#23373 [Fbk->Bgs]: Possible security vulnerability: bindshell found running
| From: | magnus@php.net | Date: | Sun, 27 Apr 2003 17:33:16 +0000 |
| Subject: | #23373 [Fbk->Bgs]: Possible security vulnerability: bindshell found running | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-38515@lists.php.net to get a copy of this message | ||
ID: 23373
Updated by: magnus@php.net
Reported By: dyls at dylansmith dot co dot im
-Status: Feedback
+Status: Bogus
Bug Type: Unknown/Other Function
Operating System: Linux 2.4.19
PHP Version: 4.3.1
New Comment:
After a quick search on google I found these results:
http://www.securityfocus.com/archive/1/301811/2002-11-25/2002-12-01/0
http://packetstormsecurity.nl/0009-exploits/thatware.txt
http://www.securitytracker.com/alerts/2002/Dec/1005733.html
which probably explains how someone managed exploit your
machine. Patches are also included with the reports for
these issues, there are several.
If you find proof that it isn't related to ThatWare, you
can open the report again.
Previous Comments:
------------------------------------------------------------------------
[2003-04-27 12:12:11] rasmus@php.net
What makes you think that this isn't a ThatWare-specific issue?
------------------------------------------------------------------------
[2003-04-27 12:03:12] dyls at dylansmith dot co dot im
I didn't witness this actually in progress - it happened a
short while before I logged on.
I have a PHP news site running ThatWare. It looks like an
attacker managed to get a file /tmp/bindshell uploaded and
executed. The attacker was trying to exploit the ptrace()
vulnerability (which I have implemented a workaround to
prevent, fortunately). I can't find anything suspicious in
the HTTP logs, but bindshell owned by apache with the name
in the process table 'th1s iz my 3l33t backdoor' was
running on port 1234/tcp, and its CWD was set to the
virtual host of the PHP news site.
I will continue to look for details on this and update the
bug report if I find anything significant.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=23373&edit=1