剛剛承擔了新客戶網站的責任。作業系統是Linux。他們在文檔根目錄下有一個 cgi-bin 目錄。
我正在查看 error.log 中是否存在腳本問題,並發現多次嘗試存取廢棄的 Perl 腳本。我現在已經刪除了整個 cgi-bin 目錄。
問題:
在 Linux VPS 上哪裡可以找到 suexec 日誌?它不在 /var/log/httpd/suexec_log 中
假設權限設定正確,攻擊者如何取得 cgi-bin 的目錄清單?
既然 cgi-bin 已被刪除,您對採取進一步行動有什麼想法嗎?
[Mon Nov 21 01:15:08 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 01:15:08 2011] [error] [client 66.249.68.193] Premature end of script headers: excel.pl
[Mon Nov 21 01:32:30 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 01:32:30 2011] [error] [client 66.249.68.193] Premature end of script headers: forward.pl
[Mon Nov 21 01:49:52 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 01:49:52 2011] [error] [client 66.249.68.193] Premature end of script headers: harvest.pl
[Mon Nov 21 01:58:27 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 01:58:27 2011] [error] [client 66.249.68.193] Premature end of script headers: who.pl
[Mon Nov 21 02:07:14 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 02:07:14 2011] [error] [client 66.249.68.193] Premature end of script headers: thousandwords.pl
[Mon Nov 21 02:17:21 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 02:17:21 2011] [error] [client 66.249.68.193] Premature end of script headers: news.pl
[Mon Nov 21 02:41:58 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 02:41:58 2011] [error] [client 66.249.68.193] Premature end of script headers: environment.pl
[Mon Nov 21 02:52:14 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 02:52:14 2011] [error] [client 66.249.68.193] Premature end of script headers: xpdf.pl
[Mon Nov 21 02:59:20 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 02:59:20 2011] [error] [client 66.249.68.193] Premature end of script headers: mail.pl
[Mon Nov 21 02:59:47 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 02:59:47 2011] [error] [client 66.249.68.193] Premature end of script headers: score.pl
[Mon Nov 21 03:16:42 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 03:16:42 2011] [error] [client 66.249.68.193] Premature end of script headers: pdfextract.pl
[Mon Nov 21 03:16:54 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 03:16:54 2011] [error] [client 66.249.68.193] Premature end of script headers: surveysays.pl
[Mon Nov 21 03:26:22 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 03:26:22 2011] [error] [client 66.249.68.193] Premature end of script headers: surveycookie.pl
[Mon Nov 21 03:51:26 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 03:51:26 2011] [error] [client 66.249.68.193] Premature end of script headers: search.cgi
[Mon Nov 21 04:08:48 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 04:08:48 2011] [error] [client 66.249.68.193] Premature end of script headers: shuffler.pl
[Mon Nov 21 06:37:34 2011] [error] [client 66.249.68.193] suexec policy violation: see suexec log for more details
[Mon Nov 21 06:37:34 2011] [error] [client 66.249.68.193] Premature end of script headers: tickerBN.pl
[Mon Nov 21 06:56:58 2011] [error] [client 66.249.68.193] suexec failure: could not open log file
[Mon Nov 21 06:56:58 2011] [error] [client 66.249.68.193] fopen: Permission denied
[Mon Nov 21 06:56:58 2011] [error] [client 66.249.68.193] Premature end of script headers: weatherFind.pl
[Mon Nov 21 08:14:37 2011] [error] [client 66.249.68.193] suexec failure: could not open log file
[Mon Nov 21 08:14:37 2011] [error] [client 66.249.68.193] fopen: Permission denied
[Mon Nov 21 08:14:37 2011] [error] [client 66.249.68.193] Premature end of script hea
答案1
Linux 是什麼風格?嘗試 /var/log/apache2/suexec.log,但看起來 suexec (Apache) 沒有寫入日誌檔案的權限。似乎是一個尋找易受攻擊腳本的機器人。