服务器维护,服务器代维,安全设置,漏洞扫描,入侵检测服务

dirtysea 发表于 2007-11-9 19:51:21

渗透华夏黑客联盟

<SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">本次渗透是我和好友雪飘一起完成的,华夏黑客联盟是我的启蒙网站,很早我就想对它进行一次检测,但是一直没时间,今天终于有了一天的休息时间,便有了我们这次渗透。&nbsp;</SPAN>&nbsp;
<P></P>
<P>&nbsp;</P>
<P>&nbsp;</P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 156.6pt; mso-outline-level: 1; mso-layout-grid-align: none"><B><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"><FONT face=Arial>旁注拿到webshell&nbsp;</FONT></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 156.6pt; mso-outline-level: 1; mso-layout-grid-align: none"><B><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"><FONT face=Arial></FONT></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 156.6pt; mso-outline-level: 1; mso-layout-grid-align: none"><B><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"></SPAN></B>&nbsp;</P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 20pt; TEXT-ALIGN: left; mso-layout-grid-align: none" align=left><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"><FONT face=Arial>下面开始我们的渗透之旅,华夏黑客同盟是老牌子的黑客网站,我想主站应该不会有什么漏洞,那我们还是旁注来完成吧,我先ping了主站的域名</FONT><A href="http://www.77169.com/" target=_blank><FONT face=Arial>www.77169.com</FONT></A><FONT face=Arial>,返回219.147.204.245。下面打开名小子的旁注工具domain3.5,扫描这个IP绑定了多少个域名,(如图1)</FONT></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 20pt; TEXT-ALIGN: left; mso-layout-grid-align: none" align=left><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"><FONT face=Arial><IMG alt="" src="http://www.rabbitsafe.cn/attachments/month_0709/i200791621598.jpg"></FONT></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 20pt; TEXT-ALIGN: left; mso-layout-grid-align: none" align=left><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"></SPAN><FONT face=Arial><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">三个域名,但是都是指向主站,这也在我的意料之中,我想华夏应该是独立服务器。</SPAN>&nbsp;</FONT></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><FONT face=Arial><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">这时我想,华夏的机房总不只一台主机吧,如果华夏这个网段的其它主机存在漏洞,先拿下再想办法渗透主站也可以啊。说干就干,拿出扫描器scanner3.0,先扫了一下219.147.204.245</SPAN><SPAN lang=EN-US style="FONT-SIZE: 10pt; mso-font-kerning: 0pt">—</SPAN><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">219.147.204.254这一段,只扫描了80端口,(如图2)</SPAN></FONT></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"><FONT face=Arial><IMG alt="" src="http://www.rabbitsafe.cn/attachments/month_0709/i20079162206.jpg"></FONT></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"><FONT face=Arial>最后通过分析定下ip219.147.204.249进行渗透,因为直接扫到一个动网论坛的备份后的默认数据库没改,</FONT><A href="http://www.kaisendianli.com/databackup/dvbbs7_backup.mdb" target=_blank><FONT face=Arial>http://www.kaisendianli.com/databackup/dvbbs7_backup.mdb</FONT></A><FONT face=Arial>下载数据库后轻松得到webshell,(如图3)</FONT></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><FONT face=Arial><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"><A title=在新窗口打开图片 href="http://www.rabbitsafe.cn/attachments/month_0709/r200791622230.jpg" target=_blank><IMG alt="" src="http://www.rabbitsafe.cn/attachments/month_0709/r200791622230.jpg" width=550></A>下面开始收集服务器的可用信息,</SPAN><FONT size=3><SPAN lang=EN-US style="mso-bidi-font-size: 10.5pt">fso</SPAN><SPAN style="FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-size: 10.5pt">可用;</SPAN></FONT><SPAN lang=EN-US style="FONT-SIZE: 9pt">wscript..shell</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">不可用,当然</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">cmd</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">命令也不能执行;</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">d</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">盘下不可访问,其他盘均可访问;可以上传文件。而且在c盘和f盘下面都找到一些华夏的东西,这时我怀疑可能是华夏的一个分站,还是想办法提权,服务器是2003的系统,竟然asp网页木马没多大权限,那先试试其它的网页木马吧,上传了php,aspx,jsp,cgi在渗透网站的那个目录,但是都不能解析,其它溢出提权方法也试了,但都以失败而告终。于是叫上了好友雪飘和煙圈配咖啡,把webshell给他们,让他们想想办法,我说这个站和华夏关系很大,大家马上来了精神,我就把任务交给雪飘和煙圈配咖啡了。&nbsp;</SPAN></FONT></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"></SPAN>&nbsp;</P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 153.35pt; mso-outline-level: 1; mso-layout-grid-align: none"><B><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"><FONT face=Arial>从asp到asp.net&nbsp;</FONT></SPAN></B></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 153.35pt; mso-outline-level: 1; mso-layout-grid-align: none"><B><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"></SPAN></B>&nbsp;</P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><FONT face=Arial><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">雪拿到我给他的webshell后,对各个盘的目录粗略的访问了下,其中两个目录引起了雪的注意,</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">E:\webdisk</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">和</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">F:\xxxx_webdisk</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">(其中的</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">xxxx</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">是几个数字,具体也记不得了)。在这两个目录里都是</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">ASP.NET</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">文件。雪的第一反映是这服务器可能是</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">win2003</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">的机子。扫了下</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">80</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">端口,返回</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">IIS6.0</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">,八九不离十就是</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">win2003</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">了。在默认情况下</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">win2003</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">下</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">ASP.NET</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">木马比</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">ASP</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">木马的权限要大。接下去是要找到这个</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">web</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">目录所对应的网址,之后上传</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">ASP.NET</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">木马。</SPAN>&nbsp;</FONT></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><FONT face=Arial><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">由于这个webshell和华夏的站有关,而且说明文件写的是网络硬盘程序,抱着试试看的心态在百度上搜了下</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">“</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">华夏黑客同盟网络硬盘</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">”</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">,百度真是个好东西啊,终于找到了,并且是</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">ASP</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">。</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">NET</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">的,接下去,在</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">E:\webdisk</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">和</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">F:\xxxx_webdisk</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">各下写入一个asp.net木马文件,访问了下(如图4),</SPAN></FONT></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><FONT face=Arial><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"><A title=在新窗口打开图片 href="http://www.rabbitsafe.cn/attachments/month_0709/72007917105310.jpg" target=_blank><IMG alt="" src="http://www.rabbitsafe.cn/attachments/month_0709/72007917105310.jpg" width=550></A>最终确定</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">web</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">目录是</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">F:\xxxx_webdisk</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">,看了下权限,但权限还是很小。比asp权限高点可以执行cmd命令了。</SPAN>&nbsp;</FONT></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"><FONT face=Arial>执行ipconfig,(如图5)</FONT></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><FONT face=Arial><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"><A title=在新窗口打开图片 href="http://www.rabbitsafe.cn/attachments/month_0709/k2007917105344.jpg" target=_blank><IMG alt="" src="http://www.rabbitsafe.cn/attachments/month_0709/k2007917105344.jpg" width=550></A>服务器上竟然用了三网卡,其中两个电信ip是</SPAN><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">219.147.204.245和219.147.204.249,一个网通的ip是60.14.252.196,当我们看到其中一个ip是219.147.204.245时,和ping主站<A href="http://www.77169.com/" target=_blank>www.77169.com</A>返回219.147.204.245一样,没想到这台主机竟然是华夏主站,真是踏破铁鞋无觅处,得来全不费功夫。拿到</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">华夏网络硬盘的</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">webshell</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">后,下面就应该把目标放到华夏主站的webshell。现在可以确认主站放在d盘,但是d盘没权限访问,渗透又陷入困境。</SPAN></FONT></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"></SPAN>&nbsp;</P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 141.45pt; mso-layout-grid-align: none"><FONT face=Arial><B><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">得到主站webshell</SPAN></B><B><SPAN lang=EN-US style="FONT-SIZE: 12pt">&nbsp;</SPAN></B></FONT></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 141.45pt; mso-layout-grid-align: none"><B><SPAN lang=EN-US style="FONT-SIZE: 12pt"></SPAN></B>&nbsp;</P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><FONT face=Arial><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">在接下去的一两个小时里没有半点思路。后来雪用</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">pulist.exe</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">查看了下服务器的进程。之后当雪访问到</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">C:\syn\</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">目录时,一个文件引起了雪的兴趣:</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">SEServer.exe</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">,在进程当中雪也看到了这个文件名,于是雪把</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">C:\syn\syn.zip</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">下载到了本地。</SPAN>&nbsp;</FONT></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"><FONT face=Arial>看了下里面的文件,(如图6)。</FONT></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"><FONT face=Arial><IMG alt="" src="http://www.rabbitsafe.cn/attachments/month_0709/k200791710546.jpg"></FONT></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><FONT face=Arial><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">是个同步专家,读了下自述文件。基本确定华夏是通过这个软件来实现镜像文件和主站文件同步的。在本地测试了下这个软件,发现可以向服务器</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">web</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">目录下写入文件,但是现在还不知道安装在华夏的那个服务器端的用户和密码。</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">&nbsp;</SPAN>&nbsp;</FONT></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><FONT face=Arial><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">回到</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">webshell</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">,发现这个软件同目录下有个</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">SEServer.cfg</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">文件,用记事本打开本地的这个文件是乱码。给雪的感觉这个文件可能是服务器端的配置文件。我从服务器上下载了这个文件,并把本地的覆盖掉,重新运行</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">SEServer.exe</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">。用星号密码读取器读出密码。(如图7)</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">&nbsp;</SPAN></FONT></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><SPAN lang=EN-US style="FONT-SIZE: 9pt"></SPAN>&nbsp;<IMG alt="" src="http://www.rabbitsafe.cn/attachments/month_0709/o2007917105431.jpg"></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><FONT face=Arial><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">现在,激动的时候到了,我小心翼翼的拿出</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">SEClient.exe</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">连接华夏的服务器端,提示登陆成功(图8),</SPAN></FONT></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"><FONT face=Arial><IMG alt="" src="http://www.rabbitsafe.cn/attachments/month_0709/m2007917105449.jpg"></FONT></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><FONT face=Arial><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">真是爽歪了,接着当然是写入</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">asp</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">木马。</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">&nbsp;</SPAN>&nbsp;</FONT></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><FONT face=Arial><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">登陆</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">asp</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">木马后却发现权限设置的真</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">BT</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">啊,在</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">web</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">目录都没法写入,还好我有文件同步,可以写入文件,这样华夏主站的</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">webshell</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">就拿到了(图9)。</SPAN></FONT></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none">&nbsp;<IMG alt="" src="http://www.rabbitsafe.cn/attachments/month_0709/b200791710559.jpg"></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><FONT face=Arial><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">看看时间也不早了,</SPAN><SPAN lang=EN-US style="FONT-SIZE: 9pt">4</SPAN><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">点多了,给兔子发了个留言,也就睡下了。&nbsp;</SPAN></FONT></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><FONT face=Arial><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"></SPAN></FONT></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"></SPAN>&nbsp;</P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 189.15pt; mso-layout-grid-align: none"><FONT face=Arial><B><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'">冲刺3389</SPAN></B><B><SPAN lang=EN-US style="FONT-SIZE: 12pt">&nbsp;</SPAN></B></FONT></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 189.15pt; mso-layout-grid-align: none"><FONT face=Arial><B><SPAN lang=EN-US style="FONT-SIZE: 12pt"></SPAN></B></FONT></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 189.15pt; mso-layout-grid-align: none"><B><SPAN lang=EN-US style="FONT-SIZE: 12pt"></SPAN></B>&nbsp;</P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"><FONT face=Arial>第二天早上,我上qq就看见雪给我发的信息,雪真强啊,尽然拿到主站的的权限了,这一时刻终于来到了。 </FONT></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"></SPAN><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"><FONT face=Arial>雪让我继续完成接下来的工作,拿下服务器,看了下雪拿下服务器的过程,我也认真看了c:\syn\目录里的文件,一个文件引起了我的兴趣:stop.bat这个批处理文件,是重启iis的命令,这让我想起来了昨天晚上华夏的主站突然不能访问,到底是服务器重启还是iis重启呢?为了确定,在webshell中执行query user,发现管理员登陆时间是几天前,这样就排除了重启这种可能,我就试着对这个文件进行编辑,写入了加管理员的命令,没想到这个文件竟然有权限修改。其实在system32下也有写入权限的,可以用替换服务,然后用3389.exe(3389.exe是开3389的但是有重启功能,而且权限不用很高)让它重启,进行提权,但是这样过于危险,所以选择了前面这种被动的方式。接下来的就是等待。 </FONT></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"></SPAN><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"><FONT face=Arial>晚上10点多,雪上线后说服务器怎么加了个用户,我马上打开webshell,查看了下服务器用户,早上加的用户真的在上面,马上和雪一起分析了情况,我们肯定了,那个stop.bat文件应该是计划任务文件,可能是每12小时执行一次,晚上9点多执行,用于重启iis服务的,尽然用户加上了,通过测试,网通的那个ip可以登录3389,于是我们登录上去了,(如图10)</FONT></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"><FONT face=Arial><A title=在新窗口打开图片 href="http://www.rabbitsafe.cn/attachments/month_0709/e2007917105544.jpg" target=_blank><IMG alt="" src="http://www.rabbitsafe.cn/attachments/month_0709/e2007917105544.jpg" width=550></A>但网速慢了,我就传了个灰鸽子上去,上线的华夏主机(如图11),</FONT></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none"><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"><FONT face=Arial><A title=在新窗口打开图片 href="http://www.rabbitsafe.cn/attachments/month_0709/c200791710561.jpg" target=_blank><IMG alt="" src="http://www.rabbitsafe.cn/attachments/month_0709/c200791710561.jpg" width=550></A>在灰鸽子上执行cmd后返回的信息(如图12)。</FONT></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 21.75pt; mso-layout-grid-align: none">&nbsp;<IMG alt="" src="http://www.rabbitsafe.cn/attachments/month_0709/n2007917105616.jpg"></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-layout-grid-align: none"><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"><FONT face=Arial>但是最后有一点出乎我们的判断,stop.bat并不是计划任务启动的,当然在服务器上我们也没找到它的定时启动方式,希望哪位大虾能给我们指点指点.&nbsp;</FONT></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-layout-grid-align: none"><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-layout-grid-align: none"><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-layout-grid-align: none"><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-layout-grid-align: none"><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-layout-grid-align: none" align=center><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"><STRONG><FONT face=Arial size=5>尾声</FONT></STRONG></SPAN></P>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-layout-grid-align: none" align=center><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"><STRONG><FONT face=Arial size=5></FONT></STRONG></SPAN></P><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 宋体; mso-font-kerning: 0pt; mso-bidi-font-family: 宋体; mso-ansi-language: ZH-CN; mso-hansi-font-family: 'Times New Roman'"><STRONG>
<P class=MsoNormal style="MARGIN: 0cm 0cm 0pt; mso-layout-grid-align: none" align=left><FONT face=Arial></FONT>&nbsp;</P></STRONG><FONT face=Arial>&nbsp;&nbsp; 至此,我们的渗透已经结束,本次渗透并没有什么新的技术,只是利用了服务器权限设置上的不当。当然在写文章之前我们已经通知了华夏,但华夏的应急机制似乎……网络安全不是儿戏,希望所有的网管都能尽到自己的责任</FONT></SPAN>

骨色骨香 发表于 2006-6-7 05:31:11

re:渗透华夏黑客联盟

呃.....七天了吧?
据说7天是一个习惯养成的周期....
花上帝造人外加休息的时间来酝酿失恋后的感觉,应该是够了吧?
可以继续飞翔了么?
页: [1]
查看完整版本: 渗透华夏黑客联盟