Re: [Security-Discuss] apache exploit?

Vincent Danen <vdanen-7Aj/b8uzpy6AmYF/[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On Jan 27, 2005, at 9:39, Jason M Temple wrote:

> Hello,
>
> We are running mandrake official 10.1, with all the latest updates, as 
> a web server.
>
> Apache is at apache2-common-2.0.50-7.2.101mdk.
>
> We were recently nailed by a cracker called ImFlower, who somehow 
> managed to get in using the apache user, and was running elflbl to try 
> and get root perms.  Is the apache level above patched for all the 
> recent exploits that were patched in the apache.org 2.0.52 release?
>
> Any help on this would be appreciated.

No, and because 2.0.52 fixes a security flaw that is only in 2.0.51; 
see:

http://www.apache.org/dist/httpd/Announcement2.html

And since this is 2.0.50, it's not vulnerable.  AFAIK, apache2 is fully 
patched up.  Just checked here:

http://www.apacheweek.com/features/security-20

and it looks like all of the security issues noted are fixed, 
referencing by their CVE names.

Have you determined what web service he maybe got in through?  It's 
quite possible that he compromised a web app or CGI script to gain 
access (apache is just one part of the puzzle).

-- 
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C  A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig (application/pgp-signature, 186 B) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.