·¹º§ ÇØÅ·

 2844, 6/143 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   Mastel
   level4 ¸¦ ¾ó¶³°á¿¡ ²£½À´Ï´Ù. Áö½ÄÀ» ³ª´²ÁÖ¼¼¿ä ¤Ð¤Ð

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_level&no=3225 [º¹»ç]


Á¶±Ý ±é´Ï´Ù. Á˼ÛÇÕ´Ï´Ù. µµ¿ÍÁÖ¼¼¿ä. °Ë»öÀ» Á» ÇغÁµµ Á¦°¡ ¿øÇÏ´Â ´äÀ» ±¸Çϱâ Èûµé´õ±º¿ä ¤Ð


Àü óÀ½¿¡ ¹®Á¦¸¦ ²£À» ¶§ finger ¼­ºñ½º°¡ ÀÌ¹Ì standalone »óÅ·Π½ÇÇàµÇ°í ÀÖ°í
°Å±â¼­ finger @localhost À» ½ÇÇàÇÏ¸é ¼öÆÛµ¥¸óÀ» ÅëÇؼ­ finger°¡ ´Ù½Ã ÀÛµ¿Çؼ­
¼­¹ö¿¡ Á¢±ÙÇÏ·Á ÇÏ´Ï backdoor(my-pass) ¸¦ level5 ±ÇÇÑÀ¸·Î ½ÇÇàÇÏ°Ô µÇ¾î¼­ ÇØ°áµÇ´Â ÁÙ ¾Ë¾Ò½À´Ï´Ù.
(ÇöÀçµµ ¼ÖÁ÷È÷ Á» Çò±ò¸³´Ï´Ù.)

±Ùµ¥ ±×·¸°Ô »ý°¢ÇÏ¸é ¹º°¡ ¸»ÀÌ ¾ÈµÇ´õ±º¿ä.

±×·¡¼­ finger ¼­ºñ½º°¡ standalone »óÅ·Π½ÇÇàµÇ°í ÀÖ´Ù´Â °Ç ¾Æ´Ï¶ó°í ´ÜÁ¤Áö¾î¹ö·È½À´Ï´Ù;

finger À¯Àú@localhost ¶ó°í Ä¡¸é localhost ÀÚ°ÝÀ¸·Î(?) À¯ÀúÀÇ Á¤º¸¸¦ ã±â À§ÇØ ¼­¹ö¿¡ Á¢±ÙÇؼ­(true) Á¤º¸¸¦ Ãâ·ÂÇϱâ À§ÇØ backdoor(my-pass) ¿¡ Á¢±ÙÇÏ°í localhost ÀÚ°ÝÀ¸·Î level5 ÀÇ my-pass°¡ ½ÇÇàµÇ´Â °É·Î »ý°¢Çß½À´Ï´Ù.


Á¦°¡ »ý°¢ÇÑ °Ô ¸Â´Â °Ç°¡¿ä?


  Hit : 2361     Date : 2011/07/23 11:58



    
´¾´¾ Èì.. ±×³É backdoor ¶ó´Â ÇÁ·Î±×·¥ ÀÚü¸¦ ½ÇÇàÇϴ°ſ¡¿ä

¿¹¸¦µé¾î¼­
a.c ÀÇ ³»¿ëÀÌ ´ÙÀ½°ú °°´Ù°íÇßÀ»‹š
#include <stdio.h>
main()
{
printf("Backdoor Activated\n");
}
gcc -o backdoor a.c ¸¦ ÇØÁֽøé
backdoor ¶ó´Â ÇÁ·Î±×·¥ÀÌ »ý¼ºµÇÁÒ?
À̶§ finger @localhost
¸¦Çغ¸½Ã¸é ÀÌÇØ °¡½Ç°Å¿¡¿ä


Èì.. ¿øÇÏ½Ã´Â°Ô ÀÌ°Ô ¸Â³ª¿ä?
2011/07/24  
pwn3r [level4@ftz xinetd.d]$ cat backdoor
service finger
{
disable = no
flags = REUSE
socket_type = stream
wait = no
user = level5
server = /home/level4/tmp/backdoor
log_on_failure += USERID
}

[level4@ftz xinetd.d]$ cat finger
# default: on
# description: The finger server answers finger requests. Finger is \
# a protocol that allows remote users to see information such \
# as login name and last login time for local users.
service finger
{
socket_type = stream
wait = no
user = nobody
server = /usr/sbin/in.fingerd
disable = yes
}

/etc/xinetd.d/ ¿¡ ÀÖ´Â backdoor °ú fingerÀ̶õ ÆÄÀÏÀ» ¿­¾îº»°Çµ¥¿ä,
º¸½Ã¸é µÎ ÆÄÀϸðµÎ finger ¼­ºñ½º¸¦ Á¤ÀÇÇÏ°í Àִµ¥ ¸®´ª½º¿¡¼­ ±âº»ÀûÀ¸·Î »ç¿ëÇÏ´ø finger service´Â disableµÇÀֱ⠶§¹®¿¡ , backdoor¶ó´Â ÆÄÀÏ¿¡¼­ Á¤ÀÇÇÑ finger¼­ºñ½º°¡ ½ÇÇàµË´Ï´Ù.
finger¼­ºñ½º´Â Á¢¼ÓÀ» ¹ÞÀ¸¸é level5 userÀÇ ±ÇÇÑÀ¸·Î /home/level4/tmp/backdoor¸¦ ½ÇÇàÇϱ⶧¹®¿¡ backdoor¶ó´Â ÇÁ·Î±×·¥À» ¸¸µé¾îµÎ°í finger ¼­ºñ½º°¡ »ç¿ëÇÏ´Â Æ÷Æ®¿¡ Á¢¼ÓÇϸé backdoor¶ó´Â ÇÁ·Î±×·¥ÀÌ ½ÇÇàµÇ°Ô µË´Ï´Ù.
2011/07/24  
Mastel ´¾´¾/pwn3r

µÎºÐ ´äº¯ °¨»çµå¸³´Ï´Ù. È®½ÅÀÌ »ý°å³×¿ä ¤¾¤¾
2011/07/24  
2744   level 4 °ü·Ã Áö½Ä Á¤¸®¿Í Áú¹®ÀÔ´Ï´Ù.[2]     ÇØÄ¿sV
01/01 3566
2743   ·¹º§ 11, 12 ¹®ÀÇ µå¸³´Ï´Ù.[1]     3rdlifer
01/01 2738
2742   Leve4 ÆÄÀ̽ã Áú¹®[5]     ÀÌÇö¹è
12/28 2456
2741   level2¿¡¼­ vim ÆÄÀÏ ÀúÀåÀÌ ¾ÈµÇ³×¿ä..[2]     vbvbdldh
12/09 1860
2740   level3¿¡¼­[1]     hipro
12/05 1784
2739   bash sh[4]     qweqazsdxc
11/05 2419
2738   ¿Ö ¹Ì±¹ÄÄÀ¸·Ð ftz¼·¿¡ Á¢¼Ó ¸øÇϴ°ÅÁÒ?[1]     ov13
10/28 2211
2737   ftz¼­¹ö ±¸Ãà Áú¹®Á»..[7]     gearh0c
10/06 2990
2736   ftz level11[3]     kimgs0725
10/04 2097
2735   vuln Áú¹®..[1]     kimgs0725
09/25 1766
2734   ÇØÄð ´ëÇб³¿¡¼­ vulnÀ» ÇØÅ·ÇÏ·Á´Âµ¥....[2]     kimgs0725
09/24 2673
2733   ftz¼­¹ö ¾ðÁ¦¿­¸®³ª¿ä?[4]     tkangksmf
09/10 1924
2732   Æ÷Æ®23 ¿¬°áÇÏÁö ¸øÇß½À´Ï´Ù.[7]     ¶ß°Å¿îīǪġ³ë
09/07 11881
2731   level2 °ü·Ã Áú¹®ÀÌ¿ä~[4]     dner06
09/06 1997
2730   level6Áú¹®!!![4]     ov13
09/04 1907
2729   level4 Áú¹®     ov13
09/02 2031
2728   gdb°¡ µ¿ÀÛÇÏÁö¾Ê½À´Ï´Ù.[5]     dlddu
08/05 6006
  level4 ¸¦ ¾ó¶³°á¿¡ ²£½À´Ï´Ù. Áö½ÄÀ» ³ª´²ÁÖ¼¼¿ä ¤Ð¤Ð[3]     Mastel
07/23 2360
2726   ¿¡±×½©¿¡¼­ statck¿¡ °ø°£À» Àâ¾Æ¼­ ½©Äڵ带 ³Ö°í ȯ°æº¯¼ö·Î µî·ÏÇÏ¿´À» °æ¿ì     adiangrowif
07/23 2733
2725   level12¸¦ Ç®´Ù°¡ ½©ÄÚµå ±¸¼º¿¡ ´ëÇØ ±Ã±ÝÁõÀÌ »ý°Ü¼­ Áú¹®¿Ã¸³´Ï´Ù.[4]     adiangrowif
07/18 3016
[1][2][3][4][5] 6 [7][8][9][10]..[143]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org