> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/zh/writeups-ctf/hackthebox/linux-medium.md).

# HTB Linux 中等难度

具有更深层利用链、横向移动和权限提升流程的 Linux 中等难度 HackTheBox 靶机。

<table data-view="cards" data-full-width="false" data-search="false"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><h3><i class="fa-linux" style="color:$primary;">:linux:</i></h3></td><td><h4>MonitorsThree HackTheBox Linux 中等难度</h4></td><td>MonitorsThree HackTheBox 中等难度 Linux 靶机复盘，涵盖子域枚举、SQLI - 手动基于时间的盲注（Python 脚本）、哈希破解、Cacti 利用（CVE-2024-25642）- 恶意包导入，并包含实用的枚举、利用、立足点和权限提升笔记。</td><td><a href="/pages/e15036bd6c6bf38f695a1e0f7d34be20e4416497">/pages/e15036bd6c6bf38f695a1e0f7d34be20e4416497</a></td></tr><tr><td><h3><i class="fa-linux" style="color:$primary;">:linux:</i></h3></td><td><h4>Devzat HackTheBox Linux 中等难度</h4></td><td>Devzat HackTheBox 中等难度 Linux 靶机复盘，涵盖目录 Fuzzing、Web 注入（RCE）、滥用 InfluxDB（CVE-2019-20933）、滥用 Devzat 聊天 /file 命令（权限提升），并包含实用的枚举、利用、立足点和权限提升笔记。</td><td><a href="/pages/54041789b5a67c4e6ff703c601767daf289001fd">/pages/54041789b5a67c4e6ff703c601767daf289001fd</a></td></tr><tr><td><h3><i class="fa-linux" style="color:$primary;">:linux:</i></h3></td><td><h4>Bolt HackTheBox Linux 中等难度</h4></td><td>Bolt HackTheBox 中等难度 Linux 靶机复盘，涵盖信息泄露、子域枚举、SSTI（服务端模板注入）、滥用 PassBolt，并包含实用的枚举、利用、立足点和权限提升笔记。</td><td><a href="/pages/0628c2e307eddab4388653beb3852b560e657e17">/pages/0628c2e307eddab4388653beb3852b560e657e17</a></td></tr><tr><td><h3><i class="fa-linux" style="color:$primary;">:linux:</i></h3></td><td><h4>Solidstate HackTheBox Linux 中等难度</h4></td><td>Solidstate HackTheBox 中等难度 Linux 靶机复盘，涵盖滥用 James 远程管理工具、更改用户的邮箱密码、信息泄露、逃逸受限 Bash（rbash），并包含实用的枚举、利用、立足点和权限提升笔记。</td><td><a href="/pages/85ad07b5c063af40c84e75b155671a10e2f3f862">/pages/85ad07b5c063af40c84e75b155671a10e2f3f862</a></td></tr><tr><td><h3><i class="fa-linux" style="color:$primary;">:linux:</i></h3></td><td><h4>Hawk HackTheBox Linux 中等难度</h4></td><td>Hawk HackTheBox 中等难度 Linux 靶机复盘，涵盖 OpenSSL 密码套件暴力破解与解密、Drupal 枚举/利用、H2 数据库利用，并包含实用的枚举、利用、立足点和权限提升笔记。</td><td><a href="/pages/5080b74e88ca14f44ffb1996a635035096d13539">/pages/5080b74e88ca14f44ffb1996a635035096d13539</a></td></tr><tr><td><h3><i class="fa-linux" style="color:$primary;">:linux:</i></h3></td><td><h4>Node HackTheBox Linux 中等难度</h4></td><td>Node HackTheBox 中等难度 Linux 靶机复盘，涵盖信息泄露、API 枚举、哈希破解、ZIP 文件破解，并包含实用的枚举、利用、立足点和权限提升笔记。</td><td><a href="/pages/6fe1c14723e3db931dc7c1f29811ae0b6e92351d">/pages/6fe1c14723e3db931dc7c1f29811ae0b6e92351d</a></td></tr><tr><td><h3><i class="fa-linux" style="color:$primary;">:linux:</i></h3></td><td><h4>Union HackTheBox Linux 中等难度</h4></td><td>Union HackTheBox 中等难度 Linux 靶机复盘，涵盖 SQLI（SQL 注入）- UNION 注入、SQLI - 读取文件、HTTP 头命令注入 - X-FORWARDED-FOR（RCE）、滥用 sudoers 权限（权限提升），并包含实用的枚举、利用、立足点和权限提升笔记。</td><td><a href="/pages/01bc040fac1464ca73d0a54eab27ceaeacb7a664">/pages/01bc040fac1464ca73d0a54eab27ceaeacb7a664</a></td></tr><tr><td><h3><i class="fa-linux" style="color:$primary;">:linux:</i></h3></td><td><h4>Backfire HackTheBox Linux 中等难度</h4></td><td>Backfire HackTheBox 中等难度 Linux 靶机复盘，涵盖信息泄露（Yaotl 文件）、Havoc-C2 利用（端口 40046）、SSH 密钥创建、横向移动（用户：Sergej），并包含实用的枚举、利用、立足点和权限提升笔记。</td><td><a href="/pages/bc7353f308627ff4ed2eff4d6ad926de3c56ea68">/pages/bc7353f308627ff4ed2eff4d6ad926de3c56ea68</a></td></tr><tr><td><h3><i class="fa-linux" style="color:$primary;">:linux:</i></h3></td><td><h4>Apocalyst HackTheBox Linux 中等难度</h4></td><td>Apocalyst HackTheBox 中等难度 Linux 靶机复盘，涵盖 WordPress 枚举、图像隐写挑战 - Steghide、信息泄露 - 用户枚举、WordPress 利用 - 主题编辑器（RCE），并包含实用的枚举、利用、立足点和权限提升笔记。</td><td><a href="/pages/400f3184abf12acd202e7399b98578f89ee3077d">/pages/400f3184abf12acd202e7399b98578f89ee3077d</a></td></tr><tr><td><h3><i class="fa-linux" style="color:$primary;">:linux:</i></h3></td><td><h4>Poison HackTheBox Linux 中等难度</h4></td><td>Poison HackTheBox 中等难度 Linux 靶机复盘，涵盖本地文件包含（LFI）、ZIP 文件破解、滥用 VNC - vncviewer（权限提升），并包含实用的枚举、利用、立足点和权限提升笔记。</td><td><a href="/pages/9e2c2ef1ecf653e557eba6bf76532ac69f723fa2">/pages/9e2c2ef1ecf653e557eba6bf76532ac69f723fa2</a></td></tr><tr><td><h3><i class="fa-linux" style="color:$primary;">:linux:</i></h3></td><td><h4>Waldo HackTheBox Linux 中等难度</h4></td><td>Waldo HackTheBox 中等难度 Linux 靶机复盘，涵盖 LFI（本地文件包含）- 过滤绕过、通过 LFI 获取用户的 SSH 私钥、从容器中逃逸、受限 Shell 绕过，并包含实用的枚举、利用、立足点和权限提升笔记。</td><td><a href="/pages/d4df5b4c851e757ba2894a6653261cd19484792b">/pages/d4df5b4c851e757ba2894a6653261cd19484792b</a></td></tr><tr><td><h3><i class="fa-linux" style="color:$primary;">:linux:</i></h3></td><td><h4>Chaos HackTheBox Linux 中等难度</h4></td><td>Chaos HackTheBox 中等难度 Linux 靶机复盘，涵盖密码猜测、滥用电子邮件服务（claws-mail）、密码学挑战（解密秘密消息 - AES 加密）、LaTeX 注入（RCE），并包含实用的枚举、利用、立足点和权限提升笔记。</td><td><a href="/pages/200624528baa98f80bca0c2590f4c4b55e22e55a">/pages/200624528baa98f80bca0c2590f4c4b55e22e55a</a></td></tr><tr><td><h3><i class="fa-linux" style="color:$primary;">:linux:</i></h3></td><td><h4>Stratosphere HackTheBox Linux 中等难度</h4></td><td>Stratosphere HackTheBox 中等难度 Linux 靶机复盘，涵盖 Apache Struts 利用（CVE-2017-5638）、Python 库劫持（权限提升），并包含实用的枚举、利用、立足点和权限提升笔记。</td><td><a href="/pages/ae8c5c37c9feab70ca7beb65f98397a05b75b664">/pages/ae8c5c37c9feab70ca7beb65f98397a05b75b664</a></td></tr><tr><td><h3><i class="fa-linux" style="color:$primary;">:linux:</i></h3></td><td><h4>Cat HackTheBox Linux 中等难度</h4></td><td>Cat HackTheBox 中等难度 Linux 靶机复盘，涵盖目录 Fuzzing（.git 文件）、源代码分析（Git 仓库转储）、存储型 XSS 利用与会话劫持、使用 sqlmap 的 SQL 注入（SQLite），并包含实用的枚举、利用、立足点和权限提升笔记。</td><td><a href="/pages/cd5626a933ad74f80b0ca2e43396d9e4535ac0e2">/pages/cd5626a933ad74f80b0ca2e43396d9e4535ac0e2</a></td></tr><tr><td><h3><i class="fa-linux" style="color:$primary;">:linux:</i></h3></td><td><h4>Heal HackTheBox Linux 中等难度</h4></td><td>Heal HackTheBox 中等难度 Linux 靶机复盘，涵盖 LFI（本地文件包含）、LimeSurvey 中的 RCE（远程代码执行）、使用 Hashcat 进行哈希破解、用户横向移动，并包含实用的枚举、利用、立足点和权限提升笔记。</td><td><a href="/pages/e2dd0c3ccd66ca2a18d0adfb545c6bdf372dad11">/pages/e2dd0c3ccd66ca2a18d0adfb545c6bdf372dad11</a></td></tr><tr><td><h3><i class="fa-linux" style="color:$primary;">:linux:</i></h3></td><td><h4>Cypher HackTheBox Linux 中等难度</h4></td><td>Cypher HackTheBox 中等难度 Linux 靶机复盘，涵盖使用 JD-GUI 对 Java .jar 文件进行逆向工程、自定义 Java 代码漏洞分析、Neo4j 中的 Cypher 注入、通过未过滤输入实现远程代码执行（RCE），并包含实用的枚举、利用、立足点和权限提升笔记。</td><td><a href="/pages/72ce8f23894864cab56e8b13bd04066823cd1e29">/pages/72ce8f23894864cab56e8b13bd04066823cd1e29</a></td></tr></tbody></table>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/zh/writeups-ctf/hackthebox/linux-medium.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
