Hints

  1. Notice the version and you may get a passage through it.
  2. What is being run by highest authority? any events? also its already abandoned on 2012.

Nmap Scan

➜  connected cat rust.result 
.----. .-. .-. .----..---.  .----. .---.   .--.  .-. .-.
| {}  }| { } |{ {__ {_   _}{ {__  /  ___} / {} \ |  `| |
| .-. \| {_} |.-._} } | |  .-._} }\     }/  /\  \| |\  |
`-' `-'`-----'`----'  `-'  `----'  `---' `-'  `-'`-' `-'
The Modern Day Port Scanner.
________________________________________
: http://discord.skerritt.blog         :
: https://github.com/RustScan/RustScan :
 --------------------------------------
Nmap? More like slowmap.🐢

[~] The config file is expected to be at "/home/blackbear/.rustscan.toml"
[~] File limit higher than batch size. Can increase speed by increasing batch size '-b 924'.
Open 10.129.5.76:22
Open 10.129.5.76:80
Open 10.129.5.76:443
[~] Starting Script(s)
[~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-07-13 10:16 -0400
Initiating Ping Scan at 10:16
Scanning 10.129.5.76 [4 ports]
Completed Ping Scan at 10:16, 0.08s elapsed (1 total hosts)
Initiating SYN Stealth Scan at 10:16
Scanning connected.htb (10.129.5.76) [3 ports]
Discovered open port 443/tcp on 10.129.5.76
Discovered open port 80/tcp on 10.129.5.76
Discovered open port 22/tcp on 10.129.5.76
Completed SYN Stealth Scan at 10:16, 0.04s elapsed (3 total ports)
Nmap scan report for connected.htb (10.129.5.76)
Host is up, received echo-reply ttl 63 (0.017s latency).
Scanned at 2026-07-13 10:16:40 EDT for 0s

PORT    STATE SERVICE REASON
22/tcp  open  ssh     syn-ack ttl 63
80/tcp  open  http    syn-ack ttl 63
443/tcp open  https   syn-ack ttl 63

Read data files from: /usr/share/nmap
Nmap done: 1 IP address (1 host up) scanned in 0.49 seconds
           Raw packets sent: 7 (284B) | Rcvd: 44 (10.240KB)

Enumeration

For the HTTP port, we got FreePBX version 16.0.40.7

🔒

Protected Content

Password is /etc/shadow of root (root:$1$[REDACTED]/:[REDACTED]:0:99999:7:::)