{"id":1223,"date":"2019-09-07T22:59:54","date_gmt":"2019-09-07T14:59:54","guid":{"rendered":"http:\/\/van-yzt.com\/?p=1223"},"modified":"2019-09-07T22:59:54","modified_gmt":"2019-09-07T14:59:54","slug":"bandit-level-16-%e2%86%92-level-17","status":"publish","type":"post","link":"https:\/\/huzi-baozi.com\/?p=1223","title":{"rendered":"Bandit Level 16 \u2192 Level 17"},"content":{"rendered":"<p>The credentials for the next level can be retrieved by submitting the password of the current level to a port on localhost in the range 31000 to 32000. First find out which of these ports have a server listening on them. Then find out which of those speak SSL and which don\u2019t. There is only 1 server that will give the next credentials, the others will simply send back to you whatever you send to it.<\/p>\n<h2>\n\u89e3\u5bc6<\/h2>\n<pre><code class=\"language-shell\">bandit15@bandit:~$ nmap -p31000-32000 localhost\n\nStarting Nmap 7.40 ( https:\/\/nmap.org ) at 2019-09-07 16:57 CEST\nNmap scan report for localhost (127.0.0.1)\nHost is up (0.00019s latency).\nNot shown: 999 closed ports\nPORT      STATE SERVICE\n31518\/tcp open  unknown\n31790\/tcp open  unknown\n\nNmap done: 1 IP address (1 host up) scanned in 0.07 seconds\n\nbandit15@bandit:~$ openssl s_client -host localhost -port 31790\n\n....\n\n---\nBfMYroe26WYalil77FoDi9qh59eK5xNr\nWrong! Please enter the correct current password\nclosed\n\n<\/code><\/pre>\n<h2>\n\u77e5\u8bc6\u70b9<\/h2>\n<ol>\n<li>\n<code>nmap<\/code>\u547d\u4ee4\u662f\u5f3a\u5927\u7684\u7f51\u7edc\u626b\u63cf\u5de5\u5177\uff0c\u5728\u8fd9\u91cc\u4f7f\u7528\u53c2\u6570<code>-p<\/code>\u6765\u6307\u5b9a\u9700\u8981\u626b\u63cf\u7aef\u53e3\u7684\u533a\u95f4\u8303\u56f4\uff1b<\/li>\n<li>\n<code>openssl s_client<\/code>\u7528\u4e8e\u5efa\u7acbTLS\u94fe\u63a5\uff1b<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>The credentials for the next level can be retrieved by submitting the password of the current level to a port on localhost in the range 31000 to 32000. First find out which of these ports have a server listening on them. Then find out which of those speak SSL and which don\u2019t. There is only &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/huzi-baozi.com\/?p=1223\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Bandit Level 16 \u2192 Level 17&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-1223","post","type-post","status-publish","format-standard","hentry","category-bandit"],"_links":{"self":[{"href":"https:\/\/huzi-baozi.com\/index.php?rest_route=\/wp\/v2\/posts\/1223","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/huzi-baozi.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/huzi-baozi.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/huzi-baozi.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/huzi-baozi.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1223"}],"version-history":[{"count":1,"href":"https:\/\/huzi-baozi.com\/index.php?rest_route=\/wp\/v2\/posts\/1223\/revisions"}],"predecessor-version":[{"id":1224,"href":"https:\/\/huzi-baozi.com\/index.php?rest_route=\/wp\/v2\/posts\/1223\/revisions\/1224"}],"wp:attachment":[{"href":"https:\/\/huzi-baozi.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1223"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/huzi-baozi.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1223"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/huzi-baozi.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1223"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}