It appears to be a CGI dropped by a hacker tool. It may execute shell commands from several different directories. Doesn't anyone use Google anymore....
Just because Nessus says alya.cgi could be a backdoor doesn't mean it is..Nessus is a very good VA scanning but it does produce a fair amount of false positives. > -----Original Message----- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf > Of Nobody Special > Sent: Monday, June 13, 2005 2:17 PM > To: [email protected] > Subject: [Full-disclosure] alya.cgi > > I ran a nessus scan on my neighbor's Soniwall firewall > appliance's ip address and found out there is an alya.cgi > file, which is ranked as HIGH risk. However, no one knows > what it does beside that "alya.cgi is a cgi backdoor > distributed with multiple rootkits." > Does anyone on list know what this cgi can do? > > cokster > > > > __________________________________ > Do you Yahoo!? > Read only the mail you want - Yahoo! Mail SpamGuard. > http://promotions.yahoo.com/new_mail > _______________________________________________ > Full-Disclosure - We believe in it. > Charter: http://lists.grok.org.uk/full-disclosure-charter.html > Hosted and sponsored by Secunia - http://secunia.com/ > _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
