Challenge HN: There's only one truly open port on this machine. Can you find it?
There's a VPS on 152.70.178.90 with a quite unique firewall configuration. Open to the internet are two services: an HTTP server on :80 for verifying my ownership of the machine, and... something else, somewhere. Your task is to find and connect to the second service – bonus points if you successfully authenticate. (yeah, I know I said only one port but c'mon, the HTTP server doesn't count)
There's no port knocking, fail2ban, or anything like that. The port is always open for everyone to see. The VPS is also on a gigabit connection, so go wild! Just don't purposefully DDoS it please, for the sake of everyone else.
Also, you're more than welcome to crosspost this on reddit, lemmy, or wherever else! I'll likely release the iptables config once someone gets in and documents how.
13 comments
[ 4.3 ms ] story [ 54.8 ms ] threadAnother brand new account jumps in to participate, but again is asking for help on how to pen test.
Looks legit.
I also really wasn't looking for help on how to pentest, I think I'm pretty capable as is. The server has such an unusual firewall config though (even outside the 'all ports look open to a basic `nmap -sS`' stuff) that I thought it could be a nice learning experience for folks, or something.
That other account is an irl friend of mine.