Bonjour,
Matthieu Marcillaud a écrit :
Je viens de mettre en place un nouveau site http://www.countrysaintesbuffalodancers17.com
avec Spip 2.0.10 + Zpip + ZenGarden
Par contre tu as bel et bien un trojan qui est arrivé au moins dans tmp/cache/skel (du coup tous les caches générés par SPIP l'ont aussi). Si le trojan n'a pas été introduit via SPIP (y a peu de chance)
(les squelettes ont l'air clean aussi), c'est que quelqu'un est entré par une autre porte... Faut donc changer les serrures ; et essayer d'analyser les logs pour trouver comment le gars est entré...
J'ai relancé SPIP_loader, ça a l'air d'avoir écrasé les fichiers JS vérolés.
Dans les logs, que dois-je chercher ?
Je vois en http :
- des GET et de POST depuis des IP 8x. 9x. qui doivent être des Orange.
- des GET depuis 66.249.65.229 Googlebot
66.249.65.229 www.countrysaintesbuffalodancers17.com - [10/Jan/2010:02:53:17 +0100] "GET /spip.php?page=backend HTTP/1.1" 200 4534 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +What Is Googlebot | Google Search Central | Documentation | Google for Developers)"
- un HEAD bizarre :
194.72.238.62 www.countrysaintesbuffalodancers17.com - [10/Jan/2010:02:53:41 +0100] "HEAD / HTTP/1.0" 200 - "http://www.netcraft.com/survey/" "Mozilla/4.0 (compatible; Netcraft Web Server Survey)"
En FTP :
[2010 Jan 8 14:30:26] vsftpd: Fri Jan 8 14:30:26 2010 [pid 21137] [countrys] FTP response: Client "74.208.166.27", "150 Opening BINARY mode data connection for ajaxCallback.js (10558 bytes)."
[2010 Jan 8 14:30:27] vsftpd: Fri Jan 8 14:30:27 2010 [pid 21137] [countrys] OK DOWNLOAD: Client "74.208.166.27", "/www/prive/javascript/ajaxCallback.js", 10558 bytes, 27.18Kbyte/sec
[2010 Jan 8 14:30:27] vsftpd: Fri Jan 8 14:30:27 2010 [pid 21137] [countrys] FTP response: Client "74.208.166.27", "226 File send OK."
[2010 Jan 8 14:30:27] vsftpd: Fri Jan 8 14:30:27 2010 [pid 21137] [countrys] FTP command: Client "74.208.166.27", "QUIT"
[2010 Jan 8 14:30:27] vsftpd: Fri Jan 8 14:30:27 2010 [pid 21137] [countrys] FTP response: Client "74.208.166.27", "221 Goodbye."
[2010 Jan 8 14:31:51] vsftpd: Fri Jan 8 14:31:51 2010 [pid 14586] [countrys] FTP response: Client "212.34.138.195", "331 Please specify the password."
[2010 Jan 8 14:31:52] vsftpd: Fri Jan 8 14:31:52 2010 [pid 14586] [countrys] FTP command: Client "212.34.138.195", "PASS <password>"
[2010 Jan 8 14:31:52] vsftpd: Fri Jan 8 14:31:52 2010 [pid 14585] [countrys] OK LOGIN: Client "212.34.138.195"
[2010 Jan 8 14:31:52] vsftpd: Fri Jan 8 14:31:52 2010 [pid 14610] [countrys] FTP response: Client "212.34.138.195", "230 Login successful."
[2010 Jan 8 14:31:52] vsftpd: Fri Jan 8 14:31:52 2010 [pid 14610] [countrys] FTP command: Client "212.34.138.195", "PWD"
[2010 Jan 8 14:31:52] vsftpd: Fri Jan 8 14:31:52 2010 [pid 14610] [countrys] FTP response: Client "212.34.138.195", "257 "/""
[2010 Jan 8 14:31:52] vsftpd: Fri Jan 8 14:31:52 2010 [pid 14610] [countrys] FTP command: Client "212.34.138.195", "CWD www"
[2010 Jan 8 14:31:52] vsftpd: Fri Jan 8 14:31:52 2010 [pid 14610] [countrys] FTP response: Client "212.34.138.195", "250 Directory successfully changed."
[2010 Jan 8 14:31:52] vsftpd: Fri Jan 8 14:31:52 2010 [pid 14610] [countrys] FTP command: Client "212.34.138.195", "CWD prive"
[2010 Jan 8 14:31:52] vsftpd: Fri Jan 8 14:31:52 2010 [pid 14610] [countrys] FTP response: Client "212.34.138.195", "250 Directory successfully changed."
[2010 Jan 8 14:31:53] vsftpd: Fri Jan 8 14:31:53 2010 [pid 14610] [countrys] FTP command: Client "212.34.138.195", "CWD javascript"
[2010 Jan 8 14:31:53] vsftpd: Fri Jan 8 14:31:53 2010 [pid 14610] [countrys] FTP response: Client "212.34.138.195", "250 Directory successfully changed."
[2010 Jan 8 14:31:53] vsftpd: Fri Jan 8 14:31:53 2010 [pid 14610] [countrys] FTP command: Client "212.34.138.195", "EPSV"
[2010 Jan 8 14:31:53] vsftpd: Fri Jan 8 14:31:53 2010 [pid 14610] [countrys] FTP response: Client "212.34.138.195", "229 Entering Extended Passive Mode (|||34384|)"
[2010 Jan 8 14:31:54] vsftpd: Fri Jan 8 14:31:54 2010 [pid 14610] [countrys] FTP command: Client "212.34.138.195", "TYPE I"
[2010 Jan 8 14:31:54] vsftpd: Fri Jan 8 14:31:54 2010 [pid 14610] [countrys] FTP response: Client "212.34.138.195", "200 Switching to Binary mode."
[2010 Jan 8 14:31:54] vsftpd: Fri Jan 8 14:31:54 2010 [pid 14610] [countrys] FTP command: Client "212.34.138.195", "SIZE jquery.ifixpng.js"
[2010 Jan 8 14:31:54] vsftpd: Fri Jan 8 14:31:54 2010 [pid 14610] [countrys] FTP response: Client "212.34.138.195", "213 3885"
[2010 Jan 8 14:31:54] vsftpd: Fri Jan 8 14:31:54 2010 [pid 14610] [countrys] FTP command: Client "212.34.138.195", "RETR jquery.ifixpng.js"
[2010 Jan 8 14:31:54] vsftpd: Fri Jan 8 14:31:54 2010 [pid 14610] [countrys] FTP response: Client "212.34.138.195", "150 Opening BINARY mode data connection for jquery.ifixpng.js (3885 bytes)."
[2010 Jan 8 14:31:54] vsftpd: Fri Jan 8 14:31:54 2010 [pid 14610] [countrys] OK DOWNLOAD: Client "212.34.138.195", "/www/prive/javascript/jquery.ifixpng.js", 3885 bytes, 80.55Kbyte/sec
[2010 Jan 8 14:31:54] vsftpd: Fri Jan 8 14:31:54 2010 [pid 14610] [countrys] FTP response: Client "212.34.138.195", "226 File send OK."
[2010 Jan 8 14:31:54] vsftpd: Fri Jan 8 14:31:54 2010 [pid 14610] [countrys] FTP command: Client "212.34.138.195", "QUIT"
[2010 Jan 8 14:31:54] vsftpd: Fri Jan 8 14:31:54 2010 [pid 14610] [countrys] FTP response: Client "212.34.138.195", "221 Goodbye."
[2010 Jan 8 14:30:27] vsftpd: Fri Jan 8 14:30:27 2010 [pid 10315] [countrys] FTP response: Client "91.135.229.250", "331 Please specify the password."
[2010 Jan 8 14:30:27] vsftpd: Fri Jan 8 14:30:27 2010 [pid 10315] [countrys] FTP command: Client "91.135.229.250", "PASS <password>"
[2010 Jan 8 14:30:28] vsftpd: Fri Jan 8 14:30:28 2010 [pid 10314] [countrys] OK LOGIN: Client "91.135.229.250"
[2010 Jan 8 14:30:28] vsftpd: Fri Jan 8 14:30:28 2010 [pid 10322] [countrys] FTP response: Client "91.135.229.250", "230 Login successful."
[2010 Jan 8 14:30:28] vsftpd: Fri Jan 8 14:30:28 2010 [pid 10322] [countrys] FTP command: Client "91.135.229.250", "PWD"
[2010 Jan 8 14:30:28] vsftpd: Fri Jan 8 14:30:28 2010 [pid 10322] [countrys] FTP response: Client "91.135.229.250", "257 "/""
[2010 Jan 8 14:30:28] vsftpd: Fri Jan 8 14:30:28 2010 [pid 10322] [countrys] FTP command: Client "91.135.229.250", "CWD www"
[2010 Jan 8 14:30:28] vsftpd: Fri Jan 8 14:30:28 2010 [pid 10322] [countrys] FTP response: Client "91.135.229.250", "250 Directory successfully changed."
[2010 Jan 8 14:30:28] vsftpd: Fri Jan 8 14:30:28 2010 [pid 10322] [countrys] FTP command: Client "91.135.229.250", "CWD prive"
[2010 Jan 8 14:30:28] vsftpd: Fri Jan 8 14:30:28 2010 [pid 10322] [countrys] FTP response: Client "91.135.229.250", "250 Directory successfully changed."
[2010 Jan 8 14:30:28] vsftpd: Fri Jan 8 14:30:28 2010 [pid 10322] [countrys] FTP command: Client "91.135.229.250", "CWD javascript"
[2010 Jan 8 14:30:28] vsftpd: Fri Jan 8 14:30:28 2010 [pid 10322] [countrys] FTP response: Client "91.135.229.250", "250 Directory successfully changed."
[2010 Jan 8 14:30:28] vsftpd: Fri Jan 8 14:30:28 2010 [pid 10322] [countrys] FTP command: Client "91.135.229.250", "EPSV"
[2010 Jan 8 14:30:28] vsftpd: Fri Jan 8 14:30:28 2010 [pid 10322] [countrys] FTP response: Client "91.135.229.250", "229 Entering Extended Passive Mode (|||24170|)"
[2010 Jan 8 14:30:29] vsftpd: Fri Jan 8 14:30:29 2010 [pid 10322] [countrys] FTP command: Client "91.135.229.250", "TYPE I"
[2010 Jan 8 14:30:29] vsftpd: Fri Jan 8 14:30:29 2010 [pid 10322] [countrys] FTP response: Client "91.135.229.250", "200 Switching to Binary mode."
[2010 Jan 8 14:30:29] vsftpd: Fri Jan 8 14:30:29 2010 [pid 10322] [countrys] FTP command: Client "91.135.229.250", "STOR ajaxCallback.js"
[2010 Jan 8 14:30:29] vsftpd: Fri Jan 8 14:30:29 2010 [pid 10322] [countrys] FTP response: Client "91.135.229.250", "150 Ok to send data."
[2010 Jan 8 14:30:29] vsftpd: Fri Jan 8 14:30:29 2010 [pid 10322] [countrys] OK UPLOAD: Client "91.135.229.250", "/www/prive/javascript/ajaxCallback.js", 11713 bytes, 27.73Kbyte/sec
[2010 Jan 8 14:30:29] vsftpd: Fri Jan 8 14:30:29 2010 [pid 10322] [countrys] FTP response: Client "91.135.229.250", "226 File receive OK."
[2010 Jan 8 14:30:29] vsftpd: Fri Jan 8 14:30:29 2010 [pid 10322] [countrys] FTP command: Client "91.135.229.250", "QUIT"
[2010 Jan 8 14:30:29] vsftpd: Fri Jan 8 14:30:29 2010 [pid 10322] [countrys] FTP response: Client "91.135.229.250", "221 Goodbye."
On dirait que ajaxCallback.js est envoyé une première fois à 14:30:27 avec 10558 octets,
puis une seconde fois à 14:30:29 avec 11713 octets... avec un "Client" différent...
Et après cette liste de logs, les logs suivants reviennent à 14:27:58...
Des explications pour moi ??
Merci