Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 04-15-2006, 11:06 AM   #1
Tipsy
Confirmed User
 
Join Date: Jul 2001
Location: See sig
Posts: 6,989
Server Security Help

A quick question:

One of our servers has been used for spamming. We're almost certain it's via an exploit in a script such as an unsecure form etc. We're currently wading through logs to track it down (mod_security isn't stopping it) but in the meantime does anyone know of a decent scanner that will check a server for known vulerabilities like that?

Most I can find are program specific such as something that looks for unsecure phpbb's. Are there any programs that check for a broad range of possible exploits?
__________________
Ignorance is never bliss.
Tipsy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2006, 11:16 AM   #2
IceMaster
Confirmed User
 
Join Date: Jan 2005
Posts: 8,920
chkrootkit --> http://www.chkrootkit.org/
IceMaster is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2006, 11:20 AM   #3
Tipsy
Confirmed User
 
Join Date: Jul 2001
Location: See sig
Posts: 6,989
Thanks but no help. It's thankfully not rootkit related (run both the rootkit checkers) and as I say pretty certainly a script which will eventually be tracked down via the logs (I hope).

It'd be nice to have something to scan for stuff like this though. Given the amount of exploits in the 1000's of script out there you'd have thought someone would have a nice little script that looks for them
__________________
Ignorance is never bliss.
Tipsy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2006, 11:27 AM   #4
BigBen
Confirmed User
 
Join Date: Nov 2004
Location: scv
Posts: 2,299
http://www.nessus.org/
BigBen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2006, 11:31 AM   #5
chaze
Confirmed User
 
Industry Role:
Join Date: Aug 2002
Posts: 9,752
Quote:
Originally Posted by IceMaster
this is the industry standard right now.
chaze is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2006, 12:46 PM   #6
Tipsy
Confirmed User
 
Join Date: Jul 2001
Location: See sig
Posts: 6,989
Quote:
Originally Posted by BigBen
Thanks - shame their latest release doesn't seem to support bsd 4.9 though Only 5+.

I may give it a go anyway and just copy across any missing bsd5 binaries see if I can get it running.
__________________
Ignorance is never bliss.
Tipsy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.