#23373 [Bgs]: Possible security vulnerability: bindshell found running
| From: | dyls at dylansmith dot co dot im | Date: | Sun, 27 Apr 2003 19:23:31 +0000 |
| Subject: | #23373 [Bgs]: Possible security vulnerability: bindshell found running | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-38519@lists.php.net to get a copy of this message | ||
ID: 23373
User updated by: dyls at dylansmith dot co dot im
Reported By: dyls at dylansmith dot co dot im
Status: Bogus
Bug Type: Unknown/Other Function
Operating System: Linux 2.4.19
PHP Version: 4.3.1
New Comment:
Mea culpa. Further examination of the logs showed the
exact problem. Good job I had ptrace patched, really.
Previous Comments:
------------------------------------------------------------------------
[2003-04-27 12:33:15] magnus@php.net
After a quick search on google I found these results:
http://www.securityfocus.com/archive/1/301811/2002-11-25/2002-12-01/0
http://packetstormsecurity.nl/0009-exploits/thatware.txt
http://www.securitytracker.com/alerts/2002/Dec/1005733.html
which probably explains how someone managed exploit your
machine. Patches are also included with the reports for
these issues, there are several.
If you find proof that it isn't related to ThatWare, you
can open the report again.
------------------------------------------------------------------------
[2003-04-27 12:12:11] rasmus@php.net
What makes you think that this isn't a ThatWare-specific issue?
------------------------------------------------------------------------
[2003-04-27 12:03:12] dyls at dylansmith dot co dot im
I didn't witness this actually in progress - it happened a
short while before I logged on.
I have a PHP news site running ThatWare. It looks like an
attacker managed to get a file /tmp/bindshell uploaded and
executed. The attacker was trying to exploit the ptrace()
vulnerability (which I have implemented a workaround to
prevent, fortunately). I can't find anything suspicious in
the HTTP logs, but bindshell owned by apache with the name
in the process table 'th1s iz my 3l33t backdoor' was
running on port 1234/tcp, and its CWD was set to the
virtual host of the PHP news site.
I will continue to look for details on this and update the
bug report if I find anything significant.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=23373&edit=1