[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[suse-security] perl script drop
hi there
i have 2.4.20 with apache 1.3.26 and mod_php 4.2.2
somehow it was possible for a guy, to drop a file /tmp/.ps on the machine, and to start perl on that file
#>ps ax
1234 perl /tmp/.ps
the file was created under wwwrun.www - ownership, which tells me that apache created it.
the script just listens for incoming connections on p 4098, and opens a shell if the correct password is entered.
is this issue known to someone here ?
thanks,
gerhard
the script :
---------------------------------->8--------------
<<.ps>>
~~~~~~~~~~~~~~~~~~~~~~
--
Check the headers for your unsubscription address
For additional commands, e-mail: suse-security-help@xxxxxxxx
Security-related bug reports go to security@xxxxxxx, not here