18.01.2015 Views

Untitled - Xakep Online

Untitled - Xakep Online

Untitled - Xakep Online

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Ñïèñîê îòêðûòûõ ïîðòîâ íà ñåðâåðå<br />

ëàäêå. Èìåííî òàêèå ïàðîëè è ëþáÿò íàøè äîáëåñòíûå<br />

àäìèíû :).<br />

Õàêåð íå îøèáñÿ. ×åðåç íåñêîëüêî ÷àñîâ áðóòôîðñåð<br />

ðàçãàäàë ïàðîëü. Ýòî áûëî ïðîñòîå ñëîâî<br />

Flvbybcnhfnjh, ÷òî ïî-ðóññêè îçíà÷àåò Àäìèíèñòðàòîð.<br />

ËÎÊÀËÜÍÛÉ ÂÇËÎÌ<br />

Íàóòðî, ïîñìîòðåâ ëîãè, çëîóìûøëåííèê ñêîííåêòèëñÿ<br />

ïî ssh íà ñåðâåð. Äåìîí âïóñòèë õàêåðà â<br />

ñèñòåìó, òàê êàê ïàðîëü äåéñòâèòåëüíî áûë ïîäîáðàí<br />

âåðíî. Òåïåðü ñëåäîâàëî äîñòàòü root-ïàðîëü<br />

è ïðåäîñòàâèòü äîñòóï çàêàç÷èêó. ×òî êàñàåòñÿ<br />

îïåðàöèîíêè, òî íà ìàøèíå áûë óñòàíîâëåí íîâûé<br />

Alt Master 2.2. ßäðî íå ïîääàâàëîñü ptrace, è<br />

ýêñïëîèòîâ äëÿ ýòîé ñèñòåìû åùå íå áûëî. Ïðèøëîñü<br />

äåéñòâîâàòü íåñòàíäàðòíûìè ïóòÿìè.<br />

Õàêåð îòêðûë ôàéë ~owner/.bash_history è ïî÷èòàë<br />

êîìàíäû àäìèíèñòðàòîðà ñ öåëüþ îáíàðóæèòü<br />

òàì ïàðîëü äëÿ root. Èíòóèöèÿ íå ïîäâåëà íàøåãî<br />

ãåðîÿ: àäìèí îøèáñÿ â íàïèñàíèè êîìàíäû "su",<br />

ïîñëå ÷åãî ñëåäîâàë ðóò-ïàðîëü â plain-òåêñòå. Ýòî<br />

äîâîëüíî òèïè÷íàÿ îøèáêà àäìèíîâ. Âîîáùå, â<br />

.bash_history ìîæíî íàéòè î÷åíü èíòåðåñíûå êîìàíäû<br />

;).<br />

Íàïîñëåäîê õàêåð äîëæåí áûë ñîçäàòü êàêóþëèáî<br />

ìàñêèðîâêó â ñèñòåìå, ÷òîáû àäìèíèñòðàòîð<br />

íå çàñåê åãî ïðåáûâàíèå. Íàñêîðî áûë ïîñòàâëåí<br />

ðóòêèò, ñêðûâàþùèé ôàéëû, à òàêæå íàïèñàí ñèøíèê,<br />

çàïóñêàþùèé /bin/bash ñ ïðàâàìè root (ïîñðåäñòâîì<br />

suid-áèòà). Çàòåì âçëîìùèê ñîçäàë ôàéë<br />

/var/adm/.profile è íàïèñàë òóäà âñåãî äâå ñòðîêè:<br />

Ïðîôèëü-ôàéë ïîëüçîâàòåëÿ adm<br />

Çàòåì õàêåð ñòåð øåëë ó ïîëüçîâàòåëÿ adm.<br />

Ìàëî êòî çíàåò, ÷òî ïðè îòñóòñòâèè øåëëà þçåðó<br />

ïðèñâàèâàåòñÿ äåôîëòîâûé èíòåðïðåòàòîð<br />

/bin/sh. Îí îáðàáàòûâàåò ôàéë ~/.profile, à â íàøåì<br />

ñëó÷àå òàì ñîäåðæàëñÿ çàïóñê ðóòîâîãî<br />

/bin/bash. Ïîñëå çàâåðøåíèÿ ñåàíñà âûïîëíèëàñü<br />

êîìàíäà exit.<br />

/var/lib/modules/linux.so<br />

exit<br />

Åñòåñòâåííî, ÷òî linux.so ÿâëÿëñÿ áèíàðíèêîì,<br />

â êîòîðîì áûë ïîñëåäîâàòåëüíûé çàïóñê ÷èñòèëêè<br />

ëîãîâ è øåëëà ÷åðåç èñïîëíÿåìûé ôàéë Adore<br />

(packetstormsecurity.nl/groups/teso/adore-0.14.tar.gz).<br />

Ðóòîâûé ïàðîëü â .bash_history àäìèíà<br />

×ÒÎ ÂÛÄÀËÎ ÕÀÊÅÐÀ ÏÐÈ ÂÇËÎÌÅ<br />

1. Õàêåð çàáûë èçó÷èòü ïðîöåññû, êðóòÿùèåñÿ íà ìàøèíå. Íåïðîñòèòåëüíàÿ<br />

îïëîøíîñòü, ïîñêîëüêó äàæå ñàìûé ïðîñòîé äåòåêòîð àòàê ìîæåò<br />

âûäàòü âçëîìùèêà.<br />

2. Õàêåð íå èçó÷èë syslog. Ïðîñìîòð /etc/syslog.conf íåîáõîäèìî äåëàòü<br />

âñåãäà, ïîñêîëüêó âàæíàÿ èíôîðìàöèÿ ìîæåò âûñûëàòüñÿ êàê íà<br />

e-mail, òàê è íà êîíñîëü.<br />

3. Õàêåð çàïàëèëñÿ ïðè çàõîäå íà ñàéò ïîä ñîáñòâåííûì IP-àäðåñîì.<br />

Íåîáõîäèìî áûëî ñðàçó æå ïðèíÿòü ìåðû ïî ñîáñòâåííîé<br />

áåçîïàñíîñòè.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!