/cgi-bin/phf /cgi-bin/test-cgi /cgi-bin/handler

/cgi-bin/phf /cgi-bin/test-cgi /cgi-bin/handler

Post by Quowong P L » Tue, 07 Jul 1998 04:00:00



I've been seeing a number of attacks of this sort recently
from various sites in the http logs.  The time correlation
between the logs on various hosts suggests that the attacker
was scanning sequentially upward in IP addresses.  Since all
tcp and udp packets to ports below 1024 except for http,
smtp, and ident are filtered out for most, including the
attacking, sites, I'm not seeing anything else in the logs.

209.61.73.47 - - [04/Jul/1998:07:19:27 -0500] "GET /cgi-bin/phf" 404 -
209.61.73.47 - - [04/Jul/1998:07:19:28 -0500] "GET /cgi-bin/test-cgi" 404 -
209.61.73.47 - - [04/Jul/1998:07:19:28 -0500] "GET /cgi-bin/handler" 404 -

Is this a signature of some known attackware?  If so, what
other attacks accompany these http probes?

--

 
 
 

/cgi-bin/phf /cgi-bin/test-cgi /cgi-bin/handler

Post by Timothy J. L » Wed, 08 Jul 1998 04:00:00


|209.61.73.47 - - [04/Jul/1998:07:19:28 -0500] "GET /cgi-bin/handler" 404 -
|
|Is this a signature of some known attackware?  If so, what
|other attacks accompany these http probes?

In a web search engine, search for "cgi-bin/handler" and see what comes up.

--
------------------------------------------------------------------------

Unsolicited bulk or commercial email is not welcome.             netcom.com
No warranty of any kind is provided with this message.

 
 
 

/cgi-bin/phf /cgi-bin/test-cgi /cgi-bin/handler

Post by Kevin Connoll » Thu, 09 Jul 1998 04:00:00



> 209.61.73.47 - - [04/Jul/1998:07:19:27 -0500] "GET /cgi-bin/phf" 404 -

>  Is this a signature of some known attackware?

Yes, phf is a well known hole. See
http://www.cert.org/advisories/CA-96.06.cgi_example_code.html

--
Remove the NOSPAM from the reply address
Kevin Connolly, EI4ANB
ICBM: 51 40.2'N   08 29.7'W

 
 
 

/cgi-bin/phf /cgi-bin/test-cgi /cgi-bin/handler

Post by Martin W. Freis » Thu, 09 Jul 1998 04:00:00



> 209.61.73.47 - - [04/Jul/1998:07:19:27 -0500] "GET /cgi-bin/phf" 404 -
> 209.61.73.47 - - [04/Jul/1998:07:19:28 -0500] "GET /cgi-bin/test-cgi" 404 -
> 209.61.73.47 - - [04/Jul/1998:07:19:28 -0500] "GET /cgi-bin/handler" 404 -

> Is this a signature of some known attackware?  If so, what
> other attacks accompany these http probes?

vito (one of a bunch of scripts that try for known holes in webservers) does this in
the order you posted in default configuration. More attacks in the default config are
on mglimpse and campas.

Check any bugtraq archive for vito.

-Martin

--

 Siemens Nixdorf, CC IT Networks, Solution Team Internet/Intranet
Half male, half e-mail.

 
 
 

/cgi-bin/phf /cgi-bin/test-cgi /cgi-bin/handler

Post by Quowong P L » Thu, 09 Jul 1998 04:00:00




Quote:>Is this a signature of some known attackware?  If so, what
>other attacks accompany these http probes?

To follow up, there are reports of finger/telnet/imap/pop3/regex
probes accompanying these.

A little research on www.rootshell.com turns up something
called mscan, which also probes portmapper/statd/named and
X servers, for a range of addresses or all the addresses in
a domain.

In the last week or so, such attacks were logged from these
sites:

  cr543730-a.surrey1.bc.wave.home.com [24.113.45.75]
  210.152.89.1
  207-172-251-229.s38.as2.loc.erols.com [207.172.251.229]
  209.61.73.47
  dixie.introspect.net [199.72.239.200]

as well as reports of one from *.ix.netcom.com, so I
suspect these cookie-cutter attacks are carried out by
"h4x0r" wannabes.

--

 
 
 

1. cgi-bin/view-source?cgi-bin/view-source

This line is out of my Web server log file:

ultra.mpls.k12.mn.us - - [09/Apr/2000:01:44:55 -0500] "GET /cgi-bin/view-source?cgi-bin/view-source HTTP/1.0" 404 213

This line is the only one from this IP address in the log file.
Does anybody know what this is intended to do? I didn't find any hints on a program
view-source. Is it kind of phf or aglimpse?

Thanks,
Andre

Andre van Straaten
http://www.vanstraatensoft.com
______________________________________________

2. HOWTO: Add A New RH8 Session Type

3. cgi-bin (C bin) hangs under Linux

4. Job : UNIX, SOLARIS DEVELOPER, LONDON

5. cgi-bin and cgi file security

6. How do I tile the windows in GNOME?

7. cgi-bin access with .cgi file

8. unlock a package under SCO UnixWare 2.12

9. Execute cgi outside of cgi-bin

10. .cgi-Files will only work in the cgi-bin ???

11. Aliasing cgi-bin directory to CGI directory

12. How could let CGI run not only at cgi-bin?

13. apache: give /home/mailman/cgi-bin permissions to run cgi-scripts.