Full Disclosure mailing list archives
RE: alya.cgi
From: "Todd Towles" <toddtowles () brookshires com>
Date: Mon, 13 Jun 2005 14:34:36 -0500
It appears to be a CGI dropped by a hacker tool. It may execute shell commands from several different directories. Doesn't anyone use Google anymore.... Just because Nessus says alya.cgi could be a backdoor doesn't mean it is..Nessus is a very good VA scanning but it does produce a fair amount of false positives.
-----Original Message----- From: full-disclosure-bounces () lists grok org uk [mailto:full-disclosure-bounces () lists grok org uk] On Behalf Of Nobody Special Sent: Monday, June 13, 2005 2:17 PM To: full-disclosure () lists grok org uk Subject: [Full-disclosure] alya.cgi I ran a nessus scan on my neighbor's Soniwall firewall appliance's ip address and found out there is an alya.cgi file, which is ranked as HIGH risk. However, no one knows what it does beside that "alya.cgi is a cgi backdoor distributed with multiple rootkits." Does anyone on list know what this cgi can do? cokster __________________________________ Do you Yahoo!? Read only the mail you want - Yahoo! Mail SpamGuard. http://promotions.yahoo.com/new_mail _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- alya.cgi Nobody Special (Jun 13)
- <Possible follow-ups>
- RE: alya.cgi Todd Towles (Jun 13)
