Acabei de assumir a responsabilidade pelo site de um novo cliente. O sistema operacional é Linux. Eles tinham um diretório cgi-bin abaixo da raiz do documento.
Eu estava procurando em meu error.log um problema com um script e encontrei várias tentativas de acessar scripts Perl fora de uso. Eu removi todo o diretório cgi-bin agora.
Questões:
Onde eu encontraria o log suexec em um Linux VPS? Não está em /var/log/httpd/suexec_log
Como o invasor teria obtido uma listagem de diretório do cgi-bin, assumindo que as permissões foram definidas corretamente?
Alguma ideia sobre outras ações agora que o cgi-bin foi removido?
[Mon Nov 21 01:15:08 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 01:15:08 2011] [error] [client 66.249.68.193] Premature end of script headers: excel.pl
[Mon Nov 21 01:32:30 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 01:32:30 2011] [error] [client 66.249.68.193] Premature end of script headers: forward.pl
[Mon Nov 21 01:49:52 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 01:49:52 2011] [error] [client 66.249.68.193] Premature end of script headers: harvest.pl
[Mon Nov 21 01:58:27 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 01:58:27 2011] [error] [client 66.249.68.193] Premature end of script headers: who.pl
[Mon Nov 21 02:07:14 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 02:07:14 2011] [error] [client 66.249.68.193] Premature end of script headers: thousandwords.pl
[Mon Nov 21 02:17:21 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 02:17:21 2011] [error] [client 66.249.68.193] Premature end of script headers: news.pl
[Mon Nov 21 02:41:58 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 02:41:58 2011] [error] [client 66.249.68.193] Premature end of script headers: environment.pl
[Mon Nov 21 02:52:14 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 02:52:14 2011] [error] [client 66.249.68.193] Premature end of script headers: xpdf.pl
[Mon Nov 21 02:59:20 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 02:59:20 2011] [error] [client 66.249.68.193] Premature end of script headers: mail.pl
[Mon Nov 21 02:59:47 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 02:59:47 2011] [error] [client 66.249.68.193] Premature end of script headers: score.pl
[Mon Nov 21 03:16:42 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 03:16:42 2011] [error] [client 66.249.68.193] Premature end of script headers: pdfextract.pl
[Mon Nov 21 03:16:54 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 03:16:54 2011] [error] [client 66.249.68.193] Premature end of script headers: surveysays.pl
[Mon Nov 21 03:26:22 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 03:26:22 2011] [error] [client 66.249.68.193] Premature end of script headers: surveycookie.pl
[Mon Nov 21 03:51:26 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 03:51:26 2011] [error] [client 66.249.68.193] Premature end of script headers: search.cgi
[Mon Nov 21 04:08:48 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 04:08:48 2011] [error] [client 66.249.68.193] Premature end of script headers: shuffler.pl
[Mon Nov 21 06:37:34 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 06:37:34 2011] [error] [client 66.249.68.193] Premature end of script headers: tickerBN.pl
[Mon Nov 21 06:56:58 2011] [error] [client 66.249.68.193] suexec failure: could not open log file
[Mon Nov 21 06:56:58 2011] [error] [client 66.249.68.193] fopen: Permission denied
[Mon Nov 21 06:56:58 2011] [error] [client 66.249.68.193] Premature end of script headers: weatherFind.pl
[Mon Nov 21 08:14:37 2011] [error] [client 66.249.68.193] suexec failure: could not open log file
[Mon Nov 21 08:14:37 2011] [error] [client 66.249.68.193] fopen: Permission denied
[Mon Nov 21 08:14:37 2011] [error] [client 66.249.68.193] Premature end of script hea
Responder1
Qual sabor do Linux? Tente /var/log/apache2/suexec.log, mas parece que suexec (Apache) não tem permissões para gravar no arquivo de log. Parece ser um bot em busca de scripts vulneráveis.