1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192
| ┌──(root㉿kali)-[/home/kali] └─# ifconfig eth0: flags=4163<UP,BROADCAST,RUNNING,MULTICAST> mtu 1500 inet 192.168.56.102 netmask 255.255.255.0 broadcast 192.168.56.255 inet6 fe80::20c:29ff:fe66:2ae1 prefixlen 64 scopeid 0x20<link> ether 00:0c:29:66:2a:e1 txqueuelen 1000 (Ethernet) RX packets 5 bytes 1543 (1.5 KiB) RX errors 0 dropped 0 overruns 0 frame 0 TX packets 30 bytes 3784 (3.6 KiB) TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
lo: flags=73<UP,LOOPBACK,RUNNING> mtu 65536 inet 127.0.0.1 netmask 255.0.0.0 inet6 ::1 prefixlen 128 scopeid 0x10<host> loop txqueuelen 1000 (Local Loopback) RX packets 8 bytes 480 (480.0 B) RX errors 0 dropped 0 overruns 0 frame 0 TX packets 8 bytes 480 (480.0 B) TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
┌──(root㉿kali)-[/home/kali] └─# arp-scan -l Interface: eth0, type: EN10MB, MAC: 00:0c:29:66:2a:e1, IPv4: 192.168.56.102 WARNING: Cannot open MAC/Vendor file ieee-oui.txt: Permission denied WARNING: Cannot open MAC/Vendor file mac-vendor.txt: Permission denied Starting arp-scan 1.10.0 with 256 hosts (https://github.com/royhills/arp-scan) 192.168.56.1 0a:00:27:00:00:0d (Unknown: locally administered) 192.168.56.100 08:00:27:c9:f2:ac (Unknown) 192.168.56.112 08:00:27:e0:b9:48 (Unknown)
3 packets received by filter, 0 packets dropped by kernel Ending arp-scan 1.10.0: 256 hosts scanned in 1.892 seconds (135.31 hosts/sec). 3 responded ┌──(root㉿kali)-[/home/kali] └─# nmap -sC -sV -p- 192.168.56.112 Starting Nmap 7.95 ( https://nmap.org ) at 2025-10-19 13:06 +08 Nmap scan report for 192.168.56.112 Host is up (0.00038s latency). Not shown: 65533 closed tcp ports (reset) PORT STATE SERVICE VERSION 80/tcp open http Apache httpd 2.4.62 ((Debian)) |_http-title: SSH Private Key |_http-server-header: Apache/2.4.62 (Debian) 8080/tcp open http Golang net/http server | http-title: GMSSH |_Requested resource was /web/ | fingerprint-strings: | FourOhFourRequest: | HTTP/1.0 404 Not Found | Access-Control-Allow-Headers: * | Access-Control-Allow-Methods: * | Access-Control-Allow-Origin: * | Content-Type: text/plain | Date: Sun, 19 Oct 2025 05:07:02 GMT | Content-Length: 18 | page not found | GenericLines, Help, LPDString, RTSPRequest, SIPOptions, SSLSessionReq, Socks5: | HTTP/1.1 400 Bad Request | Content-Type: text/plain; charset=utf-8 | Connection: close | Request | GetRequest: | HTTP/1.0 301 Moved Permanently | Access-Control-Allow-Headers: * | Access-Control-Allow-Methods: * | Access-Control-Allow-Origin: * | Content-Type: text/html; charset=utf-8 | Location: /web | Date: Sun, 19 Oct 2025 05:07:01 GMT | Content-Length: 39 | href="/web">Moved Permanently</a>. | HTTPOptions: | HTTP/1.0 204 No Content | Access-Control-Allow-Headers: * | Access-Control-Allow-Methods: * | Access-Control-Allow-Origin: * |_ Date: Sun, 19 Oct 2025 05:07:02 GMT 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service : SF-Port8080-TCP:V=7.95%I=7%D=10/19%Time=68F471F9%P=x86_64-pc-linux-gnu%r(G SF:etRequest,11C,"HTTP/1\.0\x20301\x20Moved\x20Permanently\r\nAccess-Contr SF:ol-Allow-Headers:\x20\*\r\nAccess-Control-Allow-Methods:\x20\*\r\nAcces SF:s-Control-Allow-Origin:\x20\*\r\nContent-Type:\x20text/html;\x20charset SF:=utf-8\r\nLocation:\x20/web\r\nDate:\x20Sun,\x2019\x20Oct\x202025\x2005 SF::07:01\x20GMT\r\nContent-Length:\x2039\r\n\r\n<a\x20href=\"/web\">Moved SF:\x20Permanently</a>\.\n\n")%r(HTTPOptions,A2,"HTTP/1\.0\x20204\x20No\x2 SF:0Content\r\nAccess-Control-Allow-Headers:\x20\*\r\nAccess-Control-Allow SF:-Methods:\x20\*\r\nAccess-Control-Allow-Origin:\x20\*\r\nDate:\x20Sun,\ SF:x2019\x20Oct\x202025\x2005:07:02\x20GMT\r\n\r\n")%r(RTSPRequest,67,"HTT SF:P/1\.1\x20400\x20Bad\x20Request\r\nContent-Type:\x20text/plain;\x20char SF:set=utf-8\r\nConnection:\x20close\r\n\r\n400\x20Bad\x20Request")%r(Four SF:OhFourRequest,E1,"HTTP/1\.0\x20404\x20Not\x20Found\r\nAccess-Control-Al SF:low-Headers:\x20\*\r\nAccess-Control-Allow-Methods:\x20\*\r\nAccess-Con SF:trol-Allow-Origin:\x20\*\r\nContent-Type:\x20text/plain\r\nDate:\x20Sun SF:,\x2019\x20Oct\x202025\x2005:07:02\x20GMT\r\nContent-Length:\x2018\r\n\ SF:r\n404\x20page\x20not\x20found")%r(Socks5,67,"HTTP/1\.1\x20400\x20Bad\x SF:20Request\r\nContent-Type:\x20text/plain;\x20charset=utf-8\r\nConnectio SF:n:\x20close\r\n\r\n400\x20Bad\x20Request")%r(GenericLines,67,"HTTP/1\.1 SF:\x20400\x20Bad\x20Request\r\nContent-Type:\x20text/plain;\x20charset=ut SF:f-8\r\nConnection:\x20close\r\n\r\n400\x20Bad\x20Request")%r(Help,67,"H SF:TTP/1\.1\x20400\x20Bad\x20Request\r\nContent-Type:\x20text/plain;\x20ch SF:arset=utf-8\r\nConnection:\x20close\r\n\r\n400\x20Bad\x20Request")%r(SS SF:LSessionReq,67,"HTTP/1\.1\x20400\x20Bad\x20Request\r\nContent-Type:\x20 SF:text/plain;\x20charset=utf-8\r\nConnection:\x20close\r\n\r\n400\x20Bad\ SF:x20Request")%r(LPDString,67,"HTTP/1\.1\x20400\x20Bad\x20Request\r\nCont SF:ent-Type:\x20text/plain;\x20charset=utf-8\r\nConnection:\x20close\r\n\r SF:\n400\x20Bad\x20Request")%r(SIPOptions,67,"HTTP/1\.1\x20400\x20Bad\x20R SF:equest\r\nContent-Type:\x20text/plain;\x20charset=utf-8\r\nConnection:\ SF:x20close\r\n\r\n400\x20Bad\x20Request"); MAC Address: 08:00:27:E0:B9:48 (PCS Systemtechnik/Oracle VirtualBox virtual NIC)
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 41.06 seconds ┌──(root㉿kali)-[/home/kali] └─# curl -i http://192.168.56.112/ HTTP/1.1 200 OK Date: Sun, 19 Oct 2025 05:08:55 GMT Server: Apache/2.4.62 (Debian) Last-Modified: Sun, 19 Oct 2025 03:49:08 GMT ETag: "628-6417ad954b9f7" Accept-Ranges: bytes Content-Length: 1576 Vary: Accept-Encoding Content-Type: text/html
<!DOCTYPE html> <html lang="en"> <head> <meta charset="UTF-8"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <title>SSH Private Key</title> <style> body { font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Oxygen, Ubuntu, Cantarell, 'Open Sans', 'Helvetica Neue', sans-serif; background-color: display: flex; justify-content: center; align-items: center; height: 100vh; margin: 0; color: } .container { text-align: center; padding: 2rem; background: white; border-radius: 8px; box-shadow: 0 2px 10px rgba(0,0,0,0.1); max-width: 90%; } h1 { font-weight: 400; margin-bottom: 1.5rem; font-size: 1.8rem; } .download-link { display: inline-block; padding: 0.8rem 1.5rem; background-color: color: white; text-decoration: none; border-radius: 4px; transition: background-color 0.2s; font-size: 1.1rem; } .download-link:hover { background-color: } </style> </head> <body> <div class="container"> <h1>This is your SSH private key</h1> <a href="id_rsa" class="download-link">Your Private Key</a> </div> <!-- Dont over think. the things you see is all --> </body> </html> ┌──(root㉿kali)-[/home/kali] └─# curl -i http://192.168.56.112:8080/ HTTP/1.1 301 Moved Permanently Access-Control-Allow-Headers: * Access-Control-Allow-Methods: * Access-Control-Allow-Origin: * Content-Type: text/html; charset=utf-8 Location: /web Date: Sun, 19 Oct 2025 05:09:24 GMT Content-Length: 39
<a href="/web">Moved Permanently</a>.
|