Re: Another overflow exploit for Apache? *RESOLVED*

From: Andrew Simmons (andrews_at_mis-cds.com)
Date: 07/04/03

  • Next message: Tri Huynh: "Re: frontpage extensions; backdoor or initial compromise?"
    Date: Fri, 04 Jul 2003 10:57:15 +0100
    To: trihuynh@zeeup.com
    
    

    trihuynh@zeeup.com wrote:
    >
    > Yes, the script is really unsecure. Some of my clients' sites was defaced
    > a couple days ago. I don't know much about those dudes from CCBill, but it
    > looks like they don't care much about security. Here is also some other
    > files you should check too :
    >
    > /ccbill/ccbill-local.cgi
    > /ccbill/secure/ccbill.log
    > /cgi-bin/test.cgi (sometimes these dudes at CCBill forgets to remove the
    > script they use to test the client's servers)
    >
    > There are no reasons that any remote users to access thoses files.
    >

    This page:

            http://www.xs4all.nl/~frico/exploit.htm

    has a list of well-known insecure webserver scripts / paths / exploits -
    including rather a lot of other CCBill references...

    eg:

    /admin/ccbill-.cgi
    /admin/ccbill-local.cgi
    /admin/ccbill-local.cgi?cmd=MENU
    /admin/ccbill-local.pl?cmd=MENU

    [...]

    /ccbill.log
    /ccbill/.memberfile
    /ccbill/_vti_cnf/
    /ccbill/ccbill-.cgi
    /ccbill/ccbill-local.cgi
    /ccbill/ccbill-local.pl
    /ccbill/male/password/.htpasswd
    /ccbill/members/.htpasswd
    /ccbill/Msbilllog.txt
    /ccbill/newpass.txt
    /ccbill/password/.htpassfile
    /ccbill/password/.htpasswd
    /ccbill/password/.htpasswd.410
    /ccbill/password/.htpasswd.bak
    /ccbill/password/.htpasswd20227
    /ccbill/password/.htpasswd-bak
    /ccbill/password_manager/
    /ccbill/secure/.htnew
    /ccbill/secure/.htpasswd
    /ccbill/secure/cbill.log
    /ccbill/secure/ccbill.log
    /cc-bill/secure/ccbill.log
    /ccbill/secure/ccbill.log
    /ccbill/secure/current.log
    /ccbill/secure/current.log-bak
    /ccbill/secure/history.dat
    /ccbill/secure/password
    /ccbill/secure/private_key
    /ccbill/secure/purge
    /ccbill/secure/secure/ccbill.log
    /ccbill/secure/WS_FTP.LOG
    /ccbill/secured/
    /ccbill/secured/current.log-bak
    /ccbill/welcome.htm
    /ccbill/whereami.cgi
    /ccbill2/.htpasswd
    /ccbill2/access.log
    /ccbill2/male/password/.htpasswd
    /ccbill2/password/.htpassfile
    /ccbill2/password/.htpasswd
    /ccbill2/password_manager/
    /ccbill2/secure/.htpasswd
    /ccbill2/secure/current.log
    /ccbill2/secured/.htpasswd
    /ccbill2/secured/current.log
    /ccbill5/secure/ccbill.log
    /ccbill-local.cgi
    /ccbill-local.pl

    > Best regards,
    >
    > Tri Huynh
    > SentryUnion
    >
    >

    The information contained in this message or any of its attachments may be privileged and confidential and intended for the exclusive use of the addressee. If you are not the addressee any disclosure, reproduction, distribution or other dissemination or use of this communications is strictly prohibited. The views expressed in this e-mail are those of the individual and not necessarily of MIS Corporate Defence Solutions Ltd. Any prices quoted are only valid if followed up by a formal written quote. If you have received this transmission in error, please contact our Security Manager on 44 (0) 1622 723410.

    ----------------------------------------------------------------------------
    Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the
    world's premier technical IT security event! 10 tracks, 15 training sessions,
    1,800 delegates from 30 nations including all of the top experts, from CSO's to
    "underground" security specialists. See for yourself what the buzz is about!
    Early-bird registration ends July 3. This event will sell out. www.blackhat.com
    ----------------------------------------------------------------------------


  • Next message: Tri Huynh: "Re: frontpage extensions; backdoor or initial compromise?"

    Relevant Pages

    • SUMMARY WAS: OT? Philosophical Question on SA responsibilities
      ... helpful for managers interested in hiring new administrators. ... Would you go thru the 14,600 messages in root and admin ... If I was a new SA I would if encountering a security hole, ... I can see some use for the passwd -s part of the crontab script, ...
      (SunManagers)
    • Re: Clarification-Win2k Netstat sockets interpretation
      ... snip.. ... Before I could manually download every security upate and servicepack from MS.com but now...they send you a bit of Cop-code that fails to run unless ALL defences are down ... Are you sure the script from ntsvcfg is benign in addition to being useful? ... You are absolutely correct there HAL, er ah, Sebastian. ...
      (alt.computer.security)
    • [NT] Flaw in Windows Script Engine Could Allow Code Execution
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The Windows Script Engine provides Windows operating systems with the ... blocked by Outlook Express 6.0 and Outlook 2002 in their default ...
      (Securiteam)
    • Re: BUG with RES/SCRIPT/XP-SP2
      ... I consider JavaScript (known to security people as JavaVirus) as one of the Really Top ... to have a bad script cause damage to my machine. ... This security feature is called the "Local Machine Zone Lockdown". ... Tags, and the CDHtmlDialog class in this forum, and got no response. ...
      (microsoft.public.vc.mfc)
    • BUG with RES/SCRIPT/XP-SP2
      ... This security feature is called the "Local Machine Zone Lockdown". ... past week since I started posting problems with the RES Protocol, SCRIPT ... Tags, and the CDHtmlDialog class in this forum, and got no response. ...
      (microsoft.public.vc.mfc)

    Loading