22019, 1/1101 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   xassault
   zz.jpg (89.5 KB), Download : 34     [¿À¸¥ÂÊ ¹öư ´­·¯ ´Ù¿î ¹Þ±â]
   gg.jpg (79.1 KB), Download : 26     [¿À¸¥ÂÊ ¹öư ´­·¯ ´Ù¿î ¹Þ±â]
   ¹öÆÛ¿À¹öÇÃ·Î¿ì ¿Õ±âÃÊÆí ¿¬½ÀÁßÀÔ´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=Free_Board&no=24497 [º¹»ç]




»çÁø ÷ºÎÇß±¸¿ä ¼Ò½º ÄÚµå ¶È°°ÀÌ ÃÆ´Âµ¥ ·çÆ® ±ÇÇÑÀÌ ¾ÈµÇ´Âµ¥  µµ´ëü ¾î¶»°Ô ÇØ¾ßµÇ³ª¿ä?

Áö±Ý À̰Ŷ§¹®¿¡ 10½Ã°£ ³Ñ°Ô ÇØº¸°í ¶ÇÇØ°í ±×·¡µµ ¾ÈµÇ¼­ µ¹¾Æ ¹ö¸®°Ú½À´Ï´Ù.

  Hit : 16138     Date : 2012/09/20 02:33



    
phpmyadmin vulnÆÄÀÏ¿¡ setuid°¡ °É·ÁÀִ°ǰ¡¿ä? 2012/09/20  
xassault ³× °É·ÁÀÖ½À´Ï´Ù. 2012/09/20  
phpmyadmin ÇöÀç°æ·Î path Ãß°¡¾ÈÇϽøé
½Ã½ºÅÛÇÔ¼ö°¡ È£ÃâµÇµµ ÇØ´ç ½Éº¼¸¯¸µÅ©¸¦ ½ÇÇàÇÒ¼ö¾ø½À´Ï´Ù.

innsas// ¹ÞÀ¸½ÅÀ̹ÌÁöºÎÆÃÇÏ½ÅµÚ ·Î±×ÀÎÇϽðí /sbin/ifconfig
ÀÔ·ÂÇÏ½Ã¸é ¾ÆÀÌÇǰ¡ ³ª¿É´Ï´Ù. ±âº»¼³Á¤Àº ¾Æ¸¶ 192.168.x.x ÀÌ·±½ÄÀä
¿©±â·Î telnet Á¢¼ÓÇϽøéµË´Ï´Ù.
2012/09/21  
xassault export path ù¹øÀç À̹ÌÁö µÎ¹øÂ° ÁÙ¿¡ ½ÇÇà µÇ¾îÀÖ½À´Ï´Ù. 2012/09/21  
phpmyadmin Çë.. ¿ä»õ ´«ÀÌ Ä§Ä§ÇØÁ³³×¿ä
Àú°É ¸øº¸´Ù´Ï..
¸¶Áö¸· ÆÞ¹® ½ÇÇà½ÃŰ½Ã°í id Ä¡½Ã±âÀü¿¡
ps ÇÏ½Ã¸é ¾Æ±î ½Éº¼¸¯ ¸µÅ© °É¾îÁֽŠÆÄÀÏ¸í ½ÇÇàµÇ°íÀÖ³ª¿ä?
¸¸¾à ½ÇÇàµÇ°íÀִµ¥ id°¡ ¿©ÀüÈ÷ Àú·±°Å¶ó¸é ±ÇÇÑ»ó½ÂÀÌ ¾ÈµÈ°ÍÀ̰í
PID TTY TIME CMD
839 pts/0 00:00:00 bash
922 pts/0 00:00:00 bash2
939 pts/0 00:00:00 ps
ÀÌ·±½ÄÀ¸·Î¸¸ ÀÖ´Ù¸é ÇØ´ç ½Éº¼¸¯ ¸µÅ©°¡ ½ÇÇàÀÌ ¾ÈµÈ°ÍÀÔ´Ï´Ù.
2012/09/21  
xassault À̹ÌÁö ¹ØºÎºÐ »õ·Î Ãß°¡Çß½À´Ï´Ù. 2012/09/21  
cd80 Ȥ½Ã À̰Џ®´ª½º ¹öÁ¯ÀÌ ¾î¶»°Ô µÇ½Ã³ª¿ä? 2012/09/22  
cd80 Ä¿³Î¹öÁ¯µµ °°ÀÌÁ» ¾Ë·ÁÁÖ¼¼¿ä 2012/09/22  
xassault ¸®´ª½º ¹öÁ¯°ú Ä¿³Î¹öÀü À̹ÌÁö ¹Ø¿¡ Ãß°¡Çß½À´Ï´Ù.. ±×¸®°í ¹öÆÛ ÇÃ·Î¿ì ¿Õ±âÃÊÆí¿¡ ³ª¿Â »çÀÌÆ®http://bit.ly/ntat42 ¿¡¼­ ¹Þ¾Ò½À´Ï´Ù. 2012/09/22  
cd80 Ȥ½Ã³ªÇؼ­ ±×·±µ¥ ls -l ÇϽŰ͵µ ¿Ã·ÁÁֽǼö ÀÖ³ª¿ä? 2012/09/22  
xassault ls -l Ãß°¡·Î À̹ÌÁö ¿Ã·È½À´Ï´Ù..°ü½É °®¾îÁּż­ °¨»çÇÕ´Ï´Ù. 2012/09/23  
cd80 Àú¾ß ¿ÀÈ÷·Á ±ÍÂú°Ô ÇØµå¸®´Â°Í°°¾Æ Á˼ÛÇϳ׿ä;;
¿ª½Ã setuid°¡ ¹®Á¦¿´½À´Ï´Ù
Áö±Ý ÇöÀç student°èÁ¤¿¡¼­ vuln ÇÁ·Î±×·¥À» °ø°ÝÇϴµ¥
vulnÇÁ·Î±×·¥¿¡µµ student°èÁ¤ÀÇ setuid°¡ °É·ÁÀÖ¾î °ø°ÝÀÌ ¼º°øÇصµ
student ±ÇÇÑÀÇ ½©À» µû°ÔµË´Ï´Ù
rootÁ¢¼ÓÀÌ °¡´ÉÇϽôٸé root·Î ·Î±×ÀÎÇϼż­
ÇØ´ç vulnÇÁ·Î±×·¥ÀÌ Àִ°÷¿¡¼­
chown root:root ./vuln
chmod 6755 ./vuln
À» ÇØº¸½Ã°í student °èÁ¤¿¡¼­ ¶È°°Àº ÆäÀ̷εå·Î ½ÃµµÇغ¸½Ã¸é ¼º°øÇÏ½Ç°Í °°½À´Ï´Ù
È­ÀÌÆÃÇϼ¼¿ä~~
2012/09/24  
cd80 * chmod 6755 ¿¡¼­ 6755 ´Â
-rwsr-sr-x ±ÇÇÑÀ¸·Î
ÇöÀç vulnÇÁ·Î±×·¥¿¡ °É¸° ±ÇÇÑÇÏ°í °°Áö¸¸
chownÀ¸·Î ¼ÒÀ¯ÀÚ ¼³Á¤À» ¹Ù²ãÁÖ¸é setuid°¡ »ç¶óÁ®¼­ ´Ù½Ã ÇØÁּžßÇÕ´Ï´Ù
2012/09/24  
xassault Àç°¡ »ç¿ëÇÏ´Â ¸®´ª½º°¡ óÀ½ºÎÅÍ ÇØÄ¿½ºÄð¿¡¼­ ½Ç½À¿ëÀ¸·Î ¸¸µéÁ®¼­ ¹èÆ÷ÇÏ¿´°í ¾Ë°íÀÖ´Â °èÁ¤Àº
student/student ¹Û¿¡ ¾ø½À´Ï´Ù.. ·çÆ® ÆÐ½º¿öµå¸¦ ¸ð¸¨´Ï´Ù....
2012/09/25  
xassault À̰мº°øÇÏ·Á¸é ¸®´ª½º6.2¸¦ Àç°¡ ·çÆ® ±ÇÇÑÀ¸·Î ´Ù½Ã ¼³Ä¡ ÇÏ´Â ¹æ¹ý ¹Û¿¡ ¾ø´ÂÁö¿ä? 2012/09/25  
cd80 ¾ÆÀ̵ð root
ºñ¹ø hackerschool
·Î Á¢¼ÓÇÏ½Ç ¼ö ÀÖÀ¸½Ç°Í °°½À´Ï´Ù

Ȥ½Ã ¾ÈµÇ½Å´Ù¸é vm¿¡¼­ ½º³À¼¦À» ÂïÀ¸½ÅÈÄ
http://www.exploit-db.com/exploits/3/
¿©±âÀÖ´Â ÀͽºÇ÷ÎÀÕÀ» ÄÄÆÄÀÏÇÏ°í ½ÇÇà½ÃŰ½Å ÈÄ
mkdir /home/xassult; echo "xassult::0:0:xassult:/home/xassult:/bin/bash" >> /etc/passwd
¸¦ ±×´ë·Î Ä¡½Ã°í ·Î±×ÀÎÀ» Á¾·áÇϽÅÈÄ
localhost login: ºÎºÐ¿¡¼­
xassult ¶ó°í Ä¡½Ã¸é ·çÆ®±ÇÇÑÀ¸·Î Á¢¼Ó µÇ½Ê´Ï´Ù
¿©±â¼­ ·çÆ® ºñ¹øÀ» º¯°æÇϽðųª ±×³É xassult °èÁ¤À¸·Î Á¢¼ÓÇϽø鼭 »ç¿ëÇÏ½Ã¸é µË´Ï´Ù

¾ÆÀ̵ð root ºñ¹ø hackerschool·Î Á¢¼ÓÀÌ µÇ½Ã¸é ±»ÀÌ ÀͽºÇ÷ÎÀÕÀº ¾È¾²¼ÅµµµË´Ï´Ù
2012/09/25  
xassault °¨»çÇÕ´Ï´Ù ÀÌÁ¦ µÇ³×¿ä...^^ 2012/09/26  
cd80 ´ÙÇàÀÔ´Ï´Ù ¿­°øÇϼ¼¿ä ¤¾_¤¾ 2012/09/26  
     [°øÁö]ÇØÄ¿½ºÄð ÀÌ¿ë¼öÄ¢ 2021/04/11 ¼öÁ¤ÆÇ [54] ÇѽÂÀç 01/05 11604
22018   À¸¾Ó!!![1]     ÇØÅ·ÀßÇϰí½Í´Ù
02/05 36
22017   A¤¿...     ÇØÅ·ÀßÇϰí½Í´Ù
01/27 86
22016   ¿À·£¸¸~     DarkSlayer
12/11 270
22015   ÇØÄ¿½ºÄð ¿¾³¯ BGM[1]     wkfhddl4041
11/07 416
22014   È÷À×...     ÇØÅ·ÀßÇϰí½Í´Ù
11/02 337
22013   ¹ÙµÏ°ú Àå±â     ÇØÅ·ÀßÇϰí½Í´Ù
10/30 371
22012   ³ª´Â ¾ðÁ¦ ¾ÖÀÎÀÌ »ý±â³ª¿è...     ÇØÅ·ÀßÇϰí½Í´Ù
10/27 427
22011   Àü±¹ 1À§     ÇØÅ·ÀßÇϰí½Í´Ù
10/27 377
22010   ´ã¹è ¤»¤»[1]     ÇØÅ·ÀßÇϰí½Í´Ù
10/27 385
22009   ¸ÅÆ®¸¯½ºÀÇ ÆÄ¶õ¾àÀ» ¾Æ½Ê´Ï±î..?     ÇØÅ·ÀßÇϰí½Í´Ù
10/27 367
22008   ¤·¤·[1]     ÇØÅ·ÀßÇϰí½Í´Ù
10/20 357
22007   ¿ÉÄ¡ ÇÙ°¨Áö ÇÁ·Î±×·¥Á» ¸¸µé¾îÁÖ¼¼¿ä[1]     powerima
10/15 360
22006   ÇØÅ·ÆÀ¿ø ¸ðÁý[1]     koromoon
08/27 884
22005   °°ÀÌ ÇØÅ· ÆÀ ÀÌ·ç½ÇºÐ??     hacs98
08/26 572
22004   ¾Æ........ ¤Ð¤Ð     ÇØÅ·ÀßÇϰí½Í´Ù
08/04 728
22003   ±Í¼ö(Сâ¢) µû¶óÇϱâ(?)     ÇØÅ·ÀßÇϰí½Í´Ù
07/28 718
22002   ½º½º·Î ¸ñ¼ûÀ» Á®¹ö¸°´Ù´Â °ÍÀº     ÇØÅ·ÀßÇϰí½Í´Ù
07/27 748
22001   ¹ÌÄ£µí     ÇØÅ·ÀßÇϰí½Í´Ù
07/02 803
22000   »ç¹«½Ç     ÇØÅ·ÀßÇϰí½Í´Ù
07/02 740
1 [2][3][4][5][6][7][8][9][10]..[1101]

Copyright 1999-2026 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org