Re: backdoor named tvic / Kayten / ttyshd download in apache logfile
From: Henning (Henning.Lieder_at_gmail.com)
Date: 04/28/05
- Next message: Security Alert: "SSRT5958 rev.0 - HP OpenView Radia Management Portal (RMP) Radia Management Agent (RMA) Remote Unauthorized Privileged Access and Denial of Service (DoS)"
- Previous message: Anne & Lynn Wheeler: "Re: Good passwords and security priorities"
- In reply to: Chris Kronberg: "Re: backdoor named tvic / Kayten / ttyshd download in apache logfile"
- Next in thread: Chris Kronberg: "Re: backdoor named tvic / Kayten / ttyshd download in apache logfile"
- Reply: Chris Kronberg: "Re: backdoor named tvic / Kayten / ttyshd download in apache logfile"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: 28 Apr 2005 01:00:04 -0700
> Are you sure that your www-data user is/was not part of that group?
no apache runs as www-data:www-data and www-data is only in www-data
> Btw. what does your access log say? If those were GET requests the
> commands given can be reconstructed.
Thats my problem. I searched all access.log's for GET commands around
the Timestamp of the attack. But id didn't find any cgi-bin/php access
with GET at that time.
So i don't know whick script the attack used. I looked at the phpBB
Version but it was a newer Version without serious Security bugs.
I hope my actions secured the system. My Server may be on a list of
"hackable" Servers so there will be more attacks... :(
But luckily it isn't on any Mail Blacklist.
ciao
Henning
- Next message: Security Alert: "SSRT5958 rev.0 - HP OpenView Radia Management Portal (RMP) Radia Management Agent (RMA) Remote Unauthorized Privileged Access and Denial of Service (DoS)"
- Previous message: Anne & Lynn Wheeler: "Re: Good passwords and security priorities"
- In reply to: Chris Kronberg: "Re: backdoor named tvic / Kayten / ttyshd download in apache logfile"
- Next in thread: Chris Kronberg: "Re: backdoor named tvic / Kayten / ttyshd download in apache logfile"
- Reply: Chris Kronberg: "Re: backdoor named tvic / Kayten / ttyshd download in apache logfile"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|