Re: Compromised FBSD/Apache

From: Benjamin Krueger (benjamin@seattlefenix.net)
Date: 11/18/02

  • Next message: Ragnar Paulson: "Fraudulent use of ebay's name"
    From: "Benjamin Krueger" <benjamin@seattlefenix.net>
    To: "Greg S. Wirth" <greg@beldamar.com>
    Date: Mon, 18 Nov 2002 05:27:20 -0800
    
    

    ----- Original Message -----
    From: "Greg S. Wirth" <greg@beldamar.com>
    To: <incidents@securityfocus.com>
    Sent: Saturday, November 16, 2002 9:11 AM
    Subject: Compromised FBSD/Apache

    > Hello...
    > November 14, 2002 I noticed a service running on port 127/tcp.
    > The box runs only Apache, no SSL.
    > Only open ports before this were 21/22/80
    > PHP was installed 5 days prior to this.
    > PHP runs in safemode.
    > I run netstat -an every morning, which is how I found the issue.
    > There were no log entries that showed anything out of the ordinary.
    > Users have access to FTP only.
    > Connections to port 127 are being blocked by the firewall.
    > If anyone would like more information, feel free to contact me.
    > Enjoy the day.

    What process is listening on the port?

    sockstat | grep ':127'

    Find out what the process is, who owns it, when it was started, when it was
    put there, and what its purpose is.

    > Greg S. Wirth
    > Anchorage, Alaska
    > http://rapidfx.org

    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management
    and tracking system please see: http://aris.securityfocus.com



    Relevant Pages

    • Upgrading to 60 question.
      ... <ACPI PCI bus> on pcib0 ... <Parallel port bus> on ppc0 ... libmcrypt-2.5.7_1 Multi-cipher cryptographic library (used in PHP) ... p5-XML-Parser-2.34_1 Perl extension interface to James Clark's XML parser, ...
      (freebsd-questions)
    • Re: Reading COM1 with php-win
      ... loop waiting for data on the COM port to get data off it. ... buffer built in. ... Yes, you can use the com activex object, and it does help. ... > reliable asynchronous comms using PHP on Win32 other than using the ...
      (comp.lang.php)
    • phpbb - install.php script> blank screen
      ... Copy of problem report to phpbb forum.. ... Do you use a port of phpBB:Freebsd ... Version of PHP: ... dns1# ls -l ...
      (freebsd-questions)
    • Re: Reading COM1 with php-win
      ... loop waiting for data on the COM port to get data off it. ... buffer built in. ... Yes, you can use the com activex object, and it does help. ... > reliable asynchronous comms using PHP on Win32 other than using the ...
      (comp.lang.php)
    • RE: Mea Culpa, Ive killed OWA/RWW/Other stuff with NET STOP
      ... the SSL port to the new site, once that was deleted, I was able to ... Perhaps posting my config, as you requested, will help answer this question: ... available - it's a PHP intranet/extranet application, ... >>I was trying to install PHP manually, ...
      (microsoft.public.windows.server.sbs)