Get exclusive CAP network offers from top brands

View CAP Offers

I need some linux/SQL security help

[bsa_pro_ad_space id=2]
  • This topic is empty.
Viewing 10 posts - 16 through 25 (of 25 total)
  • Author
    Posts
  • #756312
    Anonymous
    Inactive

    Somehow he is running a VB cron that initiates a TRUNCATE TABLE, then addds all the data back in.. strill tracking the entire process

    IP 75.83.153.248
    – – [10/Dec/2007:18:55:07 -0600

    “GET /phpBB2/cron.php?rand=911745 HTTP/1.1” 200 43 “http://www.allfreechips.com/casino_guide/no-deposit-casinos.html” “Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)”

    #756313
    Anonymous
    Inactive

    If this guy truely came from VA he’s going to get some suprises

    #756321
    prettie
    Member

    Well I told you that there is some cron job:)

    #756333
    Anonymous
    Inactive

    not an actual cron job though :)

    I see now in my FTP log (yes i didnt catch this to start with) im getting hex data transfered to my servers mail system – /home/account/mail/.Sent/cur/ and i am going to guess that is automatically processed as well into somthing.

    user is from
    inetnum: 117.0.0.0 – 117.7.255.255
    netname: VIETEL-VNNIC-VN
    descr: Vietel Corporation
    descr: No 1, Giang Van Minh Street, Ba Dinh District, Hanoi City
    country: VN
    admin-c: LHN1-AP
    tech-c: NMH2-AP
    status: ALLOCATED PORTABLE
    remarks: For spamming matters, mail to *****@viettel.com.vn
    mnt-by: MAINT-VN-VNNIC
    mnt-lower: MAINT-VN-VIETEL
    mnt-routes: MAINT-VN-VIETEL

    Im changing all passwords as we speak and will continue to monitor whats up.

    #756348
    Anonymous
    Inactive

    I pm’ed you a link which may help to find out what kind of attack this is and how to fix it.

    #756353
    Anonymous
    Inactive

    As im going over the hacked links some really piss me off

    like..

    InetBet affiliate id 1471

    #756356
    Anonymous
    Inactive

    Somebody you know? Is that person on CAP?

    #756368
    Anonymous
    Inactive

    nobody I know, and of course the affiliate managers can not reveal anyone.

    #756462
    supervince
    Member

    It looks like the user found a phpbb vulnerability and is doing some XSS. I would search google for phpbb2 exploits and see what comes up. Maybe you will find a patch. If you can’t get it fixed and want to give someone else a shot then send me a pm and I can look into it.

    #756466
    Anonymous
    Inactive

    no phpbb here :)
    it all got moved to VB months ago when I had issues with it, they had access via http://FTP.. all new crptographical passwords accross the board now and heavy log monitoring has shown no more access as of yet :P

Viewing 10 posts - 16 through 25 (of 25 total)