Linux worm turns on Mambo and PHP

Posted on Tuesday, February 21, 2006 @ 00:27:49 CST in Security
by Raven

68_andahalf_68 writes:  
Security experts today warned of a Linux network worm that exploits holes in the Mambo content management system and the PHP XML-RPC library.

Dubbed Mare.D, the worm leaves multiple backdoors on infected systems. Two of these are connectback shell backdoors that link to a remote host, while a third allows the malware's writer to access and control infected systems via IRC.

Read More
Note:
from Raven: Check your security logs and access_logs. I have been diluged with attempts to use the Mambo hack on my site, to no avail of course. If your host does not provide you with an Apache module called mod_security, insist that they get it installed and configured. It's one of the easiest and best tools for stopping so many of these kinds of exploits :)
 
 
click Related        click Share
 
 

Re: Linux worm turns on Mambo and PHP (Score: 1)
by hitwalker on Tuesday, February 21, 2006 @ 09:49:21 CST
  
(User Info | Send a Message)

any sample of how this attack looks like....
naturaly this sample in txt can be send by pm... :)

 
News ©

Site Info

Last SeenLast Seen
  • vashd1
  • neralex
Server TrafficServer Traffic
  • Total: 513,129,148
  • Today: 195,343
Server InfoServer Info
  • Apr 23, 2025
  • 05:38 pm CDT