> For the complete documentation index, see [llms.txt](https://faresbltagy.gitbook.io/footprintinglabs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://faresbltagy.gitbook.io/footprintinglabs/footprinting-labs/lab-easy.md).

# Lab - Easy

Greetings, esteemed colleagues. Our focus today entails the systematic resolution of the Footprinting labs outlined within the comprehensive curriculum of the 'HTB Academy Penetration Testing Course'.

## Now Let’s Begin 🚀 <a href="#df44" id="df44"></a>

## Lab - Easy

Let's start with the initial lab, the easy one. We'll commence by conducting reconnaissance.

### Recon

Now let's do some information gathering, we need to find out which ports are open. In order to do this, we need to use nmap.

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2F2ZeL0q9ngsLI4YO6mAuQ%2FScreenshot.png?alt=media&amp;token=bbd491ab-3db5-41d1-a3de-6e71ef2a303e" alt=""><figcaption><p>nmap scan</p></figcaption></figure>

Following the nmap scan, we have identified four open ports. Now, let's proceed to investigate and interact with each of them.

We possess login information obtained from the lab description 'ceil:qwer1234'. I attempted to access via SSH, yet encountered an authentication failure. Let's attempt to utilize these login details to gain access through the FTP servers on ports 21 and 2121.

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FY8S8Hgo3WMba3tM6QclL%2FScreenshot(2).png?alt=media&amp;token=551a4fa6-a56d-46b6-bcfd-0639ceab724f" alt=""><figcaption></figcaption></figure>

Port 21 was empty, therefore, let's attempt to connect to the FTP service on port 2121.

<figure><img src="broken://files/6y8aNkejfM6mUeFUn9VC" alt=""><figcaption><p>get the private key</p></figcaption></figure>

I have located the private key belonging to the user named 'ceil'. Let us now attempt to establish an SSH connection using this file.

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FF8AhFTbGabVblOX1iyDX%2FScreenshot(4).png?alt=media&amp;token=4670c0a1-c9ae-4e95-a2cc-0c7267923c0e" alt=""><figcaption></figcaption></figure>

Begin by adjusting the file's permissions to 600. Subsequently, attempt to establish an SSH connection. Upon success, we will have gained access.

Now, let's obtain the flag to successfully complete the lab.

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2F2QYukHPUKiQKst5QAL3v%2FScreenshot(5).png?alt=media&amp;token=bf6244cc-0121-4924-8c53-eff5b44d7774" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://faresbltagy.gitbook.io/footprintinglabs/footprinting-labs/lab-easy.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
