CXCX's Singularity
  • Home
  • Archives
  • Categories
  • Tags
  • About
  • Links
HTB-Artificial

HTB-Artificial

Here's something encrypted, password is required to continue reading.
2025-06-25
靶机
#渗透
HTB-TombWatcher

HTB-TombWatcher

Here's something encrypted, password is required to continue reading.
2025-06-25
域
#渗透 #域
HTB-Certificate

HTB-Certificate

Here's something encrypted, password is required to continue reading.
2025-06-25
域
#渗透 #域
HTP-TheFrizz

HTP-TheFrizz

2025-06-19
域
#渗透 #域
HTP-Fluffy

HTP-Fluffy

Here's something encrypted, password is required to continue reading.
2025-06-17
域
#渗透 #域
HTB-Puppy

HTB-Puppy

Here's something encrypted, password is required to continue reading.
2025-06-16
域
#渗透 #域
HTB-Planning

HTB-Planning

此为一个简单的Linux靶机,考察点在于DNS子域名枚举,信息收集CMS Nday,端口转发等。 As is common in real life pentests, you will start the Planning box with credentials for the following account: admin / 0D5oT70Fq13EvB5r 端口探测12
2025-06-06
靶机
#渗透
Shadow Credentials 初探

Shadow Credentials 初探

Here's something encrypted, password is required to continue reading.
2025-06-03
域
#渗透 #域
AS_REP Roasting初探

AS_REP Roasting初探

前置知识此为我第一次接触域渗透,在此之前也通过HTB的俩个靶机进行了了解。我觉得挺有意思的,关于本次AS_REP Roasting 的攻击原理也非常简单。 先决条件要想利用 AS-REP Roasting ,首先需要 Kerberos 禁用了 预身份验证 。 并且我们已经获取到了域内可与KDC通信的一台主机或用户 原理由于Kerberos默认开启 预身份验证,当客户端请求密钥分发中心(KDC) 颁
2025-06-01
域
#渗透 #域
LITCTF 2025

LITCTF 2025

easy_file 弱口令进入 文件上传,这里过滤了ph字符,但是在主页面中发现传参 file能够查看头像。我们尝试上传一个jpg 过滤了<?php 成功上传,尝试包含。 nest_js 还是弱口令 星愿信箱是ssti,过滤了 {{}} {%print(lipsum.__globals__.__builtins__['__im
2025-05-30
比赛
#CTF
123

Search

Hexo Fluid