Re: [EMAIL PROTECTED] Please help... apache hacked?

2006-07-15 Thread Ricardo Kleemann
does ANYBODY even know what bots.txt even DOES? bots.txt should look like this: accept all reject altaVista look at virussin.com/bots.txt to see what it SHOULD do... its for SEARCH EINGINES. the bot grabs it, looks at it, and it its on the white list of eingines, it caches the site, if its on

Re: [EMAIL PROTECTED] Please help... apache hacked?

2006-07-15 Thread Ricardo Kleemann
Thanks Max. A first look shows that the script "bots.txt" currently available targets vulnerable installation of "Joomla" and "Mambo". There are some vulnerabilities reported for the included phpBB and an extension called perForms. But how in the first place, is apache even downloading the b

[EMAIL PROTECTED] Please help... apache hacked?

2006-07-14 Thread Ricardo Kleemann
Hi,   I'm running an older version of apache 1.3.28 under a Suse install.   Today I noticed that somehow a bots.txt perl program is being run, yet it is not run from the filesystem. Somehow this script is being downloaded and run.   Yesterday the server was also a victim of an attack from PS