#23373 [NEW]: Possible security vulnerability: bindshell found running
| From: | dyls at dylansmith dot co dot im | Date: | Sun, 27 Apr 2003 17:03:12 +0000 |
| Subject: | #23373 [NEW]: Possible security vulnerability: bindshell found running | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-38513@lists.php.net to get a copy of this message | ||
From: dyls at dylansmith dot co dot im
Operating system: Linux 2.4.19
PHP version: 4.3.1
PHP Bug Type: Unknown/Other Function
Bug description: Possible security vulnerability: bindshell found running
I didn't witness this actually in progress - it happened a
short while before I logged on.
I have a PHP news site running ThatWare. It looks like an
attacker managed to get a file /tmp/bindshell uploaded and
executed. The attacker was trying to exploit the ptrace()
vulnerability (which I have implemented a workaround to
prevent, fortunately). I can't find anything suspicious in
the HTTP logs, but bindshell owned by apache with the name
in the process table 'th1s iz my 3l33t backdoor' was
running on port 1234/tcp, and its CWD was set to the
virtual host of the PHP news site.
I will continue to look for details on this and update the
bug report if I find anything significant.
--
Edit bug report at http://bugs.php.net/?id=23373&edit=1
--
Try a CVS snapshot: http://bugs.php.net/fix.php?id=23373&r=trysnapshot
Fixed in CVS: http://bugs.php.net/fix.php?id=23373&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=23373&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=23373&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=23373&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=23373&r=support
Expected behavior: http://bugs.php.net/fix.php?id=23373&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=23373&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=23373&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=23373&r=globals
PHP 3 support discontinued: http://bugs.php.net/fix.php?id=23373&r=php3
Daylight Savings: http://bugs.php.net/fix.php?id=23373&r=dst
IIS Stability: http://bugs.php.net/fix.php?id=23373&r=isapi
Install GNU Sed: http://bugs.php.net/fix.php?id=23373&r=gnused