root@yulock:~/Nagini# nmap -sT -sV -sC -O -p22,80 192.168.13.104 -oA nmapscan/details
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-09-07 20:19 HKT
Nmap scan report for 192.168.13.104
Host is up (0.00052s latency).
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 7.9p1 Debian 10+deb10u2 (protocol 2.0)| ssh-hostkey:
|2048 48:df:48:37:25:94:c4:74:6b:2c:62:73:bf:b4:9f:a9 (RSA)|256 1e:34:18:17:5e:17:95:8f:70:2f:80:a6:d5:b4:17:3e (ECDSA)|_ 256 3e:79:5f:55:55:3b:12:75:96:b4:3e:e3:83:7a:54:94 (ED25519)80/tcp open http Apache httpd 2.4.38 ((Debian))|_http-title: Site doesn't have a title (text/html).
|_http-server-header: Apache/2.4.38 (Debian)MAC Address: 08:00:27:EE:FC:CF (Oracle VirtualBox virtual NIC)Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose
Running: Linux 4.X|5.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5
OS details: Linux 4.15 - 5.8
Network Distance: 1 hop
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
找不到更多信息了,重新进行目录扫描,看看会不会泄露其他文件格式的信息
可以用wfuzz的FUZZ.txt进行扫描,但我想同时扫描多个后缀,因此还是得用回gobuster: gobuster dir -u http://192.168.13.104/ -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x .txt,.html,.zip
扫出了note.txt,拉取下来查看其内容
1
2
3
4
5
6
7
8
9
Hello developers!!
I will be using our new HTTP3 Server at https://quic.nagini.hogwarts for further communications.
All developers are requested to visit the server regularly for checking latest announcements.
Regards,
site_amdin
<html><head><title>Information Page</title></head><body> Greetings Developers !
I am having two announcements that I need to share with you:
1.We no longer require functionality at /internalResourceFeTcher.php in our main production servers.So I will be removing the same by this week.
2.All developers are requested not to put any configuration's backup file (.bak)in main production servers as they are readable by every one.
Regards
site_admin
</body></html>