visitor (0 QPoints)
  • FR
  • EN
  • NL
  • DE
  • ES
315 experts, 1193 registered users, 1659 questions already answered
European Experts Exchange, the very best site for high-quality IT solutions

New Improved Search!

 


05/10/2011 1h30 : Steve Jobs is dead, the father of Apple ][ is gone, we are all orphaned.

Support :: Feedback :: remote file inclusion attack


By: pjssms Portugal  Date: 23/10/2007 20:32:03  English  Points: 0 Status: Answered
Quality : Excellent
Hello,

I would like to know more details about the attack from 85.17.116xxx

I am the server admnistrator and I would like to fix the issue and prevent the situation.

Thank you,

Paulo Santos
By: VGR Date: 26/10/2007 23:42:52 English  Type : Comment
hi, sorry for the delay in noticing your message.
the 85.17.116.* machine is used to remotely test one server (this one) as vulnerable to RFI attacks, in order to use it for spamming or participating in DDoD attacks for sure. The attack (or probe) vector involves trying to reach a file situated on an other server ; in our case http://201.37.71.117:8090/cmd.txt

that file was dropped in using other security holes, mainly permissive upload scripts, like in a lot of blog or forum packages.

closing the hole on your side involves either patching your software for known RFI or "open http relay" vulnerabilities, or killing viral processes in case you got infected by a worm (sh*t happens and then it hits the fan)

I don't have much more details to provide, because this server is invulnerable so far, but I'm willing to send you a list of people which said "we fixed the problem", so that you may contact them. You'll have an email soon.

regards

Do register to be able to answer

EContact
browser fav
page generated in 334.470990 milliseconds

Why Google AdSense ads ?

compteur
 Ranking-Hits PageRank for this page