Re: Apache attacks

From: Bernie Johnson (bernie_at_e-mich.com)
Date: 01/27/05

  • Next message: David Gillett: "RE: Possible weird/insecure configuration of an ISP router exposed unfiltered to public internet?"
    To: Kenny <kenny@codez.co.uk>
    Date: Thu, 27 Jan 2005 17:55:06 -0500
    
    

    Kenny,

    Look at www.rfxnetworks.com and get APF, BFD and look at the other
    scripts there. This should od what you want and need.

    B. Johnson

    On Wed, 2005-01-26 at 15:56, Kenny wrote:
    > Hi List,
    >
    > Long time reader, first time poster...
    >
    > My server crashed yesturday and I had to restart it, to get it going
    > again. Now everything seems ok, however looking at my
    > /var/log/httpd/access_log.1 shows a visitor to the website posting some
    > big chunks of exploit code (containing a massive nop sled).
    > How do I know if this attacker actually got in or not?
    >
    > This is a redhat fedora core 2 box, and I would describe myself as an
    > "intermediate" linux user.
    >
    > Also, has anyone got any scripts that can detect attacks against apache
    > and ban the ip for a period of time?
    >
    > I will post the exploit on request.
    >
    > Thanks, Kenny

    -- 
    

  • Next message: David Gillett: "RE: Possible weird/insecure configuration of an ISP router exposed unfiltered to public internet?"

    Relevant Pages

    • Re: Anyone know this rootkit (rootkits?)
      ... There's a collection of scripts that checks for various rootkits at: ... sometimes when using an exploited login program, ... and it may have been missed by the attacker. ...
      (Incidents)
    • [UNIX] KisMAC Local Privilege Escalation
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... shell scripts enabled by KisMAC. ... The core issue is that an attacker can ... Load arbitrary kernel modules. ...
      (Securiteam)
    • Re: Interesting webserver intrusion (apache 1.3.31, mod_ssl 2.8.18, php 4.3.7)
      ... since they managed to execute commands via Apache. ... and 30 minutes before one of the scripts was uploaded. ... Sounds like one of the many PHP scripts is exploitable. ... this means that the exploit would allow the attacker to run ...
      (Incidents)
    • Re: CGI scripts
      ... (Otherwise, an attacker might gain read access to scripts, ... I have been distracted with real work, but when I get a second to play with that again, I'll bug a SysAdmin so we can work it out. ...
      (comp.lang.tcl)
    • Re: Top Ten PHP Security Issues, a preliminary list
      ... I'm pretty sure this would still be secure if you ... attacker is able to inject Javascript into your page, ... site is only accessible to scripts originating from the same site. ...
      (comp.lang.php)