Full Disclosure mailing list archives

Re: Apache 2.2.17 exploit?


From: Darren Martyn <d.martyn.fulldisclosure () gmail com>
Date: Mon, 3 Oct 2011 15:43:33 +0100

Thats one worry of mine, which is why I need a computer to test it on :)

I wish I had my own computers to test with right now... Dont think the Uni
will be happy if I accidentally their boxen :P

On Mon, Oct 3, 2011 at 5:32 PM, Laurelai <laurelai () oneechan org> wrote:

 On 10/3/2011 7:31 AM, Darren Martyn wrote:

I regularly trawl Pastebin.com to find code - often idiots leave some 0day
and similar there and it is nice to find.

Well, seeing as I have no test boxes at the moment, can someone check this
code in a VM? I am not sure if it is legit or not.

http://pastebin.com/ygByEV2e

Thanks :)

~Darren


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

 Pretty sure its a trojan.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: