Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 28 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
Assistance please
EH-Net
May 24, 2013, 03:51:57 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
Assistance please
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: Assistance please (Read 12250 times)
0 Members and 1 Guest are viewing this topic.
odius1
Newbie
Offline
Posts: 5
Assistance please
«
on:
April 18, 2008, 02:39:04 PM »
I recently got my CEH cirtifcation and I'm on a penetratin test for a big company. While I was learning I watched quite a few videos to build my skills.
What does Rm -rf / do?
On this penetration test I was able to get access with help from the CEH book and mentioned tools, but now the system isn't responding to anything?!?
Please help. Did the system administrator see my activity and patch the exploit?
Logged
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4168
Editor-In-Chief
Re: Assistance please
«
Reply #1 on:
April 18, 2008, 03:01:23 PM »
First of all, go to a shell and type man rm
rm is the remove command. Here are the switches you mention:
-r Recursively remove directories and subdirectories in the argument list.
-f Remove all files (whether write-protected or not) in a directory without prompting the user.
Since everything in Linux is a file, this could really hose up a system.
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4168
Editor-In-Chief
Re: Assistance please
«
Reply #2 on:
April 18, 2008, 03:03:55 PM »
Of course, if you are asking this after just passing your CEH and already on a live pen test... this sounds like horrible news for your client.
Do you have permission on this network with a contract of some sort? Hopefully they put a scope on the project so that you and they both would know not to do something that destructive.
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
odius1
Newbie
Offline
Posts: 5
Re: Assistance please
«
Reply #3 on:
April 18, 2008, 03:07:37 PM »
when I type man rm I get
"'man' is not recognized as an internal or external command, operable program or batch file."
Do think the system not responding could be my fault or did the administrator patch the exploit?
I didn't get a letter from the network. I email them and asked if they wanted a penetration test, then I find the exploit.
Logged
BillV
Hero Member
Offline
Posts: 1892
Re: Assistance please
«
Reply #4 on:
April 18, 2008, 03:26:26 PM »
Quote from: don on April 18, 2008, 03:03:55 PM
Of course, if you are asking this after just passing your CEH and already on a live pen test...
this sounds like horrible news for your client.
lol...
Quote from: odius1 on April 18, 2008, 03:07:37 PM
Do think the system not responding could be my fault or did the administrator patch the exploit?
'man' is not an exploit.. it was not patched. I honestly don't know how you got this far (is it really possible to pass the CEH without knowing what 'rm -rf' does?), but I would suggest contacting your client if you just ran that command and now the system is unresponsive....
edit: Sorry, forgot to mention.. in the event a system goes down like you've mentioned during a test, it's usually written in your papers to call your contact
«
Last Edit: April 18, 2008, 03:30:10 PM by BillV
»
Logged
odius1
Newbie
Offline
Posts: 5
Re: Assistance please
«
Reply #5 on:
April 18, 2008, 03:30:43 PM »
I did not see "rm" on my examination for CEH. From the video I was thought that it was a privelage escalation. I am worried to tell my boss because I do not want to be fired. This is my first security job after CEH training and test.
Who should I contact about this server? I can not get to the web site contacts. The web server ecommerce is down and can not get to contacts page.
Logged
BillV
Hero Member
Offline
Posts: 1892
Re: Assistance please
«
Reply #6 on:
April 18, 2008, 03:33:08 PM »
I don't know the scope of your engagement, what you're testing, etc.
That in mind, I would suggest first contacting your boss and letting him/her know that one of the target systems has become unresponsive, and you think it's possibly due to what you have done.
Hopefully he/she will know where to go from there.
Logged
rance
Full Member
Offline
Posts: 212
<censored>
Re: Assistance please
«
Reply #7 on:
April 18, 2008, 03:45:39 PM »
Not to rehash anything that anyone has said, but I don't know if it's clearly been stated, but the command
rm -rf /
*will* attempt to erase every file on the server, without confirmation.
If you had the privlege to run the "rm" command, and it took, then chances are pretty high that you completely toasted their server.
And not to sound like a jerk, but if you're running around on servers (that you don't own or manage) executing commands you don't know about at will, you should probably take a step back from a penetration specialist role and get some more basic experience under your belt.
Logged
Poking at security since 1986. +++ATH
odius1
Newbie
Offline
Posts: 5
Re: Assistance please
«
Reply #8 on:
April 18, 2008, 03:49:56 PM »
Bill I can not get in contact with my boss. I am the technical lead on this and when I called back to the company he was out.. They told me to call his wife if I needed to get in contact wtih him. When I did she responded hardly because he had just served her with divorce papers. Should I contact his boss? This is onlymy secod week at this job and I don't wan tto look bad.
Logged
odius1
Newbie
Offline
Posts: 5
Re: Assistance please
«
Reply #9 on:
April 18, 2008, 03:51:41 PM »
Rance I thought deltree was the command to do that?
I have experience from the CEH course and exam. The company said I did the best on the interview fo all the candidates.
Logged
rance
Full Member
Offline
Posts: 212
<censored>
Re: Assistance please
«
Reply #10 on:
April 18, 2008, 03:59:37 PM »
Quote from: odius1 on April 18, 2008, 03:51:41 PM
Rance I thought deltree was the command to do that?
I have experience from the CEH course and exam. The company said I did the best on the interview fo all the candidates.
deltree is a windows command, rm is a linux/unix command. Lack of basic file manipulation command knowledge says you're out of your league. And just because you can pass an exam doesn't necessarily mean you're qualified. I mean, you admittedly executed a command you have *no* knowledge about... that's a huge no-no, even just in every-day computing. That's how viruses start propagating, and rootkis get installed.
I'm sorry, I don't want to be harsh, but I wouldn't plan on holding this job of yours for too long. Doing something like this is going to show pretty blatant incompetence, and I'd bet a paycheck or two that your boss is going to quickly realize that you're not the best qualified candidate they interviewed.
Again, sorry to be so harsh, but reality is what it is.
Logged
Poking at security since 1986. +++ATH
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4168
Editor-In-Chief
Re: Assistance please
«
Reply #11 on:
April 18, 2008, 04:20:37 PM »
You mention that you watched some videos, so if you simply type "rm -rf /" with the quotation marks into Google, you'll see several videos showing exactly how this will hose a system. You had to have known.
So, not to be a doubter, but are you pulling our collective leg?
Don
«
Last Edit: April 19, 2008, 10:31:21 AM by don
»
Logged
CISSP, MCSE, CSTA, Security+ SME
LSOChris
Guest
Re: Assistance please
«
Reply #12 on:
April 18, 2008, 04:27:09 PM »
if you are the tech lead and you did that, you need to be fired right now. pack your crap go home, get a new job. give the client a BIG apology.
Logged
geekyone
Full Member
Offline
Posts: 180
Re: Assistance please
«
Reply #13 on:
April 18, 2008, 08:52:13 PM »
Hmmm... sounds like a joke to me. If not I have to be honest I agree with ChrisG. You don't by any chance read BOFH (Bastard Operator from Hell) do you? Cause that is a favorite command of Simon's. LOL!
Logged
CISSP, CEH, GPEN, GCIH, GCFA
BillV
Hero Member
Offline
Posts: 1892
Re: Assistance please
«
Reply #14 on:
April 18, 2008, 09:48:01 PM »
Quote from: ChrisG on April 18, 2008, 04:27:09 PM
if you are the tech lead and you did that, you need to be fired right now. pack your crap go home, get a new job. give the client a BIG apology.
lol... yup, in essence this is what I was alluding too, just didn't want to come out and say it
well stated
Logged
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: ÌÀÃÀÇÈÍ ÌÎÄÍÎÉ ÎÄÅÆÄÛ APPLE-FASHION!
(0) by
Infabeemace
News Items and General Discussion About EH-Net
: When your benjamin will be to your own car and truck clean up
(0) by
areluctes
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(8) by
ajohnson
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(29) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
Greetings
: Hi from the UK
(4) by
MrTuxracer
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.