[Full-Disclosure] Suggested filters against PHP Attacking Worms

From: Paul Laudanski (zx_at_castlecops.com)
Date: 12/28/04

  • Next message: Elle Chicka: "[Full-Disclosure] And you're proud of this Mike Evanchick?"
    Date: Tue, 28 Dec 2004 00:16:22 -0500 (EST)
    To: bugs@securitytracker.com, <bugtraq@securityfocus.com>, <full-disclosure@lists.netsys.com>, <moderators@osvdb.org>, <news@securiteam.com>, <vuln@secunia.com>, <vulnwatch@vulnwatch.org>
    
    

    With the whole Santy and Phpinclude worms running around lately, I ran
    some stats and put up some filter suggestions in the below article link.

    As a highlight, in a 55 hour period my site received just under 300,000
    verified attacks. Some GET examples have been shown, and filters false
    positives are analyzed.

    http://castlecops.com/article5642.html

    Filter examples are provided for:

    - modsecurity
    - php
    - modrewrite

    A couple hardening suggestions are also included.

    -- 
    Regards,
    Paul Laudanski - Computer Cops, LLC. CEO & Founder
    CastleCops(SM) - http://castlecops.com
    Promoting education and health in online security and privacy.
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: Elle Chicka: "[Full-Disclosure] And you're proud of this Mike Evanchick?"

    Relevant Pages

    • Filter the results of a list based on a previous vlookup against the same list
      ... Stats ... I then in a seperate cell have a list (Data, ... Onehand item ... So I guess with all of the above I am asking two things - filter the ...
      (microsoft.public.excel.worksheet.functions)
    • Re: OT: Newsgroup statistics for the last 30 day(s)
      ... I don't want to be seen as policing the stats, ... IYSWIM. ... You can filter me out if you want. ... See if I care. ...
      (uk.rec.motorcycles.classic)
    • Re: Stats comp.os.linux.misc (last 7 days)
      ... |> extracted from the Message-ID header? ... Do your stats filter out spam before counting? ... "Enhanced" cross posting is filtered out, ... obviously disorder the stats if I did it via leafnode. ...
      (comp.os.linux.misc)
    • Re: OT: Newsgroup statistics for the last 30 day(s)
      ... don't want to be seen as policing the stats, IYSWIM. ... You can filter me out if you want. ... See if I care. ...
      (uk.rec.motorcycles.classic)
    • Re: % of flops seen
      ... I'm curious as to why this stat would be of much interest - the % flop seen ... averages over all the microlimit games? ... It seems to me that the % flop seen (and many other stats) should be highly ... You can filter by table ...
      (rec.gambling.poker)