__ __ __ __ __ __ __ __ __ /\ \ /\__\ /\ \ /\__\ /\__\ /\ \ /\__\ /\ \ /\ \ /::\ \ /:/ / /::\ \ /:/ / /:/ / /::\ \ /::| | /::\ \ /::\ \ /:/\:\ \ /:/__/ /:/\:\ \ /:/ / /:/ / /:/\:\ \ /:|:| | /:/\:\ \ /:/\:\ \ /:/ \:\ \ /::\ \ ___ /::\~\:\ \ /:/ / /:/ / /::\~\:\ \ /:/|:| |__ /:/ \:\ \ /::\~\:\ \ /:/__/ \:\__\ /:/\:\ /\__\ /:/\:\ \:\__\ /:/__/ /:/__/ /:/\:\ \:\__\ /:/ |:| /\__\ /:/__/_\:\__\ /:/\:\ \:\__\ \:\ \ \/__/ \/__\:\/:/ / \/__\:\/:/ / \:\ \ \:\ \ \:\~\:\ \/__/ \/__|:|/:/ / \:\ /\ \/__/ \:\~\:\ \/__/ \:\ \ \::/ / \::/ / \:\ \ \:\ \ \:\ \:\__\ |:/:/ / \:\ \:\__\ \:\ \:\__\ \:\ \ /:/ / /:/ / \:\ \ \:\ \ \:\ \/__/ |::/ / \:\/:/ / \:\ \/__/ \:\__\ /:/ / /:/ / \:\__\ \:\__\ \:\__\ /:/ / \::/ / \:\__\ \/__/ \/__/ \/__/ \/__/ \/__/ \/__/ \/__/ \/__/ \/__/ ======================================================== 2010-10 ================================================== Hey boys! New challenge. If you can, deface this web page ;) http://shell-storm.org:85 The first guy to deface it, win the challenge 2010-10 ! EDIT! Congratulation to ROPEME@ for the first guy to resolve challenge http://shell-storm.org:85 If you still want to participate in the challenge go in http://shell-storm.org:85/indexbackup.html but the index.html is now chattr +i Have fun. ======================= Edit: Challenge closed. ======================= If you still want participate in the challenge in your local machine, you can download sources : http://shell-storm.org/smashme/files/serv_httpd.tar.gz Others informations for challenge ---------------------------------------------------------------------------------------------------------- root@defaceme [/] $ iptables -L Chain INPUT (policy DROP) target prot opt source destination ACCEPT icmp -- anywhere anywhere ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED ACCEPT all -- anywhere anywhere ACCEPT tcp -- anywhere anywhere ACCEPT udp -- anywhere anywhere ACCEPT all -- anywhere anywhere Chain FORWARD (policy DROP) target prot opt source destination Chain OUTPUT (policy DROP) target prot opt source destination ACCEPT tcp -- anywhere anywhere tcp dpt:mit-ml-dev flags:FIN,SYN,RST,ACK/SYN ACCEPT tcp -- anywhere anywhere tcp dpt:http-alt ACCEPT tcp -- anywhere anywhere tcp spt:mit-ml-dev ACCEPT tcp -- anywhere anywhere tcp spt:http-alt root@defaceme [/] $ cat /proc/sys/kernel/randomize_va_space 0 And if you want, writeup is here: http://shell-storm.org/smashme/files/resolve201010.txt