owefsad 的博客


  • Home

  • Tags

  • Categories

  • Archives

Spring Boot Actuator之jolokia利用

Posted on 2020-10-11 | In 安全研究
Words count in article: 139 | Reading time ≈ 1
The article has been encrypted, please enter your password to view.
Read more »

IAST交互式安全测试之核心流程

Posted on 2020-10-10 | In DevSecOps
Words count in article: 411 | Reading time ≈ 1

IAST是一种灰盒漏洞检测工具,它结合了SAST和DAST,利用动态污点跟踪的方法梳理出污点的数据流图,然后判断是否存在漏洞。更多细节请关注【灵芝IAST-社区版】(https://huoxianclub.github.io/LingZhi/)

Read more »

Linux提权之PATH环境变量(译文)

Posted on 2020-06-16 | In 安全研究
Words count in article: 360 | Reading time ≈ 1

译文声明:

本文为翻译文章,原文地址:http://www.hackingarticles.in/linux-privilege-escalation-using-path-variable/

Read more »

HTB-Windows-Resolute

Posted on 2020-06-07 | In CTF
Words count in article: 1.5k | Reading time ≈ 8

infocard

知识点 :
信息收集和dnsadmins用户组提权

Read more »

windows privilege escalate: DnsAdmins Group

Posted on 2020-06-07 | In 安全研究
Words count in article: 1.2k | Reading time ≈ 7

简介

通过DnsAdmins用户组可写入恶意dll,重启dns服务器即可执行恶意dll。

Read more »

HTB Windows Nest

Posted on 2020-02-23 | In CTF
Words count in article: 2.7k | Reading time ≈ 14

infocard
Nest是一台在靶机中找线索,根据线索找下一步线索的机器,像极了密室逃脱,不需要CVE即可完成。
机器通过smb匿名共享访问获取初始用户,通过初始用户获取VB项目和user的账号密码,解密之后 拿到明文,通过隐写术获得”HQK Reporting Service V1.2“服务的debug权限,根据HqkLdap.exe了解到下一步的方向,找到Administrator用户的密钥,利用HqkLdap.exe中的解密算法获得Administrator的用户密码,拿到root.txt。

机器中比较有趣的点在于使用NTFS Stream进行隐写。

Read more »

HTB Linux Postman

Posted on 2020-01-20 | In CTF
Words count in article: 2k | Reading time ≈ 11

简介
通过redis未授权访问获得初始访问权限,通过备份文件可直接获得root权限或先获取Matt权限再获取root权限

靶机状态:rooted

Read more »

HTB Linux Traverxec

Posted on 2020-01-20 | In CTF
Words count in article: 2.9k | Reading time ≈ 15

简介
Nostromo中间件拿到初始访问权限,理解账号Nostromo配置文件的含义得到david shell,suid提权。靶机的难点在于理解并利用Nostromo配置文件,如果之前不了解Nostromo中间件,这块可能会成为最耗时的地方,另外,英文真的很重要,要学习了。

Read more »

HTB Linux OpenAdmin

Posted on 2020-01-11 | In CTF
Words count in article: 2.4k | Reading time ≈ 12

简介
1.端口扫描
2.WEB目录、URI枚举
3.Linux信息收集
4.Crack id_rsa
5.sudoers misconfig

靶机状态:rooted.

Read more »

htb-windows-Forest

Posted on 2019-12-12 | In CTF
Words count in article: 1.3k | Reading time ≈ 7

简介

Read more »

1234…10

owefsad

91 posts
6 categories
175 tags
GitHub E-Mail
© 2023 owefsad | Site words total count: 118.6k
Powered by Hexo
|
Theme — NexT.Mist v5.1.4
0%