RE: Hack attempt

Jan.Albrecht_at_bertelsmann.de
Date: 07/23/04

  • Next message: Eric Paynter: "Re: Hack attempt"
    To: focus-linux@securityfocus.com
    Date: Fri, 23 Jul 2004 08:06:18 +0200
    
    

    Hi Norbert,

    > -----Original Message-----
    > From: Norbert Crettol [mailto:norbert.crettol@idiap.ch]
    > Sent: Wednesday, July 21, 2004 5:03 PM
    >
    > We've had a undesired visitor, last night, that I discovered in the
    > reports of tripwire.
    >
    > Has someone seen this kind of attack ? (chkrootkit doesn't detect it).
    > Has someone heard of this www.bosscalvin.com (or www.calvinmumu.org) ?
    > Is there a way to stop this guy ? His nickname (CaEm) appears in the
    > the uploaded scripts.

    this is a "File Injection Bug" attack. As far as I know this script gains
    access as nobody (or webserver user), reads files placed in /tmp (or where
    the webserver user can read), places some files an executes them.

    Problem: Some of your scripts accepts user data without validation. This is
    the most common way to inject files onto a webserver.

    Resolution: Shutdown system, clean it up, update it to the latest versions
    and recheck your scripts.

    Regards

    Jan


  • Next message: Eric Paynter: "Re: Hack attempt"

    Relevant Pages

    • Re: OT: spammers are using my domain again
      ... >> has similar packages to what Trevor is getting. ... option for us because then scripts need to change permissions. ... I was pointed to a script to track which user send mail using nobody. ... Exim is a little touchy with it mixed ...
      (Fedora)
    • Re: Cron to Launchd migration not working
      ... it ran various scripts launched by cron to do ... Nobody would be logged into the system and the scripts would ... What do I need to change to get it to work when started with Launchd? ...
      (comp.sys.mac.system)
    • Memcached Daemon Startup Issues
      ... flags into rc.conf, but when I start it with the rc.d scripts, it always ... executing the rc.d script as root, yet it still starts as nobody. ...
      (freebsd-questions)
    • Re: [PHP] Create .php file with php [POC CODE INCLUDED]
      ... will most likely be running universally as `nobody`, `httpd`, ... `apache`, or `daemon` for all scripts, including all web-based scripts ...
      (php.general)