CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

WsIRT(TM)

Webserver Incident Reporting and Termination(TM) Squad

NOTE: Web servers have logs and in those logs is evidence of attempted hacking. For instance, one may notice an attack that calls such a script from a remote server "r57.php??". Its these kinds of attacks we're looking to investigate. For a concrete example, see these reports.

Please do not submit phish, spam, or malware to WsIRT. Only submit attack signatures from web server logs. As this project hasn't officially been publicly launched, we are still reclassifying the tool and its verbiage.

[ How-To / FAQ ]

WsIRT -> Confirmed Attacks | Terminated Attacks


status: confirmed attack

HTTP Response
21 Nov, 2008
19:50:29
HTTP/1.1 404 Not Found
ID89 (termination link)
TitleOS Disclosure
Entry
WsIRT Squad
Reporter
Paul
Timestamp28 Nov, 2007 @ 19:39:12
Topic ID209160 - Read/respond to WsIRT commentary.
Handler Note:
29 Nov, 2007
13:16:01
Paul: View CIDR AS39144 Report: http://www.cidr-report.org/cgi-bin/as-report?as=39144

"39144 | ES | ripencc | 2005-12-20 | OCHOA-AS Transportes Ochoa_s AS Number"

Handler Note:
29 Nov, 2007
13:16:02
Paul: Extended information for AS39144:
State/Province:
Country:
Responsible Domain: redestel.net
Abuse Email:
Handler Note:
29 Nov, 2007
13:18:24
Paul: Remote webservers are being probed for vulnerabilities, and if found, this script is injected onto those systems to help the attacker determine various system information illegally.
Handler Note:
29 Nov, 2007
13:18:46
Paul: Generated and sent email attack alert to respective parties.
Fetched URLs

Report for at 28 Nov, 2007 @ 19:40:01


fetched page

at 28 Nov, 2007 @ 19:40:02
MD5 Fingerprint: 28b61a457f54849a819fee366ab733cb
SHA1 Fingerprint: 9099014e03c4bca1dd9fa22be2e631432519076e
Version 1.0
spacer spacer