s25

s25



Terminal


ox

File Edit View lerminal Tabs Help

root@honeypot honeyd# arpd -d 10.0.0.4-10.0.0.254

arpd[6539): listening on ethO: arp and (dst net 10.0.0.4/30 or dst net 10.0.0.8/29 or dst net 10.0.0.16/28 or dst net 10.0.0.32/27 or dst net 10.0.0.64/26 or dst net 10.0.0.128/26 or dst net 10.0.0.192/27 or dst net 10.0.0.224/28 or dst net 10.0.0.240/29 or dst net 10.0.0.248/30 or dst net 10.0.0.252/31 or dst net 10.0.0.254/32) and not ether src 00:00:39:af:68:f7

i

File Edit View lerminal Tabs Help


root@honeypot honeyd# honeyd -d -u O -g O -f config3 10.0.0.4-10.0.0.254 Honeyd V0.8b Copyright (c) 2002-2004 Niels Provos

honeyd!6536]: started with -d -u O -g O -f config3 10.0.0.4-10.0.0.254 Warning: Impossible SI rangę in Class fingerprint "IBM 0S/400 V4R2M0"

Warning: Impossible SI rangę in Class fingerprint "Microsoft Windows NT 4.0 SP3"

honeyd!6536]: listening promiscuously on ethO: (arp or ip proto 47 or (ip and (dst net 10.0.0.4/30 or dst net 10.0.0.8/29 or dst net 10.0.0.1

6/28 or dst net 10.0.0.32/27 or dst net 10.0.0.64/26 or dst net 10.0.0.128/26 or dst net 10.0.0.192/27 or dst net 10.0.0.224/28 or dst net 10

.0.0.240/29 or dst net 10.0.0.248/30 or dst net 10.0.0.252/31 or dst net 10.0.0.254/32))) and not ether src 00:00:39:af:68:f7

honeyd!6536]: Demoting process privileges to uid O, gid O

honeyd!6536]: Connection request: tcp (10.0.0.3:32808 - 10.0.0.200:9996)

honeyd!6536]: Connection established: tcp (10.0.0.3:32808 - 10.0.0.200:9996) <-> /bin/sh scripts/Sasser_Catcher.sh 10.0.0.3 10.0.0.200 honeyd!6536]: E(10.O.O.3:32808 - 10.0.0.200:9996): 1234_up.exe:

1234_up.exe:    ETA:    0:00    13.24/ 50.00 kB    5.95 MB/s

1234_up.exe:    ETA:    0:00    50.00/ 50.00 kB    7.84 MB/s

1234_up.exe:    50.00 kB 7.84 MB/s

honeyd!6536]: Expiring TCP (10.0.0.3:32808 - 10.0.0.200:9996) (0x832ale0) in state 7 honeyd!6536]: exiting on signal 2 root@honeypot honeyd# Is -1 /worms/Sasser/ total 4

drwxr-xr-x 2 root root 4096 Feb 23 18:43 10.0.0.3-10.0.0.200-1109180623 root@honeypot honeyd# Is -1 /worms/Sasser/10.O.O.3-10.O.O.200-1109180623/ total 56

-rw-r--r--    1 root root 51200 Feb 23 18:08 1234_up.exe

root@honeypot honeyd# [


Wyszukiwarka

Podobne podstrony:
s23 TerminalFile Edit View lerminal Tabs Help root@honeypot honeyd# arpd -d 10.0.0.4-10.0.0.254 arpd
s3 (2) File Edit View lerminal Tabs Help root@honeypot honeyd# arpd -d 10.0.0.10-10.0.0.12 arpd[6
s40 File Edit View lerminal Tabs Help root@honeypot honeyd# arpd -d 10.0.0.4-10.0.0.254 arpd[6301
s5 (3) File Edit View lerminal Tabs Help root@honeypot honeyd# arpd -d 10.0.0.10-10.0.0.12 arpd[6
s43 Terminal File Edit View lerminal Tabs Help root@honeypot honeyd# cat /worms/cłeanup Thu Feb
s11 (2) File Edit View lerminal Tabs Help root@honeypot honeyd# cat logs/test .log Tue Feb 22 11:
s42 File Edit View lerminal Tabs Help root@honeypot honeyd# honeyd -d -u 0 -g 0 -f config4 10.0.0
s13 (2) == Terminal File Edit View lerminal Tabs Help root@evil : ~# ping 10.0.0.123 PING 10.0.0
s22 minal File Edit View lerminal Tabs Help root@evil:~# telnet 10.0.0.200 4444 T rying
s24 :_File Edit View lerminal Tabs Help root@evil:~# telnet 10.0.0.200 9996 T rying 10.0.0.200... Co
s18 Terminal File Edit View lerminal Tabs Help # # ftpusers This file describes the names of th
s1 (2) Terminal File Edit View lerminal Tabs Help create linux set linux personality "Linu
s21 :: Terminal File Edit View lerminal Tabs Help DATE= datę +%s mkdir /vorms/Sasser/$l-$2-$DAT
s28 Terminal File Edit View lerminal Tabs Help rootghoneypot honeyd# ssh -l Administrator
s33 Terminal File Edit View Terminal Tabs Help root@honeypot honeyd# ssh -1 Administ
2u El S?
s10 (3) File Edit View lerminal Tabs Help arpd! 6210): arpd_timeout:
s20 — — 1 1 1 ninal File Edit View lerminal Tabs Help DATE= datę +’.s mkdir

więcej podobnych podstron