
1st January 2008, 16:32
|
|
Member
|
|
Join Date: Aug 2007
Location: Paris, France
Posts: 47
Thanks: 4
Thanked 1 Time in 1 Post
|
|
Hello Falko,
I also found some exploits installed in the backups of the web sites but not in the main web sites !
Seems that my exclusion rules are not properly set up
When I make a safe copy of the web sites I host I usually just make a brutal "cp" in a "backup" directory, seems that apache has access to that sub directory (I thought only document root was accessible).
ideas ?
regards,
Arnaud
|

1st January 2008, 21:55
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 41,665
Thanks: 1,896
Thanked 2,595 Times in 2,446 Posts
|
|
Do you use vulnerable web applications? Do you use PHP Safe Mode?
|

2nd January 2008, 08:00
|
|
Member
|
|
Join Date: Aug 2007
Location: Paris, France
Posts: 47
Thanks: 4
Thanked 1 Time in 1 Post
|
|
I host a lot of joomla web sites which don't support PHP_SafeMode. The difficulty for a joomla web site is to find an hosting server with the SafeMode turned off.
Now I believe I will reconsider those web sites and encourage the use of Drupal as CMS instead.
regards,
Arnaud
|

2nd January 2008, 11:48
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 31,911
Thanks: 693
Thanked 4,198 Times in 3,213 Posts
|
|
Quote:
|
I host a lot of joomla web sites which don't support PHP_SafeMode. The difficulty for a joomla web site is to find an hosting server with the SafeMode turned off.
|
I know this problem, its common with joomla. I had a joomla site on one of the servers that I maintained, the owner of the site did not install all joomla patches immediately when they get released. The website got hacked serveral times and only a strict php setup with safemode on prevented that the hackers were able to break out of the website directory. The last time it was a r57shell too if I remember correctly.
|

4th January 2008, 05:46
|
|
Member
|
|
Join Date: Aug 2007
Location: Paris, France
Posts: 47
Thanks: 4
Thanked 1 Time in 1 Post
|
|
Hello Till,
Do you mean he actually succeeded to make his joomla site operate with phpsafemode turned on ?
I have a question concerning perl scripts ...
The server has been used to run perl scripts sending phishing mail
Since none of my sites actually use perl script I brutaly uninstalled mode_perl ... and still attacks have restarted using perl scripts !!
I looked at http://perl.apache.org/docs/2.0/user/config/config.html
To enable mod_perl built as DSO add to httpd.conf:
LoadModule perl_module modules/mod_perl.so
This setting specifies the location of the mod_perl module relative to the ServerRoot setting, therefore you should put it somewhere after ServerRoot is specified.
If mod_perl has been statically linked it's automatically enabled.
How do I know if it has been statically linked ?
Anyway, removing mod_perl from the machine should have prevented the use of perl scripts, no ?
regards,
Arnaud
|

4th January 2008, 11:24
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 31,911
Thanks: 693
Thanked 4,198 Times in 3,213 Posts
|
|
Quote:
|
Do you mean he actually succeeded to make his joomla site operate with phpsafemode turned on ?
|
Partially. But this guy did use joomla only for edit the text on some pages.
Quote:
|
How do I know if it has been statically linked ?
|
I dont think that its statically linked in one of the common linux distributions.
Quote:
|
Anyway, removing mod_perl from the machine should have prevented the use of perl scripts, no ?
|
Do you have cgi support enabled for the website? Additionally, if php is run without safemode, it can be used to start a perl script even if mod_perl is not loaded.
|

10th May 2009, 15:06
|
|
Senior Member
|
|
Join Date: Sep 2005
Posts: 1,186
Thanks: 60
Thanked 13 Times in 11 Posts
|
|
I just had a similar rkhunter report:
Quote:
Warning: The command '/sbin/chkconfig' has been replaced by a script:
/sbin/chkconfig: a /usr/bin/perl script text executable
|
this hapened while I was still setting up the serevr, I remember, I couldn't find chkconfig, had to look for the package containing it and install it. would rkhunter --propupd remove this warning? I am sure that was me who caused that warning...
|

11th May 2009, 13:19
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 41,665
Thanks: 1,896
Thanked 2,595 Times in 2,446 Posts
|
|
Which distribution are you using? How did you install rkhunter?
|

11th May 2009, 13:33
|
|
Senior Member
|
|
Join Date: Sep 2005
Posts: 1,186
Thanks: 60
Thanked 13 Times in 11 Posts
|
|
its the perfect debian lenny setup for ispcfg3, didn't want to open a new thread as this topic seemed pretty close.
|

12th May 2009, 18:23
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 41,665
Thanks: 1,896
Thanked 2,595 Times in 2,446 Posts
|
|
Debian doesn't use /sbin/chkconfig (that's for RedHat-based distros only).
How did you install rkhunter?
|
| Thread Tools |
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT +2. The time now is 21:18.
|
|
Recent comments
19 hours 56 min ago
1 day 1 hour ago
1 day 5 hours ago
1 day 7 hours ago
1 day 21 hours ago
1 day 21 hours ago
2 days 2 hours ago
2 days 9 hours ago
2 days 9 hours ago
2 days 11 hours ago