This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

XML-RPC for PHP Vulnerability Attack

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?storyid=823
Last Updated: 2005-11-05 14:48:16 UTC
"We have received a few reports on an attack exploiting xml-rpc for php vulnerability.
xml-rpc for php is used in a large number of popular web applications such as PostNuke, Drupal, b2evolution, Xoops, WordPress, PHPGroupWare and TikiWiki. When exploited, this could compromise a vulnerable system…
Checking on port 7111, it happens that there is a spike recently too (UDP on 3 Nov 05).
http://isc.sans.org/port_details.php?port=7111 …
For a list of vulnerable applications, please refer to:
http://www.securityfocus.com/bid/14088/info
If you are running a vulnerable version, you are advised to upgrade immediately:
http://www.securityfocus.com/bid/14088/solution
If you are running Snort, the Snort ID is 3827 (WEB-PHP xmlrpc.php post attempt)…"

:ph34r:
FYI…

- http://news.netcraft.com/archives/2005/11/…gging_apps.html
November 6, 2005 11:44 PM
"Hackers are launching attacks on popular PHP-based blogging, wiki and content management program that failed to patch a serious security hole discovered in July. The attacks exploit flaws in the way PHP libraries handle XML-RPC commands, and appear to be targeting installations of WordPress and Drupal.
If left unpatched, an attacker could compromise a web server through vulnerable programs including WordPress, Drupal, PostNuke, Serendipity, phpAdsNew and phpWiki, among others. These projects all issued fixes six months ago, as did the authors of the affected PHP libraries.
But as is often the case, some web servers and individual blogging applications remain unpatched. The Internet Storm Center has been receiving reports of attacks that install a remote access trojan through a weakness in the XML-RPC function in some PHP libraries, which allow applications to exchange XML data using remote procedure calls (RPC). XML-RPC has many uses in web applications, including "ping" update notifications for RSS feeds. The affected libraries, including PHPXMLRPC and Pear XML-RPC, are included in many interactive applications written in PHP.
The flaws may be of particular interest to phishing operations, which have recently been installing spoof pages through security holes in bulletin boards and content management apps. Updated copies of the affected PHP libraries are now available, and immediate upgrades are recommended."

:ph34r:
FYI…

- http://www.websensesecuritylabs.com/alerts…php?AlertID=331
11/7/2005
"Websense® Security Labs™ is monitoring the spreading of a new worm which targets web servers running vulnerable versions of XML-RPC for PHP. Once the worm infects a web server, it opens a backdoor to the compromised server and begins scanning for additional servers to infect. Versions of XML-RPC for PHP prior to 1.1.1 are vulnerable. XML-RPC for PHP is used in many third-party products, including:
AWStats
PHPGroupWare
phpMyFAQ
PostNuke
PHPWiki
TikiWiki
WordPress

Additional details, along with a complete list of vulnerable products, can be found at the Internet Storm Center: http://isc.sans.org/diary.php?storyid=823
…
The server currently hosting the payload of the worm is hosted in Norway…"

:ph34r:
FYI…

PHP Notes
- http://isc.sans.org/diary.php?storyid=890
Last Updated: 2005-11-23 23:09:40 UTC
"Two items concerning PHP came to us today.
1- Micheal wrote to tell us that phpBB has been working on putting an Incident Response Team together to help users understand how they were attacked and get back on their feet. The announcement is here: http://www.phpbb.com/phpBB/viewtopic.php?t=343745.
2- Juha-Matti wrote to tell us that in reference to an earlier diary about XML-RPC for PHP issues a new script was published at…

XML-RPC for PHP Remote Code Injection Vulnerability
- http://www.securityfocus.com/bid/14088/info
Updated: Nov 23 2005 05:30PM
>>> Solution: http://www.securityfocus.com/bid/14088/solution

;)