DC-7
author:leadlife
data:2023/5/18
blog:https://tripse.github.io/
本次测试使用到的工具如下:
- 信息收集:nmap、fscan、cmseek、searchsploit
- 获取 SHELL:无
- 暴力破解:无
- FUZZ:无
- 辅助工具:无
- 权限提升:无
外部信息收集
Nmap ICMP 扫描发现主机
本地靶机 IP为 10.10.10.137
sudo nmap -sP 10.10.10.0/24 -T4 --min-rate 10000
Starting Nmap 7.93 ( https://nmap.org ) at 2023-05-18 18:08 CST
Nmap scan report for 10.10.10.137
Host is up (0.00015s latency).
MAC Address: 08:00:27:05:5E:F0 (Oracle VirtualBox virtual NIC)
Nmap scan report for 10.10.10.254
Host is up (0.00045s latency).
MAC Address: 00:50:56:EF:7D:81 (VMware)
Nmap scan report for 10.10.10.1
Host is up.
Nmap done: 256 IP addresses (3 hosts up) scanned in 0.34 seconds
Fsacn 探测开放端口
sudo fscan -h 10.10.10.137 -t 30 -p 0-65535
___ _
/ _ \ ___ ___ _ __ __ _ ___| | __
/ /_\/____/ __|/ __| '__/ _` |/ __| |/ /
/ /_\\_____\__ \ (__| | |