#23373 [Opn->Fbk]: Possible security vulnerability: bindshell found running

From: Date: Sun, 27 Apr 2003 17:12:12 +0000
Subject: #23373 [Opn->Fbk]: Possible security vulnerability: bindshell found running
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-38514@lists.php.net to get a copy of this message
ID: 23373 Updated by: rasmus@php.net Reported By: dyls at dylansmith dot co dot im -Status: Open +Status: Feedback Bug Type: Unknown/Other Function Operating System: Linux 2.4.19 PHP Version: 4.3.1 New Comment: What makes you think that this isn't a ThatWare-specific issue? Previous Comments: ------------------------------------------------------------------------ [2003-04-27 12:03:12] dyls at dylansmith dot co dot im I didn't witness this actually in progress - it happened a short while before I logged on. I have a PHP news site running ThatWare. It looks like an attacker managed to get a file /tmp/bindshell uploaded and executed. The attacker was trying to exploit the ptrace() vulnerability (which I have implemented a workaround to prevent, fortunately). I can't find anything suspicious in the HTTP logs, but bindshell owned by apache with the name in the process table 'th1s iz my 3l33t backdoor' was running on port 1234/tcp, and its CWD was set to the virtual host of the PHP news site. I will continue to look for details on this and update the bug report if I find anything significant. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=23373&edit=1

« previous php.bugs (#38514) next »