<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>EntreBits &#187; iptables</title>
	<atom:link href="http://rd.entrebits.com.mx/tag/iptables/feed/" rel="self" type="application/rss+xml" />
	<link>http://rd.entrebits.com.mx</link>
	<description>Blog sobre todo lo que se puede encontrar navegando entre bits</description>
	<lastBuildDate>Sat, 06 Sep 2008 05:01:32 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Seguridad: protegete de espías</title>
		<link>http://rd.entrebits.com.mx/2008/04/16/seguridad-protegete-de-espias/</link>
		<comments>http://rd.entrebits.com.mx/2008/04/16/seguridad-protegete-de-espias/#comments</comments>
		<pubDate>Wed, 16 Apr 2008 07:42:18 +0000</pubDate>
		<dc:creator>Rodrigo</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[iptables]]></category>
		<category><![CDATA[seguridad]]></category>

		<guid isPermaLink="false">http://rd.entrebits.com.mx/?p=22</guid>
		<description><![CDATA[Ha sido una semana muy dura, mucho trabajo y muchas cosas pendientes por hacer.
Estaba revisando los logs de apache y vi unas cosas raras:
69.64.197.157 &#8211; - [15/Apr/2008:07:06:07 -0500] &#8220;GET /phpmyadmin/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;
69.64.197.157 &#8211; - [15/Apr/2008:07:06:07 -0500] &#8220;GET /phpmyadmin/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;
69.64.197.157 &#8211; - [15/Apr/2008:07:06:07 -0500] &#8220;GET /phpMyAdmin/main.php HTTP/1.0&#8243; 404 296 [...]]]></description>
			<content:encoded><![CDATA[<p>Ha sido una semana muy dura, mucho trabajo y muchas cosas pendientes por hacer.</p>
<p>Estaba revisando los logs de apache y vi unas cosas raras:</p>
<blockquote><p>69.64.197.157 &#8211; - [15/Apr/2008:07:06:07 -0500] &#8220;GET /phpmyadmin/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:07 -0500] &#8220;GET /phpmyadmin/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:07 -0500] &#8220;GET /phpMyAdmin/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:07 -0500] &#8220;GET /phpMyAdmin/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:07 -0500] &#8220;GET /PHPMYADMIN/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:07 -0500] &#8220;GET /PHPMYADMIN/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:07 -0500] &#8220;GET /pHpMyAdMiN/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:07 -0500] &#8220;GET /pHpMyAdMiN/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:07 -0500] &#8220;GET /PhPmYaDmIn/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:07 -0500] &#8220;GET /PhPmYaDmIn/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:07 -0500] &#8220;GET /PHPmyadmin/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:07 -0500] &#8220;GET /PHPmyadmin/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:07 -0500] &#8220;GET /PHPMYadmin/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:07 -0500] &#8220;GET /PHPMYadmin/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:07 -0500] &#8220;GET /phpMYadmin/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:07 -0500] &#8220;GET /phpMYadmin/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:07 -0500] &#8220;GET /phpmyADMIN/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:07 -0500] &#8220;GET /phpmyADMIN/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:08 -0500] &#8220;GET /pmamy/main.php HTTP/1.0&#8243; 404 291 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:08 -0500] &#8220;GET /pmamy/main.php HTTP/1.0&#8243; 404 291 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:08 -0500] &#8220;GET /pma/main.php HTTP/1.0&#8243; 404 289 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:08 -0500] &#8220;GET /pma/main.php HTTP/1.0&#8243; 404 289 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:08 -0500] &#8220;GET /PMA/main.php HTTP/1.0&#8243; 404 289 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:08 -0500] &#8220;GET /PMA/main.php HTTP/1.0&#8243; 404 289 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:08 -0500] &#8220;GET /myadmin/main.php HTTP/1.0&#8243; 404 293 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:08 -0500] &#8220;GET /myadmin/main.php HTTP/1.0&#8243; 404 293 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:08 -0500] &#8220;GET /phpmyadmin/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:08 -0500] &#8220;GET /phpmyadmin/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:08 -0500] &#8220;GET /MYADMIN/main.php HTTP/1.0&#8243; 404 293 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:08 -0500] &#8220;GET /MYADMIN/main.php HTTP/1.0&#8243; 404 293 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:08 -0500] &#8220;GET /phpMyAdmin/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:08 -0500] &#8220;GET /phpMyAdmin/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:08 -0500] &#8220;GET /MYadmin/main.php HTTP/1.0&#8243; 404 293 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:08 -0500] &#8220;GET /MYadmin/main.php HTTP/1.0&#8243; 404 293 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:08 -0500] &#8220;GET /PHPMYADMIN/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;<br />
69.64.197.157 &#8211; - [15/Apr/2008:07:06:08 -0500] &#8220;GET /PHPMYADMIN/main.php HTTP/1.0&#8243; 404 296 &#8220;-&#8221; &#8220;-&#8221;</p></blockquote>
<p>Bueno a  primera vista se ve que buscan vulnerabilidades del phpmyadmin, pero primero tienen que saber donde está (si es que está), intentaron con no menos de 100 nombres distintos de carpetas y archivos, así que mejor añadí una regla a las IPTABLES para bannear definitivamente esa ip</p>
<p><code>iptables -A INPUT -s 69.64.197.157  -j DROP<br />
</code></p>
<p>Bueno eso no fui lo único que vi en los logs, también andaba un scanner:</p>
<blockquote><p>67.205.68.215 &#8211; - [15/Apr/2008:17:13:18 -0500] &#8220;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&#8243; 400 300 &#8220;-&#8221; &#8220;-&#8221;<br />
67.205.68.215 &#8211; - [15/Apr/2008:17:13:18 -0500] &#8220;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&#8243; 400 300 &#8220;-&#8221; &#8220;-&#8221;<br />
67.205.68.215 &#8211; - [15/Apr/2008:17:13:18 -0500] &#8220;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&#8243; 400 300 &#8220;-&#8221; &#8220;-&#8221;<br />
67.205.68.215 &#8211; - [15/Apr/2008:17:13:18 -0500] &#8220;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&#8243; 400 300 &#8220;-&#8221; &#8220;-&#8221;<br />
67.205.68.215 &#8211; - [15/Apr/2008:17:13:18 -0500] &#8220;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&#8243; 400 300 &#8220;-&#8221; &#8220;-&#8221;<br />
67.205.68.215 &#8211; - [15/Apr/2008:17:13:18 -0500] &#8220;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&#8243; 400 300 &#8220;-&#8221; &#8220;-&#8221;<br />
67.205.68.215 &#8211; - [15/Apr/2008:17:13:18 -0500] &#8220;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&#8243; 400 300 &#8220;-&#8221; &#8220;-&#8221;</p></blockquote>
<p>Bueno investigando un poco veo que se trata de un <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-011411-1411-99">scanner que busca vulnerabilidades</a> bueno si ponen esa dirección en el navegador <a href="http://67.205.68.215/">http://67.205.68.215/</a> verán que es un servidor con Plesk instalado (en plataforma windows por cierto) ,  bueno aplicando lo mismo agregue una regla para banear esa ip<br />
<code>iptables -A INPUT -s  67.205.68.215 -j DROP</code></p>
<p>Les sugiero que si ven en sus logs algo parecido a esto agreguen unas reglas para banear las ips &#8220;No bienvenidas&#8221;.</p>
]]></content:encoded>
			<wfw:commentRss>http://rd.entrebits.com.mx/2008/04/16/seguridad-protegete-de-espias/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
