Re: Apache attacks

From: Ty Bodell (tebodell_at_gmail.com)
Date: 01/31/05

  • Next message: Joe Hood: "Re: Exchange <--> Outlook Monitoring"
    Date: Mon, 31 Jan 2005 14:55:55 -0600
    To: Kenny <kenny@codez.co.uk>
    
    

    Kenny--
    Checkout http://www.apachesecurity.net Ivan Ristic has some script
    listed for exactly that and a package with the tools you can download.
     Lookout for the book too :-)

    Goodluck,
    Ty Bodell

    On Wed, 26 Jan 2005 20:56:52 +0000, Kenny <kenny@codez.co.uk> wrote:
    > Hi List,
    >
    > Long time reader, first time poster...
    >
    > My server crashed yesturday and I had to restart it, to get it going
    > again. Now everything seems ok, however looking at my
    > /var/log/httpd/access_log.1 shows a visitor to the website posting some
    > big chunks of exploit code (containing a massive nop sled).
    > How do I know if this attacker actually got in or not?
    >
    > This is a redhat fedora core 2 box, and I would describe myself as an
    > "intermediate" linux user.
    >
    > Also, has anyone got any scripts that can detect attacks against apache
    > and ban the ip for a period of time?
    >
    > I will post the exploit on request.
    >
    > Thanks, Kenny
    >


  • Next message: Joe Hood: "Re: Exchange <--> Outlook Monitoring"

    Relevant Pages

    • Re: cross site scripint and post form
      ... cross site scripint and post form ... Its easier with the GET method because, as you have noticed, the attacker ... script tags out of the input with your client code -The attacker can still ...
      (Security-Basics)
    • Re: Strange Attack On A Webserver I Work On
      ... My guess is that this guy definitely was a script kiddie. ... If you Google for the e-mail addresses that appear in the flooder ... >> The attacker replaced all ...
      (Focus-Linux)
    • NextPlace.com E-Commerce ASP Engine
      ... Any attacker can fake messages, and betray the trust of all the people who ... XSS appears and the server allows an attacker to inject & execute scripts. ... and script code will be executed by their web client. ...
      (Bugtraq)
    • vBulletin PHP Forum Version
      ... Cross Site Scripting attacks are the most trusted evil urls when it concerns ... forum messages are always long and contain many parameters. ... XSS appears and the server allows an attacker to inject & execute scripts. ... and script code will be executed by their web client. ...
      (Bugtraq)
    • phpBB 2.06 search.php SQL injection
      ... A vulnerability exists in phpBB 2.06 that could allow an attacker to manipulate SQL ... The search.php script of the application does not sufficiently sanitize the input of the ...
      (Bugtraq)