Re: [bitfolk] PHP-CGI exploit probes seen - please make sure…

Top Page

Reply to this message
Author: Ian
Date:  
Subject: Re: [bitfolk] PHP-CGI exploit probes seen - please make sure your VPS is secured against this
m
X-Mailman-Version: 2.1.13
Precedence: list
List-Id: Users of BitFolk hosting <users.lists.bitfolk.com>
List-Unsubscribe: <https://lists.bitfolk.com/mailman/options/users>,
    <mailto:users-request@lists.bitfolk.com?subject=unsubscribe>
List-Archive: <http://lists.bitfolk.com/lurker/list/users.html>
List-Post: <mailto:users@lists.bitfolk.com>
List-Help: <mailto:users-request@lists.bitfolk.com?subject=help>
List-Subscribe: <https://lists.bitfolk.com/mailman/listinfo/users>,
    <mailto:users-request@lists.bitfolk.com?subject=subscribe>
X-List-Received-Date: Tue, 17 Jul 2012 12:06:33 -0000


On 2012-07-17 12:21, Chris Tallon wrote:

> Are there any rules in the IPv6 FORWARD table preventing traffic from
> flowing?
>


Bingo. ip6tables --flush FORWARD, and all works.

Cheers,
Stuart


From mike@??? Wed Jul 18 11:00:31 2012
Received: from mail-ee0-f48.google.com ([74.125.83.48])
    by mail.bitfolk.com with esmtps (TLS1.0:RSA_ARCFOUR_SHA1:16)
    (Exim 4.72) (envelope-from <mike@???>) id 1SrRza-0000Oj-Bb
    for users@???; Wed, 18 Jul 2012 11:00:31 +0000
Received: by eekb57 with SMTP id b57so569991eek.21
    for <users@???>; Wed, 18 Jul 2012 04:00:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=zanker.org; s=google;
    h=message-id:date:from:user-agent:mime-version:to:subject
    :content-type:content-transfer-encoding;
    bh=ttlKnDuLecIgDgXQbfaQTEEx06UOHXPloHMB8psS2mk=;
    b=cvc0EIRW5StVBELwwz7Ne+mGVdJkEgL3LM95hXrqRmGWisMmDCfG/W4YaU9fgTf/+A
    I+XIeCe/kdo1V3AbwVIyGI0iiDuZhk2zlYXmCf4u7zbK3i7Ylrc33nkpgrkKocTj3aGx
    bA5kyzwxb+q6vNcrWpAnQOzMM7ULhG45Q+e6w=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
    d=google.com; s=20120113;
    h=message-id:date:from:user-agent:mime-version:to:subject
    :content-type:content-transfer-encoding:x-gm-message-state;
    bh=ttlKnDuLecIgDgXQbfaQTEEx06UOHXPloHMB8psS2mk=;
    b=I5e5NC16jNSNFNm6bdi7zEktWvg/eKs4hJx1ldNrq7mK5v+BA6Hxeb3UjZg+Y9a0Ja
    e31vK24eftF59q+O3l2I+bn/k7F07N8SRPeSrECvLc7YA5E12iE1GuVSfXBQNw8aKbnG
    0C85IK37SxmWhRFSGfKfdgXyDjgilnLNWytiaLHSfuvWJ7XolWcqge7UDDajz9G52Sjj
    P6LUZ80Ikiy9lXrZ6onyE2zrfFq3/ewB6+yRWLOE9mA75jtQvTgTmK5a0R+OJ3Hp2e+n
    ZtCr/5niR2z5vr0CDYURSY+TBaP5VwHC5NFJyohRsxjuGNL9D/yZqyxL1aDjzrA7HJyZ
    G5pw==
Received: by 10.14.204.72 with SMTP id g48mr3109347eeo.36.1342609224215;
    Wed, 18 Jul 2012 04:00:24 -0700 (PDT)
Received: from [192.168.1.34] (wan-gw.zanker.org. [95.172.230.183])
    by mx.google.com with ESMTPS id d7sm35319015eep.1.2012.07.18.04.00.23
    (version=SSLv3 cipher=OTHER); Wed, 18 Jul