#23373 [NEW]: Possible security vulnerability: bindshell found running

From: Date: Sun, 27 Apr 2003 17:03:12 +0000
Subject: #23373 [NEW]: Possible security vulnerability: bindshell found running
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-38513@lists.php.net to get a copy of this message
From: dyls at dylansmith dot co dot im Operating system: Linux 2.4.19 PHP version: 4.3.1 PHP Bug Type: Unknown/Other Function Bug description: Possible security vulnerability: bindshell found running I didn't witness this actually in progress - it happened a short while before I logged on. I have a PHP news site running ThatWare. It looks like an attacker managed to get a file /tmp/bindshell uploaded and executed. The attacker was trying to exploit the ptrace() vulnerability (which I have implemented a workaround to prevent, fortunately). I can't find anything suspicious in the HTTP logs, but bindshell owned by apache with the name in the process table 'th1s iz my 3l33t backdoor' was running on port 1234/tcp, and its CWD was set to the virtual host of the PHP news site. I will continue to look for details on this and update the bug report if I find anything significant. -- Edit bug report at http://bugs.php.net/?id=23373&edit=1 -- Try a CVS snapshot: http://bugs.php.net/fix.php?id=23373&r=trysnapshot Fixed in CVS: http://bugs.php.net/fix.php?id=23373&r=fixedcvs Fixed in release: http://bugs.php.net/fix.php?id=23373&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=23373&r=needtrace Try newer version: http://bugs.php.net/fix.php?id=23373&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=23373&r=support Expected behavior: http://bugs.php.net/fix.php?id=23373&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=23373&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=23373&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=23373&r=globals PHP 3 support discontinued: http://bugs.php.net/fix.php?id=23373&r=php3 Daylight Savings: http://bugs.php.net/fix.php?id=23373&r=dst IIS Stability: http://bugs.php.net/fix.php?id=23373&r=isapi Install GNU Sed: http://bugs.php.net/fix.php?id=23373&r=gnused

« previous php.bugs (#38513) next »