May 21st 2023


nmap -p 22,80,5132,8433 -sV -vvv -T4 --open -Pn

New option --open = only shows open ports

Also tip for -Pn is if I know a port is open but being blocked by a firewall or a proxy etc, I can force normal scanning since nmap will typically scan if it sees the host is up.

22/tcp   open  ssh     syn-ack OpenSSH 8.2p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)

80/tcp   open  http    syn-ack nginx 1.18.0 (Ubuntu)

5132/tcp open  unknown syn-ack

8433/tcp open  http    syn-ack Werkzeug httpd 2.0.2 (Python 3.8.10)

Check the website on 80

Now to check port 5132

Run nc to check

nc -v 5132

nc -v 5132 inverse host lookup failed: Unknown host

(UNKNOWN) [] 5132 (?) open

Enter Username: admin One Shot

Enter OTP: 3425752 Random

Incorrect username or password

Service asks for an OTP

8433 runs GraphQL with the login format as seen in the code comments

 Use graphQL to pull data from the app





  "data": {

    "getOTP": "Your One Time Password is: nuWWLk8Ub05tP6zJ"