C:\Users\Yongz\nmap# nmap -sn 192.168.146.0/24 Starting Nmap 7.92 ( https://nmap.org ) at 2022-04-25 11:08 中国标准时间 Nmap scan report for 192.168.146.147 Host is up (0.00025s latency). MAC Address: 00:0C:29:D3:73:91 (VMware) Nmap scan report for 192.168.146.254 Host is up (0.00s latency). MAC Address: 00:50:56:E0:72:82 (VMware) Nmap scan report for 192.168.146.1 Host is up. Nmap done: 256 IP addresses (3 hosts up) scanned in 21.93 seconds
判断出 192.168.146.147 为靶机 IP 地址。
服务探测
1 2 3 4 5 6 7 8 9 10 11 12 13
C:\Users\Yongz\nmap# nmap -sS -sV 192.168.146.147 Starting Nmap 7.92 ( https://nmap.org ) at 2022-04-25 11:10 中国标准时间 Nmap scan report for 192.168.146.147 Host is up (0.00067s latency). Not shown: 998 closed tcp ports (reset) PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.8 (Ubuntu Linux; protocol 2.0) 80/tcp open http Apache httpd 2.4.18 ((Ubuntu)) MAC Address: 00:0C:29:D3:73:91 (VMware) Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 18.76 seconds
username : admin password : 3v1l_H@ck3r The 2nd flag is : {7412574125871236547895214}
文件上传
用上述账号密码来尝试 SSH 登录。
1 2 3 4 5 6 7
C:\Users\Yongz\dirsearch# ssh admin@192.168.146.147 The authenticity of host '192.168.146.147 (192.168.146.147)' can't be established. ECDSA key fingerprint is SHA256:ThPvIGqyDX2PSqt5JWHyy/J/Hy2hK5aVcpKTpkTKHQE. Are you sure you want to continue connecting (yes/no/[fingerprint])? yes Warning: Permanently added '192.168.146.147' (ECDSA) to the list of known hosts. admin@192.168.146.147's password: Permission denied, please try again.