[¿ì¸®ÀÇ °ø°Ý ¹æ¾î ±×¸®°í ÃÖ±Ù ÇØÅ· µ¿Çâ]
CRLAB
È«¹ÎÇ¥.¼ÛÀΰæ.±â¿µÈ£

----------------------------------------
[¿ì¸®ÀÇ °ø°Ý ¹æ¹ý]
Á¤º¸ Ž»ö
¹æ¹ý·Ð ÀÌ¿ë
¹öÆÛ ¿À¹ö Ç÷οì ÀÌ¿ë ÇÑÆÀ °ø°Ý
°¢Á¾ °ø°Ý ½Ãµµ
ÇØÄ¿¸¦ ÇØÅ·ÇÏ´Ù.
----------------------------------------
[Á¤º¸ Ž»ö]
°¢Á¾ ÃֽŠbug report
Server Scan
----------------------------------------
[¹æ¹ý·Ð ÀÌ¿ë]
¹«Â÷º° ´ëÀÔ¹ý
³ëÇÏ¿ì ÀÌ¿ë
°æ·Î¿Í ±âº» ¿¢¼¼½º
ÆÄÀÏ ÁöÁ¤ ÈÄlevel1 ±ÇÇÑÆнº
----------------------------------------
[¹öÆÛ ¿À¹ö Ç÷οì ÀÌ¿ë hanterm °ø°Ý]
hanterm â ¶ç¿ì±â
hanterm â ¶ç¿ì¸é wizard Àüȯ ?
hanterm buffer over flow
Bof ÀÌÈÄ euid shell ȹµæ
°£´ÜÇÑ ¼Ò½º·Î uid ȹµæ
----------------------------------------
[°¢Á¾ °ø°Ý ½Ãµµ]
IV2¸¦ Åë°úÇϱâ À§ÇØ pass ½ÇÇàÇؾßÇÑ´Ù.
°¢ÀÚ °ø°Ý¹ý ÀÌ¿ë
Setuid °É¸° ÆÄÀÏ ÀüºÎ °ø°Ý
Procmail °ø°Ý¹ý ½Ãµµ
Movemail °ø°Ý ½Ãµµ
È­ÀÏ»ó gid ¾òÀ½
Shell ÆÄÀÏ¿¡ ±×·ì Setuid °É¾î¾ß ÇÑ´Ù.
----------------------------------------
[ÇØÄ¿¸¦ ÇØÅ·ÇÏ´Ù.]
Level 1 ¹ö±× È°¿ë
¹ö±× ÀÌ¿ë Å×½ºÆ®
ÇØÄ¿¸¦ ÇØÅ·
----------------------------------------
[¿ì¸®ÀÇ ¹æ¾î]
À¥ÆäÀÌÁö À¯Áö ÇÁ·Î±×·¥ Á¦ÀÛ
level 1 ¹ö±×¿¡ ´ëÇÑ ´ëºñ
ÃֽŠÁ¤º¸ ¼öÁý
µ¿Å ÆľÇ
----------------------------------------
[À¥ÆäÀÌÁö À¯Áö ÇÁ·Î±×·¥ Á¦ÀÛ]
¸¶Áö¸·±îÁö ȨÆäÀÌÁö ÁöÅ°±â
ÇÁ·Î±×·¥ Á¦ÀÛ
----------------------------------------
[¼Ò½º]
#include
void(main){
        FILE *fp;
        int i;
        char *buf[24] = {
                "<HTML>"
        ...»ý·«...
        while(1){
        ...»ý·«...
        }|
}
---------------------------------------- 

----------------------------------------
[Level 1 ¹ö±×¿¡ ´ëÇÑ ´ëºñ]
level 1 ¹ö±×â À¯Áö
level 1 ¹ö±×¿¡ ´ëÇÑ ´ëºñÃ¥ ¼¼¿ò
´Ù¸¥ °èÁ¤¿¡ Á¤º¸ º¸°ü
----------------------------------------
[level 1 ¹ö±×¿¡ ´ëÇÑ ¼³¸í]
Level 1 passâÀ» À¯Áö
Level 1 pass¿¡ ŸÀ¯Àú ID »ðÀÔ
ŸÀ¯ÀúÀÇ password ¾òÀ» ¼ö ÀÖÀ½
----------------------------------------
[»ó´ëÀÇ µ¿Å ÆľÇ]
´ëȸ Á¾·á ½ÃÁ¡À» ³öµÎ°í »ó´ëÀÇ µ¿Å ÆľÇ
À¥ÆäÀÌÁö À¯Áö ÇÁ·Î±×·¥ ½ÇÇà
¹é±×¶ó¿îµå ½ÇÇà
----------------------------------------
[¿ì¸®°¡ º¸´Â À̹ø ½Ã½ºÅÛ]
·¹º§1  161 ¼­¹ö
·¹º§1  162 ¼­¹ö
·¹º§1  163 ¼­¹ö
·¹º§2  164 ¼­¹ö
·¹º§3  203.227.243.173
----------------------------------------
[·¹º§ 1 161 ¼­¹ö]
Unix Server
´ëȸ½ÃÀÛ Á÷ÈÄ ¹ö±× ¹ß°ß
ÀÎÁõâ ¾øÀÌ pass
----------------------------------------
[·¹º§1 162 ¼­¹ö]
Linux Server
ÀÎÁõâ¿¡ ¾Ïȣũ·¢»ç¿ë½Ã¾ÏÈ£¾òÀ½
id:admin passwd:pine
----------------------------------------
[·¹º§ 1 163 ¼­¹ö]
NT Server
----------------------------------------
[Level 2]
Linux 6.2 Kernel 2.2.16
hanterm ¿¡ ¹öÆÛ ¿À¹öÇ÷οì
Procmail & movemail ?
Man 񀀥
----------------------------------------
[Level 3]
¹°¸®ÀûÀÎ ÀåÄ¡·Î º¸¾È ?
³×Æ®¿ö¿¬°áÀÌ ¾ÈµÊ ?
ƯÁ¤ °æ·Î ÀÌ¿ë ?
----------------------------------------
[¿ì¸®°¡ º¸´Â ÃÖ±Ù ÇØÅ· µ¿Çâ]
ÃÖ±Ù ÇØÅ· µ¿Çâ
ÃÖ±Ù ±â¹ýµé°ú ¾ÕÀ¸·ÎÀÇ ±â¹ýµé
Bind
Web Bind(PHP Attack)
FTP Attack
FTP Attack (WuFTPD , ProFTPD)
Sendmail&procmail Attack
Dns Spoofing
----------------------------------------