It appears you have not registered with our community. To register please click here ...

Author Topic: Phishing via Gamma Web Shell  (Read 1838 times)

dynaweb

  • <b>Canine Deamon</b>
  • Administrator
  • Sr. Member
  • *****
  • Posts: 493
  • Karma: +10/-0
  • Generic personal text here ...
    • MSN Messenger - danno_d_manno@yahoo.com
    • View Profile
    • DynaWeb Designs
    • Email
Phishing via Gamma Web Shell
« on: December 17, 2005, 11:33:45 AM »
Just a security-related heads-up for admins and account holders.
 
One of our servers was reported to spamcop on the 15th for sending of paypal phishing scam emails. As the administrator of the server, I was tasked to finding the source of the offending email and stopping it.
 
After searching through the server logs for the better part of a day, the suexec_log revealed a suspicious script being accessed near the same time that the mail log reported the message was sent. The script was under someone\'s cgi-bin and called mt.cgi. This was an extremely clever move on the part of the perpetrator since the file name mt.cgi is a common file name used for the popular script "Movable Type". Our client\'s mt.cgi was uploaded on the day that the spam was sent, which tipped me off to take a look at it closer.
It appears that a domain user had some files in his cgi-bin named upload.cgi and formmail.cgi. It was only a matter of time before someone on the internet figured it out and uploaded the shell script Gamma Web Shell (the mt.cgi) and blasted out this SPAM to hundreds of victims.
 
We are informing the client of the danger of insecure scripts on his account and in the meantime have suspended his account and taken away cgi permission.
 
WATCH YOUR UPLOAD SCRIPTS! This is the second time this month we have had a server abuse problem due to neglected upload scripts.
 
I hope this is helpful to you.  If you have any more information on phishing or other exploits using Gamma Web Shell, post it here.
« Last Edit: January 15, 2006, 12:39:48 AM by dynaweb »
Those who cannot learn from history are doomed to repeat it. -- Linux learns.

zelo

  • Super Moderator
  • Global Moderator
  • Sr. Member
  • *****
  • Posts: 264
  • Karma: +10/-0
    • ICQ Messenger - 233717
    • MSN Messenger - webmaster@zelo.com
    • Yahoo Instant Messenger - zelo@yahoo.com
    • View Profile
    • http://www.zelo.com
    • Email
Phishing via Gamma Web Shell
« Reply #1 on: December 17, 2005, 01:14:51 PM »
Quote from: dynaweb
As the administrator of the server, I was tasked to finding the source of the offending email and stopping it.

It was only a matter of time before someone on the internet figured it out and uploaded the shell script Gamma Web Shell (the mt.cgi) and blasted out this SPAM to hundreds of victims.
 


Has the server been blacklisted, if so what server is it?

I\'m sure it was millions not hundreds.

dynaweb

  • <b>Canine Deamon</b>
  • Administrator
  • Sr. Member
  • *****
  • Posts: 493
  • Karma: +10/-0
  • Generic personal text here ...
    • MSN Messenger - danno_d_manno@yahoo.com
    • View Profile
    • DynaWeb Designs
    • Email
Phishing via Gamma Web Shell
« Reply #2 on: January 15, 2006, 12:36:50 AM »
Fortunately, our web server IP was not blacklisted since we were able to diagnose and fix the problem so quickly.
Those who cannot learn from history are doomed to repeat it. -- Linux learns.

 

Related Topics

  Subject / Started by Replies Last post
6 Replies
4083 Views
Last post July 06, 2008, 11:37:34 AM
by nebula
0 Replies
549 Views
Last post August 21, 2005, 09:57:05 PM
by SpamTalk.net
0 Replies
575 Views
Last post November 29, 2005, 07:41:30 PM
by SpamTalk.net
0 Replies
180 Views
Last post December 18, 2005, 09:28:31 AM
by Linux News
4 Replies
1792 Views
Last post January 09, 2006, 09:48:08 PM
by dynaweb