Full Disclosure mailing list archives

RE: alya.cgi


From: "Todd Towles" <toddtowles () brookshires com>
Date: Mon, 13 Jun 2005 14:34:36 -0500

It appears to be a CGI dropped by a hacker tool. It may execute shell
commands from several different directories. Doesn't anyone use Google
anymore....

Just because Nessus says alya.cgi could be a backdoor doesn't mean it
is..Nessus is a very good VA scanning but it does produce a fair amount
of false positives. 

-----Original Message-----
From: full-disclosure-bounces () lists grok org uk 
[mailto:full-disclosure-bounces () lists grok org uk] On Behalf 
Of Nobody Special
Sent: Monday, June 13, 2005 2:17 PM
To: full-disclosure () lists grok org uk
Subject: [Full-disclosure] alya.cgi

I ran a nessus scan on my neighbor's Soniwall firewall 
appliance's ip address and found out there is an alya.cgi 
file, which is ranked as HIGH risk.  However, no one knows 
what it does beside that "alya.cgi is a cgi backdoor 
distributed with multiple rootkits." 
Does anyone on list know what this cgi can do?  

cokster


              
__________________________________
Do you Yahoo!? 
Read only the mail you want - Yahoo! Mail SpamGuard. 
http://promotions.yahoo.com/new_mail
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: