PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.4 (Ubuntu Linux; protocol 2.0) 80/tcp open http Apache httpd 2.4.52 3000/tcp open http Node.js Express framework
SQLite format 3 otableticketstickets CREATETABLE tickets ( id INTEGERPRIMARY KEY AUTOINCREMENT, name TEXT, topic TEXT, description TEXT, status TEXT )P
Ytablesqlite_sequencesqlite_sequence
CREATETABLE sqlite_sequence(name,seq)
tableusersusers
CREATETABLE users ( id INTEGERPRIMARY KEY AUTOINCREMENT, username TEXT UNIQUE, password TEXT ))
Joe WilliamsLocal setup?I use this site lot of the time. Is it possible toset this up locally? Like instead of coming to this site, can I download this andset it up in my own computer? A feature like that would be nice.open Tom HanksNeed networking modulesI think it would be better if you can implement a way to handle network-based stuff. Would help me out a lot. Thanks!open
然后搜索了相关的sqllite数据库文件,大致看得出有个tickets,sqlite_sequence,users表,其中users表中有账号密码, 下面就是joshua$2a$12$SOn8Pf6z8fO/nVsNbAAequ/P6vLRJJl7gCUEiYBU2iLHn4G/p/Zw2直接登录是不可能的了,明显不是明文 然后用john the ripper破解密文,得到密码成功登录joshua,再user目录中得到了第一个flag
[sudo] password for joshua: Matching Defaults entries for joshua on codify: env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin, use_pty
User joshua may run the following commands on codify: (root) /opt/scripts/mysql-backup.sh