#23373 [Opn->Fbk]: Possible security vulnerability: bindshell found running
| From: | rasmus@php.net | Date: | Sun, 27 Apr 2003 17:12:12 +0000 |
| Subject: | #23373 [Opn->Fbk]: Possible security vulnerability: bindshell found running | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-38514@lists.php.net to get a copy of this message | ||
ID: 23373
Updated by: rasmus@php.net
Reported By: dyls at dylansmith dot co dot im
-Status: Open
+Status: Feedback
Bug Type: Unknown/Other Function
Operating System: Linux 2.4.19
PHP Version: 4.3.1
New Comment:
What makes you think that this isn't a ThatWare-specific issue?
Previous Comments:
------------------------------------------------------------------------
[2003-04-27 12:03:12] dyls at dylansmith dot co dot im
I didn't witness this actually in progress - it happened a
short while before I logged on.
I have a PHP news site running ThatWare. It looks like an
attacker managed to get a file /tmp/bindshell uploaded and
executed. The attacker was trying to exploit the ptrace()
vulnerability (which I have implemented a workaround to
prevent, fortunately). I can't find anything suspicious in
the HTTP logs, but bindshell owned by apache with the name
in the process table 'th1s iz my 3l33t backdoor' was
running on port 1234/tcp, and its CWD was set to the
virtual host of the PHP news site.
I will continue to look for details on this and update the
bug report if I find anything significant.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=23373&edit=1