Σχόλιο Νο 52: chenxiaolong έγραψε:TL;DR:
There's a script that sends logs, hardware information, and takes a screenshot of the active Xorg session to http://www.sphinux.org/bug_report.php/sbin/au
Grabs MAC addresses of all network interfaces
/sbin/auther
Segfaults
/sbin/besbes-otta
Fake tool that benchmarks the time it takes to allocate a certain amount of memory
/sbin/getarch
Prints 'x86_64' or 'i686'
/sbin/koko-wawa
(Removed boost, so can't test right now)
/sbin/lsx
Symlink to /dist/sbin/
/sbin/sau
Sends /dist/usr/share/misc/tune to
http://www.sphinux.org/stats.php, however that file doesn't exist (Screenshot:
http://i.imgur.com/XcDOKk8.png)
/sbin/sendstat
Downloads http://www.sphinux.org/56734 and does a string comparison with "SphinUS rocks other suck". The downloaded output is never used in an exec statement so command execution is not possible.
/bin/autodriver
Detects graphics card and installs proprietary drivers
/bin/lsx
Symlink to /dist/bin/
/bin/oba
Also downloads
http://www.sphinux.org/56734 and does the same string comparison
Sends the following to http://www.sphinux.org/bug_report.php
date
lspci
lsusb
lscpu
lshw
lshal
lsmod
dmesg
lsblk
/var/log/boot.log
whoami
xwd -root ***WARNING: This takes a screenshot of the current Xorg session***
This script presents a fake "# Authenticating ..." text when sending the data/bin/readme
Prints out /usr/share/horus/scripts/readme and pipes it to less
/bin/xhost
***WARNING: Potentially dangerous: Calls "xhost +"***Runs "/etc/init.d/autofs start"
/opt/Synaptics/HKLM_Kernel
Dump of Synaptics registry entries from Windows (includes some device IDs unrelated to touchpads)
/opt/Synaptics/HKLM_User
Some more Synaptics registry entries
/opt/Synaptics/**/*.so
Lots of libraries here. I have no idea what they are for
/opt/firefox
Custom(?) Firefox build. Tarball here:
http://ubuntuone.com/2Xa1ggYqd7YvN5IDtBdFi6/usr/bin/4L-cli
Broken symlink
/usr/bin/4L-gui
Broken symlink
/usr/bin/au
Same as /sbin/au
/usr/bin/auther
Same as /sbin/auther
/usr/bin/disoff
Calls some ACPI methods to supposedly turn of the discrete graphics card
/usr/bin/dison
Opposite of above
/usr/bin/edu
echos a short description of readme, rkhunter, nmap, ip, nbtscan, besbes-otta
/usr/bin/getarch
Same as /sbin/getarch, except last line has "&>/dev/null 2>&1"
/usr/bin/mangui
Shows /usr/share/horus/scripts/readme with kdialog
/usr/bin/powercontrol
Performs some power management tweaks (CPU freq, VM write back timeout, SATA ALPM, etc)
/usr/bin/sau
Same as /sbin/sau
And yeah...I highly doubt these people could create a kernel since they can't create a distro properly:
Their bluetooth devices address is 9C:B7:0D:69:E7:BF
All of their prior DHCP leases are in /var/lib/dhcp/ and /var/lib/NetworkManager/
All policykit actions are automatically allowed (even on installed system)(ΣΣ: Γι αυτό έχεις πάντα δικαιώματα, λογικό είναι!!): /var/lib/polkit-1/localauthority/10-vendor.d/10-live-cd.pkla