乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2014-02-16: 细节已通知厂商并且等待厂商处理中 2014-02-16: 厂商已经确认,细节仅向厂商公开 2014-02-26: 细节向核心白帽子及相关领域专家公开 2014-03-08: 细节向普通白帽子公开 2014-03-18: 细节向实习白帽子公开 2014-04-02: 细节向公众公开
hard to dream。
http://files.sogou.com/.bash_history.bash_history保存了最近使用过的一些命令。
df -h#1366626326cd /search/nginx/script/#1366626331vi zabbix_ob.sh #1366626355./zabbix_ob.sh Req#1366669640unset LANG; lsb_release -a; uname -a; #1366756042unset LANG; lsb_release -a; uname -a; #1366770959w#1366770966clustat #1366771739clustat #1366771744nload #1366771825cd /search/nginx/logs/#1366771825ll#1366771838cd /search/nginx/logs/#1366771838ll#1366772145cd /search/nginx/logs#1366772146ll#1366772150ll | grep error#1366772154ll | grep error#1366772162nload#1366772192ps aux | grep nginx#1366772435ll#1366772444ll | grep news#1366772450ll | grep news#1366772457tail news#1366772464ll | grep error.log #1366772467cd history/nginx#1366772467ll#1366772481head error.log.2013042409#1366772494grep "news" error.log.2013042409#1366772513grep "news" error.log.2013042409 | grep "09:44"#1366772525grep "news" error.log.2013042409 | grep "09:44" | wc -l#1366772538grep "news" error.log.2013042409 | grep "09:44" | less#1366772555ll /usr/local/nginx/conf/vhosts/| grep news#1366772563grep "news.sogou.com" error.log.2013042409 | grep "09:44" | less#1366772594grep "news.sogou.com" error.log.2013042409 | grep "09:44" #1366772625grep "server: news.sogou.com" error.log.2013042409 | grep "09:4" #1366772627grep "server: news.sogou.com" error.log.2013042409 | grep "09:4" #1366842431unset LANG; lsb_release -a; uname -a; #1366854343cd /etc/cluster/#1366854344ll#1366854359vi cluster.conf #1366854428clear#1366854429pwd#1366854434clear#1366854436vi cluster.conf #1366854578sogou-host -a#1366854579clear#1366854581sogou-host #1366855885vi cluster.conf #1366875534cd /etc/cluster/#1366875566ll#1366875570vi cluster.conf #1366875576clear#1366875586cd /usr/lib/nagios/plugins/#1366875587ll#1366875613rsync [email protected]::search/sumiao/script/check_ilo ./#1366875638ll -rt#1366875648./check_ilo #1366875814clear#1366875821cd /etc/nagios/#1366875822ll#1366875823vi external_command.cfg #1366875847vi external_command.cfg #1366875961ll /usr/lib/nagios/plugins/check_ilo#1366876034service nrpe restart#1366878996cd /etc/cluster/#1366928852unset LANG; lsb_release -a; uname -a; #1366949921cd /usr/local/nginx/conf/vhosts/#1366949927vi proxy.sogou.com.conf #1366949959cd /search/nginx/html/#1366949960ll#1366949964cd VPN#1366949967ll [B#1366949971vi index.html#1366950063vi index.html#1366950077ll#1366950087mr -f vpn_for_*#1366950088LL#1366950090ll#1366950099rm -rf vpn_for_*#1366950100ll#1366950103rm -f SOGOU\ VPN配置手册.docx #1366950103ll#1366950106ll#1366950163ll#1366950165vi index.html #1366950237vi index.html #1366956323cd /search/nginx/logs/#1366956323ll#1366956326cd ../html/#1366956326ll#1366956330cd VPN#1366956330ll#1366956344rm -f index.html #1366957375rm -f SOGOU\ VPN配置手册.docx #1366957436ll#1366972024cd /usr/local/nginx/html/#1366972025ll#1366972037vi index.html #1366973652w#1366973652top#1366973802free#1366973816w#1366973818top#1366979561host cloud.pinyin.sogou.com#1366993458cd /usr/local/nginx/logs/#1366993459ll#1366993462cd history/prox#1366993464pwd#1366993472cd /usr/local/nginx/logs/history/proxy.sogou.com#1366993473ll#1366993506cat proxy.sogou.com_access_log* |> /search/`sogou-host|grep -v rsync`.log#1366993511cd /search/#1366993511ll#1366993519cd -#1366993526cat proxy.sogou.com_access_log* > /search/`sogou-host|grep -v rsync`.log#1366993529cd /search/#1366993530ll#1366993535less proxy07.ha.cnc.log #1366993541ll#1366993611rsync -avz *.log 10.12.143.107::search/odin/apache/test/#1366993637rm -f *.log#1366993638ll#1367101663unset LANG; lsb_release -a; uname -a; #1367188057unset LANG; lsb_release -a; uname -a; #1367274462unset LANG; lsb_release -a; uname -a; #1367336724unset LANG; lsb_release -a; uname -a; #1367360855unset LANG; lsb_release -a; uname -a; #1367387192unset LANG; lsb_release -a; uname -a; #1367395869unset LANG; lsb_release -a; uname -a; #1367447164unset LANG; lsb_release -a; uname -a; #1367533574unset LANG; lsb_release -a; uname -a; #1367619968unset LANG; lsb_release -a; uname -a; #1367706371unset LANG; lsb_release -a; uname -a; #1367792771unset LANG; lsb_release -a; uname -a; #1367824195clustat #1367824196nload #1367824354ll#1367824358cd /search/nginx/#1367824359ll#1367824366cd /usr/local/nginx/conf/vhosts/#1367824367ll#1367824368ll -rt#1367824374vi bobo.sogou.com.conf#1367824452/usr/local/nginx/sbin/nginx -t #1367824610service nginx reload#1367824630curl -H "Host: bobo.sogou.com" http://localhost/#1367824700curl -H "Host: bobo.sogou.com" http://localhost/#1367827572exit#1367879175unset LANG; lsb_release -a; uname -a; #1367831909curl -H "Host: search.waibao.sogou-inc.com" http://localhost/#1367898474sogou-host #1367922435cd /search/nginx/logs/#1367922435ll#1367922483cd /usr/local/nginx/conf/vhosts/#1367922484ll#1367922489rm -f waibao.sogou-inc.com.conf #1367922499/usr/local/nginx/sbin/nginx -t#1367965580unset LANG; lsb_release -a; uname -a; #1368052141unset LANG; lsb_release -a; uname -a; #1368138560unset LANG; lsb_release -a; uname -a; #1368224970unset LANG; lsb_release -a; uname -a; #1368311349unset LANG; lsb_release -a; uname -a; #1368397719unset LANG; lsb_release -a; uname -a; #1368484164unset LANG; lsb_release -a; uname -a; #1368513153cd /search/nginx/logs/#1368513153ll#1368513156cd history/#1368513157ll#1368513161cd sto#1368513161ll#1368513214ll st41*#1368513437clear#1368513470ll -rt#1368517945cd /search/nginx/logs#1368517953tail -f jobsogou| grep hr#1368517970tail -f jobsogou| grep "hr.sogou.com"#1368570546unset LANG; lsb_release -a; uname -a; #1368607620ping 10.132.3.2#1368656929unset LANG; lsb_release -a; uname -a; #1368678312cd /search/nginx/logs/#1368678326tail -f account.sogou.com_access_log #1368708197if id smarton > /dev/null ; then echo ok; setfacl -R -x u:smarton /var ; fi#1368717769cd /usr/local/nginx/conf/vhosts/#1368717770ll#1368717774cd /search/g#1368717776cd /search/nginx/#1368717777ll#1368717779cd logs/#1368717780ll#1368717783cat /etc/rc.local #1368717791cat /etc/passwd#1368743350unset LANG; lsb_release -a; uname -a; #1368761942cd /search/nginx/html/#1368761942ll#1368762182ll#1368762186rsync -avz apache01.profile.cnc.dt.nop.vm#1368762186apache02.profile.cnc.dt.nop.vm#1368762186apache01.profile.djt.dt.nop.vm#1368762187apache02.profile.djt.dt.nop.vm#1368762187apache03.profile.djt.dt.nop.vm#1368762187apache04.profile.djt.dt.nop.vm#1368762187apache05.profile.djt.dt.nop.vm#1368762189ll#1368762226rsync -avz rsync.repos01.cdn.djt::search/deploy/repos/cdn.sogou.com/* ./#1368762238ll#1368762273rm -rf monitor update test#1368762276ll#1368762288rm -f del_path_list#1368762291ll#1368829738unset LANG; lsb_release -a; uname -a; #1368916145unset LANG; lsb_release -a; uname -a; #1369002536unset LANG; lsb_release -a; uname -a; #1369013643w#1369013654curl localhost#1369013671top#1369013682cd /search/nginx/logs/#1369013683ll#1369013692ll -h error.log #1369013700> error.log #1369013703ll#1369013704cd history/#1369013705ll#1369013708cd nginx#1369013708ll#1369013711ll -h error.log.201305#1369013717ll -h error.log.201305*#1369013722cd ../#1369013723cd ..#1369013724ll#1369013725tail error.log #1369014670w#1369014685w#1369014688> error.log #1369015221> error.log #1369015225ll#1369015228cd history/nginx#1369015229ll#1369015242> error.log.2013052009#1369088965unset LANG; lsb_release -a; uname -a; #1369175340unset LANG; lsb_release -a; uname -a; #1369206655ip addr#1369231887df -h#1369231890w#1369231902cd /search/nginx/logs/#1369231902ll#1369231915cat status.proxy.sogou.com_access_log|grep nagios|less#1369261747unset LANG; lsb_release -a; uname -a; #1369277542sogou-host#1369304082ip addr |grep "115.25.216.36"#1369304088ip addr#1369304093clustat #1369347978unset LANG; lsb_release -a; uname -a; #1369434370unset LANG; lsb_release -a; uname -a; #1369520778unset LANG; lsb_release -a; uname -a; #1369607181unset LANG; lsb_release -a; uname -a; #1369693573unset LANG; lsb_release -a; uname -a; #1369725260cd /usr/local/nginx/conf/vhosts/#1369725261ll#1369779983unset LANG; lsb_release -a; uname -a; #1369866380unset LANG; lsb_release -a; uname -a; #1369952778unset LANG; lsb_release -a; uname -a; #1369971204cd /usr/local/nginx/sbin/#1369971205ll#1369971216rm -f spawn-php.sh#1369971217ll#1369973269df -h#1369976441ll#1369976452cp nginx nginx.20130531#1369976452ll#1369977465w#1369979644w#1369979655w#1369980466ll#1370039197unset LANG; lsb_release -a; uname -a; #1370125580unset LANG; lsb_release -a; uname -a; #1370211982unset LANG; lsb_release -a; uname -a; #1370254095w#1370254099w#1370254100w#1370254101top#1370254130curl localhost#1370254132curl localhost#1370254132curl localhost#1370254133curl localhost#1370254134curl localhost#1370254134curl localhost#1370254135w#1370254141free#1370254143top#1370277337cd /search/nginx/html/#1370277337ll#1370277354rsync -avz 10.12.133.3::search/nginx/html/* /search/nginx/html/#1370277360ll#1370277377ll#1370277380cat index.html #1370277389cat index.html #1370277404vi index.html #1370298388unset LANG; lsb_release -a; uname -a; #1370343560w#1370343563w#1370343563w#1370343565w#1370343570w#1370343571w#1370343572top#1370343582ps aux |grep nginx#1370343586curl localhost#1370343587curl localhost#1370343588curl localhost#1370343589curl localhost#1370343589curl localhost#1370343590curl localhost#1370343591curl localhost#1370343591curl localhost#1370343592curl localhost#1370343592curl localhost#1370343593curl localhost#1370343593curl localhost#1370343594curl localhost#1370343595w#1370343610w#1370343611w#1370343611w#1370343618iostat -kx 1#1370343625/search/nginx/script/zabbix_ob.sh Req#1370343631/search/nginx/script/zabbix_ob.sh Req#1370343642/search/nginx/script/zabbix_ob.sh Req#1370343644cd /search/nginx/logs/#1370343645ll#1370343648cd latest/#1370343648ll#1370343650ll#1370343654ll#1370343655ll#1370343656ll#1370343699w#1370343700w#1370384790unset LANG; lsb_release -a; uname -a; #1370418393cd /usr/local/nginx/sbin/#1370418393ll#1370418421yum clean all#1370418435cd /usr/local/nginx/c#1370418436cd /usr/local/nginx/#1370418437ll#1370418440mv conf conf.bak#1370418441ll#1370418446yum update nginx-sogou#1370418579ll#1370418583rm -rf conf#1370418589ll#1370418594mv conf.bak conf#1370418595ll#1370418599w#1370418602cd /search/nginx/data#1370418603ll#1370418616cp ip2location.dat.sample ip2location.dat#1370418618ll#1370418622/usr/local/nginx/sbin/nginx-t#1370418624/usr/local/nginx/sbin/nginx -t#1370418635service nginx smoothupdate#1370418651cd /usr/local/nginx/sbin/#1370418651ll#1370418662kill -QUIT `cat nginx.pid.oldbin`#1370418666ps aux |grep nginx#1370418673top#1370418696/usr/local/nginx/sbin/nginx -V#1370418706top#1370419116ps aux |grep nginx#1370419325w#1370429096w#1370429108w#1370471189unset LANG; lsb_release -a; uname -a; #1370427019cd /var/log/sogou-resource-util/#1370427020ll#1370427076vi message.log.20130605 #1370427135cd /var/log#1370427135ll#1370427139cd sogou-resource-util/#1370427140ll#1370427149tail message.log.20130605 #1370509980w#1370509985curl localhost#1370509992curl localhost#1370509993curl localhost#1370509995w#1370509995w#1370509996top#1370510042top#1370510050cd /search/nginx/logs#1370510050ll#1370510058ll | grep error#1370510060ll | grep error#1370510261nload#1370510703nload#1370510803sogou-host#1370510825history | tail#1370510830history |less#1370510894sogou-host#1370513191cd /search/nginx/logs#1370513191ll#1370513200grep "config.zhushou" error.log #1370513213grep "zhushou" error.log | less#1370557580unset LANG; lsb_release -a; uname -a; #1370572557w#1370572566curl localhost#1370573525w#1370573527curl localhost#1370573532clustat #1370573771w#1370573896w#1370588496clustat #1370588534sogou-host #1370588543exit#1370589275cd /opt/sogou-pack/#1370589276ll#1370589278cd resource-util/#1370589279ll#1370589281vi ru.cfg #1370591916ll#1370596217cd /search/nginx/logs/history/#1370596218ll#1370596232cd union.sogou.com/#1370596233ll#1370596248cat union.sogou.com_access_log.2013060711 |grep "2013-06-07 11:50:20"#1370596259head union.sogou.com_access_log.2013060711 #1370596270cat union.sogou.com_access_log.2013060711 |grep "11:50:20"#1370596326cat union.sogou.com_access_log.2013060711 |grep "10.14.140.205"#1370596364cat union.sogou.com_access_log.2013060711 |grep "10.14.140.205"|grep "10.13.198.194"#1370596369cat union.sogou.com_access_log.2013060711 |grep "10.14.140.205"|grep "10.13.198.194"#1370596819cd /search/nginx/logs/#1370596829cd history/union.sogou.com#1370596836ll#1370596841ll#1370596855cat union.sogou.com_access_log.2013060711|grep "59.53.170.8"#1370644003unset LANG; lsb_release -a; uname -a; #1370597731cd /opt/sogou-pack/resource-util/#1370597731ll#1370597746sogou-host#1370598440ll#1370598452cd /var/log/sogou-resource-util/#1370598453ll#1370598459tail -f message.log.20130607#1370702459w#1370702684curl localhost#1370702685curl localhost#1370702694w#1370730405unset LANG; lsb_release -a; uname -a; #1370702416top#1370702457nload#1370702536top#1370702667cd /search/nginx/logs#1370702668ll#1370702672cd latest#1370702673ll#1370702784ll#1370702792tail nginx.lat.log.201306082245#1370703035ll#1370703329uptime#1370761961cd /usr/local/nginx/#1370761961ll#1370761969cp -r conf conf.20130609#1370761970ll#1370763400cd /search/#1370763401ll#1370763404rm -f *.rpm#1370763405ll#1370763410cd logs#1370763411ll#1370763412cd log#1370763412ll#1370763418cd /search/#1370763419ll#1370763421rm -rf log#1370763422ll#1370763692ll#1370763712rsync -avz rsync.proxy07.ha.djt::search/conf.tar /usr/local/nginx/#1370763721cd /usr/local/nginx/#1370763722ll#1370763728rm -rf conf#1370763732tar -xvf conf.tar#1370763734ll#1370763740rm -f conf.tar#1370763741ll#1370763748cat conf/nginx.conf #1370763761/usr/local/nginx/sbin/nginx -t#1370763775service nginx reload#1370763787cd#1370763790cd /usr/local/nginx/#1370763790ll#1370763792cd /search/#1370763793ll#1370763797rm -f conf.tar#1370763798ll#1370763825cd /usr/local/nginx/html/#1370763825ll#1370763827vi index.html #1370763843ll#1370763858vi index.html #1370763877chattr +i index.html #1370763878ll#1370763907rsync -avz [email protected]::search/nginx/html/* /search/nginx/html/#1370763915ll#1370763916ll#1370763917cd ..#1370763918ll#1370763927cd /search/nginx/#1370763928ll#1370763932cd data#1370763932ll#1370763936cd ..#1370763937ll#1370763938df -h#1370763941ll#1370763948rm -f nginx_fail.log#1370763949ll#1370763954cd /usr/local/nginx/#1370763954ll#1370763955cd sbin/#1370763956ll#1370763966rm -f nginx.20130531#1370763967ll#1370763975ps aux#1370763977ps aux|grep nginx#1370764029ll#1370764031ll#1370816826unset LANG; lsb_release -a; uname -a; #1370903214unset LANG; lsb_release -a; uname -a; #1370917719w#1370917731curl localhost#1370918317curl localhost#1370918319curl localhost#1370918322ll#1370918328cd /search/nginx/logs/latest/#1370918329ll#1370918501ip addr#1370989623unset LANG; lsb_release -a; uname -a; #1371076015unset LANG; lsb_release -a; uname -a; #1371106063unset LANG; lsb_release -a; uname -a; #1371162423unset LANG; lsb_release -a; uname -a; #1371248833unset LANG; lsb_release -a; uname -a; #1371335228unset LANG; lsb_release -a; uname -a; #1371421619unset LANG; lsb_release -a; uname -a; #1371508036unset LANG; lsb_release -a; uname -a; #1371522005cd /search/nginx/logs/#1371522006ll#1371522012cd /search/nginx/#1371522013cd ..#1371522014ll#1371522026rm -f nginx.err* nginx.lat*#1371522027ll#1371522031ll#1371522060rm -rf tmp_log hostlist.txt proxy_deploy.sh zls rescue_nginx.sh#1371522062ll#1371522089rm -rf home proxy_1.sh monitor lost+found #1371522092ll#1371522103ll#1371522104ll#1371522106df -h#1371522109ll#1371522110cd nginx/#1371522111ll#1371522113cd logs/#1371522113ll#1371522115cd ..#1371522115ll#1371522127chown -R odin.odin .#1371522135cd /usr/local/nginx/conf#1371522135ll#1371522147chown -R root.root .#1371522224ll#1371522226cd#1371522228cd /search/#1371522229ll#1371529375w#1371529378cd /search/nginx/logs/#1371529378ll#1371529381ll#1371529385cd ..#1371529386ll#1371529395chown -R nobody.nobody .#1371529397ll#1371529399cd logs/#1371529400ll#1371529405ll -h logs#1371529410ll -h error.log #1371529415> error.log #1371529422tail -f error.log #1371529441ll#1371529821cd /usr/local/nginx/#1371529821ll#1371529827rm -rf conf.20130609#1371529828ll#1371529829cd sbin#1371529830ll#1371529968w#1371594431unset LANG; lsb_release -a; uname -a; #1371637514cd /search/#1371637515ll#1371637517mkdir tmp#1371637517ll#1371637519cd tmp/#1371637526ftp ftp://proxy.wsfdupload.lxdns.com#1371637545lftp [email protected]#1371637658ll#1371637662rm -f *#1371637668lftp [email protected]#1371637995ll#1371638000wget -R "http://files.sogou.com/test/"#1371638004man wget#1371638010wget -r "http://files.sogou.com/test/"#1371638017man wget#1371638084wget -nd "http://files.sogou.com/test/"#1371638094ll#1371638096ll -h#1371638097ll#1371638098w#1371638100top#1371638115ll#1371638116cd ,,#1371638117cd ..#1371638117ll#1371638125cp url url2#1371638127vi url2 #1371638146mkdir tmp2#1371638148cd tmp2/#1371638173for i in `cat ../url2`;do wget -r -nd "$i" ; done#1371638183ll#1371638184ll#1371638186cd ..#1371638187ll#1371638194rm -rf url2 tmp2/#1371638194ll#1371638199cd tmp/#1371638199ll#1371638842host android2.cdn.sogou.com#1371638845cd#1371638854cd /search/#1371638854ll#1371638856du -sh tmp/#1371648980cd /search/tmp/#1371648980ll#1371648983ll |wc -l#1371648986ll|less#1371648991ll|head#1371649157ll|head#1371649221ll#1371649225ll|head#1371649226ll|head#1371649226ll|head#1371649227ll|head#1371649227ll|head#1371649227ll|head#1371649228ll|head#1371649228ll|head#1371649228ll|head#1371649237ll |grep 130619#1371649241ll |grep 130619#1371649242ll |grep 130619#1371649242ll |grep 130619#1371649243ll |grep 130619#1371649243ll |grep 130619#1371649243ll |grep 130619#1371649244ll |grep 130619#1371649246ll |grep 130619#1371649246ll |grep 130619#1371649247ll |grep 130619#1371649247ll |grep 130619#1371649455ll |grep 130619#1371649456ll |grep 130619#1371649457ll |grep 130619#1371649458ll |grep 130619#1371649458ll |grep 130619#1371649459ll |grep 130619#1371649984wget files2.sogou.com/sogou_explorer_silent_2.0.0.891_2180.exe#1371649996ll sogou_explorer_silent_2.0.0.891_2180.exe*#1371650008ll sogou_explorer_silent_2.0.0.891_2180.exe*#1371650012ll sogou_explorer_silent_2.0.0.891_2180.exe.1#1371650019rm -f sogou_explorer_silent_2.0.0.891_2180.exe.1#1371650020ll#1371650042cd ..#1371650042ll#1371650045grep sogou_explorer_silent_2.0.0.891_2180.exe url #1371650059cd tmp/#1371650059ll#1371650061ll#1371650099ll|head#1371680835unset LANG; lsb_release -a; uname -a; #1371703743cd /search/nginx/logs/latest/#1371703743ll#1371649169cd /search/tmp/#1371649169ll#1371649180lftp sogou@ftp://125.39.17.8#1371649192lftp [email protected]#1371637581cd /search/tmp/#1371637582ll#1371637583ll#1371637616ll#1371637618ll#1371637740lftp [email protected]#1371637905ll#1371637907rm -rf *#1371637908cd ..#1371637909ll#1371637912vi tmp#1371637916vi txt#1371637936awk '{print "http://files2.sogou.com/"$NF}'#1371637940awk '{print "http://files2.sogou.com/"$NF}' txt#1371637946awk '{print "http://files2.sogou.com/"$NF}' txt >> url#1371637946ll#1371637950rm -f txt#1371637952cat url #1371637953ll#1371637955cd tmp/#1371637973for i in `cat ../url` ;do wget "$i" ;done#1371648915ll#1371648918du -sh .#1371648929lftp [email protected]#1371649288ll#1371649318rm -f PreUpdater130619.exe #1371649323wget files2.sogou.com/PreUpdater130619.exe #1371649328lftp [email protected]#1371651076ll#1371654433lftp [email protected]#1371715240cd#1371767235unset LANG; lsb_release -a; uname -a; #1371853636unset LANG; lsb_release -a; uname -a; #1371709913clustat #1371711427top#1371940041unset LANG; lsb_release -a; uname -a; #1372026423unset LANG; lsb_release -a; uname -a; #1372078340w#1372078349cd /search/nginx/logs/#1372078359cd /search/nginx/logs/#1372078360ll#1372078365cd latest/#1372078366ll#1372078374tail nginx.lat.log.20130624205#1372078376tail nginx.lat.log.201306242051#1372078389cd /search/#1372078390ll#1372078401rm -f 123* nginx.la* skin.ie*#1372078401ll#1372078504w#1372078677w#1372078680w#1372078681nload#1372078709w#1372078863w#1372078864ll#1372078868cd nginx/logs/#1372078877tail 123.sogou.com_access_log #1372079100w#1372079104w#1372079105nload#1372079187w#1372079189top#1372079471nload#1372079831w#1372079835w#1372079982w#1372080132w#1372080235w#1372080434grep "175.5.18.23" 123.sogou.com_access_log |less#1372081121nload#1372081273ll#1372081280ll#1372081286cd /etc/sysconfig/#1372081289cat iptables#1372081303ll#1372081451iptables -F#1372081457cat /etc/sysconfig/iptables#1372081473iptables -Ln#1372081479iptables -ln#1372082504w#1372082506clustat #1372112817unset LANG; lsb_release -a; uname -a; #1372199224unset LANG; lsb_release -a; uname -a; #1372222628w#1372222755w#1372222759w#1372230219vi /etc/hosts#1372230274service nginx reload#1372230293ps aux |grep nginx#1372230487ll#1372230489df -h#1372230491cd /var/#1372230491ll#1372230494du -sh *#1372230497cd account/#1372230497ll#1372230507> pacct#1372230509ll#1372230515rm -f pacct.*#1372230517l#1372230518ll#1372230522ll -h#1372230536ll#1372230537cd ..#1372230538ll#1372230542df -h#1372230834ll#1372230836free#1372230844ll#1372230847crontab -l#1372230850ll#1372230853w#1372240721vi /etc/hosts#1372240742host bbs01.ie.cnc.vm#1372240768service nginx reload#1372285620unset LANG; lsb_release -a; uname -a; #1372312211curl -H "Host: extention.ie.sogou.com" "http://localhost/se_plugin/getfile?key=8f3db89aa260989bbd315c8a26764933" -I -v#1372312223curl -H "Host: extention.ie.sogou.com" "http://localhost/se_plugin/getfile?key=8f3db89aa260989bbd315c8a26764933" -I -v#1372312360curl -H "Host: extention.ie.sogou.com" "http://localhost/se_plugin/getfile?key=8f3db89aa260989bbd315c8a26764933" -I -v#1372315257cd /var/log/acpid #1372315259cd /var/account/#1372315261ll#1372315264ll -h#1372315283/etc/init.d/psacct stop#1372315285ll#1372315287cd ..#1372315287ll#1372315291rm -rf account/#1372315297mkdir /search/account#1372315300df -h#1372315317mv /search/account/ /opt/#1372315324ln -s /opt/account/ account#1372315325ll#1372315333/etc/init.d/psacct start#1372315338ll#1372315339cd account/#1372315340ll#1372315343ll#1372315345cd /opt/#1372315345ll#1372315347cd account/#1372315348ll#1372315351crontab -l#1372315355ll#1372331100w#1372332658w#1372332661w#1372332663w#1372332669cd /search/nginx/logs/latest/#1372332670ll#1372332678w#1372332680ccd#1372332689cd /search/#1372332690ll#1372332699rm -f nginx.lat.log.201306251430#1372332701ll#1372332708crontab -l#1372332730ll#1372332733w#1372332736clustat #1372332743w#1372332791w#1372332794ll#1372332799cd ac#1372332800ll#1372332806tail qul#1372332816iptables -l#1372332821iptables -L#1372333014ip addr#1372333017clustat #1372333067ll#1372333078tail qudb#1372333081ll#1372333085quota.log#1372333090tail qlog#1372333110cat qlog#1372333118cat qdb#1372333130cat qres#1372333250ll#1372333252cat so#1372333257ll#1372333262tail qre#1372333267cat qres#1372333621ll#1372333625cat qres#1372334372cd#1372334398ll#1372334400cd /search/#1372334401ll#1372334431rsync -avz rsync.proxy01.ha.djt::search/acmilan /search/#1372334454rsync -avz rsync.proxy01.ha.djt::search/acmilan /search/#1372334456ll#1372334486echo "* * * * * cd /search/acmilan; ./sogou-quake" >> /var/spool/cron/root #1372334488crontab -l#1372334495cd#1372334501cd /search/acmilan/#1372334502ll#1372334503crontab -l#1372334548w#1372334554crontab -l#1372334602iptables -L#1372334627iptables -L#1372334629iptables -L#1372334718w#1372334722iptables -Ln#1372334724iptables -L#1372334744iptables -L#1372334810iptables -L#1372334813iptables -L#1372334841ll#1372334846cat quake.res#1372335010cat quake.res#1372335565w#1372335573top#1372335632cat quake.res #1372335641iptables -L#1372372041unset LANG; lsb_release -a; uname -a; #1372387345w#1372387353w#1372387354w#1372387355w#1372387356w#1372397372cd /search/nginx/logs/#1372397372ll#1372397374cd /search/#1372397375ll#1372397377cd acmilan/#1372397377ll#1372397411vi sogou-quake #1372397447ll#1372397451ll#1372397470cat test#1372397471ll#1372397474cat sogou-quake #1372397475ll#1372397596ll#1372397605cat xxx#1372397609rm -f xxx#1372397609ll#1372397619rm -f 1#1372397620ll#1372397626df -h#1372397640cat /opt/sogou-pack/observer/conf/ob_nginx_cnc.cfg #1372397647ll#1372397653iptables -L#1372397681iptables -L#1372397697ll#1372397705ll#1372397822rsync -avz 10.136.120.65::search/acmilan/sogou-quake /search/acmilan/#1372397828ll#1372397835ll#1372397840iptables -F#1372397841ll#1372397848cat quake.db#1372397853ll#1372397854ll#1372397857cat quake.res#1372397865iptables -L#1372397873vi sogou-quake #1372397886ll#1372397889cd snapshot/#1372397890ll#1372397896cd ..#1372397897ll#1372397902vi sogou-quake #1372397931vi sogou-quake #1372397935ll#1372397939iptables -F#1372397940ll#1372397942ll#1372397947cat quake.db#1372397969iptables -L#1372397980ll#1372397984cat quake.log #1372398178ll#1372398180ll -h#1372398183ll#1372398187iptables -L#1372398205ll#1372398206w#1372398209iptables -L#1372398213ll#1372398216cat quake.res#1372145935top#1372145981clustat #1372403107ll rescue_nginx.sh#1372403116sogou-host #1372403142ll#1372403166cp rescue_nginx.sh /search/#1372403183clear#1372403237rsync [email protected]::search/rescue_nginx.sh ./#1372403250vi rescue_nginx.sh #1372405767cd /sae#1372405768cd /search/#1372405769ll#1372405770cd tmp/#1372405771ll#1372405774history |grep ftp#1372405778lftp [email protected]#1372407769lftp [email protected]#1372407843lftp [email protected]#1372407924lftp [email protected]#1372412161cd#1372458454unset LANG; lsb_release -a; uname -a; #1372544838unset LANG; lsb_release -a; uname -a;
.bash_history保存了最近使用过的一些命令。建议删除。
危害等级:中
漏洞Rank:10
确认时间:2014-02-16 17:08
感谢提供
暂无