On 10 May 2012 09:14, Duane <duane@???> wrote:
> A friend of mine thinks php5-suhosin prevents the attack from working.
Suhosin has been harmful other folks say.
https://pierre-schmitz.com/php-5-4-1-in-suhosin-out/
http://mailman.archlinux.org/pipermail/arch-announce/2012-May/000312.html
From duane@??? Thu May 10 08:06:34 2012
Received: from mail.aus-biz.com ([208.82.100.153])
by mail.bitfolk.com with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32)
(Exim 4.72) (envelope-from <duane@???>) id 1SSOOO-00021e-2z
for users@???; Thu, 10 May 2012 08:06:34 +0000
Received: from [192.168.2.141] (220-245-82-41.static.tpgi.com.au
[220.245.82.41])
(using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits))
(Client did not present a certificate)
by mail.aus-biz.com (Postfix) with ESMTPSA id C31C4FF2D3;
Thu, 10 May 2012 18:06:24 +1000 (EST)
Message-ID: <4FAB76FA.1000508@???>
Date: Thu, 10 May 2012 18:06:18 +1000
From: Duane <duane@???>
User-Agent: Mozilla/5.0 (X11; Linux x86_64;
rv:12.0) Gecko/20120430 Thunderbird/12.0.1
MIME-Version: 1.0
To: Kai Hendry <hendry@???>
References: <20120509142238.GR12360@???> <4FAB167B.3080703@???>
<CAF8XF0eKooFxBw5KaEqSdR97gwPmVXvfKXsK8R8O88sNPs755w@???>
In-Reply-To: <CAF8XF0eKooFxBw5KaEqSdR97gwPmVXvfKXsK8R8O88sNPs755w@???>
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Virus-Scanner: Scanned by ClamAV on mail.bitfolk.com at Thu,
10 May 2012 08:06:32 +0000
X-SA-Exim-Connect-IP: 208.82.100.153
X-SA-Exim-Mail-From: duane@???
X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on
spamd0.lon.bitfolk.com
X-Spam-Level:
X-Spam-ASN: AS36252 208.82.96.0/21
X-Spam-Status: No, score=0.7 required=5.0 tests=SPF_NEUTRAL shortcircuit=no
autolearn=disabled version=3.3.1
X-Spam-Report: * 0.7 SPF_NEUTRAL SPF: sender does not match SPF record
(neutral)
X-SA-Exim-Version: 4.2.1 (built Mon, 22 Mar 2010 06:51:10 +0000)
X-SA-Exim-Scanned: Yes (on mail.bitfolk.com)
Cc: users@???
Subject: Re: [bitfolk] PHP-CGI exploit probes seen - please make sure your
VPS is secured against this
X-BeenThere: users@???
X-Mailman-Version: 2.1.13
Precedence: list
List-Id: Users of BitFolk hosting <users.lists.bitfolk.com>
List-Unsubscribe: <https://lists.bitfolk.com/mailman/options/users>,
<mailto:users-request@lists.bitfolk.com?subject=unsubscribe>
List-Archive: <http://lists.bitfolk.com/lurker/list/users.html>
List-Post: <mailto:users@lists.bitfolk.com>
List-Help: <mailto:users-request@lists.bitfolk.com?subject=help>
List-Subscribe: <https://lists.bitfolk.com/mailman/listinfo/users>,
<mailto:users-request@lists.bitfolk.com?subject=subscribe>
X-List-Received-Date: Thu, 10 May 2012 08:06:34 -0000
Kai Hendry wrote:
> On 10 May 2012 09:14, Duane<duane@???> wrote:
>> A friend of mine thinks php5-suhosin prevents the attack from working.
> Suhosin has been harmf