BugTraq
Apache hacks (./atac, d0s.txt) Apr 29 2005 07:03PM
Andrew Y Ng (ayn AndrewNg com) (10 replies)
Re: Apache hacks (./atac, d0s.txt) May 01 2005 03:11AM
a.list.address (at) gmail (dot) com [email concealed] (a list address gmail com) (1 replies)
Re: Apache hacks (./atac, d0s.txt) May 02 2005 09:35PM
Nick Bright (nick-tech terraworld net)
Re: Apache hacks (./atac, d0s.txt) Apr 30 2005 07:46AM
Chris Umphress (umphress gmail com)
Re: Apache hacks (./atac, d0s.txt) Apr 30 2005 07:17AM
Sagiko (sagiko gmail com)
Re: Apache hacks (./atac, d0s.txt) Apr 30 2005 04:48AM
Daniel Cid (danielcid yahoo com br)
Re: Apache hacks (./atac, d0s.txt) Apr 30 2005 01:55AM
Luiz Henrique (luizhwk inf ufsc br)
Re: Apache hacks (./atac, d0s.txt) Apr 29 2005 11:33PM
Skip Carter (skip taygeta com)
Re: Apache hacks (./atac, d0s.txt) Apr 29 2005 11:21PM
Robert Zilbauer (zilbauer slappy org)
Re: Apache hacks (./atac, d0s.txt) Apr 29 2005 09:49PM
Jay D. Dyson (jdyson treachery net)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Fri, 29 Apr 2005, Andrew Y Ng wrote:

> My server has been seeing some usual activities today, I don't have much
> time to get down to the bottom of things, but after I investigated
> briefly I have decided to disable PERL executable permission for
> www-data (Apache process's user), also locked /var/tmp so www-data
> cannot write to it.
>
> Looks like it ignores all the `kill` signals, not sure how I can
> actually kill it...

Seems a bit premature to call this an "Apache hack." First off,
it's probably not Apache's fault. Judging from what I've seen thus far,
it looks more like a flaw in one of your CGI scripts which allowed someone
to create and execute an arbitrary file in one of the system's most
obvious world-writable directories.

From what I've seen, the script looks like a vanilla, PERL-based
IRC bot. You should be able to kill -9 it via root.

Either way, your system got molested. Take the box offline, back
up your data, audit your CGI scripts and access policies for flaws and
weaknesses, scrub the system, reinstall the OS from trusted media, apply
all the latest patches, bring the box back online, and have a nice day.

- -Jay

( ( _______
)) )) .-"There's always time for a good cup of coffee"-. >====<--.
C|~~|C|~~| \----- Jay D. Dyson -- jdyson (at) treachery (dot) net [email concealed] -----/ | = |-'
`--' `--' `-- Pardon me, but am I on the right planet? --' `------'

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (TreacherOS)
Comment: See http://www.treachery.net/~jdyson/ for current keys.

iD8DBQFCcqv9xzN3WIW0edsRAiVfAKCACT2YlymlkBvDuhMVCHY2zqubOwCffTZm
ZzGeGHgc8KpjDCUx33zhtPg=
=xvyc
-----END PGP SIGNATURE-----

[ reply ]
Re: Apache hacks (./atac, d0s.txt) Apr 29 2005 09:45PM
KF (lists) (kf_lists digitalmunition com)
Re: Apache hacks (./atac, d0s.txt) Apr 29 2005 09:36PM
Steve Kemp (steve steve org uk)


 

Privacy Statement
Copyright 2010, SecurityFocus