PoC – “Web Server – Inside Job Attack”
Read the details published by our friends from iGuru.gr
The existence of the mentioned weaknesses is impressive, especially when it comes to 2 of the largest hosting providers in Greece. Furthermore, as reported on iGuru.gr, although an attempt was made to contact the mentioned websites, no one has responded regarding the existence of the weakness, nor has a press release been published.
The following vulnerability has been exploited in two major Web Hosting companies
Why "Web Server – Inside Job Attack"?
The attacker does not need to hack the website. He buys space from one of the above companies and uploads a very small php file. In my case, no firewall, Antivirus, IDS/IPS stopped me.
The attack is based on the rights of the users within the WebServer and I believe that many have the same problem. Some may have been exploiting these for quite some time as both have the same problem.
For security reasons I cannot go into further details but I will show you some images of the Server data.
“Luckily for them, Linux doesn't give you sufficient permissions to read /etc/shadow,” that is, the passwords of their Server users.
What can one do?
- Log files
- /etc/passwd
- Web server directories
Hosts
/etc/passwd

Error Log

Access Log
Server Files
We remain at the disposal of the competent authorities to publish a relevant press release regarding the existence or correction of the mentioned weaknesses to inform the general public, if they deem it appropriate.
With the support of
Note:
We have already updated the above websites and to date we have not received a response.
Source: iGuru.gr









