Icy Phoenix

     
 


Post new topic  This topic is locked: you cannot edit posts or make replies. 
Page 1 of 1
 
 
Reply with quote Download Post 
Post Strange File Found In My XS: /files/py2 
 
There's a copy of my XS site on my computer and inside the "files" folder there's no file called "py2" but in the live version of my site there is and I'm writing  here to seek an understanding of what that file is please.

Apparently it was created on 30Aug and when I view it in Notepad, there are lots of symbols and the following text amongst those symbols:


Quote:
v ƒëÿЋƒøÿuôX[ÉÃU‰åSè    [Ã  PèªûÿÿY[Éà      [+] getting root shell
 /bin/sh [-] execle  
prctl() suidsafe exploit

(C) Julien TINNES

 /proc/self/exe [-] readlink  This is not fatal, rewrite the exploit
 [-] signal [+] Installed signal handler
 /etc/cron.d [-] chdir [-] prtctl   Is you kernel version >= 2.6.13 ?
  [+] We are suidsafe dumpable!
 /etc/cron.d/core
 [-] cronstring is too small
 [+] Malicious string forged
 [-] fork [+] Segfaulting child
 [-] kill    [+] Waiting for exploit to succeed (~%ld seconds)
  [-] It looks like the exploit failed

The current owner of the file is: Webserver

I've stuck the file here: http://europeclubitalia.net/xs/uploads/

I would greatly appreciate an explanation of what the function of this file might be.

Thanks in advance
 



 
KanguraSend private messageVisit poster's website  
Back to topPage bottom
Icy Phoenix is an open source project, you can show your appreciation and support future development by donating to the project.

Support us
 
Reply with quote Download Post 
Post Re: Strange File Found In My XS: /files/py2 
 
it look like your site mabe hacked!

check here http://www.milw0rm.com/exploits/2005

you need to sum updated on your box i think
 



 
ch0pperSend private message  
Back to topPage bottom
Reply with quote Download Post 
Post Re: Strange File Found In My XS: /files/py2 
 
kkkk
Could that be why it takes extra time to log on to our site now but navigating around it is fast?
 



 
KanguraSend private messageVisit poster's website  
Back to topPage bottom
Reply with quote Download Post 
Post Re: Strange File Found In My XS: /files/py2 
 
yep check for rookits , and updated as much as you can
 



 
ch0pperSend private message  
Back to topPage bottom
Reply with quote Download Post 
Post Re: Strange File Found In My XS: /files/py2 
 
ch0pper wrote: [View Post]
yep check for rookits , and updated as much as you can


sorry what are rookits ??

all patches as advised by MG are installed
 



 
KanguraSend private messageVisit poster's website  
Back to topPage bottom
Post new topic  This topic is locked: you cannot edit posts or make replies.  Page 1 of 1
 


Display posts from previous:    

HideWas this topic useful?

Link this topic
URL
BBCode
HTML




 
Permissions List
You cannot post new topics
You cannot reply to topics
You cannot edit your posts
You cannot delete your posts
You cannot vote in polls
You cannot attach files
You can download files
You cannot post calendar events


  

 

  cron