Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 29 guests and 2 members online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow Assistance please
Ethical Hacker Community Forums
November 21, 2008, 08:06:50 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1] 2   Go Down
  Print  
Author Topic: Assistance please  (Read 4682 times)
0 Members and 1 Guest are viewing this topic.
odius1
Newbie
*
Offline Offline

Posts: 5


View Profile
« on: April 18, 2008, 02:39:04 PM »

I recently got my CEH cirtifcation and I'm on a penetratin test for a big company. While I was learning I watched quite a few videos to build my skills.

What does Rm -rf / do?

On this penetration test I was able to get access with help from the CEH book and mentioned tools, but now the system isn't responding to anything?!?

Please help. Did the system administrator see my activity and patch the exploit?
Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2347


Editor-In-Chief


View Profile WWW
« Reply #1 on: April 18, 2008, 03:01:23 PM »

First of all, go to a shell and type man rm

rm is the remove command. Here are the switches you mention:

-r Recursively remove directories and subdirectories in the argument list.
-f Remove all files (whether write-protected or not) in a directory without prompting the user.

Since everything in Linux is a file, this could really hose up a system.

Don
Logged

CISSP, MCSE, CEH, Security+ SME
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2347


Editor-In-Chief


View Profile WWW
« Reply #2 on: April 18, 2008, 03:03:55 PM »

Of course, if you are asking this after just passing your CEH and already on a live pen test... this sounds like horrible news for your client.

Do you have permission on this network with a contract of some sort? Hopefully they put a scope on the project so that you and they both would know not to do something that destructive.

Don
Logged

CISSP, MCSE, CEH, Security+ SME
odius1
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #3 on: April 18, 2008, 03:07:37 PM »

when I type man rm I get
"'man' is not recognized as an internal or external command, operable program or batch file."

Do think the system not responding could be my fault or did the administrator patch the exploit?

I didn't get a letter from the network.  I email them and asked if they wanted a penetration test, then I find the exploit.
Logged
BillV
Hero Member
*****
Offline Offline

Posts: 862


View Profile
« Reply #4 on: April 18, 2008, 03:26:26 PM »

Of course, if you are asking this after just passing your CEH and already on a live pen test... this sounds like horrible news for your client.

lol...

Do think the system not responding could be my fault or did the administrator patch the exploit?

'man' is not an exploit.. it was not patched. I honestly don't know how you got this far (is it really possible to pass the CEH without knowing what 'rm -rf' does?), but I would suggest contacting your client if you just ran that command and now the system is unresponsive....

edit: Sorry, forgot to mention.. in the event a system goes down like you've mentioned during a test, it's usually written in your papers to call your contact
« Last Edit: April 18, 2008, 03:30:10 PM by BillV » Logged
odius1
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #5 on: April 18, 2008, 03:30:43 PM »

I did not see "rm" on my examination for CEH. From the video I was thought that it was a privelage escalation. I am worried to tell my boss because I do not want to be fired. This is my first security job after CEH training and test.

Who should I contact about this server? I can not get to the web site contacts. The web server ecommerce is down and can not get to contacts page.
Logged
BillV
Hero Member
*****
Offline Offline

Posts: 862


View Profile
« Reply #6 on: April 18, 2008, 03:33:08 PM »

I don't know the scope of your engagement, what you're testing, etc.

That in mind, I would suggest first contacting your boss and letting him/her know that one of the target systems has become unresponsive, and you think it's possibly due to what you have done.

Hopefully he/she will know where to go from there.
Logged
rance
Jr. Member
**
Offline Offline

Posts: 60


<censored>


View Profile
« Reply #7 on: April 18, 2008, 03:45:39 PM »

Not to rehash anything that anyone has said, but I don't know if it's clearly been stated, but the command rm -rf / *will* attempt to erase every file on the server, without confirmation.

If you had the privlege to run the "rm" command, and it took, then chances are pretty high that you completely toasted their server.

And not to sound like a jerk, but if you're running around on servers (that you don't own or manage) executing commands you don't know about at will, you should probably take a step back from a penetration specialist role and get some more basic experience under your belt.
Logged

I use my powers for good, and not for evil... now.
odius1
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #8 on: April 18, 2008, 03:49:56 PM »

Bill I can not get in contact with my boss. I am the technical lead on this and when I called back to the company he was out.. They told me to call his wife if I needed to get in contact wtih him. When I did she responded hardly because he had just served her with divorce papers. Should I contact his boss? This is onlymy secod week at this job and I don't wan tto look bad.
Logged
odius1
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #9 on: April 18, 2008, 03:51:41 PM »

Rance I thought deltree was the command to do that?

I have experience from the CEH course and exam. The company said I did the best on the interview fo all the candidates.
Logged
rance
Jr. Member
**
Offline Offline

Posts: 60


<censored>


View Profile
« Reply #10 on: April 18, 2008, 03:59:37 PM »

Rance I thought deltree was the command to do that?

I have experience from the CEH course and exam. The company said I did the best on the interview fo all the candidates.

deltree is a windows command, rm is a linux/unix command.  Lack of basic file manipulation command knowledge says you're out of your league.  And just because you can pass an exam doesn't necessarily mean you're qualified.  I mean, you admittedly executed a command you have *no* knowledge about... that's a huge no-no, even just in every-day computing.  That's how viruses start propagating, and rootkis get installed. 

I'm sorry, I don't want to be harsh, but I wouldn't plan on holding this job of yours for too long.  Doing something like this is going to show pretty blatant incompetence, and I'd bet a paycheck or two that your boss is going to quickly realize that you're not the best qualified candidate they interviewed.

Again, sorry to be so harsh, but reality is what it is.
Logged

I use my powers for good, and not for evil... now.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2347


Editor-In-Chief


View Profile WWW
« Reply #11 on: April 18, 2008, 04:20:37 PM »

You mention that you watched some videos, so if you simply type "rm -rf /" with the quotation marks into Google, you'll see several videos showing exactly how this will hose a system. You had to have known.

So, not to be a doubter, but are you pulling our collective leg?

Don
« Last Edit: April 19, 2008, 10:31:21 AM by don » Logged

CISSP, MCSE, CEH, Security+ SME
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1037


View Profile WWW
« Reply #12 on: April 18, 2008, 04:27:09 PM »

if you are the tech lead and you did that, you need to be fired right now. pack your crap go home, get a new job. give the client a BIG apology.
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
geekyone
Full Member
***
Offline Offline

Posts: 119



View Profile
« Reply #13 on: April 18, 2008, 08:52:13 PM »

Hmmm... sounds like a joke to me.  If not I have to be honest I agree with ChrisG.  You don't by any chance read BOFH (Bastard Operator from Hell) do you?  Cause that is a favorite command of Simon's. LOL!
Logged
BillV
Hero Member
*****
Offline Offline

Posts: 862


View Profile
« Reply #14 on: April 18, 2008, 09:48:01 PM »

if you are the tech lead and you did that, you need to be fired right now. pack your crap go home, get a new job. give the client a BIG apology.

lol... yup, in essence this is what I was alluding too, just didn't want to come out and say it Grin well stated
Logged
Pages: [1] 2   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.048 seconds with 24 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.