{"id":685,"date":"2007-11-19T23:26:30","date_gmt":"2007-11-20T06:26:30","guid":{"rendered":"http:\/\/www.uncle-andrew.net\/blog\/?p=685"},"modified":"2008-06-21T18:10:46","modified_gmt":"2008-06-22T01:10:46","slug":"interesting-php-attack-making-the-rounds","status":"publish","type":"post","link":"http:\/\/www.uncle-andrew.net\/blog\/?p=685","title":{"rendered":"Interesting PHP Attack Making The Rounds&#8230;."},"content":{"rendered":"<p>Those of you who run or maintain Web servers probably already know about this, but it doesn&#8217;t hurt to <a href=\"http:\/\/www.google.com\/\">Google<\/a> it up a bit with another post on the subject.<\/p>\n<p>A while back I cribbed a php script from somewhere online and futzed around with it until I had a little file that would continuously generate an HTML-based record of my visitors: IP address, host name, date, time referrer and OS\/browser. (I take no credit for this whatsoever, save for the ability to cut and paste other people&#8217;s shit together until it more or less works.) It&#8217;s faster and easer than checking the actual IIS logs or generating a complete report, and can be checked from completely outside the firewall without a lot of dangerous port forwarding or tedious VPN.<\/p>\n<p>About three weeks ago I began to notice some interesting hits in my access log. These hits always start with the main address of my blog but end with a regular page identifier (&#8220;?p=&#8221;, as in, &#8220;please take me to page number&#8230;.&#8221;), then a long URL for any of a number of directories on various sites in Russia. It looked really suspicious. At first I took it to be some sort of trackback spam or &#8220;<a href=\"http:\/\/en.wikipedia.org\/wiki\/Sping\">sping<\/a>&#8220;. However, my software is pretty good at trashing these sorts of intrusions, and anyway these didn&#8217;t include a referrer, which is the usual SOP for trackback spammers. After switching to my Mac and donning my +10 <a href=\"http:\/\/www.torproject.org\/\">Tor<\/a> Helmet of Anonymity, I visited one of these sites. I was immediately presented with a screen full of gibberish, a text file containing some dense and (to me) unreadable code. I was getting a little paranoid.<\/p>\n<p>After noodling around for what seemed like hours I found some answers online, courtesy of <a href=\"http:\/\/groups.google.com\/group\/nzphpug\/browse_thread\/thread\/49fe1af519a25318\/5cdd83fe297bd242?lnk=raot\">some folks much smarter than myself<\/a> on a New Zealand PHP user BBS. The page of gibberish, once deobfuscated, appears to be a remote file include attack; an attempt to get my server to access and execute a piece of code from a remote computer. In this case, the code happens to be an <a href=\"http:\/\/en.wikipedia.org\/wiki\/IRC\">IRC<\/a> client. The client would then link up with a group of IRC hosts and set up to exchange files with them, presumably more exploits that would turn my computer into a zombie, using it as a staging ground for attacks on other servers. Pretty cute.<\/p>\n<p>Fortunately a few different aspects of my setup&#8211;including but not limited to a lack of this sort of vulnerability in recent versions of <a href=\"http:\/\/www.wordpress.org\/\">WordPress<\/a>&#8211;kept this attack from having any effect on my system, nor those of most relatively well-maintained servers. But the exploit is obviously making headway somewhere, because the number and variety of these hits in my access log is increasing. And I&#8217;m seeing <a href=\"http:\/\/todd.wallentine.com\/blog\/?p=174\">a lot<\/a> more <a href=\"http:\/\/www.jerry-bell.com\/2007\/11\/19\/php-include-attacks-rolling-on\/\">chatter<\/a> online <a href=\"http:\/\/www.thehouse.net\/2007\/10\/27\/how-to-frustrate-a-trojan-bot-script\/\">about it<\/a> as well&#8230;.considerably more than I found when I was doing my initial search.<\/p>\n<p>It seems for the moment that my system is (reasonably) safe (from this particular attack [knock phenolic resin]). But like I said in the beginning of this, the more people who write about this sort of thing, the greater the overall awareness. Knowledge is power. And power corrupts. Therefore&#8230;.um&#8230;.knowledge corrupts. But not as much as a corrupted server. Pass it on. <img src=\"http:\/\/www.uncle-andrew.net\/blog\/wp-includes\/images\/smilies\/mrgreen.png\" alt=\":mrgreen:\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Those of you who run or maintain Web servers probably already know about this, but it doesn&#8217;t hurt to Google it up a bit with another post on the subject. A while back I cribbed a php script from somewhere online and futzed around with it until I had a little file that would continuously [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-685","post","type-post","status-publish","format-standard","hentry","category-roominations"],"_links":{"self":[{"href":"http:\/\/www.uncle-andrew.net\/blog\/index.php?rest_route=\/wp\/v2\/posts\/685","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.uncle-andrew.net\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.uncle-andrew.net\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.uncle-andrew.net\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.uncle-andrew.net\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=685"}],"version-history":[{"count":0,"href":"http:\/\/www.uncle-andrew.net\/blog\/index.php?rest_route=\/wp\/v2\/posts\/685\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.uncle-andrew.net\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=685"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.uncle-andrew.net\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=685"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.uncle-andrew.net\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=685"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}