Acid – Reloaded | Root privileged Escalation

nmap -sT -p- -Pn IP -oN nmap_scan.txt

For open filtered port I’ve run this command

for x in 3 2 1; do nmap -Pn –host_timeout 201 –max-retries 0 -p $x; done

Or I’ll post bash script later very soon

P.S. If you’re using Virtualbox, please be sure that you’re using just Host-only Adapter, otherwise the knock will fail. Don’t know why, but as soon as I’ve changed it the port was open.

After knocking I’ve run nmap again to check what was changed, and this is what I’ve found:

nmap -sS -p- -Pn IP -oN nmap_scan_stealth_2.txt

So, Dirbuster has always been my friend.
sqlmap -u “” –dbs –dbms=MySQL -p “id” –tamper=space2comment

