The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Top Forums > UNIX for Dummies Questions & Answers
Google UNIX.COM


UNIX for Dummies Questions & Answers If you're not sure where to post a UNIX or Linux question, post it here. All UNIX and Linux newbies welcome !!

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Apache help ejbrever UNIX for Dummies Questions & Answers 2 08-24-2006 06:50 AM
Apache ebethea27703 UNIX for Dummies Questions & Answers 1 05-18-2006 06:44 PM
Apache! hassan2 UNIX for Advanced & Expert Users 1 08-07-2002 01:27 PM
Apache Vijayanand IP Networking 1 07-02-2002 05:14 PM
Apache henke UNIX for Dummies Questions & Answers 5 07-31-2001 11:16 AM

Closed Thread
 
Submit Tools LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 02-03-2003
Registered User
 

Join Date: Jul 2002
Location: new york
Posts: 1,025
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit! Stumble this Post!Spurl this Post!
apache

on my webserver, and im sure many of you who also run one see this all the time, but the majority of my access log is filled with attempted exploits from computers compromised by some virus (NIMBDA?) and anyway i know this is harmless to an apache/linux webserver, but its annoying, anyway, on slashdot i saw this:
RedirectMatch permanent (.*)c+dir http://127.0.0.1/scripts/..%255c..%255cwinnt/syste m32/cmd.exe?/c+rundll32.exe+shell32.dll,SHExitWind owsEx%201

to put in the .htaccess file, someone with more knowledge of .htaccess than me, please what does this do? it looks like it would try to execute the command on a windows machine to shut down the computer(exit windows) how does this work? and is it safe to include in my .htaccess file? thanks.
Forum Sponsor
  #2 (permalink)  
Old 02-04-2003
LivinFree's Avatar
Goober Extraordinaire
 

Join Date: Jul 2001
Location: Portland, OR, USA
Posts: 1,584
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit! Stumble this Post!Spurl this Post!
That does appear to be what it does...
While some people think it's only fair, it's of dubious legality since you're using the same exploit against them - It's better to just continue letting them fail, knowing that you won't be affected other than the relatively minor bandwidth consumption. If you redirect them, why not redirect them to a bandwidth-sucker of a web page, such as www.microsoft.com

By the way, what it's doing is redirecting them to the exploit on their local machine, then calling the rundll32 executable to use a function in the specified DLL file that's called when the box logs itself out or reboots. I don't know exactly what happens when you try to log out a service, though - I wonder if it even works. Plus this will only work on an NT/2000 machine that has %systemroot% at C:\WINNT (although it does by default).

Last edited by LivinFree; 02-04-2003 at 06:44 PM.
  #3 (permalink)  
Old 02-05-2003
Registered User
 

Join Date: Jul 2002
Location: new york
Posts: 1,025
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit! Stumble this Post!Spurl this Post!
i see. thanks for the responce. using that probably wouldnt be nice also to the person whos computer is infected and dosnt even know it. maybe even better would be redirecting them to a virus scanning software page. anyway, thanks livinfree
  #4 (permalink)  
Old 02-07-2003
LivinFree's Avatar
Goober Extraordinaire
 

Join Date: Jul 2001
Location: Portland, OR, USA
Posts: 1,584
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit! Stumble this Post!Spurl this Post!
Well, they wouldn't actually see any page you redirected them to... It's not a foreground process. Redirecting them to microsoft.com would, say, distribute bandwidth consumption in a slightly more fair way
  #5 (permalink)  
Old 02-07-2003
Neo's Avatar
Neo Neo is offline
Administrator
 

Join Date: Sep 2000
Location: Asia Pacific
Posts: 4,058
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit! Stumble this Post!Spurl this Post!
We often configure our web servers to redirect web-based viruses back to the origin, defining 'origin' as:

Quote:
A very large software company that is very very rich and powerful, historically has very poor security and is the source of all these classes of virii. -Neo
  #6 (permalink)  
Old 02-08-2003
Registered User
 

Join Date: Jul 2002
Location: new york
Posts: 1,025
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit! Stumble this Post!Spurl this Post!
hahahaha is all i can say to that! thanks for the info.
Google UNIX.COM
Closed Thread

Tags
linux

Thread Tools
Display Modes


The 50 most popular UNIX and Linux searches.
Google Search Cloud for The UNIX and Linux Forums
421 service not available, remote server has closed connection ^m automate ftp autosys awk trim bash eval bash for loop bash split boot: cannot open kernel/sparcv9/unix check if file exists command copy/move folder in unix curses.h cut command in unix find grep find mtime find null character in a unix file from ip can we get machine name +unix glance unix grep or grep recursive inaddr_any inappropriate ioctl for device known problems with fork unix c ksh if last login from unix lynx javascript mailx attachment mget mtime ping port remove first character from string in k shell replace blank spaces by comma , perl script scp recursive segmentation fault(coredump) sftp script snoop unix solaris change ip address stale nfs file handle syn_sent tar exclude tar extract to folder test: argument expected unix unix .profile unix forum unix forums unix interview questions unix mtime unix.com vi substitute


All times are GMT -7. The time now is 06:58 PM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008 The CEP Blog All Rights Reserved -Ad Management by RedTyger Visit The Global Fact Book

Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101