❯ sudo arp-scan -l [sudo] password for Pepster: Interface: eth0, type: EN10MB, MAC: 5e:bb:f6:9e:ee:fa, IPv4: 192.168.60.100 Starting arp-scan 1.10.0 with 256 hosts (https://github.com/royhills/arp-scan) 192.168.60.1 00:50:56:c0:00:08 VMware, Inc. 192.168.60.2 00:50:56:e3:f6:57 VMware, Inc. 192.168.60.211 08:00:27:ec:12:5f PCS Systemtechnik GmbH 192.168.60.254 00:50:56:e5:e5:eb VMware, Inc.
4 packets received by filter, 0 packets dropped by kernel Ending arp-scan 1.10.0: 256 hosts scanned in 2.094 seconds (122.25 hosts/sec). 4 responded ❯ export ip=192.168.60.211 ❯ rustscan -a $ip .----. .-. .-. .----..---. .----. .---. .--. .-. .-. | {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| | | .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ | `-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-' The Modern Day Port Scanner. ________________________________________ : http://discord.skerritt.blog : : https://github.com/RustScan/RustScan : -------------------------------------- Scanning ports like it's my full-time job. Wait, it is.
[~] The config file is expected to be at "/home/Pepster/.rustscan.toml" [!] File limit is lower than default batch size. Consider upping with --ulimit. May cause harm to sensitive servers [!] Your file limit is very small, which negatively impacts RustScan's speed. Use the Docker image, or up the Ulimit with '--ulimit 5000'. Open 192.168.60.211:22 Open 192.168.60.211:80 Open 192.168.60.211:3306 [~] Starting Script(s) [~] Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-02-26 21:19 CST Initiating ARP Ping Scan at 21:19 Scanning 192.168.60.211 [1 port] Completed ARP Ping Scan at 21:19, 0.09s elapsed (1 total hosts) Initiating Parallel DNS resolution of 1 host. at 21:19 Completed Parallel DNS resolution of 1 host. at 21:19, 0.01s elapsed DNS resolution of 1 IPs took 0.01s. Mode: Async [#: 3, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0] Initiating SYN Stealth Scan at 21:19 Scanning 192.168.60.211 [3 ports] Discovered open port 3306/tcp on 192.168.60.211 Discovered open port 22/tcp on 192.168.60.211 Discovered open port 80/tcp on 192.168.60.211 Completed SYN Stealth Scan at 21:19, 0.03s elapsed (3 total ports) Nmap scan report for 192.168.60.211 Host is up, received arp-response (0.00036s latency). Scanned at 2025-02-26 21:19:01 CST for 0s PORT STATE SERVICE REASON 22/tcp open ssh syn-ack ttl 64 80/tcp open http syn-ack ttl 64 3306/tcp open mysql syn-ack ttl 64 MAC Address: 08:00:27:EC:12:5F (Oracle VirtualBox virtual NIC) Read data files from: /usr/share/nmap Nmap done: 1 IP address (1 host up) scanned in 0.34 seconds Raw packets sent: 4 (160B) | Rcvd: 4 (160B)
浏览器访问一下80端口,编辑hosts添加一下域名
1 2 3
❯ sudo vim /etc/hosts [sudo] password for Pepster: 192.168.60.211 www.mywaf.nyx
入口
发现有个注册的表单
注册成功后
又两个新的域名,添加一下
1 2
❯ sudo vim /etc/hosts 192.168.60.211 www.mywaf.nyx maintenance.mywaf.nyx configure.mywaf.nyx