馬上註冊,結交更多好友,享用更多功能,讓你輕鬆玩轉社區。
您需要 登錄 才可以下載或查看,沒有賬號?註冊
x
因為更新ZIN-5005HD韌體後出了點"意外"可能是因為個人關係所以並沒有讓我很滿意
故..努力了幾個小時,打開了 韌體更新檔 查了一下相關的內容 意外的發現了幾個小秘密 [或許是公開的秘密吧!!]
[ 1 ] 執行 telnet / ssh / ftp 應該是可行的!!
[root@fedora etc]# more inetd.conf
#ftp stream tcp nowait root /usr/sbin/ftpd ftpd -u 100
telnet stream tcp nowait root /usr/sbin/telnetd telnetd
#auth stream tcp nowait nobody /usr/sbin/nullidentd nullidentd
www stream tcp nowait www-data /usr/sbin/httpd httpd -h /var/www
...
[root@fedora etc]# ls -al ../usr/sbin/ftpd
ls: cannot access ../usr/sbin/ftpd: No such file or directory [印象中 busybox 好像有支援 ftpd]
[root@fedora etc]# ls -al ../usr/sbin/telnetd
lrwxrwxrwx. 1 root root 17 Apr 12 18:56 ../usr/sbin/telnetd -> ../../bin/busybox
[root@fedora etc]# ls ../bin/busybox../bin/busybox
[root@fedora etc]# ls -al ../bin/busybox
-rwxr-xr-x. 1 root root 993544 Apr 12 18:56 ../bin/busybox
[2] http://5005HD ip/webtorrent.cgi ??
[root@fedora www]# pwd
/root/test/install_img/package2/yaffs2_1/tmp_orig/www
[root@fedora www]# ls -al
total 20
drwxr-xr-x. 4 root root 4096 Apr 12 18:56 .
drwxr-xr-x. 9 root root 4096 Apr 12 18:56 ..
drwxr-xr-x. 2 root root 4096 Apr 12 18:56 adm <- 又一個被閹掉的地方!!
drwxr-xr-x. 2 root root 4096 Apr 12 18:56 cgi-bin
-rwxr-xr-x. 1 root root 339 Apr 12 18:56 index.html
[root@fedora www]# ls -al adm/
total 8
drwxr-xr-x. 2 root root 4096 Apr 12 18:56 .
drwxr-xr-x. 4 root root 4096 Apr 12 18:56 ..
[root@fedora www]# ls -al cgi-bin/
total 76
drwxr-xr-x. 2 root root 4096 Apr 12 18:56 .
drwxr-xr-x. 4 root root 4096 Apr 12 18:56 ..
-rwxr-xr-x. 1 root root 336 Apr 12 18:56 sum.cgi [就是用瀏覽器直接看ZIN-5005HD port 80 時出現的小程式]
-rwxr-xr-x. 1 root root 63724 Apr 12 18:56 webtorrent.cgi
緊接著查了 httpd.conf 的內容
[root@fedora etc]# more httpd.conf
#Allow address from 172.20.*.*
#A:172.20.#Deny from other IP connections
#D:*#No need account to access cgi/cgi-bin::
#You need root account to access "adm" pages. See here: http://www.uclibc.org/lists/busybox/2004-November/013053.html
#If you need to store password here, enable "CONFIG_FEATURE_HTTPD_AUTH_MD5"
#/adm:root:
#The second account to access "adm" pages
#/adm:nobody:
以上..個人小小的發現!希望 ZIN-5005HD 會出現像 友站 ZP-600t 補完計劃 將效能榨乾乾..
[ 本帖最後由 ackw 於 2010-4-15 23:11 編輯 ] |