[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[suse-security] perl script drop



hi there
i have 2.4.20 with apache 1.3.26 and mod_php 4.2.2

somehow it was possible for a guy, to drop a file /tmp/.ps on the machine, and to start perl on that file 

#>ps ax

1234 perl /tmp/.ps

the file  was created under wwwrun.www - ownership, which tells me that apache created it.
the script just listens for incoming connections on p 4098, and opens a shell if the correct password is entered.

is this issue known to someone here ?

thanks, 
gerhard

the script :

---------------------------------->8--------------





 <<.ps>> 


~~~~~~~~~~~~~~~~~~~~~~


-- 
Check the headers for your unsubscription address
For additional commands, e-mail: suse-security-help@xxxxxxxx
Security-related bug reports go to security@xxxxxxx, not here