|
||||||
| Perl Discussion for the PERL language - Practical Extraction and Reporting Language, is a programming language often used for creating CGI programs. |
![]() |
|
|
LinkBack | Thread Tools | Search this Thread | Display Modes |
|
|||
|
I was looking through my log files and happened by a file upload that should not have been uploaded (through a script somehow they managed to upload although they shouldn't have access). I then immediatly went to the directory the script was inserted into "/tmp" and opened the file. The first line reads #!/usr/bin/perl and even though I have used perl before I still don't entirely understand what this script does.
Perl Code:
I can see that it opens lynx and connects to the local machine but what does this do: Perl Code:
I understand echo and uname but is it calling /bin/sh? From this point down I do not understand. Any of this I do not really understand what it is doing: Perl Code:
Can someone help me figure out what the intention of this script is? Last edited by John; 11-10-2007 at 12:32 AM. |
| Sponsored Links |
|
|
|
|||
|
hmmm.... I don't know what it is trying to do. Maybe ask on PerlMonks - The Monastery Gates if you get an answer post back here.
|
|
|||
|
I believe it is indeed malicious. In my case I was presented with a mailqueue of 9000 emails trying to send out a phising/scam type of email (excerpt below), right after this script showed up.
I am not that good of a server admin but I am pretty sure this script started it somehow. Excerpt of the email: The Local Organizing Committee of the Heineken European Champions League is glad to announce to the world the giving away of the sum of TWO HUNDRED MILLION POUNDS to 100 lucky email addresses all over the world. I hope you didn't have the same problem... it was pretty annoying to delete all those... thankfully they all came from nobody@. Last edited by zosorock; 11-18-2007 at 01:58 AM. |
|
|||
|
It in itself is not malicious. It connects to an external server and port passed as parameters to the script and sends all of the detailed system information to that server. Then that can be used to find commmon security flaws for that os/aric
__________________
CodeCall Blog | CodeCall Wiki | Shareware | Linux Forum Chat with other CodeCall members on IRC; connect to irc.codecall.net and join #codecall |
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| JavaScript:Tutorial, Using an External Script | TcM | Javascript | 7 | 09-11-2007 07:39 AM |
| Perl is Dead. Long live Perl. | Kernel | Programming News | 3 | 08-10-2007 10:49 AM |
| (Script) Copy content to clipboard, how? | annannienann | Visual Basic Programming | 0 | 06-19-2007 05:20 PM |
| Packet Loss Perl Script | Jordan | Tutorials, Classes and Code | 1 | 04-29-2007 12:29 PM |
| John | ........ | 167.00000 |
| Xav | ........ | 164.00000 |
| dargueta | ........ | 148.00000 |
| gaylo565 | ........ | 18.00000 |
| WingedPanther | ........ | 15.00000 |
| |pH| | ........ | 15.00000 |
| Johnnyboy | ........ | 3.00000 |
| navghost | ........ | 1.00000 |