Webserver Incident Reporting and Termination(TM) Squad
NOTE: Web servers have logs and in those logs is evidence of attempted hacking. For instance, one may notice an attack that calls such a script from a remote server "r57.php??". Its these kinds of attacks we're looking to investigate. For a concrete example, see these reports.
Please do not submit phish, spam, or malware to WsIRT. Only submit attack signatures from web server logs. As this project hasn't officially been publicly launched, we are still reclassifying the tool and its verbiage.
"39144 | ES | ripencc | 2005-12-20 | OCHOA-AS Transportes Ochoa_s AS Number"
Handler Note: 29 Nov, 2007 13:16:02
Paul: Extended information for AS39144:
State/Province:
Country:
Responsible Domain: redestel.net
Abuse Email:
Handler Note: 29 Nov, 2007 13:18:24
Paul: Remote webservers are being probed for vulnerabilities, and if found, this script is injected onto those systems to help
the attacker determine various system information illegally.
Handler Note: 29 Nov, 2007 13:18:46
Paul: Generated and sent email attack alert to respective parties.