LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-18-2006, 01:05 PM   #16
vbfischer
Member
 
Registered: Jun 2004
Location: Tampa, FL
Distribution: CentOS 3.x
Posts: 33

Original Poster
Rep: Reputation: 15

Yes. I was reading about the exploit in one of the sticky's here. I *think* I've patched things up... We'll see.
 
Old 01-19-2006, 10:59 AM   #17
TigerOC
Senior Member
 
Registered: Jan 2003
Location: Devon, UK
Distribution: Debian Etc/kernel 2.6.18-4K7
Posts: 2,380

Rep: Reputation: 49
You need to update the relevant php app that has the flaw. Install the security module from www.modsecurity.org (your distro probably has a package), insert and activate the module in httpd and also set the rules from modsecurity.org and this should prevent further attacks.
 
Old 01-25-2006, 05:27 AM   #18
benr77
Member
 
Registered: Sep 2004
Location: London, UK
Distribution: Fedora Core 4
Posts: 59

Rep: Reputation: 15
vbfischer - could you tell me where you found details of how to patch up this exploit? I'm currently suffering from the same problem.

Thanks very much
 
Old 01-25-2006, 06:22 AM   #19
vbfischer
Member
 
Registered: Jun 2004
Location: Tampa, FL
Distribution: CentOS 3.x
Posts: 33

Original Poster
Rep: Reputation: 15
I deleted the file in question. Updated my PHP apps. Then I installed the security module (www.modsecurity.org).

Then I purchased the "Apache Security" book from Ivan Ristic
http://www.amazon.com/gp/product/059...books&v=glance

Hope that helps.
 
Old 01-25-2006, 06:25 AM   #20
benr77
Member
 
Registered: Sep 2004
Location: London, UK
Distribution: Fedora Core 4
Posts: 59

Rep: Reputation: 15
Thanks for that - were the files you deleted all living in /tmp ?? Or were there any others elsewhere on the filesystem?

So far I've removed files from /tmp but haven't worked out how they got there - i.e. what application was compromised to permit the exploit
 
Old 01-25-2006, 11:48 AM   #21
TigerOC
Senior Member
 
Registered: Jan 2003
Location: Devon, UK
Distribution: Debian Etc/kernel 2.6.18-4K7
Posts: 2,380

Rep: Reputation: 49
From what I have seen they operate as the user www-data or whatever your apache user is called. Have a look at your httpd.conf. To establish all the files owned by this user on the system do from a consol find -user <user_name> eg www-data.
Basically the intruder has used the fault in the application to connect a php hacking tool to give them the ability to upload software to your system. The scary part is that they probably had access to your whole file system as the apache user.

Last edited by TigerOC; 01-25-2006 at 11:51 AM.
 
Old 01-25-2006, 12:49 PM   #22
benr77
Member
 
Registered: Sep 2004
Location: London, UK
Distribution: Fedora Core 4
Posts: 59

Rep: Reputation: 15
Thanks for that TigerOC - I have searched for all files owned by my "apache" user and it's only turned up expected results. Hopefully I've removed all the files that the malicious user added.

However, I did see that at least one of the files created was owned by root - so presumably this means they were able to execute a root shell and that could mean a huge amount more trouble.
 
Old 01-25-2006, 02:14 PM   #23
TigerOC
Senior Member
 
Registered: Jan 2003
Location: Devon, UK
Distribution: Debian Etc/kernel 2.6.18-4K7
Posts: 2,380

Rep: Reputation: 49
You need to check whether the file owned by root was created by the intruder. If they got root access then you need to pull the server, image the drive if you want to do forensics on it, and then reformat the drive.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
connecting a host to internet thru another host (both running suse9.3) rcbell Linux - Networking 1 12-17-2005 05:35 PM
Resolving <www.some remote host>.... failed: Host not found. koodoo Linux - Newbie 2 06-27-2005 08:48 AM
procmail and spam -- do not send out of office auto replay to spam draix Linux - Software 0 12-30-2004 08:35 AM
What other anti-spam for Linux that can be used, other than Spam assassin? johnportiz Linux - Software 6 01-27-2004 03:17 AM
Unknown Host <Linuxmachinename> / Unable to ping by host name nishi_k_79 Linux - Networking 4 11-01-2003 01:24 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:06 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration