<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0"><channel><title>Linux取证 | baozongwi's blog</title><link>https://baozongwi.xyz/tags/linux%E5%8F%96%E8%AF%81/</link><description>Currently exploring Java security and internal network penetration, with CTFs as a hobby.</description><generator>Hugo</generator><language>zh-cn</language><item><title>玄机第五章</title><link>https://baozongwi.xyz/p/xuanji-chapter-5/</link><pubDate>Tue, 08 Apr 2025 20:50:06 +0000</pubDate><guid>https://baozongwi.xyz/p/xuanji-chapter-5/</guid><description>第五章 Windows 实战-evtx 文件分析 附件题，样本不能在本地运行，我掏出了很早之前装的ctfos虚拟机，放这里面来分析，密码为hello-ctf.com，有三个extx文件，根本不知道怎么来的，看peterpan的文章偷点东西过来， .evtx 文件简介 .evtx 文件是 Windows 事件日志文件，存 …</description></item><item><title>玄机第三章</title><link>https://baozongwi.xyz/p/xuanji-chapter-3/</link><pubDate>Fri, 14 Mar 2025 14:56:32 +0000</pubDate><guid>https://baozongwi.xyz/p/xuanji-chapter-3/</guid><description>第三章 权限维持-linux权限维持-隐藏 f1&amp;&amp;f2 libprocesshider是用于隐藏文件的项目，一般权限维持都是在/tmp，包括我打CTF也是这么做的，进入之后依次递进到了/tmp/.temp/libprocesshider，看到了1.py #!/usr/bin/python3 import …</description></item><item><title>玄机第一章</title><link>https://baozongwi.xyz/p/xuanji-chapter-1/</link><pubDate>Fri, 14 Mar 2025 10:44:01 +0000</pubDate><guid>https://baozongwi.xyz/p/xuanji-chapter-1/</guid><description>第一章 应急响应- Linux入侵排查 f1 链接之后把整个html文件夹下载下来然后让D盾里面扫一下，看到1.php，直接就是一个一句话，所以直接交 f2&amp;&amp;f3 存在不死马，这种一般隐藏的比较好，ls -al直接找到.shell.php &lt;?php …</description></item></channel></rss>