> For the complete documentation index, see [llms.txt](https://oklencodes.gitbook.io/untitled/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://oklencodes.gitbook.io/untitled/ctfs/explore-android-box/initial-foothold.md).

# Initial foothold

![](https://2022164620-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtzurpgroDJSMn9AFVmQP%2Fuploads%2FMuZ4hSjeKrnZs03zOgxY%2Fimage%204.PNG?alt=media\&token=f451dccd-45b9-4668-bc83-9221fb8d1ad1)

![commands](https://2022164620-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtzurpgroDJSMn9AFVmQP%2Fuploads%2F5GcLc1yykf8DBE3Y3utP%2Fimage%205%20commands.PNG?alt=media\&token=fa245c2a-601b-493a-ab4c-bd2b38f66411)

I then chose to list files but there looked like there would atleast be 50 of them, so I decided to look at the next thing below which were pictures.

![](https://2022164620-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtzurpgroDJSMn9AFVmQP%2Fuploads%2FhJWEsQAZKi6ehT2pgRwN%2Fimage%206.PNG?alt=media\&token=ed070fbe-c4b7-47c9-8aa2-94742f61ab7b)

The image "creds" sounded interesting so that was the one I wanted to get first

![](https://2022164620-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtzurpgroDJSMn9AFVmQP%2Fuploads%2FO2JDfo3kbTwzigwWCeXh%2Fimage%207.PNG?alt=media\&token=fb5d7a94-c060-472d-a3ac-91cd68433030)

Using the script I was able to get the image, it was automatically saved as out.dat - To me this had to be ssh creds which would make sense as the initial nmap scan discovered ssh port 2222
