I write this article the goal not to lie in teach the human to invade, but to enhance own technology and strengthen network administrator's safe guard consciousness. Only this! The careless network administrator should understand: Because a you small operate miss will possibly cause the entire network to fall to the enemy comprehensively! This article is mainly revolves under UNIX a small service advancement (LPD: Network printing service) the attack carries on.
Let me say nothing of slowly .....
Coughing…Coughing…Serves tea first to me! (what?! Does not have? I did not say!! ) ha-ha ......Cracks a joke, returns to the proper topic. First determines the goal, looks for a Taiwan search engine casually. Selects one casually! The supposition is: www.fbi.gov.tw. ^__^
Lets me have a look is first continually on:
C:\ping www.fbi.gov.tw
Pinging www.fbi.gov.tw [202.106.184.200] with 32 bytes of data:
Reply from 202.106.184.200: bytes=32 time=541ms TTL=244
Reply from 202.106.184.200: bytes=32 time=620ms TTL=244
Reply from 202.106.184.200: bytes=32 time=651ms TTL=244
Reply from 202.106.184.200: bytes=32 time=511ms TTL=244
Ping statistics for 202.106.184.200:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 511ms, Maximum = 651ms, Average = 580ms
Not only hee hee - continually on, speed also good ......
Telnet has a look at banner first:
C:\ >telnet www.fbi.gov.tw
Losing to main engine's connection.
Ha ......Looked like falls the telnet service to shut! Tries ftp again
C:\ >ftp www.fbi.gov.tw
Connected to www.fbi.gov.tw.
220 fbi-www FTP server (Version wu-2.6.1(1) Wed Aug 9 05:54: 50 EDT 2000) ready.
User (www.fbi.gov.tw: (none)):
~~wu-2.6.1 looked like a little the feature. This machine is likely famous ............Right! RedHat7.0! Wrong has not been she! Must first confirm, is connected including the above my springboard:
C:\ >telnet xxx.xxx.xxx.xxx
Red Hat Linux release 7.0 (Guinness)
Kernel 2.2.16-22smp on an i686
login: fetdog
Password:
bash-2.04$
Ha-ha ~~ this is I in a Taiwan's springboard. RH7! Under and so on I will tell you to take these meat chicken means ......Takes the nmap scanner, has a look at mysterious ~~~
bash-2.04$nmap - sT - O www.fbi.gov.tw
Starting nmap V. 2.54BETA7 (www.insecure.org/nmap/)
WARNING! The following files exist and are readable: /usr/local/sha
- services and ./nmap-services. I am choosing /usr/local/share/nmap/
s for security reasons. set NMAPDIR=. to give priority to files in
irectory
Interesting ports on (www.fbi.gov.tw):
(The 1520 ports scanned but not shown below are in state: closed)
Port State Service
25/tcp open smtp
79/tcp open finger
80/tcp open http
111/tcp open sunrpc
113/tcp open auth
443/tcp open https
513/tcp open login
514/tcp open shell
515/tcp open printer
587/tcp open submission
1024/tcp open kdm