LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-02-2013, 03:44 AM   #1
newbie14
Member
 
Registered: Sep 2011
Posts: 646

Rep: Reputation: Disabled
Any known attack using KoolTabs tool.


Dear All,
I notice there is two lines /KoolTabs/kooltabs.php?32981a13284db7a9021131df49e6cd203 and /KoolTabs/styles/silver/silver.css in my log 403 Not Found error. We are wondering as risk via this tool or any known penetration so that we can stop using it too.
 
Old 11-02-2013, 01:07 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by newbie14 View Post
403 Not Found
If its not installed then you don't need to think about it.
 
Old 11-02-2013, 01:29 PM   #3
newbie14
Member
 
Registered: Sep 2011
Posts: 646

Original Poster
Rep: Reputation: Disabled
Dear Unspawn,
It is installed just happened that is not the right folder it managed to traverse too.
 
Old 11-02-2013, 03:42 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by newbie14 View Post
It is installed just happened that is not the right folder it managed to traverse too.
Then check the vendor for version / vulnerability reports, update if necessary and move the files to the right directory?..
 
Old 11-03-2013, 02:43 AM   #5
newbie14
Member
 
Registered: Sep 2011
Posts: 646

Original Poster
Rep: Reputation: Disabled
Dear Unspawn,
For example I am using is say folder /abc/v1/kooltabs but the error was found to be /kooltabs. So it means they have attempted to scan for it right?
 
Old 11-03-2013, 03:29 AM   #6
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by newbie14 View Post
So it means they have attempted to scan for it right?
Like other tools Logwatch only analyses events leaving the final vuln / not vuln verdict to the person doing the analysis. So if the resource was searched for in the cause of a regular browsing session (grep access / error logs for IP address) then the developer could have made an error but if other resources include only often scanned for ones like web-based management panels or other commonly known vulnerabilities then it was likely scanned for.
 
Old 11-03-2013, 03:44 AM   #7
newbie14
Member
 
Registered: Sep 2011
Posts: 646

Original Poster
Rep: Reputation: Disabled
Dear Unspawn,
I have google on the kooltabs so far did not find any vuln linking to it either. I dont really get you here "So if the resource was searched for in the cause of a regular browsing session (grep access / error logs for IP address) then the developer could have made an error but if other resources include only often scanned for ones like web-based management panels or other commonly known vulnerabilities then it was likely scanned for." What do you mean here" You mean to first look for access and error logs is it? Ok based on the IP you want to determine is it valid access is it ? I dont get you here "developer could have made an error" ? What error you mean on programming or interpreting the results?
 
Old 11-03-2013, 06:46 AM   #8
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by newbie14 View Post
You mean to first look for access and error logs is it? Ok based on the IP you want to determine is it valid access is it ?
Yes. Just grep your access and error logs for that particular IP address, about 10 to 20 lines leading up to the KoolTabs one should do, and post the output here.
 
Old 11-03-2013, 10:36 AM   #9
newbie14
Member
 
Registered: Sep 2011
Posts: 646

Original Poster
Rep: Reputation: Disabled
Dear Unspawn,
Something puzzle me here now I took all my log file for few months n when through manually. I notice this quite a number of times and what puzzle me is that most of the Directory index forbidden by Options directive have some referer but this one dont have. I am worried that they know my directory structure and trying to attack. Could it be any scanners?

Quote:
[Sun Oct 13 12:33:29 2013] [error] [client 103.246.38.196] Directory index forbidden by Options directive: /var/www/html/*******/
[Sun Oct 13 12:33:30 2013] [error] [client 103.246.38.196] File does not exist: /var/www/html/images
[Sun Oct 13 12:33:30 2013] [error] [client 103.246.38.196] Directory index forbidden by Options directive: /var/www/html/******/images/
[Sun Oct 13 12:33:51 2013] [error] [client 103.246.38.196] Directory index forbidden by Options directive: /var/www/html/******/KoolTabs/
 
Old 11-03-2013, 10:46 AM   #10
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Error log has differently formatted lines, not the same as access log.
 
Old 11-03-2013, 11:01 AM   #11
newbie14
Member
 
Registered: Sep 2011
Posts: 646

Original Poster
Rep: Reputation: Disabled
Dear Unspawn,
Below are some of it from the access log.

Quote:
103.246.38.196 - - [13/Oct/2013:12:33:28 +0800] "GET /***** HTTP/1.1" 301 234 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; InfoPath.1; .NET CLR 2.0.50727; .NET CLR 1.1.4322; MS-RTC LM 8; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)"
103.246.38.196 - - [13/Oct/2013:12:33:29 +0800] "GET /****/ HTTP/1.1" 403 206 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; InfoPath.1; .NET CLR 2.0.50727; .NET CLR 1.1.4322; MS-RTC LM 8; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)"
103.246.38.196 - - [13/Oct/2013:12:33:30 +0800] "GET /****/images HTTP/1.1" 301 241 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; InfoPath.1; .NET CLR 2.0.50727; .NET CLR 1.1.4322; MS-RTC LM 8; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)"
103.246.38.196 - - [13/Oct/2013:12:33:30 +0800] "GET /images HTTP/1.1" 404 204 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; InfoPath.1; .NET CLR 2.0.50727; .NET CLR 1.1.4322; MS-RTC LM 8; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)"
103.246.38.196 - - [13/Oct/2013:12:33:31 +0800] "GET / HTTP/1.1" 200 30 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; InfoPath.1; .NET CLR 2.0.50727; .NET CLR 1.1.4322; MS-RTC LM 8; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)"


103.246.38.196 - - [13/Oct/2013:12:33:51 +0800] "GET /******/KoolTabs HTTP/1.1" 301 243 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; InfoPath.1; .NET CLR 2.0.50727; .NET CLR 1.1.4322; MS-RTC LM 8; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)"
103.246.38.196 - - [13/Oct/2013:12:33:51 +0800] "GET /******/KoolTabs/ HTTP/1.1" 403 215 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; InfoPath.1; .NET CLR 2.0.50727; .NET CLR 1.1.4322; MS-RTC LM 8; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)"
 
Old 11-03-2013, 11:09 AM   #12
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Apart from accessing "/" these are all 30x to 40x type return codes. No harm done, the IP seems to be a scraper, but if you don't like it feel free to use something like fail2ban + ipset to block access.
 
Old 11-03-2013, 11:15 AM   #13
newbie14
Member
 
Registered: Sep 2011
Posts: 646

Original Poster
Rep: Reputation: Disabled
Dear Unspawn,
Great but I want to learn this too. How do you know its scraper ? So which type of codes are harm full ? I have ban the ip from my firewall itself. But what surprises me is that the have traverse through my directory that worries me. They know my main directory and sub directories too. Any idea how they do ?
 
Old 11-04-2013, 01:20 AM   #14
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by newbie14 View Post
How do you know its scraper ?
Search for the IP address using your favorite search engine.


Quote:
Originally Posted by newbie14 View Post
So which type of codes are harm full ?
A return code that indicates the remote host may access resources could mean a risk but that's not a given, it's only by taking all things into account you see what behavior the host has.


Quote:
Originally Posted by newbie14 View Post
But what surprises me is that the have traverse through my directory that worries me.
Depending on access patterns, four lines being not enough really, it's likely automated scanning for common resources, not a thought out attack.
 
Old 11-04-2013, 01:54 AM   #15
newbie14
Member
 
Registered: Sep 2011
Posts: 646

Original Poster
Rep: Reputation: Disabled
Dear Unspawn,
Yes I search and got this link http://www.projecthoneypot.org/ip_103.246.38.196. So I guess we got to see the return 200 and then map with other behavior to ascertain if its legitimate or not ? I guess this is challenging rite. Actually can a scrapper know what are the directories available in my server from /var/www/html ? This scraper first when to one of my main directory and then only the kooltabs.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Apache / Squid - DoS attack tool in the wild.. farslayer Linux - Security 5 06-21-2009 12:26 AM
LXer: Attack on SSL Users Discovered, Tool Sources Released LXer Syndicated Linux News 0 02-25-2009 05:30 AM
tool which performs an attack against an encryption key ddaas Linux - Security 1 03-13-2006 08:10 PM
possible BIOS attack tool??? Paul6253 Linux - Security 8 11-05-2004 06:13 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:02 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration