Billu-Box Full Tutorial From Vulnhub


In this post, You will learn how to CTF the Billu box from vulnhub and below is the video format of the post, Check it out

To Download the box [Click here]


Hacking phases in Billu box

  • Finding target IP
  • Network mapping (NMAP)
  • Directory busting
  • Enumeration
  • ssh connection to target
  • Accessing root

Let’s Hack Billu Box

Finding target IP

To find the target IP just enter sudo arp-scan -l or net discover command

sudo arp-scan -l

In my case the target IP is

Nmap Scan

Now, Let’s do the NMap scan to find the open Ports and the service and version to do that just enter the below command.

nmap -p- -sV -A -T4

From the above scan we could say that the port 22 (ssh) and the port 80 (http) are open. There is a way to connect to the ssh if we knew the password.

Directory Busting

I thought of directory busting the target website so, that I could get some of the directories and I could enumerate.

Luckily I have found the /phpmy

dirb /usr/share/wordlists/dirb/big.txt


I saw /test.php that reads a parameter called file so i passed it using curl 

curl -X POST -F 'file=/etc/issue'

Then i tried to extract phpmyadmin’s config file

curl -X POST -F 'file=/var/www/phpmy/'

We could see the username and the password so, let’s connect it using the ssh service.

ssh connection to target

I tried to access with username : root, password : roottoor and i failed then i treid ssh.

ssh root@
cat <flag>

We have successfully captured the flag.



According to me this is the simplest box I have ever played from vulnhub and the rating is going to be just 0.5 out of 10 and hope you try it.

See ya in the next post ????????

