#23373 [Fbk->Bgs]: Possible security vulnerability: bindshell found running

From: Date: Sun, 27 Apr 2003 17:33:16 +0000
Subject: #23373 [Fbk->Bgs]: Possible security vulnerability: bindshell found running
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-38515@lists.php.net to get a copy of this message
ID: 23373 Updated by: magnus@php.net Reported By: dyls at dylansmith dot co dot im -Status: Feedback +Status: Bogus Bug Type: Unknown/Other Function Operating System: Linux 2.4.19 PHP Version: 4.3.1 New Comment: After a quick search on google I found these results: http://www.securityfocus.com/archive/1/301811/2002-11-25/2002-12-01/0 http://packetstormsecurity.nl/0009-exploits/thatware.txt http://www.securitytracker.com/alerts/2002/Dec/1005733.html which probably explains how someone managed exploit your machine. Patches are also included with the reports for these issues, there are several. If you find proof that it isn't related to ThatWare, you can open the report again. Previous Comments: ------------------------------------------------------------------------ [2003-04-27 12:12:11] rasmus@php.net What makes you think that this isn't a ThatWare-specific issue? ------------------------------------------------------------------------ [2003-04-27 12:03:12] dyls at dylansmith dot co dot im I didn't witness this actually in progress - it happened a short while before I logged on. I have a PHP news site running ThatWare. It looks like an attacker managed to get a file /tmp/bindshell uploaded and executed. The attacker was trying to exploit the ptrace() vulnerability (which I have implemented a workaround to prevent, fortunately). I can't find anything suspicious in the HTTP logs, but bindshell owned by apache with the name in the process table 'th1s iz my 3l33t backdoor' was running on port 1234/tcp, and its CWD was set to the virtual host of the PHP news site. I will continue to look for details on this and update the bug report if I find anything significant. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=23373&edit=1

« previous php.bugs (#38515) next »