543822,"errors":659,"successes":0,"redirects":1024045,"client_errors":1,"server_errors":0,"total_scans":1,"initial_targets":0,"links_extracted":0,"extensions_collected":0,"status_200s":0,"status_301s":1024045,"status_302s":0,"status_401s":0,"status_403s":0,"status_429s":0,"status_500s":0,"status_503s":0,"status_504s":0,"status_508s":0,"wildcards_filtered":1024041,"responses_filtered":1024041,"resources_discovered":2,"url_format_errors":0,"redirection_errors":0,"connection_errors":27,"request_errors":0,"directory_scan_times":[],"total_runtime":[0.0]},"collected_extensions":[],"filters":[{"dynamic":18446744073709551615,"size":178,"method":"GET","dont_filter":false}]} \ No newline at end of file diff --git a/HTB/stocker/ferox-http_10_10_11_196 b/HTB/stocker/ferox-http_10_10_11_196 new file mode 100644 index 00000000..e69de29b diff --git a/HTB/stocker/ferox-http_10_10_11_196:80_-1674572985.state b/HTB/stocker/ferox-http_10_10_11_196:80_-1674572985.state deleted file mode 100644 index 4225f197..00000000 --- a/HTB/stocker/ferox-http_10_10_11_196:80_-1674572985.state +++ /dev/null @@ -1 +0,0 @@ -{"scans":[{"id":"194e314ac376490ab61036712740816e","url":"http://10.10.11.196:80/","normalized_url":"http://10.10.11.196:80/","scan_type":"Directory","status":"Running","num_requests":833000}],"config":{"type":"configuration","wordlist":"/home/kali/.local/share/AutoRecon/wordlists/dirbuster.txt","config":"/etc/feroxbuster/ferox-config.toml","proxy":"","replay_proxy":"","target_url":"http://10.10.11.196:80/","status_codes":[200,204,301,302,307,308,401,403,405,500],"replay_codes":[200,204,301,302,307,308,401,403,405,500],"filter_status":[],"threads":10,"timeout":7,"verbosity":1,"silent":false,"quiet":true,"auto_bail":false,"auto_tune":false,"json":false,"output":"/home/kali/htb/stocker/results/10.10.11.196/scans/tcp80/tcp_80_http_feroxbuster_dirbuster.txt","debug_log":"","user_agent":"feroxbuster/2.7.3","random_agent":false,"redirects":false,"insecure":true,"extensions":["txt","html","php","asp","aspx","jsp"],"methods":["GET"],"data":[],"headers":{},"queries":[],"no_recursion":true,"extract_links":true,"add_slash":false,"stdin":false,"depth":4,"scan_limit":0,"parallel":0,"rate_limit":0,"filter_size":[],"filter_line_count":[],"filter_word_count":[],"filter_regex":[],"dont_filter":false,"resumed":false,"resume_from":"","save_state":true,"time_limit":"","filter_similar":[],"url_denylist":[],"regex_denylist":[],"collect_extensions":false,"dont_collect":["tif","tiff","ico","cur","bmp","webp","svg","png","jpg","jpeg","jfif","gif","avif","apng","pjpeg","pjp","mov","wav","mpg","mpeg","mp3","mp4","m4a","m4p","m4v","ogg","webm","ogv","oga","flac","aac","3gp","css","zip","xls","xml","gz","tgz"],"collect_backups":false,"collect_words":false,"force_recursion":false},"responses":[{"type":"response","url":"http://10.10.11.196/d9be98ffce1147d895aa41acab853b02","original_url":"http://10.10.11.196:80/","path":"/d9be98ffce1147d895aa41acab853b02","wildcard":true,"status":301,"method":"GET","content_length":178,"line_count":7,"word_count":12,"headers":{"content-type":"text/html","date":"Tue, 24 Jan 2023 15:03:01 GMT","server":"nginx/1.18.0 (Ubuntu)","connection":"keep-alive","content-length":"178","location":"http://stocker.htb"},"extension":""},{"type":"response","url":"http://10.10.11.196/40a69154f6cb4f6f971bb2c2f9b7b175e2c9e69a2c99434a87642f75616cde486080134b076149d7a47f124e3f59b178","original_url":"http://10.10.11.196:80/","path":"/40a69154f6cb4f6f971bb2c2f9b7b175e2c9e69a2c99434a87642f75616cde486080134b076149d7a47f124e3f59b178","wildcard":true,"status":301,"method":"GET","content_length":178,"line_count":7,"word_count":12,"headers":{"content-type":"text/html","server":"nginx/1.18.0 (Ubuntu)","content-length":"178","date":"Tue, 24 Jan 2023 15:03:01 GMT","connection":"keep-alive","location":"http://stocker.htb"},"extension":""}],"statistics":{"type":"statistics","timeouts":0,"requests":87512,"expected_per_scan":833000,"total_expected":833000,"errors":0,"successes":1,"redirects":87511,"client_errors":0,"server_errors":0,"total_scans":1,"initial_targets":0,"links_extracted":0,"extensions_collected":0,"status_200s":1,"status_301s":87511,"status_302s":0,"status_401s":0,"status_403s":0,"status_429s":0,"status_500s":0,"status_503s":0,"status_504s":0,"status_508s":0,"wildcards_filtered":87507,"responses_filtered":87507,"resources_discovered":2,"url_format_errors":0,"redirection_errors":0,"connection_errors":0,"request_errors":0,"directory_scan_times":[],"total_runtime":[0.0]},"collected_extensions":[],"filters":[{"dynamic":18446744073709551615,"size":178,"method":"GET","dont_filter":false}]} \ No newline at end of file diff --git a/HTB/vessel/ferox-http_openwebanalytics_vessel_htb b/HTB/vessel/ferox-http_openwebanalytics_vessel_htb new file mode 100644 index 00000000..e69de29b diff --git a/HTB/vessel/ferox-http_openwebanalytics_vessel_htb:80-1676229429.state b/HTB/vessel/ferox-http_openwebanalytics_vessel_htb:80-1676229429.state deleted file mode 100644 index be9febba..00000000 --- a/HTB/vessel/ferox-http_openwebanalytics_vessel_htb:80-1676229429.state +++ /dev/null @@ -1 +0,0 @@ -{"scans":[{"id":"a6976f9b92f24b008285f6602ee59bbc","url":"http://openwebanalytics.vessel.htb:80/","normalized_url":"http://openwebanalytics.vessel.htb:80/","scan_type":"Directory","status":"Running","num_requests":1543829},{"id":"643afc14e5ff4a30b92dce4ed5a24618","url":"http://openwebanalytics.vessel.htb/log.php","normalized_url":"http://openwebanalytics.vessel.htb/log.php/","scan_type":"File","status":"NotStarted","num_requests":1543829},{"id":"e9e026a065c94174b9e5cefa9c26cbb1","url":"http://openwebanalytics.vessel.htb/text/css","normalized_url":"http://openwebanalytics.vessel.htb/text/css/","scan_type":"File","status":"NotStarted","num_requests":1543829},{"id":"2b0bc3b8cbdc4a1cb26f1126b8f71e5d","url":"http://openwebanalytics.vessel.htb/api/index.php","normalized_url":"http://openwebanalytics.vessel.htb/api/index.php/","scan_type":"File","status":"NotStarted","num_requests":1543829},{"id":"0de10af96a18423495dd2802114cfac7","url":"http://openwebanalytics.vessel.htb/install.php","normalized_url":"http://openwebanalytics.vessel.htb/install.php/","scan_type":"File","status":"NotStarted","num_requests":1543829},{"id":"a25cf34ba7684504a909c106be5c4dd0","url":"http://openwebanalytics.vessel.htb/text/","normalized_url":"http://openwebanalytics.vessel.htb/text/","scan_type":"File","status":"NotStarted","num_requests":1543829},{"id":"b3f7947d39c14e48a684da59a4b22ba7","url":"http://openwebanalytics.vessel.htb/modules/base/js/owa.js","normalized_url":"http://openwebanalytics.vessel.htb/modules/base/js/owa.js/","scan_type":"File","status":"NotStarted","num_requests":1543829},{"id":"5d47563f4bc343138c24e867fd7633f0","url":"http://openwebanalytics.vessel.htb/text/javascript","normalized_url":"http://openwebanalytics.vessel.htb/text/javascript/","scan_type":"File","status":"NotStarted","num_requests":1543829},{"id":"c8e3de4aea234ae8aa6215e739d9702a","url":"http://openwebanalytics.vessel.htb/modules/base/css/owa.css","normalized_url":"http://openwebanalytics.vessel.htb/modules/base/css/owa.css/","scan_type":"File","status":"NotStarted","num_requests":1543829},{"id":"35359c768aaf43a08c23d926b07e0233","url":"http://openwebanalytics.vessel.htb/modules/base/i/owa_logo_150w.jpg","normalized_url":"http://openwebanalytics.vessel.htb/modules/base/i/owa_logo_150w.jpg/","scan_type":"File","status":"NotStarted","num_requests":1543829},{"id":"2b7f618719be4597835a997283a4b793","url":"http://openwebanalytics.vessel.htb/js","normalized_url":"http://openwebanalytics.vessel.htb/js/","scan_type":"File","status":"NotStarted","num_requests":1543829}],"config":{"type":"configuration","wordlist":"/usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt","config":"/etc/feroxbuster/ferox-config.toml","proxy":"","replay_proxy":"","target_url":"http://openwebanalytics.vessel.htb:80","status_codes":[200,204,301,302,307,308,401,403,405,500],"replay_codes":[200,204,301,302,307,308,401,403,405,500],"filter_status":[],"threads":10,"timeout":7,"verbosity":1,"silent":false,"quiet":false,"auto_bail":false,"auto_tune":false,"json":false,"output":"/home/simon/htb/vessel/results/vessel.htb/scans/tcp80/tcp_80_http_feroxbuster_dirbuster.txt","debug_log":"","user_agent":"feroxbuster/2.7.3","random_agent":false,"redirects":false,"insecure":true,"extensions":["txt","html","php","asp","aspx","jsp"],"methods":["GET"],"data":[],"headers":{},"queries":[],"no_recursion":true,"extract_links":true,"add_slash":false,"stdin":false,"depth":4,"scan_limit":0,"parallel":0,"rate_limit":0,"filter_size":[],"filter_line_count":[],"filter_word_count":[],"filter_regex":[],"dont_filter":false,"resumed":false,"resume_from":"","save_state":true,"time_limit":"","filter_similar":[],"url_denylist":[],"regex_denylist":[],"collect_extensions":false,"dont_collect":["tif","tiff","ico","cur","bmp","webp","svg","png","jpg","jpeg","jfif","gif","avif","apng","pjpeg","pjp","mov","wav","mpg","mpeg","mp3","mp4","m4a","m4p","m4v","ogg","webm","ogv","oga","flac","aac","3gp","css","zip","xls","xml","gz","tgz"],"collect_backups":false,"collect_words":false,"force_recursion":false},"responses":[{"type":"response","url":"http://openwebanalytics.vessel.htb/","original_url":"http://openwebanalytics.vessel.htb:80","path":"/","wildcard":false,"status":302,"method":"GET","content_length":0,"line_count":0,"word_count":0,"headers":{"date":"Sun, 12 Feb 2023 19:06:13 GMT","content-length":"0","content-type":"text/html; charset=UTF-8","connection":"close","server":"Apache/2.4.41 (Ubuntu)","location":"http://openwebanalytics.vessel.htb/index.php?owa_do=base.loginForm&owa_go=http%3A%2F%2Fopenwebanalytics.vessel.htb%2F&"},"extension":""},{"type":"response","url":"http://openwebanalytics.vessel.htb/.html","original_url":"http://openwebanalytics.vessel.htb:80","path":"/.html","wildcard":false,"status":403,"method":"GET","content_length":292,"line_count":9,"word_count":28,"headers":{"date":"Sun, 12 Feb 2023 19:06:13 GMT","content-type":"text/html; charset=iso-8859-1","content-length":"292","server":"Apache/2.4.41 (Ubuntu)"},"extension":""},{"type":"response","url":"http://openwebanalytics.vessel.htb/.php","original_url":"http://openwebanalytics.vessel.htb:80","path":"/.php","wildcard":false,"status":403,"method":"GET","content_length":292,"line_count":9,"word_count":28,"headers":{"content-length":"292","content-type":"text/html; charset=iso-8859-1","server":"Apache/2.4.41 (Ubuntu)","date":"Sun, 12 Feb 2023 19:06:13 GMT"},"extension":""},{"type":"response","url":"http://openwebanalytics.vessel.htb/index.php","original_url":"http://openwebanalytics.vessel.htb:80","path":"/index.php","wildcard":false,"status":302,"method":"GET","content_length":0,"line_count":0,"word_count":0,"headers":{"server":"Apache/2.4.41 (Ubuntu)","date":"Sun, 12 Feb 2023 19:06:13 GMT","location":"http://openwebanalytics.vessel.htb/index.php?owa_do=base.loginForm&owa_go=http%3A%2F%2Fopenwebanalytics.vessel.htb%2Findex.php&","connection":"close","content-type":"text/html; charset=UTF-8","content-length":"0"},"extension":""},{"type":"response","url":"http://openwebanalytics.vessel.htb/modules","original_url":"http://openwebanalytics.vessel.htb:80","path":"/modules","wildcard":false,"status":301,"method":"GET","content_length":344,"line_count":9,"word_count":28,"headers":{"location":"http://openwebanalytics.vessel.htb/modules/","date":"Sun, 12 Feb 2023 19:06:16 GMT","content-length":"344","server":"Apache/2.4.41 (Ubuntu)","content-type":"text/html; charset=iso-8859-1"},"extension":""},{"type":"response","url":"http://openwebanalytics.vessel.htb/blank.php","original_url":"http://openwebanalytics.vessel.htb:80","path":"/blank.php","wildcard":false,"status":200,"method":"GET","content_length":0,"line_count":0,"word_count":0,"headers":{"server":"Apache/2.4.41 (Ubuntu)","content-length":"0","content-type":"text/html; charset=UTF-8","date":"Sun, 12 Feb 2023 19:06:16 GMT"},"extension":""},{"type":"response","url":"http://openwebanalytics.vessel.htb/plugins","original_url":"http://openwebanalytics.vessel.htb:80","path":"/plugins","wildcard":false,"status":301,"method":"GET","content_length":344,"line_count":9,"word_count":28,"headers":{"server":"Apache/2.4.41 (Ubuntu)","location":"http://openwebanalytics.vessel.htb/plugins/","content-type":"text/html; charset=iso-8859-1","date":"Sun, 12 Feb 2023 19:06:25 GMT","content-length":"344"},"extension":""},{"type":"response","url":"http://openwebanalytics.vessel.htb/includes","original_url":"http://openwebanalytics.vessel.htb:80","path":"/includes","wildcard":false,"status":301,"method":"GET","content_length":345,"line_count":9,"word_count":28,"headers":{"content-type":"text/html; charset=iso-8859-1","server":"Apache/2.4.41 (Ubuntu)","date":"Sun, 12 Feb 2023 19:06:29 GMT","location":"http://openwebanalytics.vessel.htb/includes/","content-length":"345"},"extension":""},{"type":"response","url":"http://openwebanalytics.vessel.htb/log.php","original_url":"http://openwebanalytics.vessel.htb:80","path":"/log.php","wildcard":false,"status":200,"method":"GET","content_length":42,"line_count":1,"word_count":1,"headers":{"content-encoding":"none","content-length":"42","pragma":"no-cache","last-modified":"Wed, 11 Jan 2006 12:59:00 GMT","server":"Apache/2.4.41 (Ubuntu)","expires":"Wed, 11 Jan 2000 12:59:00 GMT","content-type":"image/gif","cache-control":"private, no-cache, no-cache=Set-Cookie, proxy-revalidate","date":"Sun, 12 Feb 2023 19:06:29 GMT"},"extension":""},{"type":"response","url":"http://openwebanalytics.vessel.htb/api/index.php","original_url":"http://openwebanalytics.vessel.htb/api/index.php","path":"/api/index.php","wildcard":false,"status":200,"method":"GET","content_length":0,"line_count":0,"word_count":0,"headers":{"content-length":"0","server":"Apache/2.4.41 (Ubuntu)","content-type":"text/html; charset=UTF-8","date":"Sun, 12 Feb 2023 19:06:31 GMT"},"extension":""},{"type":"response","url":"http://openwebanalytics.vessel.htb/install.php","original_url":"http://openwebanalytics.vessel.htb/install.php","path":"/install.php","wildcard":false,"status":302,"method":"GET","content_length":2927,"line_count":79,"word_count":190,"headers":{"content-type":"text/html; charset=UTF-8","location":"http://openwebanalytics.vessel.htb/","content-length":"2927","date":"Sun, 12 Feb 2023 19:06:31 GMT","server":"Apache/2.4.41 (Ubuntu)","connection":"close"},"extension":""},{"type":"response","url":"http://openwebanalytics.vessel.htb/modules/base/js/owa.js","original_url":"http://openwebanalytics.vessel.htb/modules/base/js/owa.js","path":"/modules/base/js/owa.js","wildcard":false,"status":200,"method":"GET","content_length":76203,"line_count":2220,"word_count":7885,"headers":{"date":"Sun, 12 Feb 2023 19:06:31 GMT","etag":"\"129ab-5d076d7099100\"","content-type":"application/javascript","server":"Apache/2.4.41 (Ubuntu)","vary":"Accept-Encoding","accept-ranges":"bytes","content-length":"76203","last-modified":"Wed, 10 Nov 2021 22:35:16 GMT"},"extension":""},{"type":"response","url":"http://openwebanalytics.vessel.htb/modules/base/css/owa.css","original_url":"http://openwebanalytics.vessel.htb/modules/base/css/owa.css","path":"/modules/base/css/owa.css","wildcard":false,"status":200,"method":"GET","content_length":8410,"line_count":287,"word_count":740,"headers":{"last-modified":"Tue, 12 May 2020 20:20:29 GMT","accept-ranges":"bytes","date":"Sun, 12 Feb 2023 19:06:31 GMT","vary":"Accept-Encoding","server":"Apache/2.4.41 (Ubuntu)","content-type":"text/css","content-length":"8410","etag":"\"20da-5a57931d19d40\""},"extension":""},{"type":"response","url":"http://openwebanalytics.vessel.htb/modules/base/i/owa_logo_150w.jpg","original_url":"http://openwebanalytics.vessel.htb/modules/base/i/owa_logo_150w.jpg","path":"/modules/base/i/owa_logo_150w.jpg","wildcard":false,"status":200,"method":"GET","content_length":9849,"line_count":35,"word_count":186,"headers":{"content-length":"9849","content-type":"image/jpeg","etag":"\"2679-5a57931d19d40\"","last-modified":"Tue, 12 May 2020 20:20:29 GMT","date":"Sun, 12 Feb 2023 19:06:31 GMT","accept-ranges":"bytes","server":"Apache/2.4.41 (Ubuntu)"},"extension":""},{"type":"response","url":"http://openwebanalytics.vessel.htb/api","original_url":"http://openwebanalytics.vessel.htb:80","path":"/api","wildcard":false,"status":301,"method":"GET","content_length":340,"line_count":9,"word_count":28,"headers":{"content-type":"text/html; charset=iso-8859-1","location":"http://openwebanalytics.vessel.htb/api/","server":"Apache/2.4.41 (Ubuntu)","date":"Sun, 12 Feb 2023 19:06:38 GMT","content-length":"340"},"extension":""},{"type":"response","url":"http://openwebanalytics.vessel.htb/conf","original_url":"http://openwebanalytics.vessel.htb:80","path":"/conf","wildcard":false,"status":301,"method":"GET","content_length":341,"line_count":9,"word_count":28,"headers":{"date":"Sun, 12 Feb 2023 19:06:45 GMT","server":"Apache/2.4.41 (Ubuntu)","location":"http://openwebanalytics.vessel.htb/conf/","content-length":"341","content-type":"text/html; charset=iso-8859-1"},"extension":""},{"type":"response","url":"http://openwebanalytics.vessel.htb/vendor","original_url":"http://openwebanalytics.vessel.htb:80","path":"/vendor","wildcard":false,"status":301,"method":"GET","content_length":343,"line_count":9,"word_count":28,"headers":{"content-length":"343","date":"Sun, 12 Feb 2023 19:06:48 GMT","server":"Apache/2.4.41 (Ubuntu)","location":"http://openwebanalytics.vessel.htb/vendor/","content-type":"text/html; charset=iso-8859-1"},"extension":""},{"type":"response","url":"http://openwebanalytics.vessel.htb/owa.php","original_url":"http://openwebanalytics.vessel.htb:80","path":"/owa.php","wildcard":false,"status":200,"method":"GET","content_length":0,"line_count":0,"word_count":0,"headers":{"content-length":"0","server":"Apache/2.4.41 (Ubuntu)","date":"Sun, 12 Feb 2023 19:10:05 GMT","content-type":"text/html; charset=UTF-8"},"extension":""},{"type":"response","url":"http://openwebanalytics.vessel.htb/queue.php","original_url":"http://openwebanalytics.vessel.htb:80","path":"/queue.php","wildcard":false,"status":200,"method":"GET","content_length":0,"line_count":0,"word_count":0,"headers":{"date":"Sun, 12 Feb 2023 19:15:14 GMT","content-type":"text/html; charset=UTF-8","server":"Apache/2.4.41 (Ubuntu)","content-length":"0"},"extension":""}],"statistics":{"type":"statistics","timeouts":0,"requests":212475,"expected_per_scan":1543829,"total_expected":1543983,"errors":0,"successes":16,"redirects":18,"client_errors":212441,"server_errors":0,"total_scans":1,"initial_targets":0,"links_extracted":22,"extensions_collected":0,"status_200s":16,"status_301s":12,"status_302s":6,"status_401s":0,"status_403s":2,"status_429s":0,"status_500s":0,"status_503s":0,"status_504s":0,"status_508s":0,"wildcards_filtered":0,"responses_filtered":0,"resources_discovered":19,"url_format_errors":0,"redirection_errors":0,"connection_errors":0,"request_errors":0,"directory_scan_times":[],"total_runtime":[0.0]},"collected_extensions":[],"filters":[]} \ No newline at end of file diff --git a/HTB/vessel/ferox-http_vessel_htb b/HTB/vessel/ferox-http_vessel_htb new file mode 100644 index 00000000..e69de29b diff --git a/HTB/vessel/ferox-http_vessel_htb:80-1676228307.state b/HTB/vessel/ferox-http_vessel_htb:80-1676228307.state deleted file mode 100644 index bed0c130..00000000 --- a/HTB/vessel/ferox-http_vessel_htb:80-1676228307.state +++ /dev/null @@ -1 +0,0 @@ -{"scans":[{"id":"6458d4e1fda246e7a2e75ce5a8e79e56","url":"http://vessel.htb:80/","normalized_url":"http://vessel.htb:80/","scan_type":"Directory","status":"Running","num_requests":1543829},{"id":"ca4cef0d225a42139980fe04e0f5d3f9","url":"http://vessel.htb/login","normalized_url":"http://vessel.htb/login/","scan_type":"File","status":"NotStarted","num_requests":1543829},{"id":"9556e72ffc3c4208959d49965ba797ed","url":"http://vessel.htb/img/portfolio/thumbnails/4.jpg","normalized_url":"http://vessel.htb/img/portfolio/thumbnails/4.jpg/","scan_type":"File","status":"NotStarted","num_requests":1543829},{"id":"586209accf8944ee9840002a69bb8b0c","url":"http://vessel.htb/img/portfolio/thumbnails/2.jpg","normalized_url":"http://vessel.htb/img/portfolio/thumbnails/2.jpg/","scan_type":"File","status":"NotStarted","num_requests":1543829},{"id":"af0e6f21197349c981d21329db99ca0b","url":"http://vessel.htb/js/script.js","normalized_url":"http://vessel.htb/js/script.js/","scan_type":"File","status":"NotStarted","num_requests":1543829},{"id":"64250574fe4a4f8981bc08da7112f753","url":"http://vessel.htb/register","normalized_url":"http://vessel.htb/register/","scan_type":"File","status":"NotStarted","num_requests":1543829},{"id":"0a92402420a242a989b81bf55ecfd9cc","url":"http://vessel.htb/img/portfolio/thumbnails/3.jpg","normalized_url":"http://vessel.htb/img/portfolio/thumbnails/3.jpg/","scan_type":"File","status":"NotStarted","num_requests":1543829},{"id":"fffb9134765e497c8525175d076e5fc4","url":"http://vessel.htb/reset","normalized_url":"http://vessel.htb/reset/","scan_type":"File","status":"NotStarted","num_requests":1543829},{"id":"88f4f29e102f486b889b16eb61092aae","url":"http://vessel.htb/js/scripts.js","normalized_url":"http://vessel.htb/js/scripts.js/","scan_type":"File","status":"NotStarted","num_requests":1543829},{"id":"b8ba5cae89754f04ae5fada540d8491c","url":"http://vessel.htb/css/style.css","normalized_url":"http://vessel.htb/css/style.css/","scan_type":"File","status":"NotStarted","num_requests":1543829},{"id":"fb6cae849c444685957043e04db73e9f","url":"http://vessel.htb/img/portfolio/thumbnails/1.jpg","normalized_url":"http://vessel.htb/img/portfolio/thumbnails/1.jpg/","scan_type":"File","status":"NotStarted","num_requests":1543829},{"id":"5739e8e43c724697b1857a271801640d","url":"http://vessel.htb/img/portfolio/thumbnails/6.jpg","normalized_url":"http://vessel.htb/img/portfolio/thumbnails/6.jpg/","scan_type":"File","status":"NotStarted","num_requests":1543829},{"id":"06f512706b5f477a8be93ff05e36632b","url":"http://vessel.htb/css/styles.css","normalized_url":"http://vessel.htb/css/styles.css/","scan_type":"File","status":"NotStarted","num_requests":1543829},{"id":"b845db5b3ef54592940b9b8bc61fbb68","url":"http://vessel.htb/img/portfolio/thumbnails/5.jpg","normalized_url":"http://vessel.htb/img/portfolio/thumbnails/5.jpg/","scan_type":"File","status":"NotStarted","num_requests":1543829},{"id":"f4fd250755a343fc9872f1b4e18e5a81","url":"http://vessel.htb/img/error-404-monochrome.svg","normalized_url":"http://vessel.htb/img/error-404-monochrome.svg/","scan_type":"File","status":"NotStarted","num_requests":1543829}],"config":{"type":"configuration","wordlist":"/usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt","config":"/etc/feroxbuster/ferox-config.toml","proxy":"","replay_proxy":"","target_url":"http://vessel.htb:80","status_codes":[200,204,301,302,307,308,401,403,405,500],"replay_codes":[200,204,301,302,307,308,401,403,405,500],"filter_status":[],"threads":10,"timeout":7,"verbosity":1,"silent":false,"quiet":false,"auto_bail":false,"auto_tune":false,"json":false,"output":"/home/simon/htb/vessel/results/vessel.htb/scans/tcp80/tcp_80_http_feroxbuster_dirbuster.txt","debug_log":"","user_agent":"feroxbuster/2.7.3","random_agent":false,"redirects":false,"insecure":true,"extensions":["txt","html","php","asp","aspx","jsp"],"methods":["GET"],"data":[],"headers":{},"queries":[],"no_recursion":true,"extract_links":true,"add_slash":false,"stdin":false,"depth":4,"scan_limit":0,"parallel":0,"rate_limit":0,"filter_size":[],"filter_line_count":[],"filter_word_count":[],"filter_regex":[],"dont_filter":false,"resumed":false,"resume_from":"","save_state":true,"time_limit":"","filter_similar":[],"url_denylist":[],"regex_denylist":[],"collect_extensions":false,"dont_collect":["tif","tiff","ico","cur","bmp","webp","svg","png","jpg","jpeg","jfif","gif","avif","apng","pjpeg","pjp","mov","wav","mpg","mpeg","mp3","mp4","m4a","m4p","m4v","ogg","webm","ogv","oga","flac","aac","3gp","css","zip","xls","xml","gz","tgz"],"collect_backups":false,"collect_words":false,"force_recursion":false},"responses":[{"type":"response","url":"http://vessel.htb/af1b5bfa8f33472bb571a201efef834c","original_url":"http://vessel.htb:80","path":"/af1b5bfa8f33472bb571a201efef834c","wildcard":true,"status":302,"method":"GET","content_length":26,"line_count":1,"word_count":4,"headers":{"location":"/404","content-type":"text/plain; charset=utf-8","date":"Sun, 12 Feb 2023 18:30:08 GMT","vary":"Accept","content-length":"26","x-powered-by":"Express","server":"Apache/2.4.41 (Ubuntu)"},"extension":""},{"type":"response","url":"http://vessel.htb/e12490f639ae465e96feecf421ac5e64431666860e794c2195a6eb171c16f49652be7acb29b0430ebde73b090d1497fc","original_url":"http://vessel.htb:80","path":"/e12490f639ae465e96feecf421ac5e64431666860e794c2195a6eb171c16f49652be7acb29b0430ebde73b090d1497fc","wildcard":true,"status":302,"method":"GET","content_length":26,"line_count":1,"word_count":4,"headers":{"date":"Sun, 12 Feb 2023 18:30:08 GMT","content-type":"text/plain; charset=utf-8","content-length":"26","location":"/404","server":"Apache/2.4.41 (Ubuntu)","vary":"Accept","x-powered-by":"Express"},"extension":""},{"type":"response","url":"http://vessel.htb/login","original_url":"http://vessel.htb/login","path":"/login","wildcard":false,"status":200,"method":"GET","content_length":4213,"line_count":70,"word_count":182,"headers":{"date":"Sun, 12 Feb 2023 18:30:08 GMT","content-length":"4213","server":"Apache/2.4.41 (Ubuntu)","x-powered-by":"Express","etag":"W/\"1075-CVcMucj15ZerlofF1+GJKI+u68Q\"","vary":"Accept-Encoding","set-cookie":"connect.sid=s%3Aq2EZLZ3l7Z4gOefAxabuzmiTeai0IeAL.lRPPKxSxwuCNo%2BcljS3%2FFioFm87YxEAvh9B7%2FKf9898; Path=/; Expires=Sun, 12 Feb 2023 18:34:08 GMT; HttpOnly; SameSite=Strict","content-type":"text/html; charset=utf-8"},"extension":""},{"type":"response","url":"http://vessel.htb/img/portfolio/thumbnails/4.jpg","original_url":"http://vessel.htb/img/portfolio/thumbnails/4.jpg","path":"/img/portfolio/thumbnails/4.jpg","wildcard":false,"status":200,"method":"GET","content_length":274424,"line_count":1277,"word_count":6344,"headers":{"server":"Apache/2.4.41 (Ubuntu)","accept-ranges":"bytes","content-type":"image/jpeg","date":"Sun, 12 Feb 2023 18:30:08 GMT","last-modified":"Sun, 13 Mar 2022 21:43:59 GMT","content-length":"274424","etag":"W/\"42ff8-17f853cf518\"","cache-control":"public, max-age=0","x-powered-by":"Express"},"extension":""},{"type":"response","url":"http://vessel.htb/img","original_url":"http://vessel.htb:80","path":"/img","wildcard":false,"status":301,"method":"GET","content_length":173,"line_count":10,"word_count":16,"headers":{"content-length":"173","date":"Sun, 12 Feb 2023 18:30:09 GMT","x-powered-by":"Express","server":"Apache/2.4.41 (Ubuntu)","content-security-policy":"default-src 'none'","location":"/img/","content-type":"text/html; charset=UTF-8","x-content-type-options":"nosniff"},"extension":""},{"type":"response","url":"http://vessel.htb/img/portfolio/thumbnails/2.jpg","original_url":"http://vessel.htb/img/portfolio/thumbnails/2.jpg","path":"/img/portfolio/thumbnails/2.jpg","wildcard":false,"status":200,"method":"GET","content_length":240234,"line_count":919,"word_count":5377,"headers":{"last-modified":"Sun, 13 Mar 2022 21:43:59 GMT","accept-ranges":"bytes","cache-control":"public, max-age=0","content-length":"240234","date":"Sun, 12 Feb 2023 18:30:09 GMT","content-type":"image/jpeg","server":"Apache/2.4.41 (Ubuntu)","etag":"W/\"3aa6a-17f853cf518\"","x-powered-by":"Express"},"extension":""},{"type":"response","url":"http://vessel.htb/js/script.js","original_url":"http://vessel.htb/js/script.js","path":"/js/script.js","wildcard":false,"status":200,"method":"GET","content_length":976,"line_count":26,"word_count":70,"headers":{"etag":"W/\"3d0-17f853cf518\"","server":"Apache/2.4.41 (Ubuntu)","accept-ranges":"bytes","x-powered-by":"Express","content-type":"application/javascript; charset=UTF-8","content-length":"976","cache-control":"public, max-age=0","last-modified":"Sun, 13 Mar 2022 21:43:59 GMT","date":"Sun, 12 Feb 2023 18:30:09 GMT","vary":"Accept-Encoding"},"extension":""},{"type":"response","url":"http://vessel.htb/register","original_url":"http://vessel.htb/register","path":"/register","wildcard":false,"status":200,"method":"GET","content_length":5830,"line_count":89,"word_count":234,"headers":{"content-type":"text/html; charset=utf-8","content-length":"5830","x-powered-by":"Express","date":"Sun, 12 Feb 2023 18:30:09 GMT","vary":"Accept-Encoding","server":"Apache/2.4.41 (Ubuntu)","set-cookie":"connect.sid=s%3A8yJF3ds1vTdIxHL3AOuzcgHRy6JDVUSO.V3tZmZmbuKwlN2xxExzLtS2kj%2Bjh7fGJIpww8xe1BcU; Path=/; Expires=Sun, 12 Feb 2023 18:34:09 GMT; HttpOnly; SameSite=Strict","etag":"W/\"16c6-fRWBDxVm0yplTV7OyEjrxNG72xg\""},"extension":""},{"type":"response","url":"http://vessel.htb/img/portfolio/thumbnails/3.jpg","original_url":"http://vessel.htb/img/portfolio/thumbnails/3.jpg","path":"/img/portfolio/thumbnails/3.jpg","wildcard":false,"status":200,"method":"GET","content_length":250242,"line_count":587,"word_count":4806,"headers":{"server":"Apache/2.4.41 (Ubuntu)","content-type":"image/jpeg","last-modified":"Sun, 13 Mar 2022 21:43:59 GMT","date":"Sun, 12 Feb 2023 18:30:09 GMT","content-length":"250242","x-powered-by":"Express","cache-control":"public, max-age=0","accept-ranges":"bytes","etag":"W/\"3d182-17f853cf518\""},"extension":""},{"type":"response","url":"http://vessel.htb/reset","original_url":"http://vessel.htb/reset","path":"/reset","wildcard":false,"status":200,"method":"GET","content_length":3637,"line_count":63,"word_count":177,"headers":{"content-length":"3637","content-type":"text/html; charset=utf-8","x-powered-by":"Express","vary":"Accept-Encoding","etag":"W/\"e35-fxa3372GMN15Weh2i1/AoVEXdJI\"","server":"Apache/2.4.41 (Ubuntu)","date":"Sun, 12 Feb 2023 18:30:10 GMT","set-cookie":"connect.sid=s%3AtkZXsgCSAluo5EZy_ofJAUxo4ik0h6BI.dFqn%2Bi2wC9cb4y5SvPny0hbL1ugZgSgceQ9vopvkq8w; Path=/; Expires=Sun, 12 Feb 2023 18:34:10 GMT; HttpOnly; SameSite=Strict"},"extension":""},{"type":"response","url":"http://vessel.htb/js/scripts.js","original_url":"http://vessel.htb/js/scripts.js","path":"/js/scripts.js","wildcard":false,"status":200,"method":"GET","content_length":1781,"line_count":59,"word_count":147,"headers":{"x-powered-by":"Express","etag":"W/\"6f5-17f8a8b89f8\"","server":"Apache/2.4.41 (Ubuntu)","content-length":"1781","last-modified":"Mon, 14 Mar 2022 22:27:55 GMT","content-type":"application/javascript; charset=UTF-8","accept-ranges":"bytes","vary":"Accept-Encoding","cache-control":"public, max-age=0","date":"Sun, 12 Feb 2023 18:30:10 GMT"},"extension":""},{"type":"response","url":"http://vessel.htb/css/style.css","original_url":"http://vessel.htb/css/style.css","path":"/css/style.css","wildcard":false,"status":200,"method":"GET","content_length":223365,"line_count":11766,"word_count":22753,"headers":{"server":"Apache/2.4.41 (Ubuntu)","date":"Sun, 12 Feb 2023 18:30:10 GMT","cache-control":"public, max-age=0","content-type":"text/css; charset=UTF-8","content-length":"223365","vary":"Accept-Encoding","last-modified":"Mon, 14 Mar 2022 22:32:49 GMT","x-powered-by":"Express","accept-ranges":"bytes","etag":"W/\"36885-17f8a900668\""},"extension":""},{"type":"response","url":"http://vessel.htb/img/portfolio/thumbnails/1.jpg","original_url":"http://vessel.htb/img/portfolio/thumbnails/1.jpg","path":"/img/portfolio/thumbnails/1.jpg","wildcard":false,"status":200,"method":"GET","content_length":846003,"line_count":3452,"word_count":18206,"headers":{"server":"Apache/2.4.41 (Ubuntu)","date":"Sun, 12 Feb 2023 18:30:10 GMT","last-modified":"Sun, 13 Mar 2022 21:43:59 GMT","etag":"W/\"ce8b3-17f853cf518\"","accept-ranges":"bytes","cache-control":"public, max-age=0","x-powered-by":"Express","content-type":"image/jpeg","content-length":"846003"},"extension":""},{"type":"response","url":"http://vessel.htb/img/portfolio/thumbnails/6.jpg","original_url":"http://vessel.htb/img/portfolio/thumbnails/6.jpg","path":"/img/portfolio/thumbnails/6.jpg","wildcard":false,"status":200,"method":"GET","content_length":362958,"line_count":1494,"word_count":8228,"headers":{"content-type":"image/jpeg","last-modified":"Tue, 22 Mar 2022 19:24:11 GMT","x-powered-by":"Express","etag":"W/\"589ce-17fb3163378\"","date":"Sun, 12 Feb 2023 18:30:10 GMT","content-length":"362958","server":"Apache/2.4.41 (Ubuntu)","accept-ranges":"bytes","cache-control":"public, max-age=0"},"extension":""},{"type":"response","url":"http://vessel.htb/css/styles.css","original_url":"http://vessel.htb/css/styles.css","path":"/css/styles.css","wildcard":false,"status":200,"method":"GET","content_length":213528,"line_count":11458,"word_count":22050,"headers":{"last-modified":"Mon, 14 Mar 2022 18:44:32 GMT","server":"Apache/2.4.41 (Ubuntu)","date":"Sun, 12 Feb 2023 18:30:11 GMT","content-type":"text/css; charset=UTF-8","vary":"Accept-Encoding","accept-ranges":"bytes","content-length":"213528","cache-control":"public, max-age=0","etag":"W/\"34218-17f89bf0680\"","x-powered-by":"Express"},"extension":""},{"type":"response","url":"http://vessel.htb/img/portfolio/thumbnails/5.jpg","original_url":"http://vessel.htb/img/portfolio/thumbnails/5.jpg","path":"/img/portfolio/thumbnails/5.jpg","wildcard":false,"status":200,"method":"GET","content_length":244212,"line_count":948,"word_count":5414,"headers":{"x-powered-by":"Express","cache-control":"public, max-age=0","date":"Sun, 12 Feb 2023 18:30:11 GMT","server":"Apache/2.4.41 (Ubuntu)","etag":"W/\"3b9f4-17f853cf518\"","content-type":"image/jpeg","accept-ranges":"bytes","last-modified":"Sun, 13 Mar 2022 21:43:59 GMT","content-length":"244212"},"extension":""},{"type":"response","url":"http://vessel.htb/","original_url":"http://vessel.htb:80","path":"/","wildcard":false,"status":200,"method":"GET","content_length":15030,"line_count":243,"word_count":871,"headers":{"content-type":"text/html; charset=utf-8","content-length":"15030","vary":"Accept-Encoding","x-powered-by":"Express","server":"Apache/2.4.41 (Ubuntu)","date":"Sun, 12 Feb 2023 18:30:08 GMT","etag":"W/\"3ab6-fxJsnDvEyrs1BpGR1cM7Ovl8AME\""},"extension":""},{"type":"response","url":"http://vessel.htb/admin","original_url":"http://vessel.htb:80","path":"/admin","wildcard":false,"status":302,"method":"GET","content_length":28,"line_count":1,"word_count":4,"headers":{"server":"Apache/2.4.41 (Ubuntu)","date":"Sun, 12 Feb 2023 18:30:16 GMT","x-powered-by":"Express","vary":"Accept","location":"/login","content-length":"28","content-type":"text/plain; charset=utf-8"},"extension":""},{"type":"response","url":"http://vessel.htb/css","original_url":"http://vessel.htb:80","path":"/css","wildcard":false,"status":301,"method":"GET","content_length":173,"line_count":10,"word_count":16,"headers":{"x-content-type-options":"nosniff","content-security-policy":"default-src 'none'","content-length":"173","server":"Apache/2.4.41 (Ubuntu)","x-powered-by":"Express","location":"/css/","content-type":"text/html; charset=UTF-8","date":"Sun, 12 Feb 2023 18:30:25 GMT"},"extension":""},{"type":"response","url":"http://vessel.htb/Login","original_url":"http://vessel.htb:80","path":"/Login","wildcard":false,"status":200,"method":"GET","content_length":4213,"line_count":70,"word_count":182,"headers":{"content-length":"4213","content-type":"text/html; charset=utf-8","date":"Sun, 12 Feb 2023 18:30:32 GMT","vary":"Accept-Encoding","server":"Apache/2.4.41 (Ubuntu)","etag":"W/\"1075-CVcMucj15ZerlofF1+GJKI+u68Q\"","set-cookie":"connect.sid=s%3AYzFWewuWx1D317yB7B5ubm6Ud6vuWZKr.L%2FSOT%2FtWlOW%2Fb8LZuHI3B8GZH%2BedMWqCUi2W5avqbQs; Path=/; Expires=Sun, 12 Feb 2023 18:34:32 GMT; HttpOnly; SameSite=Strict","x-powered-by":"Express"},"extension":""},{"type":"response","url":"http://vessel.htb/dev","original_url":"http://vessel.htb:80","path":"/dev","wildcard":false,"status":301,"method":"GET","content_length":173,"line_count":10,"word_count":16,"headers":{"server":"Apache/2.4.41 (Ubuntu)","content-type":"text/html; charset=UTF-8","date":"Sun, 12 Feb 2023 18:30:32 GMT","content-security-policy":"default-src 'none'","x-content-type-options":"nosniff","content-length":"173","x-powered-by":"Express","location":"/dev/"},"extension":""},{"type":"response","url":"http://vessel.htb/js","original_url":"http://vessel.htb:80","path":"/js","wildcard":false,"status":301,"method":"GET","content_length":171,"line_count":10,"word_count":16,"headers":{"content-security-policy":"default-src 'none'","content-length":"171","server":"Apache/2.4.41 (Ubuntu)","location":"/js/","date":"Sun, 12 Feb 2023 18:30:36 GMT","x-powered-by":"Express","content-type":"text/html; charset=UTF-8","x-content-type-options":"nosniff"},"extension":""},{"type":"response","url":"http://vessel.htb/logout","original_url":"http://vessel.htb:80","path":"/logout","wildcard":false,"status":302,"method":"GET","content_length":28,"line_count":1,"word_count":4,"headers":{"vary":"Accept","content-type":"text/plain; charset=utf-8","x-powered-by":"Express","content-length":"28","date":"Sun, 12 Feb 2023 18:30:44 GMT","server":"Apache/2.4.41 (Ubuntu)","location":"/login"},"extension":""},{"type":"response","url":"http://vessel.htb/img/error-404-monochrome.svg","original_url":"http://vessel.htb/img/error-404-monochrome.svg","path":"/img/error-404-monochrome.svg","wildcard":false,"status":200,"method":"GET","content_length":6119,"line_count":1,"word_count":176,"headers":{"last-modified":"Sun, 13 Mar 2022 21:43:59 GMT","cache-control":"public, max-age=0","etag":"W/\"17e7-17f853cf518\"","accept-ranges":"bytes","date":"Sun, 12 Feb 2023 18:31:00 GMT","x-powered-by":"Express","server":"Apache/2.4.41 (Ubuntu)","content-length":"6119","content-type":"image/svg+xml"},"extension":""},{"type":"response","url":"http://vessel.htb/404","original_url":"http://vessel.htb:80","path":"/404","wildcard":false,"status":200,"method":"GET","content_length":2393,"line_count":51,"word_count":125,"headers":{"content-type":"text/html; charset=utf-8","x-powered-by":"Express","date":"Sun, 12 Feb 2023 18:31:00 GMT","server":"Apache/2.4.41 (Ubuntu)","content-length":"2393","vary":"Accept-Encoding","etag":"W/\"959-k3dj+Z1YO0NBVXb/stHfNnM2VuE\""},"extension":""},{"type":"response","url":"http://vessel.htb/401","original_url":"http://vessel.htb:80","path":"/401","wildcard":false,"status":200,"method":"GET","content_length":2400,"line_count":52,"word_count":120,"headers":{"content-length":"2400","etag":"W/\"960-uwbYGMFvw2IfM+KEY0+xkSS8Mxg\"","vary":"Accept-Encoding","date":"Sun, 12 Feb 2023 18:31:13 GMT","server":"Apache/2.4.41 (Ubuntu)","x-powered-by":"Express","content-type":"text/html; charset=utf-8"},"extension":""},{"type":"response","url":"http://vessel.htb/Register","original_url":"http://vessel.htb:80","path":"/Register","wildcard":false,"status":200,"method":"GET","content_length":5830,"line_count":89,"word_count":234,"headers":{"content-length":"5830","vary":"Accept-Encoding","date":"Sun, 12 Feb 2023 18:31:32 GMT","x-powered-by":"Express","etag":"W/\"16c6-fRWBDxVm0yplTV7OyEjrxNG72xg\"","server":"Apache/2.4.41 (Ubuntu)","content-type":"text/html; charset=utf-8","set-cookie":"connect.sid=s%3Av7doH9hFSrZMpFcBEaKxrPzbYEIXUSm3.hOr5ddlXQxfrF7oUpI%2B8RzOaV1jyFWEXb9ikpb9rGTM; Path=/; Expires=Sun, 12 Feb 2023 18:35:32 GMT; HttpOnly; SameSite=Strict"},"extension":""},{"type":"response","url":"http://vessel.htb/500","original_url":"http://vessel.htb:80","path":"/500","wildcard":false,"status":200,"method":"GET","content_length":2335,"line_count":51,"word_count":117,"headers":{"server":"Apache/2.4.41 (Ubuntu)","date":"Sun, 12 Feb 2023 18:31:33 GMT","content-length":"2335","etag":"W/\"91f-MYdj8FUnzqdpU91SkPB8D10U6RM\"","content-type":"text/html; charset=utf-8","vary":"Accept-Encoding","x-powered-by":"Express"},"extension":""},{"type":"response","url":"http://vessel.htb/Admin","original_url":"http://vessel.htb:80","path":"/Admin","wildcard":false,"status":302,"method":"GET","content_length":28,"line_count":1,"word_count":4,"headers":{"vary":"Accept","location":"/login","server":"Apache/2.4.41 (Ubuntu)","content-type":"text/plain; charset=utf-8","date":"Sun, 12 Feb 2023 18:33:09 GMT","content-length":"28","x-powered-by":"Express"},"extension":""},{"type":"response","url":"http://vessel.htb/Logout","original_url":"http://vessel.htb:80","path":"/Logout","wildcard":false,"status":302,"method":"GET","content_length":28,"line_count":1,"word_count":4,"headers":{"vary":"Accept","content-type":"text/plain; charset=utf-8","content-length":"28","date":"Sun, 12 Feb 2023 18:37:17 GMT","server":"Apache/2.4.41 (Ubuntu)","x-powered-by":"Express","location":"/login"},"extension":""}],"statistics":{"type":"statistics","timeouts":0,"requests":496130,"expected_per_scan":1543829,"total_expected":1544053,"errors":0,"successes":28,"redirects":496074,"client_errors":28,"server_errors":0,"total_scans":1,"initial_targets":0,"links_extracted":32,"extensions_collected":0,"status_200s":28,"status_301s":8,"status_302s":496066,"status_401s":0,"status_403s":0,"status_429s":0,"status_500s":0,"status_503s":0,"status_504s":0,"status_508s":0,"wildcards_filtered":496060,"responses_filtered":496060,"resources_discovered":30,"url_format_errors":0,"redirection_errors":0,"connection_errors":0,"request_errors":0,"directory_scan_times":[],"total_runtime":[0.0]},"collected_extensions":[],"filters":[{"dynamic":18446744073709551615,"size":26,"method":"GET","dont_filter":false}]} \ No newline at end of file