151,000 domains attacked via dangerous PHP hole

Powered by SC Magazine
 

PHP Group issues fix for the second time.

More than 151,000 domains held by US hosting provider Dreamhost have been targeted by attackers exploiting a dangerous and long-standing PHP vulnerability.

As reported by SC Magazinethe PHP-CGI vulnerability had existed since 2004 and allowed remote code execution on current versions of the language.

The hole has now been patched, but only after preceeding fixes (versions 5.3.12 and 5.4.2) failed to work.

Some 230,000 attacks against the hosts directly attempted to exploit the vulnerability, according to SpiderLabs which obtained the figures from Dreamhost.

The attacks attempted to install webshells and backdoors on targeted machines, analysis from Spiderlabs' honeypots revealed.

One string of attacks had tried to upload a RFI file PHP backdoor program and then write a crude mod_rewrite fix to close off the PHP vulnerability, in efforts to prevent other attackers gaining access. 

''.chr(10).
'RewriteEngine On'.chr(10).
'RewriteCond %{QUERY_STRING} ^(%2d|-)[^=]+$ [NC]'.chr(10).
'RewriteRule ^(.*) $1? [L]'.chr(10).	

The PHP-CGI flaw was publicly disclosed, reportedly in error, to Reddit following the issuance of the patches but before the fixes were found to have failed. Researcher Steffan Esser was the first to note the failure.

The vulnerability was discovered during a capture-the-flag event at the Nullcon event last year by Dutch security firm De Eindbazen.

Users can apply an interim fix using Spiderlabs' code which it said was better than others because it closed off vulnerability to the RFI attack.

SecRule QUERY_STRING "^-[sdcr]" "phase:1,t:none,t:urlDecodeUni,t:removeWhitespace,block,log,msg:'Potential PHP-CGI Exploit Attempt'"

Copyright © SC Magazine, Australia


151,000 domains attacked via dangerous PHP hole
 
 
 
Top Stories
Beyond ACORN: Cracking the infosec skills nut
[Blog post] Could the Government's cybercrime focus be a catalyst for change?
 
The iTnews Benchmark Awards
Meet the best of the best.
 
Telstra hands over copper, HFC in new $11bn NBN deal
Value of 2011 deal remains intact.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  39%
 
Your insurance company
  3%
 
A technology company (Google, Facebook et al)
  8%
 
Your telco, ISP or utility
  7%
 
A retailer (Coles, Woolworths et al)
  2%
 
A Federal Government agency (ATO, Centrelink etc)
  20%
 
An Australian law enforcement agency (AFP, ASIO et al)
  14%
 
A State Government agency (Health dept, etc)
  6%
TOTAL VOTES: 1793

Vote
Do you support the abolition of the Office of the Information Commissioner?