Re: apache compromised to send spam, need way to check file access

From: Ohmster (notareal_at_emailaddress.com)
Date: 04/26/05


Date: Mon, 25 Apr 2005 22:53:50 GMT

Mike <honey@michaelmoyse.co.uk> wrote in
news:X_adnbpNZ_SmqPDfRVnyvw@pipex.net:

> I took the liberty of running a scan against www.ohmster.com.
>
> You need a firewall as you have a load of ports open and a lot of
> vulnerabilities in the exposed applications.
>
> In my opinion, a rogue perl script is the least of your problems on
this
> machine.
>
> Drop me an email to mike AT michaelmoyse.co.uk and I'll send you a PDF
> of the report. It lists what you need to do to fix the problems.

Oooohh... this is bad.

Okay Mike, I have and use firestarter firewall because it was pretty easy
to install and setup. Got me NAT'ed and online quickly. Was supposed to
only open service ports that were needed at the time. Of course, I have
not messed with it since, other than to forward a few ports to my XP
machine for p2p and gaming. I also enabled network UPnP for Windows
Messenger and run upnpd to enable that network universal plug and play
stuff and do whatever it is that it does for Messenger.

Agreed that the machine is old now and out of date for security. I do
have fedoralegacy for my apt.sources and did a major upgrade with apt-get
a couple of months ago. Got close to 80 packages that way, only one I
really did not want, the rp-pppoe package. I have rp-pppoe-3.5-1
installed and when I tried 3.5-2 years ago, it simply did not work, at
all and had to downgrade back to 3.5-1 again. Forgot all about that and
after the apt upgrade from fedoralegacy, I lost the net again and the
wife was pissed because it took me hours to figure it out and remember
about the rp-pppoe package again.

So what did you find? Detailed analysis would be appreciated,
suggestions, or recommendations too of course. Thank you for your time
and for your help, Mike. You got the right machine. I still have to find
the source of this email spam from apache and will be working on that
unless you come up with something of a higher priority

Email sent and anxiously awaiting your reply. Thanks buddy.

-- 
~Ohmster
ohmster at newsguy dot com


Relevant Pages

  • SUMMARY: T3 and IPFilter
    ... Anthony Florendo and Mike Box ... General consensus was to allow all from the T3 through to the ... Paul ... pfil/IPFilter running....it seems to use different from and to ports ...
    (SunManagers)
  • Re: THIS is the future - but how to make it work? - VOiP
    ... Depending on what type of router you have it's as easy as going to the ports ... Eric Hicks ... "Mike" wrote in message ...
    (microsoft.public.pocketpc)
  • Re: portsentry
    ... Mike wrote: ... >>Since I installed portsentry, after running nmap on my system ... it seems that I have a lot of new open ports like ... > Those ports are opened by your current Portsentry configuration, ...
    (comp.os.linux.security)
  • Re: UPDATE: [wcolburn@nmt.edu: SMTP relay through checkpoint firewall]
    ... Mike> People use the CONNECT method from inside a LAN to make SSL/HTTPS ... Mike> connections through a proxy. ... but can add additional ports or deny even those ...
    (Bugtraq)
  • Re: Change COM port
    ... Mike, other readers and of course I, do appreciate the complete ... back to DOS 6.22, when in connecting up a modem, it had to ... I interpret your advice to be saying that COM3 is assigned to the modem, ... > at least the physical ports found on the back of most computers.. ...
    (microsoft.public.windowsxp.basics)

Quantcast