[Mailman-Users] message about probes

Gruver, Sandi sgruver at cis.ctc.edu
Mon Apr 27 22:55:47 CEST 2009

>From the mailman server's Logwatch program:

A total of 1 sites probed the server

!!!! 2 possible successful probes
 /mailman/private/sqlhelp///includes/session.php?baseDir=../../../../../../../../etc/passwd HTTP Response 200
 /mailman/admin///includes/session.php?baseDir=../../../../../../../../etc/passwd HTTP Response 200

Is this likely a probe only or a notification of a compromise?

Thank you,

More information about the Mailman-Users mailing list