Preface: CGI guestbook.cgiLogo -Internet Security Systems

CGI guestbook.cgi

advICE :Intrusions : 2002514
 FAQ
Oh my gosh, I'm being HACKED!!!
How do I report the hacker to my ISP?
I'm seeing lots of attacks, is this normal?

Summary

Suspicious URL.

An attempt to execute guestbook, which is a program with known vulnerabilities.

Details

The intruder is scanning the web server on the system looking for potential vulnerabilities in the "dynamic content generation" portion of the web server. This feature of the web server runs a separate program to create web pages when users access the site.

There are hundreds of such programs that have security bugs in them. In this instance, a hacker is browsing the web server looking for one of these programs. Most of the hacking you read about in the news is due to hackers exploiting these programs and "defacing" the web site.

More information can be found under cgi-bin exploits.

Defense

If this script is visible to the outside world, you should remove it from the directory.

Remove all dynamic content that isn't absolutely necessary to run the web site. Double-check the scripts that you do use in order to verify that they won't permit a security breach.

 more information
CERT: VB-97.02.sol_guestbook  
 
BugtraqID: 776   Guestbook CGI Remote Command Execution Vulnerability
 
CVE-1999-0237   Remote execution of arbitrary commands through Guestbook CGI program.
 

 parametric information
URLThe suspicious URL.
accessedIndicates whether the URL was successfully accessed.
codeThe HTTP return code.
argThe argument to the GET command (if any).

 
Version appeared:  

Privacy Policy |  Copyright Info