Hello everyone,
This evening we noticed a fairly large spike in outbound traffic. After a bit of investigating and suspensions, it looks like there's a WEBMIN related exploit on the loose.
As of right now we're seeing UDP floods pounding away at 91.217.189.77 so if you have SFLOW's, port mirrors, or basic TCPDUMP knowledge (read further down), keep an eye on it.
It looks like the expliot is just the BASH exploit tied together with webmin doing poor validation inside /usr/share/webmin/session_login.cgi.
I've also spotted the following inside /tmp on every VPS so far:
total 232K
drwxrwxrwt 5 root root 4.0K Oct 23 03:37 ./
drwxr-xr-x 21 root root 4.0K Oct 17 06:51 ../
-rwxr-xr-x 1 root root 172K Oct 21 16:33 arm*
drwxrwxrwt 2 root root 4.0K Oct 17 06:51 .ICE-unix/
-rwxr-xr-x 1 root root 37K Oct 21 17:09 mips*
drwxr-xr-x 2 root root 4.0K Oct 17 06:51 .webmin/
-rw-r--r-- 1 root root 0 Oct 21 17:41 .x
drwxrwxrwt 2 root root 4.0K Oct 17 06:51 .X11-unix/
the 'arm' file looks to be an IRC bot: http://pastebin.com/nfsqr7fx
EDIT - Removed the bot commands and moved them to pastebin instead.
Francisco
This evening we noticed a fairly large spike in outbound traffic. After a bit of investigating and suspensions, it looks like there's a WEBMIN related exploit on the loose.
As of right now we're seeing UDP floods pounding away at 91.217.189.77 so if you have SFLOW's, port mirrors, or basic TCPDUMP knowledge (read further down), keep an eye on it.
It looks like the expliot is just the BASH exploit tied together with webmin doing poor validation inside /usr/share/webmin/session_login.cgi.
I've also spotted the following inside /tmp on every VPS so far:
total 232K
drwxrwxrwt 5 root root 4.0K Oct 23 03:37 ./
drwxr-xr-x 21 root root 4.0K Oct 17 06:51 ../
-rwxr-xr-x 1 root root 172K Oct 21 16:33 arm*
drwxrwxrwt 2 root root 4.0K Oct 17 06:51 .ICE-unix/
-rwxr-xr-x 1 root root 37K Oct 21 17:09 mips*
drwxr-xr-x 2 root root 4.0K Oct 17 06:51 .webmin/
-rw-r--r-- 1 root root 0 Oct 21 17:41 .x
drwxrwxrwt 2 root root 4.0K Oct 17 06:51 .X11-unix/
the 'arm' file looks to be an IRC bot: http://pastebin.com/nfsqr7fx
EDIT - Removed the bot commands and moved them to pastebin instead.
Francisco
Last edited by a moderator: