RE: Hack attempt

[email protected]
Newsgroups gmane.comp.security.linux
Message-ID <[email protected]>
Hi Norbert,

> -----Original Message-----
> From: Norbert Crettol [mailto:[email protected]] 
> Sent: Wednesday, July 21, 2004 5:03 PM
>
> We've had a undesired visitor, last night, that I discovered in the 
> reports of tripwire.
>
> Has someone seen this kind of attack ? (chkrootkit doesn't detect it).
> Has someone heard of this www.bosscalvin.com (or www.calvinmumu.org) ?
> Is there a way to stop this guy ? His nickname (CaEm) appears in the 
> the uploaded scripts.


this is a "File Injection Bug" attack. As far as I know this script gains
access as nobody (or webserver user), reads files placed in /tmp (or where
the webserver user can read), places some files an executes them.

Problem: Some of your scripts accepts user data without validation. This is
the most common way to inject files onto a webserver.

Resolution: Shutdown system, clean it up, update it to the latest versions
and recheck your scripts.

Regards

Jan
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.