HI,
I Have a linux shared hosting server,and a couple of days i am facing the serious issue regarding dark mailer or some .cgi script like (dark.cgi,dm.cgi,coms.cgi,mrm.cgi) ,i have also using mod_security2.0 +WHM to prevent such type of problem,So can any one tell me the best solution to block these type of attacks through mod_security,how to create a rule specific for the attacker "(dark.cgi,dm.cgi,coms.cgi,mrm.cgi)" scripts..please do need ful and let me know the best solution...
*******************************************************************************************
Time: Sun Jun 28 10:13:48 2009 +0530
PID: 30951
Account: hebbali
Uptime: 25705 seconds
Executable:
/usr/bin/perl
Command Line (often faked in exploits):
/usr/bin/perl dark.cgi
Network connections by the process (if any):
tcp: 144.38.110.14:58427 -> 210.8.231.6:25
Files open by the process (if any):
/dev/null
/home/hebbali/public_html/truck/sys/.pureftpd-rename.23258.7342c161 (deleted)
/home/hebbali/public_html/truck/sys/.pureftpd-rename.23258.7342c161 (deleted)
/tmp/ZCUD4Fyc93 (deleted)
Memory maps by the process (if any):
00110000-0024e000 r-xp 00000000 08:05 9176295 /lib/libc-2.5.so
0024e000-00250000 r--p 0013e000 08:05 9176295 /lib/libc-2.5.so
00250000-00251000 rw-p 00140000 08:05 9176295 /lib/libc-2.5.so
00251000-00254000 rw-p 00251000 00:00 0
00254000-00258000 r-xp 00000000 08:05 9175078 /lib/libnss_dns-2.5.so
00258000-00259000 r--p 00003000 08:05 9175078 /lib/libnss_dns-2.5.so
00259000-0025a000 rw-p 00004000 08:05 9175078 /lib/libnss_dns-2.5.so
00500000-0062b000 r-xp 00000000 08:03 10270297 /usr/lib/perl5/5.8.8/i386-linux-thread-multi/CORE/libperl.so
0062b000-00630000 rw-p 0012a000 08:03 10270297 /usr/lib/perl5/5.8.8/i386-linux-thread-multi/CORE/libperl.so
00630000-00632000 rw-p 00630000 00:00 0
006ca000-006e6000 r-xp 00000000 08:03 10269980 /usr/lib/perl5/5.8.8/i386-linux-thread-multi/auto/POSIX/POSIX.so
006e6000-006e7000 rw-p 0001b000 08:03 10269980 /usr/lib/perl5/5.8.8/i386-linux-thread-multi/auto/POSIX/POSIX.so
006eb000-006f0000 r-xp 00000000 08:03 10270142 /usr/lib/perl5/5.8.8/i386-linux-thread-multi/auto/Socket/Socket.so
006f0000-006f1000 rw-p 00004000 08:03 10270142 /usr/lib/perl5/5.8.8/i386-linux-thread-multi/auto/Socket/Socket.so
00771000-0078b000 r-xp 00000000 08:05 9176294 /lib/ld-2.5.so
0078b000-0078c000 r--p 00019000 08:05 9176294 /lib/ld-2.5.so
0078c000-0078d000 rw-p 0001a000 08:05 9176294 /lib/ld-2.5.so
007bd000-007be000 r-xp 007bd000 00:00 0 [vdso]
00801000-00805000 r-xp 00000000 08:03 10269967 /usr/lib/perl5/5.8.8/i386-linux-thread-multi/auto/IO/IO.so
00805000-00806000 rw-p 00003000 08:03 10269967 /usr/lib/perl5/5.8.8/i386-linux-thread-multi/auto/IO/IO.so
008d5000-008d7000 r-xp 00000000 08:05 9176298 /lib/libdl-2.5.so
008d7000-008d8000 r--p 00001000 08:05 9176298 /lib/libdl-2.5.so
008d8000-008d9000 rw-p 00002000 08:05 9176298 /lib/libdl-2.5.so
008db000-00900000 r-xp 00000000 08:05 9176297 /lib/libm-2.5.so
00900000-00901000 r--p 00024000 08:05 9176297 /lib/libm-2.5.so
00901000-00902000 rw-p 00025000 08:05 9176297 /lib/libm-2.5.so
00904000-00917000 r-xp 00000000 08:05 9176308 /lib/libpthread-2.5.so
00917000-00918000 r--p 00012000 08:05 9176308 /lib/libpthread-2.5.so
00918000-00919000 rw-p 00013000 08:05 9176308 /lib/libpthread-2.5.so
00919000-0091b000 rw-p 00919000 00:00 0
0099f000-009b2000 r-xp 00000000 08:05 9176300 /lib/libnsl-2.5.so
009b2000-009b3000 r--p 00012000 08:05 9176300 /lib/libnsl-2.5.so
009b3000-009b4000 rw-p 00013000 08:05 9176300 /lib/libnsl-2.5.so
009b4000-009b6000 rw-p 009b4000 00:00 0
009b8000-009c1000 r-xp 00000000 08:05 9176317 /lib/libcrypt-2.5.so
009c1000-009c2000 r--p 00008000 08:05 9176317 /lib/libcrypt-2.5.so
009c2000-009c3000 rw-p 00009000 08:05 9176317 /lib/libcrypt-2.5.so
009c3000-009ea000 rw-p 009c3000 00:00 0
00a3a000-00a43000 r-xp 00000000 08:05 9175080 /lib/libnss_files-2.5.so
00a43000-00a44000 r--p 00008000 08:05 9175080 /lib/libnss_files-2.5.so
00a44000-00a45000 rw-p 00009000 08:05 9175080 /lib/libnss_files-2.5.so
00be0000-00bef000 r-xp 00000000 08:05 9176302 /lib/libresolv-2.5.so
00bef000-00bf0000 r--p 0000e000 08:05 9176302 /lib/libresolv-2.5.so
00bf0000-00bf1000 rw-p 0000f000 08:05 9176302 /lib/libresolv-2.5.so
00bf1000-00bf3000 rw-p 00bf1000 00:00 0
00e4d000-00e4f000 r-xp 00000000 08:03 10270168 /usr/lib/perl5/5.8.8/i386-linux-thread-multi/auto/Sys/Hostname/Hostname.so
00e4f000-00e50000 rw-p 00001000 08:03 10270168 /usr/lib/perl5/5.8.8/i386-linux-thread-multi/auto/Sys/Hostname/Hostname.so
05ad4000-05ad6000 r-xp 00000000 08:05 9176299 /lib/libutil-2.5.so
05ad6000-05ad7000 r--p 00001000 08:05 9176299 /lib/libutil-2.5.so
05ad7000-05ad8000 rw-p 00002000 08:05 9176299 /lib/libutil-2.5.so
08048000-0804b000 r-xp 00000000 08:03 1733841 /usr/bin/perl
0804b000-0804c000 rw-p 00002000 08:03 1733841 /usr/bin/perl
084e5000-087bb000 rw-p 084e5000 00:00 0 [heap]
b7f3a000-b7f5e000 rw-p b7f3a000 00:00 0
b7f67000-b7f68000 rw-p b7f67000 00:00 0
bfdb3000-bfdc8000 rw-p bffea000 00:00 0 [stack]
****************************************************************************************



LinkBack URL
About LinkBacks
The Linux Dude
Reply With Quote






