SIÇÁ·ÎÁ§Æ® ½Ç¹«°æÇè¹ÙÅÁ Àü¹®ÀÚ¹Ù°³¹ßÀÚ°øµ¿Ã¼    
    WASÀü¹®±â¼ú/½Ã½ºÅÛÀå¾ÖÁø´Ü/¼º´ÉÀÌ·Ð/ÄÁ¼³ÆÃ
¾ÆÀ̵ð: 
ºñ¹Ð¹øÈ£: 
[ȸ¿ø°¡ÀÔ]
¡ßUnix/DB/JVM/Etc
--------------
- Unix/Network
- Hacking/Cracking

- DataBase
- JDBC @

- JVM/JDK Issue
- ±âŸ ÀÚ·á½Ç
Áú¹®Àº [¹¯°í´äÇϱâ]¶õ¿¡¸¸ ¿Ã·ÁÁÖ¼¼¿ä





ÃÖ±Ù¿¡ Å͵æÇÑ »õ·Î¿î °ÍÀÌ ÀÖ³ª¿ä? ¸Ó¸® ¼Ó¿¡ ³Ö¾î µÎ¸é ±Ý¹æ Àؾî¹ö¸®ÁÒ? ÀÛÀº °ÍÀÌ¶óµµ ±¦ÂúÀ¸´Ï À̰÷¿¡ ¿Ã·Á³õ°í ³²µé°ú °øÀ¯ÇϽÃÁö¿ä.. ¿Ã¸±¸¸ÇÑ ¸Þ´º°¡ ¾ø´Ù±¸¿ä? ¸¸µé¾î µå¸±²²¿ä.


[ÃÖ±Ù ¿Ã¶ó¿Â ±Ûº¸±â] °Ë»ö¾î:
 JavaResource | API Tips | Open Source | APM | ApplicationServer | Unix/DB/JVM/Etc | Q&A/Help
¡ß Java Resources
--------------------
- °øÁö»çÇ×
- ÃÖ±Ù IT ¼Ò½Ä
- ¼¼¹Ì³ª¼Ò½Ä
- À̺¥Æ® & ÇÁ·Î¸ð¼Ç

- Ãßõ¹®¼­(2006)
- Ãßõ¹®¼­(2003-2005)
- Ãßõ¹®¼­(±¸)

- °ü·Ã »çÀÌÆ®

- ¹¯°í´äÇϱâ @
- ¹¯°í´äÇϱâ-BACKUP @
- ±â¼ú Åä·ÐÀå @
- ÀÏ¹Ý Åä·ÐÀå @
- »çȸ Åä·ÐÀå @


- ÇÁ·ÎÁ§Æ®½Ç¹«ÄÁ¼³ÆÃ@

- ±³À°/°­ÀÇ/°­ÁÂ
- ÇÁ·ÎÁ§Æ®/¼Ö·ç¼ÇÁ¦¾È
- ä¿ë°ø°í/°³¹ßÀÚ±¸ÀÎ
- ±¸Á÷¶õ

- Àǰ߳ª´®ÅÍ/Àâ´ã

- ÀÚ¹Ù¼­ºñ½º³ÝÀº...
¡ß Java API Tips
--------------------
- Programming Tips
- JDC Tech Tips

- Servlet/JSP
- J2EE/EJB
- XML/SOAP/UDDI/WSDL
- Jakarta POI
- JDBC
- Mobile Java
- Applet,Swing,SWT
- CORBA
- RMI
- JavaMail
- HTML/HTC/css/js
- Web ÀϹÝ

- ¼­ºí·¿¿£Áø @
(JServ,Tomcat,JRun,..)
¡ß Open Source
----------------------
- Eclipse/Plugin
- Apache Struts
- JDF Framework
  - Download / API

- Open Source Q&A
* ¿ÀǼҽº °Ô½ÃÆÇ
  ½Åû¹Þ¾Æ¿ä.
¡ß APM
----------------------
- Performance Forum
- Jennifer
  - Consulting Doc.
  - »ç¿ëÈıâ/±â´ÉÃß°¡¿äû
  - Jennifer FAQ
  - Jennifer Q&A
  - Jennifer Download
- CA/Wily
- Mercury Topaz/J2EE Diag.
- Symantec i3
- Borland Optimizeit
- Compuware Vantage
¡ßApplicationServer
-------------------- 
- ¾îÇø®ÄÉÀ̼Ǽ­¹ö

- Apache Geronimo
- ATG Dynamo
- BEA WebLogic
- BolandEnterpriseServer
- Evermind Orion Server
- Fujitsu Interstage
- GemStone's GemStone/J
- HP Netaction
- IBM WebSphere
- IONA iPortal
- InfronTech WebTide
- Macromedia JRun
- Marc Fleury's JBoss
- Oracle 9iAS/OAS/OSDK
- Persistence PowerTier
- SilverStream eXtend
- Sun/Netscape iPlanet
- Sybase EAServer
- TmaxSoft JEUS

- ¼­ºí·¿¿£Áø
(JServ,Tomcat,Resin,..)

- eclipse/Plugin
- Other IDE Tools
¡ßUnix/DB/JVM/Etc
--------------
- Unix/Network
- Hacking/Cracking

- DataBase
- JDBC @

- JVM/JDK Issue
- ±âŸ ÀÚ·á½Ç
¡ß Q&A/Help
--------------------
- ¹¯°í´äÇϱâ
- ¹¯°í´äÇϱâ-BACKUP
- Åä·ÐÀå
- ÇÁ·ÎÁ§Æ®½Ç¹«ÄÁ¼³ÆÃ
- Framework Q&A @
- Jennifer Q&A @

- °Ô½ÃÆÇ »ç¿ë¹ý
- ÀÚ¹Ù¼­ºñ½º³ÝÀº... @
Hacking/Cracking
  [±Û¸ñ·Ï /½Ã°£¼ø] [´ä±Û¾²±â] [ÇÁ¸°Æ®]   
Á¦¸ñ : ÀÚ¹Ù¼­ºñ½º³Ý Å©·¡Å·(cracking) ÁøÇà»çÇ×-Updated-
±Û¾´ÀÌ: ÀÌ¿ø¿µ(javaservice) 2001/12/10 08:46:12 Á¶È¸¼ö:19025 ÁÙ¼ö:975
Á¦¸ñ : Re: ÀÚ¹Ù¼­ºñ½º³Ý Å©·¡Å·(cracking) ´çÇÏ´Ù...
±Û¾´ÀÌ: ÀÌ¿ø¿µ(javaservice)   2001/11/29 04:19:11  Á¶È¸¼ö:110  ÁÙ¼ö:31
  
ÀÚ¹Ù¼­ºñ½º³Ý ¿î¿µÀÚ ÀÌ¿ø¿µÀÔ´Ï´Ù. ÀÚ¹Ù¼­ºñ½º³ÝÀÌ Áö³­ ±Ý¿äÀÏ(11¿ù23ÀÏ)Àú³áºÎÅÍ,
¹ÙÀÌ·¯½º³ª Å©·¡Å·À¸·Î ÃßÁ¤µÇ´Â ÀÏ·ÃÀÇ »çÅ·ΠÀÎÇØ Åä¿äÀÏ/ÀÏ¿äÀÏ/È­¿äÀÏ/¼ö¿äÀÏ 
4Àϵ¿¾È Á¤»óÀûÀÎ ¼­ºñ½º¸¦ ÇÏÁö ¸øÇß½À´Ï´Ù.
N/W ¼­ºñ½º¸¦ Á¦°øÇÏ´Â ÀÎÅ͹з¹´Ï¾ö(ÁÖ)ÀÇ N/W ¸ÁÀÌ ÀÚ¹Ù¼­ºñ½º³Ý ¼­¹öÀÇ  LAN Æ÷Æ®¸¸
N/W ¿¡ ºÙ¿´´ÙÇϸé, ÇØ´ç N/W ÀÌ ¸¶ºñµÇ´Â Çö»óÀÌ ÀϾ½À´Ï´Ù.
¾î¶»°Ô È¥ÀÚ¼­ ÇØ°áÇØ º¸·Á°í ³¢Àû³¢Àû ÇØ º¸¾ÒÀ¸³ª, /usr/sbin/ µð·ºÅ丮ÀÇ ÀϺÎ
binary ½ÇÇàÆÄÀÏÀÇ ³¯Â¥°¡ Áö³­ ±Ý¿äÀÏ ¿ÀÈÄ 5½Ã·Î º¯°æµÇ¾î ÀÖ´Â °ÍµéÀ» Á¾ÇÕÇØ º¼¶§,
¾î¶² back-door ÇÁ·Î±×·¥À̳ª Å©·¡Å·ÀÌ ÀÖ¾ú´ø °ÍÀ¸·Î ÃßÃøÇÕ´Ï´Ù.
±Þ±â¾ß ¼ö¿äÀÏ Àú³á¿¡ Ãß°¡·Î Hard Disk ¸¦ ±¸¸ÅÇÏ¿© Linux¸¦ »õ·Î ¼³Ä¡ÇÏ°í ±âÁ¸
µ¥ÀÌŸ¸¦ º¹±¸ÇØ µÎ¾ú½À´Ï´Ù.

¼³¸¶ ÀÚ¹Ù¼­ºñ½º³Ý ¼­¹ö°¡ Å©·¡Å·ÀÇ Å¸Å¶Àº ¾Æ´Ï¾ú°ÚÁö¸¸, ÀÌ ¼­¹ö¸¦ °æÀ¯ÇÏ¿© ¾îµò·Ð°¡
´Ù¸¥ »çÀÌÆ®·Î ´ë·®ÀÇ ÆÐŶÀ» º¸³½ µí ÇÏ´Ù´Â °ÍÀÌ Á¦°¡ ÃßÃøÇÒ ¼ö ÀÖ´Â ÀüºÎ¿´½À´Ï´Ù.

ÇöÀç ºÎ»êÀÇ SPASH(ÁÖ)("ÀÌÇüÀç"<gaia7@orgio.net>)¶ó´Â ½Å»ý º¸¾È¾÷ü¿¡¼­ ¹«·á·Î Á¡°ËÀ»
ÇØ ÁÖ°í ÀÖ½À´Ï´Ù.

ºÐ¼®°á°ú¹°ÀÌ ³ª¿À¸é À̰÷ ÀÚ¹Ù¼­ºñ½º³Ý--> Unix/Network --> Hacking/Cracking °Ô½ÃÆÇ¿¡
±× ºÐ¼®³»¿ëÀ» ¿Ã¸®µµ·Ï ÇϰڽÀ´Ï´Ù.

¸çÄ¥µ¿¾È ¼­ºñ½º¸¦ ¹ÞÁö ¸øÇØ ¾î¶»°Ô µÈ ¿¬À¯³Ä°í ¹°À¸½Å ºÐÀÌ ¸¹¾Ò¾ú´Âµ¥, °Åµì ¶ÇÇѹø
Á˼ÛÇÕ´Ï´Ù. 

ÀÚ¹Ù¼­ºñ½º³Ý ÀÌ¿ø¿µ


--------------------------------------------------------------------------------
2001³â 11¿ù 29ÀÏ

Á¦¸ñ  ¾È³çÇϼ¼¿ä spash ÀÔ´Ï´Ù.  
º¸³½³¯Â¥  2001³â 11¿ù 29ÀÏ ¸ñ¿äÀÏ, ¹ã 11½Ã 03ºÐ 18ÃÊ KST  
º¸³½ÀÌ  "ÀÌÇüÀç" <gaia7@orgio.net> [ÁÖ¼Ò·Ï¿¡ Ãß°¡] [¼ö½Å°ÅºÎ¿¡ Ãß°¡]  
¹Þ´ÂÀÌ  javaservice@hanmail.net  

¾È³çÇϼ¼¿ä spashÀÇ ÀÌÇüÀç ÀÔ´Ï´Ù.

¹Ì¾àÇϳª¸¶ µµ¿òÀÌ µÇ¾úÀ¸¸é Á¤¸»·Î °¨»çÇϰڽÀ´Ï´Ù.
ÀúÈñ°¡ °£´ÜÇÑ º¸¾È¼¼ÆÃÀ» ³¡³ª°í Àá±ñÀ̳ª¸¶ ·Î±×¸¦ ºÐ¼®ÇØ º» °á°ú ssh crv32 °ø°ÝÀ¸·Î
±Í»çÀÇ ¼­¹ö¿¡ µé¾î¿Â°Í °°½À´Ï´Ù(crc32 exploitÀÌ ÀÎÅͳݻ󿡼­ µ¹°íÀÖ±º¿ä)
ip¸¦ È®ÀÎÇØ º» °á°ú ¹Ì±¹¿¡¼­ µé¾î¿ÔÀ¸¸ç ´õ Á¶»çÁßÀÔ´Ï´Ù.

Á¶¸¸°£ ¸®Æ÷ÆÃ Çü½ÄÀ¸·Î Á¤¸®ÇÏ¿© º¸³»µå¸®°Ú½À´Ï´Ù


--------------------------------------------------------------------------------
Á¦¸ñ  11/24 Å©·¡Å· »ç°í ºÐ¼®ÀÔ´Ï´Ù..  
º¸³½³¯Â¥  2001³â 12¿ù 10ÀÏ ¿ù¿äÀÏ, ¿ÀÈÄ 5½Ã 50ºÐ 29ÃÊ KST  
º¸³½ÀÌ  "ÀÌÇüÀç" <gaia7@orgio.net> [ÁÖ¼Ò·Ï¿¡ Ãß°¡] [¼ö½Å°ÅºÎ¿¡ Ãß°¡]  
¹Þ´ÂÀÌ  javaservice@hanmail.net  

ÀÛ¼º:Spash security team 

Nov 24 02:05:13 javaservice sshd[7974]: log: Connection from 216.33.49.23 port 2233
Nov 24 02:05:13 javaservice sshd[7974]: log: Could not reverse map address 216.33.49.23.
Nov 24 02:05:13 javaservice sshd[7976]: log: Connection from 216.33.49.23 port 2609
Nov 24 02:05:14 javaservice sshd[7976]: log: Could not reverse map address 216.33.49.23.
Nov 24 02:05:30 javaservice sshd[7976]: fatal: Bad protocol version identification:  
Nov 24 02:05:30 javaservice sshd[7974]: fatal: Did not receive ident string
(.....Áß·«.....)

·Î±×ÆÄÀÏ¿¡¼­ ¹ß°ßµÈ ù °ø°Ý ÈçÀûÀÔ´Ï´Ù.
24ÀÏ »õº® 2½Ã 5ºÐ¿¡ 216.33.49.23 À̶ó´Â ip ¿¡¼­ javaservice ÀÇ ssh ¿¡ ¿¬°áÀ» ½Ãµµ
Çϰí Àִµ¥ ¾Æ¸¶µµ sshÀÇ ¹öÁ¯À» È®ÀÎÇϰí exploit À» ½ÇÇàÇÏ¿© °ø°ÝÀ» ½ÃµµÇϰí ÀÖ¾úÀ»
°ÍÀ̶ó ÃßÁ¤µË´Ï´Ù.

Nov 24 02:10:17 javaservice sshd[8138]: fatal: Local: Corrupted check bytes on input.

remote attackÀÇ Æ¯¼º»ó ½±°Ô overflow °¡ ÀϾÁö ¾ÊÀ¸¹Ç·Î Å©·¡Ä¿´Â ¾Æ¸¶ stack »óÀÇ
return address ÀÇ offset °ªÀ» ÃßÃøÇϱâ À§ÇØ ¹Ýº¹ÀûÀ¸·Î °ø°ÝÀ» ½ÃÀÛÇÏ¿´½À´Ï´Ù.

Nov 24 02:15:38 javaservice sshd[8263]: fatal: Local: crc32 compensation attack:
network attack detected

¹Ýº¹ÀûÀ¸·Î ½ÃµµÇÏ´Ù°¡ Å©·¡Ä¿´Â ´Ù¸¥  ssh exploitÀ» ȹµæÇÏ¿© °ø°ÝÀ» ½ÃµµÇÏ·Á
Çß½À´Ï´Ù. Áï ssh crc32 exploitÀ¸·Î °ø°ÝÀ» ½ÃµµÇÏ¿´½À´Ï´Ù.

Nov 24 02:20:00 javaservice sshd[398]: log: Generating new 768 bit RSA key.
Nov 24 02:20:01 javaservice sshd[398]: log: RSA key generation complete.
Nov 24 02:23:19 javaservice sshd[8485]: log: Connection from 216.33.49.23 port 2016

ssh crc32 °ø°ÝÀ» ¾à 5 ºÐ Á¤µµ ½ÃµµÇÏ¿© ssh ÀÇ ¿ÀÀÛµ¿À¸·Î ÀÎÇØ 216.33.49.23 ipÀÇ
Á¢±Ù ÀÎÁõÀÌ ÀÌ·ç¾î Á³½À´Ï´Ù.

¿©±â±îÁö°¡ /var/log/messages ÆÄÀÏÀÇ ³»¿ëÀÔ´Ï´Ù

Nov 23 19:20:24 javaservice proftpd[29148]: javaservice.net (203.253.146.231[203.
253.146.231]) - ANON anonymous: Login successful. 
Nov 23 20:09:49 javaservice proftpd[31098]: javaservice.net (210.123.181.204[210.
123.181.204]) - ANON anonymous: Login successful. 
Nov 24 14:30:54 javaservice login: ROOT LOGIN ON tty1
Nov 24 17:38:22 javaservice proftpd[517]: javaservice

Å©·¡Å·ÀÌ ÀÌ·ç¾îÁø ½Ã°£´ëÀÇ /var/log/secure ÆÄÀÏ ÀÌÁö¸¸ ¾Ö¼®ÇϰԵµ Å©·¡Ä¿°¡ secure
ÆÄÀÏÀÇ ±â·ÏÀ» ¼öÁ¤ÇѰÍÀ¸·Î º¸¿©Áý´Ï´Ù.(º¸½Ã´Ù ½ÃÇÇ 23ÀÏ 20½Ã ÀÌÈÄÀÇ ±â·ÏÀº
»èÁ¦µÇ¾úÀ½)

ÁÖ)ÀÎÅ͹з¹´Ï¾ö(ÇöÀç javaserviceÀÇ ¼­¹ö°¡ Àִ°÷)ÀÇ N/W ¸¶ºñ Çö»óÀº Å©·¡Ä¿ÀÇ SSH 
°ø°ÝÀ¸·Î ÀÎÇÑ Æ®·¡ÇÈ ÆøÁÖÇö»ó°ú ÀÎÅ͹з¹´Ï¾öÀÇ ¹éº»¸ÁÀÌ E1 ±ÞÀÇ Á¼Àº ´ë¿©ÆøÀ»
»ç¿ëÇϱ⠶§¹®¿¡ Æ®·¡ÇÈÀ» °ßµ® ³»Áö ¸øÇѰÍÀ¸·Î ÃßÁ¤ÇÕ´Ï´Ù.

½Ã½ºÅÛ ³»ºÎ·Î µé¾î°£ Å©·¡Ä¿´Â ¹éµµ¾î¸¦ ¼³Ä¡ÇÏ¿´½À´Ï´Ù. ¹éµµ¾îÀÇ Á¾·ù°¡ ¿©·¯
Á¾·ùÀÌÁö¸¸ Á¦ °ßÇØ·Î´Â rootkit À» ¼³Ä¡ÇѰÍÀ¸·Î º¸ÀÔ´Ï´Ù. ps ¸í·É¾î°¡ Àß µÇÁö
¾Ê¾ÒÀ¸¹Ç·Î ldd ¸í·É¾î·Î ¶óÀ̺귯¸®ÀÇ ÀÇÁ¸¼ºÀ» Ã¼Å©ÇØº» °á°ú ´ÙÀ½°ú °°½À´Ï´Ù.

# ldd /bin/ps
libproc.so.2.0.6 => /lib/libproc.so.2.0.6 (0x40018000)
libc.so.6 => /lib/libc.so.6 (0x40024000)
/lib/ld-linux.so.2 => /lib/ld-linux.so.2 (0x40000000)
Á¤»óÀÎ °æ¿ì

# ldd /bin/ps
libproc.so.2.0.0 => not found
libc.so.6 => /lib/libc.so.6 (0x40018000)
/lib/ld-linux.so.2 => /lib/ld-linux.so.2 (0x40000000)
rootkitÀÌ ¼³Ä¡µÇ¾î ÀÖ´Â °æ¿ì

ÀúÈñ°¡ ·Î±×¸¦ ºÐ¼®ÇÏ´ø Áß javaservice °¡ anonymous ftp  »óÅ·Π¼­¹ö°¡ ¿­·ÁÀ־
¿©·¯°÷¿¡¼­ ftp Á¢¼ÓÀ» ½ÃµµÇÏ´Â °ÍÀ» ¹ß°ßÇÒ¼ö ÀÖ¾ú½À´Ï´Ù.(ÀϺ»,¹Ì±¹µî) 
anonymous ftp ¸¦ ¿î¿µÇÏ´Â °æ¿ì ¼­¹ö³»ºÎ¸¦ ¾à°£À̳ª¸¶ º¼¼ö ÀÖ°í ¶Ç ºÒÇÊ¿äÇÑ
Æ®·¡ÇÈÀ» ÀÏÀ¸Å³ ¼ö Àֱ⠶§¹®¿¡ ÇöÀç ¸·¾Æ³í »óÅÂÀ̸ç ÇöÀç javaservice´Â ¹æÈ­º®ÀÌ
¼³Ä¡µÇ¾î ÀÖ½À´Ï´Ù.


ÀÌó·³ º¸¾ÈÀ» °­È­Çϱâ À§ÇØ ¼³Ä¡Çسí ssh °¡ ¿ÀÈ÷·Á ÇØÅ·ÀÇ À§ÇèÀÌ µÉ¼öÀÖÀ½À» È®ÀÎÇÒ
¼ö ÀÖ¾ú°í ¼­¹ö°ü¸®ÀÚµéÀº Ç×»ó ÃֽŠÇÁ·Î±×·¥À» ¼³Ä¡ÇÏ½Ã±æ ±ÇÀåÇÕ´Ï´Ù.

-spash-


--------------------------------------------------------------------------------
2001³â 12¿ù 3ÀÏ ¿ù¿äÀÏ ¾ÆÄ§

Network Á¦°ø¾÷üÀÇ Á¤Àü »ç°í·Î ÀÎÇØ, ÀÚ¹Ù¼­ºñ½º³Ý Hard Disk°¡ ¸Á°¡Áü.
ºÎ»êÀÇ SPASH(ÁÖ) º¸¾È¾÷üÀÇ µµ¿òÀ¸·Î ÀϺΠÀڷḸ º¹±¸ÇÏ¿© 12¿ù 7ÀÏ(±Ý¿äÀÏ)ºÎÅÍ
Á¤»óÀûÀÎ ¼­ºñ½º¸¦ ´Ù½Ã Á¦°øÇÔ.



--------------------------------------------------------------------------------
2001³â 12¿ù 9ÀÏ(ÀÏ¿äÀÏ) ¿ÀÈÄ 5½Ã 20ºÐ °æ ´Ù½Ã Å©·¡Å· ´çÇÔ.

ÀÚ¹Ù¼­ºñ½º³ÝÀÇ Ã¹ index.html ÆäÀÌÁö°¡ "This is lame" À̶ó´Â ¹®±¸·Î º¯°æµÇ¾î ÀÖÀ½.

drwxr-xr-x    4 root     root         4096 Dec  9 17:53 ./
-rw-r--r--    1 root     root         1113 Dec  9 02:38 .,  <-- index.html ¿øº»
drwxr-xr-x    6 root     root         4096 Dec  7 04:10 ../
-rw-r--r--    1 root     root         2494 Dec  7 05:10 favicon.ico
-rw-rw-r--    1 root     root           14 Dec  9 17:20 index.html
drwxr-xr-x    3 root     root         4096 Dec  6 10:20 manual/
-rw-r--r--    1 root     root         1154 Mar  1  2000 poweredby.png
drwxr-xr-x   10 root     root         4096 Dec  8 03:46 wwwcount2.5/


ªÀº ¼Ò°ßÀ¸·Î º¸¸é, /var/log/ µð·ºÅ丮ÀÇ wtmp ÆÄÀÏÀÌ »èÁ¦µÇ¾î ÀÖ¾î ÃÖ±Ù Á¢¼ÓµÈ
·Î±×Á¤º¸°¡ ¾ø¾îÁ® ÀÖÀ½. /var/log/messages ÆÄÀϵµ Áö¿öÁ® ÀÖÀ¸³ª, ¾Æ·¡¿Í °°Àº ±â·ÏÀÌ
³²¾Æ ÀÖÀ½.

[/var/log/messages]
Dec  9 17:33:51 javaservice syslogd 1.3-3: restart.
Dec  9 17:35:53 javaservice identd[17549]: request_thread: read(11, ..., 1023)
failed: Connection reset by peer
Dec  9 17:35:55 javaservice kernel: lockd: connect from unprivileged port: 
66.21.117.9:3210<4>lockd: accept failed (err 11)!
Dec  9 17:35:55 javaservice kernel: lockd: accept failed (err 11)!
Dec  9 17:36:03 javaservice ftpd[17550]: getpeername (in.ftpd): Transport endpoint
is not connected
Dec  9 17:36:03 javaservice inetd[476]: pid 17550: exit status 1
Dec  9 17:36:20 javaservice ftpd[17551]: FTP session closed
Dec  9 17:38:19 javaservice PAM_pwdb[15883]: (su) session closed for user b
Dec  9 17:38:19 javaservice inetd[476]: pid 15844: exit status 1
....(»ý·«)...
Dec  9 18:14:54 javaservice inetd[476]: pid 17877: exit status 1
Dec  9 18:46:01 javaservice PAM_pwdb[18352]: check pass; user unknown
Dec  9 18:46:03 javaservice login[18352]: FAILED LOGIN 1 FROM 210.182.138.4 FOR 
wh^H^H^H^H, User not known to the underlying authent
ication module
Dec  9 18:46:16 javaservice PAM_pwdb[18352]: authentication failure; (uid=0) 
-> root for login service
Dec  9 18:46:17 javaservice login[18352]: FAILED LOGIN 2 FROM 210.182.138.4 FOR
root, Authentication failure
Dec  9 18:46:27 javaservice login[18352]: FAILED LOGIN 3 FROM 210.182.138.4 FOR
root, Authentication failure
Dec  9 18:46:31 javaservice login[18352]: FAILED LOGIN SESSION FROM 210.182.138.4
FOR (null), Error in service module
Dec  9 18:46:31 javaservice inetd[476]: pid 18351: exit status 1
Dec  9 18:46:49 javaservice ftpd[18368]: FTP LOGIN REFUSED (ftp not in /etc/passwd)
FROM dns.csjh.kh.edu.tw [163.18.161.1], ftp
Dec  9 18:46:50 javaservice ftpd[18368]: FTP session closed
....(»ý·«)...




[/var/log/secure]
Dec  9 17:36:03 javaservice in.ftpd[17550]: connect from 66.21.117.9
Dec  9 17:36:19 javaservice in.ftpd[17551]: connect from 66.21.117.5
Dec  9 17:36:20 javaservice sshd[16223]: connection from "66.21.117.5"
Dec  9 17:36:21 javaservice sshd[17552]: Local disconnected: Illegal protocol 
version.
Dec  9 17:36:21 javaservice sshd[17552]: protocol version not supported in local:
'Illegal protocol version.'
Dec  9 17:43:17 javaservice sshd[16223]: connection from "217.156.72.182"
Dec  9 17:43:17 javaservice sshd[17565]: DNS lookup failed for "217.156.72.182".
Dec  9 17:43:48 javaservice sshd[17565]: Local disconnected: Connection closed by
remote host.
Dec  9 17:43:48 javaservice sshd[17565]: connection lost: 'Connection closed by
remote host.'
....(Áß°£»ý·«)...
Dec  9 18:45:43 javaservice in.telnetd[18351]: connect from 210.182.138.4
Dec  9 18:46:48 javaservice in.ftpd[18368]: connect from 163.18.161.1
Dec  9 19:20:42 javaservice sshd[17630]: Local disconnected: Connection closed.
Dec  9 19:20:42 javaservice sshd[17630]: connection lost: 'Connection closed.'
Dec  9 19:34:04 javaservice sshd[16223]: connection from "200.218.43.199"
Dec  9 19:34:05 javaservice sshd[19373]: DNS lookup failed for "200.218.43.199".
Dec  9 19:34:21 javaservice sshd[19373]: Local disconnected: Connection closed by
remote host.
Dec  9 19:34:21 javaservice sshd[19373]: connection lost: 'Connection closed by
remote host.'



»ó±âÀÇ 66.21.117.9 IP´Â ¾Æ·¡¿Í °°ÀÌ  ³ë½º¾ÆÆ²¶õŸ Áö¿ªÀÇ °ÍÀ¸·Î º¸ÀÓ


Bellsouth.net, Inc. (NETBLK-BELLSNET-BLK8)
301 Perimeter Center North Atlanta, GA  30346 US

Netname: BELLSNET-BLK8
Netblock: 66.20.0.0 - 66.21.255.255
Maintainer: BELL

Coordinator:
  Geurin, Joe  (JG726-ARIN)  ipadmin@bellsouth.net
  678-441-7800 (FAX) 678-441-6968


217.156.72.182 IP´Â ·ç¸¶´Ï¾ÆÀÇ °ÍÀ¸·Î º¸¿©Áø´Ù.

% This is the RIPE Whois secondary server.
% The objects are in RPSL format.
% Please visit http://www.ripe.net/rpsl for more information.
% Rights restricted by copyright.
% See http://www.ripe.net/ripencc/pub-services/db/copyright.html


inetnum:      217.156.72.128 - 217.156.72.191
netname:      JOHN-CO
descr:        SC John Co. SRL
descr:        Str. Armand Calinescu, Nr.9A,
descr:        Pitesti, 0300, jud. Arges, Romania
country:      ro
admin-c:      BD497-RIPE
tech-c:       BD497-RIPE
status:       ASSIGNED PA
mnt-by:       AS3233-MNT
notify:       domain-admin@listserv.rnc.ro
changed:      cristih@rnc.ro 20010705
source:       RIPE




dns.csjh.kh.edu.tw(163.18.161.1)Àº ¾Æ·¡ÀÇ Á¤º¸¸¦ ³ªÅ¸³»°í ÀÖÀ½.
  
Ministry of Education Computer Center (NETBLK-TANET-B) TANET-B
 163.13.0.0 - 163.32.255.255
Ministry of Education Computer Center (NET-TANET-B-6) TANET-B-6
 163.18.0.0 - 163.18.255.255

Ministry of Education Computer Center (NETBLK-TANET-B)
   Ministry of Education Computer Center
   12th Fl, 106, Hoping E. Road, Sec 2.
   TW

   Netname: TANET-B
   Netblock: 163.13.0.0 - 163.32.255.255
   Maintainer: MOEC

   Coordinator:
      Chen, Wen-Sung  (WSC1-ARIN)  ZCHEN@TWNMOE10.EDU.TW
      886-2-737-7011




210.182.138.4 ´Â ±¹³» IPÀε¥, ¾î´À ºÐÀÌÁÒ?


---------------------------------------------------------------------------------
index.html ÀÌ º¯°æµÈ ÈÄ ºÒ°ú 15ºÐ µÚ 17½Ã 35ºÐ °æ,

"Alldas.de Incident Handling Center"¶ó´Â ¿Ü±¹º¸¾È¾÷ü·ÎºÎÅÍ ¾Æ·¡ÀÇ ¸ÞÀÏÀÌ
º»Àο¡°Ô µµÂøÇÔ.


Á¦¸ñ  Security Incident at www.javaservice.net ( IP: 211.53.127.180 )  
º¸³½³¯Â¥  2001³â 12¿ù 09ÀÏ ÀÏ¿äÀÏ, »õº® 02½Ã 35ºÐ 06ÃÊ -0600 (CST)  
º¸³½ÀÌ  "Alldas.de Incident Handling Center" <abuse@alldas.de> 
¹Þ´ÂÀÌ  security@javaservice.net, hostmaster@javaservice.net,abuse@javaservice.net  
ÇÔ²² ¹Þ´ÂÀÌ  javaservice@hanmail.net, IncidentInformed@alldas.de  
Greetings. 

You are being contacted because you are listed as an Internic contact for the domain 
referred to. 

Alldas.de is a non-profit, hobby web site that monitors computer crime on the 
internet. In the past few minutes, we have been notified that your domain was hacked, 
and your web page defaced. This means that the intruder has edited your web page in 
some way. Due to this, it is quite likely that one or all of the machines on your 
network are compromised. You may wish to take immediate action to correct this 
problem and respond to the intrusion. 

One of the free services Alldas.de offers is mirroring defaced pages to aid in 
statistics on computer crime. The various archives of information we maintain is
used by security professionals and law enforcement every day. We comply with all
law enforcement subpoenas for information related to the intrusion. 

We want to assure you that we had no advanced knowledge of the intrusion. Any 
reference to Alldas.de (66.21.117.5 & 66.21.117.9) in your logs is due to our 
mirroring utility. Any greeting or reference to Alldas.de on the actual web page
is beyond our control. We send out over 2000 mails like this every month. 

You should contact the appropriate CERT and law enforcement agency with follow-up 
information. 
They can provide recommendations for recovering and dealing with this incident. 

If you receive any additional mail from a security company or vendor, we'd like to 
state up front that we are in no way affiliated with them. We have found out that 
some security companies prey on victims of web defacement to solicit their products 
or services. If you receive such mail, please forward the full text with headers to 
us so that we can confront them. 

Please feel free to mail us if you have any questions or would like assistance. 

For more on security and incident response: 
http://www.ciac.org/ciac/ 

For more on computer forensics and preservation of evidence: 
http://www.forensics-intl.com/info.html 

Contacting Law Enforcement 
http://www.fbi.gov/contact/fo/fo.htm 

For the latest on vulnerabilities and good security practice: 
http://www.securityfocus.com 

Explanation of our mirroring Utility: 
http://defaced.alldas.de/?FAQ=admin 

The Alldas Mirror: 
http://defaced.alldas.de 

For the latest patches and mailing lists 
http://security.alldas.de/patches/ 

Contacting us: 
abuse@alldas.de 
 

·Î±×¿¡ ³²¾Æ ÀÖ´Â IP´Â °á±¹, À§ º¸¾È¾÷üÀÇ mirroring utilityÀÇ ÀÇÇÑ °ÍÀ¸·Î º¸ÀÓ
(±Ùµ¥, Á» ¹Ì½ÉÀûÀºµ¥... 17½Ã 20ºÐ¿¡ index.html ÀÌ º¯°æµÇ¾î ÀÖ°í, ºÒ°ú 15ºÐ µÚÀÎ
35ºÐ°æ¿¡ mirroring utility ¸¦ µ¹¸®°í, °ð¹Ù·Î ³»°Ô ÁÖÀǼº ¸ÞÀÏÀ» ³¯·È´Ù±¸?  
´ë´ÜÇÏ´Ù°í ÇØ¾ß Çϴ°žß, ¾Æ´Ï¸é ÀǽÉÇØ¾ß Çϴ°žß...??)

±×·¯³ª, ¸ðµç ·Î±×°¡ 35ºÐ ÀÌÈÄ¿¡³ª ³²¾Æ ÀÖ´Â °Í°ú index.html ÀÇ ÃÖÁ¾ º¯°æ½Ã°¢Àº
17½Ã 20ºÐ ÀΰÍÀ¸·Î ºÁ¼±, Å©·¡Ä¿ÀÇ ÈçÀûÀº ¸ðµÎ Áö¿öÁø °ÍÀ¸·Î ÃßÁ¤µÊ.

±Ùµ¥, À¯·´ ·ç¸¶´Ï¾Æ¿¡¼­ Á¢¼ÓÇÑ 217.156.72.182 ¿Í, ´ë¸¸ÀÇ ±³À°ºÎ Àü»ê½ÇÀÎ 
163.18.161.1Àº ¹»±î.. ÀÌ IP¿ª½Ã Å©·¡Å·À» ¾Ë¾ÆÂ÷¸° º¸¾È¾÷üÀϱî..


---------------------------------------------------------------------------------
2001.12.09 20:35 È®ÀÎµÈ »çÇ×

¾î´À ºÐÀÇ Á¦º¸¿Í À¥¼­¹ö ·Î±×¸¦ ÃßÀûÇØ º¸´Ï, 15½Ã 48ºÐºÎÅÍ 17½Ã 05ºÐ±îÁö
/ezs.html À̶ó´Â ¹®¼­¸¦ ¸µÅ©¸¦ °É¾î µÎ¾ú°í, ±× ³»¿ëÀº ¾ßÇÑ À̹ÌÁö¿´´Ù ÇÔ.

# cat access_log | grep ezs.html
211.44.101.120 - - [09/Dec/2001:15:48:58 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
209.63.9.37 - - [09/Dec/2001:15:53:00 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
203.239.99.52 - - [09/Dec/2001:15:53:05 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
211.222.255.98 - - [09/Dec/2001:16:00:21 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
211.200.83.100 - - [09/Dec/2001:16:04:42 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
211.224.157.167 - - [09/Dec/2001:16:10:11 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
61.77.5.209 - - [09/Dec/2001:16:10:11 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
61.83.148.156 - - [09/Dec/2001:16:17:14 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
211.208.184.103 - - [09/Dec/2001:16:20:36 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
211.208.184.103 - - [09/Dec/2001:16:21:06 -0500] "GET /ezs.html HTTP/1.1" 304 - 0
211.216.144.157 - - [09/Dec/2001:16:22:16 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
211.217.154.236 - - [09/Dec/2001:16:23:29 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
211.177.47.191 - - [09/Dec/2001:16:27:48 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
211.187.5.131 - - [09/Dec/2001:16:28:06 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
61.98.14.62 - - [09/Dec/2001:16:36:31 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
211.52.63.53 - - [09/Dec/2001:16:37:56 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
210.99.135.76 - - [09/Dec/2001:16:44:42 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
210.99.135.76 - - [09/Dec/2001:16:45:11 -0500] "GET /ezs.html HTTP/1.1" 304 - 0
211.52.63.53 - - [09/Dec/2001:16:45:38 -0500] "GET /ezs.html HTTP/1.1" 304 - 0
211.110.91.105 - - [09/Dec/2001:16:47:39 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
210.99.135.78 - - [09/Dec/2001:16:49:08 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
210.100.244.207 - - [09/Dec/2001:16:49:29 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
211.37.182.199 - - [09/Dec/2001:16:50:09 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
211.37.182.199 - - [09/Dec/2001:16:50:33 -0500] "GET /ezs.html HTTP/1.1" 304 - 0
211.219.177.242 - - [09/Dec/2001:16:51:10 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
211.219.177.242 - - [09/Dec/2001:16:51:25 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
211.56.58.30 - - [09/Dec/2001:16:51:28 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
211.56.58.29 - - [09/Dec/2001:16:54:19 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
211.56.58.29 - - [09/Dec/2001:16:55:29 -0500] "GET /ezs.html HTTP/1.1" 304 - 0
211.218.242.222 - - [09/Dec/2001:16:58:29 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
61.78.54.26 - - [09/Dec/2001:16:59:14 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
61.78.54.26 - - [09/Dec/2001:17:00:21 -0500] "GET /ezs.html HTTP/1.1" 304 - 0
61.254.20.225 - - [09/Dec/2001:17:00:22 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
61.78.54.21 - - [09/Dec/2001:17:00:22 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
61.254.20.225 - - [09/Dec/2001:17:00:48 -0500] "GET /ezs.html HTTP/1.1" 304 - 0
61.78.54.26 - - [09/Dec/2001:17:03:53 -0500] "GET /ezs.html HTTP/1.1" 304 - 0
61.78.54.26 - - [09/Dec/2001:17:04:07 -0500] "GET /ezs.html HTTP/1.1" 304 - 0
24.78.56.107 - - [09/Dec/2001:17:04:09 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
211.111.176.243 - - [09/Dec/2001:17:05:33 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
210.222.46.22 - - [09/Dec/2001:17:05:53 -0500] "GET /ezs.html HTTP/1.1" 200 1113 0
210.222.46.22 - - [09/Dec/2001:17:05:55 -0500] "GET /ezs.html HTTP/1.0" 200 1113 0


---------------------------------------------------------------------------------
2001.12.09 21:00 È®ÀÎµÈ »çÇ×

À¥¼­¹öÀÇ ·Î±×¸¦ È®ÀÎÇØ º» °á°ú, ùÆäÀÌÁöÀÎ index.html ÀÌ ÃÖÃÊ¿¡ ¹Ù²ï ½Ã°¢Àº
15½Ã 45ºÐÀ̸ç, 15½Ã 46ºÐ¿¡ ¶ÇÇѹø º¯°æÇÑ °ÍÀ¸·Î º¸ÀδÙ.

# cat access_log | grep GET\ /\ HTTP/1
211.196.229.166 - - [09/Dec/2001:15:39:28 -0500] "GET / HTTP/1.1" 200 1113 0
211.47.204.70 - - [09/Dec/2001:15:41:09 -0500] "GET / HTTP/1.1" 200 1113 0
211.48.33.170 - - [09/Dec/2001:15:41:37 -0500] "GET / HTTP/1.1" 200 1113 0
211.106.185.130 - - [09/Dec/2001:15:42:11 -0500] "GET / HTTP/1.1" 200 1113 0
169.140.115.136 - - [09/Dec/2001:15:42:47 -0500] "GET / HTTP/1.0" 200 1113 0
209.63.9.37 - - [09/Dec/2001:15:45:35 -0500] "GET / HTTP/1.1" 200 1158 0
211.233.134.99 - - [09/Dec/2001:15:45:59 -0500] "GET / HTTP/1.1" 200 1158 0
211.233.134.99 - - [09/Dec/2001:15:46:15 -0500] "GET / HTTP/1.1" 200 1158 0
211.233.134.99 - - [09/Dec/2001:15:46:33 -0500] "GET / HTTP/1.1" 304 - 0
209.63.9.37 - - [09/Dec/2001:15:46:47 -0500] "GET / HTTP/1.1" 200 1169 0
203.252.90.69 - - [09/Dec/2001:15:48:05 -0500] "GET / HTTP/1.1" 200 1169 0
211.44.101.120 - - [09/Dec/2001:15:48:35 -0500] "GET / HTTP/1.1" 200 1169 0
211.204.33.7 - - [09/Dec/2001:15:52:23 -0500] "GET / HTTP/1.1" 200 1169 0
203.239.99.52 - - [09/Dec/2001:15:52:52 -0500] "GET / HTTP/1.1" 200 1169 0
209.63.9.37 - - [09/Dec/2001:15:53:09 -0500] "GET / HTTP/1.1" 304 - 0
210.117.131.204 - - [09/Dec/2001:15:53:27 -0500] "GET / HTTP/1.1" 200 1169 0
211.111.176.243 - - [09/Dec/2001:15:55:27 -0500] "GET / HTTP/1.1" 200 1169 0
211.48.6.249 - - [09/Dec/2001:15:57:55 -0500] "GET / HTTP/1.1" 200 1169 0
211.37.182.199 - - [09/Dec/2001:15:59:32 -0500] "GET / HTTP/1.1" 200 1169 0
211.222.255.98 - - [09/Dec/2001:16:00:05 -0500] "GET / HTTP/1.1" 200 1169 0
211.217.52.36 - - [09/Dec/2001:16:00:59 -0500] "GET / HTTP/1.1" 200 1169 0
211.217.52.36 - - [09/Dec/2001:16:01:02 -0500] "GET / HTTP/1.1" 304 - 0
211.217.52.36 - - [09/Dec/2001:16:01:04 -0500] "GET / HTTP/1.1" 304 - 0
211.111.176.243 - - [09/Dec/2001:16:02:59 -0500] "GET / HTTP/1.1" 304 - 0
211.200.83.100 - - [09/Dec/2001:16:03:51 -0500] "GET / HTTP/1.1" 200 1169 0
....
.......
210.222.46.22 - - [09/Dec/2001:17:05:35 -0500] "GET / HTTP/1.1" 200 1169 0
210.222.46.22 - - [09/Dec/2001:17:05:38 -0500] "GET / HTTP/1.0" 200 1169 0
211.111.176.243 - - [09/Dec/2001:17:05:51 -0500] "GET / HTTP/1.1" 304 - 0
61.72.68.200 - - [09/Dec/2001:17:08:51 -0500] "GET / HTTP/1.1" 200 1113 0
203.252.3.27 - - [09/Dec/2001:17:09:41 -0500] "GET / HTTP/1.1" 200 1113 0
211.216.27.212 - - [09/Dec/2001:17:10:22 -0500] "GET / HTTP/1.1" 200 1113 0
211.42.202.32 - - [09/Dec/2001:17:10:51 -0500] "GET / HTTP/1.1" 200 1113 0
210.99.135.78 - - [09/Dec/2001:17:12:21 -0500] "GET / HTTP/1.1" 200 1113 0
210.99.135.78 - - [09/Dec/2001:17:12:24 -0500] "GET / HTTP/1.1" 200 1113 0
210.99.135.78 - - [09/Dec/2001:17:12:37 -0500] "GET / HTTP/1.1" 304 - 0
211.217.147.248 - - [09/Dec/2001:17:12:54 -0500] "GET / HTTP/1.1" 200 1113 0
210.99.135.78 - - [09/Dec/2001:17:13:36 -0500] "GET / HTTP/1.1" 200 1113 0
203.246.6.124 - - [09/Dec/2001:17:13:57 -0500] "GET / HTTP/1.1" 200 1113 0
211.216.27.212 - - [09/Dec/2001:17:14:32 -0500] "GET / HTTP/1.1" 304 - 0
211.218.242.222 - - [09/Dec/2001:17:14:51 -0500] "GET / HTTP/1.1" 200 1113 0
211.37.182.199 - - [09/Dec/2001:17:17:48 -0500] "GET / HTTP/1.1" 200 1113 0
211.228.2.229 - - [09/Dec/2001:17:22:28 -0500] "GET / HTTP/1.1" 200 14 0
209.63.9.37 - - [09/Dec/2001:17:22:31 -0500] "GET / HTTP/1.1" 200 14 0
62.163.101.134 - - [09/Dec/2001:17:22:59 -0500] "GET / HTTP/1.0" 200 14 0
211.238.138.19 - - [09/Dec/2001:17:24:02 -0500] "GET / HTTP/1.1" 200 14 0


Ʋ¸²¾øÀÌ, index.html À» ¹Ù²Ù¾úÀ¸¸é, ºê¶ó¿ìÁ®¸¦ ÀÌ¿ëÇÏ¿© È®ÀÎÀ» ÇßÀ» °ÍÀÌ´Ù.
°¡Àå Àǽɽº·± IP´Â 209.63.9.37 ÀÌ´Ù.

# cat access_log | grep 209.63.9.37
209.63.9.37 - - [09/Dec/2001:15:37:23 -0500] "GET / HTTP/1.1" 200 1113 0
209.63.9.37 - - [09/Dec/2001:15:37:24 -0500] "GET /~java/bbs/search.cgi?m=resou
209.63.9.37 - - [09/Dec/2001:15:37:24 -0500] "GET /cgi-bin/musicbox.cgi HTTP/1.
209.63.9.37 - - [09/Dec/2001:15:37:24 -0500] "GET /~java/bbs/conf/bbs.css HTTP/
209.63.9.37 - - [09/Dec/2001:15:37:24 -0500] "GET /~java/bbs/images/jsn_logo.gi
209.63.9.37 - - [09/Dec/2001:15:37:25 -0500] "GET /~java/bbs/images/banner/jsn8
209.63.9.37 - - [09/Dec/2001:15:37:25 -0500] "GET /cgi-bin/Count.cgi?ft=0&df=po
209.63.9.37 - - [09/Dec/2001:15:37:25 -0500] "GET /cgi-bin/Count.cgi?ft=0&df=po
209.63.9.37 - - [09/Dec/2001:15:37:25 -0500] "GET /cgi-bin/Count.cgi?ft=0&df=po
209.63.9.37 - - [09/Dec/2001:15:37:25 -0500] "GET /cgi-bin/Count.cgi?ft=0&df=po
209.63.9.37 - - [09/Dec/2001:15:37:26 -0500] "GET /~java/bbs/images/round_left0
209.63.9.37 - - [09/Dec/2001:15:37:26 -0500] "GET /~java/bbs/images/round_right
209.63.9.37 - - [09/Dec/2001:15:37:26 -0500] "GET /~java/bbs/images/c.gif HTTP/
209.63.9.37 - - [09/Dec/2001:15:37:26 -0500] "GET /~java/bbs/images/close-new.g
209.63.9.37 - - [09/Dec/2001:15:37:26 -0500] "GET /~java/bbs/images/clip.jpg HT
209.63.9.37 - - [09/Dec/2001:15:37:26 -0500] "GET /~java/bbs/images/open-new.gi
209.63.9.37 - - [09/Dec/2001:15:37:26 -0500] "GET /~java/bbs/images/1pixel.gif 
209.63.9.37 - - [09/Dec/2001:15:45:35 -0500] "GET / HTTP/1.1" 200 1158 0
209.63.9.37 - - [09/Dec/2001:15:46:47 -0500] "GET / HTTP/1.1" 200 1169 0
209.63.9.37 - - [09/Dec/2001:15:53:00 -0500] "GET /ezs.html HTTP/1.1" 200 1113 
209.63.9.37 - - [09/Dec/2001:15:53:01 -0500] "GET /~java/bbs/search.cgi?m=resou
209.63.9.37 - - [09/Dec/2001:15:53:01 -0500] "GET /cgi-bin/musicbox.cgi HTTP/1.
209.63.9.37 - - [09/Dec/2001:15:53:01 -0500] "GET /~java/bbs/conf/bbs.css HTTP/
209.63.9.37 - - [09/Dec/2001:15:53:02 -0500] "GET /~java/bbs/images/jsn_logo.gi
209.63.9.37 - - [09/Dec/2001:15:53:02 -0500] "GET /~java/bbs/images/banner/jsn8
209.63.9.37 - - [09/Dec/2001:15:53:03 -0500] "GET /cgi-bin/Count.cgi?ft=0&df=po
209.63.9.37 - - [09/Dec/2001:15:53:03 -0500] "GET /cgi-bin/Count.cgi?ft=0&df=po
209.63.9.37 - - [09/Dec/2001:15:53:04 -0500] "GET /cgi-bin/Count.cgi?ft=0&df=po
209.63.9.37 - - [09/Dec/2001:15:53:04 -0500] "GET /cgi-bin/Count.cgi?ft=0&df=po
209.63.9.37 - - [09/Dec/2001:15:53:04 -0500] "GET /~java/bbs/images/round_left0
209.63.9.37 - - [09/Dec/2001:15:53:04 -0500] "GET /~java/bbs/images/round_right
209.63.9.37 - - [09/Dec/2001:15:53:05 -0500] "GET /~java/bbs/images/c.gif HTTP/
209.63.9.37 - - [09/Dec/2001:15:53:05 -0500] "GET /~java/bbs/images/close-new.g
209.63.9.37 - - [09/Dec/2001:15:53:05 -0500] "GET /~java/bbs/images/clip.jpg HT
209.63.9.37 - - [09/Dec/2001:15:53:05 -0500] "GET /~java/bbs/images/open-new.gi
209.63.9.37 - - [09/Dec/2001:15:53:05 -0500] "GET /~java/bbs/images/1pixel.gif 
209.63.9.37 - - [09/Dec/2001:15:53:09 -0500] "GET / HTTP/1.1" 304 - 0
209.63.9.37 - - [09/Dec/2001:17:03:08 -0500] "GET / HTTP/1.1" 304 - 0
209.63.9.37 - - [09/Dec/2001:17:22:31 -0500] "GET / HTTP/1.1" 200 14 0


15½Ã 37ºÐ¿¡ ÃÖÃÊ Á¢¼ÓÇϰí, 15½Ã 45ºÐ°æ¿¡ 1Â÷ º¯°æÇßÀ¸¸ç, 17½Ã 20ºÐ¿¡ 
"This is lame"À̶õ ¹®±¸¸¦ º¯°æÈÄ, 17½Ã 22ºÐ¿¡ ±×°ÍÀ» È®ÀÎÇÑ °ÍÀ¸·Î º¸ÀδÙ.


IP 209.63.9.37 ´Â ¹Ì±¹ÀÇ CDS NetworkÀ» °æÀ¯ÇÏ¿© Á¢¼ÓÇÑ °ÍÀ¸·Î ³ªÅ¸³µ´Ù.

Electric Lightwave Inc (NETBLK-NETBLK-ELI-NETBLK7) NETBLK-ELI-NETBLK7
				   209.63.0.0 - 209.63.255.255
CDS Networks (NETBLK-ELINETBLK-CDSNET) ELINETBLK-CDSNET
				    209.63.8.0 - 209.63.15.255

CDS Networks (NETBLK-ELINETBLK-CDSNET)
   2661 South Pacific Highway
   Medford, OR 97501
   US

   Netname: ELINETBLK-CDSNET
   Netblock: 209.63.8.0 - 209.63.15.255
   Maintainer: CDSN

   Coordinator:
      Mathisen, Jaye  (JM468-ARIN)  mrcpu@CDSNET.NET
      +1-503-773-9600 (FAX) 541-773-1832



-------------------------------------------------------------------------------
Á¦¸ñ  ¿ÀÈ£¶ó~  
º¸³½³¯Â¥  2001³â 12¿ù 10ÀÏ ¿ù¿äÀÏ, ¿ÀÀü 10½Ã 41ºÐ 42ÃÊ KST  
º¸³½ÀÌ  "ÀÌÇüÀç" <gaia7@orgio.net> [ÁÖ¼Ò·Ï¿¡ Ãß°¡] [¼ö½Å°ÅºÎ¿¡ Ãß°¡]  
¹Þ´ÂÀÌ  javaservice@hanmail.net  


¾Æ..¿¹..¿À·£¸¸¿¡ ¸ÞÀÏÀ» È®ÀÎÇÏ´À¶ó..
¿¡°í..°³ÀÎÀûÀ¸·Î ¿ö³« º¹ÀâÇÑ ÀÏÀÌ ¸¹¾Æ¼­ ^^

¾Æ..¿Ü±¹¾÷ü¿¡¼­ ¿Â°Å´Â¿ä..
¾Æ¸¶ ÀÚ¹Ù¼­ºñ½º¸¦ Å©·¡Å·ÇÑ Å©·¡Ä¿°¡
±× ¾÷ü¿¡ ½Å°í¸¦ Çß³ª º¾´Ï´Ù.

¾Æ¸¶ Å©·¡Ä¿°¡ ´ÔÀÇ »çÀÌÆ®¸¦ Å©·¡Å·ÇÑÈÄ ¾à°£ÀÇ ·Î±×ÆÄÀϰú
ȨÆäÀÌÁö¸¦ º¯°æÇѰÍÀ» ±× ¾÷ü¿¡ ¿Ã·Á ³ù±º¿ä,
º¸¾ÆÇÏ´Ï ±×¸® ³ª»Û»ç¶÷Àº ¾Æ´Ï³×¿ä ^^..

lame À̶ó´Â »ç¶÷ÀÎ°Í °°´øµ¥..
Á¦°¡ ¾Ë±â·Ð ±× ¾ç¹ÝÀÌ µ¶ÀÏ¿¡¼­ À¯¸íÇÑ ÇØÄ¿Àε¥..
¾ó¸¶Àü¿¡ wu-ftp Ŭ¶óÀÌ¾ðÆ® format string ¹ö±× ¾î¼±¸ ÇÏ´ø »ç¶÷Àε¥..
¾Æ..lam ÀÌ¿´´Â°¡? ¿À¶ô°¡¶ô Çϳ׿ä..

¾ÆÂü!! Á¦°¡ Àá½Ã º¸´Ï±ñ ssh ·Î ¶Ç µé¾î ¿Ô³×¿ä
ÀÌ·±..¿¹ÀüÀÇ ssh ¹öÁ¯ ±×´ë·Î ¼³Ä¡ÇÏ½Å°Í °°Àºµ¥..

Áö±Ý »ç¹«½Ç °¡¼­ ´Ù½Ã ¿¬¶ôµå¸®°Ú½À´Ï´Ù

ÀÌÇüÀç



-------------------------------------------------------------------------------
Á¦¸ñ  Re: ´ë´ÜÈ÷ °¨»çµå¸³´Ï´Ù.  
º¸³½³¯Â¥  2001³â 12¿ù 10ÀÏ ¿ù¿äÀÏ, ¿ÀÀü 11½Ã 17ºÐ 10ÃÊ +0900  
º¸³½ÀÌ  "goldennet" <ch3cooh@golden21.net> [ÁÖ¼Ò·Ï¿¡ Ãß°¡] [¼ö½Å°ÅºÎ¿¡ Ãß°¡]  
¹Þ´ÂÀÌ  ÀÌ¿ø¿µ <javaservice@hanmail.net>  

Çü ±Û°í! 
¾ó¸¶Àü¿¡ ¿ï ȸ»ç ÂÊ ¼­¹ö¿¡µµ ÇÔ´çÇß¾ú´Âµ¥.. ¿äÁò sshÂÊ buffer overflow¹ö±×¸¦
ÀÌ¿ëÇØ ¹Ù·Î bin ±ÇÇÑÀ» ¾ò¾î ¹ö¸®µçµ¥.. Ȥ½Ã ±×·± À¯ÇüÀÌ ¾Æ³æÀ»±î..? 

³ªµÎ ¿©‹Ü ½ÄÀÇ attackÀÌ¿´´ÂÁö ±Ã±ÝÇÏ´Ù.. ^^; 
±×·³... 

±ÝÀ¯È¯


-------------------------------------------------------------------------------
2001.12.10 

To: "Alldas.de Incident Handling Center" <abuse@alldas.de>
From : "ÀÌ¿ø¿µ"<javaservice@hanmail.net>
CC : "ÀÌÇüÀç" <gaia7@orgio.net>, "±èÁ¤¼ö"<coculi@lycos.co.kr>
Subject : Re: [RE]Security Incident at www.javaservice.net ( IP: 211.53.127.180 ) 


Hello, 

Thank you for your notification of my web site cracked. 
Here is some information. 

2001.12.09(Sunday) 17:20 KOREA local time. 

"index.html" of my web site was changed as "This is lame". 

# ls -alF 
drwxr-xr-x 4  root root 4096 Dec 9 17:53 ./ 
-rw-r--r-- 1  root root 1113 Dec 9 02:38 .,   <-- ³ªÁß¿¡ ¾Ë¾ÆÂ÷¸° index.html ¿øº»
drwxr-xr-x 6  root root 4096 Dec 7 04:10 ../ 
-rw-r--r-- 1  root root 2494 Dec 7 05:10 favicon.ico 
-rw-rw-r-- 1  root root 14   Dec 9 17:20 index.html 
drwxr-xr-x 3  root root 4096 Dec 6 10:20 manual/ 
-rw-r--r-- 1  root root 1154 Mar 1 2000 poweredby.png 
drwxr-xr-x 10 root root 4096 Dec 8 03:46 wwwcount2.5/ 

All logs in /var/log directory were deleted before 17:33. 
The following logs started at 17:33 again. 

[/var/log/messages] 
....(ommitted)... 

[/var/log/secure] 
....(ommitted)... 


...(log analysis ommitted)...

I suspect the IP address, 209.63.9.37. Whenever the web pages were changed, 
the IP address was logged. 


But, I don't have any information about how the cracker could have 
my system root authentication. Do you know ? 
If you want to check my system and log files, don't hesitate to 
contect me. 

Thanks again. 

WonYoung, Lee 
http://www.javaservice.net 
javaservice@hanmail.net 
+82-11-898-7904 


-------------------------------------------------------------------------------
Á¦¸ñ  Re: [RE]Security Incident at www.javaservice.net ( IP: 211.53.127.180 )  
º¸³½³¯Â¥  2001³â 12¿ù 09ÀÏ ÀÏ¿äÀÏ, ¿ÀÈÄ 4½Ã 21ºÐ 50ÃÊ +0100  
º¸³½ÀÌ  "Helpdesk of Alldas.de" <helpdesk@alldas.de>
¹Þ´ÂÀÌ  "ÀÌ¿ø¿µ" <javaservice@hanmail.net>  
¼Ò¼Ó±â°ü  Alldas.de  

Hi! 

As far as I can see from the statistics that we gathered you were penetrated by 
a bug in BIND 8.2.2-p5. There's a known linux exploit circulating that exploit
that vulnability. Check your logs for bind requests that looks weird and/or other
stuff connected to that application. Did you find anything in ~/.bash_history? 

Best Regards 

Fredrik Ostergren - helpdesk@alldas.de 
Helpdesk of Alldas.de 
IT-Security Information Network 
http://www.alldas.de 

--------------------------------------------------------------------------------
Á¦¸ñ  spash ÀÔ´Ï´Ù.  
º¸³½³¯Â¥  2001³â 12¿ù 10ÀÏ ¿ù¿äÀÏ, Àú³á 6½Ã 09ºÐ 19ÃÊ KST  
º¸³½ÀÌ  "ÀÌÇüÀç" <gaia7@orgio.net> [ÁÖ¼Ò·Ï¿¡ Ãß°¡] [¼ö½Å°ÅºÎ¿¡ Ãß°¡]  
¹Þ´ÂÀÌ  javaservice@hanmail.net  

¾È³çÇϽʴϱî spash ÀÔ´Ï´Ù.

12/9 ÀÏ ÀϾ Å©·¡Å· »ç°í´Â ÇöÀç log ÆÄÀÏÀÌ °ÅÀÇ ³²¾Æ ÀÖÁö ¾ÊÀº »óŶó ±íÀº ºÐ¼®Àº
¾î·Á¿î »óÅÂÀÔ´Ï´Ù.(ÀÌÁ¡ ¾çÇØ ºÎʵ右´Ï´Ù..)
°£´ÜÈ÷ ¸»¾¸µå¸®¸é 53Æ÷Æ®·Î ÅëÇØ¼­ ³×ÀÓ¼­¹ö °ø°ÝÀÌ ÀÌ·ç¾î Á³½À´Ï´Ù.
Áö±ÝÀº ¹æÈ­º®ÀÌ ¼³Ä¡µÇ¾î À§Çè¿ä¼Ò´Â ¾ø¾îÁø »óÅÂÀÌ°í ¹æÈ­º®ÀÌ ¼³Ä¡µÇ¾úÁö¸¸ ssh´Â
¿­¾î³ö¾ß ÇÒ »óȲÀ̹ǷΠÃֽŠssh2 ¸¦ ´Ù½Ã ¼³Ä¡ÇϽñ⠹ٶø´Ï´Ù..

±×¸®°í Àú¹ø Çϵ庹±¸ °ÇÀº Àúº¸´Ù ±×³¯ ¹ãÀ» »õ¸é¼­ ¸ð´ÏÅ͸µ(/homeÀÌ »ì·ÁÁö´ÂÁö
È®ÀÎ ^^) ÇØÁֽŠºÐÀÌ °í»ý ¸¹ÀÌ Çϼ̽À´Ï´Ù..

ÀÌÇüÀç

-------------------------------------------------------------------------------
2001.12.11 02:30ºÐ È®ÀÎÇÑ »çÇ×

jsn:/usr/src# /usr/sbin/named -version
named 8.2.2-P5 Mon Feb 28 10:17:53 EST 2000
  root@porky.devel.redhat.com:/usr/src/bs/BUILD/bind-8.2.2_P5/src/bin/named

ÇöÀç ¿î¿µµÇ°í ÀÖ´Â BIND 8.2.2-P5 ´Â ÀÎÅͳݿ¡¼­ °Ë»öÇØ º» °á°ú ´ÙÀ½°ú °°Àº ¹ö±×µé
Åõ¼ºÀ̾ú´Ù. 

http://www.isc.org/products/BIND/bind-security.html
http://slashdot.org/articles/01/01/30/0435256.shtml


-------------------------------------------------------------------------------
2001.12.11 02:50 BIND 9.1.3À¸·Î Upgrade

jsn:/# /usr/sbin/named -version
BIND 9.1.3


--------------------------------------------------------------------------------
2001.12.11 04:12 Å©·¡Å· ÈçÀû Ãß°¡ ¹ß°ß

/etc/passwd ÆÄÀÏ¿¡ ¾Æ·¡ÀÇ Ç׸ñÀÌ Ãß°¡µÇ¾î ÀÖÀ½À» µÚ´Ê°Ô³ª¸¶ ¹ß°ß.

jsn:/# cat /etc/passwd
.....
a:x:501:501::/.,:/bin/bash
b:x:0:0::/.,:/bin/bash

jsn:/# ls -alFt /      
total 75
drwx------    2 501      501          1024 Dec 11 05:50 .,/
drwxr-xr-x    3 root     root         3072 Dec 11 05:40 sbin/
drwxr-xr-x   30 root     root         3072 Dec 11 05:37 etc/
drwxrwxrwt    3 root     root         1024 Dec 11 05:00 tmp/
drwxr-xr-x   21 root     root         1024 Dec 11 04:14 var/
drwxr-x---    3 root     root         1024 Dec 11 02:03 root/
drwxr-xr-x   18 root     root         1024 Dec  9 15:44 ./
drwxr-xr-x   18 root     root         1024 Dec  9 15:44 ../
drwxr-xr-x    6 root     root        34816 Dec  8 23:41 dev/
drwxr-xr-x   18 root     root         4096 Dec  7 05:28 home/
drwxr-xr-x    3 root     root         1024 Dec  6 14:14 boot/
drwxr-xr-x    5 root     root         1024 Dec  6 10:29 mnt/
drwxr-xr-x    2 root     root         2048 Dec  6 10:21 bin/
drwxr-xr-x    4 root     root         3072 Dec  6 10:21 lib/
drwxr-xr-x   21 root     root         4096 Dec  6 10:20 usr/
drwxr-xr-x    2 root     root        12288 Dec  6 10:13 lost+found/
dr-xr-xr-x   72 root     root            0 Dec  6 09:13 proc/
drwxr-xr-x    2 root     root         1024 Aug 23  1999 opt/

jsn:/# cd /.,
jsn:/.,# ls -alF
total 33
drwx------    2 501      501          1024 Dec 11 05:44 ./
drwxr-xr-x   18 root     root         1024 Dec  9 15:44 ../
-rw-------    1 root     root          492 Dec  9 17:38 .bash_history
-rw-r--r--    1 root     root           24 Dec  9 15:44 .bash_logout
-rw-r--r--    1 root     root          230 Dec  9 15:44 .bash_profile
-rw-r--r--    1 root     root          124 Dec  9 15:44 .bashrc
-rwxr-xr-x    1 root     root          333 Dec  9 15:44 .emacs*
-rw-r--r--    1 root     root         3394 Dec  9 15:44 .screenrc
-rwxr-xr-x    1 501      501          7831 Dec  9 16:21 fame*
-rwxrwxr-x    1 root     root        12654 Dec  9 16:21 rh*

jsn:/.,# cat .bash_history
cd /home/httpd/html
ls
pico
ls
mv index.html .,
mv ezs.html index.html
mv ., ezs.html
rm index.html
pico
ls
who
pico
make fame
ls
rm fame.c
make rh
./rh
chmod +x fame
./fame 209.125.201.200
./fame 209.125.201.38
./rh
rm *.c
./fame 209.125.253.195
./fame 203.251.0.90
./fame 203.251.21.1
./fame 203.251.0.90
./fame 203.251.21.1
./fame 203.251.173.10
./fame 203.251.183.112
cd /home/httpd/html
ls
rm index.html
mv ezs.html index.html
mv index.html .,
echo "this is lame." >> index.html
cd
./rh

jsn:/.,# 

fame °ú rh °¡ ¹¹ÇÏ´Â ³ðÀϱî... ¼Ò½ºÆÄÀÏÀº Áö¿ö¹ö·È´Âµ¥, Disk º¹±¸ ¼Ö·ç¼ÇÀ» ÀÌ¿ëÇϸé
º¹±¸°¡´ÉÇÏÁö ¾ÊÀ»±î... (À¥·Î±× ¶§¹®¿¡ ¾þ¾îÃÆ°Ú±º..)


¾îµð·Î ´Ù½Ã °ø°ÝÇϰí ÀÖ¾ú³ª?

209.125.201.200
209.125.201.38
 Eventide, Inc. (NETBLK-ATWORK-EVENTIDE)
   638 Mountain Road
   Kinnelon, NJ 07405
   US

   Netname: ATWORK-EVENTIDE
   Netblock: 209.125.201.0 - 209.125.201.255

   Coordinator:
      Factor, Richard  (RF68-ARIN)  rcf@eventide.com
      201-641-1200


209.125.253.195
 RETAIL RESOURCES, LP (DSL REPLACEMENT) (NETBLK-ATWORK-55608-49022)
   221 W. 57TH STREET, 2ND FLOOR
   NEW YORK, NY 10005
   US

   Netname: ATWORK-55608-49022
   Netblock: 209.125.253.192 - 209.125.253.255

   Coordinator:
      CESLER, ROBERT  (RC1296-ARIN)  ROB@RRLP.COM
      212-509-5483


¾Æ·¡´Â ±¹³» ¼­¹öµéÀε¥, ....

203.251.0.90 : ¼­¿ï Çѱ¹Åë½Å
203.251.21.1 : ´ëÀü ÇѶó°øÁ¶ Àü»ê½Ç
203.251.173.10 : ¼­¿ï »ùÇ¥½Äǰ
203.251.183.112 : ¼­¿ï ¿õÁøÃâÆÇ¼­


¿©·¯ Á¤È²À¸·Î º¸°Çµ¥, À¥¼­¹ö·Î±×¿¡ ³²¾Æ ÀÖ´ø IP 209.63.9.37 ÀÌ Å©·¡Ä¿ÀÇ IPÀÏ °¡´É¼ºÀÌ
´õ¿í ³ô¾Æ Á³´Ù.

209.63.9.37
 CDS Networks (NETBLK-ELINETBLK-CDSNET)
   2661 South Pacific Highway
   Medford, OR 97501
   US

   Netname: ELINETBLK-CDSNET
   Netblock: 209.63.8.0 - 209.63.15.255
   Maintainer: CDSN

   Coordinator:
      Mathisen, Jaye  (JM468-ARIN)  mrcpu@CDSNET.NET
      503-773-9600 (FAX) 541-773-1832


ÀÌÁ¦ ±×¸¸ Àھ߰ڴÙ.....

-------------------------------------------------------------------------------
2001.12.11 07:40

fame, rh ?  ±×·¸±¸³ª, Á÷Á¢ ½ÇÇà½ÃÄÑ º¸¸é µÇ°Ú±¸³ª...

jsn:/.,# ls -alF
total 33
drwx------    2 501      501          1024 Dec 11 05:50 ./
drwxr-xr-x   18 root     root         1024 Dec  9 15:44 ../
-rw-------    1 root     root          492 Dec  9 17:38 .bash_history
-rw-r--r--    1 root     root           24 Dec  9 15:44 .bash_logout
-rw-r--r--    1 root     root          230 Dec  9 15:44 .bash_profile
-rw-r--r--    1 root     root          124 Dec  9 15:44 .bashrc
-rwxr-xr-x    1 root     root          333 Dec  9 15:44 .emacs*
-rw-r--r--    1 root     root         3394 Dec  9 15:44 .screenrc
-rwxr-xr-x    1 501      501          7831 Dec  9 16:21 fame*
-rwxrwxr-x    1 root     root        12654 Dec  9 16:21 rh*
jsn:/.,# ./rh
Logs have been cleaned!
syslogd restarted!

¾ï... log ÆÄÀÏÀ» Áö¿î ³à¼®ÀÌ À̳ðÀ̱º... rh ´Â ¾Æ¸¶ red hat ÀÇ ¾àÀÚ°ÚÁö?

jsn:/.,# last 

wtmp begins Tue Dec 11 07:43:26 2001


"fame"Àº ¹»±î....

jsn:/.,# ./fame

Omniback II *: remote exploit by DiGiT - teddi@linux.is
Gives possibility to execute any command on a remote system as root!

Usage: ./fame  hostname 

ÈìÈìÈì....

hacker °¡ ´º¿åÀ¸·Î ./fame 209.125.201.200, ./fame 209.125.253.195¸¦ ½ÃµµÇßÀ¸´Ï
Alldas.de º¸¾È¾÷ü¿¡¼­ °ð¹Ù·Î ¾Ë¾ÆÂ÷·È°Ú±º... 
·ç¸¶´Ï¾Æ¿Í ´ë¸¸¿¡¼­´Â ¾î¶»°Ô °ð¹Ù·Î ¾Ë¾ÒÀ»±î... ¹«¼·±º....

-------------------------------------------------------------------------------
2001.12.11 08:20

HP OpenView OmniBack II generic remote exploit

http://www.securiteam.com/exploits/6M00O150KG.html

ÀÚ¹Ù¼­ºñ½º³Ý ÀÌ¿ø¿µ

-------------------------------------------------------------------------------
Á¦¸ñ  Re: Security Incident Last Report(www.javaservice.net)  
º¸³½³¯Â¥  2002³â 02¿ù 01ÀÏ ±Ý¿äÀÏ, ¿ÀÀü 11½Ã 20ºÐ 15ÃÊ +0900  
º¸³½ÀÌ  "knight" <ch3cooh@knight.ce.knu.ac.kr>
¹Þ´ÂÀÌ  ÀÌ¿ø¿µ <javaservice@hanmail.net>  

Çü! °í»ýÀÌ ¸¹³×¿ä! 

Èå¹Ì ´Ê¾úÁö¸¸... 

jsn:/.,# ls -al 
total 33 
drwx------ 2 501 501 1024 Dec 11 10:20 ./ 
drwxr-xr-x 18 root root 1024 Dec 11 10:21 ../ 
-rw------- 1 root root 492 Dec 9 17:38 .bash_history 
-rw-r--r-- 1 root root 24 Dec 9 15:44 .bash_logout 
-rw-r--r-- 1 root root 230 Dec 9 15:44 .bash_profile 
-rw-r--r-- 1 root root 124 Dec 9 15:44 .bashrc 
-rwxr-xr-x 1 root root 333 Dec 9 15:44 .emacs* 
-rw-r--r-- 1 root root 3394 Dec 9 15:44 .screenrc 
-rwxr-xr-x 1 501 501 7831 Dec 9 16:21 fame* ==> ***** 
-rwxrwxr-x 1 root root 12654 Dec 9 16:21 rh* 

fameÀ» Á÷Á¢ ½ÇÇà ½ÃÄÑ ¹»·Î °ø°ÝÇϳª ÇØ¼­ tcpdump·Î °üÂû Çߴµ¥.. 

[root@ns /]# tcpdump -i eth0 -vv | grep 211.53.127.180 
Kernel filter, protocol ALL, datagram packet socket 
tcpdump: listening on eth0 
10:49:11.119681 < 211.53.127.180.2623 > ns.knu.keumkyungyun.com.5555: S 2268633
268:2268633268(0) win 32120 <mss 1460,sackOK,timestamp 42036548 0,nop,wscale 0>
(DF) (ttl 56, id 40461) 
10:49:11.119715 > ns.knu.keumkyungyun.com.5555 > 211.53.127.180.2623: R 0:0(0) 
ack 2268633269 win 0 (DF) (ttl 255, id 0) 
10:49:11.142926 < 211.53.127.180 > ns.knu.keumkyungyun.com: icmp: 211.53.127.18
0 tcp port 2623 unreachable Offending pkt: ns.knu.keumkyungyun.com.5555 > 211.5
3.127.180.2623: R 0:0(0) ack 1 win 0 (DF) (ttl 247, id 0) [tos 0xc0] (ttl 247, 
id 40462) 
10:49:14.106268 < 211.53.127.180.2623 > ns.knu.keumkyungyun.com.5555: S 2268633
268:2268633268(0) win 32120 <mss 1460,sackOK,timestamp 42036848 0,nop,wscale 0>
(DF) (ttl 56, id 40499) 
10:49:14.106292 > ns.knu.keumkyungyun.com.5555 > 211.53.127.180.2623: R 0:0(0) 
ack 1 win 0 (DF) (ttl 255, id 0) 
10:49:14.121148 < 211.53.127.180 > ns.knu.keumkyungyun.com: icmp: 211.53.127.18
0 tcp port 2623 unreachable Offending pkt: ns.knu.keumkyungyun.com.5555 > 211.5
3.127.180.2623: R 0:0(0) ack 1 win 0 (DF) (ttl 247, id 0) [tos 0xc0] (ttl 247, 
id 40500) 
10:49:20.105209 < 211.53.127.180.2623 > ns.knu.keumkyungyun.com.5555: S 2268633
268:2268633268(0) win 32120 <mss 1460,sackOK,timestamp 42037448 0,nop,wscale 0>
(DF) (ttl 56, id 40512) 
10:49:20.105247 > ns.knu.keumkyungyun.com.5555 > 211.53.127.180.2623: R 0:0(0) 
ack 1 win 0 (DF) (ttl 255, id 0) 
10:49:20.120000 < 211.53.127.180 > ns.knu.keumkyungyun.com: icmp: 211.53.127.18
0 tcp port 2623 unreachable Offending pkt: ns.knu.keumkyungyun.com.5555 > 211.5
3.127.180.2623: R 0:0(0) ack 1 win 0 (DF) (ttl 247, id 0) [tos 0xc0] (ttl 247, 
id 40513)  

  [±Û¸ñ·Ï /½Ã°£¼ø] [´ä±Û¾²±â] [ÇÁ¸°Æ®]