Bug#622897: Re: webalizer: remote exploit

2011-04-18 Thread Moritz Muehlenhoff
On Mon, Apr 18, 2011 at 02:05:27PM -0400, Jim Salter wrote: > Package: webalizer > Followup-For: Bug #622897 > > > Moritz, I believe that the initial attack was through webalizer because > the path /var/www/.webalizer contained php injections which gave the > attackers their initial shell, whic

Bug#622897: Re: webalizer: remote exploit

2011-04-18 Thread Julien Viard de Galbert
Hello Jim, As stated in bug #491200 I'm packaging the latest version of webalizer but I didn't get it uploaded yet. On Mon, Apr 18, 2011 at 02:05:27PM -0400, Jim Salter wrote: > Package: webalizer > Followup-For: Bug #622897 > > > Moritz, I believe that the initial attack was through webalizer

Bug#622897: Re: webalizer: remote exploit

2011-04-18 Thread Jim Salter
Package: webalizer Followup-For: Bug #622897 Moritz, I believe that the initial attack was through webalizer because the path /var/www/.webalizer contained php injections which gave the attackers their initial shell, which was first used to host a phishing form which was also under /var/www/we