$ nmap -sC -sV -Pn 10.10.10.134 Host discovery disabled (-Pn). All addresses will be marked 'up' and scan times will be slower. Starting Nmap 7.91 ( https://nmap.org ) at 2021-04-17 13:55 CST Nmap scan report for 10.10.10.134 Host is up (0.33s latency). Not shown: 996 closed ports PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH for_Windows_7.9 (protocol 2.0) | ssh-hostkey: | 2048 3a:56:ae:75:3c:78:0e:c8:56:4d:cb:1c:22:bf:45:8a (RSA) | 256 cc:2e:56:ab:19:97:d5:bb:03:fb:82:cd:63:da:68:01 (ECDSA) |_ 256 93:5f:5d:aa:ca:9f:53:e7:f2:82:e6:64:a8:a3:a0:18 (ED25519) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 445/tcp open microsoft-ds Windows Server 2016 Standard 14393 microsoft-ds Service Info: OSs: Windows, Windows Server 2008 R2 - 2012; CPE: cpe:/o:microsoft:windows
Host script results: |_clock-skew: mean: -39m58s, deviation: 1h09m14s, median: 0s | smb-os-discovery: | OS: Windows Server 2016 Standard 14393 (Windows Server 2016 Standard 6.3) | Computer name: Bastion | NetBIOS computer name: BASTION\x00 | Workgroup: WORKGROUP\x00 |_ System time: 2021-04-17T07:57:33+02:00 | smb-security-mode: | account_used: guest | authentication_level: user | challenge_response: supported |_ message_signing: disabled (dangerous, but default) | smb2-security-mode: | 2.02: |_ Message signing enabled but not required | smb2-time: | date: 2021-04-17T05:57:30 |_ start_date: 2021-04-17T05:53:40
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 137.36 seconds
SMB
smb匿名访问:
Backups
backup里有个note,根据内容大概是整个系统的备份,非常大:
note.txt
1
Sysadmins: please don't transfer the entire backup file locally, the VPN to the subsidiary office is too slow.
mount
所以不直接下载,而是挂载后查看:
1 2 3 4
➜ Desktop sudo mount -t cifs //10.10.10.134/backups miao -o user=,password= [sudo] password for miao: ➜ Desktop ls miao note.txt SDT65CB.tmp WindowsImageBackup