{"id":109,"date":"2024-11-13T09:18:46","date_gmt":"2024-11-13T01:18:46","guid":{"rendered":"https:\/\/www.misaka19008-lab.icu\/?p=109"},"modified":"2024-11-13T09:51:00","modified_gmt":"2024-11-13T01:51:00","slug":"htb_machine_valentine","status":"publish","type":"post","link":"https:\/\/www.misaka19008-lab.icu\/index.php\/2024\/11\/13\/htb_machine_valentine\/","title":{"rendered":"HTB\u9776\u673a Valentine \u6e17\u900f\u6d4b\u8bd5\u8bb0\u5f55"},"content":{"rendered":"<hr \/>\n<h1>\u76ee\u6807\u4fe1\u606f<\/h1>\n<blockquote><p><strong>IP\u5730\u5740\uff1a<\/strong><code>10.10.10.79<\/code><\/p><\/blockquote>\n<hr \/>\n<h1>\u4fe1\u606f\u6536\u96c6<\/h1>\n<h2>ICMP\u68c0\u6d4b<\/h2>\n<pre><code class=\"language-plain\">\u250c\u2500\u2500(root\u327fhacker)-[\/home\/\u2026\/Documents\/pentest_notes\/valentine\/nmap_reports]\n\u2514\u2500# ping -c 4 10.10.10.79\nPING 10.10.10.79 (10.10.10.79) 56(84) bytes of data.\n64 bytes from 10.10.10.79: icmp_seq=1 ttl=63 time=307 ms\n64 bytes from 10.10.10.79: icmp_seq=2 ttl=63 time=300 ms\n64 bytes from 10.10.10.79: icmp_seq=3 ttl=63 time=280 ms\n64 bytes from 10.10.10.79: icmp_seq=4 ttl=63 time=268 ms\n\n--- 10.10.10.79 ping statistics ---\n4 packets transmitted, 4 received, 0% packet loss, time 3009ms\nrtt min\/avg\/max\/mdev = 267.755\/288.768\/307.389\/15.692 ms<\/code><\/pre>\n<p>\u653b\u51fb\u673a\u548c\u9776\u673a\u4e4b\u95f4\u7f51\u7edc\u8fde\u63a5\u826f\u597d\u3002<\/p>\n<h2>\u9632\u706b\u5899\u68c0\u6d4b<\/h2>\n<pre><code class=\"language-plain\"># Nmap 7.94SVN scan initiated Fri Jun 28 08:02:02 2024 as: nmap -sF -p- --min-rate 2000 -oN .\/fin_result.txt 10.10.10.79\nNmap scan report for 10.10.10.79 (10.10.10.79)\nHost is up (0.30s latency).\nNot shown: 65532 closed tcp ports (reset)\nPORT    STATE         SERVICE\n22\/tcp  open|filtered ssh\n80\/tcp  open|filtered http\n443\/tcp open|filtered https\n\n# Nmap done at Fri Jun 28 08:02:45 2024 -- 1 IP address (1 host up) scanned in 43.35 seconds<\/code><\/pre>\n<p>\u9776\u673a\u5f00\u653e\u4e86<code>3<\/code>\u4e2a<code>TCP<\/code>\u7aef\u53e3\u3002<\/p>\n<h2>\u7f51\u7edc\u7aef\u53e3\u626b\u63cf<\/h2>\n<p><code>TCP<\/code><strong>\u7aef\u53e3\u626b\u63cf\u7ed3\u679c<\/strong><\/p>\n<pre><code class=\"language-plain\"># Nmap 7.94SVN scan initiated Fri Jun 28 08:07:48 2024 as: nmap -sS -sV -A -p 22,80,443 -oN .\/tcp_result.txt 10.10.10.79\nNmap scan report for 10.10.10.79 (10.10.10.79)\nHost is up (0.30s latency).\n\nPORT    STATE SERVICE  VERSION\n22\/tcp  open  ssh      OpenSSH 5.9p1 Debian 5ubuntu1.10 (Ubuntu Linux; protocol 2.0)\n| ssh-hostkey: \n|   1024 96:4c:51:42:3c:ba:22:49:20:4d:3e:ec:90:cc:fd:0e (DSA)\n|   2048 46:bf:1f:cc:92:4f:1d:a0:42:b3:d2:16:a8:58:31:33 (RSA)\n|_  256 e6:2b:25:19:cb:7e:54:cb:0a:b9:ac:16:98:c6:7d:a9 (ECDSA)\n80\/tcp  open  http     Apache httpd 2.2.22 ((Ubuntu))\n|_http-title: Site doesn't have a title (text\/html).\n|_http-server-header: Apache\/2.2.22 (Ubuntu)\n443\/tcp open  ssl\/http Apache httpd 2.2.22 ((Ubuntu))\n|_http-server-header: Apache\/2.2.22 (Ubuntu)\n|_http-title: Site doesn't have a title (text\/html).\n|_ssl-date: 2024-06-28T00:09:28+00:00; +58s from scanner time.\n| ssl-cert: Subject: commonName=valentine.htb\/organizationName=valentine.htb\/stateOrProvinceName=FL\/countryName=US\n| Not valid before: 2018-02-06T00:45:25\n|_Not valid after:  2019-02-06T00:45:25\nWarning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port\nDevice type: general purpose|phone|media device\nRunning (JUST GUESSING): Linux 3.X|2.6.X (96%), Nokia embedded (95%), Google Android 4.0.X|4.2.X|4.X (93%)\nOS CPE: cpe:\/o:linux:linux_kernel:3.0 cpe:\/o:linux:linux_kernel:2.6 cpe:\/o:linux:linux_kernel:2.6.32 cpe:\/h:nokia:n9 cpe:\/o:google:android:4.0.4 cpe:\/o:google:android:4.2.1 cpe:\/o:google:android:4.2.2 cpe:\/o:google:android:4.0\nAggressive OS guesses: Linux 3.0 (96%), Linux 3.2 (96%), Linux 2.6.32 - 3.5 (95%), Nokia N9 phone (Linux 2.6.32) (95%), Linux 2.6.38 - 3.0 (94%), Linux 2.6.38 - 2.6.39 (94%), Linux 2.6.39 (94%), Linux 3.5 (93%), Linux 2.6.32 - 3.10 (93%), Linux 2.6.32 - 3.9 (93%)\nNo exact OS matches for host (test conditions non-ideal).\nNetwork Distance: 2 hops\nService Info: OS: Linux; CPE: cpe:\/o:linux:linux_kernel\n\nHost script results:\n|_clock-skew: 57s\n\nTRACEROUTE (using port 80\/tcp)\nHOP RTT       ADDRESS\n1   286.58 ms 10.10.14.1 (10.10.14.1)\n2   286.73 ms 10.10.10.79 (10.10.10.79)\n\nOS and Service detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\n# Nmap done at Fri Jun 28 08:08:32 2024 -- 1 IP address (1 host up) scanned in 43.80 seconds<\/code><\/pre>\n<p><code>UDP<\/code><strong>\u7aef\u53e3\u5f00\u653e\u5217\u8868\u626b\u63cf\u7ed3\u679c<\/strong><\/p>\n<pre><code class=\"language-plain\"># Nmap 7.94SVN scan initiated Fri Jun 28 08:14:30 2024 as: nmap -sU -p- --min-rate 2000 -oN .\/udp_ports.txt 10.10.10.79\nWarning: 10.10.10.79 giving up on port because retransmission cap hit (10).\nNmap scan report for valentine.htb (10.10.10.79)\nHost is up (0.27s latency).\nNot shown: 65185 open|filtered udp ports (no-response), 349 closed udp ports (port-unreach)\nPORT     STATE SERVICE\n5353\/udp open  zeroconf\n\n# Nmap done at Fri Jun 28 08:20:33 2024 -- 1 IP address (1 host up) scanned in 362.51 seconds<\/code><\/pre>\n<p><code>UDP<\/code><strong>\u7aef\u53e3\u8be6\u7ec6\u4fe1\u606f\u626b\u63cf\u7ed3\u679c<\/strong><\/p>\n<pre><code class=\"language-plain\"># Nmap 7.94SVN scan initiated Fri Jun 28 08:23:30 2024 as: nmap -sU -sV -A -p 5353 -oN .\/udp_result.txt 10.10.10.79\nNmap scan report for valentine.htb (10.10.10.79)\nHost is up (0.29s latency).\n\nPORT     STATE SERVICE VERSION\n5353\/udp open  mdns    DNS-based service discovery\n| dns-service-discovery: \n|   9\/tcp workstation\n|     Address=10.10.10.79 dead:beef::250:56ff:fe94:8f0e\n|   22\/tcp udisks-ssh\n|_    Address=10.10.10.79 dead:beef::250:56ff:fe94:8f0e\nToo many fingerprints match this host to give specific OS details\nNetwork Distance: 2 hops\n\nTRACEROUTE (using port 5353\/udp)\nHOP RTT       ADDRESS\n1   294.07 ms 10.10.14.1 (10.10.14.1)\n2   ... 30\n\nOS and Service detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\n# Nmap done at Fri Jun 28 08:23:43 2024 -- 1 IP address (1 host up) scanned in 12.89 seconds<\/code><\/pre>\n<p>\u540c\u65f6\u53d1\u73b0\u9776\u673a\u64cd\u4f5c\u7cfb\u7edf\u4e3a<code>Ubuntu Linux<\/code>\uff0c\u5185\u6838\u7248\u672c\u5927\u81f4\u4e3a<code>Linux 3.0<\/code>\uff0c\u6ce8\u610f\u5230<code>OpenSSH<\/code>\u548c<code>Apache HTTP Server<\/code>\u7248\u672c\u8f83\u4f4e\uff0c\u6709\u53ef\u80fd\u5b58\u5728\u5fc3\u810f\u6ef4\u8840\u6f0f\u6d1e\u3002<\/p>\n<hr \/>\n<h1>\u670d\u52a1\u63a2\u6d4b<\/h1>\n<h2>SSH\u670d\u52a1\uff0822\u7aef\u53e3\uff09<\/h2>\n<p>\u7aef\u53e3<code>Banner<\/code>\uff1a<\/p>\n<pre><code class=\"language-shell\">\u250c\u2500\u2500(root\u327fhacker)-[\/home\/megumin\/Documents\/pentest_notes\/valentine]\n\u2514\u2500# nc -nv 10.10.10.79 22                                   \n(UNKNOWN) [10.10.10.79] 22 (ssh) open\nSSH-2.0-OpenSSH_5.9p1 Debian-5ubuntu1.10<\/code><\/pre>\n<h2>Web\u5e94\u7528\u7a0b\u5e8f\uff0880\u7aef\u53e3\uff09<\/h2>\n<p>\u6253\u5f00\u4e3b\u9875\uff1a<code>http:\/\/valentine.htb\/<\/code><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1719705613674-c335672d-9dfb-4857-aa6d-91b242ff20cd.png\" alt=\"\" \/><\/p>\n<pre><code class=\"language-html\">&lt;center&gt;&lt;img src=\"omg.jpg\"\/&gt;&lt;\/center&gt;<\/code><\/pre>\n<p>\u76f4\u63a5\u626b\u63cf\u76ee\u5f55\uff1a<\/p>\n<pre><code class=\"language-plain\"># Dirsearch started Tue Jul  2 12:47:29 2024 as: \/usr\/lib\/python3\/dist-packages\/dirsearch\/dirsearch.py -u http:\/\/valentine.htb\/ -x 400,403,404 -t 60 -e php,js,html,asp,aspx,txt,tar.gz,zip,pcap -w \/usr\/share\/wordlists\/dirb\/big.txt\n\n200   334B   http:\/\/valentine.htb\/decode\n301   243B   http:\/\/valentine.htb\/dev    -&gt; REDIRECTS TO: http:\/\/valentine.htb\/dev\/\n200   336B   http:\/\/valentine.htb\/encode<\/code><\/pre>\n<p>\u53d1\u73b0\u4e86<code>3<\/code>\u4e2a\u76ee\u5f55\u3002<\/p>\n<p><code>\/dev<\/code>\u76ee\u5f55\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1719896698893-49f62858-a485-4a11-ae4a-f278e3216bce.png\" alt=\"\" \/><\/p>\n<p>\u5176\u4e2d<code>notes.txt<\/code>\u6587\u4ef6\u5185\u5bb9\u5982\u4e0b\uff1a<\/p>\n<pre><code class=\"language-plain\">To do:\n\n1) Coffee.\n2) Research.\n3) Fix decoder\/encoder before going live.\n4) Make sure encoding\/decoding is only done client-side.\n5) Don't use the decoder\/encoder until any of this is done.\n6) Find a better way to take notes.<\/code><\/pre>\n<p><code>hype_key<\/code>\u6587\u4ef6\u5185\u5bb9\u4e3a\u4e00\u5927\u5806<code>16<\/code>\u8fdb\u5236\u5b57\u7b26\u4e32\uff1a<\/p>\n<pre><code class=\"language-plain\">2d 2d 2d 2d 2d 42 45 47 49 4e 20 52 53 41 20 50 52 49 56 41 54 45 20 4b 4<\/code><\/pre>\n<p>\u4f7f\u7528\u5728\u7ebf\u5de5\u5177\u5c06\u5176\u8f6c\u6362\u4e3a\u6587\u4ef6\u4e4b\u540e\u4e0b\u8f7d\uff0c\u5c1d\u8bd5\u8fdb\u884c\u5206\u6790\uff0c\u53d1\u73b0\u4e3a<code>SSH<\/code>\u79c1\u94a5\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1719897173448-6da17067-a4d3-4c77-a502-61827ee7b1bf.png\" alt=\"\" \/><\/p>\n<p>\u5c1d\u8bd5\u67e5\u770b\u6587\u4ef6\u5185\u5bb9\uff0c\u53d1\u73b0\u8be5<code>SSH<\/code>\u79c1\u94a5\u88ab\u52a0\u5bc6\uff1a<\/p>\n<pre><code class=\"language-plain\">-----BEGIN RSA PRIVATE KEY-----\nProc-Type: 4,ENCRYPTED\nDEK-Info: AES-128-CBC,AEB88C140F69BF2074788DE24AE48D46\n\nDbPrO78kegNuk1DAqlAN5jbjXv0PPsog3jdbMFS8iE9p3UOL0lF0xf7PzmrkDa8R\n5y\/b46+9nEpCMfTPhNuJRcW2U2gJcOFH+9RJDBC5UJMUS1\/gjB\/7\/My00Mwx+aI6\n0EI0SbOYUAV1W4EV7m96QsZjrwJvnjVafm6VsKaTPBHpugcASvMqz76W6abRZeXi\nEbw66hjFmAu4AzqcM\/kigNRFPYuNiXrXs1w\/deLCqCJ+Ea1T8zlas6fcmhM8A+8P\nOXBKNe6l17hKaT6wFnp5eXOaUIHvHnvO6ScHVWRrZ70fcpcpimL1w13Tgdd2AiGd\npHLJpYUII5PuO6x+LS8n1r\/GWMqSOEimNRD1j\/59\/4u3ROrTCKeo9DsTRqs2k1SH\nQdWwFwaXbYyT1uxAMSl5Hq9OD5HJ8G0R6JI5RvCNUQjwx0FITjjMjnLIpxjvfq+E\np0gD0UcylKm6rCZqacwnSddHW8W3LxJmCxdxW5lt5dPjAkBYRUnl91ESCiD4Z+uC\nOl6jLFD2kaOLfuyee0fYCb7GTqOe7EmMB3fGIwSdW8OC8NWTkwpjc0ELblUa6ulO\nt9grSosRTCsZd14OPts4bLspKxMMOsgnKloXvnlPOSwSpWy9Wp6y8XX8+F40rxl5\nXqhDUBhyk1C3YPOiDuPOnMXaIpe1dgb0NdD1M9ZQSNULw1DHCGPP4JSSxX7BWdDK\naAnWJvFglA4oFBBVA8uAPMfV2XFQnjwUT5bPLC65tFstoRtTZ1uSruai27kxTnLQ\n+wQ87lMadds1GQNeGsKSf8R\/rsRKeeKcilDePCjeaLqtqxnhNoFtg0Mxt6r2gb1E\nAloQ6jg5Tbj5J7quYXZPylBljNp9GVpinPc3KpHttvgbptfiWEEsZYn5yZPhUr9Q\nr08pkOxArXE2dj7eX+bq65635OJ6TqHbAlTQ1Rs9PulrS7K4SLX7nY89\/RZ5oSQe\n2VWRyTZ1FfngJSsv9+Mfvz341lbzOIWmk7WfEcWcHc16n9V0IbSNALnjThvEcPky\ne1BsfSbsf9FguUZkgHAnnfRKkGVG1OVyuwc\/LVjmbhZzKwLhaZRNd8HEM86fNojP\n09nVjTaYtWUXk0Si1W02wbu1NzL+1Tg9IpNyISFCFYjSqiyG+WU7IwK3YU5kp3CC\ndYScz63Q2pQafxfSbuv4CMnNpdirVKEo5nRRfK\/iaL3X1R3DxV8eSYFKFL6pqpuX\ncY5YZJGAp+JxsnIQ9CFyxIt92frXznsjhlYa8svbVNNfk\/9fyX6op24rL2DyESpY\npnsukBCFBkZHWNNyeN7b5GhTVCodHhzHVFehTuBrp+VuPqaqDvMCVe1DZCb4MjAj\nMslf+9xK+TXEL3icmIOBRdPyw6e\/JlQlVRlmShFpI8eb\/8VsTyJSe+b853zuV2qL\nsuLaBMxYKm3+zEDIDveKPNaaWZgEcqxylCC\/wUyUXlMJ50Nw6JNVMM8LeCii3OEW\nl0ln9L1b\/NXpHjGa8WHHTjoIilB5qNUyywSeTBF2awRlXH9BrkZG4Fc4gdmW\/IzT\nRUgZkbMQZNIIfzj1QuilRVBm\/F76Y\/YMrmnM9k\/1xSGIskwCUQ+95CGHJE8MkhD3\n-----END RSA PRIVATE KEY-----<\/code><\/pre>\n<p>\u8bbf\u95ee<code>\/encode<\/code>\uff0c\u53d1\u73b0\u4e3a<code>Base64<\/code>\u52a0\u5bc6\u7a0b\u5e8f\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1719897467098-2fb20910-ee60-48c5-8b32-9d1c4070392b.png\" alt=\"\" \/><\/p>\n<p>\u8bbf\u95ee<code>\/decode<\/code>\uff0c\u53d1\u73b0\u4e3a<code>Base64<\/code>\u89e3\u5bc6\u7a0b\u5e8f\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1719897712071-ed2e0bcb-c195-4149-a300-bc35b8ffe8cd.png\" alt=\"\" \/><\/p>\n<h2>Web\u670d\u52a1\u63a2\u6d4b\uff08443\u7aef\u53e3\uff09<\/h2>\n<p>\u6253\u5f00\u4e3b\u9875\uff1a<code>https:\/\/valentine.htb\/<\/code><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1719898392574-b3ab18b4-9113-405f-acc7-4dac7e4b7bd5.png\" alt=\"\" \/><\/p>\n<p>\u76f4\u63a5\u626b\u63cf\u6f0f\u6d1e\uff0c\u53d1\u73b0\u76ee\u5f55\u6587\u4ef6\u548c<code>80<\/code>\u7aef\u53e3\u76f8\u540c\uff1a<\/p>\n<pre><code class=\"language-plain\"># Dirsearch started Tue Jul  2 13:38:59 2024 as: \/usr\/lib\/python3\/dist-packages\/dirsearch\/dirsearch.py -u https:\/\/valentine.htb\/ -x 400,403,404 -t 60 -e php,js,html,asp,aspx,txt,zip,tar.gz,pcap -w \/usr\/share\/wordlists\/dirb\/big.txt\n\n200   334B   https:\/\/valentine.htb\/decode\n301   244B   https:\/\/valentine.htb\/dev    -&gt; REDIRECTS TO: https:\/\/valentine.htb\/dev\/\n200   336B   https:\/\/valentine.htb\/encode<\/code><\/pre>\n<hr \/>\n<h1>\u6e17\u900f\u6d4b\u8bd5<\/h1>\n<h2>\u5fc3\u810f\u6ef4\u8840\u6f0f\u6d1e\u5229\u7528<\/h2>\n<p>\u8054\u7f51\u67e5\u8be2<code>Apache HTTP Server 2.2.22<\/code>\u4f7f\u7528\u7684<code>SSL<\/code>\u7248\u672c\uff0c\u53d1\u73b0\u8be5\u7248\u672c<code>HTTP<\/code>\u670d\u52a1\u5668\u4f7f\u7528<code>OpenSSL 1.0.1<\/code>\uff0c\uff0c\u4ee5\u53ca\u53d1\u5e03\u5e74\u4efd\u4e3a<code>2012<\/code>\u5e74\uff0c\u5f88\u6709\u53ef\u80fd\u5b58\u5728\u5fc3\u810f\u6ef4\u8840\u6f0f\u6d1e\u3002<\/p>\n<p>\u5c1d\u8bd5\u4f7f\u7528<code>Metasploit<\/code>\u5229\u7528<code>Heartbleed<\/code>\u6f0f\u6d1e\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1719901634766-0f5ec0a7-2fde-4c50-8dcf-3da848aba505.png\" alt=\"\" \/><\/p>\n<p><strong>\u6210\u529f\u83b7\u53d6\u4e86\u4e00\u5c0f\u6bb5<\/strong><code>HTTP<\/code><strong>\u8bf7\u6c42\u5305\u5185\u5bb9\uff01<\/strong>\u8be5\u8bf7\u6c42\u5305\u8bf7\u6c42\u4e86<code>decode.php<\/code>\uff0c<code>POST<\/code>\u53c2\u6570<code>text<\/code>\u7684\u5185\u5bb9\u4e3a\uff1a<code>aGVhcnRibGVlZGJlbGlldmV0aGVoeXBlCg==<\/code>\u3002<\/p>\n<p><strong>\u4f7f\u7528<\/strong><code>Base64<\/code><strong>\u89e3\u7801\u5668\u89e3\u7801\u540e\uff0c\u5c1d\u8bd5\u5c06\u539f\u6587\u4f5c\u4e3a<\/strong><code>SSH<\/code><strong>\u79c1\u94a5\u7684\u53e3\u4ee4\u8fdb\u884c\u9a8c\u8bc1\uff0c\u53d1\u73b0\u53e3\u4ee4\u6b63\u786e\u3002<\/strong><\/p>\n<ul>\n<li><code>SSH<\/code>\u79c1\u94a5\u53e3\u4ee4\uff1a<code>heartbleedbelievethehype<\/code><\/li>\n<\/ul>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1719901910756-93404e79-218d-48bd-9853-fb991fac21f0.png\" alt=\"\" \/><\/p>\n<p>\u63a5\u4e0b\u6765\u9700\u8981\u5f97\u77e5\u7528\u6237\u540d\u3002\u9274\u4e8e\u4ece\u7f51\u9875\u4e0a\u83b7\u53d6\u7684<code>16<\/code>\u8fdb\u5236\u5b57\u7b26\u4e32\u6e90\u6587\u4ef6\u540d\u4e3a<code>hype_key<\/code>\uff0c\u5c1d\u8bd5<code>hype<\/code>\u4f5c\u4e3a\u7528\u6237\u540d\u767b\u5f55\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1719902089898-a0f55489-7742-45d1-9f9c-341ff22ffb46.png\" alt=\"\" \/><\/p>\n<p><strong>\u6210\u529f\uff01\uff01\uff01<\/strong><\/p>\n<hr \/>\n<h1>\u6743\u9650\u63d0\u5347<\/h1>\n<h2>\u5386\u53f2\u547d\u4ee4\u63d0\u6743<\/h2>\n<p>\u8fdb\u5165\u7cfb\u7edf\u4e4b\u540e\uff0c\u67e5\u770b<code>hype<\/code>\u7528\u6237\u5386\u53f2\u547d\u4ee4\u8bb0\u5f55\u6587\u4ef6<code>\/home\/hype\/.bash_history<\/code>\uff1a<\/p>\n<pre><code class=\"language-shell\">exit\nexot\nexit\nls -la\ncd \/\nls -la\ncd .devs\nls -la\ntmux -L dev_sess \ntmux a -t dev_sess \ntmux --help\ntmux -S \/.devs\/dev_sess \nexit\nid\nqexit\nexit<\/code><\/pre>\n<p>\u53d1\u73b0\u6709\u51e0\u4e2a\u4e0d\u77e5\u662f\u4f55\u4f5c\u7528\u7684<code>Tmux<\/code>\u547d\u4ee4\uff0c\u4ee5\u53ca\u53d1\u73b0\u4e86\u53ef\u7591\u76ee\u5f55<code>\/.devs<\/code>\uff0c\u76ee\u5f55\u5217\u8868\u5982\u4e0b\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1719902828804-f7a86fb3-58dd-437e-a34d-ee4c76c26f34.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u4e00\u4e2a<code>SUID<\/code>\u7a7a\u6587\u4ef6<code>\/.devs\/dev_sess<\/code>\uff0c\u5c5e\u4e3b\u4e3a<code>root:hype<\/code>\uff0c\u6743\u9650\u4e3a<code>4660<\/code>\uff0c\u5f53\u524d\u65e0\u6743\u66f4\u6539\u5176\u6743\u9650\u3002<\/p>\n<p>\u4e00\u5934\u96fe\u6c34\u4e4b\u4e0b\uff0c\u5c1d\u8bd5\u4f9d\u6b21\u6267\u884c\u5f53\u524d\u7528\u6237\u7684\u5386\u53f2\u547d\u4ee4\uff0c\u5f53\u6267\u884c\u5230\u5982\u4e0b\u547d\u4ee4\u65f6\uff0c\u53d1\u751f\u4e86\u60ca\u559c\uff1a<\/p>\n<pre><code class=\"language-shell\">tmux -S \/.devs\/dev_sess<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1719903097597-6aa075a3-8d87-421a-bef0-65f3159e23cc.png\" alt=\"\" \/><\/p>\n<p><strong>\u63d0\u6743\u6210\u529f\uff01\uff01\uff01\uff01<\/strong><\/p>\n<hr \/>\n<h1>Flag\u6587\u4ef6\u5c55\u793a<\/h1>\n<pre><code class=\"language-plain\">fcb76f2df9447c53833a9ddf510f9747<\/code><\/pre>\n<hr \/>\n<h1>\u672c\u6b21\u9776\u673a\u6e17\u900f\u5230\u6b64\u7ed3\u675f<\/h1>\n<hr \/>\n","protected":false},"excerpt":{"rendered":"<p>\u76ee\u6807\u4fe1\u606f IP\u5730\u5740\uff1a10.10.10.79 \u4fe1\u606f\u6536\u96c6 ICMP\u68c0\u6d4b \u250c\u2500\u2500(root\u327fhacker)-[\/home\/\u2026\/Docum &#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","emotion":"","emotion_color":"","title_style":"","license":"","footnotes":""},"categories":[3,14],"tags":[],"class_list":["post-109","post","type-post","status-publish","format-standard","hentry","category-htb_retired","category-linux_machines"],"_links":{"self":[{"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/posts\/109","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/comments?post=109"}],"version-history":[{"count":1,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/posts\/109\/revisions"}],"predecessor-version":[{"id":110,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/posts\/109\/revisions\/110"}],"wp:attachment":[{"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/media?parent=109"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/categories?post=109"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/tags?post=109"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}