Creds
wade : parzival
80/tcp open http Microsoft IIS httpd 10.0 | http-methods: |_ Potentially risky methods: TRACE |_http-title: IIS Windows Server |http-server-header: Microsoft-IIS/10.0 3389/tcp open ms-wbt-server Microsoft Terminal Services | rdp-ntlm-info: | Target_Name: RETROWEB | NetBIOS_Domain_Name: RETROWEB | NetBIOS_Computer_Name: RETROWEB | DNS_Domain_Name: RetroWeb | DNS_Computer_Name: RetroWeb | Product_Version: 10.0.14393 | System_Time: 2022-05-15T16:41:31+00:00 |_ssl-date: 2022-05-15T16:41:34+00:00; 0s from scanner time. | ssl-cert: Subject: commonName=RetroWeb | Not valid before: 2022-05-14T16:33:00 |_Not valid after: 2022-11-13T16:33:00 Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
000004255: 200 545 L 2796 W 30386 Ch “http://10.10.14.71/retro//”
-Did an additional dir brute on /retro/ and found WordPress
-Ran a wpscan and found the following:
WordPress version 5.2.1 identified (Insecure, released on 2019-05-21).