I was blacklisted again over the weekend by several sites.
How would I go about finding if somebody is exploiting a flaw in PHP or the like??? My httpd-error.log files show that people are trying to access all sorts of files that are not on my web server for different versions of PHP, and there's nothing in any of my maillogs about the spam sent back to me, so I think that's likely the cause of the problems. I don't know anything about PHP though, so don't even know where to look to find problems.
Log sample - the IP shown is from China:
Code:
61.152.207.5 - - [09/Aug/2010:13:01:49 -0400] "GET /phpMyAdmin-2.5.5-rc1/scripts/setup.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6"
61.152.207.5 - - [09/Aug/2010:13:01:49 -0400] "GET /phpMyAdmin-2.5.5-rc2/scripts/setup.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6"
61.152.207.5 - - [09/Aug/2010:13:01:49 -0400] "GET /phpMyAdmin-2.5.5/scripts/setup.php HTTP/1.1" 404 232 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6"
61.152.207.5 - - [09/Aug/2010:13:01:50 -0400] "GET /phpMyAdmin-2.5.6-rc1/scripts/setup.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6"
61.152.207.5 - - [09/Aug/2010:13:01:50 -0400] "GET /phpMyAdmin-2.5.6-rc2/scripts/setup.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6"
61.152.207.5 - - [09/Aug/2010:13:01:50 -0400] "GET /phpMyAdmin-2.5.6/scripts/setup.php HTTP/1.1" 404 232 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6"
61.152.207.5 - - [09/Aug/2010:13:01:51 -0400] "GET /phpMyAdmin-2.5.7-pl1/scripts/setup.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6"
61.152.207.5 - - [09/Aug/2010:13:01:51 -0400] "GET /phpMyAdmin-2.5.7/scripts/setup.php HTTP/1.1" 404 232 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6"
<many, many, many more like this, and then...>
61.152.207.5 - - [09/Aug/2010:13:02:18 -0400] "GET /phpmy/scripts/setup.php HTTP/1.1" 404 221 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6"
61.152.207.5 - - [09/Aug/2010:13:02:19 -0400] "GET /phpmyad-sys/scripts/setup.php HTTP/1.1" 404 227 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6"
61.152.207.5 - - [09/Aug/2010:13:02:19 -0400] "GET /phpmyad/scripts/setup.php HTTP/1.1" 404 223 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6"
61.152.207.5 - - [09/Aug/2010:13:02:19 -0400] "GET /phpmyadmin/scripts/setup.php HTTP/1.1" 404 226 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6"
61.152.207.5 - - [09/Aug/2010:13:02:20 -0400] "GET /phpmyadmin2/scripts/setup.php HTTP/1.1" 404 227 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6"
61.152.207.5 - - [09/Aug/2010:13:02:20 -0400] "GET /pma/scripts/setup.php HTTP/1.1" 404 219 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6"
61.152.207.5 - - [09/Aug/2010:13:02:20 -0400] "GET /pma2005/scripts/setup.php HTTP/1.1" 404 223 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6"
Here are the headers for one of the spam message samples that was sent back to my by junkemailfilter.com; I replaced the IP/machine name and have notes inline with all CAPS:
Code:
======== Original Headers ========
Received: from mail.MYDOMAIN.com ([MYIPADDRESS] helo=MYDOMAIN.com)
by pascal.junkemailfilter.com with esmtp (Exim 4.72)
id 1OhieI-0005BU-2d on interface=65.49.42.60
for old_black@crunet.com; Sat, 07 Aug 2010 05:37:14 -0700
From: <eveveke3351@MYDOMAIN.com>
EVEVEKE3351 IS NOT A VALID ACCOUNT ON MY BOX
To: old_black@crunet.com
NEITHER EVEVEKE, OLD_BLACK, OR CRUNET.COM ARE LISTED ANYWHERE IN MY MAILLOG FOR THE PAST 2+ WEEKS
Date: Sat, 7 Aug 2010 08:37:10 -0400
Subject: Leak right into her mouth
Reply-To: <eveveke3351@MYDOMAIN.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 8bit
X-Sender-Domain: MYDOMAIN.com
X-Spamfilter-host: pascal.junkemailfilter.com - http://www.junkemailfilter.com
X-Mail-from: eveveke3351@MYDOMAIN.com
X-Spam-Class: SPAM-HIGH-VERY - MULTI-BLACKLIST - [S=9 - rep.mailspike.net
cbl.abuseat.org bl.spamcop.net] - OurBl BlList - X=pascal H=mail.graffsales.com
[MYIPADDRESS] HELO=[MYDOMAIN.com] F=[eveveke3351@MYDOMAIN.com]
T=[old_black@crunet.com] S=[Leak right into her mouth]
X-Honeypot: Yes - MULTI-BLACKLIST - [S=9 - rep.mailspike.net cbl.abuseat.org
bl.spamcop.net] - OurBl BlList - X=pascal H=mail.MYDOMAIN.com [MYIPADDRESS]
HELO=[MYDOMAIN.com] F=[eveveke3351@MYDOMAIN.com] T=[old_black@crunet.com]
S=[Leak right into her mouth]
X-Abuse-email:
X-Abuse-email: postmaster@MYDOMAIN.com
X-Sender-Host-Address: MYIPADDRESS
X-Sender-Host-Name: mail.MYDOMAIN.com
X-Original-helo: MYDOMAIN.com
sockstat -l does not show anything out of the ordinary.
The only odd thing in /var/log/messages is the following - the IPs are from Taiwan:
Code:
Aug 7 12:07:05 graffsales kernel: icmp redirect from 61.219.191.226: 61.219.191.228 => 61.219.191.228
Aug 7 12:07:05 graffsales kernel: icmp redirect from 61.219.191.226: 61.219.191.227 => 61.219.191.227
I'm frankly at a loss as what to do next. I'm currently in the process of updating all the ports that went out of date during the time I was off with my concussion (apache, php, python, amavisd-new, squirrelmail, some libraries and perl modules), but I don't have much confidence in it solving the problem. The only problems reported by portaudit was a DOS vulnerability in apache22 and an infinite loop in cabextract.
My apologies if this is something I should know. (My memory definitely isn't right since I hit my head - I'm trying to work through the pain and mental problems I'm still having.) I appreciate any help.