RE: Hack attempt
| Newsgroups | gmane.comp.security.linux |
|---|---|
| Message-ID | <[email protected]> |
Hi Norbert, > -----Original Message----- > From: Norbert Crettol [mailto:[email protected]] > Sent: Wednesday, July 21, 2004 5:03 PM > > We've had a undesired visitor, last night, that I discovered in the > reports of tripwire. > > Has someone seen this kind of attack ? (chkrootkit doesn't detect it). > Has someone heard of this www.bosscalvin.com (or www.calvinmumu.org) ? > Is there a way to stop this guy ? His nickname (CaEm) appears in the > the uploaded scripts. this is a "File Injection Bug" attack. As far as I know this script gains access as nobody (or webserver user), reads files placed in /tmp (or where the webserver user can read), places some files an executes them. Problem: Some of your scripts accepts user data without validation. This is the most common way to inject files onto a webserver. Resolution: Shutdown system, clean it up, update it to the latest versions and recheck your scripts. Regards Jan