hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : Hosting Security and Technology Tutorials : Br0keN-Pr0xy hack - FIX (the popular index defacement hack)
Reply

Hosting Security and Technology Tutorials Tutorials related to server security or the like.
Forum Jump

Br0keN-Pr0xy hack - FIX (the popular index defacement hack)

Reply Post New Thread In Hosting Security and Technology Tutorials Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 09-03-2006, 11:22 AM
layer0 layer0 is offline
Performance Specialist
 
Join Date: Dec 2004
Location: New York, NY
Posts: 10,342

Br0keN-Pr0xy hack - FIX (the popular index defacement hack)


Login to SSH as root:

wget http://noc.medialayer.com/public/index-hack
chmod 700 index-hack
## make sure you edit index-hack to your needs, there is one variable "STRUCT" which defines the directory structure - the default is fine for cPanel servers but you may have to change this for other servers. $1 is the username.

To run this:

./index-hack <username>

So:

./index-hack layer0

would be correct

The purpose of this script is to list any files containg the "broken proxy" text. This attack has effected many hosts and I'm sure it's a pain for some customers to find all files that contain "index", "home", or "default", etc - this can provide your customers with a nice list if you are hit with the attack - thus they know exactly what files need to be replaced.

Obviously you really should be staying up to date kernel wise, and if you simply typed:

yum upgrade kernel or yum upgrade kernel-smp (for dual processor boxes) and rebooted you'd be fine but hey...we're not all that lucky

Reply With Quote


Sponsored Links
  #2  
Old 09-04-2006, 06:57 AM
jpetersen jpetersen is offline
Disabled
 
Join Date: Aug 2005
Posts: 439
Nice post. It's always good to see people helping out and providing useful utilities such as this. I have an idea for a performance improvement as well, which would basically be this modification to line 31:

if grep "Br0keN-Pr0xy" $i >&2>/dev/null

That way the files are just being grepped vice both catted and grepped. Thanks again, good stuff!

Reply With Quote
  #3  
Old 09-04-2006, 08:42 AM
layer0 layer0 is offline
Performance Specialist
 
Join Date: Dec 2004
Location: New York, NY
Posts: 10,342
Quote:
Originally Posted by jpetersen
Nice post. It's always good to see people helping out and providing useful utilities such as this. I have an idea for a performance improvement as well, which would basically be this modification to line 31:

if grep "Br0keN-Pr0xy" $i >&2>/dev/null

That way the files are just being grepped vice both catted and grepped. Thanks again, good stuff!
Thanks, I've made the change.

Reply With Quote
Sponsored Links
  #4  
Old 09-09-2006, 10:42 AM
Steven Steven is offline
I like ice cream
 
Join Date: Mar 2003
Location: California USA
Posts: 11,637
just for people reading this, this is not a fix all for all the bugs running around. There are some out there that have suid perl scripts and binarys you need to find them or you risk having this issue even after you update your kernel.

Reply With Quote
  #5  
Old 09-09-2006, 01:14 PM
layer0 layer0 is offline
Performance Specialist
 
Join Date: Dec 2004
Location: New York, NY
Posts: 10,342
Quote:
Originally Posted by Steven
just for people reading this, this is not a fix all for all the bugs running around. There are some out there that have suid perl scripts and binarys you need to find them or you risk having this issue even after you update your kernel.
Yes, of course it can be a perl script, but most of the time it's old kernel versions being exploited.

Reply With Quote
  #6  
Old 09-09-2006, 01:23 PM
Steven Steven is offline
I like ice cream
 
Join Date: Mar 2003
Location: California USA
Posts: 11,637
Quote:
Originally Posted by layer0
Yes, of course it can be a perl script, but most of the time it's old kernel versions being exploited.
Its the kernel exploited yes in 99% of the cases but there is almost always a perl script somewhere being used to do a mass deface, they are starting to set them suid which will allow them to be executed as root even as a regular user.

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
StopTheHacker Launches Version 3.7 of Website Security Tool Web Hosting News 2013-02-04 18:40:30
GoGrid Partners with Boston Big Data Research Group hack/reduce With Free Cloud Hosting Web Hosting News 2012-11-08 17:42:48
Dutch Security Firm Gemnet and Certificate Authority Division Gemnet CSP Offline Following Hack Web Hosting News 2011-12-09 15:33:53
Sony Temporarily Locks Accounts After Hack Attempt Detected Web Hosting News 2011-10-12 16:21:46
WikiLeaks Documentary Prompts Hacker Attack on PBS Website Web Hosting News 2011-05-30 14:57:30


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?