perl/php connect-back backdoor?

From: Ingram (Vailat_private)
Date: Sun Jul 27 2003 - 10:19:52 PDT

  • Next message: wirepair: "is it even possible for a worm with dcom vuln?"

    hi folks,
    
    while pentesting a webserver i found a way to upload cgi/php scripts to
    /cgi-bin, but as verified with hping all ports except 113 (which needs root
    privs) are filtered. Means i couldn't use a portbinding backdoor, because
    all
    i got right know is uid www. I think a connect-back perl/php code could
    made it through this packtfilter, as the outbound rules could be less tight.
    
    Anyone aware of a backdoor like this?
    
    Thx in advantage
    Ingram
    
    -- 
    +++ GMX - Mail, Messaging & more  http://www.gmx.net +++
    
    Jetzt ein- oder umsteigen und USB-Speicheruhr als Prämie sichern!
    



    This archive was generated by hypermail 2b30 : Mon Jul 28 2003 - 12:36:32 PDT