·¹º§ ÇØÅ·

 2844, 1/143 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   muzen2540
   [re] ·¹º§4°¡ ÀÌÇØ°¡ ¾ÈµÅ¿ä..

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_level&no=52 [º¹»ç]


vngkgkx ´ÔÀÇ Áú¹®ÀÌ Àß ÀÌÇØ°¡ ¾ÈµÇ¼­... (ºØµÎ ¹ÂÁ¨!)

¹Ì¾àÇÑ ½Ç·ÂÀ̳ª¸¶ º¸ÅÆÀÌ µÇ°íÀÚ-
·¹º§ 4¿¡ ´ëÇؼ­ ¼³¸íÀ» µå¸®·Á°í ÇÕ´Ï´Ù-

Á¦°¡ Áö±Ý ¼³¸íÇϴµ¥¿¡ ¸ð¸£´Â ´Ü¾î°¡ ÀÖ´Ù¸é ¹Ù·Î¹Ù·Î °Ë»öÇϼż­ ¾Ë¾Æ³»½Ã±¸¿ä
(±×°Ô °øºÎÀÔ´Ï´Ù :)~ )
°Ë»öÇصµ ¾ø´Ù¸é? ´Ù½Ã Áú¹®~ ÀÌ µÇ°Ú½À´Ï´Ù :)

·¹º§4´Â ÈùÆ®ÆÄÀÏÀ» ºÁµµ ¾Æ½Ã°ÚÁö¸¸

[level4@ftz level4]$ cat hint


´©±º°¡ /etc/xinetd.d/¿¡ ¹éµµ¾î¸¦ ½É¾î³õ¾Ò´Ù.!

¹éµµ¾î ¹®Á¦À̱º¿ä...
¹éµµ¾î´Â ½±°Ô ¸»Çؼ­..
ÇØÄ¿°¡ Ÿ°Ù ¼­¹ö¸¦ ¸Ô¾úÀ»¶§
³ªÁß¿¡ ´Ù½Ã µé¾î¿À±â ½±°Ô ¸¸µé¾î³õÀº µÞ±¸¸Û °°Àº°ÍÀÔ´Ï´Ù.
ÀÌ ¹®Á¦´Â ·çÆ®ÀÇ ±ÇÇÑÀ¸·Î  
xinetd.d µð·º¿¡ ·çÆ®ÀÇ ±ÇÇÑÀ¸·Î ¹éµµ¾îÀÇ ¼³Á¤ ÆÄÀÏÀÌ ¸¸µé¾îÁ® ÀÖ±¸¿ä
¼³Á¤ ÆÄÀÏ´ë·Î user level5¿¡ finger¸¦ º¸³»¸ç ¼³Á¤ÆÄÀÏÀÇ ¼­¹ö°æ·Î¿¡´Ù°¡ ¹éµµ¾î¸¦ ¸¸µé¾îÁÖ°í
Á¢¼ÓÇÏ´Â ¹®Á¦ÀÔ´Ï´Ù.

service finger
{
        disable = no
        flags           = REUSE
        socket_type     = stream
        wait            = no
        user            = level5
        server          = /home/level4/tmp/backdoor
        log_on_failure  += USERID
}

¿©±â ´Ù ³ª¿ÍÀÖÁö¿ä?

/etc/xinetd.d ¶ó´Â µð·ºÅ丮´Â... inet ¼­ºñ½º¸¦ Á¦°øÇÏ´Â µð·ºÅ丮ÀÔ´Ï´Ù
Ŭ¶óÀ̾ðÆ®·ÎºÎÅÍ ³×Æ®¿÷Á¢¼ÓÀÌ ÀÌ·ç¾îÁö¸é ¸ÕÀú inet µ¥¸óÀÌ ¸ðµç Á¢¼ÓÀ» °¨ÁöÇÏ´Â
°ÍÀÌÁö¿ë.. (µ¥¸óÀÌ ¹ºÁö ¸ð¸£¼¼¿ä? ±×·¸´Ù¸é °Ë»ö!)
Stand alone À̶ó´Â ¹æ½ÄÀ» ¾Æ½Ã´ÂÁö¿ä...
ÀÌ°Ç Á¦°¡ ¸»¾¸µå¸®°Ú½À´Ï´Ù.. µ¥¸óÀ» °Ë»öÇؼ­ ¾Æ¼Ì´Ù¸é.
stand alone Àº.. 24½Ã°£ °è~~~¼Ó~ µ¥¸óÀ» µ¹¸®´Â ¹æ½ÄÀÔ´Ï´Ù..
telnet Àº telnet ´ë·Î~ web Àº web´ë·Î` ftp ´Â ftp´ë·Î~
ssh ´Â ssh´ë·Î~ µîµî ¸ðµç ´ë¸óµéÀÌ 24½Ã°£ Ŭ¶óÀ̾ðÆ®°¡ ¿äûÇϱ⸸À»
´«À» ²û»¶ ²û»¶ °Å¸®¸é¼­ ±â´Ù¸®°í ÀÖ½À´Ï´Ù.

µ¥¸óµéÀÇ Ã¼·ÂÀº ¼­¹öÀÇ Èû;
À§¿Í °°Àº ÁþÀº... ¸Þ¸ð¸® ³¶ºñÀÇ Áö¸§±æÀÌÁö¿ä...

±×·¡¼­ inet ÀÌ Å¾½À´Ï´Ù.
ÀÌ inet¶ÇÇÑ µ¥¸óÀÔ´Ï´Ù.. 24½Ã°£ È¥ÀÚ µ¹¾Æ°¡Áö¿ë...
±×¸®°í ÇÒÀϾø´Â µ¥¸óµéÀº ¸ðµÎ ÀáÀ» Àç¿ó´Ï´Ù. sleep
±×·¯°í ÀÖ´Ù°¡(?) Ŭ¶óÀ̾ðÆ®¿¡°Ô¼­ µ¥¸ó¿äûÀÌ µé¾î¿À¸é
inet ÀÌ ¸ÕÀú ±×°ÍÀ» °¨ÁöÇÏ°í (listening)
inetÀº ¿äûÇÑ µ¥¸ó¿¡°Ô ÈÄ´Ù´Ú ¶Ù¾î°¡¼­~
"ÀϾ ÀÌÀÚ½Ä¾Æ ¼Õ´ÔÀÌ¾ß ¤±_¤±+"
¶ó°í Çϸç ÀáÀÚ°í ÀÖ´Â µ¥¸óÀ» Èçµé¾î ±ú¿ì°í..

±× µ¥¸óÀº "À½³Ä.. ¼Õ´ÔÀ̳×~" Çϸç
Ŭ¶óÀ̾ðÆ®¿¡°Ô ¿äû¹ÞÀº ÀÏÀ» ´Ù ÇÏ°í ´Ù½Ã inet ¿¡ ÀÇÇØ ÀáÀÌ µì´Ï´Ù~
...
...
...


±×·±µ¥ ±×·± xinetd.d µð·ºÅ丮¿¡ backdoor ¼³Á¤ ÆÄÀÏÀÌ Àֳ׿ä
finger service ¸¦ ÇÑ´Ù°í Çϴ±º¿©
user level5 ±ÇÇÑÀÌ°í...
server °æ·Î´Â /home/level4/tmp/backdoor À̱¸¿ë
disable ÀÌ no ÀÌ´Ï inet ÀÇ Á¦¾î¸¦ ¹Þ°í.. µ¿ÀÛÀ» ÇÏÁö¿ä

disable ÀÌ no ·Î ¼³Á¤ÇÏ¸é µ¿ÀÛÀ» ÇÏ°í
yes ·Î ¼³Á¤ÇÏ¸é µ¿ÀÛÀ» ÇÏÁö ¾Ê´Â´Ù´Â °ÍÀÔ´Ï´Ù.

finger ¼­ºñ½º¶õ
´©°¡ ½Ã½ºÅÛÀ» »ç¿ëÇÏ°í ÀÖ´ÂÁö¸¦ ¾Ë ¼ö ÀÖ´Â ¸í·É¾îÀÔ´Ï´Ù.
finger @È£½ºÆ®¸í ÀÌÁö¿ë ÀÌ°ÅÇÏ°í ºñ½ÁÇÑ ¸í·É¾î´Â Àͼ÷ÇϽǼöµµ ÀÖ´Â..
ping ÀÔ´Ï´Ù.. ¾µµ¥ ¾ø°ÚÁö¸¸ ¼³¸íµå¸®ÀÚ¸é.
pingÀº ¾Ë°íÀÚ ÇÏ´Â ½Ã½ºÅÛÀÌ µ¿ÀÛÁßÀΰ¡¸¦ ¾Ë ¼ö ÀÖ´Â ¸í·É¾îÀÌÁö¿ä.

¾îÂîµÆµç /etc/services ¸¦ º¸½Ã¸é.
finger °¢ µ¥¸óµéÀÇ Æ÷Æ®°¡ ³ª¿Í ÀÖ±¸¿ä

¹éµµ¾î ¼­¹ö °æ·Î¿¡ ¹éµµ¾î°¡ ¾ø´Ù¸é ¸¸µé°í
Á¢¼ÓÀ» ÇÏ¸é µÇ´Â ¹®Á¦ÀÔ´Ï´Ù.

Ȥ½Ã Á¦°¡ ¹º°¡ Ʋ¸°°Ô ÀÖ´Ù¸é
±ÍÂúÀ¸½Ã´õ¶óµµ ²À ´äº¯À» ÁÖ¼¼¿ä
Àúµµ °øºÎ¸¦ ÇØ¾ß µÇ°Åµç¿ä ¤Ð_¤Ð

±×·³ ¼ö°íÇϼ¼¿ä~

  Hit : 5641     Date : 2003/09/07 11:27



    
cksrnrkd level3 2003/09/12  
kooki Çæ 2003/09/17  
cjssus48wn ·¹º§5 2003/11/02  
alwaystrike level3 2004/07/26  
parkjh888 ½É°¢ÇÏ°Ô º¸´Ù°¡ "ÀϾ ÀÌÀÚ½Ä¾Æ ¤±_¤±+" ÇѸ¶µð¿¡ ÇǽÄ;;¤¾ °¨»çÇÕ´Ï´Ù~ 2007/01/16  
2844   Æ÷Æ®23 ¿¬°áÇÏÁö ¸øÇß½À´Ï´Ù.[7]     ¶ß°Å¿îīǪġ³ë
09/07 11877
2843   level1 Á¢¼ÓÇÏ´Â ¹æ¹ý[2]     ¾ÓÀ׿Ë
07/27 8363
2842   Á¸´õ¸®ÆÛ »ç¿ë¹ý °¥ÄÑÁÖ¼¼¿ä...À©µµ¿ì¿ë..[1]     78jeongho
10/18 7554
2841   È£½ºÆ®¿¡´ëÇÑ¿¬°áÀ»ÀÒ¾ú½À´Ï´Ù.[3]     vxvx44
10/08 6837
2840   ·¹º§8 ÈùÆ® level8 ...UpDate 03.11.19[10]     bigfood
10/01 6771
2839   ¿£ÇÁ·ÎÅØÆ® Áú¹®ÀÔ´Ï´Ù.[1]     tyu1023
11/16 6618
2838   ·¹º§3 level3 ÈùÆ®...(2)[4]     bigfood
09/15 6057
2837   ·¹º§4 level4 ÈùÆ®...UPDATE 03.10.01[10]     bigfood
09/15 6029
2836     [re] ¿Ö find Çϸé Çã°¡ °ÅºÎµÊÀÌ ¶ßÁÒ?[3]     qkreoghks00
03/14 6001
2835   gdb°¡ µ¿ÀÛÇÏÁö¾Ê½À´Ï´Ù.[5]     dlddu
08/05 5999
2834     [re] shellcode ¾îÂî ¸¸µé¾î¾ß Çմϱî?[6]     hackermario
11/25 5966
2833   level1 Ŭ¸®¾î ÇÒ¼ö ÀÖ°Ô ÈùÆ®Á» ÁÖ¼¼¿ä[9]     wormes
09/02 5888
2832   webhacking.kr 21¹ø ¹®Á¦[1]     jaewonm
07/11 5833
2831   Level1~3°ø·«(ÀÏÁ¾ÀÇ ÈùÆ®)[3]     sbshs77
06/18 5737
2830   Debian putty SSH¿¡¼­ Çѱ۱úÁü     dominvs
08/15 5706
2829   °ü¸®ÀÚ ÆäÀÌÁö ã±â[2]     jxpl80
11/18 5681
2828   ·¹º§3 level3 ÈùÆ®...(1)[2]     bigfood
09/15 5651
2827     [re] level5 ¿¡¼­,¤Ð¤Ð     ¼Û½Ã
10/31 5648
    [re] ·¹º§4°¡ ÀÌÇØ°¡ ¾ÈµÅ¿ä..[5]     muzen2540
09/07 5640
2825   ftz¸¦ ½ÇÇà => cmd·Î Çߴµ¥µµ[10]     3609ÇØÄ¿
10/27 5469
1 [2][3][4][5][6][7][8][9][10]..[143]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org