D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] Apache security flaw - my website cracked

 

Ben Goodger wrote:
> On 19/07/06, Ed Rackham <ed@xxxxxxxxxxxxxxx> wrote:
> http://dev.shaunevans.co.uk/ben/
> 
> The /wordpress bit was the bit hacked, but I don't have FTP access to it so
> I can't tell whether the data was overridden.. was it?

Probably not - it looks like a simple redirection.
<?php
header("Location:http://somewebsite.org/";);
?>
That goes into the index.php file at the top and suddenly the rest of
the content is hidden. Try some fuller URL's that do not reference the
index page. Also try any subdirectories that are normally available.

> Apache 2.0.54 with custom patches on FC5 or FC2, can't remember which.

You'd *better* know which!! FC2 is ancient!

Apache/2.0.54 (Unix) PHP/4.3.10 Server at dev.shaunevans.co.uk Port 80
c.f.
pache/2.0.55 (Debian) mod_python/3.1.3 Python/2.3.5 PHP/5.1.4-0.1
mod_perl/2.0.2 Perl/v5.8.8 Server at localhost Port 80

Looks like FC5 but you really should update to PHP5.

-- 

Neil Williams
=============
http://www.data-freedom.org/
http://www.nosoftwarepatents.com/
http://www.linux.codehelp.co.uk/


Attachment: signature.asc
Description: OpenPGP digital signature

-- 
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/linux_adm/list-faq.html