Thanks Thanks:  1
Likes Likes:  1
Dislikes Dislikes:  0
Results 1 to 10 of 10

Thread: virusare ?????

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Standard RSP member
    Join Date
    07 Sep 2013
    Location
    https://t.me/blackhatshiller
    Posts
    386
    Mentioned
    2 Post(s)
    Rep Power
    53

    Default

    intra cu telnet/ssh pe echipament si vezi dai comanda ps
    vezi daca apare ceva de streamming pe acolo
    mai nou am vazut ca arabetii intra pe cutii si fac streamming catre servere de iptv.

  2. #2
    none
    Join Date
    01 Jan 1999
    Location
    acasa
    Posts
    849
    Mentioned
    42 Post(s)
    Rep Power
    100

    Default

    dingo31 : daca vrei sa postezi poze, pui doar jpg,jpeg sau png la 1024/760 jepg=ca.790k sau png=ca. 690k..si o sa arate cam asa:

    Attachment 1141

    daca nu-ti iese...foloseste "Add image to post" de jos din stinga...

    chiar daca nu fae thumb, nu-i problema...se poate vedea la klick...
    ^^^^
    bafta

  3. #3
    maniac lao's Avatar
    Join Date
    02 Sep 2009
    Posts
    3,722
    Mentioned
    31 Post(s)
    Rep Power
    107

    Default

    Eu cred ca e o vulnerabilitate in webif la imaginea VTI. Asa cum au mai fost aceleasi probleme cu webif...
    Am testat-o si eu nitel, e stabila si la un moment dat am vazut ca merg 2 tunere. Noroc cu display-ul care afiseaza mai multe info.
    Am verificat daca e vreun pc conectat si nu era. Apoi m-am uitat in oscam si am vazut ca decoda 2 canale.
    Am intrat in ruter si am oprit porturile webif si streaming si a disparut al 2-lea tuner!
    Deci fara sa am porturi ssh, telnet sau ftp deschise s-a intamplat asta. Apoi am cautat in loguri si am gasit ;
    [1970/01/01 02:00:16, 1] lib/account_pol.c:account_policy_get(286)
    account_policy_get: tdb_fetch_uint32 failed for field 1 (min password length), returning 0
    [1970/01/01 02:00:16, 1] lib/account_pol.c:account_policy_get(286)
    account_policy_get: tdb_fetch_uint32 failed for field 2 (password history), returning 0
    [1970/01/01 02:00:16, 1] lib/account_pol.c:account_policy_get(286)
    account_policy_get: tdb_fetch_uint32 failed for field 3 (user must logon to change password), returning 0
    [1970/01/01 02:00:16, 1] lib/account_pol.c:account_policy_get(286)
    account_policy_get: tdb_fetch_uint32 failed for field 4 (maximum password age), returning 0
    [1970/01/01 02:00:16, 1] lib/account_pol.c:account_policy_get(286)
    account_policy_get: tdb_fetch_uint32 failed for field 5 (minimum password age), returning 0
    [1970/01/01 02:00:16, 1] lib/account_pol.c:account_policy_get(286)
    account_policy_get: tdb_fetch_uint32 failed for field 6 (lockout duration), returning 0
    [1970/01/01 02:00:16, 1] lib/account_pol.c:account_policy_get(286)
    account_policy_get: tdb_fetch_uint32 failed for field 7 (reset count minutes), returning 0
    [1970/01/01 02:00:16, 1] lib/account_pol.c:account_policy_get(286)
    account_policy_get: tdb_fetch_uint32 failed for field 8 (bad lockout attempt), returning 0
    [1970/01/01 02:00:16, 1] lib/account_pol.c:account_policy_get(286)
    account_policy_get: tdb_fetch_uint32 failed for field 9 (disconnect time), returning 0
    [1970/01/01 02:00:16, 1] lib/account_pol.c:account_policy_get(286)
    account_policy_get: tdb_fetch_uint32 failed for field 10 (refuse machine password change), returning 0
    [1970/01/01 02:00:16, 0] /media/build/openvuplus/build/tmp/work/mips32el-oe-linux/samba/samba-3.0.37-r2-vuplus3/samba-3.0.37/source/lib/pidfile.cidfile_create(112)
    ERROR: smbd is already running. File /var/run/smbd.pid exists and process id 695 is running.
    Am schimbat imaginea, am pus VIX si acum folosesc webif pe https nu pe http.
    Si n-am obiceiul sa instalez tot felul de ciudatenii de pluginuri
    Doi mari vrăjmași are românul: mila pentru străini și ura pentru ai lui - Grigore Vieru

  4. #4
    Standard RSP member
    Join Date
    07 Sep 2013
    Location
    https://t.me/blackhatshiller
    Posts
    386
    Mentioned
    2 Post(s)
    Rep Power
    53

    Default

    Lol,din ce ai postat tu acolo pare un exploit de samba(care are destule)
    Interesant.....
    Samba e cam in toate imaginile(posibil sa fi fost o coincidenta sa incerce la voi la rec)
    De obicei scannerele(cu xpl) de samba vizeaza pagini web....dar mai sti...pe foametea asta cu araboteii ...nu se stie niciodata

  5. #5
    maniac lao's Avatar
    Join Date
    02 Sep 2009
    Posts
    3,722
    Mentioned
    31 Post(s)
    Rep Power
    107

    Default

    Nu-s de care o fi fost , dar n-avea pe unde intra decat pe webif (http)
    Din cate stiu, pe https nu au succes deloc.
    Din pacate, m-am grabit sa-l opresc in loc sa investighez cu un netstat sa-i vad ip-ul.
    PS Si n-avea gusturi rele, isi alesese un canal bun de la italieni
    Last edited by lao; 17-02-14 at 00:20.
    Doi mari vrăjmași are românul: mila pentru străini și ura pentru ai lui - Grigore Vieru

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •