sh
ãã®ä¸ã®ã©ããã«ããã¨ããlog4j.properties(ã®å ¥ã£ãjar)ãæ¢ãä¸è¡ã§ãã $ for f in `find / -name "*.jar"`; do if [ "`jar tf $f | grep log4j.properties`" ]; then echo "$f"; fi; doneãWEB-INF/classesãã¨ãã«ç´ ã§ç½®ããã¦ããå ´åã¯æªèæ ®ãªã®ã§â¦
suã使ã以å¤ã«ãdeamontoolsä»å±ã®ãsetuidgidãã使ãæ¹æ³ãããã¾ãã $ setuidgid <ã¦ã¼ã¶ã¼> <ã³ãã³ã>å ·ä½ä¾ã¯ä»¥ä¸ãwhoamiã¯å®è¡ã¦ã¼ã¶ã¼ãåºåããã³ãã³ãã§ãã(ãããä»æ¥ç¥ã£ãã»ã»ã»ã) $ setuidgid unageanu whoamiå®è¡çµæã§ãã unageanuãâ¦
ãtime ãã§ã³ãã³ãã®æè¦æéãè¨æ¸¬ã§ãã¾ãã $ time sleep 3å®è¡çµæã§ãã real 0m3.315s user 0m0.000s sys 0m0.000såºåå ã¯æ¨æºã¨ã©ã¼ãªã®ã§ããªãã¤ã¬ã¯ããã¦çµæãä¿åããå ´åã¯æ³¨æã $ time sleep 3 > a.txt real 0m3.030s user 0m0.001s sys â¦
$ su - <ã¦ã¼ã¶ã¼> -c <ã³ãã³ã>ã§ãæå®ããã¦ã¼ã¶ã¼ã§ã³ãã³ããå®è¡ã§ãã¾ãã ã-cããªãã·ã§ã³ãã¤ããã¨ã·ã§ã«ãèµ·åããªãã®ã§ãå®è¡å¾ã¯ãã¨ãã¨ã®ã¦ã¼ã¶ã¼ã®ã·ã§ã«?ã«æ»ãã¾ãã ä¸è¬ã¦ã¼ã¶ã¼ã§å®è¡ããå ´åã¯ã(å½ããåã§ãã)ãã¹ã¯ã¼ããå¿ è¦â¦
yesã§ã³ãã³ããåºåããshã§å®è¡ã $ yes date | shå®è¡çµæã§ãã 2009å¹´ 11æ 11æ¥ æ°´ææ¥ 13:05:33 JST 2009å¹´ 11æ 11æ¥ æ°´ææ¥ 13:05:33 JST 2009å¹´ 11æ 11æ¥ æ°´ææ¥ 13:05:33 JST 2009å¹´ 11æ 11æ¥ æ°´ææ¥ 13:05:33 JST 2009å¹´ 11æ 11æ¥ æ°´ææ¥ 13:â¦