Expressway Writeup

Published on January 19, 2026


Expressway Banner

I. About

Expressway is a box that focuses on the exploitation of ...

II. Service Enumeration

Port Scan Results

Protocols Open Ports
TCP 22
UDP 68, 69, 500, 4500

TCP

I used nmap to scan the target for open TCP ports.

└─$ sudo nmap -sS -sV -sC 10.129.45.122 
[sudo] password for user: 
Starting Nmap 7.98 ( https://nmap.org ) at 2026-01-18 15:15 +0100
Nmap scan report for 10.129.45.122
Host is up (0.075s latency).
Not shown: 999 closed tcp ports (reset)
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 10.0p2 Debian 8 (protocol 2.0)
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
  • -sC: default script
  • -sV: to enumerate versions

UDP

I used nmap to scan the target for open UDP ports.

└─$ sudo nmap -sU -sV -sC 10.129.45.122   
[sudo] password for user: 
Starting Nmap 7.98 ( https://nmap.org ) at 2026-01-18 14:27 +0100
Nmap scan report for 10.129.45.122
Host is up (0.024s latency).
Not shown: 996 closed udp ports (port-unreach)
PORT     STATE         SERVICE   VERSION
68/udp   open|filtered dhcpc
69/udp   open          tftp      Netkit tftpd or atftpd
500/udp  open          isakmp?
| ike-version: 
|   attributes: 
|     XAUTH
|_    Dead Peer Detection v1.0
| fingerprint-strings: 
|   IKE_MAIN_MODE: 
|_    "3DUfwR`
4500/udp open|filtered nat-t-ike
🔒

Active Lab

This section of the write-up is intentionally hidden while the lab is still active, in order to respect the platform rules.

It will be released once the lab is retired.