data:image/s3,"s3://crabby-images/4bc91/4bc916e8411008baf7f44c4ae8157ef5e3b864f2" alt=""
一、web目录存在木马,请找到木马的密码提交
到web目录进行搜索
find ./ type f -name "*.php" | xargs grep "eval("
发现有三个可疑文件
data:image/s3,"s3://crabby-images/65560/6556002c4587be016a702db841e464f251cc2e29" alt=""
1.php看到密码 1
data:image/s3,"s3://crabby-images/0dddd/0dddd9e80f47ecd5998474958d29fcc8794303fe" alt=""
flag{1}
二、服务器疑似存在不死马,请找到不死马的密码提交
data:image/s3,"s3://crabby-images/13908/1390872b758726503006aba8360bc8e5bb0a7137" alt=""
被md5加密的木马密码
data:image/s3,"s3://crabby-images/bc505/bc50524c207c6fec902d5ef8e5331aa3684e4fdb" alt=""
flag{hello}
三、不死马是通过哪个文件生成的,请提交文件名
能看出是index.php生成的shell.php
data:image/s3,"s3://crabby-images/ab8ba/ab8ba306d33380017606a956e4fcccfb9913c23c" alt=""
flag{index.php}
四、黑客留下了木马文件,请找出黑客的服务器ip提交
木马一般后缀都为elf
find ./ type f -name "*.elf"
data:image/s3,"s3://crabby-images/7f15f/7f15ff583aeef7eaee6fc7797203a2bdfc2f4af6" alt=""
赋权执行
data:image/s3,"s3://crabby-images/e8632/e8632d69d8a89c0ba948d931c417bfb13aafcda1" alt=""
netstat -atnlp
查看黑客服务器地址和端口
data:image/s3,"s3://crabby-images/407e0/407e02fec336782eaba7b8e367f835617c9e93b4" alt=""
flag{10.11.55.21}
五、黑客留下了木马文件,请找出黑客服务器开启的监端口提交
data:image/s3,"s3://crabby-images/376bd/376bde838a806dcb29d03b34e4930baaa60ffde2" alt=""
flag{3333}