PHP Web Host - Quality Web Hosting For All PHP Applications Free RavenNuke(tm) Add Ons
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
webservant
Worker
Worker


Joined: Feb 26, 2006
Posts: 168
Location: Springfield, MA

PostPosted: Mon Jun 21, 2010 6:58 am Reply with quote Back to top

I haven't seen GCalendar targeted before. So, I figure that I'd share it with the community.

Code:
Created By: NukeSentinel(tm) 2.6.03
Date & Time: 2010-06-21 00:20:00 EDT GMT -0400
Blocked IP: 88.191.94.*
User ID: Anonymous (1)
Reason: Abuse-CLike
--------------------
Referer: none
User Agent: libwww-perl/5.805
HTTP Host:
Only registered users can see links on this board!
Get registered or login to the forums!

Script Name: /modules.php
Query String: name=GCalendar&fil...wday&y=2007&m=12&d=23&e=1/*.php?option=com_gcalendar&controller=../../../../../../../../../../../../../../../proc/self/environ
Get String: name=GCalendar&fil___wday=&y=2007&m=12&d=23&e=1/*.php?option=com_gcalendar&controller=../../../../../../../../../../../../../../../proc/self/environ\0
Post String: Not Available
Forwarded For: none
Client IP: none
Remote Address: 88.191.94.188
Remote Port: 43792
Request Method: GET
--------------------
Who-Is for IP
View user's profile Send private message Visit poster's website AIM Address
Palbin
Site Admin


Joined: Mar 30, 2006
Posts: 1921
Location: Pennsylvania

PostPosted: Mon Jun 21, 2010 7:05 am Reply with quote Back to top

They must be trying that because of the reference to gCalendar, but there is nothing to worry about even without sentinel. I'm not sure what this attack is trying to do, but it has absolutely no correlation to the gCalendar that we are using.
View user's profile Send private message Visit poster's website
webservant
Worker
Worker


Joined: Feb 26, 2006
Posts: 168
Location: Springfield, MA

PostPosted: Mon Jun 21, 2010 8:41 am Reply with quote Back to top

Thanks for the quick response. I was comforted that Sentinel blocked it. However, knowing what is coming is gives us the ability to harden the code - but that's obviously not necessary.
View user's profile Send private message Visit poster's website AIM Address
fkelly
Moderator


Joined: Aug 30, 2005
Posts: 2783
Location: near Albany NY

PostPosted: Mon Jun 21, 2010 10:17 am Reply with quote Back to top

I think it's a google calendar attack. The "G" is just a coincidence. LOL, I was going to say the G is just a string but I won't.

You can Google the proc/self/environ attack. It appears to be aimed at UNIX type systems that are not up to date.
View user's profile Send private message Visit poster's website
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2010 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum