Go Back   HowtoForge Forums | HowtoForge - Linux Howtos and Tutorials > ISPConfig 2 > General

Do you like HowtoForge? Please consider supporting us by becoming a subscriber.
Reply
 
Thread Tools Display Modes
  #1  
Old 2nd March 2011, 21:37
dayjahone dayjahone is offline
Senior Member
 
Join Date: Jan 2007
Posts: 385
Thanks: 27
Thanked 0 Times in 0 Posts
Default Security Flaw in ISPC2

With the latest version of ISPConfig installed, attackers are able to execute arbitrary code as admispconfig on the server (uid=1001). They have used this exploit to upload email addresses to /tmp and /dev/shm and send spam email to the addresses. They have also been able to run a backdoor perl shell (dc.txt). We are unable to identify the security exploit allowing them to execute code in the first place.
Reply With Quote
Sponsored Links
  #2  
Old 3rd March 2011, 01:14
till till is offline
Super Moderator
 
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 31,911
Thanks: 693
Thanked 4,198 Times in 3,213 Posts
Default

Do you have phpmyadmin installed? Then the hackers most likely got in trough phpmyadmin, there were several problems in phpmyadmin detected in the last months. A installed phpmyadmin package runs under the user admispconfig, thats why this can be easily mixed up with a ispconfig problem.
__________________
Till Brehm
--
Get ISPConfig support and the ISPConfig 3 manual from ispconfig.org.
Reply With Quote
  #3  
Old 3rd March 2011, 02:05
dayjahone dayjahone is offline
Senior Member
 
Join Date: Jan 2007
Posts: 385
Thanks: 27
Thanked 0 Times in 0 Posts
Default

Yes, I do have phpmyadmin installed. Any idea how to solve it?
Reply With Quote
  #4  
Old 3rd March 2011, 11:30
till till is offline
Super Moderator
 
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 31,911
Thanks: 693
Thanked 4,198 Times in 3,213 Posts
 
Default

First you should remove the current phpmyadmin package:

rm -r /home/admispconfig/ispconfig/web/phpmyadmin
rm /home/admispconfig/ispconfig/web/phpmyadmin.tar.gz
rm -r /home/admispconfig/ispconfig/web/tools/tools/phpmyadmin

and install a new one trough ispconfig. Jonas is releasing new phpmyadmin packages for ispconfig on a regular basis, the latest package can be found here:

http://www.howtoforge.com/forums/showthread.php?t=47423

Then you will have to try to find the files that the hacker uploaded. If you know the creation date of the dc.txt, you can e.f. scan for files that date, especially interesiting are files inside /home/admispconfig/. Also look for files owned by the user admispconfig that are in unusual places (outside of /home/admispconfig). If you are unsure if a file belongs to ispconfig, feel free to post the path here.

You should then check your system with rkhunter and chkrootkit in case that the attacker was able to get root permissions.
__________________
Till Brehm
--
Get ISPConfig support and the ISPConfig 3 manual from ispconfig.org.
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
ISPConfig 3 Security mnzava Installation/Configuration 8 8th March 2010 11:00
Access Denied by security policy Sndan General 2 4th February 2010 08:59
Unable to install ISPConfig bdonecker Installation/Configuration 21 26th May 2009 08:20
Security Flaw: I Don't think this is normal... pg001 General 4 12th July 2008 21:31
SE linux problem when security context is modified raj123 Technical 1 28th June 2006 08:57


All times are GMT +2. The time now is 06:01.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.