CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

WsIRT(TM)

Webserver Incident Reporting and Termination(TM) Squad

NOTE: Web servers have logs and in those logs is evidence of attempted hacking. For instance, one may notice an attack that calls such a script from a remote server "r57.php??". Its these kinds of attacks we're looking to investigate. For a concrete example, see these reports.

Please do not submit phish, spam, or malware to WsIRT. Only submit attack signatures from web server logs. As this project hasn't officially been publicly launched, we are still reclassifying the tool and its verbiage.

[ How-To / FAQ ]

WsIRT -> Confirmed Attacks | Terminated Attacks


status: confirmed attack

HTTP Response
21 Nov, 2008
20:30:54
HTTP/1.1 302 Found
HTTP/1.1 404 Not Found
ID483 (termination link)
TitleC99Shell, r57shell
Entry
WsIRT Squad
Reporter
0
Timestamp03 Dec, 2007 @ 12:44:01
Topic ID209587 - Read/respond to WsIRT commentary.
Handler Note:
04 Dec, 2007
05:02:07
Paul: Attackers are trying to inject this script into exploitable web servers which then gives them remote shell access. Please remove.
Handler Note:
04 Dec, 2007
05:02:57
Paul: View CIDR AS12832 Report: http://www.cidr-report.org/cgi-bin/as-report?as=12832

"12832 | DE | ripencc | 1999-12-01 | LYCOS-EUROPE Lycos Europe GmbH"

Handler Note:
04 Dec, 2007
05:03:03
Paul: Extended information for AS12832:
State/Province:
Country: se
Responsible Domain: spray.se
Abuse Email: postmaster@spray.se
Handler Note:
04 Dec, 2007
05:05:42
Paul: Generated and sent email attack alert to respective parties.
Fetched URLs

Report for at 03 Dec, 2007 @ 12:50:01


fetched page

at 03 Dec, 2007 @ 12:50:05
MD5 Fingerprint: 26f22bdcde1f193ad5de4e9f1907034c
SHA1 Fingerprint: 48767f73dac16ed61379602d0d0f0d251903b603

fetched page

at 04 Dec, 2007 @ 05:02:57
MD5 Fingerprint: 669617c94ca55ace85ac96338a012116
SHA1 Fingerprint: c60d43a3ffe6faf837c70618193f2b6541f27a30
Version 1.0
spacer spacer