Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 28 guests and 1 member online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow Assistance please
EH-Net
May 24, 2013, 03:51:57 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1] 2   Go Down
  Print  
Author Topic: Assistance please  (Read 12250 times)
0 Members and 1 Guest are viewing this topic.
odius1
Newbie
*
Offline Offline

Posts: 5


View Profile
« on: April 18, 2008, 02:39:04 PM »

I recently got my CEH cirtifcation and I'm on a penetratin test for a big company. While I was learning I watched quite a few videos to build my skills.

What does Rm -rf / do?

On this penetration test I was able to get access with help from the CEH book and mentioned tools, but now the system isn't responding to anything?!?

Please help. Did the system administrator see my activity and patch the exploit?
Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4168


Editor-In-Chief


View Profile WWW
« Reply #1 on: April 18, 2008, 03:01:23 PM »

First of all, go to a shell and type man rm

rm is the remove command. Here are the switches you mention:

-r Recursively remove directories and subdirectories in the argument list.
-f Remove all files (whether write-protected or not) in a directory without prompting the user.

Since everything in Linux is a file, this could really hose up a system.

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4168


Editor-In-Chief


View Profile WWW
« Reply #2 on: April 18, 2008, 03:03:55 PM »

Of course, if you are asking this after just passing your CEH and already on a live pen test... this sounds like horrible news for your client.

Do you have permission on this network with a contract of some sort? Hopefully they put a scope on the project so that you and they both would know not to do something that destructive.

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
odius1
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #3 on: April 18, 2008, 03:07:37 PM »

when I type man rm I get
"'man' is not recognized as an internal or external command, operable program or batch file."

Do think the system not responding could be my fault or did the administrator patch the exploit?

I didn't get a letter from the network.  I email them and asked if they wanted a penetration test, then I find the exploit.
Logged
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« Reply #4 on: April 18, 2008, 03:26:26 PM »

Of course, if you are asking this after just passing your CEH and already on a live pen test... this sounds like horrible news for your client.

lol...

Do think the system not responding could be my fault or did the administrator patch the exploit?

'man' is not an exploit.. it was not patched. I honestly don't know how you got this far (is it really possible to pass the CEH without knowing what 'rm -rf' does?), but I would suggest contacting your client if you just ran that command and now the system is unresponsive....

edit: Sorry, forgot to mention.. in the event a system goes down like you've mentioned during a test, it's usually written in your papers to call your contact
« Last Edit: April 18, 2008, 03:30:10 PM by BillV » Logged
odius1
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #5 on: April 18, 2008, 03:30:43 PM »

I did not see "rm" on my examination for CEH. From the video I was thought that it was a privelage escalation. I am worried to tell my boss because I do not want to be fired. This is my first security job after CEH training and test.

Who should I contact about this server? I can not get to the web site contacts. The web server ecommerce is down and can not get to contacts page.
Logged
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« Reply #6 on: April 18, 2008, 03:33:08 PM »

I don't know the scope of your engagement, what you're testing, etc.

That in mind, I would suggest first contacting your boss and letting him/her know that one of the target systems has become unresponsive, and you think it's possibly due to what you have done.

Hopefully he/she will know where to go from there.
Logged
rance
Full Member
***
Offline Offline

Posts: 212


<censored>


View Profile
« Reply #7 on: April 18, 2008, 03:45:39 PM »

Not to rehash anything that anyone has said, but I don't know if it's clearly been stated, but the command rm -rf / *will* attempt to erase every file on the server, without confirmation.

If you had the privlege to run the "rm" command, and it took, then chances are pretty high that you completely toasted their server.

And not to sound like a jerk, but if you're running around on servers (that you don't own or manage) executing commands you don't know about at will, you should probably take a step back from a penetration specialist role and get some more basic experience under your belt.
Logged

Poking at security since 1986.  +++ATH
odius1
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #8 on: April 18, 2008, 03:49:56 PM »

Bill I can not get in contact with my boss. I am the technical lead on this and when I called back to the company he was out.. They told me to call his wife if I needed to get in contact wtih him. When I did she responded hardly because he had just served her with divorce papers. Should I contact his boss? This is onlymy secod week at this job and I don't wan tto look bad.
Logged
odius1
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #9 on: April 18, 2008, 03:51:41 PM »

Rance I thought deltree was the command to do that?

I have experience from the CEH course and exam. The company said I did the best on the interview fo all the candidates.
Logged
rance
Full Member
***
Offline Offline

Posts: 212


<censored>


View Profile
« Reply #10 on: April 18, 2008, 03:59:37 PM »

Rance I thought deltree was the command to do that?

I have experience from the CEH course and exam. The company said I did the best on the interview fo all the candidates.

deltree is a windows command, rm is a linux/unix command.  Lack of basic file manipulation command knowledge says you're out of your league.  And just because you can pass an exam doesn't necessarily mean you're qualified.  I mean, you admittedly executed a command you have *no* knowledge about... that's a huge no-no, even just in every-day computing.  That's how viruses start propagating, and rootkis get installed. 

I'm sorry, I don't want to be harsh, but I wouldn't plan on holding this job of yours for too long.  Doing something like this is going to show pretty blatant incompetence, and I'd bet a paycheck or two that your boss is going to quickly realize that you're not the best qualified candidate they interviewed.

Again, sorry to be so harsh, but reality is what it is.
Logged

Poking at security since 1986.  +++ATH
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4168


Editor-In-Chief


View Profile WWW
« Reply #11 on: April 18, 2008, 04:20:37 PM »

You mention that you watched some videos, so if you simply type "rm -rf /" with the quotation marks into Google, you'll see several videos showing exactly how this will hose a system. You had to have known.

So, not to be a doubter, but are you pulling our collective leg?

Don
« Last Edit: April 19, 2008, 10:31:21 AM by don » Logged

CISSP, MCSE, CSTA, Security+ SME
LSOChris
Guest
« Reply #12 on: April 18, 2008, 04:27:09 PM »

if you are the tech lead and you did that, you need to be fired right now. pack your crap go home, get a new job. give the client a BIG apology.
Logged
geekyone
Full Member
***
Offline Offline

Posts: 180



View Profile
« Reply #13 on: April 18, 2008, 08:52:13 PM »

Hmmm... sounds like a joke to me.  If not I have to be honest I agree with ChrisG.  You don't by any chance read BOFH (Bastard Operator from Hell) do you?  Cause that is a favorite command of Simon's. LOL!
Logged

CISSP, CEH, GPEN, GCIH, GCFA
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« Reply #14 on: April 18, 2008, 09:48:01 PM »

if you are the tech lead and you did that, you need to be fired right now. pack your crap go home, get a new job. give the client a BIG apology.

lol... yup, in essence this is what I was alluding too, just didn't want to come out and say it Grin well stated
Logged
Pages: [1] 2   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.071 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.