Author Topic: Urgent Security Patch for album.pl  (Read 14400 times)

0 Members and 1 Guest are viewing this topic.

Offline Andrew

  • album.pl Hacker
  • ****
  • Posts: 114
  • Karma: +0/-0
  • I love YaBB 1G - SP1!
    • WHITEWATER!
Re:Urgent Security Patch for album.pl
« Reply #15 on: June 24, 2003, 23:37:01 »
Well I just got hit....Lords prayer on my sites, index page.  That'll teach me to not pay attention!  

Should have been checking back here more often.  I don't really know whether they got in via album.pl or my yabb though.

Looks like they infected the server with linux.Osf.8759 (named on server : b.1, kik, y2) a signatured telnet server, a file called inul.htm, password.txt, a log of somesort, a file called ucing txt. which lists some album pl permissions, a un-tgz'd telnet server named 'book' and a replacement of my index page.

Hope I managed to get everything.  I have made the change to the script, as described above.  

Maybe I better take you up on your offer Mike.  Which I apologize for not responding to.  Had a death in the family recently and have been sort of diverted.

thankfully the little turds didn't screw anything up to bad...at least not that I can see.

211.9.194.185 is where the original attack came from I believe...thouhg it appears that several other IP's accessed the girsang.pl (telnet server) on my host.

Andrew



« Last Edit: June 25, 2003, 00:11:29 by Andrew »

Offline Mike Bobbitt

  • album.pl Author
  • Administrator
  • I Spend Too Much Time Here
  • *****
  • Posts: 3381
  • Karma: +35/-2
    • Mike's Development Archive
Re:Urgent Security Patch for album.pl
« Reply #16 on: June 25, 2003, 19:00:21 »
Man, I'm sorry to hear about both the hack and the loss. Thanks for the info, that'll help a lot when both tracking these guys down, and cleaning up for those unfortunate enough to be hit.

Looks like these guys hit a *lot* of album sites, but for the most part, were just an annoyance, not a real threat per se...

Let me know if you want a hand bringing your album up to 6.2, instead of applying the patch... I just got back from a trip, and will be out again in a couple of days, but should have some time next week...

Offline immaturity

  • album.pl User
  • *
  • Posts: 1
  • Karma: +0/-0
  • I forgot to change the default text.
Re:Urgent Security Patch for album.pl
« Reply #17 on: November 04, 2003, 16:08:14 »
Obviously, I should have been coming here to get updates so it's my own fault my old version of album.pl was hacked. I just wanted to add more information on this problem. On two of my sites album.pl was used to install psyBNC, which caused outages on the server I am on. One of my sites was suspended and I lost all of my files, the other left me with a warning that I would be denied service from that company completely if they found it again. They replaced my index file once with information on how to download the bouncer. Usually, though, I found it hidden in my tmp directory or in its own directory under various names. Once it was "Daniel" and I forget the other times. It would have a gibberish directory inside of it as well as pupet.tar.gz - I'll be updating to the newest version of album.pl right away.

Offline Mike Bobbitt

  • album.pl Author
  • Administrator
  • I Spend Too Much Time Here
  • *****
  • Posts: 3381
  • Karma: +35/-2
    • Mike's Development Archive
Re:Urgent Security Patch for album.pl
« Reply #18 on: November 06, 2003, 00:12:14 »
Damn. Sorry to hear that man... Thanks for the extra info though, I hope you didn't lose too much... :(

Offline mmedley

  • album.pl User
  • *
  • Posts: 3
  • Karma: +0/-0
  • Press what key?
Re:Urgent Security Patch for album.pl
« Reply #19 on: November 17, 2003, 08:52:07 »
Go ahead and chock up another victim.

Fortunately my site is being hosted by a provider and they've been able to catch the malicious file before any real damage had been done.

Great tool nonetheless, just gotta keep those haXor's at bay.

Offline Mike Bobbitt

  • album.pl Author
  • Administrator
  • I Spend Too Much Time Here
  • *****
  • Posts: 3381
  • Karma: +35/-2
    • Mike's Development Archive
Re:Urgent Security Patch for album.pl
« Reply #20 on: November 17, 2003, 09:34:07 »
Yeah, they got the drop on me once, but I'm going to be much more cautious now... (Unfortunately that slows me down and takes more time to get releases out, but what can you do... :()

Sorry to hear you got hit...

Offline ljweb

  • album.pl User
  • *
  • Posts: 4
  • Karma: +0/-0
  • I didnt forget to change the default text.
    • Contemporary Music Centre
Re:Urgent Security Patch for album.pl
« Reply #21 on: January 01, 2004, 18:04:49 »

Bugger, thought my album.pl was hacked!  I run the album at cmcaustralia.com (one of those listed on your home page) and discovered that bnc had found its way into my cgi-bin. The IP address that did it was 202.95.133.50 .  

I had to pull it down as it was the quickest thing i could do. There had already been over 200 requests for test.pl and book.pl and i caught it a couple of hours after it was done.

I'll install the latest version asap!.


Thanks!.

Offline Mike Bobbitt

  • album.pl Author
  • Administrator
  • I Spend Too Much Time Here
  • *****
  • Posts: 3381
  • Karma: +35/-2
    • Mike's Development Archive
Re:Urgent Security Patch for album.pl
« Reply #22 on: January 02, 2004, 10:38:39 »
Sorry to hear that... I know SecurityFocus has now posted exploit code with the listing, so any script kiddie can start hacking around... :(

Offline ljweb

  • album.pl User
  • *
  • Posts: 4
  • Karma: +0/-0
  • I didnt forget to change the default text.
    • Contemporary Music Centre
Re:Urgent Security Patch for album.pl
« Reply #23 on: January 14, 2004, 04:54:42 »

So far, blacklisted IPs are:

24.175.21.132
80.84.237.140
200.14.64.143
202.77.97.33
202.159.10.155
202.169.227.63
211.9.194.185
212.78.70.221

Please feel free to add to this list.




here's another one to add: 65.214.36.57  . They've tried a couple of times to get test.pl and book.pl.