This is Lamar Spells's TypePad Profile.
Join TypePad and start following Lamar Spells's activity
Lamar Spells
Recent Activity
I have seen the same LFI and code injection attacks discussed here and today yet more PHP attacks. This time, an attempt to exploit phpthumb via CVE-2010-1598.
Full details along with IPs seen are at: http://foxtrot7security.blogspot.com/2011/12/new-attempts-to-exploit-old-phpthumb.html
Anyone else see a big uptick in this activity today?
[Honeypot Alert] User Agent Field Arbitrary PHP Code Execution
While reviewing today's web honeypot logs, SpiderLabs Research identified two new attack variations. Focus on Local File Inclusion attacks Here are some of the LFI attack payloads identified today: GET /_functions.php?prefix=../../../../../../../proc/self/environ%00 HTTP/1.1 GET /ashnews.php?pat...
Ryan,
You are correct. This issue is apparently related to the awstats issue we discussed last week, along with some additional information regarding code injection against phpAlbum:
http://foxtrot7security.blogspot.com/2011/12/attacks-against-awstats-also-includes.html
[Honeypot Alert] WordPress/Joomla/Mambo SQL Injection Scanning Detected
Our web honeypot analysis today detected scanning looking for SQL Injection flaws in a number of Wordpress/Joomla/Mambo components. GET /index.php?option=com_garyscookbook&Itemid=S@BUN&func=detail&id=-666%2F%2A%2A%2Funion%2F%2A%2A%2Fselect%2F%2A%2A%2F0%2C0%2C0x33633273366962%2C0%2C0%2C0%2C0%2C0%...
@Ryan -- agree completely. There are also some older PHP versions running around out there and at least one of the IPs was/is running Joomla. Lots of other ways to attack other than Apache, but Apache seems to be a pretty common link. Of course, that's to be expected...
[Honeypot Alert] Awstats Command Injection Scanning Detected
Issue Detected Our daily web honeypot analysis has detected an increase in scanning looking for command injection flaws in the Awstats package. Here are example attacks from the logs: GET /awstats/awstats.pl?configdir=|echo;echo%20YYYAAZ;uname;id;echo%20YYY;echo| HTTP/1.0 GET /awstats/awstats....
Some additional analysis and advice: Patch your ancient versions of Apache too!
http://foxtrot7security.blogspot.com/2011/12/importance-of-patching.html
[Honeypot Alert] Awstats Command Injection Scanning Detected
Issue Detected Our daily web honeypot analysis has detected an increase in scanning looking for command injection flaws in the Awstats package. Here are example attacks from the logs: GET /awstats/awstats.pl?configdir=|echo;echo%20YYYAAZ;uname;id;echo%20YYY;echo| HTTP/1.0 GET /awstats/awstats....
Lamar Spells is now following The Typepad Team
Dec 16, 2011
Subscribe to Lamar Spells’s Recent Activity
