Port recognition withnmapor you can use recon

└─# recon appointment.htb

[OS] Linux (99%)
Starting Nmap 7.92 ( https://nmap.org ) at 2022-07-21 11:15 EDT
Initiating Ping Scan at 11:15
Scanning appointment.htb ( [4 ports]
Completed Ping Scan at 11:15, 0.06s elapsed (1 total hosts)
Initiating SYN Stealth Scan at 11:15
Scanning appointment.htb ( [65535 ports]
Discovered open port 80/tcp on
Completed SYN Stealth Scan at 11:15, 14.40s elapsed (65535 total ports)
Nmap scan report for appointment.htb (
Host is up (0.067s latency).
Not shown: 65336 closed tcp ports (reset), 198 filtered tcp ports (no-response)
Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
80/tcp open  http

Nmap done: 1 IP address (1 host up) scanned in 14.63 seconds
           Raw packets sent: 71640 (3.152MB) | Rcvd: 67934 (2.717MB)

[+] [fuzzin server]
http://appointment.htb [200 OK] Apache[2.4.38], Bootstrap, Country[RESERVED][ZZ], HTML5, HTTPServer[Debian Linux][Apache/2.4.38 (Debian)], IP[], JQuery[3.2.1], PasswordField[password], Script, Title[Login]

START_TIME: Thu Jul 21 11:15:56 2022
URL_BASE: http://appointment.htb:80/
WORDLIST_FILES: /usr/share/dirb/wordlists/common.txt
OPTION: Not Recursive


GENERATED WORDS: 4612                                                          

---- Scanning URL: http://appointment.htb:80/ ----
==> DIRECTORY: http://appointment.htb:80/css/                                                                                                                                                     
==> DIRECTORY: http://appointment.htb:80/fonts/                                                                                                                                                   
==> DIRECTORY: http://appointment.htb:80/images/                                                                                                                                                  
+ http://appointment.htb:80/index.php (CODE:200|SIZE:4896)                                                                                                                                        
==> DIRECTORY: http://appointment.htb:80/js/                                                                                                                                                      
+ http://appointment.htb:80/server-status (CODE:403|SIZE:280)                                                                                                                                     
==> DIRECTORY: http://appointment.htb:80/vendor/                                                                                                                                                  
END_TIME: Thu Jul 21 11:21:15 2022

recon http web service on port 80

We have a login

Trying SQL injection ' or 1=1; --