View Full Version : WArning: AWStats Security Hole discovered!
Redleg
Feb 8th 2005, 12:37 pm
Warning, a security hole was recently found in AWStats versions from 5.0 to 6.2 when AWStats is used as a CGI: A remote user can execute arbitrary commands on your server using permissions of your web server user (in most cases user "nobody").
If you use AWStats with another version or with option AllowToUpdateStatsFromBrowser to 0, you are safe. If not, it is highly recommended to update to 6.3 version that fix this security hole.
Hackers have already used this security hole to deface www.phpbb.com
Several popular blogs have also been hacked as well..
http://www.blogherald.com/2005/02/03/awstats-exploit-downs-blogs/
Update Awstats here:
http://awstats.sourceforge.net/
ResaleBroker
Feb 8th 2005, 12:52 pm
Holy Moly! Will it ever end? :rolleyes:
joeychgo
Feb 8th 2005, 12:57 pm
Yeah, it was discovered when they took control over PHPbb's server and locked the phpbb admins out
Chrissicom
Feb 9th 2005, 2:38 am
I think this won't affect awstats users who don't allow public access to their awstats folder right?
I am using AWStats for almost all my domains on IIS6 but it's only accessible with the server admin username and password through the web not as guest user. The server admin name is not Administrator and it's a highly cryptic password as well, so I think it shouldn't be a problem.
mxlabs
Feb 9th 2005, 7:21 am
yup, I don't think there is any risk when running awstats through cPanel or similar panels which use password protection for stats.
Guy G
Feb 9th 2005, 7:40 am
Wow thats major...
*Updates*
Starbug
Feb 9th 2005, 10:17 am
wow.. I had that installed by my hosting company, without the password protection...
It's been removed now :D
Thanks for the info!! :)
Chrissicom
Feb 9th 2005, 11:04 am
if we are already on the AWStats topic here, has anyone reverse lookup enabled to see country data info or does it cost too much bandwidth and server requests? (only around 3000 uniques a day on the measured sites)
ziandra
Jun 28th 2005, 9:58 pm
I wish I had seen this message earlier. I just got finished cleaning two systems of all the crap the script kiddies dropped on it. I wouldn't have noticed it except one of them did not have enough memory to run their programs ;)
The good news is ... as long as awstats was the only mistake you made ... they got access as your web server user and couldn't do much harm. The bad news is ... Had to clean up a bunch of mess. It could have been worse. They could have done some real damage. Seems all they wanted in both cases were machines to host irc bots.
6th Ave
Jun 30th 2005, 1:46 pm
I get hit with this scan several times a day. Although I'm not vulnerable, it's nice to know what they are looking for. Thanks for the update.
vBulletin® v3.6.8, Copyright ©2000-2008, Jelsoft Enterprises Ltd.