192.168.10.12
端口扫描

web目录扫描
进一步扫描 WordPress 下的目录

发现敏感文件 secret. txt,

根据收集的用户名, 密码爆破 ssh




sarah:bohicon
USER. txt PWD

收集泄露信息,横向移动
jresig secret


sarah@VivifyTech:~/.gnupg/crls.d$ cat DIR.txt
v:1:
在用户目录里面发现了 TASK. txt 文件 下次应该直接全局找一下. txt 文件

sarah@VivifyTech:~/.private$ cat Tasks.txt
- Change the Design and architecture of the website
- Plan for an audit, it seems like our website is vulnerable
- Remind the team we need to schedule a party before going to holidays
- Give this cred to the new intern for some tasks assigned to him - gbodja:4Tch055ouy370N
利用 sudo git 提权


