Tryharder
备注
[Linux VM] [Tested on VirtualBox] created by || Sublarge
⏲️ Release Date // 2025-04-09
✔️ MD5 // a95f664b02775d44cf4a1f8bbbbad1ce
☠ Root // 3
💀 User // 6
📝 Notes // Hello Hacker! Try Harder!
靶机启动
靶机 IP
192.168.56.129
信息搜集
┌──(randark ㉿ kali)-[~]
└─$ sudo nmap --min-rate=2000 -A -p- 192.168.56.129
Nmap scan report for bogon (192.168.56.129)
Host is up (0.0013s latency).
Not shown: 65533 closed tcp ports (reset)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 7.9p1 Debian 10+deb10u2 (protocol 2.0)
| ssh-hostkey:
| 2048 93:a4:92:55:72:2b:9b:4a:52:66:5c:af:a9:83:3c:fd (RSA)
| 256 1e:a7:44:0b:2c:1b:0d:77:83:df:1d:9f:0e:30:08:4d (ECDSA)
|_ 256 d0:fa:9d:76:77:42:6f:91:d3:bd:b5:44:72:a7:c9:71 (ED25519)
80/tcp open http Apache httpd 2.4.59 ((Debian))
|_http-title: \xE8\xA5\xBF\xE6\xBA\xAA\xE6\xB9\x96\xE7\xA7\x91\xE6\x8A\x80 - \xE4\xBC\x81\xE4\xB8\x9A\xE9\x97\xA8\xE6\x88\xB7\xE7\xBD\x91\xE7\xAB\x99
|_http-server-header: Apache/2.4.59 (Debian)
MAC Address: 08:00:27:E6:39:25 (PCS Systemtechnik/Oracle VirtualBox virtual NIC)
Device type: general purpose|router
Running: Linux 4.X|5.X, MikroTik RouterOS 7.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3
OS details: Linux 4.15 - 5.19, OpenWrt 21.02 (Linux 5.4), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3)
Network Distance: 1 hop
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Web Service
尝试直接访问

在页面源码中,发现
/* 调试信息:API 路径 /NzQyMjE= */
访问 http://192.168.56.129/74221/ 看到

尝试目录爆破
┌──(randark ㉿ kali)-[~]
└─$ dirsearch -u http://192.168.56.129/74221/
Target: http://192.168.56.129/
[15:07:33] Starting: 74221/
[15:07:35] 403 - 279B - /74221/.ht_wsr.txt
[15:07:35] 403 - 279B - /74221/.htaccess.bak1
[15:07:35] 403 - 279B - /74221/.htaccess.orig
[15:07:35] 403 - 279B - /74221/.htaccess.sample
[15:07:35] 403 - 279B - /74221/.htaccess.save
[15:07:35] 403 - 279B - /74221/.htaccess_extra
[15:07:35] 403 - 279B - /74221/.htaccess_orig
[15:07:35] 403 - 279B - /74221/.htaccess_sc
[15:07:35] 403 - 279B - /74221/.htaccessBAK
[15:07:35] 403 - 279B - /74221/.htaccessOLD
[15:07:35] 403 - 279B - /74221/.htaccessOLD2
[15:07:35] 403 - 279B - /74221/.htm
[15:07:35] 403 - 279B - /74221/.html
[15:07:35] 403 - 279B - /74221/.htpasswd_test
[15:07:35] 403 - 279B - /74221/.htpasswds
[15:07:35] 403 - 279B - /74221/.httr-oauth
[15:07:36] 403 - 279B - /74221/.php
[15:08:01] 302 - 0B - /74221/dashboard.php -> index.php
[15:08:26] 200 - 456B - /74221/uploads/
[15:08:26] 301 - 324B - /74221/uploads -> http://192.168.56.129/74221/uploads/
尝试使用 test:123456 登录成功

分析 Cookie 部分,采用了 JWT

