
While enumerating this machine, I found a xbin folder under /system directory.Īctive Internet connections (only servers ) Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program Name Privilege Escalation # Shell as root # ADB # rw-rw- 1 root everybody 33 18:28 user.txt

userReturnĭrwxrwx- 2 root everybody 4096 17:16 Alarmsĭrwxrwx- 3 root everybody 4096 17:16 Androidĭrwxrwx- 2 root everybody 4096 02:38 DCIMĭrwxrwx- 2 root everybody 4096 17:37 Downloadĭrwxrwx- 2 root everybody 4096 17:16 Moviesĭrwxrwx- 2 root everybody 4096 17:16 Musicĭrwxrwx- 2 root everybody 4096 17:16 Notificationsĭrwxrwx- 2 root everybody 4096 17:16 Picturesĭrwxrwx- 2 root everybody 4096 17:16 Podcastsĭrwxrwx- 2 root everybody 4096 17:16 Ringtonesĭrwxrwx- 3 root everybody 4096 17:30 backupsĭrwxrwx- 2 root everybody 4096 02:12 dianxinos Total 68 drwxrwx- 15 root everybody 4096 02:12. Interacting with port 59777 from the browser gives me the response below, and no further information given. If I search for port 5975 on Google, the results show that these ports are belong to ES File Explorer. No reply given from 37817, it showed in a close state when I tried to rescan it. Nmap done: 1 IP address (1 host up) scanned in 105.79 seconds If you know the service/version, please submit the following fingerprints at : |_http-title: Site doesn't have a title (text/plain ).Ģ services unrecognized despite returning data. |_http-title: Site doesn 't have a title (text/html).ĥ9777/tcp open http Bukkit JSONAPI httpd for Minecraft game server 3.6.0 or older | Content-Length: 54 | Content-Type: text/plain charset =US-ASCIIĤ2135/tcp open http ES File Explorer Name Response httpd | Content-Length: 71 | Content-Type: text/plain charset =US-ASCII | Content-Length: 73 | Content-Type: text/plain charset =US-ASCII | Content-Length: 39 | Content-Type: text/plain charset =US-ASCII

| Content-Length: 26 | Content-Type: text/plain charset =US-ASCII | Content-Length: 29 | Content-Type: text/plain charset =US-ASCII | Content-Length: 22 | Content-Type: text/plain charset =US-ASCII Host is up, received reset ttl 63 (0.057s latency ).Ģ222/tcp open EtherNetIP-1 syn-ack ttl 63 5555/tcp filtered freeciv no-responseģ7817/tcp open unknown syn-ack ttl 63 42135/tcp open unknown syn-ack ttl 63 59777/tcp open unknown syn-ack ttl 63 Nmap done: 1 IP address ( 1 host up ) scanned in 38.81 seconds
