Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- PBS.org hacked and it was not done by SQL. Here are notes:
- - PBS.org was not owned by SQL, although to make things faster/easier for us we used Havij to dump db/tables in a nice html format. So what we used havij? You lamers could have havij/pangolin/sqlmap/nmap/metasploit/and all exploits in the world compiled on one box and you still can't own shit. umadbro?
- - PBS.org was owned via a 0day we discovered in mt4 aka MoveableType 4.
- - Once on the boxES, we uploaded php shell.
- - Once we got access to php shell, we rooted the ancient pbs.org boxes AKA 2.4.21 kernels and 2.6.18 fro 2008.
- Linux httpd27 2.4.21-37.ELsmp #1 SMP Wed Sep 7 13:28:55 EDT 2005 i686
- - We rooted the boxes. We did not destroy the boxes or content. No rm's. We did not take over the homepage of pbs.org although we could have. You know what you call that? class.
- We owned network internally thanks to password-reuse by ssh users a la:
- $ cat /etc/passwd
- [ parsed out garbage users ]
- netmgr:x:98:99:Netmgr:/home/netmgr:
- tomcatmail:x:1008:98::/home/tomcatmail:/bin/bash
- interch:x:1009:1009:Interchange User:/home/interch:/bin/bash
- teachermail:x:1003:100:TeacherSource Mailing Lists:/home/teachermail:/bin/bash
- #cramer:x:508:500:Mike Cramer:/export/home/cramer:/bin/bash
- gebhardt:x:1010:500::/home/gebhardt:/bin/bash
- markle:x:506:10:Backup Administrator:/home/markle:/bin/bash
- zopeuser:x:4000:4000::/shark/apps/pbs/zope/home:/bin/bash
- loker:x:4002:4002::/home/loker:/bin/bash
- engelson:x:1015:500:Drew Engelson:/home/engelson:/bin/bash
- responder:x:4004:4004::/home/responder:/bin/bash
- statred:x:4005:4005::/home/statred:/bin/bash
- mysql:x:4006:4006::/home/mysql:/bin/false
- krang:x:4007:4007::/home/krang:/bin/bash
- smmsp:x:4008:4008::/var/spool/mqueue:/sbin/nologin
- jdroberts:x:1016:500:Jeremy D. Roberts:/home/jdroberts:/bin/bash
- nci:x:4009:4009::/home/nci:/bin/bash
- nbstrite:x:4014:500:Nowell Strite:/home/nbstrite:/bin/bash
- srrider:x:4015:500:Shawn Rider:/home/srrider:/bin/bash
- rpm:x:37:37:Readded by Alex Loker 4-27-07:/var/lib/rpm:/sbin/nologin
- chnordholm:x:4018:500:Cameron Nordholm:/home/chnordholm:/bin/bash
- rrshrotriya:x:4020:4020::/home/rrshrotriya:/bin/bash
- cfelline:x:4021:500:Cosimo Felline:/home/cfelline:/bin/bash
- paweston:x:4022:4022::/home/paweston:/bin/bash
- sol:x:4025:4025::/home/sol:/bin/bash
- kjdykes:x:4026:500:Ken Dykes:/home/kjdykes:/bin/bash
- newshour:x:4033:4033::/home/newshour:/bin/bash
- msgarcia:x:4037:500:Mary Hope Garcia:/home/msgarcia:/bin/bash
- balvarez:x:4040:4040:Betty Alvarez:/home/balvarez:/bin/bash
- dhaggerty:x:4042:4042:Dan Haggerty PBS Vote 2008 Video Producer:/home/dhaggerty:/bin/bash
- thossain:x:4045:4045:Tareque Hossain:/home/thossain:/bin/bash
- meschoch:x:4047:4047:Matt Schoch:/home/meschoch:/bin/bash
- rscox:x:4048:500:Ron Cox:/home/rscox:/bin/bash
- twcrenshaw:x:4049:500:CAT - Thomas Crenshaw:/home/twcrenshaw:/bin/bash
- arbaroch:x:4052:4052:PBSi - Amy Baroch:/home/arbaroch:/bin/bash
- sdeng:x:4053:4053:CAT - Sam Deng:/home/sdeng:/bin/bash
- rmolguin:x:4153:4153:CAT - Renzo Olguin:/home/rmolguin:/bin/bash
- PEMST:x:4154:4154:ShopPBS Sales Site Login:/home/shoppbs:/bin/false
- dwvanhorn:x:4155:4155::/home/dwvanhorn:/bin/bash
- tnetayavichitr:x:4156:4055:Tanya Netayavichitr - Updates Press Releases:/home/tnetayavichitr:/bin/bash
- pjsteele:x:4159:3000:Intern - Patrick Steele:/home/pjsteele:/bin/bash
- jlhuls:x:4160:3002:Jen Huls - GA Designer:/home/jlhuls:/bin/bash
- git:x:100:100:git version control:/home/git:/bin/bash
- ionelmc:x:4161:4161::/home/ionelmc:/bin/false
- mpjones:x:4162:3002::/home/mpjones:/bin/bash
- teacherline:x:4163:4163::/home/teacherline:/bin/bash
- kmarkle:x:4164:4164::/home/kmarkle:/bin/bash
- rtford:x:4165:4165::/home/rtford:/bin/bash
- emroman:x:4166:4166::/home/emroman:/bin/bash
- pigs:x:4167:4167:PIGS deployer:/shark/producers01/pigs/:/bin/bash
- nkocak:x:4168:4168::/home/nkocak:/bin/bash
- hagerman:x:4169:4169::/home/hagerman:/bin/bash
- magraham:x:4170:4170:Matthew Graham - PBS Parents:/home/magraham:/bin/bash
- jyu:x:4171:4171::/home/jyu:/bin/bash
- ekim:x:4172:4172:Eugene Kim (PBS Parents consultant):/home/ekim:/bin/bash
- lcraciun:x:4173:4173::/home/lcraciun:/bin/bash
- mstuparu:x:4174:4174::/home/mstuparu:/bin/bash
- Fuck Frontline. Free Bradley Manning.
- And to everyone else:
- UMADBRO:D
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement