·¹º§ ÇØÅ·

 2844, 10/143 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   kjs90
   level4¿¡ °üÇϼ­ ¤Ð¤Ð ºÎŹµå·Á¿ä

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_level&no=3143 [º¹»ç]


¿¹ ¸»±×´ë·Î level4¿¡ °üÇÏ¿© Áú¹®µå¸³´Ï´Ù.

¸¶Áö¸·ºÎºÐÀÌ ³­ÇØÇؼ­ Áú¹®µå¸³´Ï´Ù.

¿ì¼±

1. finger ¸í·É¿¡¼­ ÀÎÅÍ³Ý ½´ÆÛµ¥¸óÀ» °ÅÄ¡´À³Ä ¾È°ÅÄ¡´À³Ä
(disableÀÌ no³Ä yes³Ä)
¿¡ µû¶ó¼­ backdoor¸¦ ½ÇÇàÇÏ°í ¾ÈÇϴ°ÍÀº ¾Ë°Ú½À´Ï´Ù.
ÀÎÅÍ³Ý ½´ÆÛµ¥¸óÀ» °ÅÄ¡´Â ±âÁØÀÌ ¹«¾ùÀΰ¡¿ä?

¿Ö È£½ºÆ®¸¦ Àû¾îÁÖ¾úÀ» ¶§¸¸ ÀÎÅÍ³Ý ½´ÆÛµ¥¸óÀ» °ÅÄ¡°Ô µÇ´ÂÁö Àß ÀÌÇØ°¡ ¾È°©´Ï´Ù.


2. À̶§ finger ÀÌ¿ëÇؼ­  backdoor¸¦ ½ÇÇàÇÒ¶§. user id°¡ level5°¡ µÇÀݾƿä? ÀÌ°Ô ½ÇÁ¦·Î ¾ÆÀ̵𰡠level5ÀÎÁö ±ÇÇÑÀÌ level5ÀÎÁö Çò°¥¸³´Ï´Ù.

3. ¿©Â÷¿©Â÷Çؼ­ finger¸í·ÉÀ» ÀÌ¿ëÇؼ­ backdoor¸¦ ½ÇÇàÇÏ°Ô µÇ¾ú½À´Ï´Ù.
Á¤È®È÷ ¸»Çϸé /home/level4/tmp/backdoor ÆÄÀÏÀ» ½ÇÇàÇϵµ·Ï ÇÏ´Â °ÍÀÌ°ÚÁö¿ä
¿©±â¼­ µÎ°¡ÁöÀÇ °æ¿ì¸¦ ÀÛ¼ºÇß½À´Ï´Ù.

int main()
{
   system("my-pass");
}
  (ÀÛµ¿ ÇÔ)

int main()
{
   system("/bin/bash");
}
  (ÀÛµ¿ ¾ÈÇÔ)

½©½ºÅ©¸³Æ®

#!/bin/bash
    (ÀÛµ¿ ¾ÈÇÔ  .... ¿©±â¼­ level5½©À» ¹Ù·Î µþ¼ö ÀÖÀ»ÁÙ ¾Ë¾Ñ´Âµ¥ ¾ÈµÇ´õ±º¿ä)

#!/bin/bash
#my-pass
   (ÀÛµ¿¾ÈÇÔ)


°¢°¢ÀÇ °æ¿ì¿¡ ´ëÇؼ­ ¿Ö ÀÛµ¿À» ¾ÈÇÒ±î¿ä? ¤Ð¤Ð


Áú¹®ÀÌ ¸¹ÁÒ? ¤Ð¤Ð ºÎŹµå¸±²²¿ä


  Hit : 2304     Date : 2010/09/07 01:13



    
kjs90 ¶Ç systemÇÔ¼ö¸¦ ÀÌ¿ëÇѹæ½ÄÀ¸·Î id¸í·É¾î¶û whoami¸¦ «‰´õ´Ï Á» ÀÌ»óÇÏ´õ±º¿ä...

idÄ¡¸é

uid = level5 gid level5 ±îÁö¸¸ ³ª¿À°í groupÀÌ Áõ¹ßÇعö¸®³×¿© ¤»¤»
2010/09/07  
2664   webhacking.kr ¹®Á¦ Áú¹®ÀÔ´Ï´Ù.[3]     kodeungeo
09/08 2588
  level4¿¡ °üÇϼ­ ¤Ð¤Ð ºÎŹµå·Á¿ä[1]     kjs90
09/07 2303
2662   level4[1]     dkflvkdnj
08/31 2771
2661   level20 ¹®Á¦....[4]     Crusius
08/31 2619
2660   Level4¿¡¼­ Áú¹®¿ä~~~[3]     fogbow0406
08/29 2265
2659   ³Ê¹« ¾ï¿ïÇÏ°í ºÐÅëÇÕ´Ï´Ù!..µµ¿ÍÁÖ¼¼¿©!![1]     ck1235
08/29 2652
2658   Æ÷Æ®23[3]     lodtkr024
08/27 2428
2657   Æ®·¹À̳Ê2¿¡¼­...[3]     lodtkr024
08/26 2397
2656   ¹öÆÛ¿À¹öÇ÷ο츻ÀÔ´Ï´Ù.[2]     deltaforce
08/25 2569
2655   ȸ¿øÁ¤º¸¿¡¼­ ftz ·¹º§Áú¹®[2]     V@luE
08/19 2398
2654   cpu »ç¿ë·ü ³ôÀº°Ô ÁÁÀº°Ç°¡¿ä ?[5]     ÇØÄ¿¿õ»ïÀÌ
08/18 3405
2653   MiniCTF level4 Áú¹®ÀÔ´Ï´Ù[3]     june4145
08/18 2380
2652   ·¹º§1°ú ´Ù¸¥ ·¹º§ÀÇ Â÷ÀÌÁ¡...[1]     jin1055
08/18 2321
2651   Àç Áú¹®ÇÒ²²¿ä ¤Ð¤Ð[3]     xodnr631
08/18 2868
2650   ÇØÄð Level9 Çϳª ¹°¾îº¼²²¿ä[5]     xodnr631
08/17 3305
2649   ¹öÆÛ ¿À¹öÇÃ·Î¿ì °­Á ´Ùº¸·Á¸é ¾î¶»°Ô ÇؾßÇϳª¿ä?[1]     hrgem
08/16 2855
2648   ¸®´ª½º·Î ÇÏ°íÀִµ¥, ÇѱÛÀÌ ¾È ÃÄÁö³×¿ä[2]     xodnr631
08/16 2860
2647   Æ®·¹ÀÌ´× 2´Ü°è, ÅÚ³Ý »ç¿ë¹æ¹ý¿¡ °üÇØ ¹®ÀÇÇÕ´Ï´Ù.[4]     xodnr631
08/16 2676
2646   ¹æ±ÝÀü¿¡ level1À» Ŭ¸®¾î Çß½À´Ï´Ù.[4]     jh31829
08/15 2509
2645   telnet Á¢¼ÓÇÒ¶§¿ä.[3]     l3m0n-tr33
08/15 2443
[1][2][3][4][5][6][7][8][9] 10 ..[143]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org