Re: awstats holes being exploited in the wild

From: John Pettitt (jpp_at_cloudview.com)
Date: 03/15/05

  • Next message: Skip Carter: "Re: awstats holes being exploited in the wild"
    Date: Tue, 15 Mar 2005 13:32:23 -0800
    To: Jeremy Anderson <jeremy@angelar.com>
    
    

    Jeremy Anderson wrote:

    >Greetings, everyone. This is my first post to the list, so please be forgiving.
    >If the formatting on this is wonky, it can also be viewed at http://www.angelar.com/~jeremy/hacked.html
    >
    >
    >On March 2nd, 2005, a server for which I am responsible received it's
    >first attempted break-in via awstats, exploiting cve CAN-2005-0116 (http://www.securityfocus.com/bid/12298):
    >
    >
    >
    >
    Several of my servers have been swept by awstats attacks in the last
    three days from four addresses. The attack script in common use seems
    to have a distinct signature in that it has a double // in GET //cgi-bin
    at the start of the URL. such as

    210.119.247.4 - - [09/Mar/2005:08:33:57 -0800] "GET
    //cgi-bin/awstats.pl?configdir=|%20id%20| HTTP/1.1" 404 217

    Attacking hosts:
    216.145.9.34
    210.225.88.43
    210.119.247.4
    206.61.118.236

    John


  • Next message: Skip Carter: "Re: awstats holes being exploited in the wild"

    Relevant Pages

    • common cookie db?
      ... The goal is to track common cookies to applications. ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Cross site scripting and other web attacks before hackers do! ...
      (Pen-Test)
    • Re: [PATCH resend][CRYPTO]: RSA algorithm patch
      ... in security there is always a threshold, ... matter) stands up to the kind of attacks we're talking about now. ... we're talking about a common implementation. ... if that isn't the case more questions pop up, like where the security threshold ...
      (Linux-Kernel)
    • Re: ASTRO any clues in the message source?
      ... or some other common feature??? ... It would help if somone could pull the plug on Suddenlink (or if their ... It is high time that irresponsible ISPs ... it cannot cope with malicious attacks of this type. ...
      (sci.astro.amateur)
    • Re: Cooks 6th Test hundred
      ... I imagine it's a mixture of a fine young player and poor Test bowling ... attacks, Australia aside. ... and it not being particularly common for a 22 year old to have played ...
      (uk.sport.cricket)
    • Re: Longstaff, Quarterstaff, Power Attack, and Flurry
      ... going for TWF is a lot more common than rapid shot. ... Take -2 to all attacks, ... Identify the mechanical difference between RS and Flurry. ...
      (rec.games.frp.dnd)