<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ubuntu &#8211; ChaBug安全</title>
	<atom:link href="/tags/ubuntu/feed" rel="self" type="application/rss+xml" />
	<link>/</link>
	<description>一个分享知识、结识伙伴、资源共享的博客</description>
	<lastBuildDate>Sat, 06 Jul 2019 17:05:54 +0000</lastBuildDate>
	<language>zh-CN</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=5.5.5</generator>
	<item>
		<title>Ubuntu Dirty Sock 本地权限提升 CVE-2019-7304</title>
		<link>/web/648.html</link>
		
		<dc:creator><![CDATA[Y4er]]></dc:creator>
		<pubDate>Sat, 06 Jul 2019 17:05:54 +0000</pubDate>
				<category><![CDATA[渗透测试]]></category>
		<category><![CDATA[cve]]></category>
		<category><![CDATA[ubuntu]]></category>
		<category><![CDATA[提权]]></category>
		<guid isPermaLink="false">/?p=648</guid>

					<description><![CDATA[在2019年1月，由于snapd API中的错误，多个版本的Ubuntu被发现本地权限提升漏洞。漏洞编号:CVE-2019-7304 漏洞原因 默认情况下，Ubuntu附带了sna...]]></description>
										<content:encoded><![CDATA[<p>在2019年1月，由于snapd API中的错误，多个版本的Ubuntu被发现本地<a class="tag_link" title="浏览关于“权限”的文章" href="/tags/%e6%9d%83%e9%99%90" target="_blank" rel="noopener noreferrer">权限</a><a class="tag_link" title="浏览关于“提升”的文章" href="/tags/%e6%8f%90%e5%8d%87" target="_blank" rel="noopener noreferrer">提升</a>漏洞。漏洞编号:CVE-2019-7304</p>
<h2 id="漏洞原因"><i class="iconfont icon-link"></i>漏洞原因</h2>
<p>默认情况下，Ubuntu附带了snapd，但是如果安装了这个软件包，任何发行版都应该可利用。运行以下命令，如果你<code>snapd</code>是2.37.1或更高，你是安全的。</p>
<div class="highlight">
<div class="chroma language-bash">
<div id="crayon-5d1fbcfbd557e978102573" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1fbcfbd557e978102573-1">1</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5d1fbcfbd557e978102573-2">2</div>
<div class="crayon-num" data-line="crayon-5d1fbcfbd557e978102573-3">3</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5d1fbcfbd557e978102573-4">4</div>
<div class="crayon-num" data-line="crayon-5d1fbcfbd557e978102573-5">5</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5d1fbcfbd557e978102573-6">6</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1fbcfbd557e978102573-1" class="crayon-line"><span class="crayon-sy">$</span> <span class="crayon-e">snap </span><span class="crayon-e">version</span></div>
<div id="crayon-5d1fbcfbd557e978102573-2" class="crayon-line crayon-striped-line"><span class="crayon-i">snap</span><span class="crayon-h">    </span><span class="crayon-cn">2.34.2</span></div>
<div id="crayon-5d1fbcfbd557e978102573-3" class="crayon-line"><span class="crayon-i">snapd</span><span class="crayon-h">   </span><span class="crayon-cn">2.34.2</span></div>
<div id="crayon-5d1fbcfbd557e978102573-4" class="crayon-line crayon-striped-line"><span class="crayon-i">series</span><span class="crayon-h">  </span><span class="crayon-cn">16</span></div>
<div id="crayon-5d1fbcfbd557e978102573-5" class="crayon-line"><span class="crayon-i"><span class="wpcom_tag_link"><a href="/tags/ubuntu" title="ubuntu" target="_blank">ubuntu</a></span></span><span class="crayon-h">  </span><span class="crayon-cn">16.04</span></div>
<div id="crayon-5d1fbcfbd557e978102573-6" class="crayon-line crayon-striped-line"><span class="crayon-i">kernel</span><span class="crayon-h">  </span><span class="crayon-cn">4.15.0</span><span class="crayon-o">&#8211;</span><span class="crayon-cn">29</span><span class="crayon-o">&#8211;</span><span class="crayon-v">generic</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<div class="post-image"><a class="fancybox" title="Ubuntu Dirty Sock 本地权限提升 CVE-2019-7304" href="https://ws3.sinaimg.cn/large/006xriynly1g08cexg0p2j30e007xgmd.jpg" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://ws3.sinaimg.cn/large/006xriynly1g08cexg0p2j30e007xgmd.jpg" alt="Ubuntu Dirty Sock 本地权限提升 CVE-2019-7304-ChaBug安全" /></a></div>
<h2 id="影响版本"><i class="iconfont icon-link"></i>影响版本</h2>
<ul>
<li>Ubuntu 18.10</li>
<li>Ubuntu 18.04 LTS</li>
<li>Ubuntu 16.04 LTS</li>
<li>Ubuntu 14.04 LTS</li>
</ul>
<h2 id="漏洞利用"><i class="iconfont icon-link"></i>漏洞利用</h2>
<p>poc链接：<a href="https://github.com/initstring/dirty_sock" target="_blank" rel="nofollow noopener noreferrer">https://github.com/initstring/dirty_sock</a></p>
<h3 id="方法一"><i class="iconfont icon-link"></i>方法一</h3>
<p>先在<a href="https://login.ubuntu.com/" target="_blank" rel="nofollow noopener noreferrer">Ubuntu SSO</a>创建账号，然后本地生成密钥：</p>
<div class="highlight">
<div class="chroma language-bash">
<div id="crayon-5d1fbcfbd5585536817907" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1fbcfbd5585536817907-1">1</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1fbcfbd5585536817907-1" class="crayon-line"><span class="crayon-v">ssh</span><span class="crayon-o">&#8211;</span><span class="crayon-v">keygen</span> <span class="crayon-o">&#8211;</span><span class="crayon-i">t</span> <span class="crayon-v">rsa</span> <span class="crayon-o">&#8211;</span><span class="crayon-i">C</span> <span class="crayon-s">&#8220;&lt;you email&gt;&#8221;</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<div class="post-image"><a class="fancybox" title="Ubuntu Dirty Sock 本地权限提升 CVE-2019-7304" href="https://ws3.sinaimg.cn/large/006xriynly1g08cgaulzej30hj0azaav.jpg" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://ws3.sinaimg.cn/large/006xriynly1g08cgaulzej30hj0azaav.jpg" alt="Ubuntu Dirty Sock 本地权限提升 CVE-2019-7304-ChaBug安全" /></a></div>
<p>然后把当前用户下<code>/.ssh/</code>目录下的<code>id_rsa.pub</code>（公钥）拷到你账户的<a href="https://login.ubuntu.com/ssh-keys" target="_blank" rel="nofollow noopener noreferrer">ssh-keys</a>中。</p>
<div class="post-image"><a class="fancybox" title="Ubuntu Dirty Sock 本地权限提升 CVE-2019-7304" href="https://ws3.sinaimg.cn/large/006xriynly1g08ch3uv9cj30k102xdgm.jpg" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://ws3.sinaimg.cn/large/006xriynly1g08ch3uv9cj30k102xdgm.jpg" alt="Ubuntu Dirty Sock 本地权限提升 CVE-2019-7304-ChaBug安全" /></a></div>
<p>执行第一个poc</p>
<div class="highlight">
<div class="chroma language-bash">
<div id="crayon-5d1fbcfbd5588860736777" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1fbcfbd5588860736777-1">1</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1fbcfbd5588860736777-1" class="crayon-line"><span class="crayon-e">python3 </span><span class="crayon-v">dirty_sockv1</span><span class="crayon-sy">.</span><span class="crayon-v">py</span> <span class="crayon-o">&#8211;</span><span class="crayon-i">u</span> <span class="crayon-s">&#8220;you@yourmail.com&#8221;</span> <span class="crayon-o">&#8211;</span><span class="crayon-i">k</span> <span class="crayon-s">&#8220;id_rsa的路径&#8221;</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<div class="post-image"><a class="fancybox" title="Ubuntu Dirty Sock 本地权限提升 CVE-2019-7304" href="https://ws3.sinaimg.cn/large/006xriynly1g08cn43nhwj30qv0iqmzy.jpg" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://ws3.sinaimg.cn/large/006xriynly1g08cn43nhwj30qv0iqmzy.jpg" alt="Ubuntu Dirty Sock 本地权限提升 CVE-2019-7304-ChaBug安全" /></a></div>
<p>出现错误，因为没有开启ssh服务。</p>
<div class="highlight">
<div class="chroma language-bash">
<div id="crayon-5d1fbcfbd558a167734691" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1fbcfbd558a167734691-1">1</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1fbcfbd558a167734691-1" class="crayon-line"><span class="crayon-e">sudo </span><span class="crayon-e">apt </span><span class="crayon-e">install </span><span class="crayon-v">openssh</span><span class="crayon-o">&#8211;</span><span class="crayon-v">server</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<p>重新执行下</p>
<div class="post-image"><a class="fancybox" title="Ubuntu Dirty Sock 本地权限提升 CVE-2019-7304" href="https://ws3.sinaimg.cn/large/006xriynly1g08cyu12fvj30te0kxq5s.jpg" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://ws3.sinaimg.cn/large/006xriynly1g08cyu12fvj30te0kxq5s.jpg" alt="Ubuntu Dirty Sock 本地权限提升 CVE-2019-7304-ChaBug安全" /></a></div>
<p>如果成功，<code>sudo -i</code>即可获取root权限。</p>
<h3 id="方法二"><i class="iconfont icon-link"></i>方法二</h3>
<p>直接执行poc</p>
<div class="highlight">
<div class="chroma language-bash">
<div id="crayon-5d1fbcfbd558b933200399" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1fbcfbd558b933200399-1">1</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1fbcfbd558b933200399-1" class="crayon-line"><span class="crayon-i">python3</span> <span class="crayon-sy">.</span><span class="crayon-o">/</span><span class="crayon-v">dirty_sockv2</span><span class="crayon-sy">.</span><span class="crayon-v">py</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<div class="post-image"><a class="fancybox" title="Ubuntu Dirty Sock 本地权限提升 CVE-2019-7304" href="https://ws3.sinaimg.cn/large/006xriynly1g08d8ew3hgj30hm0didgl.jpg" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://ws3.sinaimg.cn/large/006xriynly1g08d8ew3hgj30hm0didgl.jpg" alt="Ubuntu Dirty Sock 本地权限提升 CVE-2019-7304-ChaBug安全" /></a></div>
<p>如果成功，会创建一个账号密码都为<code>dirty_sock</code>的用户，su命令切换过去，然后通过sudo就可以切换为root了。</p>
<p>如果遇到了<code>No passwd entry for user 'dirty_sock'</code>的问题，则查看下图中的任务进度，等到doing任务执行完之后再进行尝试，如果仍不行，请使用方法一。</p>
<div class="post-image"><a class="fancybox" title="Ubuntu Dirty Sock 本地权限提升 CVE-2019-7304" href="https://ws3.sinaimg.cn/large/006xriynly1g08damzoqyj30tm0ikaeq.jpg" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://ws3.sinaimg.cn/large/006xriynly1g08damzoqyj30tm0ikaeq.jpg" alt="Ubuntu Dirty Sock 本地权限提升 CVE-2019-7304-ChaBug安全" /></a></div>
<h2 id="参考链接"><i class="iconfont icon-link"></i>参考链接</h2>
<p><a href="https://usn.ubuntu.com/3887-1/" target="_blank" rel="nofollow noopener noreferrer">https://usn.ubuntu.com/3887-1/</a></p>
<p><a href="https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SnapSocketParsing" target="_blank" rel="nofollow noopener noreferrer">https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SnapSocketParsing</a></p>
<p><a href="https://github.com/initstring/dirty_sock" target="_blank" rel="nofollow noopener noreferrer">https://github.com/initstring/dirty_sock</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Ubuntu配置java环境</title>
		<link>/code/412.html</link>
		
		<dc:creator><![CDATA[Y4er]]></dc:creator>
		<pubDate>Tue, 08 May 2018 16:18:42 +0000</pubDate>
				<category><![CDATA[编程学习]]></category>
		<category><![CDATA[ubuntu]]></category>
		<guid isPermaLink="false">/?p=352</guid>

					<description><![CDATA[装了ubunu各种环境都得自己动手来，然后Ubuntu的openjdk还是垃圾东西，简直不能用，很多都打不开，然后百度找了几篇文章，总结如下。 Ubuntu 16.04安装Java...]]></description>
										<content:encoded><![CDATA[<blockquote><p>装了ubunu各种环境都得自己动手来，然后Ubuntu的openjdk还是垃圾东西，简直不能用，很多都打不开，然后百度找了几篇文章，总结如下。</p></blockquote>
<h1>Ubuntu 16.04安装Java JDK</h1>
<p>Java JDK有两个版本，一个开源版本Openjdk，还有一个oracle官方版本jdk。下面记录在Ubuntu 16.04上安装Java JDK的步骤。</p>
<h3>安装openjdk</h3>
<p>更新软件包列表：</p>
<pre><code>$ sudo apt-get update</code></pre>
<p>安装openjdk-8-jdk：</p>
<pre><code>$ sudo apt-get install openjdk-8-jdk</code></pre>
<p>查看java版本：</p>
<pre><code>$ java -version</code></pre>
<p><img title="java Ubuntu 16.04" src="http://topspeedsnail.com/images/2016/4/Screen%20Shot%202016-04-03%20at%2018.47.24.png" alt="java Ubuntu 16.04" /></p>
<h3>安装oracle Java JDK</h3>
<p>首先，安装依赖包：</p>
<pre><code>$ sudo apt-get install python-software-properties</code></pre>
<p>添加仓库源：</p>
<pre><code>$ sudo add-apt-repository ppa:webupd8team/java</code></pre>
<p>更新软件包列表：</p>
<pre><code>$ sudo apt-get update</code></pre>
<p>安装java JDK：</p>
<pre><code>$ sudo apt-get install oracle-java8-installer</code></pre>
<p>安装过程中需要接受协议：</p>
<p><img title="java Ubuntu 16.04" src="http://topspeedsnail.com/images/2016/4/Screen%20Shot%202016-04-03%20at%2018.52.11.png" alt="java Ubuntu 16.04" /></p>
<p>查看java版本：</p>
<pre><code>$ java -version</code></pre>
<p><img title="java Ubuntu 16.04" src="http://topspeedsnail.com/images/2016/4/Screen%20Shot%202016-04-03%20at%2020.50.46.png" alt="java Ubuntu 16.04" /></p>
<hr />
<p>如果你同时安装了以上两个版本，你可以自由的在这两个版本之间切换。执行：</p>
<pre><code>$ sudo update-alternatives --config java</code></pre>
<p><img title="java Ubuntu 16.04" src="http://topspeedsnail.com/images/2016/4/Screen%20Shot%202016-04-03%20at%2020.54.50.png" alt="java Ubuntu 16.04" /></p>
<p>前面带星号的是当前正在使用的java版本，键入编号选择使用哪个版本。</p>
<p>编辑/etc/profile，在文件尾添加java环境变量：</p>
<pre><code>$ sudo vim /etc/profile
＃ 如果使用oracle java
export JAVA_HOME="/usr/lib/jvm/java-8-oracle/jre/bin"
# 如果使用openjdk
export JAVA_HOME="/usr/lib/jvm/java-8-openjdk-amd64/jre/bin"</code></pre>
<p>OK，在Ubuntu 16.04上安装java完成。</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>入坑ubuntu18.04之各种bug解决方案</title>
		<link>/tools/409.html</link>
		
		<dc:creator><![CDATA[Y4er]]></dc:creator>
		<pubDate>Sat, 05 May 2018 11:37:00 +0000</pubDate>
				<category><![CDATA[工具分享]]></category>
		<category><![CDATA[ubuntu]]></category>
		<category><![CDATA[破解]]></category>
		<category><![CDATA[笔记]]></category>
		<guid isPermaLink="false">/?p=349</guid>

					<description><![CDATA[ubuntu贼好用@(捂嘴笑) 安装 下载桌面版镜像 点我ubuntu 18.04直连下载使用U盘操作系统安装工具- Universal USB Installer最新版将iso镜...]]></description>
										<content:encoded><![CDATA[<blockquote><p><span class="wpcom_tag_link"><a href="/tags/ubuntu" title="ubuntu" target="_blank">ubuntu</a></span>贼好用@(捂嘴笑)</p></blockquote>
<h3>安装</h3>
<p>下载桌面版镜像 <a href="https://mirrors.tuna.tsinghua.edu.cn/ubuntu-releases/18.04/ubuntu-18.04-desktop-amd64.iso">点我ubuntu 18.04直连下载</a><br />使用<a href="https://pan.baidu.com/s/1cfX3jGWxUgEH7KcfNDOadw">U盘操作系统安装工具- Universal USB Installer最新版</a>将iso镜像写入到u盘里，下一步下一步就行了。</p>
<p>开机进入u盘，如果你有两张显卡（集成显卡+N卡），可能会卡在启动logo，这需要在开机时<code>install ubuntu</code>选项按下<code>e</code>键，在<code>quiet splash</code>后面加上<code> nomodeset</code>注意有一个空格，然后进入就可以安装了。</p>
<h3>优化</h3>
<hr />
<h4>装显卡驱动</h4>
<p>不装驱动的话会出现各种bug，这个必须装。<br />1.禁用nouveau驱动 <br />使用下面命令行打开文件</p>
<pre><code>sudo nautilus</code></pre>
<p>找到<code>/etc/modprobe.d/blacklist.conf</code>这个路径下的blacklist.conf文件 <br />用gedit打开blacklist.conf并在在文件末尾添加如下几行：</p>
<pre><code>blacklist vga16fb
blacklist nouveau
blacklist rivafb
blacklist rivatv
blacklist nvidiafb</code></pre>
<p>保存</p>
<p>2.更新一下内核</p>
<pre><code>sudo update-initramfs -u</code></pre>
<p>3.重启系统 <br />修改后需要重启系统确认nouveau是否已经被屏蔽掉，使用lsmod命令查看：</p>
<pre><code>lsmod | grep nouveau</code></pre>
<p>4.安装NVIDIA驱动 </p>
<p>使用如下命令添加Graphic Drivers PPA</p>
<pre><code>sudo add-apt-repository ppa:graphics-drivers/ppa
sudo apt-get update</code></pre>
<p>寻找合适的驱动版本</p>
<pre><code>ubuntu-drivers devices</code></pre>
<p>找到有recommended（推荐）就是要下载的驱动版本,记下版本数字</p>
<p>安装NVIDIA driver</p>
<pre><code>sudo apt-get install nvidia-384</code></pre>
<p>安装完成后重启</p>
<pre><code>sudo reboot</code></pre>
<p>重启系统后，执行下面的命令查看驱动的安装状态显示安装成功</p>
<pre><code>sudo nvidia-smi</code></pre>
<p>到这里安装就算完成了，你可以进入<code>/usr/share/applications/</code>目录下找到软件图标，把它复制粘贴到桌面就行了</p>
<h3>安装TIM</h3>
<p>使用corssover安装，直接在官网下载安装包，缺什么依赖装什么就行了。<br />因为这个软件是付费的，我在这分享一个<span class="wpcom_tag_link"><a href="/tags/%e7%a0%b4%e8%a7%a3" title="破解" target="_blank">破解</a></span>补丁<br />链接: <a href="https://pan.baidu.com/s/1Z-y_TbeChzBsh9WIwLqGyQ">https://pan.baidu.com/s/1Z-y_TbeChzBsh9WIwLqGyQ</a> 密码: a852</p>
<pre><code>sudo mv /opt/cxoffice/lib/wine/winewrapper.exe.so /opt/cxoffice/lib/wine/winewrapper.exe.so.bak
sudo cp winewrapper.exe.so /opt/cxoffice/lib/wine/</code></pre>
<p>安装好tim可能会乱码，找一个中文的ttf字体然后扔到<code>/opt/cxoffice/share/wine/fonts</code>目录就行了。<br />如果无法输入密码，按win+空格切换为原生的输入法再输入就ok。</p>
<h3>已知bug</h3>
<ol>
<li>TIM没声音，无法记住密码</li>
<li>主题有时候重启会乱</li>
<li><span class="wpcom_tag_link"><a href="/tags/%e7%ac%94%e8%ae%b0" title="笔记" target="_blank">笔记</a></span>本费电贼快#(无奈)</li>
</ol>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>metasploit 5 docker 镜像</title>
		<link>/tools/400.html</link>
		
		<dc:creator><![CDATA[Y4er]]></dc:creator>
		<pubDate>Wed, 18 Apr 2018 12:43:00 +0000</pubDate>
				<category><![CDATA[工具分享]]></category>
		<category><![CDATA[docker]]></category>
		<category><![CDATA[ubuntu]]></category>
		<category><![CDATA[镜像]]></category>
		<guid isPermaLink="false">/?p=329</guid>

					<description><![CDATA[基于 ubuntu x86 dockerhub 拉取 docker pull x1r0z/msf5 启动 msf 的时候如果爆这些错误 就重启数据库 FATAL: the data...]]></description>
										<content:encoded><![CDATA[<p>基于 <span class="wpcom_tag_link"><a href="/tags/ubuntu" title="ubuntu" target="_blank">ubuntu</a></span> x86</p>
<p><a href="https://hub.docker.com/r/x1r0z/msf5/">dockerhub</a></p>
<p>拉取</p>
<pre><code>docker pull x1r0z/msf5</code></pre>
<p>启动 msf 的时候如果爆这些错误 就重启数据库</p>
<pre><code>FATAL: the database system is starting up
FATAL: the database system is shutting down</code></pre>
<p>重启</p>
<pre><code>service postgresql stop
service postgresql start</code></pre>
<p>更新的话用 <code>git pull</code></p>
<p><img src="http://exp10it-1252109039.cossh.myqcloud.com/2018/04/16/1523879100.jpg" alt="" title=""></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Ubuntu提权exp</title>
		<link>/tools/378.html</link>
		
		<dc:creator><![CDATA[Y4er]]></dc:creator>
		<pubDate>Fri, 16 Mar 2018 21:51:43 +0000</pubDate>
				<category><![CDATA[工具分享]]></category>
		<category><![CDATA[exp]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[ubuntu]]></category>
		<category><![CDATA[内核]]></category>
		<category><![CDATA[提权]]></category>
		<category><![CDATA[漏洞]]></category>
		<guid isPermaLink="false">/?p=286</guid>

					<description><![CDATA[V@1n3R大咖复现的 链接: https://pan.baidu.com/s/1EseuV0RRtS7MYIDK03uhYw 密码: hfxv]]></description>
										<content:encoded><![CDATA[<p>V@1n3R大咖复现的</p>
<p><img src="/wp-content/uploads/2018/03/578379254.jpg" alt="1.jpg" title="1.jpg"><br />链接: <a href="https://pan.baidu.com/s/1EseuV0RRtS7MYIDK03uhYw">https://pan.baidu.com/s/1EseuV0RRtS7MYIDK03uhYw</a> 密码: hfxv</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
