·¹º§ ÇØÅ·

 2844, 3/143 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   muzen2540
   [re] ·¹º§4°¡ ÀÌÇØ°¡ ¾ÈµÅ¿ä..

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_level&no=52 [º¹»ç]


vngkgkx ´ÔÀÇ Áú¹®ÀÌ Àß ÀÌÇØ°¡ ¾ÈµÇ¼­... (ºØµÎ ¹ÂÁ¨!)

¹Ì¾àÇÑ ½Ç·ÂÀ̳ª¸¶ º¸ÅÆÀÌ µÇ°íÀÚ-
·¹º§ 4¿¡ ´ëÇؼ­ ¼³¸íÀ» µå¸®·Á°í ÇÕ´Ï´Ù-

Á¦°¡ Áö±Ý ¼³¸íÇϴµ¥¿¡ ¸ð¸£´Â ´Ü¾î°¡ ÀÖ´Ù¸é ¹Ù·Î¹Ù·Î °Ë»öÇϼż­ ¾Ë¾Æ³»½Ã±¸¿ä
(±×°Ô °øºÎÀÔ´Ï´Ù :)~ )
°Ë»öÇصµ ¾ø´Ù¸é? ´Ù½Ã Áú¹®~ ÀÌ µÇ°Ú½À´Ï´Ù :)

·¹º§4´Â ÈùÆ®ÆÄÀÏÀ» ºÁµµ ¾Æ½Ã°ÚÁö¸¸

[level4@ftz level4]$ cat hint


´©±º°¡ /etc/xinetd.d/¿¡ ¹éµµ¾î¸¦ ½É¾î³õ¾Ò´Ù.!

¹éµµ¾î ¹®Á¦À̱º¿ä...
¹éµµ¾î´Â ½±°Ô ¸»Çؼ­..
ÇØÄ¿°¡ Ÿ°Ù ¼­¹ö¸¦ ¸Ô¾úÀ»¶§
³ªÁß¿¡ ´Ù½Ã µé¾î¿À±â ½±°Ô ¸¸µé¾î³õÀº µÞ±¸¸Û °°Àº°ÍÀÔ´Ï´Ù.
ÀÌ ¹®Á¦´Â ·çÆ®ÀÇ ±ÇÇÑÀ¸·Î  
xinetd.d µð·º¿¡ ·çÆ®ÀÇ ±ÇÇÑÀ¸·Î ¹éµµ¾îÀÇ ¼³Á¤ ÆÄÀÏÀÌ ¸¸µé¾îÁ® ÀÖ±¸¿ä
¼³Á¤ ÆÄÀÏ´ë·Î user level5¿¡ finger¸¦ º¸³»¸ç ¼³Á¤ÆÄÀÏÀÇ ¼­¹ö°æ·Î¿¡´Ù°¡ ¹éµµ¾î¸¦ ¸¸µé¾îÁÖ°í
Á¢¼ÓÇÏ´Â ¹®Á¦ÀÔ´Ï´Ù.

service finger
{
        disable = no
        flags           = REUSE
        socket_type     = stream
        wait            = no
        user            = level5
        server          = /home/level4/tmp/backdoor
        log_on_failure  += USERID
}

¿©±â ´Ù ³ª¿ÍÀÖÁö¿ä?

/etc/xinetd.d ¶ó´Â µð·ºÅ丮´Â... inet ¼­ºñ½º¸¦ Á¦°øÇÏ´Â µð·ºÅ丮ÀÔ´Ï´Ù
Ŭ¶óÀ̾ðÆ®·ÎºÎÅÍ ³×Æ®¿÷Á¢¼ÓÀÌ ÀÌ·ç¾îÁö¸é ¸ÕÀú inet µ¥¸óÀÌ ¸ðµç Á¢¼ÓÀ» °¨ÁöÇÏ´Â
°ÍÀÌÁö¿ë.. (µ¥¸óÀÌ ¹ºÁö ¸ð¸£¼¼¿ä? ±×·¸´Ù¸é °Ë»ö!)
Stand alone À̶ó´Â ¹æ½ÄÀ» ¾Æ½Ã´ÂÁö¿ä...
ÀÌ°Ç Á¦°¡ ¸»¾¸µå¸®°Ú½À´Ï´Ù.. µ¥¸óÀ» °Ë»öÇؼ­ ¾Æ¼Ì´Ù¸é.
stand alone Àº.. 24½Ã°£ °è~~~¼Ó~ µ¥¸óÀ» µ¹¸®´Â ¹æ½ÄÀÔ´Ï´Ù..
telnet Àº telnet ´ë·Î~ web Àº web´ë·Î` ftp ´Â ftp´ë·Î~
ssh ´Â ssh´ë·Î~ µîµî ¸ðµç ´ë¸óµéÀÌ 24½Ã°£ Ŭ¶óÀ̾ðÆ®°¡ ¿äûÇϱ⸸À»
´«À» ²û»¶ ²û»¶ °Å¸®¸é¼­ ±â´Ù¸®°í ÀÖ½À´Ï´Ù.

µ¥¸óµéÀÇ Ã¼·ÂÀº ¼­¹öÀÇ Èû;
À§¿Í °°Àº ÁþÀº... ¸Þ¸ð¸® ³¶ºñÀÇ Áö¸§±æÀÌÁö¿ä...

±×·¡¼­ inet ÀÌ Å¾½À´Ï´Ù.
ÀÌ inet¶ÇÇÑ µ¥¸óÀÔ´Ï´Ù.. 24½Ã°£ È¥ÀÚ µ¹¾Æ°¡Áö¿ë...
±×¸®°í ÇÒÀϾø´Â µ¥¸óµéÀº ¸ðµÎ ÀáÀ» Àç¿ó´Ï´Ù. sleep
±×·¯°í ÀÖ´Ù°¡(?) Ŭ¶óÀ̾ðÆ®¿¡°Ô¼­ µ¥¸ó¿äûÀÌ µé¾î¿À¸é
inet ÀÌ ¸ÕÀú ±×°ÍÀ» °¨ÁöÇÏ°í (listening)
inetÀº ¿äûÇÑ µ¥¸ó¿¡°Ô ÈÄ´Ù´Ú ¶Ù¾î°¡¼­~
"ÀϾ ÀÌÀÚ½Ä¾Æ ¼Õ´ÔÀÌ¾ß ¤±_¤±+"
¶ó°í Çϸç ÀáÀÚ°í ÀÖ´Â µ¥¸óÀ» Èçµé¾î ±ú¿ì°í..

±× µ¥¸óÀº "À½³Ä.. ¼Õ´ÔÀ̳×~" Çϸç
Ŭ¶óÀ̾ðÆ®¿¡°Ô ¿äû¹ÞÀº ÀÏÀ» ´Ù ÇÏ°í ´Ù½Ã inet ¿¡ ÀÇÇØ ÀáÀÌ µì´Ï´Ù~
...
...
...


±×·±µ¥ ±×·± xinetd.d µð·ºÅ丮¿¡ backdoor ¼³Á¤ ÆÄÀÏÀÌ Àֳ׿ä
finger service ¸¦ ÇÑ´Ù°í Çϴ±º¿©
user level5 ±ÇÇÑÀÌ°í...
server °æ·Î´Â /home/level4/tmp/backdoor À̱¸¿ë
disable ÀÌ no ÀÌ´Ï inet ÀÇ Á¦¾î¸¦ ¹Þ°í.. µ¿ÀÛÀ» ÇÏÁö¿ä

disable ÀÌ no ·Î ¼³Á¤ÇÏ¸é µ¿ÀÛÀ» ÇÏ°í
yes ·Î ¼³Á¤ÇÏ¸é µ¿ÀÛÀ» ÇÏÁö ¾Ê´Â´Ù´Â °ÍÀÔ´Ï´Ù.

finger ¼­ºñ½º¶õ
´©°¡ ½Ã½ºÅÛÀ» »ç¿ëÇÏ°í ÀÖ´ÂÁö¸¦ ¾Ë ¼ö ÀÖ´Â ¸í·É¾îÀÔ´Ï´Ù.
finger @È£½ºÆ®¸í ÀÌÁö¿ë ÀÌ°ÅÇÏ°í ºñ½ÁÇÑ ¸í·É¾î´Â Àͼ÷ÇϽǼöµµ ÀÖ´Â..
ping ÀÔ´Ï´Ù.. ¾µµ¥ ¾ø°ÚÁö¸¸ ¼³¸íµå¸®ÀÚ¸é.
pingÀº ¾Ë°íÀÚ ÇÏ´Â ½Ã½ºÅÛÀÌ µ¿ÀÛÁßÀΰ¡¸¦ ¾Ë ¼ö ÀÖ´Â ¸í·É¾îÀÌÁö¿ä.

¾îÂîµÆµç /etc/services ¸¦ º¸½Ã¸é.
finger °¢ µ¥¸óµéÀÇ Æ÷Æ®°¡ ³ª¿Í ÀÖ±¸¿ä

¹éµµ¾î ¼­¹ö °æ·Î¿¡ ¹éµµ¾î°¡ ¾ø´Ù¸é ¸¸µé°í
Á¢¼ÓÀ» ÇÏ¸é µÇ´Â ¹®Á¦ÀÔ´Ï´Ù.

Ȥ½Ã Á¦°¡ ¹º°¡ Ʋ¸°°Ô ÀÖ´Ù¸é
±ÍÂúÀ¸½Ã´õ¶óµµ ²À ´äº¯À» ÁÖ¼¼¿ä
Àúµµ °øºÎ¸¦ ÇØ¾ß µÇ°Åµç¿ä ¤Ð_¤Ð

±×·³ ¼ö°íÇϼ¼¿ä~

  Hit : 5657     Date : 2003/09/07 11:27



    
cksrnrkd level3 2003/09/12  
kooki Çæ 2003/09/17  
cjssus48wn ·¹º§5 2003/11/02  
alwaystrike level3 2004/07/26  
parkjh888 ½É°¢ÇÏ°Ô º¸´Ù°¡ "ÀϾ ÀÌÀÚ½Ä¾Æ ¤±_¤±+" ÇѸ¶µð¿¡ ÇǽÄ;;¤¾ °¨»çÇÕ´Ï´Ù~ 2007/01/16  
2804   localhost¿Í /bin/bash ¿¡ ´ëÇØ Á» ÀÚ¼¼È÷ ¼³¸íÁ»...[4]     dangjang
09/06 3177
2803   ·¹º§¾÷ ÇÒ¶§¿ä[2]     comdoctor2001-7
09/06 3078
2802   ·¹º§ 1 Áú¹®~~[5]     crazynut486
09/06 3648
2801   ·¹º§4°¡ ÀÌÇØ°¡ ¾ÈµÅ¿ä..     vngkgkx
09/06 3511
    [re] ·¹º§4°¡ ÀÌÇØ°¡ ¾ÈµÅ¿ä..[5]     muzen2540
09/07 5656
2799       Ä£ÀýÇѴ亯 Á¤¸» °¨»çÇÕ´Ï´Ù^^;     vngkgkx
09/07 4270
2798         [re] Ä£ÀýÇѴ亯 Á¤¸» °¨»çÇÕ´Ï´Ù^^;     muzen2540
09/12 2665
2797   ·¹º§ 3 ¿¡¼­¿ä ã±â ÇÑÈÄ /bin/autodig ³ª¿À´Âµ¥ ±×´ã ¾î¶»°Ô ÇØ¿ä? ½ÇÇàÇÏ¸é ´Ù¸¥°Å ³ª¿À´øµ¥..[2]     tjddbs6621
09/06 3657
2796   ·¹º§8¿¡¼­....[6]     a2pjin
09/07 4166
2795     [re] ·¹º§8¿¡¼­....[2]     a2pjin
09/08 3768
2794   ¤Ì¤Ì¾î¶»°Ô ÇÏÁ®;;[4]     yeari
09/07 3129
2793   ºñ¹Ð¹øÈ£ ºÐ½Ç°Ç.[3]     hsw5757
09/07 3004
2792   ·¹º§2¿¡¼­...[4]     dnjswowkd
09/07 3404
2791   ·¹º§1À̼­¿ä..[4]     Jamak
09/07 3686
2790   ·¹º§1.... µµ¿ÍÁÖ¼¼¿© ¤Ñ_¤Ñ;[2]     leejho21c
09/07 3437
2789   Áø¤¹¤¤ ¸øÇؼ­ ±×·¯´Âµ¥¿ä.[4]     tkddmfl
09/07 3220
2788   ¹®Á¦°¡ ¾îµðÀÖ³ª¿ä...[2]     omegasox
09/07 3098
2787   level2 Áú¹®!!!![1]     slyfiox2
09/07 3690
2786   Çä! ·¹º§2·Î ¾î¶»°Ô ³Ñ¾î°¡ÁÒ?[1]     akboy1
09/07 3612
2785     [re] Çä! ·¹º§2·Î ¾î¶»°Ô ³Ñ¾î°¡ÁÒ?     hkpco
09/07 3101
[1][2] 3 [4][5][6][7][8][9][10]..[143]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org