因为在模糊匹配的地方卡住了,然后看了其他的人的HTB攻略所以当作参考信息写在下方: [HackTheBox Write-Up: Codify] - [简单] (maddevs.io) hackthebox-Codify - jtmqd - 博客园 (cnblogs.com) hackthebox-Codify - jtmqd - 博客园 (cnblogs.com) 【渗透测试】Codify - HackTheBox,Node.js沙盒_codify....
echo "10.10.11.239 codify.htb" | sudo tee -a /etc/hosts 继续访问,发现访问成功https://gist.github.com/leesh3288/381b230b04936dd4d74aaf90cc8bb244 点击about us,我们能知道这是用vm2来提供安全的沙盒环境 Vm2:Vm2是一个库,为执行 JavaScript 代码提供安全的沙盒环境,主要用于 Node.js 等服务器...
14. Broker Delivery Codify 15. Analytics Soccer Timelapse 16. Devvortex Return Irked 17. Perfection Headless Wifinetic 18. OpenAdmin CASES INVESTIGATED NOTES: NO TIMELINE ACTIVITIES TABLE CREATION FOR EVERY CHALLS. Sherlocks No.SOCDFIRMalware AnalysisThreat IntelligenceCampaign 1. Meerkat Bumblebe...
22/tcp open ssh 80/tcp open http 3000/tcp filtered ppp Nmapdone: 1 IP address (1 host up) scannedin3.56 seconds# 目录枚举└─# gobuster dir --url http://drive.htb/ --wordlist /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt=== Gobuster v3.6 by OJ Reeves (@...
Repository files navigation README htb My Hack-The-Box solutions and writeups.About Hack-The-Box stuff Resources Readme Activity Stars 0 stars Watchers 1 watching Forks 0 forks Report repository Releases No releases published Packages No packages published Languages Python 95.4% Java 2....
HackTheBox - Codify [easy] 打这台靶机时及其古怪。总是莫名其妙断开连接,请求没有响应。提交时表示flag错误等问题 访问80端口的web服务,发现使用nodjs和vm2库。搜索到vm2漏洞:Sandbox Bypass in vm2 | CVE-2023-32314 | Snyk可远程执行代码 查看当前用户,可登录...
14. Broker Delivery Codify 15. Analytics Soccer Timelapse 16. Devvortex Return Irked 17. Perfection Headless Wifinetic 18. OpenAdmin TraceBack CASES INVESTIGATED NOTES: NO TIMELINE ACTIVITIES TABLE CREATION FOR EVERY CHALLS. Sherlocks No.SOCDFIRMalware AnalysisThreat IntelligenceCampaign 1. Meerka...