[Owncloud] cgi-bin attacks

Mohammad Naghavi mohamnag at gmail.com
Wed Jan 29 12:41:48 UTC 2014

​Hi everybody,
I'm new to owncloud and just started using it since two days but I just
found out that I have been just attacked. they are trying requests similar
to the following with different target urls:

quest: "POST
HTTP/1.1", host: "

​which decodes to:

quest: "POST /cgi-bin/php4?-d allow_url_include=on -d safe_mode=off -d
suhosin.simulation=on -d disable_functions="" -d open_basedir=none -d
auto_prepend_file=php://input -d cgi.force_redirect=0 -d
cgi.redirect_status_env=0 -n HTTP/1.1", host: "XXX.XXX.XXX.XXX"

I'm using OC 6.0.1 and I want to know if my server is prone to such attacks
or not.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.kde.org/pipermail/owncloud/attachments/20140129/bd96a1fd/attachment.html>

More information about the Owncloud mailing list