Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Thu Jan 08, 2009 10:38 am 
Offline
Senior Member
User avatar

Joined: Thu Mar 06, 2008 12:21 am
Posts: 59
I am being hammered from about 30 different IPs starting a few hours ago scanning for some vulnerability I assume. So head's up if you are running Roundcude webmail.... My ossec software has been blocking after 10 attempts.

An example:


Code:
91.121.143.70 - - [08/Jan/2009:09:32:11 -0500] "GET /webmail/bin/msgimport HTTP/1.1" 404 298 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5"
91.121.143.70 - - [08/Jan/2009:09:32:11 -0500] "GET /roundcube/bin/msgimport HTTP/1.1" 404 300 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5"
91.121.143.70 - - [08/Jan/2009:09:32:11 -0500] "GET /rc/bin/msgimport HTTP/1.1" 404 293 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5"
91.121.143.70 - - [08/Jan/2009:09:32:11 -0500] "GET /webmail/bin/msgimport HTTP/1.1" 404 298 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5"
91.121.143.70 - - [08/Jan/2009:09:32:11 -0500] "GET /roundcube/bin/msgimport HTTP/1.1" 404 300 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5"
91.121.143.70 - - [08/Jan/2009:09:32:11 -0500] "GET /rc/bin/msgimport HTTP/1.1" 404 293 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5"
91.121.143.70 - - [08/Jan/2009:09:32:11 -0500] "GET /bin/msgimport HTTP/1.1" 404 290 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5"
91.121.143.70 - - [08/Jan/2009:09:32:11 -0500] "GET /mail/bin/msgimport HTTP/1.1" 404 295 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5"
91.121.143.70 - - [08/Jan/2009:09:32:10 -0500] "GET /nonexistenshit HTTP/1.1" 404 291 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5"
91.121.143.70 - - [08/Jan/2009:09:32:11 -0500] "GET /bin/msgimport HTTP/1.1" 404 290 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5"



Top
   
 Post subject:
PostPosted: Fri Jan 09, 2009 6:02 pm 
Offline
Senior Newbie

Joined: Wed Dec 31, 2008 10:49 am
Posts: 6
Me too! I'm full of this scanning! My apache log have this kind of log for almost 24h >_<
And i have the same even for Phpmyadmin.

Code:
 [Tue Jan 06 02:00:09 2009] [error] [client 87.237.209.238] File does not exist: /var/www/admin
[Tue Jan 06 02:00:09 2009] [error] [client 87.237.209.238] File does not exist: /var/www/admin
[Tue Jan 06 02:00:10 2009] [error] [client 87.237.209.238] File does not exist: /var/www/admin
[Tue Jan 06 02:00:10 2009] [error] [client 87.237.209.238] File does not exist: /var/www/phpmyadmin
[Tue Jan 06 02:00:10 2009] [error] [client 87.237.209.238] File does not exist: /var/www/phpMyAdmin
[Tue Jan 06 02:00:10 2009] [error] [client 87.237.209.238] File does not exist: /var/www/db
[Tue Jan 06 02:00:10 2009] [error] [client 87.237.209.238] File does not exist: /var/www/web
[Tue Jan 06 02:00:11 2009] [error] [client 87.237.209.238] File does not exist: /var/www/PMA
[Tue Jan 06 02:00:11 2009] [error] [client 87.237.209.238] File does not exist: /var/www/admin
[Tue Jan 06 02:00:11 2009] [error] [client 87.237.209.238] File does not exist: /var/www/mysql
[Tue Jan 06 02:00:11 2009] [error] [client 87.237.209.238] File does not exist: /var/www/myadmin
[Tue Jan 06 02:00:12 2009] [error] [client 87.237.209.238] File does not exist: /var/www/webadmin
[Tue Jan 06 02:00:12 2009] [error] [client 87.237.209.238] File does not exist: /var/www/sqlweb
[Tue Jan 06 02:00:12 2009] [error] [client 87.237.209.238] File does not exist: /var/www/websql
[Tue Jan 06 02:00:12 2009] [error] [client 87.237.209.238] File does not exist: /var/www/webdb
[Tue Jan 06 02:00:13 2009] [error] [client 87.237.209.238] File does not exist: /var/www/mysqladmin
[Tue Jan 06 02:00:13 2009] [error] [client 87.237.209.238] File does not exist: /var/www/mysql-admin
[Tue Jan 06 02:00:13 2009] [error] [client 87.237.209.238] File does not exist: /var/www/phpmyadmin2
[Tue Jan 06 02:00:13 2009] [error] [client 87.237.209.238] File does not exist: /var/www/php-my-admin
[Tue Jan 06 02:00:13 2009] [error] [client 87.237.209.238] File does not exist: /var/www/phpMyAdmin-2.2.3
[Tue Jan 06 02:00:14 2009] [error] [client 87.237.209.238] File does not exist: /var/www/phpMyAdmin-2.2.6
[Tue Jan 06 02:00:14 2009] [error] [client 87.237.209.238] File does not exist: /var/www/phpMyAdmin-2.5.1
[Tue Jan 06 02:00:14 2009] [error] [client 87.237.209.238] File does not exist: /var/www/phpMyAdmin-2.5.4
[Tue Jan 06 02:00:14 2009] [error] [client 87.237.209.238] File does not exist: /var/www/phpMyAdmin-2.5.6
[Tue Jan 06 02:00:15 2009] [error] [client 87.237.209.238] File does not exist: /var/www/phpMyAdmin-2.6.0
[Tue Jan 06 02:00:15 2009] [error] [client 87.237.209.238] File does not exist: /var/www/phpMyAdmin-2.6.0-pl1
[Tue Jan 06 02:00:15 2009] [error] [client 87.237.209.238] File does not exist: /var/www/phpMyAdmin-2.6.2-rc1
[Tue Jan 06 02:00:15 2009] [error] [client 87.237.209.238] File does not exist: /var/www/phpMyAdmin-2.6.3
[Tue Jan 06 05:48:32 2009] [error] [client 81.180.165.23] File does not exist: /var/www/signup_page.php
[Tue Jan 06 05:48:33 2009] [error] [client 81.180.165.23] File does not exist: /var/www/mantis
[Tue Jan 06 05:48:34 2009] [error] [client 81.180.165.23] File does not exist: /var/www/mantis
[Tue Jan 06 05:48:35 2009] [error] [client 81.180.165.23] File does not exist: /var/www/mantis

[Fri Jan 09 19:18:31 2009] [error] [client 63.247.72.26] File does not exist: /var/www/nonexistenshit
[Fri Jan 09 19:18:31 2009] [error] [client 63.247.72.26] File does not exist: /var/www/mail
[Fri Jan 09 19:18:32 2009] [error] [client 63.247.72.26] File does not exist: /var/www/bin
[Fri Jan 09 19:18:33 2009] [error] [client 63.247.72.26] File does not exist: /var/www/rc
[Fri Jan 09 19:18:35 2009] [error] [client 63.247.72.26] File does not exist: /var/www/roundcube
[Fri Jan 09 19:18:35 2009] [error] [client 63.247.72.26] File does not exist: /var/www/webmail
[Fri Jan 09 20:07:56 2009] [error] [client 212.95.32.211] File does not exist: /var/www/nonexistenshit
[Fri Jan 09 20:07:57 2009] [error] [client 212.95.32.211] File does not exist: /var/www/mail
[Fri Jan 09 20:07:57 2009] [error] [client 212.95.32.211] File does not exist: /var/www/bin
[Fri Jan 09 20:07:57 2009] [error] [client 212.95.32.211] File does not exist: /var/www/rc
[Fri Jan 09 20:07:57 2009] [error] [client 212.95.32.211] File does not exist: /var/www/roundcube
[Fri Jan 09 20:07:57 2009] [error] [client 212.95.32.211] File does not exist: /var/www/webmail



Top
   
 Post subject:
PostPosted: Fri Jan 09, 2009 6:48 pm 
Offline
Senior Member

Joined: Sun Nov 30, 2008 3:40 pm
Posts: 109
So, what do you guys suggest to prevent this?


Top
   
 Post subject:
PostPosted: Sat Jan 10, 2009 12:44 am 
Offline
Senior Member

Joined: Thu Apr 08, 2004 3:24 pm
Posts: 92
ICQ: 3765104
Website: http://www.unixfool.com
Yahoo Messenger: wigglit2001@yahoo.com
Location: VA
Active Scans for Roundcube Vulnerabilities, Possible 0-Day

If you're running Modsecurity, you can create rules to block this activity. There are several Emerging Threat Snort rules out there (see the link...it has the ET rules linked there). Modsecurity has a perl script that converts Snort rules into Modsecurity rules.

Either that, or create a script that will parse the access_log files, looking for certain strings...make the script add the IPs generating the certain strings to a block list (host.deny or FW rule block).


Top
   
 Post subject:
PostPosted: Tue Jan 20, 2009 7:38 pm 
Offline
Senior Member

Joined: Wed May 16, 2007 12:46 am
Posts: 71
dcelasun wrote:
So, what do you guys suggest to prevent this?


I just started dropping all APNIC net blocks. lol. Some RIPE, too.


Top
   
 Post subject:
PostPosted: Wed Jan 21, 2009 5:46 am 
Offline
Senior Member

Joined: Tue Apr 29, 2008 6:26 pm
Posts: 58
Website: http://blog.shadypixel.com/
I did nothing. I'm not getting hit more than 10-20 times a day so it's a negligible amount of traffic.


Top
   
 Post subject:
PostPosted: Wed Jan 21, 2009 6:03 pm 
Offline
Linode Staff
User avatar

Joined: Sat Jun 21, 2003 2:21 pm
Posts: 160
Location: Absecon, NJ
We've confirmed this is an active exploit for an arbitrary code exploit in RoundCube. Evidence so far points to exploited systems becoming part of a DDoS botnet. There is apparently a fix in the latest release of RoundCube.

-James


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group