ignore security and it'll go away

killmod-0.69.lsm

killmod-0.69.lsm
Posted Aug 17, 1999

LSM to kill modems using +++ATH0.

tags | exploit
MD5 | 6895d48a24ea72ea15c1462e580b2c97

killmod-0.69.lsm

Change Mirror Download
killmod-0.69

killmod.php3 is a php front end that calls a simple shell script (killmod.sh) and allows
you to use the +++ath0 bug to hang up older modems.
------------------------------------------------------------------------------------------------
killmod-0.69.tar.gz contains:

---
README
killmod.php3
killmod.sh
killmod.results
bitch.txt
stupid-bitch.txt
---

HISTORY:

This originally was a project started by me (jigz) because I had created a lame shell
script that just would ping with the `+++ATH0' pattern. I was too lazy to type "ping -p
2b2b2b415448300d [target]", so I made the script so I could just "killmod [target]". Then I
discovered PHP and made a lame PHP document that called the lame script, so I could do it
from a website. Everything was fine until my friend monkey decided to try and exploit it. I
figured it would be very unlikely. But due to the poorly written shell script, submitting
the proper hex characters to the form (something like `;cat /etc/passwd') would run and
print whatever was after the ";" and effectively pissed me off. After I discovered his
wrongdoing and he discovered I had backdoored him, we signed a full disclosure treaty,
which has worked out for the better. We worked together to create this PHP document that
effectively weeds out all the nasty characters ( ; | < > & ). Monkey did the PHP coding,
and I modified it to look pretty and added a few things.

USAGE:

In order to use this, you must have the Apache PHP module or the PHP binary installed. We
both have the Apache module, so we haven't tested it with the binary. I imagine it works
just fine, and you'll just need to edit the files more to get it to work.

These files are very very customizable, and you'll have to change some things in
`killmod.php3' depending on where you place your files.

Our recommendation would be to place everything but `killmod.php3' in a directory one level
up from site root, or in a directory that won't or can't be viewed, just for security
reasons. Just make sure to edit `killmod.php3' to reflect those changes.

NOTE: Make sure that killmod.results is chmod 666.

-rw-rw-r-- 1 root root 309 Jun 27 03:28 bitch.txt
-rw-rw-r-- 1 root root 2582 Jun 27 03:28 killmod.php3
-rw-rw-rw- 1 root root 203 Jun 27 03:29 killmod.results
-rwxr-xr-x 1 root root 276 Jun 27 03:29 killmod.sh
-rw-rw-r-- 1 root root 312 Jun 27 03:28 stupid-bitch.txt

There's so many things that could be optimized about this, but things work fine with the
current configuration for us. Hopefully things are pretty secure.

CONTACT:

Our stupid boxes haven't been added to a major DNS yet, so you'd just get your mail sent
back to you. You can try and mail us directly, but it may not work.

Jigz -- root@matrix.romeocomp.com or lewinsky@mailexcite.com
Monkey -- root@elmono.romeocomp.com or sonofabitch@mailexcite.com

Perhaps next time we'll use passthru() for way cleaner output.

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close