On Mar 3, 2005, at 12:11 AM, Thomas Cameron wrote:
<snip>
Look in /var/tmp - anything there called aVe or uselib24 or bots.txt? Also, look in your /var/log/httpd area for anything weird in access_log or error_log.
Yes, I did have a couple of PERL programs in /var/tmp. One was called https and it is attached.
As far as I understand this vulnerability it is limited to the user Apache is run by correct?
Thanks -cs
Attachment:
https
Description: Binary data