Perl/Exploit SQLinject; Increased Activity on Port 1039

Published: 2003-12-26
Last Updated: 2005-09-13 13:05:17 UTC
by Lorna Hutcheson (Version: 1)
0 comment(s)
Perl/Exploit SQLinject
A fake exploit for phpBB is circulating on security related mailing lists. This exploit claims to take advantage of a SQL Injection vulnerability in phpBB. However, intsead of sending the exploit, the script will try and find a local phpBB user database and send it to a web site as part of the query string. Exploit code should always be treated with care. Fake exploits like this, which include backdoors and other hidden functions are quite common.

http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=153818 http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=100915 http://vil.nai.com/vil/content/v_100915.htm

Increased Activity on Port 1039

Starting on December 24th the activity on Port 1039 increased drastically. The normal daily traffic records for that port was consistantly under 1000. However on the 24th traffic jumped to the hundreds of thousands and the to millions on the 25th and 26th. As far as I can tell the port is used by Dell OMI service.
http://www.seifried.org/security/ports/1000/1039.html
This
service also listens on Port 1037 and 1038. Traffic rose for port 1037 on the 22nd and 23rd and for port 1038 on the 24th before dropping back to normal. It maybe that hackers are looking for all the new Christmas presents. Just keep your eyes open and if you see anything, let us know.

http://isc.incidents.org/port_details.html?port=1037
http://isc.incidents.org/port_details.html?port=1038
http://isc.incidents.org/port_details.html?port=1039


System Lockdowns
As a reminder, don't forget to lock your systems down before putting them on the Internet. Family members and friends will be getting computers and many of them will have little to no experience using them. If you have time, give them a hand or at least point them in the right direction. The free Survival Guide found at http://www.sans.org/rr/papers/index.php?id=1298 is a great place to start. There is also a good guide found at http://www.cert.org/tech_tips/before_you_plug_in.html


Here's wishing you a safe Holiday Season
Lorna Hutcheson
Keywords:
0 comment(s)

Comments


Diary Archives