<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.yobi.be/index.php?action=history&amp;feed=atom&amp;title=Forensics_on_Incident_2</id>
	<title>Forensics on Incident 2 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.yobi.be/index.php?action=history&amp;feed=atom&amp;title=Forensics_on_Incident_2"/>
	<link rel="alternate" type="text/html" href="https://wiki.yobi.be/index.php?title=Forensics_on_Incident_2&amp;action=history"/>
	<updated>2026-05-23T16:04:22Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.8</generator>
	<entry>
		<id>https://wiki.yobi.be/index.php?title=Forensics_on_Incident_2&amp;diff=6795&amp;oldid=prev</id>
		<title>PhilippeTeuwen: Reverted edits by Etegohy (Talk) to last revision by Dpasquazzo</title>
		<link rel="alternate" type="text/html" href="https://wiki.yobi.be/index.php?title=Forensics_on_Incident_2&amp;diff=6795&amp;oldid=prev"/>
		<updated>2010-11-24T20:32:49Z</updated>

		<summary type="html">&lt;p&gt;Reverted edits by &lt;a href=&quot;/index.php?title=Special:Contributions/Etegohy&quot; title=&quot;Special:Contributions/Etegohy&quot;&gt;Etegohy&lt;/a&gt; (&lt;a href=&quot;/index.php?title=User_talk:Etegohy&amp;amp;action=edit&amp;amp;redlink=1&quot; class=&quot;new&quot; title=&quot;User talk:Etegohy (page does not exist)&quot;&gt;Talk&lt;/a&gt;) to last revision by &lt;a href=&quot;/index.php?title=User:Dpasquazzo&amp;amp;action=edit&amp;amp;redlink=1&quot; class=&quot;new&quot; title=&quot;User:Dpasquazzo (page does not exist)&quot;&gt;Dpasquazzo&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Can&#039;t load revision 6795&lt;/p&gt;</summary>
		<author><name>PhilippeTeuwen</name></author>
	</entry>
	<entry>
		<id>https://wiki.yobi.be/index.php?title=Forensics_on_Incident_2&amp;diff=6636&amp;oldid=prev</id>
		<title> at 00:26, 24 November 2010</title>
		<link rel="alternate" type="text/html" href="https://wiki.yobi.be/index.php?title=Forensics_on_Incident_2&amp;diff=6636&amp;oldid=prev"/>
		<updated>2010-11-24T00:26:44Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Can&#039;t load revision 6636&lt;/p&gt;</summary>
		<author><name></name></author>
	</entry>
	<entry>
		<id>https://wiki.yobi.be/index.php?title=Forensics_on_Incident_2&amp;diff=2189&amp;oldid=prev</id>
		<title>Dpasquazzo at 11:53, 15 May 2007</title>
		<link rel="alternate" type="text/html" href="https://wiki.yobi.be/index.php?title=Forensics_on_Incident_2&amp;diff=2189&amp;oldid=prev"/>
		<updated>2007-05-15T11:53:39Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 11:53, 15 May 2007&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 99:&lt;/td&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 99:&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Counter-measures&lt;/div&gt;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Counter-measures&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;** Protect access to catalog/admin&amp;lt;br&amp;gt;This was done but only for https, default conf with Apache was still AllowOverride None for http connections&lt;/div&gt;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;** Protect access to catalog/admin&amp;lt;br&amp;gt;This was done but only for https, default conf with Apache was still AllowOverride None for http connections&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty diff-side-deleted&quot;&gt;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty diff-side-deleted&quot;&gt;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;===OsCommerce Hacked Sites===&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty diff-side-deleted&quot;&gt;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;google Turkey :&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty diff-side-deleted&quot;&gt;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*http://www.starrynightsoftware.net/stl-web/ecommerce/os/catalog/admin&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty diff-side-deleted&quot;&gt;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*http://fashionist.se/catalog/admin/&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty diff-side-deleted&quot;&gt;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*http://usengines.us/&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty diff-side-deleted&quot;&gt;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*http://oscommerce.uksz.net/catalog/admin/&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty diff-side-deleted&quot;&gt;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty diff-side-deleted&quot;&gt;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty diff-side-deleted&quot;&gt;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*http://www.bsunlimitedshop.com/catalog/admin/&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Dpasquazzo</name></author>
	</entry>
	<entry>
		<id>https://wiki.yobi.be/index.php?title=Forensics_on_Incident_2&amp;diff=2188&amp;oldid=prev</id>
		<title>213.219.144.246 at 09:20, 15 May 2007</title>
		<link rel="alternate" type="text/html" href="https://wiki.yobi.be/index.php?title=Forensics_on_Incident_2&amp;diff=2188&amp;oldid=prev"/>
		<updated>2007-05-15T09:20:48Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==Breach in j.b.i. @ y.i==&lt;br /&gt;
===Analysis===&lt;br /&gt;
Initial report: one defaced page http://vserverX/eshare/catalog redirecting to http: // www . test . we-create . org&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Note that if redirection works apparently with IE it didn&amp;#039;t work with iceweasel, I could just see the attempt of redirection in the source of the page: &lt;br /&gt;
&amp;lt;script&amp;gt; window.location=\&amp;quot;http: // www . test . we-create . org/\&amp;quot;; &amp;lt;/script&amp;gt;&lt;br /&gt;
&lt;br /&gt;
# On host: &lt;br /&gt;
apt-get install tct sleuthkit&lt;br /&gt;
&lt;br /&gt;
# Isolate the vserverX&lt;br /&gt;
iptables -I INPUT -d &amp;lt;ip_of_vserverX&amp;gt; -j DROP&lt;br /&gt;
&lt;br /&gt;
# Grep mactimes before touching the system&lt;br /&gt;
grave-robber -o LINUX2 -c /path/to/vserverX/ -b ./vserverX -m &lt;br /&gt;
# mactime from one week ago till now&lt;br /&gt;
mactime -b vserverX -p /path/to/vserverX/etc/passwd mm/dd/yyyy |tee vserverX.mactime&lt;br /&gt;
# apparently mactime could work directly on live system with -d ...&lt;br /&gt;
&lt;br /&gt;
# Search string we-create in /var/www and /var/lib/mysql:&lt;br /&gt;
/var/lib/mysql/oscommerce/configuration.MYD&lt;br /&gt;
&lt;br /&gt;
# Extract corresponding sql table:&lt;br /&gt;
vserverX:/# mysqldump -uuserX -p  --opt oscommerce &amp;gt; oscommerce.sql&lt;br /&gt;
&lt;br /&gt;
# Analyse sql dump:&lt;br /&gt;
INSERT INTO `configuration` VALUES (1,&amp;#039;Store Name&amp;#039;,&amp;#039;STORE_NAME&amp;#039;,&amp;#039;&amp;lt;script&amp;gt; window.location=\&amp;quot;http: // www . test . we-create . org/\&amp;quot;; &amp;lt;/script&amp;gt;&amp;#039;,&amp;#039;The name of my store&amp;#039;,1,1,&amp;#039;2007-05-11 21:04:30&amp;#039;,&amp;#039;2006-12-22 09:32:15&amp;#039;,NULL,NULL)...&lt;br /&gt;
&lt;br /&gt;
# This is the modification apparent on the defaced page, done at &amp;#039;2007-05-11 21:04:30&amp;#039;&lt;br /&gt;
# note that there were other defacing attempts here:&lt;br /&gt;
INSERT INTO `categories_description` VALUES (...&lt;br /&gt;
   ,(25,4,&amp;#039;&amp;lt;script&amp;gt; window.location=\&amp;quot;http:/&amp;#039;)                                                                                                                               &lt;br /&gt;
   ,(25,2,&amp;#039;&amp;lt;script&amp;gt; window.location=\&amp;quot;http:/&amp;#039;)                                                                                                                               &lt;br /&gt;
&lt;br /&gt;
# extract infos around that time from mactime dump:&lt;br /&gt;
May 11 07 21:04:30    25168 m.c -rw-rw---- mysql    munin    /path/to/vserverX/var/lib/mysql/oscommerce/configuration.MYD                                           &lt;br /&gt;
# this is the defacing itself&lt;br /&gt;
May 11 07 21:12:15     3480 m.c drwxrwxrwx root     root     /path/to/vserverX/var/www/eshop/catalog/images                                                         &lt;br /&gt;
                       4396 mac -rwxrwxrwx www-data www-data /path/to/vserverX/var/www/eshop/catalog/images/images.jpg                                              &lt;br /&gt;
# upload of a &amp;quot;we hacked you&amp;quot; image&lt;br /&gt;
                       1164 m.c -rw-rw---- mysql    munin    /path/to/vserverX/var/lib/mysql/oscommerce/categories.MYD                                              &lt;br /&gt;
                       2508 m.c -rw-rw---- mysql    munin    /path/to/vserverX/var/lib/mysql/oscommerce/categories_description.MYD                                  &lt;br /&gt;
# this is the second attempt of defacing of the categories&lt;br /&gt;
&lt;br /&gt;
# extract infos around that time from apache logs (logs cleaned from .js and .gif urls)&lt;br /&gt;
# hacker client: &amp;quot;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)&amp;quot;&lt;br /&gt;
85.105.88.202 - - [11/May/2007:20:55:14 +0200] &amp;quot;GET /eshop/catalog/admin/backup.php?action=restorelocal HTTP/1.1&amp;quot; 200 13939 &amp;quot;http://www.google.com.tr/search?q=inurl:catalog/admin/backup.php&amp;amp;hl=tr&amp;amp;start=40&amp;amp;sa=N&amp;amp;filter=0&amp;quot;&lt;br /&gt;
85.105.88.202 - - [11/May/2007:20:55:58 +0200] &amp;quot;GET /eshop/catalog/admin/backup.php?selected_box=tools&amp;amp;osCAdminID=5340c42e400b2a4aa53923c19fa5ede2 HTTP/1.1&amp;quot; 200 10648 &amp;quot;http://vserverX/eshop/catalog/admin/backup.php?action=restorelocal&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:04:07 +0200] &amp;quot;GET /eshop/catalog/admin/define_language.php HTTP/1.1&amp;quot; 200 18713 &amp;quot;http://vserverX/eshop/catalog/admin/backup.php?selected_box=tools&amp;amp;osCAdminID=5340c42e400b2a4aa53923c19fa5ede2&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:04:11 +0200] &amp;quot;GET /eshop/catalog/admin/define_language.php?lngdir=french&amp;amp;filename=index.php HTTP/1.1&amp;quot; 200 15345 &amp;quot;http://vserverX/eshop/catalog/admin/define_language.php&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:04:13 +0200] &amp;quot;GET /eshop/catalog/admin/define_language.php?lngdir=french HTTP/1.1&amp;quot; 200 18713 &amp;quot;http://vserverX/eshop/catalog/admin/define_language.php?lngdir=french&amp;amp;filename=index.php&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:04:16 +0200] &amp;quot;GET /eshop/catalog/admin/configuration.php?gID=1&amp;amp;selected_box=configuration HTTP/1.1&amp;quot; 200 22252 &amp;quot;http://vserverX/eshop/catalog/admin/define_language.php?lngdir=french&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:04:22 +0200] &amp;quot;GET /eshop/catalog/admin/configuration.php?gID=1&amp;amp;cID=1&amp;amp;action=edit HTTP/1.1&amp;quot; 200 22550 &amp;quot;http://vserverX/eshop/catalog/admin/configuration.php?gID=1&amp;amp;selected_box=configuration&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:04:29 +0200] &amp;quot;POST /eshop/catalog/admin/configuration.php?gID=1&amp;amp;cID=1&amp;amp;action=save HTTP/1.1&amp;quot; 302 - &amp;quot;http://vserverX/eshop/catalog/admin/configuration.php?gID=1&amp;amp;cID=1&amp;amp;action=edit&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:04:30 +0200] &amp;quot;GET /eshop/catalog/admin/configuration.php?gID=1&amp;amp;cID=1 HTTP/1.1&amp;quot; 200 22329 &amp;quot;http://vserverX/eshop/catalog/admin/configuration.php?gID=1&amp;amp;cID=1&amp;amp;action=edit&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:04:30 +0200] &amp;quot;POST /eshop/catalog/admin/configuration.php?gID=1&amp;amp;cID=1&amp;amp;action=save HTTP/1.1&amp;quot; 302 - &amp;quot;http://vserverX/eshop/catalog/admin/configuration.php?gID=1&amp;amp;cID=1&amp;amp;action=edit&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:04:30 +0200] &amp;quot;GET /eshop/catalog/admin/configuration.php?gID=1&amp;amp;cID=1 HTTP/1.1&amp;quot; 200 22329 &amp;quot;http://vserverX/eshop/catalog/admin/configuration.php?gID=1&amp;amp;cID=1&amp;amp;action=edit&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:04:47 +0200] &amp;quot;GET /eshop/catalog/ HTTP/1.1&amp;quot; 200 22419 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:05:05 +0200] &amp;quot;GET /eshop/catalog/ HTTP/1.1&amp;quot; 200 22419 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:05:28 +0200] &amp;quot;GET /eshop/catalog/admin HTTP/1.1&amp;quot; 301 375 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:05:29 +0200] &amp;quot;GET /eshop/catalog/admin/ HTTP/1.1&amp;quot; 200 17760 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:05:40 +0200] &amp;quot;GET /eshop/catalog/admin/file_manager.php?selected_box=tools&amp;amp;osCAdminID=7f009d2bed82fc3c7c9da8f616307e6a HTTP/1.1&amp;quot; 200 109384 &amp;quot;http://vserverX/eshop/catalog/admin/&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:05:46 +0200] &amp;quot;GET /eshop/catalog/admin/file_manager.php?info=index.php HTTP/1.1&amp;quot; 200 109692 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:05:49 +0200] &amp;quot;GET /eshop/catalog/admin/file_manager.php?info=index.php&amp;amp;action=edit HTTP/1.1&amp;quot; 200 33371 &amp;quot;http://vserverX/eshop/catalog/admin/file_manager.php?info=index.php&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:05:52 +0200] &amp;quot;GET /eshop/catalog/admin/file_manager.php?info=index.php HTTP/1.1&amp;quot; 200 109692 &amp;quot;http://vserverX/eshop/catalog/admin/file_manager.php?info=index.php&amp;amp;action=edit&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:05:55 +0200] &amp;quot;GET /eshop/catalog/admin/file_manager.php?info=index.php&amp;amp;action=new_file HTTP/1.1&amp;quot; 200 110032 &amp;quot;http://vserverX/eshop/catalog/admin/file_manager.php?info=index.php&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:11:49 +0200] &amp;quot;GET /eshop/catalog/admin/categories.php?selected_box=catalog HTTP/1.1&amp;quot; 200 14826 &amp;quot;http://vserverX/eshop/catalog/admin/file_manager.php?info=index.php&amp;amp;action=new_file&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:11:51 +0200] &amp;quot;GET /eshop/catalog/admin/categories.php?cPath=&amp;amp;cID=25&amp;amp;action=edit_category HTTP/1.1&amp;quot; 200 15717 &amp;quot;http://vserverX/eshop/catalog/admin/categories.php?selected_box=catalog&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:11:52 +0200] &amp;quot;GET /eshop/catalog/images/homepic4.jpg HTTP/1.1&amp;quot; 404 354 &amp;quot;http://vserverX/eshop/catalog/admin/categories.php?cPath=&amp;amp;cID=25&amp;amp;action=edit_category&amp;quot; &lt;br /&gt;
[Fri May 11 21:11:52 2007] [error] [client 85.105.88.202] File does not exist: /var/www/eshop/catalog/images/homepic4.jpg, referer: http://vserverX/eshop/catalog/admin/categories.php?cPath=&amp;amp;cID=25&amp;amp;action=edit_category&lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:12:15 +0200] &amp;quot;POST /eshop/catalog/admin/categories.php?action=update_category&amp;amp;cPath= HTTP/1.1&amp;quot; 200 1872 &amp;quot;http://vserverX/eshop/catalog/admin/categories.php?cPath=&amp;amp;cID=25&amp;amp;action=edit_category&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:12:32 +0200] &amp;quot;GET /eshop/catalog HTTP/1.1&amp;quot; 301 369 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:12:37 +0200] &amp;quot;GET /eshop/catalog/ HTTP/1.1&amp;quot; 200 22419 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:12:53 +0200] &amp;quot;GET /eshop/ HTTP/1.1&amp;quot; 200 2268 &amp;quot;-&amp;quot; &lt;br /&gt;
&lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:42:13 +0200] &amp;quot;GET /eshop/catalog/admin/backup.php?action=restorelocal HTTP/1.1&amp;quot; 200 13939 &amp;quot;http://www.google.com.tr/search?q=inurl:catalog/admin/backup.php&amp;amp;hl=tr&amp;amp;start=30&amp;amp;sa=N&amp;amp;filter=0&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:42:45 +0200] &amp;quot;GET /eshop/catalog/admin/backup.php?selected_box=tools&amp;amp;osCAdminID=06f47581056b54ad6735566d29bdd3f2 HTTP/1.1&amp;quot; 200 10648 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:42:47 +0200] &amp;quot;GET /eshop/catalog/admin/define_language.php HTTP/1.1&amp;quot; 200 18713 &amp;quot;http://vserverX/eshop/catalog/admin/backup.php?selected_box=tools&amp;amp;osCAdminID=06f47581056b54ad6735566d29bdd3f2&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:42:51 +0200] &amp;quot;GET /eshop/catalog/admin/define_language.php?lngdir=french&amp;amp;filename=index.php HTTP/1.1&amp;quot; 200 15345 &amp;quot;http://vserverX/eshop/catalog/admin/define_language.php&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:42:53 +0200] &amp;quot;GET /eshop/catalog/admin/configuration.php?gID=1&amp;amp;selected_box=configuration HTTP/1.1&amp;quot; 200 22329 &amp;quot;http://vserverX/eshop/catalog/admin/define_language.php?lngdir=french&amp;amp;filename=index.php&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:42:53 +0200] &amp;quot;GET /eshop/catalog/admin/configuration.php?gID=1&amp;amp;selected_box=configuration HTTP/1.1&amp;quot; 200 8152 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:43:06 +0200] &amp;quot;GET /eshop/ HTTP/1.1&amp;quot; 200 2268 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:43:09 +0200] &amp;quot;GET /eshop/catalog/ HTTP/1.1&amp;quot; 200 22419 &amp;quot;http://vserverX/eshop/&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:43:17 +0200] &amp;quot;GET /eshop/catalog/admin HTTP/1.1&amp;quot; 301 375 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:43:17 +0200] &amp;quot;GET /eshop/catalog/admin/ HTTP/1.1&amp;quot; 200 16044 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:43:20 +0200] &amp;quot;GET /eshop/catalog/admin/file_manager.php?selected_box=tools HTTP/1.1&amp;quot; 200 109384 &amp;quot;http://vserverX/eshop/catalog/admin/&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:43:37 +0200] &amp;quot;GET /eshop/catalog/admin/file_manager.php?info=index.php HTTP/1.1&amp;quot; 200 109692 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:43:45 +0200] &amp;quot;GET /eshop/catalog/admin/file_manager.php?info=index.php&amp;amp;action=edit HTTP/1.1&amp;quot; 200 33371 &amp;quot;http://vserverX/eshop/catalog/admin/file_manager.php?info=index.php&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:43:57 +0200] &amp;quot;GET /admin HTTP/1.1&amp;quot; 404 326 &amp;quot;-&amp;quot; &lt;br /&gt;
[Sat May 12 21:43:57 2007] [error] [client 85.105.88.202] File does not exist: /var/www/admin&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Conclusions===&lt;br /&gt;
* Initial breach&lt;br /&gt;
** attack came from 85.105.88.202 = dsl.static.85-105-22730.ttnet.net.tr (Turkish ADSL)&lt;br /&gt;
** this site was found initially by a simple google search (Google Turkey!) for &amp;quot;catalog/admin/backup.php&amp;quot;&amp;lt;br&amp;gt;easy was to find unprotected oscommerce websites...&amp;lt;br&amp;gt;I visit another one from the Google list: http: // oscommerce . uksz . net/catalog/admin/&amp;lt;br&amp;gt;and surprise, Store Name = window.location=&amp;quot;http: // www . test . we-create . org/&amp;quot;;&amp;lt;br&amp;gt;no comment!&lt;br /&gt;
** eshare was defaced via eshop, simply both were sharing the same DB&lt;br /&gt;
* Counter-measures&lt;br /&gt;
** Protect access to catalog/admin&amp;lt;br&amp;gt;This was done but only for https, default conf with Apache was still AllowOverride None for http connections&lt;/div&gt;</summary>
		<author><name>213.219.144.246</name></author>
	</entry>
</feed>