AplusWebMaster
Topic Starter
FYI…
- http://isc.sans.org/diary.php?date=2005-03-15
Updated March 15th 2005 20:25 UTC
"Another exploit has been released for phpBB bulletin boards. This exploit drops a netcat into the web root and may start a listener. There is another binary in tmp which I have not directly identified which appears to exploit a race condition in the Linux kernel. The file name is pwned and it calls a data file called TTdummyfile. Previous diary entries regarding phpBB:
http://isc.sans.org/diary.php?date=2005-03-12
http://isc.sans.org/diary.php?date=2005-02-27
http://isc.sans.org/diary.php?date=2005-02-22
We have had one report of a system compromised with this tool. Since it creates at least one backdoor on the system my recommendation is to take the machine offline and rebuild it. With the caveat that the same exploit path may still exist since from the report that I have seen the exploit works on all the current versions of phpBB, Apache, and PHP. I will update this information as I learn more…"

- http://isc.sans.org/diary.php?date=2005-03-15
Updated March 15th 2005 20:25 UTC
"Another exploit has been released for phpBB bulletin boards. This exploit drops a netcat into the web root and may start a listener. There is another binary in tmp which I have not directly identified which appears to exploit a race condition in the Linux kernel. The file name is pwned and it calls a data file called TTdummyfile. Previous diary entries regarding phpBB:
http://isc.sans.org/diary.php?date=2005-03-12
http://isc.sans.org/diary.php?date=2005-02-27
http://isc.sans.org/diary.php?date=2005-02-22
We have had one report of a system compromised with this tool. Since it creates at least one backdoor on the system my recommendation is to take the machine offline and rebuild it. With the caveat that the same exploit path may still exist since from the report that I have seen the exploit works on all the current versions of phpBB, Apache, and PHP. I will update this information as I learn more…"