PORT STATE SERVICE 21/tcp open ftp 22/tcp open ssh 80/tcp open http 81/tcp open hosts2-ns 443/tcp open https 3000/tcp open ppp 3001/tcp open nessus 3003/tcp open cgms 3306/tcp open mysql 5432/tcp open postgresql
PORT STATE SERVICE VERSION 21/tcp open ftp vsftpd 3.0.3 22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.4 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 3072 23:4c:6f:ff:b8:52:29:65:3d:d1:4e:38:eb:fe:01:c1 (RSA) | 256 0d:fd:36:d8:05:69:83:ef:ae:a0:fe:4b:82:03:32:ed (ECDSA) |_ 256 cc:76:17:1e:8e:c5:57:b2:1f:45:28:09:05:5a:eb:39 (ED25519) 80/tcp open http Apache httpd 2.4.41 ((Ubuntu)) |_http-server-header: Apache/2.4.41 (Ubuntu) |_http-title: Apache2 Ubuntu Default Page: It works 81/tcp open http Apache httpd 2.4.41 ((Ubuntu)) |_http-title: Test Page for the Nginx HTTP Server on Fedora |_http-server-header: Apache/2.4.41 (Ubuntu) 443/tcp open http Apache httpd 2.4.41 |_http-title: Apache2 Ubuntu Default Page: It works |_http-server-header: Apache/2.4.41 (Ubuntu) 3000/tcp open ppp? 3001/tcp open nessus? 3003/tcp open cgms? 3306/tcp open mysql MySQL (unauthorized) 5432/tcp open postgresql PostgreSQL DB 12.9 - 12.13 | ssl-cert: Subject: commonName=aero | Subject Alternative Name: DNS:aero | Not valid before: 2021-05-10T22:20:48 |_Not valid after: 2031-05-08T22:20:48 |_ssl-date: TLS randomness does not represent time
Service Info: Host: 127.0.0.2; OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
靶机为 Linux 环境,开放有 FTP、SSH、HTTP、Mysql、PostgreSQL 服务,以及未识别到版本信息的端口(3000、3001、3003)。
PORT STATE SERVICE 21/tcp open ftp 80/tcp open http 135/tcp open msrpc 139/tcp open netbios-ssn 445/tcp open microsoft-ds 1978/tcp open unisql 3389/tcp open ms-wbt-server
PORT STATE SERVICE 22/tcp open ssh 80/tcp open http 81/tcp open hosts2-ns 135/tcp open msrpc 139/tcp open netbios-ssn 445/tcp open microsoft-ds 3306/tcp open mysql 3307/tcp open opsession-prxy 5040/tcp open unknown 5985/tcp open wsman 47001/tcp open winrm 49664/tcp open unknown 49665/tcp open unknown 49666/tcp open unknown 49667/tcp open unknown 49668/tcp open unknown 49669/tcp open unknown 49670/tcp open unknown 51775/tcp open unknown
PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH for_Windows_8.1 (protocol 2.0) | ssh-hostkey: | 3072 e0:3a:63:4a:07:83:4d:0b:6f:4e:8a:4d:79:3d:6e:4c (RSA) | 256 3f:16:ca:33:25:fd:a2:e6:bb:f6:b0:04:32:21:21:0b (ECDSA) |_ 256 fe:b0:7a:14:bf:77:84:9a:b3:26:59:8d:ff:7e:92:84 (ED25519) 80/tcp open http Apache httpd 2.4.51 ((Win64) PHP/7.4.26) |_http-server-header: Apache/2.4.51 (Win64) PHP/7. 4.26 | http-methods: |_ Potentially risky methods: TRACE |_http-generator: Nicepage 4.8.2, nicepage.com |_http-title: Home 81/tcp open http Apache httpd 2.4.51 ((Win64) PHP/7.4.26) |_http-title: Attendance and Payroll System |_http-server-header: Apache/2.4.51 (Win64) PHP/7.4.26 | http-cookie-flags: | /: | PHPSESSID: |_ httponly flag not set 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 445/tcp open microsoft-ds? 3306/tcp open mysql MySQL (unauthorized) 3307/tcp open mysql MariaDB 10.3.24 or later (unauthorized) 5040/tcp open unknown 5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-title: Not Found |_http-server-header: Microsoft-HTTPAPI/2.0 47001/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-title: Not Found |_http-server-header: Microsoft-HTTPAPI/2.0 49664/tcp open msrpc Microsoft Windows RPC 49665/tcp open msrpc Microsoft Windows RPC 49666/tcp open msrpc Microsoft Windows RPC 49667/tcp open msrpc Microsoft Windows RPC 49668/tcp open msrpc Microsoft Windows RPC 49669/tcp open msrpc Microsoft Windows RPC 49670/tcp open msrpc Microsoft Windows RPC 51775/tcp open msrpc Microsoft Windows RPC
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
PORT STATE SERVICE 135/tcp open msrpc 139/tcp open netbios-ssn 445/tcp open microsoft-ds 1433/tcp open ms-sql-s 5040/tcp open unknown 5985/tcp open wsman 47001/tcp open winrm 49665/tcp open unknown 49666/tcp open unknown 49667/tcp open unknown 49668/tcp open unknown 49669/tcp open unknown 49671/tcp open unknown 49700/tcp open unknown
PORT STATE SERVICE VERSION 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 445/tcp open microsoft-ds? 1433/tcp open ms-sql-s Microsoft SQL Server 2019 15.00.2000.00; RTM | ms-sql-ntlm-info: | 10.10.208.142:1433: | Target_Name: OSCP | NetBIOS_Domain_Name: OSCP | NetBIOS_Computer_Name: MS02 | DNS_Domain_Name: oscp.exam | DNS_Computer_Name: MS02.oscp.exam | DNS_Tree_Name: oscp.exam |_ Product_Version: 10.0.19041 |_ssl-date: 2025-10-09T02:11:06+00:00; -10s from scanner time. | ms-sql-info: | 10.10.208.142:1433: | Version: | name: Microsoft SQL Server 2019 RTM | number: 15.00.2000.00 | Product: Microsoft SQL Server 2019 | Service pack level: RTM | Post-SP patches applied: false |_ TCP port: 1433 | ssl-cert: Subject: commonName=SSL_Self_Signed_Fallback | Not valid before: 2025-02-13T00:59:29 |_Not valid after: 2055-02-13T00:59:29 5040/tcp open unknown 5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-server-header: Microsoft-HTTPAPI/2.0 |_http-title: Not Found 47001/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-server-header: Microsoft-HTTPAPI/2.0 |_http-title: Not Found 49665/tcp open msrpc Microsoft Windows RPC 49666/tcp open msrpc Microsoft Windows RPC 49667/tcp open msrpc Microsoft Windows RPC 49668/tcp open msrpc Microsoft Windows RPC 49669/tcp open msrpc Microsoft Windows RPC 49671/tcp open msrpc Microsoft Windows RPC 49700/tcp open ms-sql-s Microsoft SQL Server 2019 15.00.2000.00; RTM | ms-sql-ntlm-info: | 10.10.208.142:49700: | Target_Name: OSCP | NetBIOS_Domain_Name: OSCP | NetBIOS_Computer_Name: MS02 | DNS_Domain_Name: oscp.exam | DNS_Computer_Name: MS02.oscp.exam | DNS_Tree_Name: oscp.exam |_ Product_Version: 10.0.19041 | ssl-cert: Subject: commonName=SSL_Self_Signed_Fallback | Not valid before: 2025-02-13T00:59:29 |_Not valid after: 2055-02-13T00:59:29 |_ssl-date: 2025-10-09T02:11:06+00:00; -10s from scanner time. | ms-sql-info: | 10.10.208.142:49700: | Version: | name: Microsoft SQL Server 2019 RTM | number: 15.00.2000.00 | Product: Microsoft SQL Server 2019 | Service pack level: RTM | Post-SP patches applied: false |_ TCP port: 49700 Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
PORT STATE SERVICE 53/tcp open domain 88/tcp open kerberos-sec 135/tcp open msrpc 139/tcp open netbios-ssn 445/tcp open microsoft-ds 464/tcp open kpasswd5 593/tcp open http-rpc-epmap 636/tcp open ldapssl 3268/tcp open globalcatLDAP 5985/tcp open wsman 9389/tcp open adws 49668/tcp open unknown 49682/tcp open unknown 49683/tcp open unknown 49686/tcp open unknown 49710/tcp open unknown 56710/tcp open unknown
PORT STATE SERVICE VERSION 53/tcp open domain Simple DNS Plus 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2025-10-08 13:33:33Z) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 445/tcp open microsoft-ds? 464/tcp open kpasswd5? 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 636/tcp open tcpwrapped 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: oscp.exam0., Site: Default-First-Site-Name) 5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-server-header: Microsoft-HTTPAPI/2.0 |_http-title: Not Found 9389/tcp open mc-nmf .NET Message Framing 49668/tcp open msrpc Microsoft Windows RPC 49682/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 49683/tcp open msrpc Microsoft Windows RPC 49686/tcp open msrpc Microsoft Windows RPC 49710/tcp open msrpc Microsoft Windows RPC 56710/tcp open msrpc Microsoft Windows RPC
Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows
使用 evil-winrm 登录内网主机,在 C 盘根目录发现 Windows.old 目录,Windows 系统 sam 和 system 文件默认存储在 C:\Windows\system32\config 目录,经过检索在 C:\Windows.old\Windows\system32 目录发现了 sam 和 system 文件。