Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Ingreslock backdoor vulnerability

Shulou Source: shulou.com Published: 2022-06-01 06:35:05 10月03日 Update

Use the telnet command to connect port 1524 of the target host and directly obtain root permissions.

The Ingreslock backdoor listens on port 1524, and connects to port 1524 to gain root permissions, which is often used on an exposed server.

First, use nmap tools to scan the target host

1.1 scan the target host using the nmap command. Click in the space on the desktop, right-click the menu and choose Open in Terminal.

1.2 enter the command "nmap-sV 192.168.1.3" in the terminal, scan the port of the target host and find that port 1524 is open.

1.3 enter the command "telnet 192.168.1.3 1524" in the terminal to connect port 1524 of the target host. First, the connection is successful. As shown in figure 3

1.4 enter the command "whoami" in the terminal to find the permissions you have obtained. As shown in figure 4

1.5 enter the command "ifconfig eth0" in the terminal to view the network card information, enter "cat / etc/passwd" under the terminal, and view the password file of the remote host.

Tags: Host command port terminal target input permissions such as figure backdoor success information password tools files server desktop program blank network card menu Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno NVidia Xiaomi Shulou Tech Info Linux MariaDB