A few times my internet server was bogged down with a cpu-hogging perl process. As I did not suspect malicious activity, I just killed the process after checking the user that the process was running as. And I went on my merry way. On two occasions, however, my ISP called me and reported that their firewall could not handle the traffic and had to be restarted due to packets from my server. I could not figure out what it was until I pulled out my Sherlock Holmes magnifying glass and dedicated about 30 minutes to the problem at hand.
What I discovered made my hair stand on end: I was hacked! Not rooted, thank god. The weakness was an old version of a twiki that could be used to run any perl script by searching for a non-existing item. Of course, the search query had to be carefully constructed with lots of %XY character codes to achieve the desired effect. WIth this in place, the perpetrators could DOS IRC's they did not like and perform other nefarious deeds.
Needless to say, I have closed that twiki down.
9:29:47 PM
|