·¹º§ ÇØÅ·

 2844, 1/143 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   bigfood
   ·¹º§4 level4 ÈùÆ®...UPDATE 03.10.01

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_level&no=199 [º¹»ç]


2ÁÖÀÏÈÄ...
Ǫµé: ¤»¤»¤» °Ü¿ì Ç®¾ú´ç.... Ç®¾îº¸´Ï ½±´õ±º...¤»¤»¤» PassÇÑ »ç¶÷(?)¸¸ÀÌ
     ÇÒ ¼ö ÀÖ´Â ¸»ÀÌÁã...¤»¤»¤»

°ñµç¸®Æ®¸®¹ö: ÀßÇßÀ¸~~~ c¾ð¾î °øºÎ ¸¹ÀÌ Çß³Ä?

Ǫµé: ¹¹...ÂÍ Çß´Ù°í ÇÒ ¼ö ÀÖ¡~~¤»¤»¤» (c¾ð¾î µ¹¾Æ°¡´Â°Ç ¾î´ÀÁ¤µµ ¾Ë°Ú
                                        Áö¸¸...^^:)
Ǫµé: À̹ø ·¹º§Àº ¾î¶²Áö º¼±î?~~¢Ý

´©±º°¡ /etc/xinetd.d/ ¿¡ ¹éµµ¾î¸¦ ½É¾î³õ¾Ò´Ù!

À̹ø ¹®Á¦´Â ¹éµµ¾î ¹®Á¦±º...¤»¤»¤» À̹øµµ ±ÇÇÑ °É¸° ÆÄÀÏ Ã£¾Æ ±×°É ÀÌ¿ëÇؼ­
Ǫ´Â ¹®Á¨°¡? ¤»¤»¤»

°ñµç¸®Æ®¸®¹ö: ¾Æ³à~~ À̹ø ¹®Á¦´Â ¹éµµ¾î¸¦ ÀÌ¿ëÇϴ°ű¸ setUID °ü·Ã ¹®Á¦¸¦ Ǫ´Â°Ç
              ¾Æ´Ï¾ß~

Ǫµé: ±×·³?~~

°ñµç¸®Æ®¸®¹ö: ¿ì¼± ÀÌ ¹®Á¦ÀÇ Àǵµ¸¦ ¾Ë¾Æ¾ß °ÚÁö
1)¹éµµ¿ö¶õ?  2)/etc/xinetd.d/ ¶õ? ±×³É Æú´õ°¡ ¾Æ´Ï°í ±â´ÉÀÌ ÀÖ´Ù.

Ǫµé: ±× xinetd.d ÆÄÀÏÀÌ ¾Æ´Ï°í µðÅØÅ丮´øµ¥..
±×¾È¿¡ backdoor¶ó´Â ÆÄÀÏÀÌ ÀÖ¾û~~

service finger
{
disable=no
flags=REUSE
socket_type=stream
wait=no
user=level5
server=/home/level4/tmp/backdoor
log_on_failure +=USERID
}

°ñµç ¸®Æ®¸®¹ö: ÀÀ...ÀÌ ¹®Á¦¸¦ Ç®¼ö ÀÖ´Â keypoint´Ü¼­¾ß~!
Àú°ÍÀÌ 3¹ø° ÀÌ°í
4¹ø°~! ½©½ºÅ©¸³Æ®¸¦ ÀÛ¼º ÇÒ ÁÙ ¾Ë¾Æ¾ß ÇØ~!

°ñµç¸®Æ®¸®¹ö: ½©½ºÅ©¸³Æ®? ¶á±Ý¾øÀÌ ¿Ø ½© ½ºÅ©¸³Æ®???

Ǫµé: ÇÔ ÀÎÅͳݿ¡¼­ ã¾ÆºÁ~~~ ³Ê¹« ¸¹ÀÌ ¾Ë·ÁÁִ°Š°°¾î~~ ³ªµµ level5 Ç®¾î¾ß
      µÇ´Âµ­~~~~

°ñµç¸®Æ®¸®¹ö: ¾ß ±Ùµ¥ Àǹ®ÀÌ ÀÖ¾î~~ ¹» ÀÛµ¿ÇØ¾ß ÇÁ·Î±×·¥ÀÌ ½ÇÇàµÉ²¨ ¾ÆÀÌ°¡?~
               ±Ùµ¥ ÀÌ ´Ü¼­µéÀº ´Ù~~ ½ÇÇàÆÄÀÏÀÌ ¾øÀ¸¾ß~ ±×¸®°í ·¹º§5¶ó°í
              ³ª¿Â°Ç À§¿¡ backdoor ¿¡ ³ª¿Â°ÍÀÌ ´Ù±¸ ¸»¾ß~ ¾î¼¶ó±¸~!!!!

Ǫµé: ½ÇÇàÇÁ·Î±×·¥À̶ó.... ÁÁ¾Æ ¾Ë·ÁÁÖÁö~~ ½ÇÇàÇÁ·Î±×·¥Àº finger ¾ß~
      ±× ÇÁ·Î±×·¥À» ÀÛµ¿Çϸé À§¿¡ °ü·ÃÇؼ­ Á¶°Ç¿¡ ´ëÀÔÇؼ­ ½ÇÇàµÇ~~¿©±â±îÁö
      À½..±×¸®°í...ÇΰŠÀÛµ¿ÀÌ ³¡ÀÌ ¾Æ´Ï´Ù... ¿ì¸®°¡ ¿øÇÏ´Â°Ç ·¹º§5 Æнº¿öµå
      ¸¦ ¾ò´Â°ÅÁö... ±×·¯±â À§Çؼ± ½© ½ºÅ©¸³Æ®¸¦ ¹è¿ö¹Ù~~~ ±×·³...¤»¤»¤»

-----------------------------------------------------------------------
UPDATE 03.10.01
Ǫµé: ¾ß Á»´õ Á»´õ ½±°Ô ¾ËÄÑÁà~~ ¹«Áö ¸ð¸£°Ú´ç~ Áö±Ý ·¹º§4µéµµ ¸ð¸£°Ú´ÙÀݾî~!!!

°ñµç¸®Æ®¸®¹ö: ÁÁ¾Æ~ xinetd.d Æú´õÀÖÁö? ±× Æú´õ ¾È¿¡ ÆÄÀϵéÀº ÄÄÇ»ÅÍ°¡
ºÎÆÃÇϸ鼭 ±×¾È¿¡ ÆÄÀϵéÀÌ Ç×»ó ½ÇÇàµÇÁö~ ¹°·Ð ±×¾È¿¡ backdoor¶ó´Â ÆÄÀÏÀÌ ÀÖ¾û~~
±×°Íµµ Ç×»ó ¸®´ª½º ¼­¹ö¿¡¼­ ½ÇÇàÁß¿¡ ÀÖ¾î ±× ³»¿ëÀº ¾Æ·¡¿Í °°±¸¸»¾ß
¾Æ·¡ Á¶°Ç¿¡ ÇÕ´çÇÑ Á¤º¸°¡ µé¾î ¿À´ÂÁö ¾È¿À´ÂÁö REDAY! ¿äÀÌ~~¶¥~! ÇÏ°í Áغñ ÇÏ°í
Àִ°žß~~ ¤»¤»¤» ±×·³ ¾Æ³» ³»¿ëÀÌ Áß¿äÇÏ°Ú¡? Áß¿äÇÑ ºÎºÐ¸¸ ¼³¸íÇϸé

Âü°í:http://www-903.ibm.com/developerworks/kr/linux/library/l-xinetd.html

service finger  <-1¹ø: ÇΰŠ¸í·É¾î¿¡ ´ëÇØ ÀÛµ¿À» ÇÑ´Ù...
{
disable=no
flags=REUSE
socket_type=stream
wait=no
user=level5    <-2¹ø: º°ÀÇ¹Ì ¾ø´Ù? ¸Â³ª? ^^;
server=/home/level4/tmp/backdoor <-3¹ø: ÇΰŸ¦ ½ÇÇàÇßÀ¸¸é ¾Æ·¡ °æ·Î
¸¦ ½ÇÇàÇÑ´Ù~~ À̸»ÀÌ Å° Æ÷ÀÎÆ®°ÚÁö? (½ÇÇàµÉ Daemon)
log_on_failure +=USERID
}

Âü°í2:http://www.korealinux.org/study-menu/network-center-2.htm

±×·¯´Ï±ñ Finger¿¡ »ç¿ëµÇ´Â ±âº»ÀûÀÎ ÀÎÀÚ(argument)´Â
»ç¿ëÀÚ@È£½ºÆ®ÀÇ ½ÖÀÌ¾ß Áï finger level4@localhost ¶ó°í ½ÇÇàÇϴ°ÅÁö~

Âü°í3:http://korea.gnu.org/manual/release/finger/


Ǫµé: ¿ÀÈ£¶ó~~ ¾Ë°Ú´ç~~¤»¤»¤» ±Ùµ¥ localhost´Â ¹¹¾ß?

°ñµç¸®Æ®¸®¹ö: ÀÚ½ÅÀ» °¡¸®Å°´Â ¸»ÀÌ¾ß ¶Ç´Â level4@127.0.0.1 À̶ó°í Çصµ »ó°ü¾ø¾î
´Ù ÀÚ±â ÀÚ½ÅÀ» Áï Àڱ⠼­¹ö¸¦ °¡¸®Å°´Â ¸»ÀÌÁö~

°ñµç¸®Æ®¸®¹ö: ±×´ÙÀ½¿¡
" server=/home/level4/tmp/backdoor <-3¹ø: ÇΰŸ¦ ½ÇÇàÇßÀ¸¸é ¾Æ·¡ °æ·Î¸¦ ½ÇÇàÇÑ´Ù~~ À̸»ÀÌ Å° Æ÷ÀÎÆ®°ÚÁö? (½ÇÇàµÉ Daemon)   "
¿©±â¼­ Àú±â¿¡ ÇØ´çÇÏ´Â ½©½ºÅ©¸³Æ®¸¦ ¸¸µé¾î Áִ°žß~

Ǫµé: ½©½ºÅ©¸³Æ®? ±×°Ô ¹¹¾ç~~~?

°ñµç¸®Æ®¸®¹ö: Á¤¸®Çϸé finger level4@localhost ¶ó°í Çϸé backdoor°¡ ½ÇÇàµÇ´Â
°Å±îÁö ¹è¿üÁö~ ±×·¯¸é ±×¾È¿¡¼­ µ¥¸óÀÌ ÀÛµ¿ÇÏ°Ô µÇ´Âµ¥ ±× ½ÇÇàµÉ µ¥¸óÀ» ¸¸µå´Â°Å¾ß
½©½ºÅ©¸³Æ®·Î~ ¸»ÀÌ¾ß ÀÎÅͳݿ¡¼­ ã¾Æº¸¸é ½©½ºÅ©¸³Æ® ¸¸µå´Â°Å ³ª¿ÍÀÖ¾î
±×°É ¸¸µé¾î¼­ ¾Æ±î °æ·Î¿¡ ¸¸µé¾îÁÖ°í ÆÄÀϸíÀº ³ª¿ÍÀÖµíÀÌ backdoorÀ̶ó°í Çؾ߰ÚÁö? ¿©±â±îÁö ÇÏ¸é ¾Ë°Ú¾î?

Ǫµé: ±Û½ê...Á»´õ...

°ñµç¸®Æ®¸®¹ö: Áü..Ä£±¸³× Áý¿¡ °¡¾ßµÇ´Âµ­~~ ¾Æ·¡ »çÀÌÆ® Âü°í4ÇØ~!
http://www.superuser.co.kr/security/dacker/page09.htm





  Hit : 6046     Date : 2003/09/15 06:53



    
muzen2540 Àü¿¡ ½Ãµµ¸¦ Çغþú´Âµ¥; ½±°í ÆíÇÏ°Ô Çϱâ À§Çؼ± ½© ½ºÅ©¸³Æ®¸¦ ÀÌ¿ëÇÏ´Â°Ô È¿À²ÀûÀÎ ¹æ¹ýÀÌÁö¸¸ c·Î Çصµ Å©°Ô °ü°è´Â ¾ø´ø°Í °°½À´Ï´Ù;; 2003/09/15  
lnxdoor ¾ù ³ªÁß¿¡ ǪµéÇÏ°í °ñµåÇÏ°í »óȲ¿ªÀü 2003/09/15  
lnxdoor ÇÑ°Å °°¾Æ¿ä @____@ 2003/09/15  
happykth1 ¤Ì¸Ó°¡ ¾î¶»´Ù´Â °Å¿ä? 2003/09/27  
happykth1 Á¦´ë·Î °¡¸£ÄÑ ÁÖ¼¼¿ä 2003/09/27  
override level5 2003/11/17  
kyohack ¤¾¤¾ inxdoor´Ô ¿¹¸®ÇϽó×. ±×·¸³×¿ä 2003/12/11  
ÇÏ¿¤ À½-_-.. Á¦°¡ ³Ê¹« °£´ÜÇÏ°Ô Ç¬°Ç°¡¿äa;; 2004/02/10  
yooadocjon Á¤¸» ´ë´ÜÇÑ ¼³¸í ´É·ÂÀ̽ʴϴ٠Àß ¹è¤·¤Ï¤¶¾î¿ä 2011/07/21  
pyunhb ¹¹Áö!! 2012/07/29  
2844   hack the box vpn ¼³Ä¡°¡ ¾È µË´Ï´Ù[2]     jyk5350
07/16 1842
2843   ¿ö°ÔÀÓ¿¡¼­ ½ÇÁ¦ ÇÁ·ÎÁ§Æ®±îÁö À̾îÁö´Â °úÁ¤¿¡ °ü·ÃµÈ Áú¹®[2]     junhee329
04/28 1577
2842   ftz Á¢¼Ó °ü·Ã[1]     pk2861
04/01 1952
2841   level8ÀÇ ÈùÆ®ÆÄÀÏ ÈѼÕ[2]     MunHue
06/05 2182
2840   ·¹º§1ÀÇ /bin/bash ¸í·É¾î....     MunHue
05/15 2335
2839   ftz level4¿¡¼­ finger¸í·É¾î     krimson701
04/20 2450
2838   /bin/bash¿¡ °üÇؼ­[3]     MunHue
04/19 2535
2837   FC10 3¹ø ¹®Á¦ Áú¹®ÀÔ´Ï´Ù.[2]     tjdalstjr938
04/02 2556
2836   ftzÀÌ ¾ÈµÇ¿ä¤Ð¤Ð¤Ð¤Ð¤Ð[1]     ersd145
04/13 3210
2835   fedora core4 cruel Áú¹®[4]     vngkv123
03/29 2654
2834   Fedora core4...[3]     vngkv123
03/28 2664
2833   lob evil_wizard...[2]     vngkv123
03/27 2323
2832   lob gremlin....[1]     vngkv123
03/22 3695
2831   ftz level11 Áú¹®[1]     vngkv123
03/19 2383
2830   pwnable.kr passcode¹®Á¦ Áú¹®...[3]     vngkv123
03/14 2392
2829   ¿ö°ÔÀÓ Á¢ÇÒ ¼ö ÀÖ´Â »çÀÌÆ® ¾Ë·ÁÁÖ¼¼¿ä.[2]     ¿À¼Ò¸®
02/23 3936
2828   ¿ö°ÔÀÓ ±â¹Ý Áö½Ä¿¡ °üÇÑ Áú¹®[1]     salangi11
02/22 2280
2827   ftz Ç®±âÀ§ÇØ ÇÊ¿äÇÑ Áö½ÄÀÌ ±Ã±ÝÇÕ´Ï´Ù.[1]     read1516
01/13 2694
2826   Lob[1]     km1434
12/20 2475
2825   FTZ level4 ½© ¶ç¿ì´Â ¹®Á¦      kimstz0
10/09 2901
1 [2][3][4][5][6][7][8][9][10]..[143]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org