Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Gobbles Releases Apache Exploit
Brian McWilliams, SecurityFocus 2002-06-20

Tool makes it easy to hack vulnerable Apache servers under OpenBSD.

Comments Mode:
Gobbles Releases Apache Exploit 2002-06-20
Anonymous (1 replies)
Gobbles Releases Apache Exploit 2002-06-24
Anonymous
Hackers 2002-06-20
Anonymous (2 replies)
Hackers 2002-06-20
Anonymous2
Hackers 2002-06-21
The Clone (7 replies)
Hackers 2002-06-21
Anonymous (2 replies)
Hackers 2002-06-24
Anonymous Cowardess
Hackers-GO 2002-06-24
omikorn (at) yahoo (dot) com [email concealed] (1 replies)
Re: Hackers-GO 2005-10-26
a Nocturnal student
Hackers 2002-06-21
paralyse
Hackers 2002-06-21
Anonymous (1 replies)
Hackers 2002-06-22
Anonymous
Hackers 2002-06-21
Not Really Anonymous
Hackers 2002-06-21
Anonymous
Hackers 2002-06-21
Anonymous
Hackers 2002-06-25
Anonymous
eEye Scanner 2002-06-21
Dirk (1 replies)
eEye Scanner 2002-06-21
marc (1 replies)
eEye Scanner 2002-06-21
lord aambro (1 replies)
eEye Scanner 2002-06-23
Anonymous (1 replies)
eEye Scanner 2002-06-24
Anonymous
Gobbles Releases Apache Exploit 2002-06-21
nologin (1 replies)
Exploit Attemped on FreeBSD 2002-06-24
Anonymous
I just got the warning this morning when I checked my logs. There is apparently an exploit out for FreeBSD now as, unless the log was faked, this is the attack sequence:

XXX.XXX.XXX.XXX - - [24/Jun/2002:06:19:21 +0900] "GET /poweredby.html HTTP/1.1" 200 17339 "http://www.google.com/search?q=powered+by+freebsd&hl=en&lr=&ie=UTF-8&oe=UTF8&start=90&sa=N" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)"

XXX.XXX.XXX.XXX - - [24/Jun/2002:06:21:25 +0900] ""GET ../.." " 400 345 "-" "-"

XXX.XXX.XXX.XXX - - [24/Jun/2002:06:21:57 +0900] "GET / HTTP/1.1" 200 28178 "-" "-"

XXX.XXX.XXX.XXX - - [24/Jun/2002:06:21:58 +0900] "5" 200 11377 "-" "-"

Search for "powered by freebsd" on Google, try an illegal access ("../..") to get Apache version number ("ServerSignature Off" in httpd.conf will make finding vulnerable servers more difficult), then the final two log entries are repeated indefinately.

When I first saw the announcement and that it wasn't exploitable on FreeBSD, I wasn't too concerned and thought I'd finish testing Apache 2.0 with mod_jk on another machine before bringing it up on the production server. This attack told me that I'd better upgrade NOW!

I'd never heard of Gobbles until now. But it certainly appears to have more useful warnings than CERT, etc. Is their tool responsible for this break-in attempt? Maybe. But this attack has certainly waken me up.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/493/13214#13214
Gobbles Releases Apache Exploit 2002-06-21
<bangular (at) linuxmail (dot) org [email concealed]>
Gobbles Releases Apache Exploit 2002-06-21
Anonymous
Gobbles Releases Apache Exploit 2002-06-21
Anonymous
Gobbles on time 2002-06-21
Anonymous (4 replies)
Gobbles on time 2002-06-21
The Clone
Gobbles on time 2002-06-22
Anonymous
Gobbles on time 2002-06-22
Anonymous (4 replies)
Gobbles on time 2002-06-22
Anonymous
Gobbles on time 2002-06-22
Anonymous (1 replies)
Gobbles on time 2002-06-24
Anonymous
Gobbles should do time 2002-06-22
Anonymous (2 replies)
Gobbles should do time 2002-06-24
Anonymous
Gobbles should do time 2002-06-24
Anonymous
Gobbles on time 2002-06-22
Anonymous (1 replies)
Hacking -v- cracking 2002-06-25
Anonymous
Gobbles on time 2002-06-22
Anonymous
Gobbles Releases Apache Exploit 2002-06-23
Anonymous (2 replies)
Gobbles Releases Apache Exploit 2002-06-23
Anon (1 replies)
Gobbles Releases Apache Exploit 2002-06-25
Penile Implant
Gobbles Releases Apache Exploit 2002-06-25
Not Really Anonymous
Gobbles Releases Apache Exploit 2002-06-24
Anonymous Coward (1 replies)







 

Privacy Statement
Copyright 2009, SecurityFocus