https://idchowto.com/?p=11694
ZmEu
phpMyadmin 2.X 접속 접근 시도
404 에러를 보면서 취약점을 아나가는 툴로 생각됨
apache access log 분석
‘/phpMyAdmin-2.2.3/scripts/setup.php HTTP/1.1’ 404 311 ‘-‘ ‘ZmEu’
‘/web/phpMyAdmin/index.php HTTP/1.1’ 404 222 ‘-‘ ‘Mozilla/5.0 (Windows NT 6.1) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1’
‘/phpMyAdmin/index.php HTTP/1.1’ 404 218 ‘-‘ ‘Mozilla/5.0 (Windows NT 6.1) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1’
‘/phpMyAdmin-2/index.php HTTP/1.1’ 404 220 ‘-‘ ‘Mozilla/5.0 (Windows NT 6.1) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1’
‘/phpMyAdmin-2.2.3/index.php HTTP/1.1’ 404 224 ‘-‘ ‘Mozilla/5.0 (Windows NT 6.1) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1’
‘ /phpMyAdmin/scripts/setup.php HTTP/1.1’ 404 226 ‘-‘ ‘ZmEu’
‘ /phpMyAdmin/scripts/setup.php HTTP/1.1’ 404 226 ‘-‘ ‘ZmEu’
‘ /phpMyAdmin/translators.html HTTP/1.1’ 404 225 ‘-‘ ‘Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.1) Opera 7.01 [en]’
‘ /phpMyAdmin/translators.html HTTP/1.1’ 404 225 ‘-‘ ‘Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.1) Opera 7.01 [en]’
‘ /phpMyAdmin/translators.html HTTP/1.1’ 404 225 ‘-‘ ‘Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.1) Opera 7.01 [en]’
‘ /3rdparty/phpMyAdmin/scripts/setup.php HTTP/1.1’ 404 235 ‘-‘ ‘ZmEu’
‘ /backup/phpMyAdmin/scripts/setup.php HTTP/1.1’ 404 233 ‘-‘ ‘ZmEu’
‘ /bkup/phpMyAdmin/scripts/setup.php HTTP/1.1’ 404 231 ‘-‘ ‘ZmEu’
‘ /_phpMyAdmin/scripts/setup.php HTTP/1.1’ 404 227 ‘-‘ ‘ZmEu’
‘ /phpMyAdmin/scripts/setup.php HTTP/1.1’ 404 226 ‘-‘ ‘ZmEu’
‘ /phpMyAdmi/scripts/setup.php HTTP/1.1’ 404 225 ‘-‘ ‘ZmEu’
‘ /phpMyAds/scripts/setup.php HTTP/1.1’ 404 224 ‘-‘ ‘ZmEu’
‘ /phpMyA/scripts/setup.php HTTP/1.1’ 404 222 ‘-‘ ‘ZmEu’
‘ //phpMyAdmin/ HTTP/1.1’ 404 778 ‘-‘ ‘Made by ZmEu @ WhiteHat Team – www.whitehat.ro’
‘ //phpMyAdmin2/ HTTP/1.1’ 404 779 ‘-‘ ‘Made by ZmEu @ WhiteHat Team – www.whitehat.ro’
‘ //phpMyAdmin-2/ HTTP/1.1’ 404 211 ‘-‘ ‘Made by ZmEu @ WhiteHat Team – www.whitehat.ro’
‘ //phpMyAdmin//scripts/setup.php HTTP/1.1’ 404 227 ‘-‘ ‘Plesk’
‘ /phpMyAdmin/scripts/setup.php HTTP/1.1’ 404 226 ‘-‘ ‘ZmEu’
‘ /phpMyAdmin/scripts/setup.php HTTP/1.1’ 404 226 ‘-‘ ‘ZmEu’
‘ /phpMyAdmin/scripts/setup.php HTTP/1.1’ 200 3230 ‘-‘ ‘ZmEu’
‘ /phpMyAdmin HTTP/1.1’ 400 226 ‘-‘ ‘Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)’
‘ /phpMyAdmin/ HTTP/1.1’ 404 795 ‘-‘ ‘Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)’
‘ /phpMyAdmin2/ HTTP/1.1’ 404 796 ‘-‘ ‘Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)’
‘ /phpMyAdmin-2/ HTTP/1.1’ 404 211 ‘-‘ ‘Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)’
‘ /phpMyAdmin/scripts/setup.php HTTP/1.1’ 200 3183 ‘-‘ ‘ZmEu’
‘ /phpMyAdmin/main.php HTTP/1.1’ 404 217 ‘-‘ ‘Sharky’
대응방법
Abuse Page 생성
리다이렉션이 될 php 페이지를 생성한다.
ex) http://www.philriesch.com/special/ipblock.php
옵션으로404대신403에러를 보여 툴을 혼란시킬수 있다.
다음의 문구가 들어간 php페이지 생성
header(“HTTP/1.1 403 Forbidden”);
mod_rewrite
User-Agent스트링에 “ZmEu”
.htaccess파일을 웹루트에 생성 및 추가
RewriteEngine on
RewriteCond %{REQUEST_URI} !^/path/to/your/abusefile.php
RewriteCond %{HTTP_USER_AGENT} (.*)ZmEu(.*)
RewriteRule .* http://www.yourdomain.com/path/to/your/abusefile.php[R=301,L]
참조 블로그: http://blog.naver.com/fortop
END
댓글 0
| 번호 | 제목 | 글쓴이 | 날짜 | 조회 수 |
|---|---|---|---|---|
| 24 | apt-get upgrade 수행 시 특정 패키지만 빼고 설치하기 | proin | 2018.10.04 | 0 |
| 23 | apt-get upgrade 수행 시 특정 패키지만 설치하기 | proin | 2018.10.04 | 1 |
| 22 | 필요없을지도 모르지만 왠지 겁나니까 | proin | 2018.10.02 | 2 |
| 21 | Info - XE 백업 및 복원 (통째로 서버 옮기기) | proin | 2018.10.02 | 1 |
| 20 | 워드프레스와 백업(backup) | proin | 2018.10.02 | 0 |
| 19 | iptables 정리 | proin | 2018.10.02 | 3 |
| 18 | 변경된 iptables 저장 방법 | proin | 2018.10.02 | 0 |
| 17 | 내 서버에는 누가 들어오는걸까? (실시간 user-agent 분석기) | proin | 2018.10.02 | 1 |
| 16 | BIND DNS Server | proin | 2018.10.02 | 0 |
| 15 | Setting up a BIND DNS Server | proin | 2018.10.02 | 1 |
| 14 | How To Configure BIND as a Private Network DNS Server on Ubuntu 18.04 | proin | 2018.10.02 | 0 |
| 13 | 뭔가 쓸만 할수도 있는 사이트 | proin | 2018.10.01 | 1 |
| 12 | OpenVPN Access Server 구축하기 | proin | 2018.10.01 | 6 |
| » | ZmEu 해킹시도 접근 | proin | 2018.10.01 | 0 |
| 10 | [Linux] 압축 파일 관리 - gz 압축하기, 압축풀기 | proin | 2018.10.01 | 1 |
| 9 | [devil's camp] - 트위터 봇 만들기 (권준혁) | proin | 2018.09.27 | 0 |
| 8 | 아파치 가상호스트 | proin | 2018.09.26 | 1 |
| 7 | [SPRING] 스프링 시큐리티 (비밀번호 암호화) | proin | 2018.09.19 | 3 |
| 6 | [MySQL] MySQL의 password() 함수와 암호화 | proin | 2018.09.19 | 2 |
| 5 | 안전한 패스워드 저장 | proin | 2018.09.19 | 1 |