<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/" version="2.0"><channel><title>ENOCH-lyn Blog</title><link>https://enoch.host</link><atom:link href="https://enoch.host/feed.xml" rel="self" type="application/rss+xml"/><description>好想变强。。。</description><generator>Halo v2.22.14</generator><language>zh-cn</language><image><url>https://enoch.host/upload/ENOCH.jpg</url><title>ENOCH-lyn Blog</title><link>https://enoch.host</link></image><lastBuildDate>Sat, 13 Jun 2026 04:58:10 GMT</lastBuildDate><item><title><![CDATA[HTB Sauna]]></title><link>https://enoch.host/archives/htb-sauna</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=HTB%20Sauna&amp;url=/archives/htb-sauna" width="1" height="1" alt="" style="opacity:0;">Sauna 拿shell 扫端口 $ nmap -p- -sV 10.129.95.180 Starting Nmap 7.94SVN ( https://nmap.org ) at 2026-03-04 02:54 CST Nmap scan report for 10.129.95.180 Ho]]></description><guid isPermaLink="false">/archives/htb-sauna</guid><dc:creator>ENOCH</dc:creator><pubDate>Wed, 4 Mar 2026 11:57:31 GMT</pubDate></item><item><title><![CDATA[HTB Return]]></title><link>https://enoch.host/archives/htb-return</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=HTB%20Return&amp;url=/archives/htb-return" width="1" height="1" alt="" style="opacity:0;">Return 拿shell 先简单nmap看看开放了什么常用端口 # nmap 10.129.242.236 PORT &nbsp; &nbsp; STATE SERVICE 53/tcp &nbsp; open domain 80/tcp &nbsp; open http 88/tcp &nbsp; open kerberos-sec 13]]></description><guid isPermaLink="false">/archives/htb-return</guid><dc:creator>ENOCH</dc:creator><category>hackthebox</category><pubDate>Sun, 22 Feb 2026 09:37:48 GMT</pubDate></item><item><title><![CDATA[HTB Timelapse]]></title><link>https://enoch.host/archives/htb-timelapse</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=HTB%20Timelapse&amp;url=/archives/htb-timelapse" width="1" height="1" alt="" style="opacity:0;">先nmap PORT &nbsp; &nbsp; STATE SERVICE &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; VERSION 53/tcp &nbsp; open domain &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Simple DNS Plus 88/tcp &nbsp; open kerberos-sec &nbsp; &nbsp; Microsoft Windows]]></description><guid isPermaLink="false">/archives/htb-timelapse</guid><dc:creator>ENOCH</dc:creator><category>hackthebox</category><pubDate>Sat, 14 Feb 2026 09:34:02 GMT</pubDate></item><item><title><![CDATA[HTB Support]]></title><link>https://enoch.host/archives/htb-support</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=HTB%20Support&amp;url=/archives/htb-support" width="1" height="1" alt="" style="opacity:0;">先nmap一下 # nmap -sS -sV -A -Pn 10.129.250.29 &lt;...&gt; PORT &nbsp; &nbsp; STATE SERVICE &nbsp; &nbsp; &nbsp; VERSION 53/tcp &nbsp; open domain &nbsp; &nbsp; &nbsp; Simple DNS Plus 88/tcp &nbsp; open ker]]></description><guid isPermaLink="false">/archives/htb-support</guid><dc:creator>ENOCH</dc:creator><category>hackthebox</category><pubDate>Thu, 12 Feb 2026 10:19:29 GMT</pubDate></item><item><title><![CDATA[HTB Cicada]]></title><link>https://enoch.host/archives/htb-cicada</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=HTB%20Cicada&amp;url=/archives/htb-cicada" width="1" height="1" alt="" style="opacity:0;">Cicada 先nmap # nmap -sT -p- --min-rate 10000 -o ports 10.129.254.230 Starting Nmap 7.94SVN ( https://nmap.org ) at 2026-02-06 05:09 CST Nmap scan repo]]></description><guid isPermaLink="false">/archives/htb-cicada</guid><dc:creator>ENOCH</dc:creator><category>hackthebox</category><pubDate>Fri, 6 Feb 2026 12:19:24 GMT</pubDate></item><item><title><![CDATA[HTB EscapeTwo]]></title><link>https://enoch.host/archives/htb-escapetwo</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=HTB%20EscapeTwo&amp;url=/archives/htb-escapetwo" width="1" height="1" alt="" style="opacity:0;">EscapeTwo What is the fully qualified domain name of the machine? # nxc smb 10.129.232.128 SMB &nbsp; &nbsp; &nbsp; &nbsp; 10.129.232.128 445 &nbsp; DC01 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; [*] Win]]></description><guid isPermaLink="false">/archives/htb-escapetwo</guid><dc:creator>ENOCH</dc:creator><category>hackthebox</category><pubDate>Fri, 6 Feb 2026 10:57:16 GMT</pubDate></item><item><title><![CDATA[XS-Leak学习记录----正文]]></title><link>https://enoch.host/archives/xsleak-learning</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=XS-Leak%E5%AD%A6%E4%B9%A0%E8%AE%B0%E5%BD%95----%E6%AD%A3%E6%96%87&amp;url=/archives/xsleak-learning" width="1" height="1" alt="" style="opacity:0;">了解了前置知识后，可以正式进入xsleak的学习了 基于网络时序 这种方法主要是测量响应时间 如果能通过某种方式让命中响应明显变慢或变快，就能通过测量响应时间来判断结果 通常以下内容会影响响应时间]]></description><guid isPermaLink="false">/archives/xsleak-learning</guid><dc:creator>ENOCH</dc:creator><category>记录</category><category>文章</category><pubDate>Mon, 2 Feb 2026 06:32:32 GMT</pubDate></item><item><title><![CDATA[XS-Leak学习记录----前置知识]]></title><link>https://enoch.host/archives/xsleak-before-learning</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=XS-Leak%E5%AD%A6%E4%B9%A0%E8%AE%B0%E5%BD%95----%E5%89%8D%E7%BD%AE%E7%9F%A5%E8%AF%86&amp;url=/archives/xsleak-before-learning" width="1" height="1" alt="" style="opacity:0;">前言 XS-Leaks 的本质是Web侧信道攻击 不同于XSS直接执行代码获取敏感信息，XS-Leaks利用浏览器在处理跨站请求时的细微差异，推断用户的状态或敏感数据 国际赛关于XSS以及xsleak的考察呈逐渐增加的趋势，所以想着系统性的学学xsleak 学]]></description><guid isPermaLink="false">/archives/xsleak-before-learning</guid><dc:creator>ENOCH</dc:creator><category>文章</category><pubDate>Thu, 29 Jan 2026 09:15:47 GMT</pubDate></item><item><title><![CDATA[N1CTF Junior 2026 1/2 出题小记]]></title><link>https://enoch.host/archives/n1ctf-junior-2026-1-2-chu-ti-xiao-ji</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=N1CTF%20Junior%202026%201%2F2%20%E5%87%BA%E9%A2%98%E5%B0%8F%E8%AE%B0&amp;url=/archives/n1ctf-junior-2026-1-2-chu-ti-xiao-ji" width="1" height="1" alt="" style="opacity:0;">这次依旧是出了两道题 posetman在预期范围内 但是notes差点零解，不得已上了hint是我没想到的 可能是大部分师傅都默认http.server 这种官方库应该不存在CRLF这种问题吧，，， 以下是wp Notes 题目提供了一个笔记应用，admin用户在初始化时会创建一个包含flag的笔记]]></description><guid isPermaLink="false">/archives/n1ctf-junior-2026-1-2-chu-ti-xiao-ji</guid><dc:creator>ENOCH</dc:creator><category>文章</category><category>wp</category><pubDate>Tue, 27 Jan 2026 07:18:38 GMT</pubDate></item><item><title><![CDATA[SECCON CTF 14 Quals]]></title><link>https://enoch.host/archives/seccon-ctf-14-quals</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=SECCON%20CTF%2014%20Quals&amp;url=/archives/seccon-ctf-14-quals" width="1" height="1" alt="" style="opacity:0;">期末周，还是做了一题就润了 broken-challenge cookie 在 hack.the.planet.seccon 这个域 /hint 路由给了证书私钥 -----BEGIN EC PRIVATE KEY----- MHcCAQEEIDXSM3v5wDSRra/TS/InNmXoVWqm4]]></description><guid isPermaLink="false">/archives/seccon-ctf-14-quals</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Sun, 14 Dec 2025 17:00:00 GMT</pubDate></item><item><title><![CDATA[CyKor CTF 2025 dbchat wp]]></title><link>https://enoch.host/archives/cykor-ctf-2025</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=CyKor%20CTF%202025%20dbchat%20wp&amp;url=/archives/cykor-ctf-2025" width="1" height="1" alt="" style="opacity:0;">最近事情有点多，上线写了一题就去忙其他的了（ dbchat def _generate_sql(self, prompt: str) -&gt; (str, List): m = self._pattern.match(prompt) if not m:]]></description><guid isPermaLink="false">/archives/cykor-ctf-2025</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Mon, 8 Dec 2025 02:10:29 GMT</pubDate></item><item><title><![CDATA[铸剑杯 预选赛 WP]]></title><link>https://enoch.host/archives/zjb-2025-pre-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=%E9%93%B8%E5%89%91%E6%9D%AF%20%E9%A2%84%E9%80%89%E8%B5%9B%20WP&amp;url=/archives/zjb-2025-pre-wp" width="1" height="1" alt="" style="opacity:0;">CloudEver战队WP 战队排名：12 WEB 浅析PHP原生类 题目提供了一个反序列化入口 @unserialize($_GET]]></description><guid isPermaLink="false">/archives/zjb-2025-pre-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Wed, 26 Nov 2025 07:16:49 GMT</pubDate></item><item><title><![CDATA[RCTF 2025 wp]]></title><link>https://enoch.host/archives/rctf-2025-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=RCTF%202025%20wp&amp;url=/archives/rctf-2025-wp" width="1" height="1" alt="" style="opacity:0;">photographer flag 在 public/superadmin.php if (Auth::check() &amp;&amp; Auth::type() &lt; $user_types['admin']) { &nbsp; &nbsp;echo getenv('FLAG') ?: 'RCTF{test_flag}'; }]]></description><guid isPermaLink="false">/archives/rctf-2025-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Tue, 18 Nov 2025 02:00:00 GMT</pubDate></item><item><title><![CDATA[Infobahn CTF 2025]]></title><link>https://enoch.host/archives/infobahn-ctf-2025-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=Infobahn%20CTF%202025&amp;url=/archives/infobahn-ctf-2025-wp" width="1" height="1" alt="" style="opacity:0;">Sandbox Viewer 未解出，赛后复现 给了个iframe，任意写srcdoc然后删除 let iframe = document.getElementById('safe'); iframe.srcdoc = key; iframe.onload = () =&gt; { iframe.re]]></description><guid isPermaLink="false">/archives/infobahn-ctf-2025-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Wed, 12 Nov 2025 08:38:53 GMT</pubDate></item><item><title><![CDATA[XCTF final 2025 N1Star web wp]]></title><link>https://enoch.host/archives/xctf-final-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=XCTF%20final%202025%20N1Star%20web%20wp&amp;url=/archives/xctf-final-wp" width="1" height="1" alt="" style="opacity:0;">比赛时写的，比较简陋 kidding 参考文章curl任意库加载实现远程代码执行 (RCE) 根据文章打包so #include &lt;stdlib.h&gt; #include &lt;stdio.h&gt; __attribute__((constructor)) static void rce_init(void]]></description><guid isPermaLink="false">/archives/xctf-final-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Tue, 28 Oct 2025 15:09:40 GMT</pubDate></item><item><title><![CDATA[强网杯2025 CloudEver战队 WP]]></title><link>https://enoch.host/archives/qwb-2025-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=%E5%BC%BA%E7%BD%91%E6%9D%AF2025%20CloudEver%E6%88%98%E9%98%9F%20WP&amp;url=/archives/qwb-2025-wp" width="1" height="1" alt="" style="opacity:0;">misc Personal Vault string 搜索flag正则，一把嗦 The_Interrogation_Room import socket, re, string from hashlib import sha256 ​ HOST = "47.94.202.253" PORT = 34]]></description><guid isPermaLink="false">/archives/qwb-2025-wp</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Sun, 19 Oct 2025 16:00:00 GMT</pubDate></item><item><title><![CDATA[HTB Proxy wp]]></title><link>https://enoch.host/archives/htb-proxy-wp</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=HTB%20Proxy%20wp&amp;url=/archives/htb-proxy-wp" width="1" height="1" alt="" style="opacity:0;">分析 后端有一个flushInterface app.post("/flushInterface", validateInput, async (req, res) =&gt; { &nbsp; const { interface } = req.body; ​ &nbsp; try { &nbsp; &nbsp; &nbsp; const]]></description><guid isPermaLink="false">/archives/htb-proxy-wp</guid><dc:creator>ENOCH</dc:creator><category>hackthebox</category><pubDate>Wed, 15 Oct 2025 14:15:47 GMT</pubDate></item><item><title><![CDATA[基于LocalStack本地学习AWS]]></title><link>https://enoch.host/archives/use-localstack-learning-aws</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=%E5%9F%BA%E4%BA%8ELocalStack%E6%9C%AC%E5%9C%B0%E5%AD%A6%E4%B9%A0AWS&amp;url=/archives/use-localstack-learning-aws" width="1" height="1" alt="" style="opacity:0;">配置 皆为windows下的配置 首先要有github学生包，最近更新了，免费使用localstack进行本地aws相关开发，不用真的买存储桶 先安装aws]]></description><guid isPermaLink="false">/archives/use-localstack-learning-aws</guid><dc:creator>ENOCH</dc:creator><category>文章</category><pubDate>Sun, 5 Oct 2025 12:21:48 GMT</pubDate></item><item><title><![CDATA[SunShineCTF 2025]]></title><link>https://enoch.host/archives/sunshinectf-2025</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=SunShineCTF%202025&amp;url=/archives/sunshinectf-2025" width="1" height="1" alt="" style="opacity:0;">没啥意思，写了个白盒就润了 Intergalactic Webhook Service dns重绑定攻击 @app.route('/register', methods=['POST']) def register_webhook(): url = request.form.get('url]]></description><guid isPermaLink="false">/archives/sunshinectf-2025</guid><dc:creator>ENOCH</dc:creator><category>wp</category><pubDate>Fri, 3 Oct 2025 05:03:08 GMT</pubDate></item><item><title><![CDATA[HTB-Dusty Alleys]]></title><link>https://enoch.host/archives/htb-dusty-alleys</link><description><![CDATA[<img src="https://enoch.host/plugins/feed/assets/telemetry.gif?title=HTB-Dusty%20Alleys&amp;url=/archives/htb-dusty-alleys" width="1" height="1" alt="" style="opacity:0;">题目描述 In the dark, dusty underground labyrinth, the survivors feel lost and their resolve weakens. Just as despair sets in, they notice a faint light:]]></description><guid isPermaLink="false">/archives/htb-dusty-alleys</guid><dc:creator>ENOCH</dc:creator><category>hackthebox</category><pubDate>Tue, 23 Sep 2025 13:20:44 GMT</pubDate></item></channel></rss>