<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/" version="2.0"><channel><title>Ha-zero</title><link>https://www.ha0safe.com</link><atom:link href="https://www.ha0safe.com/rss.xml" rel="self" type="application/rss+xml"/><description>123</description><generator>Halo v2.25.4</generator><language>zh-cn</language><lastBuildDate>Wed, 16 Sep 2026 23:17:22 GMT</lastBuildDate><item><title><![CDATA[DC-1靶场总结]]></title><link>https://www.ha0safe.com/archives/dc-1ba-chang-zong-jie</link><description><![CDATA[<img src="https://www.ha0safe.com/plugins/feed/assets/telemetry.gif?title=DC-1%E9%9D%B6%E5%9C%BA%E6%80%BB%E7%BB%93&amp;url=/archives/dc-1ba-chang-zong-jie" width="1" height="1" alt="" style="opacity:0;">DC‑1 靶场渗透首先通过 nmap 扫描网段确定靶机 IP 并探测开放端口与服务版本，接着使用 msfconsole 搜索并调用 Drupal 漏洞模块，设置靶机 IP 参数执行攻击获取 meterpreter 会话，再利用 python 生成交互式 pty shell，依次读取 /var/www 下的 flag1、Drupal 配置文件 sites/default/settings.php 中的 flag2，借助获取的数据库账号登录 MySQL，使用脚本生成密码哈希修改网站 admin 用户密码，登录网页后台拿到 flag3，读取 /home/flag4 下的 flag4 后，通过 find 命令枚举 SUID 权限程序，利用 find 的 SUID 特性完成提权得到 root 权限，最终读取 /root 目录下的最终 flag 完成靶机，过程中掌握 nmap 扫描参数、msf 使用流程、SUID 提权原理以及输出重定向、Drupal 关键路径等知识点。]]></description><guid isPermaLink="false">/archives/dc-1ba-chang-zong-jie</guid><dc:creator>Ha-zero</dc:creator><enclosure url="https://www.ha0safe.com/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2F%25E3%2580%2590%25E5%2593%25B2%25E9%25A3%258E%25E5%25A3%2581%25E7%25BA%25B8%25E3%2580%2591%25E4%25BA%2591%25E6%259C%25B5-%25E5%2586%259C%25E5%259C%25BA-%25E5%258D%25A1%25E9%2580%259A.jpg&amp;size=m" type="image/jpeg" length="93594"/><category>网络安全</category><pubDate>Tue, 15 Sep 2026 02:56:44 GMT</pubDate></item><item><title><![CDATA[KB::CTF —— Misc]]></title><link>https://www.ha0safe.com/archives/kb-ctf------misc</link><description><![CDATA[<img src="https://www.ha0safe.com/plugins/feed/assets/telemetry.gif?title=KB%3A%3ACTF%20%E2%80%94%E2%80%94%20Misc&amp;url=/archives/kb-ctf------misc" width="1" height="1" alt="" style="opacity:0;">靶场:http://123.57.12.5:18081/ 注意：产生的文件和脚本均放在当前目录下的img文件夹里 1、安全杂项-1-base-png]]></description><guid isPermaLink="false">/archives/kb-ctf------misc</guid><dc:creator>Ha-zero</dc:creator><enclosure url="https://www.ha0safe.com/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2F%25E3%2580%2590%25E5%2593%25B2%25E9%25A3%258E%25E5%25A3%2581%25E7%25BA%25B8%25E3%2580%2591%25E5%2580%2592%25E5%25BD%25B1-%25E5%25A4%25A9%25E7%25A9%25BA-%25E5%25B1%25B1%25E8%2584%2589.jpg&amp;size=m" type="image/jpeg" length="43852"/><category>网络安全</category><pubDate>Fri, 21 Aug 2026 12:18:00 GMT</pubDate></item></channel></rss>