┌──(root㉿kakeru)-[~/tmp] └─# nmap -A 192.168.179.169 -p- Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-0911:22 CST Nmap scan report for 192.168.179.169 (192.168.179.169) Host is up (0.0014s latency). Not shown:65533 closed tcp ports (reset) PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 7.9p1 Debian 10+deb10u2 (protocol 2.0) | ssh-hostkey: | 20488a:cb:7e:8a:72:82:84:9a:11:43:61:15:c1:e6:32:0b (RSA) | 2567a:0e:b6:dd:8f:ee:a7:70:d9:b1:b5:6e:44:8f:c0:49 (ECDSA) |_ 25680:18:e6:c7:01:0e:c6:6d:7d:f4:d2:9f:c9:d0:6f:4c (ED25519) 80/tcp open http nginx 1.14.2 |_http-server-header: nginx/1.14.2 |_http-title: Site doesn't have a title (text/html). MAC Address: AA:6D:30:09:71:E8 (Unknown) Device type: general purpose Running: Linux 4.X|5.X OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 OS details: Linux 4.15-5.19, OpenWrt 21.02 (Linux 5.4) Network Distance:1 hop Service Info:OS: Linux; CPE: cpe:/o:linux:linux_kernel
TRACEROUTE HOP RTT ADDRESS 11.39 ms 192.168.179.169 (192.168.179.169)
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done:1 IP address (1 host up) scanned in9.93 seconds
web探测
1 2 3 4 5
┌──(root㉿kakeru)-[~/tmp] └─# curl 192.168.179.169 hi
扫到一个robots.txt 访问发现是一个摩斯密码和一个shehatesme,解密 解密时候的结果是hi again 那目标就是第二行的内容了 在web访问这个目录,出现一段话
1
She hates me because I FOUND THE REAL SECRET! I putin this directorya lot of .txt files. ONEof .txt filescontains credentials like "theuser/thepass"to access to her system! All that you need is an small dict from Seclist!
┌──(root㉿kakeru)-[~/tmp] └─# ssh jaime11@192.168.179.169 The authenticity of host '192.168.179.169 (192.168.179.169)' can't be established. ED25519 key fingerprint is SHA256:e/Y+QbyX33+qoiZpch9G5Mgf32Y1Cj2eBFPlMp3Qx10. This keyisnot known by any other names. Are you sure you want tocontinue connecting (yes/no/[fingerprint])? yes Warning: Permanently added '192.168.179.169' (ED25519) to the list of known hosts. jaime11@192.168.179.169's password: Permission denied, please try again. jaime11@192.168.179.169's password:
The programs included with the Debian GNU/Linux system are free software; the exact distribution terms foreach program are described in the individual files in /usr/share/doc/*/copyright.
Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent permitted by applicable law. Last login: Sun Sep 2700:41:282020 -bash: warning: setlocale: LC_ALL: cannot change locale (en_US.UTF-8) theuser@suidy:~$
suidy@suidy:/home$ cd suidy/ suidy@suidy:/home/suidy$ ls note.txt suidyyyyy suidy@suidy:/home/suidy$ cat note.txt I love SUID files! The best file is suidyyyyy because users can use it to feel as I feel. root know it and run an script to be sure that my file has SUID. If you are "theuser" I hate you!
-suidy
1 2 3 4 5 6 7 8 9 10
suidy@suidy:/home$ cd suidy/ suidy@suidy:/home/suidy$ ls note.txt suidyyyyy suidy@suidy:/home/suidy$ cat note.txt I love SUID files! The best file is suidyyyyy because users can use it to feel as I feel. root know it and run an script to be sure that my file has SUID. If you are "theuser" I hate you!
-suidy
1 2
suidy@suidy:/home/suidy$ file suidyyyyy suidyyyyy: setuid, setgid ELF 64-bit LSB pie executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=a68ca005dccaf529f434e0408b05dc8614758fb7, not stripped