1. PORT STATE SERVICE 21/tcp open ftp 22/tcp open ssh 25/tcp open smtp 42/tcp filtered nameserver 80/tcp open http 110/tcp open pop3 135/tcp filtered msrpc 139/tcp filtered netbios-ssn 143/tcp open imap 443/tcp open https 445/tcp filtered microsoft-ds 993/tcp open imaps 995/tcp open pop3s 3306/tcp open mysql 8009/tcp open ajp13 8080/tcp open http-proxy 8081/tcp open blackice-icecap 10000/tcp open snet-sensor-mgmt

1.1. 22/tcp open ssh OpenSSH 4.3 (protocol 2.0) | ssh-hostkey: 1024 6c:ff:ea:f2:7f:a9:21:b7:77:30:35:78:9d:7d:35:22 (DSA) |_2048 b5:76:98:66:f2:df:dd:8d:1a:fb:3a:e1:58:74:41:b4 (RSA)

1.2. 21/tcp open ftp vsftpd 2.0.5

1.3. mysql MySQL 5.0.77

2. target info

2.1. 4rum vbb 4.1.0

2.2. admin acc: Zent

2.3. admincp link:

3. whois domain

3.1. Domain Name: Registrar: LLC Expiration Date: 2012-11-19 03:46:46 Creation Date: 2010-11-19 03:46:46 Name Servers:

4. hosting info

4.1. used distro: CentOS

4.2. New node

5. exploit

5.1. sql injection: group in search.php