Now we have a password for something. Let's try looking for a username we can use together with the password.
Enum4linux is quite a handy tool for that task. I proceeded to enumerate the box using Enum4linux to see whether I can get usernames.
Enum4linux found a user!
Found username
Now that we have a username and a password, I attempted to log into the box using the credentials, but was unsuccessful due to incorrect login information. It appears that the credentials are intended for a different service.
Failed login attempt
The hunt continues.
Next, I proceeded to investigate the other HTTP-related port. Our Nmap scan had revealed that port 20000 was open and hosting a mini-server.
Port 20000 opens a Usermin login page.
I attempted authenticating into the portal using the credentials we found and I was successful!
Inside the dashboard, I found a terminal and my eyes lit up!