CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 952
Comments: 28
block bottom
spacer spacer

WsIRT(TM)

Webserver Incident Reporting and Termination(TM) Squad

NOTE: Web servers have logs and in those logs is evidence of attempted hacking. For instance, one may notice an attack that calls such a script from a remote server "r57.php??". Its these kinds of attacks we're looking to investigate. For a concrete example, see these reports.

Please do not submit phish, spam, or malware to WsIRT. Only submit attack signatures from web server logs. As this project hasn't officially been publicly launched, we are still reclassifying the tool and its verbiage.

[ How-To / FAQ ]

WsIRT -> Confirmed Attacks | Terminated Attacks


status: confirmed attack

HTTP Response
11 Oct, 2008
07:51:03
HTTP/1.1 502 Proxy Error
ID1017 (termination link)
TitleMyShell
Entry
WsIRT Squad
Reporter
downie
Timestamp16 Dec, 2007 @ 21:59:19
Topic ID210717 - Read/respond to WsIRT commentary.
Handler Note:
18 Dec, 2007
03:01:48
Paul: Criminals are attempting to inject this script into remote webservers which if successful gives them control and permits them to do nefarious things. Please remove it immediately.
Handler Note:
18 Dec, 2007
03:02:23
Paul: View CIDR AS19166 Report: http://www.cidr-report.org/cgi-bin/as-report?as=19166

"19166 | US | arin | 2005-05-31 | ALPHARED-HOUSTON - Alpha Red, INC"

Handler Note:
18 Dec, 2007
03:02:24
Paul: Extended information for AS19166:
State/Province: tx
Country: us
Responsible Domain: alphared.com
Abuse Email: james@alphared.com
Handler Note:
18 Dec, 2007
03:03:12
Paul: Generated and sent email attack alert to respective parties.
Fetched URLs

Report for at 16 Dec, 2007 @ 21:59:12


fetched page

at 16 Dec, 2007 @ 21:59:15
MD5 Fingerprint: df38c05eb2d3c16b8aed54efe57dfa5d
SHA1 Fingerprint: 37b57aeea23c995ad0769dd0b0600913f2c764ba
Version 1.0
spacer spacer