Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 8 of 8
  1. #1
    Member
    Join Date
    Feb 2004
    Posts
    95

    Default PayPal hijack -- FYI

    One of my users was hijacked today. It appears that someone used his website to upload a script named '.pay.php'. It was a PayPal hijacking script.


    Here is what the script looked like.
    http://www.devtop.com/bad.no

    Prevent via mod_security add
    SecFilterSelective THE_REQUEST "/.pay\.php"
    Last edited by laborspy; 06-07-2006 at 07:32 PM.

  2. #2
    Member
    Join Date
    Feb 2006
    Posts
    111

    Default

    With that mod_secuirty filter can't they just change the name of the file???

  3. #3
    Member
    Join Date
    Dec 2003
    Posts
    84

    Default

    here are a few sec_mod filters I use to stop repeated abuse attempts against unsecure scripts.

    SecFilter pathtoashnews=
    SecFilter absolute_path=
    SecFilter root_path=

    grep your domain logs for the pay.php and then do it for wget and look for the command right before http://remoteip. Then block that so they can't upload any scripts. wget won't show 100% of exploits but its a good start.

  4. #4
    Member
    Join Date
    Jul 2002
    Location
    Canada
    Posts
    675

    Default

    All these sites are a result of Coppermine Photo Gallery exploits.
    A new one is out now as well
    http://www.frsirt.com/english/advisories/2006/2185
    Upload Guardian 2.0 - Sign up for our early beta
    ServerProgress - Server security, consulting and assistance

  5. #5
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Mar 2004
    Posts
    347

    Default

    How to protect against http://www.frsirt.com/english/advisories/2006/2185 with mod_security?

  6. #6
    Member
    Join Date
    Jul 2002
    Location
    Canada
    Posts
    675

    Default

    I have contacted the developer for more information regarding this. Without seeing an active attack yet I cannot write a rule set for it at this time.
    Upload Guardian 2.0 - Sign up for our early beta
    ServerProgress - Server security, consulting and assistance

  7. #7
    Member
    Join Date
    Jul 2002
    Location
    Canada
    Posts
    675

    Default

    The developers will not provide this, I'm not suprised.

    Fantastico sure is doing a great job at keeping our systems secure by updating with the software providers. Latest version on Coppermine website is 1.4.8

    Latest stable Fantastico is
    New Installation (1.4.2)
    Upload Guardian 2.0 - Sign up for our early beta
    ServerProgress - Server security, consulting and assistance

  8. #8
    Member
    Join Date
    Sep 2003
    Posts
    658

    Default

    Quote Originally Posted by ramprage
    The developers will not provide this, I'm not suprised.

    Fantastico sure is doing a great job at keeping our systems secure by updating with the software providers. Latest version on Coppermine website is 1.4.8
    Latest cpanel version is....Coppermine (1.3.3)

Similar Threads & Tags
Similar threads

  1. FYI if you are running PHP < 5.3.1
    By thobarn in forum Security
    Replies: 4
    Last Post: 12-06-2009, 07:05 PM
  2. AFK untill Monday, FYI
    By darren in forum cPGS Discussions
    Replies: 1
    Last Post: 06-10-2009, 03:54 AM
  3. FYI - Hotmail Blacklisted
    By nickp666 in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 06-25-2007, 10:42 AM
  4. FYI: Monsoon Users
    By Tom Pyles in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 06-05-2004, 06:44 PM
  5. FYI PHP sending HTML emails
    By misterb in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 12-04-2003, 03:48 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube