Welcome, Guest. Please login or register.

Author Topic: Is Aminet OK/infected?  (Read 13103 times)

Description:

0 Members and 1 Guest are viewing this topic.

Offline LoadWB

  • Hero Member
  • *****
  • Join Date: Jul 2006
  • Posts: 2901
  • Country: 00
    • Show all replies
Re: Is Aminet OK/infected?
« on: May 11, 2012, 05:19:50 AM »
AVG: Script/Exploit.Kit

:(
 

Offline LoadWB

  • Hero Member
  • *****
  • Join Date: Jul 2006
  • Posts: 2901
  • Country: 00
    • Show all replies
Re: Is Aminet OK/infected?
« Reply #1 on: May 11, 2012, 11:14:47 PM »
Quote from: Piru;692794
Did you manage to find out how the initial exploitation vector was? That's the most important thing to figure out. If the hole isn't fixed properly you might just get pwned again.

The timing of these issues makes me think of the recent mod_cgi PHP command injection vuln:
http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/


I was discussing this earlier today with a colleague.  Why run PHP as a CGI under *nix rather than a compiled so or compiled into the httpd?  On Windows I can see it (FastCGI,) but on a *nix machine I just don't see an advantage.