转到正文

DalianSky's Blog

正在修建中的空中楼阁

存档

分类: ROS及相关路由

海蜘蛛ISP版本的后门==初步解决办法

etc 目录
fake_support_server    文件中的IP 指向海蜘蛛官方下载页面,需把 IP 去掉,或修改成别的地址
shadow 文件中去掉 muddyboot:wx4WPMrmiOMFA:13632:0:99999:7:::
md5check.lst      修改shadow后,shadow文件的MD5校验值就变了,修改 /etc/shadow 3e0dabfa647a76b0beb57f20f258499f到正确的值
oem    版本文件,比如其中的 VERSION=”6.1.0″   修改为 VERSION=”6.1.5″ ,不用我多说了吧,还有其他内容自己改吧
(你可以改成任意版本啦 !!!)
passwd   去掉 muddyboot:x:10:10::/home:/bin/bash    这行
注意修改 md5check.lst 文件中  /etc/passwd 5c5ab6467a5c5f18891cf7ed2c1a826f  改为正确的值
获得MD5值的方法(linux环境),md5sum -b filenames产生md5
md5sum -c md5file用来检验
md5  shadow   回车,就得到  shadow   的md5 值了,md5  passwd   回车,就得到  passwd   的md5 值了
解包命令:cat hsrouter_isp_v6.1.0.bin| openssl des-cbc -k ‘letusd01twell’ -d > 1.tar.gz
封包命令:cat 1.tar.gz | openssl des-cbc -k ‘letusd01twell’ >hsrouter_isp_v6.1.0.bin
剩下的需要自己搭建linux的环境,去慢慢修改了吧。
  • Google Reader
  • Google Bookmarks
  • Facebook
  • Twitter
  • Yahoo Bookmarks
  • Windows Live Spaces
  • MySpace
  • Hotmail
  • Yahoo Mail
  • WordPress
  • Yahoo Messenger
  • Windows Live Favorites
  • Share/Bookmark

Router OS ID & KEY:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
C1HM-PRT L3
-----BEGIN MIKROTIK SOFTWARE KEY------------
bDrDclkmLQMif9GuGRB4t4aK2k/pmI/bZyr5u27n4JvV
wsrmKpQWZVGt4UwucIfeN7x6EdSU/D2nG3wyFJrTLB==
-----END MIKROTIK SOFTWARE KEY--------------
 
Q8C4-1AN L3
-----BEGIN MIKROTIK SOFTWARE KEY------------
JdUOqhyEQcZ0JoIkxOiv5HZ6Ccxr7BGBPp7xHsVaco2A
AEnyF7qLrCK95+fhVxZgt3LB4VbqbhTN148DECuG4D==
-----END MIKROTIK SOFTWARE KEY--------------
 
MRD8-PTT L4
-----BEGIN MIKROTIK SOFTWARE KEY------------
7U3TvqRbv+RqBZr9uOYSooFj3QYKFt4nl2Ba3yZONiOH
Ogd4ghXQihcRYHgYZORSNbf4BRSsqC5c6K7fPJsreD==
-----END MIKROTIK SOFTWARE KEY--------------
 
ILTS-NX0   L4
-----BEGIN MIKROTIK SOFTWARE KEY------------
V19S9v65xiR1HfSHCLvoWcClER7efOpND1UnHjE1zG7O
wnHzHnLjL15UhoibISZBwosqn2865NX1IhEJ4NJkeC==
-----END MIKROTIK SOFTWARE KEY--------------
VNDH-NLN  L4
-----BEGIN MIKROTIK SOFTWARE KEY------------
m7mnERL9F+AUXxL/eLj96I4rqRJl32ziBWk5r0nQfrnG
Wf02zz71D86tS/5ZYZlF9RzoOeHb85T3hVSQOR8IgC==
-----END MIKROTIK SOFTWARE KEY--------------
 
FAVD-NFT L5
-----BEGIN MIKROTIK SOFTWARE KEY------------
ZkjCGcuTi8FWBkMTzD9ZAG9QOnjtEPjKTUckhnhEaZ54
oefDJdAvXP26qVQyTHaxFhB40iNMOI18ThwEuVkO1D==
-----END MIKROTIK SOFTWARE KEY--------------
 
VY3P-XNN L5
-----BEGIN MIKROTIK SOFTWARE KEY------------
WHM2ml8P20pY7wASkcuTEqNST0oKvxImS57ZcCx7FD4e
oo7tcpfW+j8DeWN0UttrJdUEaT11gY0fwnqVybsGnD==
-----END MIKROTIK SOFTWARE KEY--------------
 
798Y-K0N  L6
-----BEGIN MIKROTIK SOFTWARE KEY------------
rVV1e2RYxT/OM9SZe9OK/0ij55RlWZIYLLmF2DCnMYlo
RbZUCWy+9YIVHRJuVgb9asNXHTAQ/IcHYiQrpBXvvA==
-----END MIKROTIK SOFTWARE KEY--------------
AK73-PET  L6
-----BEGIN MIKROTIK SOFTWARE KEY------------
x+QmBpjxS9quN4UyI2tP2AdybCYZdYWDpKhnkmVWmBZf
31hfbRA2X7ncrHoUI3yAjl6H6ZLwSJKiHXSf6bJAiD==
-----END MIKROTIK SOFTWARE KEY--------------
NNFT-86N  L6
-----BEGIN MIKROTIK SOFTWARE KEY------------
QcmFFDMuzh87/l2ngPSvD513huBKwgOLXu5tL8yhqPEl
Jns9gKAjxuZ6/Uy9YVFW09riSb1jrvZ7g0uSTVQkhC==
-----END MIKROTIK SOFTWARE KEY--------------
  • Google Reader
  • Google Bookmarks
  • Facebook
  • Twitter
  • Yahoo Bookmarks
  • Windows Live Spaces
  • MySpace
  • Hotmail
  • Yahoo Mail
  • WordPress
  • Yahoo Messenger
  • Windows Live Favorites
  • Share/Bookmark

1. 配置举例
镜像源端口为GigabitEthernet 1/1/1,对端口接收和发送的报文都进行镜像
镜像目的端口为GigabitEthernet 1/1/4
配置1:
<Quidway> system-view
[Quidway] mirroring-group 1local
[Quidway] interface gigabitEthernet 1/1/4
[Quidway-GigabitEthernet1/1/4] monitor-port
[Quidway-GigabitEthernet1/1/4] quit
[Quidway] interface gigabitEthernet 1/1/1
[Quidway-GigabitEthernet1/1/1] mirroring-port both
配置2:
<Quidway> system-view
[Quidway] mirroring-group 1local
[Quidway] interface GigabitEthernet 1/1/4
[Quidway-GigabitEthernet1/1/4] mirroring-group 1 monitor-port
[Quidway-GigabitEthernet1/1/4] quit
[Quidway] interface GigabitEthernet 1/1/1
[Quidway-GigabitEthernet1/1/1] mirroring-group 1 mirroring-port both
配置3:
<Quidway> system-view
[Quidway] mirroring-group 1local
[Quidway] mirroring-group 1 monitor-port GigabitEthernet 1/1/4
[Quidway] mirroring-group 1 mirroring-port GigabitEthernet 1/1/1 both

  • Google Reader
  • Google Bookmarks
  • Facebook
  • Twitter
  • Yahoo Bookmarks
  • Windows Live Spaces
  • MySpace
  • Hotmail
  • Yahoo Mail
  • WordPress
  • Yahoo Messenger
  • Windows Live Favorites
  • Share/Bookmark

刚才看了死性不改的网站上面有一篇关于ROS被内网发起攻击的截图,发现上面少了ROS被攻击的时候的CPU占用率。现截下我用CACTI抓到的某家网吧被攻击的LAN流量和CPU占用率,并附上正常时候的LAN流量图。以供借鉴。


基本上我遇到的状况是:内网发起UDP攻击的时候,ROS就会有丢包的现象发生了。

  • Google Reader
  • Google Bookmarks
  • Facebook
  • Twitter
  • Yahoo Bookmarks
  • Windows Live Spaces
  • MySpace
  • Hotmail
  • Yahoo Mail
  • WordPress
  • Yahoo Messenger
  • Windows Live Favorites
  • Share/Bookmark