telnet 192.168.1.1:23

root

admin

shell

"telecomadmin" Password="nE7jA%5m"

#查看用户密码

WAP(Dopra Linux) # cat /etc/passwd

root:x:0:0:root:/root:/bin/sh

nobody:x:65534:65534::/tmp:/bin/sh

#查看影子密码

WAP(Dopra Linux) # cat /etc/shadow

root:aqnaBbVaP.9Zo:14453:0:99999:7:::

nobody:!:11141:0:99999:7:::

sshd:*:11880:0:99999:7:-1:-1:0

#一些结构体的定义

cat /etc/wap/hw_boardinfo_readme.txt

#define HW_DM_PD_LOID_OBJ_ID (0x00000016) /* GPON/EPON LOID *

#网页命令行列表

WAP(Dopra Linux) # cat /etc/wap/hw_shell_cli.xml

WAP(Dopra Linux) #

#WAP Linux系统版本

WAP(Dopra Linux) # cat /etc/wap/wap_version

V800R012C00SPC192B001

#hw_ctree.xml解密解压后的部分文字

#用户名和密码

#最大终端数目限制

#FTP配置

再看一个,用户获得一个shell之后执行的内容

WAP(Dopra Linux) # cat /etc/profile

# /etc/profile

# init bash prompt and enviroment.

#

#alias ls="ls --color=auto"

alias ll="ls -l"

alias cp="cp -i"

alias ..="cd .."

PATH="/bin:/usr/bin:/sbin:/usr/sbin"

#PS1="\[\033[32m\]\h \w\[\033[m\] \\$ "

PS1="WAP(Dopra Linux) # "

#set core dump according to the hw_wap_debug.config file

var_file_name=/proc/wap_proc/debug_config

if [ -e $var_file_name ]; then

var_find_core_flag=HW_WAP_AUTO_CORE_DUMP

var_find_mount=HW_WAP_AUTO_MOUNT

var_core_flag=`grep $var_find_core_flag $var_file_name | sed 's/[^0]*//' | sed 's/0x//'`

var_core_mount=`grep $var_find_mount $var_file_name | sed 's/[^\"]*//' | sed 's/"//' | cut -f 1 -d '"'`

if [ "$var_core_flag" != "" ] && [ "$var_core_flag" != "FFFFFFFF" ] && [ $var_core_flag -eq 1 ]; then

ulimit -c unlimited

echo "profile open core dump, flag=$var_core_flag"

if [ "$var_core_mount" != "" ];then

mount $var_core_mount

if [ $? = 0 ];then

echo "/mnt/nfs/core-%e-%p-%t" > /proc/sys/kernel/core_pattern

echo "profile 'mount $var_core_mount' successful"

else

echo "/var/core-%e-%p-%t" > /proc/sys/kernel/core_pattern

echo "profile 'mount $var_core_mount' failed"

route

ifconfig

fi

else

echo "/var/core-%e-%p-%t" > /proc/sys/kernel/core_pattern

echo "profile 'mount $var_core_mount' failed"

fi

else

ulimit -c 0

echo "profile close core dump, flag=$var_core_flag"

fi

else

ulimit -c 0

echo "profile close core dump"

fi

if [ `id -u` -eq 0 ]; then

umask 000

else

umask 000

fi

USER=`id -un`

LOGNAME=$USER

HOSTNAME=`/bin/hostname`

HISTSIZE=0

TMOUT=900

EDITOR=vi

VISUAL=vi

PAGER=more

INPUTRC="/etc/inputrc"

export PATH PS1 USER LOGNAME HOSTNAME HISTSIZE EDITOR VISUAL PAGER INPUTRC TMOUT

# Running the local scripts from the user

for i in /etc/profile.d/*.sh ; do

if [ -x $i ]; then

. $i

fi

done

unset i

WAP(Dopra Linux) #