[Meachines] [Medium] Lazy Padding-Oracle+AES_CBC+路径劫持权限提升
# AES-CBC Padding Oracle攻击与PATH劫持权限提升实战教学
## 1. 信息收集阶段
### 1.1 目标扫描
首先对目标IP `10.10.10.18` 进行扫描:
```bash
ip='10.10.10.18';
itf='tun0';
if nmap -Pn -sn "$ip" | grep -q "Host is up"; then
echo -e "\e[32m[+] Target $ip is up, scanning ports...
2025-08-29 05:46:49
0