LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-04-2011, 06:43 AM   #1
nike.stars
LQ Newbie
 
Registered: Jun 2009
Posts: 7

Rep: Reputation: 0
how to block shell file using mod_security


i'm having difficulties (doesn't understand) to create a mod_security rules on my cpanel server (centos5), i try to block a shell file which is being encoded using base64

i had 2 choice to block this kind of script, either by using the filename or using some string which is contained in the file (although it is base64)

anyone can help me to create this rule(s)?
 
Old 07-08-2011, 09:43 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by nike.stars View Post
i try to block a shell file which is being encoded using base64
Is it content being parsed by say PHP or a base64 URI*? Be verbose: examples?

Last edited by unSpawn; 07-09-2011 at 01:57 AM.
 
Old 07-08-2011, 11:46 PM   #3
nike.stars
LQ Newbie
 
Registered: Jun 2009
Posts: 7

Original Poster
Rep: Reputation: 0
it's the php content being encoded in base64 not the url
 
Old 07-10-2011, 10:32 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by nike.stars View Post
it's the php content being encoded in base64 not the url
In /etc/php.ini add a line "disable_functions=eval,base64_decode", restart your web server and see if that works or b0rks other things as well? Also note I asked you to elaborate but seeing you didn't I guess you're happy fighting symptoms instead the cause.

Last edited by unSpawn; 07-10-2011 at 10:34 AM.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
mod_security - exclude one file from checking ddaas Linux - Security 2 05-22-2009 08:37 AM
converting a c shell file to a bash shell file anindyarc Linux - Newbie 2 05-11-2009 03:26 PM
LXer: How to: Restrict Users to SCP and SFTP and Block SSH Shell Access with rssh LXer Syndicated Linux News 0 01-02-2008 12:40 PM
LXer: How to: Restrict Users to SCP and SFTP and Block SSH Shell Access with rssh LXer Syndicated Linux News 0 01-02-2008 12:00 PM
LXer: How to: Restrict Users to SCP and SFTP and Block SSH Shell Access with rssh LXer Syndicated Linux News 0 01-02-2008 10:00 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:37 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration