<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Posts on shibajutsu</title><link>https://blog.shiba.onl/posts/</link><description>Recent content in Posts on shibajutsu</description><generator>Hugo</generator><language>vn</language><copyright>© shibajutsu</copyright><lastBuildDate>Wed, 26 Nov 2025 00:00:00 +0700</lastBuildDate><atom:link href="https://blog.shiba.onl/posts/index.xml" rel="self" type="application/rss+xml"/><item><title>Phân tích CVE-2023-46604</title><link>https://blog.shiba.onl/posts/cve-2023-46604/</link><pubDate>Wed, 26 Nov 2025 00:00:00 +0700</pubDate><guid>https://blog.shiba.onl/posts/cve-2023-46604/</guid><description>CVE-2023-46604 CVE-2023-46604 là lỗ hổng RCE trong Apache ActiveMQ. Nguyên nhân xuất phát từ việc giải tuần tự (deserialization) dữ liệu không an toàn trong giao thức OpenWire – giao thức mặc định của ActiveMQ.
ActiveMQ và OpenWire ActiveMQ ActiveMQ là một message broker mã nguồn mở, viết bằng Java và là một dự án của Apache. Nó cung cấp khả năng gửi/nhận tin nhắn ứng dụng theo mô hình decoupled (queue và publish/subscribe).</description></item><item><title>Stealing OAuth token</title><link>https://blog.shiba.onl/posts/stealing-oauth-token/</link><pubDate>Fri, 10 Oct 2025 00:07:00 +0700</pubDate><guid>https://blog.shiba.onl/posts/stealing-oauth-token/</guid><description>Stealing OAuth token Lời nói đầu Đây là bài viết về “Stealing OAuth token”. Thực chất là mình tổng hợp các bài viết của những tác giả khác lại một cách ngắn gọn, giúp mình (và những người cần nó) có thể tìm đọc lại khi cần.
Vì đây chỉ là một bài tóm gọn nên còn nhiều chưa được nêu rõ, các bạn có thể tìm đọc kỹ hơn các bài viết ở dưới phần #References.</description></item><item><title>Gadget Store</title><link>https://blog.shiba.onl/posts/gadget-store/</link><pubDate>Fri, 26 Sep 2025 21:00:00 +0700</pubDate><guid>https://blog.shiba.onl/posts/gadget-store/</guid><description>Tóm tắt Đây là một challenge web trong khuôn khổ sự kiện Smart Banking 6th.
Trang web là một cửa hàng cho phép người dùng mua hàng, các sản phẩm đã mua sẽ được lưu trong session. Khi người dùng export thông tin mua hàng, thông tin mua hàng sẽ được serialized và người dùng tải về, ngược lại người dùng cũng có thể upload file .ser (chứa data đã serialized) để import thông tin mua hàng mua mình.</description></item><item><title>Cyber Apocalypse 2025: Eldoria Realms</title><link>https://blog.shiba.onl/posts/cyber-apocalypse-2025-eldoria-realms/</link><pubDate>Wed, 16 Jul 2025 00:12:00 +0700</pubDate><guid>https://blog.shiba.onl/posts/cyber-apocalypse-2025-eldoria-realms/</guid><description>Cyber Apocalypse 2025: Eldoria Realms Overview Hệ thống có 2 services:
Website được viết bằng Ruby gRPC Server gRPC gRPC là một framework RPC (Remote Procedure Call) mã nguồn mở và hiệu năng cao do Google phát triển, cho phép các ứng dụng giao tiếp với nhau qua mạng như thể gọi các hàm nội bộ. Có thể xem là sự thay cho RESTFul API và được sử dụng chủ yếu trong kiến trúc microservices.</description></item><item><title>Cyber Apocalypse 2025: Eldoria Panel</title><link>https://blog.shiba.onl/posts/cyber-apocalypse-2025-eldoria-panel/</link><pubDate>Tue, 15 Jul 2025 00:11:00 +0700</pubDate><guid>https://blog.shiba.onl/posts/cyber-apocalypse-2025-eldoria-panel/</guid><description>Cyber Apocalypse 2025: Eldoria Panel Overview Các chức năng chính của ứng dụng Đăng ký, đăng nhập Xem nhiệm vụ Nhận nhiệm vụ Đăng trạng thái cá nhân Phân tích Khi truy cập trang web, HTML sẽ được render từ server bằng một hàm render() từ triển khai.
function render($filePath) { if (!file_exists($filePath)) { return &amp;#34;Error: File not found.&amp;#34;; } $phpCode = file_get_contents($filePath); ob_start(); eval(&amp;#34;?&amp;gt;&amp;#34; . $phpCode); return ob_get_clean(); } $app-&amp;gt;get(&amp;#39;/&amp;#39;, function (Request $request, Response $response, $args) { $html = render($GLOBALS[&amp;#39;settings&amp;#39;][&amp;#39;templatesPath&amp;#39;] .</description></item><item><title>CachedWeb - Hackthebox challenge</title><link>https://blog.shiba.onl/posts/cachedweb/</link><pubDate>Wed, 09 Jul 2025 00:03:00 +0700</pubDate><guid>https://blog.shiba.onl/posts/cachedweb/</guid><description>CachedWeb {% embed url=&amp;ldquo;https://app.hackthebox.com/challenges/503&amp;quot; %}
Application Overview Truy cập trang thấy 1 form take screenshot từ url và lưu lại.
Trong thư mục blueprints @api.route(&amp;#34;/cache&amp;#34;, methods=[&amp;#34;POST&amp;#34;]) def cache(): if not request.is_json or &amp;#34;url&amp;#34; not in request.json: return abort(400) return cache_web(request.json[&amp;#34;url&amp;#34;]) Hàm cache_web:
def cache_web(url): domain = urlparse(url).hostname scheme = urlparse(url).scheme if not domain or not scheme: return flash(f&amp;#39;Malformed url {url}&amp;#39;, &amp;#39;danger&amp;#39;) elif not is_scheme_allowed(scheme): return flash(f&amp;#39;Scheme {scheme} is not allowed&amp;#39;, &amp;#39;danger&amp;#39;) elif not is_domain_allowed(domain): return flash(f&amp;#39;Domain {domain} is not allowed&amp;#39;, &amp;#39;danger&amp;#39;) elif cache.</description></item><item><title>Phân tích CVE-2023-21839</title><link>https://blog.shiba.onl/posts/cve-2023-21839/</link><pubDate>Tue, 10 Jun 2025 00:00:00 +0700</pubDate><guid>https://blog.shiba.onl/posts/cve-2023-21839/</guid><description>Phân tích CVE-2023-21839 Overview JNDI Java Naming Directory Interface là một API của cho phép các ứng dụng Java tìm kiếm, truy xuất và quản lý các đối tượng hoặc tài nguyên được đăng ký trong một hệ thống danh mục.
Dưới đây là ví dụ quá trình tìm và sử dụng đối tượng/tài nguyên:
flowchart TD A["Khởi tạo Context: new InitialContext()"] --> B["Gọi phương thức lookup()"] B --> C[Kết nối tới dịch vụ Naming/Directory Service] C --> D[Tra cứu đối tượng theo tên] D -- Nếu tìm thấy --> E[Trả về đối tượng] D -- Nếu không tìm thấy --> F[Throw NameNotFoundException] E --> G[Sử dụng đối tượng trong ứng dụng] F --> H[Xử lý lỗi và thông báo] JNDI Injection Là việc kẻ tấn công có thể thao túng quá trình tìm và load đối tượng/tài nguyên (lookup(), ${jndi:ldap://attacker.</description></item><item><title>Stylish - Hackthebox challenge</title><link>https://blog.shiba.onl/posts/stylish/</link><pubDate>Mon, 09 Jun 2025 00:01:00 +0700</pubDate><guid>https://blog.shiba.onl/posts/stylish/</guid><description>Stylish Dạo đầu Tìm điểm G Đầu tiên thì cứ phải quan sát để phân tích xem khai thác vào đâu.
Vì challenges cung cấp cả mã nguồn nền sẽ dễ dàng hơn.
Cái website nó trông thế này
Tổng quan thì đây là một trang web cho phép ta upload 1 đoạn CSS lên xong sẽ có con bot admin nó review gì gì đó.
Ngó qua file database.js thì thấy rõ mục tiêu là đọc flag trong database thông qua lỗ hổng SQL Injection.</description></item><item><title>Builder - Hackthebox machine</title><link>https://blog.shiba.onl/posts/builder/</link><pubDate>Mon, 09 Jun 2025 00:00:00 +0700</pubDate><guid>https://blog.shiba.onl/posts/builder/</guid><description>Builder Writeups này có sự tham khảo từ 0xdf và ippsec.
Machine link
Recon nmap sudo nmap -sC -sV nmap 10.10.11.10 Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-05-13 22:05 +07 Nmap scan report for 10.10.11.10 (10.10.11.10) Host is up (0.49s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.6 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 256 3e:ea:45:4b:c5:d1:6d:6f:e2:d4:d1:3b:0a:3d:a9:4f (ECDSA) |_ 256 64:cc:75:de:4a:e6:a5:b4:73:eb:3f:1b:cf:b4:e3:94 (ED25519) 8080/tcp open http Jetty 10.</description></item><item><title>HTB Proxy - Hackthebox challenge</title><link>https://blog.shiba.onl/posts/htb-proxy/</link><pubDate>Wed, 14 May 2025 00:02:00 +0700</pubDate><guid>https://blog.shiba.onl/posts/htb-proxy/</guid><description>HTB Proxy https://github.com/hackthebox/business-ctf-2024/
Application Overview localhost:1337
Truy cập vào /server-status cho phép ta xem được thông tin về machine.
/server-status
Phân tích source code ├── build_docker.sh ├── challenge │ ├── backend │ │ ├── index.js │ │ └── package.json │ └── proxy │ ├── go.mod │ ├── includes │ │ └── index.html │ └── main.go ├── config │ └── supervisord.conf ├── Dockerfile ├── entrypoint.sh ├── flag.txt Trong Dockerfile ta thấy được 1 vài thông tin như công nghệ machine sử dụng (nodejs, go, &amp;hellip;) và các config cơ bản khác như mọi CTF challenges khác.</description></item><item><title>Insecure Deserialization 101</title><link>https://blog.shiba.onl/posts/insecure-deserialization/</link><pubDate>Thu, 20 Mar 2025 00:05:00 +0700</pubDate><guid>https://blog.shiba.onl/posts/insecure-deserialization/</guid><description>Insecure Deserialization Overview When developing a game, you may need to save a player’s run to a file so that you don’t lose their progress and they can return to where they left off.
Indeed, there are many cases where we want to save the state of our application to restore it in the future. Two terms are used to define this process: serialization and deserialization.
What is deserialization (and serialization)?</description></item><item><title>Linux Internal 101 - Part 1</title><link>https://blog.shiba.onl/posts/linux-internal-101-part-1/</link><pubDate>Mon, 10 Mar 2025 00:04:00 +0700</pubDate><guid>https://blog.shiba.onl/posts/linux-internal-101-part-1/</guid><description>Linux Internal 101 - Part 1 Cấu trúc của một file ELF File mẫu mã nguồn C
#include &amp;lt;stdio.h&amp;gt; #include &amp;lt;stdlib.h&amp;gt; #include &amp;lt;string.h&amp;gt; /* --- PHÂN BỔ BỘ NHỚ CHO CÁC SECTIONS --- */ // 1. Biến toàn cục chưa khởi tạo -&amp;gt; Sẽ được đưa vào section .bss int global_uninit_var; // 2. Biến toàn cục đã khởi tạo -&amp;gt; Sẽ được đưa vào section .data int global_init_var = 0x1337BEEF; // 3.</description></item><item><title>Kubernetes 101</title><link>https://blog.shiba.onl/posts/kubernetes-co-ban/</link><pubDate>Sun, 09 Mar 2025 00:06:00 +0700</pubDate><guid>https://blog.shiba.onl/posts/kubernetes-co-ban/</guid><description>Kubernetes cơ bản Các thành phần cơ bản trong Kubernetes
Sơ đồ tổng quan các thành phần cơ bản trong môi trường Kubernetes
Cluster Cluster là môi trường mà Kubernetes sử dụng để triển khai và quản lý các ứng dụng container. Một cluster trong Kubernetes bao gồm:
Control Panel Là thành phần trung tâm và quan trọng nhất của 1 cluster. Chịu trách nhiệm quản lý và điều phối toàn bộ hoạt động của cluster.</description></item></channel></rss>