How many TCP ports are open? 2 What is the domainof the email address provided in the "Contact" section of the website? thetoppers.htb In the absence of a DNS server, which Linux file can we use to resolve hostnames to IP addresses inorderto be able toaccess the websites that pointto those hostnames? /etc/hosts Which sub-domainis discovered during further enumeration? s3.thetoppers.htb Which service is running on the discovered sub-domain? Amazon S3 Which command line utility can be used to interact with the service running on the discovered sub-domain? awscli Which command is used toset up the AWS CLI installation? aws configure What is the command used by the above utility to list allof the S3 buckets? aws s3 ls This serveris configured to run files written in what web scripting language? PHP
二、获取Flag
先对靶机IP进行端口扫描查看开放哪些端口
火狐浏览器访问该IP地址,在网页当中找到一个域名thetoppers.htb
使用OneForAll进行子域名爆破找到其中一个子域名s3.thetoppers.htb
在没有 DNS 服务器的情况下,我们可以使用Hosts文件将主机名解析为 IP 地址,以便能够访问指向这些主机名的网站