競äºåã®ããã€ã³ããªãžã§ã³ã¹ã®ãªã³ã©ã€ã³ç«¶äºã¯ã6幎é£ç¶ã®ããžãã£ãããã¯ãã€ãºã«ã³ãã¡ã¬ã³ã¹ã§éå¬ãããŸãããããã¯ãçŸä»£ã®äžçã§äººã ãäŒæ¥ã«é¢ããããŸããŸãªè²Žéãªæ å ±ãå ¥æããããšãããã«ç°¡åããæ確ã«ç€ºããŠããŸãã ãã®å Žåãéåžžã¯äœãã¯ã©ãã¯ããå¿ èŠãããããŸããããã¹ãŠã®ç§å¯ã¯ãããªãã¯ãããã¯ãŒã¯ã«æ£åšããŠããŸãã ãã®ã¬ãã¥ãŒã§ã¯ã2017幎ã®ãã³ã³ããã£ãã£ãã€ã³ããªãžã§ã³ã¹ãã®ã¿ã¹ã¯ãšã¯äœããã©ã®ããã«è§£æ±ºããå¿ èŠããããã誰ã競äºã«åã£ããã説æããŸãã
ä»å¹Žãåå è ã¯GreatIOTã®åŸæ¥å¡ã«é¢ããããããçš®é¡ã®æ å ±ãèŠã€ããå¿ èŠããããŸããã ã€ã³ã¿ãŒãããäžã®æ å ±ã®éåžžã®æ€çŽ¢ãšåæã«ãããŸããŸãªIoTããã€ã¹ã䜿çšããã¿ã¹ã¯ãè¿œå ãããŸããã äŒèª¬ã«ãããšãäŒç€Ÿã«å¥åŠãªããšãèµ·ãããããæç¹ã§ãéçºè ãæè¡ãµããŒããããã«ã¯CEOãå«ããã¹ãŠã®ãã®ããªããªã£ãŠããŸããã ã³ã³ãã¹ãåå è ã®ä»äºã¯ããã®é°è¬ã調æ»ããããã«å¿ èŠãªããŒã¿ãèŠã€ããããšã§ãã
1.è¡æ¹äžæã®ãã¶ã€ããŒã«é¢ããæ å ±ãèŠã€ãã
1.1ã greatiot.phdays.comã®äŒç€Ÿã®èª°ãã圌ã®å§ãšåãèšãããšããã§ããŸããã§ããã ãã¶ãããªãã¯ãããèŠã€ããããšãã§ããŸããïŒ
ãµã€ãã®ã¡ã€ã³ããŒãžã«ç§»åããŠããœãŒã¹ã³ãŒãã調ã¹ãŸãã
ç»ålogo-vender.pngãžã®ãªã³ã¯ããã©ãããšããŸãã
ä¿åããä»»æã®ããã¹ããšãã£ã¿ãŒã§éããAdobeã¢ããªã±ãŒã·ã§ã³ã®XMPã¿ã°ã衚瀺ããŸãã
ãããïŒ ãã¡ã€ã³ã¢ã«ãŠã³ãã®ãã°ã€ã³ã®ããã«èŠããŸããå§ã¯Stupininã§ãã å®å šãªé»åã¡ãŒã«ãååŸããæ¹æ³ã«ã¯ã3ã€ã®ãªãã·ã§ã³ããããŸãããã¡ã€ã³ã¢ã«ãŠã³ãããã¡ã€ã³ã®ããã«èŠããããšãããã«æšæž¬ããmail.greatiot.phdays.comãµããã¡ã€ã³ã®ãããã¯ã解é€ããŸãããœãŒã·ã£ã«ãããã¯ãŒã¯ã®ã¢ã«ãŠã³ããéåžžã«äŸ¿å©ãªåœ¢åŒã®Twitterããã®ããŒã¿ãæäŸããŸã-æã®æ°ã¯æåã®æ°ãšæ¬åœã«åãã§ãïŒInstagramãšã¯ç°ãªããŸãïŒã
å®å šãªã¡ãŒã«ã¢ãã¬ã¹ã¯
astupinin@greatiot.phdays.com
ããšãç解ããŠããŸãã ããŸããŸãªãµãŒãã¹ã®ãã¹ã¯ãŒãå埩ãè¡ããAlexã®ãããã¡ã€ã«ãèŠã€ããŸãã
åç ïŒã¢ã¬ãã¯ã¹ã»ã¹ãã¥ããã³
æ£ããå€æ ïŒ11
1.2ã æãçŽ æŽãããã 圌ã®ãã£ãããã¹ãã©ãã«ãŒããã®ãã°ãããã圌ãä»äºã®åŸã®å€ãã©ãã§éãããããç¥ãå¿ èŠããããŸãã ïŒå€§æåã®ååïŒ
Facebookã§ãã¶ã€ããŒã®ãããã£ãŒã«ãèŠã€ããããFoursquareïŒSwarmAppïŒã§ãã§ãã¯ã€ã³ããŒããèŠã€ããŠã圌ã®äœãã§ããå Žæãšå€åå ã確èªã§ããŸãã
æŽå²ã詳ãã調ã¹ããšãfitbit_log_07_05.cvsãã¡ã€ã«ãžã®ãªã³ã¯ããããŸãã
è·å Žãšå®¶ãæ¯èŒããŠãå°å³ãèŠããšããããã¯2ã€ã®ãã€ã³ãã§ããããã®éã«ã»ãšãã©ã®ã¹ãããããããšçµè«ä»ããããšãã§ããŸãã ãŸããããã€ãã®æ¥ã«ã¯ãéåžžãããå€ãã®ã¹ãããã家ã«ãšãããŸããã ä»äºã®åŸã圌ã¯700ã800æ©æ©ãããã°ãããã®å Žæã«æ»åšããŸãã Foursquareãéããšã圌ã®äœåãã500ã¡ãŒãã«ã»ã©ã®ãšããã«ããã€ãã®ãããèŠã€ãããŸããã éžæè¢ã¯ã»ãšãã©ãªãããã©ãã®ããŒã¯ããã«ãããŸãã
åç ïŒãã©ã
æ£ããå€æ ïŒ9
2.ãªãŒãIoTéçºè
2.1ã ãã¹ã¯ãããã®èæ¯ã«ãã劻ã®åçã®ã¿ããããŸãïŒ yadi.sk/i/wIMhX59h3J5ufA éçºè ã®å人ãµãŒããŒã®IPã¢ãã¬ã¹ãèŠã€ããŸãã
å ¥ãå£ã«ã¯ãåçãšãããæ®åœ±ããããšãããæ¥ä»ããããŸãïŒphoto_2017-04-25_15-46-33.jpgïŒã åçã§ã¯ãGorkyã«ã¡ãªãã§åä»ããããã»ã³ãã©ã«ããŒã¯ãªãã«ã«ãã£ãŒã¢ã³ãã¬ã¹ããããããŸãã æ€çŽ¢ããã«ã¯ã4æ25æ¥ã«VKãšInstagramã®åçãæåã§ã¹ã¯ããŒã«ããããsnradar.azurewebsites.netãµãŒãã¹ã䜿çšã§ããŸãã
èŠã€ããïŒ
ååãšå§ã§ãInstagram elena91uã§ã¢ã«ãŠã³ãã®èšåãèŠã€ããŸãã
ãããã¡ã€ã«èªäœã§ãã®åçãèŠã€ããåé¡ã調ã¹ãŸããããã§ãsoftcodermaxã¢ã«ãŠã³ããèŠã€ããPastebinã§ãããã¡ã€ã«ãèŠã€ããŸããã
åç ïŒ188.166.76.66
æ£ããå€æ ïŒ18
2.2ã©ããããéçºè ã¯ããŒã ãã£ããã䜿çšããŠããŸããããå€ãã®å ŽåãVoIPãä»ããŠç©äºã«ã€ããŠè©±ãåããŸãã VoIPã²ãŒããŠã§ã€ã®ã¢ãã¬ã¹ãååŸããŸãã
åã®ã¿ã¹ã¯ã®WebãµãŒããŒäžã§ãsitemap.xmlãèŠã€ããããšãã§ããŸããããã«ã¯ããšãããã¹ã¯ãªããã/logs.phpããžã®ãªã³ã¯ãå«ãŸããŠããŸãã
ãã©ãŠã¶ã§logs.phpã¹ã¯ãªãããéããšããlogdate is missingãããšããã¡ãã»ãŒãžã衚瀺ãããŸãã æçµãã°æ¥ä»20170428ãã188.166.76.66 / logs.phpïŒlogdate = 20170428ã®åœ¢åŒã§ãã©ã¡ãŒã¿ãŒãæå®ãããµãŒããŒã®ã¢ã¯ã»ã¹ãã°ãžã®ã¢ã¯ã»ã¹ãååŸããããšããŸãã å¯èœãªæ¥ä»ç¯å²ã®ãã°ãåæããåŸãRefererããããŒããã®Skypeãã£ããã°ã«ãŒããžã®ãªã³ã¯ãå«ã次ã®ãšã³ããªãèŠã€ãããŸããã
64.19.23.198 - - [26/Apr/2017:08:26:09 +0000] "GET / HTTP/1.1" 200 2613 "https://join.skype.com/aMxdupsIlSgI" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.133 Safari/537.36"
ãªãŒãã³ãªSkypeã°ã«ãŒãã«æ¥ç¶ãããšãéçºè ã®éä¿¡ã«VoIPã²ãŒããŠã§ã€ã®ã¢ãã¬ã¹ãèšèŒãããŠããŸãã
åç ïŒvoip-gw-home-198.phdays.com
æ£ããå€æ ïŒ3
2.3æªããªãã ãã¶ããããªãã¯åœŒãæåŸã«é»è©±ãã人ãèŠã€ããããšãã§ããŸããïŒ
æ¿èªã«å€±æãããšãvoip-gw-home-198.phdays.comããŒãžã§ãDblTekãã³ããŒã®ååãå«ã次ã®HTMLã³ãŒãã衚瀺ãããŸãã
ããŒããã¹ãã£ã³ããããšã«ãããTelnetããŒãã§èš±å¯ãèŠæ±ãããµãŒãã¹ãèŠã€ããããšãã§ããŸãã
ãã®æ å ±ãæ¯èŒããŠã€ã³ã¿ãŒããããæ€çŽ¢ãããšããã®è£œåã®ããã¯ããŒã¯ã®èª¬æãšäºæž¬å¯èœãªãã°ã€ã³ã³ãŒããçæããããã®ãšã¯ã¹ããã€ããèŠã€ãããŸãïŒ https : //github.com/JacobMisirian/DblTekGoIPPwn ã
å ¥åãããã£ã¬ã³ãž/ã¬ã¹ãã³ã¹ã³ãŒããžã§ãã¬ãŒã¿ãŒã䜿çšããŠãã·ã¹ãã å ã®ã·ã§ã«ãååŸããvoipãŠãŒã¶ãŒã®ããŒã ãã©ã«ããŒå ã®sqliteããŒã¿ããŒã¹ã§ãŠãŒã¶ãŒã®é£çµ¡å ãèŠã€ããŸãã
åç ïŒ+79262128506
æ£ããå€æ ïŒ3
3. GreatIOTãšãã³ãžã§ãªã¹ãããã³ãããã¹ã¿ãŒ
3.1ã èŠã€ããããšãã§ããã®ã¯ã圌ã®ã¡ãŒã«ã¢ãã¬ã¹digitalmane@yandex.comã ãã§ãã ãããã圌ã®ã«ãŒã¿ãŒã«é¢ããæ å ±ã¯ã©ããã«ä¿åãããŠããŸã...ãã®URLãçºèŠããŠãã ããïŒ ïŒåœ¢åŒïŒhostname.com/page/ïŒ
Yandexã§ã¢ã«ãŠã³ããäœæãããããã¹ã¯ãŒããå埩ããŠã¿ãŠãã ãããç§å¯ã®è³ªåããæ°ã«å ¥ãã®ã¢ãŒãã£ã¹ããã衚瀺ãããŸãã ãæ°ã«å ¥ãã®ã¢ãŒãã£ã¹ããèŠã€ããããã®ãªãã·ã§ã³ã¯ããŸããããŸãããVKãSoundCloudãLast.fmã®ããããã§ãã Googleããã¹ãŠãã€ã³ããã¯ã¹åã§ããã®ã¯è¯ãããšã§ãã
ãŽãŒã¹ããã³ãšããç§å¯ã®èšèã§ã¢ã«ãŠã³ãã埩å ãããšãã¢ã«ãŠã³ãã«å ¥ããŸãã Yandexã¢ããªã±ãŒã·ã§ã³ã®ãªã¹ãå šäœãéããURLãèªåã§ä¿åã§ãããã®ãéžæããŸãã ãã£ã¹ã¯ãã¡ãŒã«ããã©ãŠã¶ãšã®åæãããã³WebmasterãDirectãŸãã¯Metricãå¯èœã§ãã çµ±èšã®æåŸã®ãµãŒãã¹ã§ãã€ã³ããã¯ã¹ä»ãããŒãžold1337ãèŠã€ãããŸããã
åç ïŒgreatiot.phdays.com/old1337/
æ£ããå€æ ïŒ66 *
*ã³ã³ãã¹ãã®æåã«ã誰ããé»è©±ãã¡ãŒã«ã«çµã³ä»ããç§å¯ã®èšèã«ããå埩ãæ©èœããªããªã£ããããå®å šãªåçãæå®ããå¿ èŠããããŸããã
3.2ã ã«ãŒã¿ãŒã®IPã¢ãã¬ã¹ãèŠã€ããŸããïŒ
old1337ãã£ã¬ã¯ããªã«å ¥ããšã次ã®ã³ã³ãã³ããååŸãããŸãã
Googleã§ãã¹ãŠã®ãã¡ã€ã«ã確èªãããšãããhow_to_connect.rarãé€ãããããã®ã»ãšãã©ãããŸããŸãªã¢ããªã±ãŒã·ã§ã³ïŒHEXãnetcatïŒã®æšæºã§ããããšãããããŸããã RARã¢ãŒã«ã€ãã«ã¯1ã€ã®æ©èœããããŸã-代æ¿ã®NTFSã¹ããªãŒã ãå€ãã®å Žåæšæºã®Zone.Identifierãã¢ãŒã«ã€ãããæ©èœïŒOOXMLãã¡ã€ã«ã«$ DATAãè¿œå ããããã¡ã€ã«ããŠãŒã¶ãŒã®ãã·ã³ã«å°éããå Žæã瀺ããããText.InformationïŒ$ DATAãè¿œå ããŸããã«ãŒã¿ãŒã®IPã¢ãã¬ã¹ã«é¢ããæ å ±ãå«ãŸããŠããŸãã
åç ïŒ178.62.218.236
æ£ããå€æ ïŒ4
3.3ã èå³æ·±ã...圌ã¯ãç¹ã«ãã®ãããªååã§ããããã¹ã¿ãŒã®ããã«èŠããŸããã 圌ã®å§ãšåã調ã¹ãŠãã ããã
ç§ãã¡ã®åã«ããã®ã¯ãæšæºã®ãã°ã€ã³ãšãã¹ã¯ãŒããšã2ã€ã®èå³æ·±ãã»ã¯ã·ã§ã³ãåããã«ãŒã¿ãŒã§ãïŒæ§æãšã¹ããŒã¿ã¹ãšãã°ïŒ
XMLããæ§æãã©ãã§åŸ©å ã§ããŸããã ãã®å Žåã«æåã«æãæµ®ãã¶ã®ã¯ãXMLå€éšãšã³ãã£ãã£ã®è匱æ§ã§ãã ããããã©ã®ãã¡ã€ã«ãèªãå¿ èŠããããŸããïŒ ã¹ããŒã¿ã¹ãšãã°ã確èªãããšã次ã®ããšãããããŸãã
XXEãä»ããããŒãžãžã®çŽæ¥åºåã¯ãªãããã ããã§èª¬æããã¢ãŠããªããã³ãææ³ã䜿çšããå¿ èŠããããŸã ã / etc / passwdãªã©ã®ãã¡ã€ã«ã¯èªã¿åãå¯èœã§ããã.pcapã¯ãã€ããªã§ãããphpïŒ//ãã£ã«ã¿ãŒã©ãããŒã䜿çšããå¿ èŠããããŸããããšãã°ã www.idontplaydarts.com / 2011/02 / using-php-filter-for-local-ãã¡ã€ã«å å«
ããã«å©çšå¯èœïŒ
Base64ããã³ãŒããããšããã¡ã€ã³èš±å¯ã®ãªã¯ãšã¹ããååŸããããã®å°ããªãã³ããååŸãããŸãã
ããã§ãå§ãšå§ã®ãã¡ã€ã³åã®åœ¢åŒãèãããšãå§ïŒPanteleevãåŠç¿ããŸãã ååãèŠã€ããããã«æ®ã£ãŠããŸãã ããããã¹ã¿ãŒã®å¥åŠãªååãã«ã€ããŠã®æããããèãããšãäœäººãã¯æŽçãå§ããæ°äººã¯æ£ããæšæž¬ããããšããã§ãããšèšã䟡å€ããããŸãã ããããç§ãã¡ãå®ãã解決çã¯ããœãŒã·ã£ã«ãããã¯ãŒã¯ãéããŠæ©èœããŸããã
VCã§ã¯ãå埩ã®ããã«ãFacebookãšã¯ç°ãªããå§ãç¥ã£ãŠããå¿ èŠããããŸãããããã«ã¯ãã¹ãŠããããŸãã
åç ïŒã¢ã€ã¶ãã¯ã»ãã³ãã¬ãšã
æ£ããå€æ ïŒ2
4.ç§æžã¯äœããé ããŠããŸã...
4.1ã é»è©±çªå·ã®äžéšããèŠã€ããããšãã§ããŸããã§ãããã圌女ã®é»åã¡ãŒã«ã¯brintet@protonmail.comã§ãã ãã«ããŒãžã§ã³ãèŠã€ããæ¹æ³ã«ã€ããŠã®ã¢ã€ãã¢ã¯ãããŸããïŒ +7 985 134 ****
æåã«ããã€ãã®ç¹ãèæ ®ããã«ã¿ã¹ã¯ã®å€ãããŒãžã§ã³ãã¬ã€ã¢ãŠãããã®ã§ãèŠåãã䟡å€ãããã®ã§ãåŸã§ã¡ãŒã«ãè¿œå ããŠæŽæ°ããŸããã ãŸãããã³ãã䜿çšãããšããœãªã¥ãŒã·ã§ã³ã¯ããã«ç°¡åã«ãªããŸãããã»ãšãã©ã®äººæ°ãµã€ãã§ã¯ãPayPalã§æ¯æããåãä»ããŠãããããããã«è¡ã£ãŠã¡ãŒã«ã§ã¢ã«ãŠã³ãã埩å ããŸãã
åç ïŒ+79851348961
æ£ããå€æ ïŒ19
4.2ã 圌女ã®å§ãšåãèŠã€ããã®ã¯é£ããããšã§ã¯ãªãã§ããããïŒ
å®å šãªé»è©±çªå·ãããå Žåãå®å šãªæ å ±ãååŸããå Žæã«ã€ããŠå€ãã®ã¢ã€ãã¢ããããŸãããã¡ãã»ã³ãžã£ãŒã¯ããã«è¿œå ãããŸãïŒWhatsAppãViberãTelegramãç§ãã¡ã¯ã¢ã«ãŠã³ããèŠã€ããŸãïŒ
åç ïŒããªã¢ã»ããªã³ããã
æ£ããå€æ ïŒ14
5.è¡æ¹äžæã®ç·ïŒ1
5.1ã 圌ã¯ãã®ãŠã©ã¬ããLMksJQ3GrHXDSMjwEvPAEJsaXS7agq6DaQã«é¢é£ããç§å¯ãæã£ãŠããŸãã 圌ããã®ãã¹ãŠã®ãéãã©ãã«éã£ãã調ã¹ãŠãã ããã
ååã«ããããŠã©ã¬ãããLitecoinã«å±ããŠãããšå€æã§ããŸãã Litecoinãããã¯ãåæããæçµçãªãŠã©ã¬ãããžã®è³éã®ç§»åã远跡ã§ãããµãŒãã¹ã®ããããã䜿çšããŸãã
åç ïŒLM33p4m3ZDk5rs1BjkWUvEw3UWWiaH2u2L
æ£ããå€æ ïŒ23
5.2ã 圌ãã©ãã«ããã調ã¹ãã
åã®ã¿ã¹ã¯ã§èŠã€ãã£ããŠã©ã¬ããçªå·ã«ãã£ãŠãåœäºè ã®è©³çŽ°ãå«ãæ¯æãè«æ±æžãGoogleã§èŠã€ãããŸãã
ã¬ã¿ãŒã
jp.karter7@gmail.com
éä¿¡ãããšã次ã®èªåè¿ä¿¡ãå±ããŸãã
åç ïŒè€æ°ã®
æ£ããå€æ ïŒ12
6.ãªããããªã«å€ãã®æ¶ïŒ
6.1ã èŠã€ããããšãã§ããã®ã¯ãéçºè ã®ã¢ã«ãŠã³ããšCloudPetsã®èšé²yadi.sk/d/qTNjZYj63J5vHBã ãã§ãã 圌ã®ç§å¯ãèããŸãã
cloudpets.7zãšããååã®ã¢ãŒã«ã€ããååšãããªã³ã¯ãæäŸãããŸãããããã¯ãAWSã¯ã©ãŠãã«é³å£°ã¡ãã»ãŒãžãèšé²ããã³æçš¿ããCloudPetsããã¡ãã®ç©èªãæ瀺ããŠãããåŸã«ããã«ãŒã«ãã£ãŠããŒãžãããŸããïŒhttps://www.troyhunt.com/data-from -connected-cloudpets-teddy-bears-leaked-and-ransomed-exposing-kids-voice-messages /ïŒã
ã¢ãŒã«ã€ããéããšã2ïŒ44ã®é²é³ãèŠã€ãããé²é³å šäœãèãã®ã¯éåžžã«åé¡ãããããããªãŒãã£ãªãšãã£ã¿ãŒïŒããšãã°ãSonic VisualiserïŒã§ãã©ãã¯ãéããŸããããã§ã¯ãåšæ³¢æ°ã®å€åãããé¡èã§ããã¹ãã¯ãã«åææ©èœãå¿ èŠã§ãã å°ãç®ç«ã€ããã€ãã®ãã€ã³ããã¹ã¯ããŒã«ãããšãç·æ§ã®å£°ããã¹ã¯ãŒããèšãé»è©±ã§ã®äŒè©±ãèŠã€ãããŸãã
åç ïŒGHgq217 $ïŒ178 @ k12 /
æ£ããå€æ ïŒ5
7.ã©ãã§ãã¯ããŒã«ããPython
7.1ã éçºè ã®Twitterãã°ã€ã³ãååŸããŸãã ããã«WebãµãŒãã¹ããããŸãïŒdevsecure-srv139.phdays.com
devsecure-srv139.phdays.comãéããšãã¯ã©ã€ã¢ã³ã蚌ææžã«ãã°ãªã³ããå¥ã®å¯èœæ§ã«ã€ããŠèšåããæ¿èªããŒãžã衚瀺ãããŸãã ãµãŒããŒå¿çã«ã¯ãCloudFlareã®äœ¿çšã瀺ãããããŒããããŸãã
CF-RAY:3519eafdb3a94e84-DME Server:cloudflare-nginx
IPã¢ãã¬ã¹ã§Googleã®ããŒãžãã£ãã·ã¥ãåç §ããŸãã
蚌ææžãšCAããŒãå«ããµãŒããŒã¡ã¢ãªã®ãã©ã°ã¡ã³ããæ€åºããŸãïŒã»ãšãã©ã®å ŽåãCloudbleedã«ééããŸããïŒã
CA蚌ææžïŒca.keyãcââa.crtïŒãæœåºããã¯ã©ã€ã¢ã³ã蚌ææžãçæããŸãã
openssl genrsa -out client.key 1024 openssl req -new -key client.key -out client.csr openssl x509 -req -days 365 -in client.csr -CA ca.crt -CAkey ca.key -set_serial 3137 -out client.crt openssl pkcs12 -export -clcerts -in client.crt -inkey client.key -out client.p12
蚌ææžããã©ãŠã¶ã«ã€ã³ããŒããããšã蚌ææžã䜿çšããŠãã°ã€ã³ããéçºè ãªããžããªã«ã¢ã¯ã»ã¹ã§ããããã«ãªããŸãã ãªããžããªå ã®Twitterãããã®æ§æãã¡ã€ã«ã«ã¯ãå¿ èŠãªãŠãŒã¶ãŒåãå«ãŸããŠããŸãã
åç ïŒMontyPythonist
æ£ããå€æ ïŒ6
8.ã·ã¹ãã 管çè
8.1ã ããŒã¯ã³d91496dfcaad93f974a715fb58abeeb0ããã³VDS 188.226.148.233ãèŠã€ãããŸããã sysadminã®githubã¢ã«ãŠã³ããèŠã€ããŠãã ããã
ãã¹ãåæãããŠãŒãã£ãªãã£ã䜿çšããŠãAPIãžã®ãªã³ã¯ãèŠã€ããŸã-http://188.226.148.233/api/tasksãããã«ã¯ããŒã¯ã³ãå¿ èŠã§ãã GETãã©ã¡ãŒã¿ãŒã§ããŒã¯ã³ãæå®ãããšãç¹ã«GitHubã¢ã«ãŠã³ããå«ãJSONã®ã¿ã¹ã¯ã®ãªã¹ãã衚瀺ãããŸã ã
åç ïŒéå±
æ£ããå€æ ïŒ12
8.2ã ããŒã ã«ãŒã¿ãŒã®ããã«èŠããŸã...äœãé¢çœããã®ãæãèµ·ãããã©ããã確èªããŸãã
Googleã«anneximousãå ¥åãããšãå¯äžã®ãªããžããªãèŠã€ãããŸãã
説æã«ã¯ãIPã¢ãã¬ã¹ãš3ã€ã®ãã¡ã€ã«ãããããã®ãã¡camera_contol.htmlãšleft.jsã«é¢å¿ããããŸãã
IPã¢ãã¬ã¹188.166.30.118ã®ããŒããã¹ãã£ã³ãããšãããŒã8080ã§IPã«ã¡ã©ã«ã¢ã¯ã»ã¹ããããã®ããŒãžãèŠã€ãããŸãããã¹ã¯ãŒããšãã°ã€ã³ã¯camera_control.htmlãã¡ã€ã«ã«ãããŸããããã°ã€ã³ããããšãããšåžžã«ãšã©ãŒãçºçããŸãã
次ã«ãleft.jsãã¡ã€ã«ã®åŠç¿ãå§ããŸãããã æåã®é¢æ°ã¯ããã«ç®ãåŒããŸãïŒ
function Call(xml) { if (gVar.httpver == "https") { setCookie("snapcmd", gVar.httpver + "://" + gVar.ip + ":" + mult_https_port[IFs] + "/cgi-bin/CGIProxy.fcgi?" + (urlEncode("usr=" + gVar.user + "&pwd=" + gVar.passwd + "&cmd=snapPicture"))); }
ãããããã«ã¡ã©ããç»åããã£ããã£ããæåã®ãªã¯ãšã¹ããååŸããŸãã
http://188.166.30.118:8080/cgi-bin/CGIProxy.fcgi?usr%3Dphdaysiot%26pwd%3Dphdaysiot7%26cmd%3DsnapPicture
ãã ããã«ã¡ã©ã¯ééã£ãæ¹åã«åããããŠãããã¿ã¹ã¯ã¯å¶åŸ¡ã³ãã³ããèŠã€ããããšã§ãã è¯ãããšã¯ããã¥ã¡ã³ãããããŸãïŒ
ããã¥ã¡ã³ãã«ã¯ãã«ã¡ã©ãæ°Žå¹³ããã³åçŽã«å転ããèŠæ±ãšã移åãåæ¢ããã³ãã³ãããããŸãã
188.166.30.118ïŒ8080 / cgi-bin / CGIProxy.fcgiïŒUsrïŒ 3DphdaysiotïŒ 26pwdïŒ 3Dphdaysiot7ïŒ 26cmdïŒ 3DptzMoveLeftãªã©ïŒptzMoveDownãptzMoveUpãptzMoveRightãã¢ãŒã·ã§ã³ã¹ãããé¢æ°ïŒptzStopRunã ç²ç®çã«ã«ã¡ã©ãæ£ããæ¹åã«åããŠãã©ã°ãååŸããããšã¯æ®ã£ãŠããŸãã
åç ïŒéå±ããã£ãªãã
æ£ããå€æ ïŒ7
çµæ
66åã®åºå Žè ãå°ãªããšã1ã€ã®èª²é¡ãå®äºããŸããã 3æ¥éãã¹ãŠããªãŒããŒã¯ãã€ã€ãŒïŒSipan VardanyanïŒã§ãã-ãã¹ãŠã®ã¿ã¹ã¯ã解決ã§ããå¯äžã®äººã§ãã 2äœã¯AVictorïŒVictor AlyushinïŒãmkhazovïŒMaxim KhazovïŒã®1ãã€ã³ãå ã§ãã
1 | Noyer | 16 |
2 | ã¢ãã¯ã¿ãŒ | 13 |
3 | ã ã«ãŸã | 12 |
4 | åãç· ãŸã | 10 |
5 | ããã« | 9 |
6 | ãŠã«ãµã¹ | 9 |
7 | x010 | 8 |
8 | ã㺠| 8 |
9 | Threatintel | 8 |
10 | ãããã°ã㌠| 5 |