{"id":126,"date":"2024-11-13T09:33:19","date_gmt":"2024-11-13T01:33:19","guid":{"rendered":"https:\/\/www.misaka19008-lab.icu\/?p=126"},"modified":"2024-11-13T09:49:19","modified_gmt":"2024-11-13T01:49:19","slug":"htb_machine_mirai","status":"publish","type":"post","link":"https:\/\/www.misaka19008-lab.icu\/index.php\/2024\/11\/13\/htb_machine_mirai\/","title":{"rendered":"HTB\u9776\u673a Mirai \u6e17\u900f\u6d4b\u8bd5\u8bb0\u5f55"},"content":{"rendered":"<hr \/>\n<h1>\u76ee\u6807\u4fe1\u606f<\/h1>\n<blockquote><p><strong>IP\u5730\u5740\uff1a<\/strong><code>10.10.10.48<\/code><\/p><\/blockquote>\n<hr \/>\n<h1>\u4fe1\u606f\u6536\u96c6<\/h1>\n<h2>ICMP\u68c0\u6d4b<\/h2>\n<pre><code class=\"language-plain\">\u250c\u2500\u2500(root\u327fmisaka19008)-[\/home\/\u2026\/Documents\/pentest_notes\/mirai\/nmap_reports]\n\u2514\u2500# ping -c 4 10.10.10.48\nPING 10.10.10.48 (10.10.10.48) 56(84) bytes of data.\n64 bytes from 10.10.10.48: icmp_seq=1 ttl=63 time=264 ms\n64 bytes from 10.10.10.48: icmp_seq=2 ttl=63 time=266 ms\n64 bytes from 10.10.10.48: icmp_seq=3 ttl=63 time=265 ms\n64 bytes from 10.10.10.48: icmp_seq=4 ttl=63 time=266 ms\n\n--- 10.10.10.48 ping statistics ---\n4 packets transmitted, 4 received, 0% packet loss, time 3238ms\nrtt min\/avg\/max\/mdev = 263.531\/265.051\/265.804\/0.901 ms<\/code><\/pre>\n<p>\u653b\u51fb\u673a\u548c\u9776\u673a\u4e4b\u95f4\u901a\u4fe1\u72b6\u6001\u826f\u597d\u3002<\/p>\n<h2>\u9632\u706b\u5899\u68c0\u6d4b<\/h2>\n<pre><code class=\"language-plain\"># Nmap 7.94SVN scan initiated Sat Jul 20 21:04:03 2024 as: nmap -sF -p- --min-rate 2000 -oN .\/fin_result.txt 10.10.10.48\nWarning: 10.10.10.48 giving up on port because retransmission cap hit (10).\nNmap scan report for 10.10.10.48 (10.10.10.48)\nHost is up (0.30s latency).\nNot shown: 65529 closed tcp ports (reset)\nPORT      STATE         SERVICE\n22\/tcp    open|filtered ssh\n53\/tcp    open|filtered domain\n80\/tcp    open|filtered http\n1402\/tcp  open|filtered prm-sm-np\n32400\/tcp open|filtered plex\n32469\/tcp open|filtered unknown\n\n# Nmap done at Sat Jul 20 21:05:08 2024 -- 1 IP address (1 host up) scanned in 64.77 seconds<\/code><\/pre>\n<p>\u9776\u673a\u5f00\u653e\u4e86<code>6<\/code>\u4e2a<code>TCP<\/code>\u7aef\u53e3\u3002<\/p>\n<h2>\u7f51\u7edc\u7aef\u53e3\u626b\u63cf<\/h2>\n<p><code>TCP<\/code><strong>\u7aef\u53e3\u626b\u63cf\u7ed3\u679c<\/strong><\/p>\n<pre><code class=\"language-plain\"># Nmap 7.94SVN scan initiated Sat Jul 20 21:09:12 2024 as: nmap -sS -sV -A -p 22,53,80,1402,32400,32469 -oN .\/tcp_result.txt 10.10.10.48\nNmap scan report for 10.10.10.48 (10.10.10.48)\nHost is up (0.24s latency).\n\nPORT      STATE SERVICE    VERSION\n22\/tcp    open  ssh        OpenSSH 6.7p1 Debian 5+deb8u3 (protocol 2.0)\n| ssh-hostkey: \n|   1024 aa:ef:5c:e0:8e:86:97:82:47:ff:4a:e5:40:18:90:c5 (DSA)\n|   2048 e8:c1:9d:c5:43:ab:fe:61:23:3b:d7:e4:af:9b:74:18 (RSA)\n|   256 b6:a0:78:38:d0:c8:10:94:8b:44:b2:ea:a0:17:42:2b (ECDSA)\n|_  256 4d:68:40:f7:20:c4:e5:52:80:7a:44:38:b8:a2:a7:52 (ED25519)\n53\/tcp    open  tcpwrapped\n80\/tcp    open  http       lighttpd 1.4.35\n|_http-title: Site doesn't have a title (text\/html; charset=UTF-8).\n|_http-server-header: lighttpd\/1.4.35\n1402\/tcp  open  upnp       Platinum UPnP 1.0.5.13 (UPnP\/1.0 DLNADOC\/1.50)\n32400\/tcp open  http       Plex Media Server httpd\n|_http-cors: HEAD GET POST PUT DELETE OPTIONS\n|_http-favicon: Plex\n| http-auth: \n| HTTP\/1.1 401 Unauthorizedx0D\n|_  Server returned status 401 but no WWW-Authenticate header.\n|_http-title: Unauthorized\n32469\/tcp open  upnp       Platinum UPnP 1.0.5.13 (UPnP\/1.0 DLNADOC\/1.50)\nWarning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port\nAggressive OS guesses: Linux 3.18 (96%), Linux 3.2 - 4.9 (96%), Linux 3.16 (95%), Linux 3.12 (95%), Linux 3.13 (95%), Linux 3.8 - 3.11 (95%), Linux 4.2 (95%), ASUS RT-N56U WAP (Linux 3.4) (95%), Linux 4.4 (95%), Linux 4.8 (94%)\nNo exact OS matches for host (test conditions non-ideal).\nNetwork Distance: 2 hops\nService Info: OS: Linux; CPE: cpe:\/o:linux:linux_kernel\n\nTRACEROUTE (using port 32469\/tcp)\nHOP RTT       ADDRESS\n1   312.38 ms 10.10.14.1 (10.10.14.1)\n2   312.44 ms 10.10.10.48 (10.10.10.48)\n\nOS and Service detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\n# Nmap done at Sat Jul 20 21:09:48 2024 -- 1 IP address (1 host up) scanned in 36.37 seconds<\/code><\/pre>\n<p><code>UDP<\/code><strong>\u7aef\u53e3\u5f00\u653e\u5217\u8868\u626b\u63cf\u7ed3\u679c<\/strong><\/p>\n<pre><code class=\"language-plain\"># Nmap 7.94SVN scan initiated Sat Jul 20 21:13:06 2024 as: nmap -sU -p- --min-rate 2000 -oN .\/udp_ports.txt 10.10.10.48\nWarning: 10.10.10.48 giving up on port because retransmission cap hit (10).\nNmap scan report for 10.10.10.48 (10.10.10.48)\nHost is up (0.75s latency).\nNot shown: 65163 open|filtered udp ports (no-response), 366 closed udp ports (port-unreach)\nPORT      STATE SERVICE\n53\/udp    open  domain\n123\/udp   open  ntp\n5353\/udp  open  zeroconf\n32414\/udp open  unknown\n38276\/udp open  unknown\n54591\/udp open  unknown\n\n# Nmap done at Sat Jul 20 21:19:26 2024 -- 1 IP address (1 host up) scanned in 379.67 seconds<\/code><\/pre>\n<p><code>UDP<\/code><strong>\u7aef\u53e3\u8be6\u7ec6\u4fe1\u606f\u626b\u63cf\u7ed3\u679c<\/strong><\/p>\n<pre><code class=\"language-plain\"># Nmap 7.94SVN scan initiated Sat Jul 20 21:22:02 2024 as: nmap -sC -sU -sV -A -p 53,123,5353,32414,38276,54591 -oN .\/udp_result.txt 10.10.10.48\nNmap scan report for 10.10.10.48 (10.10.10.48)\nHost is up (0.24s latency).\n\nPORT      STATE  SERVICE VERSION\n53\/udp    open   domain  dnsmasq 2.76\n|_dns-recursion: Recursion appears to be enabled\n123\/udp   open   ntp     NTP v4 (unsynchronized)\n| ntp-info: \n|_  \n5353\/udp  open   mdns    DNS-based service discovery\n| dns-service-discovery: \n|   9\/tcp workstation\n|     Address=10.10.10.48 dead:beef::c02b:b52b:ff16:c5ef\n|   22\/tcp udisks-ssh\n|_    Address=10.10.10.48 dead:beef::c02b:b52b:ff16:c5ef\n32414\/udp open   unknown\n38276\/udp closed unknown\n54591\/udp closed unknown\nToo many fingerprints match this host to give specific OS details\nNetwork Distance: 2 hops\n\nHost script results:\n|_clock-skew: 12s\n\nTRACEROUTE (using port 443\/tcp)\nHOP RTT       ADDRESS\n1   317.31 ms 10.10.14.1 (10.10.14.1)\n2   25.98 ms  10.10.10.48 (10.10.10.48)\n\nOS and Service detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\n# Nmap done at Sat Jul 20 21:24:16 2024 -- 1 IP address (1 host up) scanned in 134.21 seconds<\/code><\/pre>\n<p>\u540c\u65f6\u53d1\u73b0\u9776\u673a\u64cd\u4f5c\u7cfb\u7edf\u4e3a<code>Debian Linux<\/code>\u3002<\/p>\n<hr \/>\n<h1>\u670d\u52a1\u63a2\u6d4b<\/h1>\n<h2>SSH\u670d\u52a1\uff0822\u7aef\u53e3\uff09<\/h2>\n<p>\u7aef\u53e3<code>Banner<\/code>\uff1a<\/p>\n<pre><code class=\"language-shell\">\u250c\u2500\u2500(root\u327fmisaka19008)-[\/home\/megumin\/Documents\/pentest_notes\/mirai]\n\u2514\u2500# nc -nv 10.10.10.48 22                                                                \n(UNKNOWN) [10.10.10.48] 22 (ssh) open\nSSH-2.0-OpenSSH_6.7p1 Debian-5+deb8u3<\/code><\/pre>\n<h2>DNS\u670d\u52a1\uff0853\u7aef\u53e3\uff09<\/h2>\n<p>\u5c1d\u8bd5\u4f7f\u7528<code>DNS<\/code>\u533a\u57df\u4f20\u8f93\u529f\u80fd\uff1a<\/p>\n<pre><code class=\"language-shell\">dig axfr @10.10.10.48<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1721521023590-9af1150d-c2fd-4f8e-89a0-229f544fac2c.png\" alt=\"\" \/><\/p>\n<p>\u9664\u6b64\u4e4b\u5916\u672a\u53d1\u73b0\u5176\u5b83\u6709\u6548\u4fe1\u606f\u3002<\/p>\n<h2>Web\u5e94\u7528\u7a0b\u5e8f\uff0880\u7aef\u53e3\uff09<\/h2>\n<p>\u6253\u5f00\u4e3b\u9875\uff1a<code>http:\/\/10.10.10.48\/<\/code><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1721607295236-a6c0c092-f487-4f20-9fe9-726362716ef1.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u4e3b\u9875\u4e0a\u6ca1\u6709\u4efb\u4f55\u5185\u5bb9\uff0c\u4f46\u662f\u5728\u54cd\u5e94\u5934\u4e2d\u53d1\u73b0\u4e00\u9879\u5947\u602a\u7684\u5185\u5bb9\uff1a<\/p>\n<pre><code class=\"language-plain\">HTTP\/1.1 404 Not Found\nX-Pi-hole: A black hole for Internet advertisements.\nContent-type: text\/html; charset=UTF-8\nContent-Length: 0\nDate: Mon, 22 Jul 2024 00:16:27 GMT\nServer: lighttpd\/1.4.35<\/code><\/pre>\n<p>\u76f4\u63a5\u626b\u63cf\u76ee\u5f55\uff1a<\/p>\n<pre><code class=\"language-plain\"># Dirsearch started Mon Jul 22 08:35:40 2024 as: \/usr\/lib\/python3\/dist-packages\/dirsearch\/dirsearch.py -u http:\/\/10.10.10.48\/ -x 400,403,404,500 -e php,js,html,txt,zip,tar.gz,asp,aspx,pcap -t 60 -w \/usr\/share\/wordlists\/wfuzz\/general\/megabeast.txt\n\n301     0B   http:\/\/10.10.10.48\/admin    -&gt; REDIRECTS TO: http:\/\/10.10.10.48\/admin\/\n200    13B   http:\/\/10.10.10.48\/versions<\/code><\/pre>\n<p>\u53d1\u73b0<code>\/versions<\/code>\u6587\u4ef6\uff0c\u5185\u5bb9\u4e3a\uff1a<\/p>\n<pre><code class=\"language-plain\">1721607651,,,<\/code><\/pre>\n<p>\u8bbf\u95ee<code>\/admin<\/code>\u76ee\u5f55\uff0c\u53d1\u73b0\u90e8\u7f72\u4e86\u5e7f\u544a\u62e6\u622a\u7cfb\u7edf<code>Pi-Hole<\/code>\uff0c\u7248\u672c\u4e3a<code>v3.1.4<\/code>\uff0c\u6709\u53ef\u80fd\u5b58\u5728\u6388\u6743\u547d\u4ee4\u6267\u884c\u6f0f\u6d1e\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1721609616977-3be30191-dcd4-4cb2-bb0e-1c61394cab40.png\" alt=\"\" \/><\/p>\n<p>\u5c1d\u8bd5\u626b\u63cf\u8be5\u76ee\u5f55\uff1a<\/p>\n<pre><code class=\"language-plain\"># Dirsearch started Mon Jul 22 08:48:16 2024 as: \/usr\/lib\/python3\/dist-packages\/dirsearch\/dirsearch.py -u http:\/\/10.10.10.48\/admin -x 400,403,404,500 -e php,js,html,txt,zip,tar.gz,asp,aspx,pcap -t 60\n\n301     0B   http:\/\/10.10.10.48\/admin\/.git    -&gt; REDIRECTS TO: http:\/\/10.10.10.48\/admin\/.git\/\n200    23B   http:\/\/10.10.10.48\/admin\/.git\/HEAD\n301     0B   http:\/\/10.10.10.48\/admin\/.git\/logs\/refs    -&gt; REDIRECTS TO: http:\/\/10.10.10.48\/admin\/.git\/logs\/refs\/\n301     0B   http:\/\/10.10.10.48\/admin\/.git\/logs\/refs\/remotes    -&gt; REDIRECTS TO: http:\/\/10.10.10.48\/admin\/.git\/logs\/refs\/remotes\/\n301     0B   http:\/\/10.10.10.48\/admin\/.git\/refs\/remotes    -&gt; REDIRECTS TO: http:\/\/10.10.10.48\/admin\/.git\/refs\/remotes\/\n301     0B   http:\/\/10.10.10.48\/admin\/.git\/refs\/tags    -&gt; REDIRECTS TO: http:\/\/10.10.10.48\/admin\/.git\/refs\/tags\/\n200   274B   http:\/\/10.10.10.48\/admin\/.git\/config\n301     0B   http:\/\/10.10.10.48\/admin\/.git\/refs\/remotes\/origin    -&gt; REDIRECTS TO: http:\/\/10.10.10.48\/admin\/.git\/refs\/remotes\/origin\/\n301     0B   http:\/\/10.10.10.48\/admin\/.git\/refs\/heads    -&gt; REDIRECTS TO: http:\/\/10.10.10.48\/admin\/.git\/refs\/heads\/\n200    11KB  http:\/\/10.10.10.48\/admin\/.git\/index\n200   240B   http:\/\/10.10.10.48\/admin\/.git\/info\/exclude\n200     1KB  http:\/\/10.10.10.48\/admin\/.github\/PULL_REQUEST_TEMPLATE.md\n200   182B   http:\/\/10.10.10.48\/admin\/.git\/logs\/refs\/remotes\/origin\/HEAD\n200   182B   http:\/\/10.10.10.48\/admin\/.git\/logs\/refs\/heads\/master\n200   182B   http:\/\/10.10.10.48\/admin\/.git\/logs\/HEAD\n200   153B   http:\/\/10.10.10.48\/admin\/.gitignore\/\n200   153B   http:\/\/10.10.10.48\/admin\/.gitignore\n200    73B   http:\/\/10.10.10.48\/admin\/.git\/description\n301     0B   http:\/\/10.10.10.48\/admin\/.git\/logs\/refs\/heads    -&gt; REDIRECTS TO: http:\/\/10.10.10.48\/admin\/.git\/logs\/refs\/heads\/\n200    41B   http:\/\/10.10.10.48\/admin\/.git\/refs\/heads\/master\n301     0B   http:\/\/10.10.10.48\/admin\/.git\/logs\/refs\/remotes\/origin    -&gt; REDIRECTS TO: http:\/\/10.10.10.48\/admin\/.git\/logs\/refs\/remotes\/origin\/\n200    32B   http:\/\/10.10.10.48\/admin\/.git\/refs\/remotes\/origin\/HEAD\n200   107B   http:\/\/10.10.10.48\/admin\/.git\/packed-refs\n200     1KB  http:\/\/10.10.10.48\/admin\/.github\/ISSUE_TEMPLATE.md\n200   648B   http:\/\/10.10.10.48\/admin\/.pullapprove.yml\n200   186B   http:\/\/10.10.10.48\/admin\/api.php\n200   846B   http:\/\/10.10.10.48\/admin\/CONTRIBUTING.md\n200    14KB  http:\/\/10.10.10.48\/admin\/debug.php\n301     0B   http:\/\/10.10.10.48\/admin\/img    -&gt; REDIRECTS TO: http:\/\/10.10.10.48\/admin\/img\/\n200    14KB  http:\/\/10.10.10.48\/admin\/LICENSE\n200     2KB  http:\/\/10.10.10.48\/admin\/README.md\n301     0B   http:\/\/10.10.10.48\/admin\/scripts    -&gt; REDIRECTS TO: http:\/\/10.10.10.48\/admin\/scripts\/\n200    14KB  http:\/\/10.10.10.48\/admin\/settings.php\n301     0B   http:\/\/10.10.10.48\/admin\/style    -&gt; REDIRECTS TO: http:\/\/10.10.10.48\/admin\/style\/<\/code><\/pre>\n<p>\u53d1\u73b0\u8be5\u76ee\u5f55\u5b58\u5728<code>Git<\/code>\u6e90\u7801\u6cc4\u9732\u95ee\u9898\uff0c\u4f7f\u7528<code>GitHack<\/code>\u5de5\u5177\u4e0b\u8f7d\u5176\u6e90\u4ee3\u7801\uff0c\u5931\u8d25\u3002<\/p>\n<h2>Web\u5e94\u7528\u7a0b\u5e8f\uff0832400\u7aef\u53e3\uff09<\/h2>\n<p>\u6253\u5f00\u4e3b\u9875\uff1a<code>http:\/\/10.10.10.48:32400\/<\/code><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1721610725299-0c33fc40-f964-4bcb-b4b7-c5aec9dc1954.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u90e8\u7f72\u4e86<code>Plex<\/code>\u7f51\u7edc\u5a92\u4f53\u7ba1\u7406\u7cfb\u7edf\uff0c\u4f46\u7248\u672c\u672a\u77e5\u3002<\/p>\n<p>\u5c1d\u8bd5\u6ce8\u518c\u7528\u6237\uff0c\u767b\u5f55\u4e4b\u540e\u8f6c\u5230\u8bbe\u7f6e\u754c\u9762\uff0c\u53d1\u73b0\u7248\u672c\u4e3a<code>v3.9.1<\/code>\uff0c\u6ca1\u6709\u5bf9\u5e94\u7684\u6f0f\u6d1e\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1721611109525-ae5c757b-879e-4c96-8c9e-765d739f8ef9.png\" alt=\"\" \/><\/p>\n<p>\u5c1d\u8bd5\u626b\u63cf\u76ee\u5f55\uff0c\u6ca1\u6709\u53d1\u73b0\u654f\u611f\u4fe1\u606f\u3002<\/p>\n<hr \/>\n<h1>\u6e17\u900f\u6d4b\u8bd5<\/h1>\n<h2>\u731c\u6d4bSSH\u7528\u6237\u540d\u5bc6\u7801<\/h2>\n<p>\u6839\u636e\u524d\u671f\u6536\u96c6\u5230\u7684\u4fe1\u606f\uff0c\u63a8\u65ad\u9776\u673a\u662f\u6811\u8393\u6d3e\u8bbe\u5907\uff0c\u56e0\u4e3a<code>Pi-Hole<\/code>\u53ea\u80fd\u5728\u6811\u8393\u6d3e\u4e0a\u8fd0\u884c\uff0c\u4e00\u822c\u8fd9\u79cd\u8bbe\u5907\u4f1a\u88ab\u4f5c\u4e3a\u5185\u7f51\u8f6f\u8def\u7531\u548c\u7f51\u5173\u4f7f\u7528\u3002<\/p>\n<p>\u5c1d\u8bd5\u4f7f\u7528\u6811\u8393\u6d3e\u9ed8\u8ba4\u7684\u767b\u5f55\u51ed\u636e\u767b\u5f55<code>SSH<\/code>\uff1a<\/p>\n<ul>\n<li>\u7528\u6237\u540d\uff1a<code>pi<\/code><\/li>\n<li>\u5bc6\u7801\uff1a<code>raspberry<\/code><\/li>\n<\/ul>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1721613873326-a86a7396-9ac3-4f3f-a901-c011df914963.png\" alt=\"\" \/><\/p>\n<p><strong>\u6210\u529f\uff01\uff01\uff01<\/strong><\/p>\n<hr \/>\n<h1>\u6743\u9650\u63d0\u5347<\/h1>\n<h2>Sudo\u63d0\u6743<\/h2>\n<p>\u767b\u5f55\u7cfb\u7edf\u4e4b\u540e\uff0c\u53d1\u73b0\u5f53\u524d\u7528\u6237<code>pi<\/code>\u53ef\u4ee5\u76f4\u63a5\u4ee5<code>root<\/code>\u8eab\u4efd\u514d\u5bc6\u8fd0\u884c\u6240\u6709\u547d\u4ee4\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1721614118764-a9ce3bf7-d536-458d-ab20-e3e770a7906c.png\" alt=\"\" \/><\/p>\n<p>\u76f4\u63a5\u5207\u6362\u7528\u6237\u5230<code>root<\/code>\uff1a<\/p>\n<pre><code class=\"language-shell\">sudo su -<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2024\/png\/42816956\/1721614176152-5bf37d00-9049-41be-9fb5-fef37e162690.png\" alt=\"\" \/><\/p>\n<p><strong>\u63d0\u6743\u6210\u529f\uff01\uff01\uff01\uff01<\/strong><\/p>\n<hr \/>\n<h1>Flag\u6587\u4ef6\u5c55\u793a<\/h1>\n<blockquote><p>\u6ce8\uff1a\u8be5Flag\u4f7f\u7528<code>strings \/dev\/sdb<\/code>\u627e\u5230\u3002\u767b\u5f55<code>root<\/code>\u540e\uff0c\u53d1\u73b0\u5bb6\u76ee\u5f55\u4e0b\u7684<code>Flag<\/code>\u63d0\u793a\u771f\u6b63\u7684<code>Flag<\/code>\u5728<code>USB<\/code>\u6302\u8f7d\u76ee\u5f55\u4e0b\uff0c\u7ecf\u8fc7\u5bfb\u627e\uff0c\u53d1\u73b0\u6709<code>\/media\/usbstick<\/code>\u76ee\u5f55\uff0c\u6302\u8f7d\u76d8\u4e3a<code>\/dev\/sdb<\/code>\uff0c\u4f7f\u7528<code>strings<\/code>\u547d\u4ee4\u5217\u51fa\u53ef\u6253\u5370\u7684\u5b57\u7b26\u4e32\u540e\u627e\u5230<code>Flag<\/code>\u3002<\/p><\/blockquote>\n<pre><code class=\"language-plain\">3d3e483143ff12ec505d026fa13e020b<\/code><\/pre>\n<hr \/>\n<h1>\u672c\u6b21\u9776\u673a\u6e17\u900f\u5230\u6b64\u7ed3\u675f<\/h1>\n<hr \/>\n","protected":false},"excerpt":{"rendered":"<p>\u76ee\u6807\u4fe1\u606f IP\u5730\u5740\uff1a10.10.10.48 \u4fe1\u606f\u6536\u96c6 ICMP\u68c0\u6d4b \u250c\u2500\u2500(root\u327fmisaka19008)-[\/home\/\u2026\/ &#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","emotion":"","emotion_color":"","title_style":"","license":"","footnotes":""},"categories":[3,14],"tags":[],"class_list":["post-126","post","type-post","status-publish","format-standard","hentry","category-htb_retired","category-linux_machines"],"_links":{"self":[{"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/posts\/126","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/comments?post=126"}],"version-history":[{"count":1,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/posts\/126\/revisions"}],"predecessor-version":[{"id":127,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/posts\/126\/revisions\/127"}],"wp:attachment":[{"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/media?parent=126"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/categories?post=126"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/tags?post=126"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}