You are here: hacking technology > hacker invade > Content
Hot Articles
Recommend Articles
New Articles
Invades the LINUX server auspicious solution(3)
  Add date: 10/27/2008   Publishing date: 10/27/2008   Hits: 3
Total 5 pages, Current page:3, Jump to page:
 

Fourth, establishes own shell account number  
     After two, 32 essential step intruder has attained the key cryptographic document finally, and explained the password. Now may move the TELNET procedure, landed the main engine. When is connected including the above the server the server to you will demonstrate that own some information, will usually be U NIX, linux, aix, irix, ultrix, bsd even are DOS and VAX/Vms; Is the Login prompt symbol appears on the screen, by now then entered the account number which and the password comes lands the system. This time the intruder might use the matter which own UNIX knowledge made itself to like doing.  

Finally makes an analysis to a cryptographic document, this document content is as follows:  
root:1234aaab:0:1:Operator:/:/bin/csh  
nobody:*:12345:12345::/:  
daemon:*:1:1::/:  
sys:*:2:2::/:/bin/csh  
sun:123456hhh:0:1:Operator:/:/bin/csh  
bin:*:3:3::/bin:  
uucp:*:4:8::/var/spool/uucppublic:  
news:*:6:6::/var/spool/news:/bin/csh  
audit:*:9:9::/etc/security/audit:/bin/csh  
sync::1:1::/:/bin/sync  
sysdiag:*:0:1:Old System  
Diagnostic:/usr/diag/sysdiag:/usr/diag/sysdiag/sysdiag  
sundiag:*:0:1:System  
Diagnostic:/usr/diag/sundiag:/usr/diag/sundiag/sundiag  
tom:456lll45uu:100:20::/home/tom:/bin/csh  
john:456fff76Sl:101:20:john:/home/john:/bin/csh  
henry:AusTs45Yus:102:20:henry:/home/henry:/bin/csh  
harry:SyduSrd5sY:103:20:harry:/home/harry:/bin/csh  
steven:GEs45Yds5Ry:104:20:steven:/home/steven:/bin/csh  
+:: 0:0:::  

And by “: ” divides into several columns, for instance: the tom:456lll45uu:100:20:tomchang:/home/tom:/bin/csh meaning is:  
User Name: tom  
Password: 456lll45uu  
User No: 100  
Group No: 20  
Real Name: tom chang  
Home Dir: /home/tom  
Shell: /bin/csh  

        The reader may discover that above such as nobody, daemon, sys, bin, uucp, news, audit, sysdiag, sundiag and so on password column is *, i.e. these account number's password has deadlocked, is unable to use directly.  

        It is noteworthy that many systems after install for the first time will have some default account numbers and the password, this will bring conveniently for the congenial principle's hacker, the following will be under some UNIX the default account number and the password.  
ACCOUNT PASSWORD  
----------- ----------------  
root root  
sys sys/system/bin  
bin sys/bin  
mountfsys mountfsys  
adm adm  
uucp uucp  
nuucp anon  
anon anon  
user user  
games games  

 

Other pages: : <<Prev * 1 * 2 * 3 * 4 * 5 * Next>>
Prev:ORACLE establishment data file WriteWebShell Next:Fox network intrusion by hackers learning

Comment:

Category: Home > hacker invade