<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vulnyx on zer0arc4</title><link>https://zer0arc4.github.io/writeups/vulnyx/</link><description>Recent content in Vulnyx on zer0arc4</description><generator>Hugo</generator><language>en-us</language><atom:link href="https://zer0arc4.github.io/writeups/vulnyx/index.xml" rel="self" type="application/rss+xml"/><item><title>Bank</title><link>https://zer0arc4.github.io/writeups/vulnyx/bank/</link><pubDate>Tue, 09 Jun 2026 21:10:28 +0530</pubDate><guid>https://zer0arc4.github.io/writeups/vulnyx/bank/</guid><description>&lt;hr&gt;
&lt;h1 id="vulnyx--bank-writeup"&gt;&lt;a href="https://vulnyx.com/"&gt;VulNyx&lt;/a&gt; – BANK Writeup&lt;/h1&gt;
&lt;img width="671" height="426" alt="image" src="https://github.com/user-attachments/assets/9b4db2b3-4119-4c80-83f6-b70d05cde7c8" /&gt;
&lt;hr&gt;
&lt;h1 id="-target-information"&gt;🎯 Target Information&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Platform:&lt;/strong&gt; VulNyx.com&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Machine Name:&lt;/strong&gt; BANK&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Key Vulnerabilities:&lt;/strong&gt;
&lt;ul&gt;
&lt;li&gt;SMB Anonymous Share Access&lt;/li&gt;
&lt;li&gt;Information Disclosure&lt;/li&gt;
&lt;li&gt;JWT Information Leakage&lt;/li&gt;
&lt;li&gt;Weak Administrative Credentials&lt;/li&gt;
&lt;li&gt;File Upload Bypass&lt;/li&gt;
&lt;li&gt;Remote Code Execution (RCE)&lt;/li&gt;
&lt;li&gt;KeePass Credential Exposure&lt;/li&gt;
&lt;li&gt;Docker Group Privilege Escalation&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h1 id="-network-discovery"&gt;🔍 Network Discovery&lt;/h1&gt;
&lt;p&gt;First, scan the local network to identify active hosts using &lt;code&gt;arp-scan&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo arp-scan --localnet
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="result"&gt;Result&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;$ sudo arp-scan --localnet
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;[sudo] password for arc: 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Sorry, try again.
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;[sudo] password for arc: 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Sorry, try again.
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;[sudo] password for arc: 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Interface: eth0, type: EN10MB, MAC: 00:0c:29:8d:a8:e2, IPv4: 172.29.112.76
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Starting arp-scan 1.10.0 with 256 hosts (https://github.com/royhills/arp-scan)
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;172.29.112.109 fe:f7:e9:58:e3:54 (Unknown: locally administered)
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;172.29.112.122 62:70:c1:a1:26:26 (Unknown: locally administered)
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;172.29.112.170 00:0c:29:09:d5:97 VMware, Inc.
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;3 packets received by filter, 0 packets dropped by kernel
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Ending arp-scan 1.10.0: 256 hosts scanned in 2.098 seconds (122.02 hosts/sec). 3 responded
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The target machine IP address was identified as:&lt;/p&gt;</description></item></channel></rss>