{"id":40,"date":"2015-12-18T01:29:19","date_gmt":"2015-12-17T16:29:19","guid":{"rendered":"http:\/\/csirt.ninja\/?p=40"},"modified":"2015-12-26T02:12:38","modified_gmt":"2015-12-25T17:12:38","slug":"ssh%e3%83%8f%e3%83%8b%e3%83%bc%e3%83%9d%e3%83%83%e3%83%88%e3%81%abmr-black","status":"publish","type":"post","link":"https:\/\/csirt.ninja\/?p=40","title":{"rendered":"SSH\u30cf\u30cb\u30fc\u30dd\u30c3\u30c8\u306bMr.Black"},"content":{"rendered":"<p>\u30dc\u30af\u306eSSH\u30cf\u30cb\u30fc\u30dd\u30c3\u30c8\u306e\u30ed\u30b0\u3092\u898b\u308b\u3068\u30ed\u30b0\u30a4\u30f3\u3057\u305f\u5f8c<br \/>\nwget\u30b3\u30de\u30f3\u30c9\u3067\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u305f\u30d5\u30a1\u30a4\u30eb\u304c\u7f6e\u3044\u3066\u3044\u304b\u308c\u3066\u3044\u307e\u3057\u305f\u3002<br \/>\nwget\u5148\u306b\u30d6\u30e9\u30a6\u30b6\u3067\u30a2\u30af\u30bb\u30b9\u3057\u3066\u307f\u308b\u3068\u30d5\u30a1\u30a4\u30eb\u7f6e\u304d\u5834\u306b\u306a\u3063\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<p>\u305d\u308c\u305e\u308c\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057[file]\u30b3\u30de\u30f3\u30c9\u3067\u78ba\u8a8d\u3059\u308b\u3068\u5f53\u305f\u308a\u524d\u3067\u3059\u304cLinux\u30d0\u30a4\u30ca\u30ea\u306e\u3088\u3046\u3067\u3059\u3002<\/p>\n<blockquote><p>$ file .\/*<br \/>\n.\/Linux2.4: ELF 32-bit LSB executable, Intel 80386, version 1 (GNU\/Linux), statically linked, stripped<br \/>\n.\/Linux2.4_2: ELF 32-bit LSB executable, Intel 80386, version 1 (GNU\/Linux), statically linked, stripped<br \/>\n.\/Linux2.6: ELF 32-bit LSB executable, Intel 80386, version 1 (GNU\/Linux), statically linked, stripped<br \/>\n.\/Linux2.6_2: ELF 32-bit LSB executable, Intel 80386, version 1 (GNU\/Linux), statically linked, stripped<br \/>\n.\/dd-wrt: ELF 32-bit MSB executable, MIPS, MIPS32 rel2 version 1 (SYSV), statically linked, stripped<br \/>\n.\/dd-wrt_2: ELF 32-bit MSB executable, MIPS, MIPS32 rel2 version 1 (SYSV), statically linked, stripped<br \/>\n.\/linux-arm: ELF 32-bit LSB executable, ARM, version 1 (GNU\/Linux), statically linked, stripped<br \/>\n.\/linux-arm_2: ELF 32-bit LSB executable, ARM, version 1 (GNU\/Linux), statically linked, stripped<br \/>\n.\/linux-mips: ELF 32-bit LSB executable, MIPS, MIPS32 rel2 version 1 (SYSV), statically linked, stripped<br \/>\n.\/linux-mips_2: ELF 32-bit LSB executable, MIPS, MIPS32 rel2 version 1 (SYSV), statically linked, stripped<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<p>\u305d\u308c\u305e\u308c\u306e\u30d5\u30a1\u30a4\u30eb\u3092[VirusTotal]\u3067\u30b9\u30ad\u30e3\u30f3\u3057\u305f\u7d50\u679c\u3068\u30cf\u30c3\u30b7\u30e5\u5024\u306f\u4ee5\u4e0b\u306e\u901a\u308a\u3067\u3059\u3002<\/p>\n<table style=\"border-color: #ffffff;\" border=\"1\">\n<tbody>\n<tr>\n<td>\u30d5\u30a1\u30a4\u30eb\u540d\uff08VT\u7d50\u679c\uff09<\/td>\n<td>\u30cf\u30c3\u30b7\u30e5\u5024(MD5 \/SHA1)<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/www.virustotal.com\/ja\/file\/5364b6b79a32be3b7be5aaf8f919696ab52a90e033613262b2ed8c1a32d99af8\/analysis\/\" target=\"_blank\">Linux2.4<\/a><\/td>\n<td>574e475db2b5a904b358e2c1a1536fb2<br \/>\n845721f7cc7e3dc87da79d089c007c63c555e7f9<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/www.virustotal.com\/ja\/file\/7bdd3068525b292b1e0d6ca999cdb37a473d46eb50ccab69ef2e529ae9c67001\/analysis\/1450362618\/\" target=\"_blank\">Linux2.4_2<\/a><\/td>\n<td>c16df0c510157e78b66d44663adc6ae0<br \/>\n0e8b6dcda8b05ca227fe728a659808058fe1cbf7<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/www.virustotal.com\/ja\/file\/547cc8517d4831f4691a940abf2a27b356972dd60486223afc2f79c19dda06c3\/analysis\/1450362748\/\" target=\"_blank\">Linux2.6<\/a><\/td>\n<td>33a157419a57def7ccb451809f82d935<br \/>\n330a06c3834d55552be72aaea2dbe2734d5afbd2<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/www.virustotal.com\/ja\/file\/2db1f1ad0c54a0ade739d979e455821f223866b7a8014b724eec8a0a623a6126\/analysis\/1450362811\/\" target=\"_blank\">Linux2.6_2<\/a><\/td>\n<td>0bfbbb2837b4b754f8a3a5a1e5454c6e<br \/>\n46395b49fddb9cf8ecd5900441c46eefa1c6faed<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/www.virustotal.com\/ja\/file\/1f5e0be81b7910488e2c70149afbe283acb77340ef16839c7364c09a9040248d\/analysis\/1450361517\/\" target=\"_blank\">dd-wrt<\/a><\/td>\n<td>7ee865e243393ab8279306b1a322e3f3<br \/>\nacdaba77bd907ecb1d5d12625c2c8de0e3995c9f<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/www.virustotal.com\/ja\/file\/b6e50b1ff794142a2f61ec7b797424f97c6589db39574ead1662195cc8972a68\/analysis\/1450361848\/\" target=\"_blank\">dd-wrt_2<\/a><\/td>\n<td>46b8ed7e8deba0a666897000c2ddc849<br \/>\n5c87eb4e8722746c7bfa1183c2286a5241d6b64e<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/www.virustotal.com\/ja\/file\/87e2950ee464dd6300afdf006cee4350cb59acc3a5235fd3dd75e4cd0cfed7b3\/analysis\/1450361981\/\" target=\"_blank\">linux-ar<\/a><\/td>\n<td>2413b41ec014648c198f1255fabd8d16<br \/>\ne2a25a639224cde972d167b80fa29a9d1342a8dc<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/www.virustotal.com\/ja\/file\/8ebe0cbead8ac335dc4d4980a7c9c1bbb1e4e7756ab71fc5c1a86da887519117\/analysis\/1450362272\/\" target=\"_blank\">linux-arm_2<\/a><\/td>\n<td>b5173030920796f5461a055c748f2f46<br \/>\nc439dc7f4681405564129a73fbd56cdd77a53e48<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/www.virustotal.com\/ja\/file\/0ea0d7751fe5b4a924f276db6a889852da9555dc716e7da55817477e95c3fba4\/analysis\/1450362410\/\" target=\"_blank\">linux-mips<\/a><\/td>\n<td>a29f39c5366b65ceadc3e77ca3cd5023<br \/>\n6b72196f9227c696c0e66a23427efe9af7646ae9<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/www.virustotal.com\/ja\/file\/1469ec06caef3b94a492b15908cb6bbe22c2ac1d7d3bb2a067c15a4ee6f10bf4\/analysis\/1450362306\/\" target=\"_blank\">linux-mips_2<\/a><\/td>\n<td>396e0c26ae1ffb914fa87211f8c9c102<br \/>\na7cb86afa1b034da5641b149416322786d842a3d<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><a href=\"http:\/\/japan.zdnet.com\/article\/35064561\/\" target=\"_blank\">\u3053\u3061\u3089\u306e\u8a18\u4e8b<\/a>\u306b\u3088\u308b\u3068\u3001\u305d\u308c\u305e\u308c\u306e\u30d5\u30a1\u30a4\u30eb\u306f\u69d8\u3005\u306a\u30a2\u30fc\u30ad\u30c6\u30af\u30c1\u30e3\u5225\u306b\u7528\u610f\u3055\u308c\u305f\u300cMr.Black\u300d\u3068\u547c\u3070\u308c\u308b\u30de\u30eb\u30a6\u30a7\u30a2\u3067<br \/>\nDDoS\u3092\u884c\u3046\u305f\u3081\u306e\u30dc\u30c3\u30c8\u30cd\u30c3\u30c8\u3092\u5f62\u6210\u3059\u308b\u305f\u3081\u306b\u5e83\u3081\u3089\u308c\u308b\u3082\u306e\u306e\u3088\u3046\u3067\u3059\u3002<br \/>\n\u307e\u305f\u3001\u904e\u53bb\u306b\u306f\u30c7\u30d5\u30a9\u30eb\u30c8\u306e\u8a8d\u8a3c\u60c5\u5831\u3092\u7528\u3044\u3066\u4fb5\u5165\u53ef\u80fd\u306a\u30eb\u30fc\u30bf\u306b\u611f\u67d3\u3057\u3066\u305f\u4e8b\u4f8b\u304c\u3042\u3063\u305f\u3088\u3046\u3067\u3059\u3002<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u30dc\u30af\u306eSSH\u30cf\u30cb\u30fc\u30dd\u30c3\u30c8\u306e\u30ed\u30b0\u3092\u898b\u308b\u3068\u30ed\u30b0\u30a4\u30f3\u3057\u305f\u5f8c wget\u30b3\u30de\u30f3\u30c9\u3067\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u305f\u30d5\u30a1\u30a4\u30eb\u304c\u7f6e\u3044\u3066\u3044\u304b\u308c\u3066\u3044\u307e\u3057\u305f\u3002 wget\u5148\u306b\u30d6\u30e9\u30a6\u30b6\u3067\u30a2\u30af\u30bb\u30b9\u3057\u3066\u307f\u308b\u3068\u30d5\u30a1\u30a4\u30eb\u7f6e\u304d\u5834\u306b\u306a\u3063\u3066\u3044\u307e\u3057\u305f\u3002 \u305d\u308c\u305e\u308c\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":61,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"views":5874,"_links":{"self":[{"href":"https:\/\/csirt.ninja\/index.php?rest_route=\/wp\/v2\/posts\/40"}],"collection":[{"href":"https:\/\/csirt.ninja\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/csirt.ninja\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/csirt.ninja\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/csirt.ninja\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=40"}],"version-history":[{"count":19,"href":"https:\/\/csirt.ninja\/index.php?rest_route=\/wp\/v2\/posts\/40\/revisions"}],"predecessor-version":[{"id":60,"href":"https:\/\/csirt.ninja\/index.php?rest_route=\/wp\/v2\/posts\/40\/revisions\/60"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/csirt.ninja\/index.php?rest_route=\/wp\/v2\/media\/61"}],"wp:attachment":[{"href":"https:\/\/csirt.ninja\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=40"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/csirt.ninja\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=40"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/csirt.ninja\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=40"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}