{"id":708,"date":"2024-07-01T15:03:16","date_gmt":"2024-07-01T07:03:16","guid":{"rendered":"http:\/\/162.14.82.114\/?p=708"},"modified":"2024-07-01T15:03:16","modified_gmt":"2024-07-01T07:03:16","slug":"hmv-_-hmvlabs-venus41-50","status":"publish","type":"post","link":"http:\/\/162.14.82.114\/index.php\/708\/07\/01\/2024\/","title":{"rendered":"HMV[-_-]HMVLabs-Venus(41-50)"},"content":{"rendered":"<h1>41 sky<\/h1>\n<pre><code class=\"language-Bash\">adela@venus:~$ su -l sky\nPassword:\nsky@venus:~$ ls -la\ntotal 36\ndrwxr-x--- 2 root sky  4096 Apr  5 06:28 .\ndrwxr-xr-x 1 root root 4096 Apr  5 06:27 ..\n-rw-r----- 1 root sky    31 Apr  5 06:28 .bash_history\n-rw-r--r-- 1 sky  sky   220 Apr 23  2023 .bash_logout\n-rw-r--r-- 1 sky  sky  3526 Apr 23  2023 .bashrc\n-rw-r--r-- 1 sky  sky   807 Apr 23  2023 .profile\n-rw-r----- 1 root sky    31 Apr  5 06:27 flagz.txt\n-rw-r----- 1 root sky   184 Apr  5 06:27 mission.txt\nsky@venus:~$ cat flagz.txt\n8===8T2IE4fNIvbs8sh1lnew===D~~\nsky@venus:~$ cat mission.txt\n################\n# MISSION 0x41 #\n################\n\n## EN ##\nUser sarah uses header in http:\/\/localhost\/key.php\n\n## ES ##\nLa usuaria sarah utiliza header para http:\/\/localhost\/key.php\nsky@venus:~$ cat .bash_history\n8===nyqRAOwkVRTiMYeePdes===D~~\nsky@venus:~$ curl -i -s http:\/\/localhost\/key.php\nHTTP\/1.1 200 OK\nServer: nginx\/1.22.1\nDate: Sun, 30 Jun 2024 19:55:46 GMT\nContent-Type: text\/html; charset=UTF-8\nTransfer-Encoding: chunked\nConnection: keep-alive\n\nKey header is true?\nsky@venus:~$ curl -i -s -H &quot;key: true&quot;  http:\/\/localhost\/key.php\nHTTP\/1.1 200 OK\nServer: nginx\/1.22.1\nDate: Sun, 30 Jun 2024 19:56:36 GMT\nContent-Type: text\/html; charset=UTF-8\nTransfer-Encoding: chunked\nConnection: keep-alive\n\nLWOHeRgmIxg7fuS<\/code><\/pre>\n<h1>42 sarah<\/h1>\n<pre><code class=\"language-Bash\">sarah@venus:~$ ls -la\ntotal 36\ndrwxr-x--- 2 root  sarah 4096 Apr  5 06:28 .\ndrwxr-xr-x 1 root  root  4096 Apr  5 06:27 ..\n-rw-r----- 1 root  sarah   16 Apr  5 06:28 ...\n-rw-r--r-- 1 sarah sarah  220 Apr 23  2023 .bash_logout\n-rw-r--r-- 1 sarah sarah 3526 Apr 23  2023 .bashrc\n-rw-r--r-- 1 sarah sarah  807 Apr 23  2023 .profile\n-rw-r----- 1 root  sarah   31 Apr  5 06:27 flagz.txt\n-rw-r----- 1 root  sarah  175 Apr  5 06:27 mission.txt\nsarah@venus:~$ cat ...\nym5yyXZ163uIS8L\nsarah@venus:~$ cat flagz.txt\n8===nLCR949OMr4pLhMepKCM===D~~\nsarah@venus:~$ cat mission.txt\n################\n# MISSION 0x42 #\n################\n\n## EN ##\nThe password of mercy is hidden in this directory.\n\n## ES ##\nLa password de mercy esta oculta en este directorio.<\/code><\/pre>\n<h1>43 mercy<\/h1>\n<pre><code class=\"language-Bash\">sarah@venus:~$ su -l mercy\nPassword:\nmercy@venus:~$ ls -la\ntotal 36\ndrwxr-x--- 2 root  mercy 4096 Apr  5 06:28 .\ndrwxr-xr-x 1 root  root  4096 Apr  5 06:27 ..\n-rw-r----- 1 root  mercy  133 Apr  5 06:28 .bash_history\n-rw-r--r-- 1 mercy mercy  220 Apr 23  2023 .bash_logout\n-rw-r--r-- 1 mercy mercy 3526 Apr 23  2023 .bashrc\n-rw-r--r-- 1 mercy mercy  807 Apr 23  2023 .profile\n-rw-r----- 1 root  mercy   31 Apr  5 06:27 flagz.txt\n-rw-r----- 1 root  mercy  190 Apr  5 06:27 mission.txt\nmercy@venus:~$ cat .bash_history\nls -A\nls\nrm \/\nps\nsudo -l\nwatch tv\nvi \/etc\/logs\nsu paula\ndlHZ6cvX6cLuL8p\nhistory\nhistory -c\nlogout\nssh paula@localhost\ncat .\nls\nls -l\nmercy@venus:~$ cat flagz.txt\n8===pBpnZCBSELaY0xQJ8YAY===D~~\nmercy@venus:~$ cat mission.txt\n################\n# MISSION 0x43 #\n################\n\n## EN ##\nUser mercy is always wrong with the password of paula.\n\n## ES ##\nLa usuaria mercy siempre se equivoca con la password de paula.<\/code><\/pre>\n<h1>44 paula<\/h1>\n<pre><code class=\"language-Bash\">mercy@venus:~$ su -l paula\nPassword:\npaula@venus:~$ ls -la\ntotal 32\ndrwxr-x--- 2 root  paula 4096 Apr  5 06:27 .\ndrwxr-xr-x 1 root  root  4096 Apr  5 06:27 ..\n-rw-r--r-- 1 paula paula  220 Apr 23  2023 .bash_logout\n-rw-r--r-- 1 paula paula 3526 Apr 23  2023 .bashrc\n-rw-r--r-- 1 paula paula  807 Apr 23  2023 .profile\n-rw-r----- 1 root  paula   31 Apr  5 06:27 flagz.txt\n-rw-r----- 1 root  paula  197 Apr  5 06:27 mission.txt\npaula@venus:~$ cat flagz.txt\n8===2pwlvMk65rw81lymKLJE===D~~\npaula@venus:~$ cat mission.txt\n################\n# MISSION 0x44 #\n################\n\n## EN ##\nThe user karla trusts me, she is part of my group of friends.\n\n## ES ##\nLa usuaria karla confia en mi, es parte de mi grupo de amigos.\npaula@venus:~$ whoami;id\npaula\nuid=1044(paula) gid=1044(paula) groups=1044(paula),1053(hidden)\npaula@venus:~$ find \/ -group hidden -type f 2&gt;\/dev\/null\n\/usr\/src\/.karl-a\npaula@venus:~$ cat \/usr\/src\/.karl-a\ngYAmvWY3I7yDKRf<\/code><\/pre>\n<h1>45 karla<\/h1>\n<pre><code class=\"language-Bash\">paula@venus:~$ su -l karla\nPassword:\nkarla@venus:~$ ls -la\ntotal 68\ndrwxr-x--- 2 root  karla  4096 Apr  5 06:28 .\ndrwxr-xr-x 1 root  root   4096 Apr  5 06:27 ..\n-rw-r--r-- 1 karla karla   220 Apr 23  2023 .bash_logout\n-rw-r--r-- 1 karla karla  3526 Apr 23  2023 .bashrc\n-rw-r--r-- 1 karla karla   807 Apr 23  2023 .profile\n-rw-r----- 1 root  karla    31 Apr  5 06:27 flagz.txt\n-rw-r----- 1 root  karla   176 Apr  5 06:27 mission.txt\n-rw-r----- 1 root  karla 32946 Apr  5 06:28 yuju.jpg\nkarla@venus:~$ cat flagz.txt\n8===SARQC95X3AWK9K4BBTMJ===D~~\nkarla@venus:~$ cat mission.txt\n################\n# MISSION 0x45 #\n################\n\n## EN ##\nUser denise has saved her password in the image.\n\n## ES ##\nLa usuaria denise ha guardado su password en la imagen.\nkarla@venus:~$ exiftool yuju.jpg\nExifTool Version Number         : 12.57\nFile Name                       : yuju.jpg\nDirectory                       : .\nFile Size                       : 33 kB\nFile Modification Date\/Time     : 2024:04:05 06:28:46+00:00\nFile Access Date\/Time           : 2024:04:05 06:28:46+00:00\nFile Inode Change Date\/Time     : 2024:04:05 06:29:46+00:00\nFile Permissions                : -rw-r-----\nFile Type                       : JPEG\nFile Type Extension             : jpg\nMIME Type                       : image\/jpeg\nJFIF Version                    : 1.01\nResolution Unit                 : inches\nX Resolution                    : 96\nY Resolution                    : 96\nExif Byte Order                 : Big-endian (Motorola, MM)\nArtist                          : sML\nDate\/Time Original              : 2021:11:01 10:34:51\nCreate Date                     : 2021:11:01 10:34:51\nSub Sec Time Original           : 95\nSub Sec Time Digitized          : 95\nXP Author                       : sML\nPadding                         : (Binary data 2060 bytes, use -b option to extract)\nXMP Toolkit                     : Image::ExifTool 12.16\nAbout                           : pFg92DpGucMWccA\nCreator                         : sML\nImage Width                     : 442\nImage Height                    : 463\nEncoding Process                : Baseline DCT, Huffman coding\nBits Per Sample                 : 8\nColor Components                : 3\nY Cb Cr Sub Sampling            : YCbCr4:2:0 (2 2)\nImage Size                      : 442x463\nMegapixels                      : 0.205\nCreate Date                     : 2021:11:01 10:34:51.95\nDate\/Time Original              : 2021:11:01 10:34:51.95<\/code><\/pre>\n<h1>46 denise<\/h1>\n<pre><code class=\"language-Bash\">denise@venus:~$ ls -la\ntotal 32\ndrwxr-x--- 2 root   denise 4096 Apr  5 06:27 .\ndrwxr-xr-x 1 root   root   4096 Apr  5 06:27 ..\n-rw-r--r-- 1 denise denise  220 Apr 23  2023 .bash_logout\n-rw-r--r-- 1 denise denise 3526 Apr 23  2023 .bashrc\n-rw-r--r-- 1 denise denise  807 Apr 23  2023 .profile\n-rw-r----- 1 root   denise   31 Apr  5 06:27 flagz.txt\n-rw-r----- 1 root   denise  144 Apr  5 06:27 mission.txt\ndenise@venus:~$ cat flagz.txt\n8===uMXbjLdQde2iQFoWc8zf===D~~\ndenise@venus:~$ cat mission.txt\n################\n# MISSION 0x46 #\n################\n\n## EN ##\nThe user zora is screaming doas!\n\n## ES ##\nLa usuaria zora no deja de gritar doas!\ndenise@venus:~$ find \/ -name doas -type f 2&gt;\/dev\/null\n\/usr\/bin\/doas\n\/etc\/pam.d\/doas\ndenise@venus:~$ cat \/etc\/pam.d\/doas\n#%PAM-1.0\n\n# Set up user limits from \/etc\/security\/limits.conf.\nsession    required   pam_limits.so\n\n@include common-auth\n@include common-account\n@include common-session-noninteractive\n\ndenise@venus:~$ \/usr\/bin\/doas\nusage: doas [-Lns] [-C config] [-u user] command [args]\ndenise@venus:~$ find \/ -name doas 2&gt;\/dev\/null\n\/usr\/share\/doc\/doas\n\/usr\/bin\/doas\n\/etc\/pam.d\/doas\ndenise@venus:~$ cat \/usr\/share\/doc\/doas\ncat: \/usr\/share\/doc\/doas: Is a directory<\/code><\/pre>\n<p>\u6ca1\u6709\u8fdb\u5c55\uff0c\u53d1\u73b0\u8fd9\u662f\u4e00\u4e2a\u7c7b\u4f3csudo\u7684\u4e1c\u897f\uff0c\u5c1d\u8bd5\u4f7f\u7528\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-Bash\">denise@venus:~$ doas -u zora bash\ndoas (denise@venus) password:\nzora@venus:\/pwned\/denise$<\/code><\/pre>\n<h1>47 zora<\/h1>\n<pre><code class=\"language-Bash\">zora@venus:~$ ls -la\ntotal 36\ndrwxr-x--- 2 root zora 4096 Apr  5 06:28 .\ndrwxr-xr-x 1 root root 4096 Apr  5 06:27 ..\n-rw-r--r-- 1 zora zora  220 Apr 23  2023 .bash_logout\n-rw-r--r-- 1 zora zora 3526 Apr 23  2023 .bashrc\n-rw-r--r-- 1 zora zora  807 Apr 23  2023 .profile\n-rw-r----- 1 root zora   31 Apr  5 06:27 flagz.txt\n-rw-r----- 1 root zora  173 Apr  5 06:27 mission.txt\n-rw-r----- 1 root zora   16 Apr  5 06:28 zora_pass.txt\nzora@venus:~$ cat flagz.txt\n8===hhp0gFTIaedSX3faXDqP===D~~\nzora@venus:~$ cat mission.txt\n################\n# MISSION 0x47 #\n################\n\n## EN ##\nThe user belen has left her password in venus.hmv\n\n## ES ##\nLa usuaria belen ha dejado su password en venus.hmv\nzora@venus:~$ cat zora_pass.txt\nBWm1R3jCcb53riO\nzora@venus:~$ cat \/etc\/hosts\n127.0.0.1       localhost\n::1     localhost ip6-localhost ip6-loopback\nfe00::0 ip6-localnet\nff00::0 ip6-mcastprefix\nff02::1 ip6-allnodes\nff02::2 ip6-allrouters\n172.66.0.10     venus\nzora@venus:~$ curl -i -s venus.hmv\nHTTP\/1.1 200 OK\nServer: nginx\/1.22.1\nDate: Sun, 30 Jun 2024 20:28:47 GMT\nContent-Type: text\/html\nContent-Length: 16\nLast-Modified: Fri, 05 Apr 2024 06:28:46 GMT\nConnection: keep-alive\nETag: &quot;660f9a1e-10&quot;\nAccept-Ranges: bytes\n\n2jA0E8bQ4WrGwWZ<\/code><\/pre>\n<h1>48 belen<\/h1>\n<pre><code class=\"language-Bash\">belen@venus:~$ ls -la\ntotal 36\ndrwxr-x--- 2 root  belen 4096 Apr  5 06:28 .\ndrwxr-xr-x 1 root  root  4096 Apr  5 06:27 ..\n-rw-r--r-- 1 belen belen  220 Apr 23  2023 .bash_logout\n-rw-r--r-- 1 belen belen 3526 Apr 23  2023 .bashrc\n-rw-r--r-- 1 belen belen  807 Apr 23  2023 .profile\n-rw-r----- 1 root  belen   31 Apr  5 06:27 flagz.txt\n-rw-r----- 1 root  belen  197 Apr  5 06:27 mission.txt\n-rw-r----- 1 root  belen   32 Apr  5 06:28 stolen.txt\nbelen@venus:~$ cat flagz.txt\n8===FzDIkqJtVgyQYfRVGH1r===D~~\nbelen@venus:~$ cat mission.txt\n################\n# MISSION 0x48 #\n################\n\n## EN ##\nIt seems that belen has stolen the password of the user leona...\n\n## ES ##\nParece que belen ha robado el password de la usuaria leona..\nbelen@venus:~$ cat stolen.txt\n$1$leona$lhWp56YnWAMz6z32Bw53L0\n\nhgbe02@pwn:~\/temp$ john -w=\/home\/hgbe02\/rockyou.txt stolen.txt\nCreated directory: \/home\/hgbe02\/.john\nLoaded 1 password hash (md5crypt [MD5 32\/64 X2])\nWill run 12 OpenMP threads\nPress &#039;q&#039; or Ctrl-C to abort, almost any other key for status\nfreedom          (?)\n1g 0:00:00:00 100% 25.00g\/s 76800p\/s 76800c\/s 76800C\/s 123456..dangerous\nUse the &quot;--show&quot; option to display all of the cracked passwords reliably\nSession completed<\/code><\/pre>\n<h1>49 leona<\/h1>\n<pre><code class=\"language-Bash\">belen@venus:~$ su -l leona\nPassword:\nleona@venus:~$ ls -la\ntotal 32\ndrwxr-x--- 2 root  leona 4096 Apr  5 06:27 .\ndrwxr-xr-x 1 root  root  4096 Apr  5 06:27 ..\n-rw-r--r-- 1 leona leona  220 Apr 23  2023 .bash_logout\n-rw-r--r-- 1 leona leona 3526 Apr 23  2023 .bashrc\n-rw-r--r-- 1 leona leona  807 Apr 23  2023 .profile\n-rw-r----- 1 root  leona   31 Apr  5 06:27 flagz.txt\n-rw-r----- 1 root  leona  195 Apr  5 06:27 mission.txt\nleona@venus:~$ cat flagz.txt\n8===jObs3nfIJG4dDtxhWuKg===D~~\nleona@venus:~$ cat mission.txt\n################\n# MISSION 0x49 #\n################\n\n## EN ##\nUser ava plays a lot with the DNS of venus.hmv lately...\n\n## ES ##\nLa usuaria ava juega mucho con el DNS de venus.hmv ultimamente...\nleona@venus:~$ cat \/etc\/hosts\n127.0.0.1       localhost\n::1     localhost ip6-localhost ip6-loopback\nfe00::0 ip6-localnet\nff00::0 ip6-mcastprefix\nff02::1 ip6-allnodes\nff02::2 ip6-allrouters\n172.66.0.10     venus\nleona@venus:~$ cat \/etc\/resolv.conf\n# Generated by Docker Engine.\n# This file can be edited; Docker Engine will not make further changes once it\n# has been modified.\n\nnameserver 127.0.0.11\nsearch .\noptions edns0 trust-ad ndots:0\n\n# Based on host file: &#039;\/etc\/resolv.conf&#039; (internal resolver)\n# ExtServers: [host(127.0.0.53)]\n# Overrides: []\n# Option ndots from: internal\nleona@venus:~$ cat \/etc\/host.conf\nmulti on<\/code><\/pre>\n<p>\u7136\u540e\u6ca1\u601d\u8def\u4e86\uff0c\u540e\u9762\u770b\u4e86\u4e00\u4e0b\u522b\u7684\u5e08\u5085\u7684\u601d\u8def\uff0c\u662f\u4e00\u4e2a\u6ca1\u6ce8\u610f\u5230\u7684\u6587\u4ef6\u5939\uff1a<\/p>\n<pre><code class=\"language-Bash\">leona@venus:~$ cd \/etc\nleona@venus:\/etc$ ls -la\ntotal 664\ndrwxr-xr-x 1 root root    4096 May 24 18:22 .\ndrwxr-xr-x 1 root root    4096 May 24 18:22 ..\n-rw------- 1 root root       0 Mar 11 00:00 .pwd.lock\ndrwxr-xr-x 3 root root    4096 Apr  5 06:27 X11\n-rw-r--r-- 1 root root    3040 May 25  2023 adduser.conf\n-rw-r--r-- 1 root root     185 Apr  5 06:27 aliases\ndrwxr-xr-x 1 root root    4096 Apr  5 06:27 alternatives\ndrwxr-xr-x 3 root root    4096 Apr  5 06:27 apache2\ndrwxr-xr-x 4 root root    4096 Apr  5 06:27 apparmor.d\ndrwxr-xr-x 8 root root    4096 Mar 11 00:00 apt\n-rw-r--r-- 1 root root    1994 Apr 23  2023 bash.bashrc\ndrwxr-sr-x 2 root bind    4096 Apr  5 06:28 bind\n-rw-r--r-- 1 root root     367 Sep 22  2022 bindresvport.blacklist\ndrwxr-xr-x 2 root root    4096 Jan 26 21:48 binfmt.d\ndrwxr-xr-x 3 root root    4096 Apr  5 06:27 ca-certificates\n-rw-r--r-- 1 root root    5989 Apr  5 06:27 ca-certificates.conf\ndrwxr-xr-x 1 root root    4096 Apr  5 06:27 cron.d\ndrwxr-xr-x 1 root root    4096 Apr  5 06:27 cron.daily\ndrwxr-xr-x 2 root root    4096 Apr  5 06:26 cron.hourly\ndrwxr-xr-x 2 root root    4096 Apr  5 06:26 cron.monthly\ndrwxr-xr-x 2 root root    4096 Apr  5 06:26 cron.weekly\ndrwxr-xr-x 2 root root    4096 Apr  5 06:26 cron.yearly\n-rw-r--r-- 1 root root    1042 Mar  2  2023 crontab\ndrwxr-xr-x 4 root root    4096 Apr  5 06:27 dbus-1\n-rw-r--r-- 1 root root    2969 Jan  8  2023 debconf.conf\n-rw-r--r-- 1 root root       5 Jan 28 21:20 debian_version\ndrwxr-xr-x 1 root root    4096 Apr  5 06:27 default\n-rw-r--r-- 1 root root    1706 May 25  2023 deluser.conf\ndrwxr-xr-x 3 root root    4096 Apr  5 06:27 dhcp\n-rw-r--r-- 1 root root      22 Apr  5 06:28 doas.conf\ndrwxr-xr-x 4 root root    4096 Mar 11 00:00 dpkg\n-rw-r--r-- 1 root root     685 Mar  5  2023 e2scrub.conf\n-rw-r--r-- 1 root root     312 Jan  1 16:58 email-addresses\n-rw-r--r-- 1 root root       0 Mar 11 00:00 environment\n-rw-r--r-- 1 root root    1853 Oct 17  2022 ethertypes\ndrwxr-xr-x 3 root root    4096 Apr  5 06:27 exim4\n-rw-r--r-- 1 root root      37 Mar 11 00:00 fstab\n-rw-r--r-- 1 root root    2584 Jul 29  2022 gai.conf\n-rw-r--r-- 1 root root    3886 Jan 14  2023 gprofng.rc\n-rw-r--r-- 1 root root    1377 Apr  5 06:28 group\n-rw-r--r-- 1 root root    1371 Apr  5 06:28 group-\n-rw-r----- 1 root shadow  1063 Apr  5 06:28 gshadow\n-rw-r----- 1 root shadow  1057 Apr  5 06:28 gshadow-\ndrwxr-xr-x 3 root root    4096 Apr  5 06:27 gss\n-rw-r--r-- 1 root root       9 Aug  7  2006 host.conf\n-rw-r--r-- 1 root root       6 May 24 18:22 hostname\n-rw-r--r-- 1 root root     168 May 24 18:22 hosts\n-rw-r--r-- 1 root root     411 Apr  5 06:27 hosts.allow\n-rw-r--r-- 1 root root     711 Apr  5 06:27 hosts.deny\ndrwxr-xr-x 1 root root    4096 Apr  5 06:27 init.d\n-rw-r--r-- 1 root root    1875 Jan  3  2023 inputrc\ndrwxr-xr-x 2 root root    4096 Apr  5 06:27 insserv.conf.d\ndrwxr-xr-x 4 root root    4096 Apr  5 06:27 iproute2\n-rw-r--r-- 1 root root      27 Jan 28 21:20 issue\n-rw-r--r-- 1 root root      20 Jan 28 21:20 issue.net\ndrwxr-xr-x 1 root root    4096 Apr  5 06:26 kernel\n-rw-r--r-- 1 root root   11566 Apr  5 06:27 ld.so.cache\n-rw-r--r-- 1 root root      34 Sep 22  2022 ld.so.conf\ndrwxr-xr-x 2 root root    4096 Mar 11 00:00 ld.so.conf.d\ndrwxr-xr-x 2 root root    4096 Apr  5 06:27 ldap\n-rw-r--r-- 1 root root     191 Feb  9  2023 libaudit.conf\nlrwxrwxrwx 1 root root      27 Mar 11 00:00 localtime -&gt; \/usr\/share\/zoneinfo\/Etc\/UTC\ndrwxr-xr-x 5 root root    4096 Apr  5 06:27 logcheck\n-rw-r--r-- 1 root root   12569 Nov 11  2022 login.defs\ndrwxr-xr-x 1 root root    4096 Apr  5 06:27 logrotate.d\n-r--r--r-- 1 root root      33 Apr  5 06:27 machine-id\n-rw-r--r-- 1 root root     111 Jan 28  2023 magic\n-rw-r--r-- 1 root root     111 Jan 28  2023 magic.mime\n-rw-r--r-- 1 root root     125 Apr 14  2022 mail.rc\n-rw-r--r-- 1 root root       6 Apr  5 06:27 mailname\n-rw-r--r-- 1 root root   73816 Feb 11  2023 mime.types\n-rw-r--r-- 1 root root     782 Mar  5  2023 mke2fs.conf\ndrwxr-xr-x 2 root root    4096 Apr  5 06:27 modules-load.d\n-rw-r--r-- 1 root root    3461 Apr  5 06:27 motd\nlrwxrwxrwx 1 root root      12 May 24 18:22 mtab -&gt; \/proc\/mounts\ndrwxr-xr-x 4 root root    4096 Apr  5 06:27 mysql\n-rw-r--r-- 1 root root   11399 Jan 18  2023 nanorc\n-rw-r--r-- 1 root root     767 Aug 11  2022 netconfig\ndrwxr-xr-x 4 root root    4096 Apr  5 06:27 network\n-rw-r--r-- 1 root root      60 Apr  5 06:27 networks\ndrwxr-xr-x 8 root root    4096 Apr  5 06:27 nginx\n-rw-r--r-- 1 root root     526 Apr  5 06:27 nsswitch.conf\ndrwxr-xr-x 2 root root    4096 Mar 11 00:00 opt\nlrwxrwxrwx 1 root root      21 Jan 28 21:20 os-release -&gt; ..\/usr\/lib\/os-release\n-rw-r--r-- 1 root root     552 Sep 21  2023 pam.conf\ndrwxr-xr-x 1 root root    4096 Apr  5 06:27 pam.d\n-rw-r--r-- 1 root root    3498 Apr  5 06:27 passwd\n-rw-r--r-- 1 root root    3454 Apr  5 06:27 passwd-\ndrwxr-xr-x 3 root root    4096 Apr  5 06:27 perl\ndrwxr-xr-x 3 root root    4096 Apr  5 06:27 php\ndrwxr-xr-x 4 root root    4096 Apr  5 06:27 ppp\n-rw-r--r-- 1 root root     769 Apr 10  2021 profile\ndrwxr-xr-x 1 root root    4096 Apr  5 06:27 profile.d\n-rw-r--r-- 1 root root    3144 Oct 17  2022 protocols\ndrwxr-xr-x 1 root root    4096 Apr  5 06:27 rc0.d\ndrwxr-xr-x 1 root root    4096 Apr  5 06:27 rc1.d\ndrwxr-xr-x 1 root root    4096 Apr  5 06:27 rc2.d\ndrwxr-xr-x 1 root root    4096 Apr  5 06:27 rc3.d\ndrwxr-xr-x 1 root root    4096 Apr  5 06:27 rc4.d\ndrwxr-xr-x 1 root root    4096 Apr  5 06:27 rc5.d\ndrwxr-xr-x 1 root root    4096 Apr  5 06:27 rc6.d\ndrwxr-xr-x 1 root root    4096 Apr  5 06:27 rcS.d\n-rw-r--r-- 1 root root     334 May 24 18:22 resolv.conf\nlrwxrwxrwx 1 root root      13 Jan 20 09:27 rmt -&gt; \/usr\/sbin\/rmt\n-rw-r--r-- 1 root root     911 Oct 17  2022 rpc\ndrwxr-xr-x 3 root root    4096 Apr  5 06:27 runit\ndrwxr-xr-x 1 root root    4096 Apr  5 06:27 security\ndrwxr-xr-x 2 root root    4096 Mar 11 00:00 selinux\n-rw-r--r-- 1 root root   12813 Mar 27  2021 services\n-rw-r----- 1 root shadow  5969 Apr  5 06:27 shadow\n-rw-r----- 1 root shadow  5869 Apr  5 06:27 shadow-\n-rw-r--r-- 1 root root     128 Mar 11 00:00 shells\ndrwxr-xr-x 2 root root    4096 Mar 11 00:00 skel\ndrwxr-xr-x 4 root root    4096 Apr  5 06:27 ssh\ndrwxr-xr-x 4 root root    4096 Apr  5 06:27 ssl\n-rw-r--r-- 1 root root    1049 Apr  5 06:27 subgid\n-rw-r--r-- 1 root root    1028 Apr  5 06:27 subgid-\n-rw-r--r-- 1 root root    1049 Apr  5 06:27 subuid\n-rw-r--r-- 1 root root    1028 Apr  5 06:27 subuid-\n-rw-r--r-- 1 root root    4343 Jun 27  2023 sudo.conf\n-rw-r--r-- 1 root root    9804 Jun 27  2023 sudo_logsrvd.conf\n-r--r----- 1 root root    1756 Apr  5 06:28 sudoers\ndrwxr-xr-x 2 root root    4096 Apr  5 06:27 sudoers.d\ndrwxr-xr-x 3 root root    4096 Apr  5 06:27 sv\n-rw-r--r-- 1 root root    2355 Dec 19  2022 sysctl.conf\ndrwxr-xr-x 2 root root    4096 Apr  5 06:27 sysctl.d\ndrwxr-xr-x 1 root root    4096 Apr  5 06:27 systemd\ndrwxr-xr-x 2 root root    4096 Mar 11 00:00 terminfo\n-rw-r--r-- 1 root root       8 Mar 11 00:00 timezone\ndrwxr-xr-x 2 root root    4096 Jan 26 21:48 tmpfiles.d\n-rw-r--r-- 1 root root    1260 Jan 27  2023 ucf.conf\ndrwxr-xr-x 3 root root    4096 Apr  5 06:27 ufw\ndrwxr-xr-x 2 root root    4096 Mar 11 00:00 update-motd.d\ndrwxr-xr-x 2 root root    4096 Apr  5 06:27 vim\n-rw-r--r-- 1 root root    4942 May 14  2022 wgetrc\n-rw-r--r-- 1 root root     681 Jan 17  2023 xattr.conf\ndrw-rw---x 3 root root    4096 Apr  5 06:28 xdg\nleona@venus:\/etc$ cd bind\nleona@venus:\/etc\/bind$ ls -la\ntotal 60\ndrwxr-sr-x 2 root bind 4096 Apr  5 06:28 .\ndrwxr-xr-x 1 root root 4096 May 24 18:22 ..\n-rw-r--r-- 1 root root 2403 Feb 12 16:28 bind.keys\n-rw-r--r-- 1 root root  255 Feb 12 16:28 db.0\n-rw-r--r-- 1 root root  271 Feb 12 16:28 db.127\n-rw-r--r-- 1 root root  237 Feb 12 16:28 db.255\n-rw-r--r-- 1 root root  353 Feb 12 16:28 db.empty\n-rw-r--r-- 1 root root  270 Feb 12 16:28 db.local\n-rw-r--r-- 1 root bind  613 Apr  5 06:28 db.venus.hmv\n-rw-r--r-- 1 root bind  458 Feb 12 16:28 named.conf\n-rw-r--r-- 1 root bind  498 Feb 12 16:28 named.conf.default-zones\n-rw-r--r-- 1 root bind  307 Apr  5 06:28 named.conf.local\n-rw-r--r-- 1 root bind  219 Apr  5 06:28 named.conf.options\n-rw-r----- 1 bind bind  100 Apr  5 06:27 rndc.key\n-rw-r--r-- 1 root root 1317 Feb 12 16:28 zones.rfc1918\nleona@venus:\/etc\/bind$ cat db.venus.hmv\n\n;\n; BIND data file for local loopback interface\n;\n    604800\n@       IN      SOA     ns1.venus.hmv. root.venus.hmv. (\n                              2         ; Serial\n                         604800         ; Refresh\n                          86400         ; Retry\n                        2419200         ; Expire\n                         604800 )       ; Negative Cache TTL\n\n;@      IN      NS      localhost.\n;@      IN      A       127.0.0.1\n;@      IN      AAAA    ::1\n@       IN      NS      ns1.venus.hmv.\n\n;IP address of Name Server\n\nns1     IN      A       127.0.0.1\nava IN      TXT     oCXBeeEeYFX34NU<\/code><\/pre>\n<h1>50 ava<\/h1>\n<pre><code class=\"language-Bash\">leona@venus:\/etc$ su -l ava\nPassword:\nava@venus:~$ ls -la\ntotal 32\ndrwxr-x--- 2 root ava  4096 Apr  5 06:27 .\ndrwxr-xr-x 1 root root 4096 Apr  5 06:27 ..\n-rw-r--r-- 1 ava  ava   220 Apr 23  2023 .bash_logout\n-rw-r--r-- 1 ava  ava  3526 Apr 23  2023 .bashrc\n-rw-r--r-- 1 ava  ava   807 Apr 23  2023 .profile\n-rw-r----- 1 root ava    31 Apr  5 06:27 flagz.txt\n-rw-r----- 1 root ava   153 Apr  5 06:27 mission.txt\nava@venus:~$ cat flagz.txt\n8===7XsGiUHUZNouh6K6CyY2===D~~\nava@venus:~$ cat mission.txt\n################\n# MISSION 0x50 #\n################\n\n## EN ##\nThe password of maria is somewhere...\n\n## ES ##\nEl password de maria esta en algun lugar...<\/code><\/pre>\n<p>\u8fd9\u4e2a\u5f88\u4f24\u8111\u7b4b\uff0c\u771f\u60f3\u4e0d\u51fa\u6765\uff0c\u5e08\u5085\u4eec\u63d0\u9192\u662f\u524d\u9762\u89c1\u8fc7\u4f46\u6ca1\u7528\u7684\u90a3\u4e2a\u6469\u65af\u5bc6\u7801\u5bc6\u6587\uff0c\u5636\u3002\u3002\u3002<\/p>\n<pre><code class=\"language-text\">.--. .- .--. .- .--. .- .-. .- -.. .. ... .<\/code><\/pre>\n<h1>51 maria<\/h1>\n<pre><code class=\"language-Bash\">ava@venus:~$ su -l maria\nPassword:\nmaria@venus:~$ ls -la\ntotal 32\ndrwxr-x--- 2 root  maria 4096 Apr  5 06:27 .\ndrwxr-xr-x 1 root  root  4096 Apr  5 06:27 ..\n-rw-r--r-- 1 maria maria  220 Apr 23  2023 .bash_logout\n-rw-r--r-- 1 maria maria 3526 Apr 23  2023 .bashrc\n-rw-r--r-- 1 maria maria  807 Apr 23  2023 .profile\n-rw-r----- 1 root  maria   31 Apr  5 06:27 flagz.txt\n-rw-r----- 1 root  maria   96 Apr  5 06:27 mission.txt\nmaria@venus:~$ cat flagz.txt\n8===ZLNu1CHYSYf0PvkK2iqS===D~~\nmaria@venus:~$ cat mission.txt\n################\n# MISSION 0x51 #\n################\n\n## EN ##\nCongrats!\n\n## ES ##\nFelicidades :)<\/code><\/pre>\n<h1>\u63a2\u6d4b<\/h1>\n<pre><code class=\"language-Bash\">ava@venus:\/opt\/hereiam$ cat .here\nF67aDmCAAgOOaOc<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>41 sky adela@venus:~$ su -l sky Password: sky@venus:~$  [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,18],"tags":[],"class_list":["post-708","post","type-post","status-publish","format-standard","hentry","category-ctf-and-protest","category-web"],"_links":{"self":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/708","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/comments?post=708"}],"version-history":[{"count":1,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/708\/revisions"}],"predecessor-version":[{"id":709,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/708\/revisions\/709"}],"wp:attachment":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/media?parent=708"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/categories?post=708"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/tags?post=708"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}