﻿{"id":277,"date":"2009-09-15T16:27:49","date_gmt":"2009-09-15T16:27:49","guid":{"rendered":""},"modified":"2011-11-18T17:06:58","modified_gmt":"2011-11-18T09:06:58","slug":"277","status":"publish","type":"post","link":"http:\/\/zerobox.org\/notes\/277.html","title":{"rendered":"\u4e00\u6b21\u5e38\u89c1\u7684Linux\u5165\u4fb5"},"content":{"rendered":"<p><span style=\"font-size: x-small;\">\u6700\u8fd1\uff0c\u6211\u75af\u72c2\u7684\u8ff7\u4e0a\u4e86Linux\u90a3\u4f18\u96c5\u7684\u7ec5\u58eb\u5e3d\u3002\u5076\u5c14\u8fde\u4e0a\u4e00\u53f0\u670d\u52a1\u5668\uff0c\u62ff\u51e0\u4e2a\u5de5\u5177\u626b\u63cf\u540e\uff0c\u6211\u53d1\u73b0Linux\u5176\u5b9e\u7f3a\u7701\u542f\u52a8\u4e86\u5f88\u591a\u670d\u52a1\uff0c\u6bd4\u8f83\u5178\u578b\u7684\u6709Rlogind\u3001Inetd\u3001Httpd\u3001Innd\u3001Fingerd\u7b49\uff0c\u4f30\u8ba1\u7f51\u7ba1\u4e0d\u662f\u4e2a\u52e4\u5feb\u7684\u4eba\u3002\u867d\u7136\u6211\u5e76\u4e0d\u662f\u4e00\u4e2a\u6f0f\u6d1e\u9769\u65b0\u8005\uff0c\u4f46\u5229\u7528\u6700\u65b0\u516c\u5e03\u7684\u9ed1\u5ba2\u5de5\u5177\u6765\u7a81\u7834\u4e00\u4e2a\u521a\u521a\u88ab\u53d1\u73b0\u7684\u5b89\u5168\u6f0f\u6d1e\uff0c\u5e76\u4e0d\u662f\u5f88\u56f0\u96be\u7684\u4e8b\u60c5\u3002<br \/>\n\u5165\u4fb5<br \/>\n\u786e\u5b9a\u76ee\u6807\u4e4b\u524d\uff0c\u6211\u51c6\u5907\u4e86\u4e00\u4e9bLinux\u4e0b\u7684\u57fa\u672c\u5de5\u5177\u3002<br \/>\n1\uff0e\u4eceGCC\u5f00\u59cb<br \/>\nGCC\u662fLinux\u4e0b\u653b\u51fb\u8005\u7684\u5fc5\u5907\u5229\u5668\u4e4b\u4e00\uff0c\u5b83\u662f\u4e00\u6b3e\u529f\u80fd\u5f3a\u5927\u3001\u6027\u80fd\u4f18\u8d8a\u7684\u591a\u5e73\u53f0\u7f16\u8bd1\u5668\u3002GCC\u7684\u57fa\u672c\u7528\u6cd5\u662f\uff1aGCC [options] [filenames]\uff0c\u5176\u4e2dOptions\u5c31\u662f\u7f16\u8bd1\u5668\u6240\u9700\u8981\u7684\u53c2\u6570\uff0cFilenames\u662f\u76f8\u5173\u7684\u6587\u4ef6\u540d\u79f0\u3002<\/span><\/p>\n<p>TIPS\uff1aGCC\u5e38\u89c1\u7684\u53c2\u6570\u6709\uff1a<br \/>\n-c\uff0c\u53ea\u7f16\u8bd1\uff0c\u4e0d\u8fde\u63a5\u6210\u4e3a\u53ef\u6267\u884c\u6587\u4ef6\uff0c\u7f16\u8bd1\u5668\u53ea\u662f\u7531\u8f93\u5165\u7684.c\u7b49<span class=\"t_tag\" onclick=\"tagshow(event)\">\u6e90\u4ee3\u7801<\/span>\u6587\u4ef6\u751f\u6210.o\u4e3a\u540e\u7f00\u7684\u76ee\u6807\u6587\u4ef6\uff0c\u901a\u5e38\u7528\u4e8e\u7f16\u8bd1\u4e0d\u5305\u542b\u4e3b\u7a0b\u5e8f\u7684\u5b50\u7a0b\u5e8f\u6587\u4ef6\u3002<br \/>\n-o output_filename\uff0c\u786e\u5b9a\u8f93\u51fa\u6587\u4ef6\u7684\u540d\u79f0\u4e3aoutput_filename\uff0c\u540c\u65f6\u8fd9\u4e2a\u540d\u79f0\u4e0d\u80fd\u548c\u6e90\u6587\u4ef6\u540c\u540d\u3002\u5982\u679c\u4e0d\u7ed9\u51fa\u8fd9\u4e2a\u9009\u9879\uff0cGCC\u5c31\u7ed9\u51fa\u9884\u8bbe\u7684\u53ef\u6267\u884c\u6587\u4ef6a.out\u3002<br \/>\n-g\uff0c\u4ea7\u751f\u7b26\u53f7\u8c03\u8bd5\u5de5\u5177\u6240\u5fc5\u8981\u7684\u7b26\u53f7\u3002<br \/>\n-O\uff0c\u5bf9\u7a0b\u5e8f\u8fdb\u884c\u4f18\u5316\u7f16\u8bd1\u3001\u8fde\u63a5\u3002<\/p>\n<p>\u4e0b\u9762\u662f\u4e00\u4e2a\u7b80\u5355\u7684\u4f8b\u5b50\u3002\u9996\u5148\u542f\u52a8Linux\uff0c\u8fdb\u5165\u5230VI\u754c\u9762\uff0c\u6253\u5f00VI a.c\uff0c\u7136\u540e\u968f\u610f\u5199\u5165\u4e00\u6bb5C\u8bed\u8a00\u7a0b\u5e8f\uff0c\u4f8b\u5982\uff1a<br \/>\n\uff03include &#8220;stdio.h&#8221;<br \/>\nint main()<br \/>\n{<br \/>\nprintf(&#8220;test GCC&#8221;);<br \/>\n}<br \/>\n\u7136\u540e\u7528GCC\u7f16\u8bd1\uff0c\u547d\u4ee4\u4e3a\uff1aGCC a.c\uff0c\u7136\u540e\u4f1a\u4ea7\u751f\u4e00\u4e2aa.out\u7684\u6587\u4ef6\uff0c\u7528\u547d\u4ee4\u201c.\/a.out\u201d\u6267\u884c\u5373\u53ef\uff0c\u8fd9\u4e2a\u5de5\u5177\u5bf9\u4e8eLinux\u4e0b\u7684\u6f0f\u6d1e\u653b\u51fb\u5341\u5206\u7ba1\u7528\uff0c\u56e0\u6b64\uff0c\u201c\u8089\u9e21\u201d\u4e0a\u662f\u5426\u5f00\u653e\u4e86\u8fd9\u4e2a\u529f\u80fd\u5c31\u663e\u5f97\u5f88\u91cd\u8981\u4e86\u3002<br \/>\n2\uff0e\u8fde\u63a5\uff1a\u5c3d\u5728\u638c\u63e1<br \/>\n\u73b0\u5728\uff0c\u8be5\u8003\u8651\u76ee\u6807\u673a\u5668\u4e86\u3002\u6839\u636e\u6211\u638c\u63e1\u7684\u60c5\u51b5\uff0c\u67d0\u5355\u4f4d\u7684\u4e00\u5e2e\u95f2\u4eba\u5b89\u5168\u610f\u8bc6\u5341\u5206\u8584\u5f31\uff0c\u800c\u4e14\u627f\u5305\u7cfb\u7edf\u7ba1\u7406\u7684\u5355\u4f4d\u4e5f\u6574\u5929\u65e0\u6240\u4e8b\u4e8b\u3002\u626b\u63cf\u3001\u641c\u7d22\uff0c\u627e\u5230\u4e00\u4e2a\u76ee\u6807\u540e\uff0c\u8be5\u8003\u8651\u8003\u8651\u653b\u51fb\u624b\u6bb5\u4e86\uff0cCrack Passwd\uff1f<span class=\"t_tag\" onclick=\"tagshow(event)\">Buffer<\/span> <span class=\"t_tag\" onclick=\"tagshow(event)\">Overflow<\/span>\uff1fCGI\u6f0f\u6d1e\u5229\u7528\uff1f\u4e0d\u8fc7\uff0c\u9996\u5148\u8981\u628a\u76ee\u6807\u673a\u8fde\u4e0a\uff0c\u6d4b\u8bd5\u4e00\u4e0b\uff1a<br \/>\nC:&gt;ping 203.207.xxx.xxx<br \/>\nPinging 203.207.xxx.xxx [203.207.xxx.xxx] with 32 bytes of data:<br \/>\nReply from 203.207.xxx.xxx: bytes=32 time=210ms TTL=119<br \/>\nReply from 203.207.xxx.xxx: bytes=32 time=130ms TTL=119<br \/>\nReply from 203.207.xxx.xxx: bytes=32 time=561ms TTL=119<br \/>\nReply from 203.207.xxx.xxx: bytes=32 time=501ms TTL=119<br \/>\nPing statistics for 203.207.xxx.xxx:<br \/>\nPackets: Sent = 4, Received = 4, Lost = 0 (0% loss),<br \/>\nApproximate round trip times in milli-seconds:<br \/>\nMinimum = 130ms, Maximum = 561ms, Average = 350ms<br \/>\n\u770b\u770b\u76ee\u6807\u6709\u6ca1\u6709\u5f00Finger\u670d\u52a1\uff1f\u4e00\u822c\u6765\u8bf4\u5229\u7528Finger\uff0c\u603b\u53ef\u4ee5\u5f97\u5230\u51e0\u4e2a\u7528\u6237\u540d\u4fe1\u606f\uff0c\u518d\u901a\u8fc7\u7b80\u5355\u7684\u731c\u6d4b\u6765\u8bd5\u63a2\u7528\u6237\u5bc6\u7801\u3002\u5f97\u5230\u4e00\u4e9b\u666e\u901a\u7528\u6237\u5e10\u53f7\u540e\uff0c\u5c31\u53ef\u4ee5\u8003\u8651\u7528Telnet\u65b9\u6cd5\u6765\u770b\u770b\u4e86\u3002<br \/>\n3\uff0e\u626b\u63cf\uff1a\u770b\u4e2a\u6e05\u6e05\u695a\u695a<br \/>\n\u73b0\u5728\uff0c\u8be5\u8003\u8651\u626b\u63cfLinux\u670d\u52a1\u5668\u4e86\u3002\u76ee\u6807\u5f00\u4e86\u54ea\u4e9b\u7aef\u53e3\uff1f\u8fd9\u4e9b\u7aef\u53e3\u6709\u4ec0\u4e48\u5229\u7528\u4ef7\u503c\uff1f\u626b\u63cf\u8fd4\u56de\u7684Banner\u4fe1\u606f\u8bf4\u660e\u76ee\u6807\u662f\u4ec0\u4e48\u7cfb\u7edf\uff1f\u4ec0\u4e48\u7248\u672c\uff1f\u8fd9\u4e9b\u7248\u672c\u7684OS\u6709\u4ec0\u4e48\u53ef\u5229\u7528\u7684\u6f0f\u6d1e\uff1f\u6211\u4eec\u6709\u54ea\u4e9b\u653b\u51fb\u65b9\u6cd5\u53ef\u4ee5\u4f7f\u7528\uff1f\u8fd8\u662f\u4e00\u6b65\u4e00\u6b65\u6765\u5427\uff01<br \/>\nNMap\uff08Network Mapper\uff09\u662fLinux\u4e0b\u7684\u7f51\u7edc\u626b\u63cf\u548c\u55c5\u63a2\u5de5\u5177\u5305\uff0c\u5176\u57fa\u672c\u529f\u80fd\u6709\u4e09\u4e2a\uff0c\u4e00\u662f\u63a2\u6d4b\u4e00\u7ec4\u4e3b\u673a\u662f\u5426\u5728\u7ebf\uff1b\u5176\u6b21\u662f\u626b\u63cf\u4e3b\u673a\u7aef\u53e3\uff0c\u55c5\u63a2\u63d0\u4f9b\u7684\u7f51\u7edc\u670d\u52a1\uff1b\u4e09\u662f\u53ef\u4ee5\u63a8\u65ad\u4e3b\u673a\u6240\u7528\u7684\u64cd\u4f5c\u7cfb\u7edf\u3002Nmap\u53ef\u7528\u4e8e\u626b\u63cf\u4ec5\u6709\u4e24\u4e2a\u8282\u70b9\u7684LAN\uff0c\u76f4\u81f3500\u4e2a\u8282\u70b9\u4ee5\u4e0a\u7684\u7f51\u7edc\u3002\u6b64\u5916\uff0c\u5b83\u8fd8\u5141\u8bb8\u7528\u6237\u5b9a\u5236\u626b\u63cf\u6280\u5de7\uff0c\u5e76\u80fd\u5c06\u63a2\u6d4b\u7ed3\u679c\u8bb0\u5f55\u5230\u5404\u79cd\u683c\u5f0f\u7684\u65e5\u5fd7\u4e2d\uff0c\u4f9b\u8fdb\u4e00\u6b65\u5206\u6790\u64cd\u4f5c\u3002<br \/>\nNMap\u53ef\u4ee5\u4ece<a href=\"http:\/\/www.insecure.org\/nmap\/\" target=\"_blank\"><span style=\"font-size: x-small;\">http:\/\/www.insecure.org\/nmap\/<\/span><\/a><span style=\"font-size: x-small;\">\u83b7\u5f97\u3002\u53ef\u4ee5\u9009\u62e9RPM\u683c\u5f0f\u6216\u8005RPM\u6e90\u7801\u683c\u5f0f\u5b89\u88c5\u3002\u4ee5\u4e0b\u662f\u4e00\u4e2a\u5b89\u88c5\u8303\u4f8b\uff1a<br \/>\nbzip2 -cd nmap-VERSION.tar.bz2 | tar xvf &#8211;<br \/>\ncd nmap-VERSION<br \/>\n.\/configure<br \/>\nmake<br \/>\nsu root<br \/>\nmake install<br \/>\n\u6267\u884cNMAP\u540e\uff0c\u6211\u4eec\u770b\u5230\u5982\u4e0b\u7ed3\u679c\uff1a<br \/>\n# nmap -sS -T Agressive -p 1-10000 203.207.xxx.xxx | grep open<br \/>\nPort State Protocol SerVIce<br \/>\n21 open tcp ftp<br \/>\n22 open tcp ssh<br \/>\n25 open tcp smtp<br \/>\n80 open tcp http<br \/>\n119 open tcp nntp<br \/>\n3306 open tcp mysql<br \/>\n\u4ece\u4ee5\u4e0a\u7684\u5206\u6790\u5217\u8868\u53ef\u4ee5\u770b\u5230\uff0c203.207.xxx.xxx\u4f5c\u4e3aWWW\u548cFTP\u670d\u52a1\u5668\u4f7f\u7528\uff0c\u6b64\u5916\uff0c\u8be5\u670d\u52a1\u5668\u8fd8\u63d0\u4f9b\u4e86SSH\u3001SMTP\u3001NNTP\u3001MSQL\u548cMSQL1\u670d\u52a1\u3002\u5728\u8fd9\u4e9b\u670d\u52a1\u4e2d\uff0cSSH\u662f\u4e00\u79cd\u5e26\u6709\u5b8c\u5584\u52a0\u5bc6\u548c\u8ba4\u8bc1\u673a\u5236\u7684\u534f\u8bae\uff0c\u5982\u679c\u670d\u52a1\u5668\u4e0a\u8fd0\u884c\u7684SSH\u662f\u6700\u65b0\u7248\u672c\uff0c\u90a3\u4e48\u653b\u51fb\u5b83\u5c31\u6709\u4e00\u5b9a\u7684\u96be\u5ea6\u3002HTTP\u3001FTP\u3001SMTP\u548cNNTP\u662f203.207.xxx.xxx\u670d\u52a1\u5668\u5b9e\u9645\u63d0\u4f9b\u7684\u670d\u52a1\uff0c\u8fd9\u4e9b\u670d\u52a1\u662f\u5fc5\u987b\u8fd0\u884c\u7684\u3002<br \/>\n\u73b0\u5728\uff0c\u6211\u4eec\u627e\u5230\u4e86\u6253\u5f00\u7684\u7aef\u53e3\uff0c\u5374\u4e0d\u77e5\u9053\u662f\u54ea\u4e2a\u7a0b\u5e8f\u5728\u64cd\u4f5c\u8fd9\u4e2a\u7aef\u53e3\uff0c\u5c31\u8981\u4f7f\u7528LSOF\u7b49\u5de5\u5177\u4e86\u3002\u6267\u884c\u547d\u4ee4\u201clsof -P -n \u2013i\u201d\uff0c\u5373\u53ef\u663e\u793a\u6240\u6709\u672c\u5730\u6253\u5f00\u7684\u7aef\u53e3\u53ca\u64cd\u4f5c\u8fd9\u4e9b\u7aef\u53e3\u7684\u7a0b\u5e8f\u3002\u4e00\u4e2a\u6bd4\u8f83\u5178\u578b\u7684\u4f8b\u5b50\u5982\u56fe1\u6240\u793a\u3002<\/span><\/p>\n<p>\u56fe1<br \/>\n\u53e6\u5916\uff0c\u5982\u679c\u60f3\u770b\u770b\u670d\u52a1\u5668\u7ba1\u7406\u5458\u4e3a\u8fd9\u4e2a\u57df\u6240\u8bbe\u7f6e\u7684\u5185\u5bb9\uff0c\u8fd8\u53ef\u4ee5\u7528Nslookup\u8f93\u51fa\u7f51\u7edc\u57df\u4fe1\u606f\uff0c\u67e5\u770bDNS\uff0c\u7136\u540e\u8fd0\u884cNMAP\u641c\u7d22\u6574\u4e2a\u7f51\u7edc\u53ef\u4ee5\u5217\u51fa\u57df\u4e4b\u5185\u6240\u6709\u5df2\u77e5\u670d\u52a1\u5668\u3002<br \/>\n4\uff0e\u67e5\u8be2\uff1a\u63a2\u4e2a\u660e\u660e\u767d\u767d<br \/>\n\u770b\u770b\u76ee\u6807\u6709\u6ca1\u6709\u5f00Finger\u670d\u52a1\uff0c\u5982\u679c\u6709\u7684\u8bdd\u5229\u7528Finger\u5f97\u5230\u7528\u6237\u540d\u4fe1\u606f\uff0c\u6211\u4eec\u53ef\u4ee5\u901a\u8fc7\u7b80\u5355\u7684\u731c\u6d4b\u6765\u8bd5\u63a2\u7528\u6237\u5bc6\u7801\uff0c\u7528\u6237\u591a\u7684\u8bdd\u603b\u4f1a\u6709\u51e0\u4e2a\u61d2\u866b\u7684\u73b0\u5728\u8fdb\u884c\u66f4\u52a0\u6df1\u5165\u7684\u63a2\u6d4b\u3002\u4f7f\u7528Rpcinfo\u548cKshowmount\u7b49\uff0c\u53ef\u4ee5\u67e5\u8be2\u673a\u5668\u63d0\u4f9b\u4e86\u54ea\u4e9b\u670d\u52a1\u3002<br \/>\n\u5982\u679cNFS\u6b63\u5728\u8fd0\u884c\uff0c\u5c31\u6709\u53ef\u80fd\u4ece\u670d\u52a1\u5668\u83b7\u5f97\u5df2\u5bfc\u51fa\u6587\u4ef6\u7cfb\u7edf\u7684\u6e05\u5355\uff0c\u4e0d\u8fc7\u6211\u5728\u8fd9\u53f0\u670d\u52a1\u5668\u4e0a\u5e76\u6ca1\u6709\u6210\u529f\uff0c\u5012\u662f\u5728\u53e6\u4e00\u53f0\u9ed8\u8ba4\u503c\u6709\u95ee\u9898\u7684\u670d\u52a1\u5668\u4e0a\u53d6\u5f97\u4e86\u6210\u529f\uff0c\u8fd9\u53f0\u670d\u52a1\u5668\u628a\u6587\u4ef6\u7cfb\u7edf\u5b8c\u5168\u4e0d\u53d7\u4fdd\u62a4\u5730\u4ee5\u53ef\u8bfb\u5199\u65b9\u5f0f\u663e\u9732\u7ed9\u5916\u754c\uff0c\u8fd9\u5c31\u7ed9\u4e86\u6211\u4e00\u4e2a\u5f88\u597d\u7684\u673a\u4f1a\uff1a<br \/>\n# \/usr\/sbin\/kshowmount -e 203.207.xxx.002<br \/>\nExport list for 203.207.xxx.002:<br \/>\n\/usr\/lib\/cobol (everyone)<br \/>\n\/usr\/sys\/inst.images (everyone)<br \/>\n\/stadtinf (everyone)<br \/>\n\/var\/spool\/mail (everyone)<br \/>\n\/usr\/lpp\/info (everyone)<br \/>\n\/usr\/local (everyone)<br \/>\n\/pd-software (everyone)<br \/>\n\/u1 (everyone)<br \/>\n\/user (everyone)<br \/>\n\/fix (everyone)<br \/>\n\/u (everyone)<br \/>\n\/install (everyone)<br \/>\n\u53ef\u4ee5\u770b\u5230\uff0c203.207.xxx.002\u4e0a\u6240\u6709\u6ce8\u660e\u4e86\u201ceveryone\u201d\u7684\u76ee\u5f55\u90fd\u662f\u5411\u516c\u4f17\u5f00\u653e\u7684\uff0c\u5176\u4e2d\u5305\u62ec\u4fdd\u5b58\u4e86\u7528\u6237\u90ae\u4ef6\u7684\u201c\/var\/spool\/mail\u201d\u76ee\u5f55\uff0c\u4ee5\u53ca\u7528\u6237\u7684\u4e3b\u76ee\u5f55\u201c\/u\u201d\u548c\u201c\/u1\u201d\u3002\u53e6\u5916\u201c\/usr\/local\u201d\u548c\u201c\/usr\/lib\/cobol\u201d\u4e5f\u662f\u5141\u8bb8\u5199\u5165\u7684\uff0c\u8fd9\u4f7f\u5f97\u5b83\u5f88\u5bb9\u6613\u88ab\u5b89\u88c5\u4e0a\u7279\u6d1b\u4f0a\u6728\u9a6c\uff0c\u8f7b\u800c\u6613\u4e3e\u7684\u83b7\u5f97\u63a7\u5236\u6743\u3002<br \/>\n5\uff0e\u51fa\u51fb\uff1a\u9501\u5b9a\u6f0f\u6d1e<br \/>\n\u901a\u8fc7\u626b\u63cf\u8fd4\u56de\u7684Banner\u548c\u5177\u4f53\u7684\u7cfb\u7edf\u7248\u672c\uff0c\u770b\u770b\u8fd9\u4e2a\u7cfb\u7edf\u6709\u6ca1\u6709\u4ec0\u4e48\u53ef\u4ee5\u5229\u7528\u7684\u5927\u6f0f\u6d1e\uff0c\u56e0\u4e3aLinux\u5185\u6838\u786e\u5b9e\u5b58\u5728\u591a\u4e2a\u5b89\u5168\u6f0f\u6d1e\uff0c\u6700\u8fd1\u6bd4\u8f83\u70ed\u95e8\u7684\u6f0f\u6d1e\u5305\u62ec\uff1aExt3\u6587\u4ef6\u7cfb\u7edf\u4fe1\u606f\u6cc4\u9732\u3001SoundBlaster\u4ee3\u7801\u5bfc\u81f4\u672c\u5730\u5d29\u6e83\u3001DRI\u95ee\u9898\u5bfc\u81f4\u672c\u5730\u5d29\u6e83\u3001Mremap\u7684\u5176\u5b83\u95ee\u9898\u5bfc\u81f4\u672c\u5730\u62d2\u7edd\u670d\u52a1\u7b49\u3002\u5229\u7528\u8fd9\u4e9b\u6f0f\u6d1e\uff0c\u653b\u51fb\u8005\u53ef\u4ee5\u83b7\u5f97\u654f\u611f\u4fe1\u606f\u6216\u8fdb\u884c\u62d2\u7edd\u670d\u52a1\u653b\u51fb\u3002\u7ec6\u7ec6\u6570\u6765\uff0c\u901a\u8fc7\u5bf9Linux\u5185\u6838\u6587\u4ef6\u7248\u672c\u7684\u5206\u6790\u548c\u8f6e\u756a\u5b9e\u9a8c\uff0c\u6211\u89c9\u5f97\uff1a\u7cfb\u7edf\u5b58\u5728Seclpd.c\u3001Netpr.c\u6f0f\u6d1e\u53ef\u80fd\u6027\u5f88\u5927\uff01<br \/>\n\u4ece\u7eff\u76df\u8d44\u6599\u5e93\u641c\u7d22\u540e\u5f97\u77e5Red Hat7.0\u7248\u672c\u6709\u4e00\u4e2aLP\u670d\u52a1\uff08515\u7aef\u53e3\uff09\u6709\u8fdc\u7a0b\u6ea2\u51fa\u6f0f\u6d1e\uff0c\u767b\u9646<a href=\"http:\/\/www.safechina.net\/www_hack_co_za\/redhat\/7.0\/seclpd.c\" target=\"_blank\"><span style=\"font-size: x-small;\">http:\/\/www.safechina.net\/www_hack_co_za\/redhat\/7.0\/seclpd.c<\/span><\/a><span style=\"font-size: x-small;\">\u3002<br \/>\n\uff08\u5b8c\u6574\u4ee3\u7801\u8bf7\u770b\u5149\u76d8\u201c\u6742\u5fd7\u76f8\u5173\u201d\u3002\uff09<br \/>\n\u4f7f\u7528VI\u8fdb\u884c\u7f16\u8f91\uff1a#VI seclpd.c\uff0c\u7136\u540e\u7528\u201c:wq\u201d\u4fdd\u5b58\u540e\u7f16\u8bd1\u3002\u628aSeclpd.c\u4f20\u5230\u76ee\u6807\u673a\u4e0a\uff0c\u7528GCC\u7f16\u8bd1\uff1a<br \/>\n$GCC -o seclpd seclpd.c<br \/>\n\u7136\u540e\uff0c\u6267\u884c\uff0c\u663e\u793a\u4e3a\u5931\u8d25\u3002<br \/>\n$.\/seclpd 203.207.*.* -t 0<br \/>\n\u5c06\u53c2\u6570\u6362\u6210t1\uff0c\u518d\u8bd5\u4ecd\u7136\u662f\u5931\u8d25\u3002<br \/>\n$.\/seclpd 203.207.*.*-t 1<br \/>\n\u770b\u6765\u8981\u6765\u4e2a\u66b4\u529b\u7834\u89e3\u4e86\u3002<br \/>\n$.\/seclpd 203.207.*.* brute \u2013t 0<br \/>\n\u8fc7\u4e86\u5927\u7ea65-8\u5206\u949f\u5de6\u53f3\uff0c\u7ed3\u679c\u51fa\u6765\u4e86\u3002<br \/>\nuid=0(root)gid=other(other)&#8230;.<br \/>\n\u641e\u5b9a\uff01\u4e00\u5207\u987a\u5229\uff0c\u73b0\u5728\uff0c\u6709\u4e86ROOT\u548c\u5b83\u7684PASSSWD\uff0c\u53ef\u4ee5\u8003\u8651\u52a0\u4e2a\u540e\u95e8\u3001\u5b89\u88c5Sniffers\u7b49\u52a8\u4f5c\u4e86\u3002<br \/>\n\u9632\u8303<br \/>\n\u201c\u77e5\u5df1\u77e5\u5f7c\uff0c\u767e\u6218\u4e0d\u6b86\u201d\u3002\u4f5c\u4e3a\u4e00\u4e2a\u597d\u7684\u7cfb\u7edf\u7ba1\u7406\u8005\uff0c\u8981\u4fdd\u969c\u6574\u4e2a\u7cfb\u7edf\u7684\u5b89\u5168\u8fd0\u884c\uff0c\u6700\u597d\u7684\u65b9\u6cd5\u662f\u4e86\u89e3\u653b\u51fb\u7684\u5de5\u4f5c\u539f\u7406\u548c\u673a\u5236\uff0c\u4e86\u89e3\u653b\u51fb\u4e2d\u4f7f\u7528\u4e86\u54ea\u4e9b\u5de5\u5177\uff0c\u5982\u4f55\u64cd\u4f5c\u5165\u4fb5\u7b49\u7b49\u3002<br \/>\n1\uff0e\u86db\u4e1d\u9a6c\u8ff9\uff1a\u4ece\u65e5\u5fd7\u7740\u624b<br \/>\n\u65e5\u5fd7\u8bb0\u5f55\u4e86\u7cfb\u7edf\u6bcf\u5929\u53d1\u751f\u7684\u4e8b\u60c5\uff0c\u53ef\u4ee5\u901a\u8fc7\u4ed6\u6765\u68c0\u67e5\u9519\u8bef\u53d1\u751f\u7684\u539f\u56e0\u6216\u8005\u653b\u51fb\u8005\u7559\u4e0b\u7684\u75d5\u8ff9\uff0c\u8fd8\u53ef\u4ee5\u5b9e\u65f6\u7684\u76d1\u6d4b\u7cfb\u7edf\u72b6\u6001\uff0c\u76d1\u6d4b\u548c\u8ffd\u8e2a\u4fb5\u5165\u8005\u7b49\u7b49\u3002<\/span><\/p>\n<p>TIPS\uff1a\u5728Linux\u7cfb\u7edf\u4e2d\uff0c\u6709\u4e09\u4e2a\u4e3b\u8981\u7684\u65e5\u5fd7\u5b50\u7cfb\u7edf\uff1a<br \/>\n\uff081\uff09\u8fde\u63a5\u65f6\u95f4\u65e5\u5fd7\u3002\u7531\u591a\u4e2a\u7a0b\u5e8f\u6267\u884c\uff0c\u628a\u7eaa\u5f55\u5199\u5165\u5230\u201c\/var\/log\/wtmp\u201d\u548c\/\u201cvar\/run\/utmp\u201d\uff0cLogin\u7b49\u7a0b\u5e8f\u66f4\u65b0Wtmp\u548cUtmp\u6587\u4ef6\uff0c\u4f7f\u7cfb\u7edf\u7ba1\u7406\u5458\u80fd\u591f\u8ddf\u8e2a\u8c01\u5728\u4f55\u65f6\u767b\u5f55\u5230\u7cfb\u7edf\u3002<br \/>\n\uff082\uff09\u7531\u7cfb\u7edf\u5185\u6838\u6267\u884c\u7684\u8fdb\u7a0b\u7edf\u8ba1\u3002\u5f53\u4e00\u4e2a\u8fdb\u7a0b\u7ec8\u6b62\u65f6\uff0c\u5f80\u7edf\u8ba1\u6587\u4ef6\u4e2d\u5199\u4e00\u4e2a\u7eaa\u5f55\u3002\u8fdb\u7a0b\u7edf\u8ba1\u7684\u76ee\u7684\u662f\u4e3a\u7cfb\u7edf\u4e2d\u7684\u57fa\u672c\u670d\u52a1\u63d0\u4f9b\u547d\u4ee4\u4f7f\u7528\u7edf\u8ba1\u3002<br \/>\n\uff083\uff09\u9519\u8bef\u65e5\u5fd7\u3002\u7531Syslogd\uff088\uff09\u6267\u884c\uff0c\u5404\u79cd\u7cfb\u7edf\u5b88\u62a4\u8fdb\u7a0b\u3001\u7528\u6237\u7a0b\u5e8f\u548c\u5185\u6838\u5411\u6587\u4ef6\u201c\/var\/log\/messages\u201d\u62a5\u544a\u503c\u5f97\u6ce8\u610f\u7684\u4e8b\u4ef6\u3002\u53e6\u5916\u6709\u8bb8\u591aUNIX\u7a0b\u5e8f\u521b\u5efa\u65e5\u5fd7\u3002\u50cfHTTP\u548cFTP\u8fd9\u6837\u63d0\u4f9b\u7f51\u7edc\u670d\u52a1\u7684\u670d\u52a1\u5668\u4e5f\u4fdd\u6301\u8be6\u7ec6\u7684\u65e5\u5fd7\u3002<\/p>\n<p>\u4ece\u653b\u51fb\u89d2\u5ea6\u800c\u8a00\uff0c\u670d\u52a1\u5668\u4e0a\u7684\u5b89\u5168\u6587\u4ef6\u5341\u5206\u91cd\u8981\uff0c\u82e5\u4f60\u5173\u95ed\u5916\u90e8\u7f51\u7edc\u5bf9\u4f60\u7684\u670d\u52a1\u5668\u7684\u8bbf\u95ee\uff0c\u653b\u51fb\u8005\u603b\u662f\u8bd5\u56fe\u8fde\u63a5\u670d\u52a1\u5668\u4e0a\u7684\u82e5\u5e72\u4e2a\u7aef\u53e3\uff0c\u4f46\u662f\u7531\u4e8e\u670d\u52a1\u5668\u5173\u95ed\u4e86Inetd\u542f\u52a8\u7684\u6240\u6709\u670d\u52a1\uff0c\u6240\u4ee5LOG\u7cfb\u7edf\u8bb0\u5f55\u4e0b\u4e86\u8fd9\u4e9b\u8bbf\u95ee\u62d2\u7edd\u3002\u5e38\u7528\u7684\u65e5\u5fd7\u6587\u4ef6\u5982\u4e0b\uff1a<br \/>\naccess-log \u7eaa\u5f55HTTP\/web\u7684\u4f20\u8f93<br \/>\nacct\/pacct \u7eaa\u5f55\u7528\u6237\u547d\u4ee4<br \/>\naculog \u7eaa\u5f55MODEM\u7684\u6d3b\u52a8<br \/>\nbtmp \u7eaa\u5f55\u5931\u8d25\u7684\u7eaa\u5f55<br \/>\nlastlog \u6700\u8fd1\u51e0\u6b21\u6210\u529f\u767b\u5f55\u548c\u6700\u540e\u4e00\u6b21\u4e0d\u6210\u529f\u7684\u767b\u5f55<br \/>\nmessages \u4ecesyslog\u4e2d\u8bb0\u5f55\u4fe1\u606f<br \/>\nsudolog \u7eaa\u5f55\u4f7f\u7528sudo\u53d1\u51fa\u7684\u547d\u4ee4<br \/>\nsulog \u7eaa\u5f55\u4f7f\u7528su\u547d\u4ee4\u7684\u4f7f\u7528<br \/>\nsyslog \u4ecesyslog\u4e2d\u8bb0\u5f55\u4fe1\u606f<br \/>\nutmp \u7eaa\u5f55\u5f53\u524d\u767b\u5f55\u7684\u6bcf\u4e2a\u7528\u6237<br \/>\nwtmp \u7528\u6237\u6bcf\u6b21\u767b\u5f55\u8fdb\u5165\u548c\u9000\u51fa\u65f6\u95f4\u7684\u6c38\u4e45\u7eaa\u5f55<br \/>\nxferlog \u7eaa\u5f55FTP\u4f1a\u8bdd<br \/>\n2\uff0e\u4ea1\u7f8a\u8865\u7262\uff1a\u52a0\u5f3a\u9632\u536b<br \/>\n\u4e00\u65b9\u9762\u8981\u79ef\u6781\u5bfb\u627e\u672c\u64cd\u4f5c\u7cfb\u7edf\u7684\u5e38\u89c1\u6f0f\u6d1e\u5e76\u53ca\u65f6\u5347\u7ea7\u5382\u5546\u6240\u516c\u5e03\u7684\u8865\u4e01\u3002\u6bd4\u5982\uff0c\u53ef\u4ee5\u4fee\u6539Inetd.conf\u6587\u4ef6\u4ee5\u5173\u95ed\u67d0\u4e9b\u670d\u52a1\uff0c\u91cd\u65b0\u542f\u52a8\u540e\u518d\u7528NMAP\u626b\u63cf\uff0c\u5728\u653b\u51fb\u8005\u53d1\u73b0\u5176\u4ee5\u524d\u66f4\u65e9\u7684\u53d1\u73b0\u81ea\u5df1\u7684\u7cfb\u7edf\u7684\u6f0f\u6d1e\uff0c\u5e76\u52a0\u4ee5\u5f25\u8865\u3002<br \/>\n\u53e6\u4e00\u65b9\u9762\u8981\u52a0\u5f3a\u5bc6\u7801\u4fdd\u62a4\u3002\u653b\u51fb\u5bc6\u7801\u7684\u624b\u6bb5\u4e3b\u8981\u6709\uff1a\u5b57\u5178\u653b\u51fb\uff08Dictionaryattack\uff09\u3001\u6df7\u5408\u653b\u51fb\uff08Hybridattack\uff09\u3001\u86ee\u529b\u653b\u51fb\uff08Bruteforceattack\uff09\u3002\u6700\u597d\u7684\u9632\u536b\u65b9\u6cd5\u4fbf\u662f\u4e25\u683c\u63a7\u5236\u8fdb\u5165\u7279\u6743\uff0c\u5373\u4f7f\u7528\u6709\u6548\u7684\u5bc6\u7801\u3002\u4e3b\u8981\u5305\u62ec\u5bc6\u7801\u5e94\u5f53\u9075\u5faa\u5b57\u6bcd\u3001\u6570\u5b57\u3001\u5927\u5c0f\u5199\uff08\u56e0\u4e3aLinux\u5bf9\u5927\u5c0f\u5199\u662f\u6709\u533a\u5206\uff09\u6df7\u5408\u4f7f\u7528\u7684\u89c4\u5219\uff0c\u5982\u52a0\u5165\u201c#\u201d\u6216\u201c%\u201d\u6216\u201c$\u201d\u8fd9\u6837\u7684\u7279\u6b8a\u5b57\u7b26\u4ee5\u6dfb\u52a0\u590d\u6742\u6027\u3002<br \/>\n3\uff0e\u53cd\u51fb\uff1a\u4ece\u7cfb\u7edf\u5f00\u59cb<br \/>\n\u653b\u51fb\u8005\u5177\u6709\u5bf9Linux\u670d\u52a1\u5668\u7684\u5168\u90e8\u63a7\u5236\u6743\uff0c\u53ef\u4ee5\u5728\u4efb\u4f55\u65f6\u523b\u90fd\u80fd\u591f\u5b8c\u5168\u5173\u95ed\u751a\u81f3\u6bc1\u706d\u6b64\u7f51\u7edc\u3002\u53ef\u4ee5\u91c7\u53d6\u7684\u53cd\u51fb\u63aa\u65bd\u6709\uff1a\u5907\u4efd\u91cd\u8981\u7684\u5173\u952e\u6570\u636e\uff1b\u6539\u53d8\u7cfb\u7edf\u4e2d\u6240\u6709\u53e3\u4ee4\uff0c\u901a\u77e5\u7528\u6237\u66f4\u65b0\u53e3\u4ee4\uff1b\u9694\u79bb\u8be5\u7f51\u6bb5\uff0c\u4f7f\u653b\u51fb\u884c\u4e3a\u4ec5\u51fa\u73b0\u5728\u4e00\u4e2a\u5c0f\u8303\u56f4\u5185\uff1b\u5141\u8bb8\u884c\u4e3a\u7ee7\u7eed\u8fdb\u884c\u3002\u5982\u6709\u53ef\u80fd\uff0c\u4e0d\u8981\u6025\u4e8e\u628a\u653b\u51fb\u8005\u8d76\u51fa\u7cfb\u7edf\uff0c\u4e89\u53d6<span class=\"t_tag\" onclick=\"tagshow(event)\">\u6536\u96c6<\/span>\u8bc1\u636e\uff1b\u8fdb\u884c\u5404\u79cd\u5c1d\u8bd5\uff0c\u8bc6\u522b\u51fa\u653b\u51fb\u6e90<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6700\u8fd1\uff0c\u6211\u75af\u72c2\u7684\u8ff7\u4e0a\u4e86Linux\u90a3\u4f18\u96c5\u7684\u7ec5\u58eb\u5e3d\u3002\u5076\u5c14\u8fde\u4e0a\u4e00\u53f0\u670d\u52a1\u5668\uff0c\u62ff\u51e0\u4e2a\u5de5\u5177\u626b\u63cf &hellip;<\/p>\n<p class=\"read-more\"><a href=\"http:\/\/zerobox.org\/notes\/277.html\">\u7ee7\u7eed\u9605\u8bfb &raquo;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[29,60],"class_list":["post-277","post","type-post","status-publish","format-standard","hentry","tag-linux-2","tag-60"],"views":1041,"_links":{"self":[{"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/posts\/277","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/comments?post=277"}],"version-history":[{"count":0,"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/posts\/277\/revisions"}],"wp:attachment":[{"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/media?parent=277"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/categories?post=277"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/tags?post=277"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}