CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

WsIRT(TM)

Webserver Incident Reporting and Termination(TM) Squad

NOTE: Web servers have logs and in those logs is evidence of attempted hacking. For instance, one may notice an attack that calls such a script from a remote server "r57.php??". Its these kinds of attacks we're looking to investigate. For a concrete example, see these reports.

Please do not submit phish, spam, or malware to WsIRT. Only submit attack signatures from web server logs. As this project hasn't officially been publicly launched, we are still reclassifying the tool and its verbiage.

[ How-To / FAQ ]

WsIRT -> Confirmed Attacks | Terminated Attacks


status: confirmed attack

HTTP Response
21 Nov, 2008
20:30:25
HTTP/1.1 403 Forbidden
ID187 (termination link)
TitleQe3shell, r57shell
Entry
WsIRT Squad
Reporter
Paul
Timestamp28 Nov, 2007 @ 19:39:12
Topic ID209502 - Read/respond to WsIRT commentary.
Handler Note:
03 Dec, 2007
01:13:17
Paul: o---[ FSN - LONG LIVE ETHNIC Kirbyna | <a href=http://www.asc.sh/ target=_blank>WWW.XSHQIPTARETX.ORG</a> | <a href=irc://irc.ascnet.biz/asc target=_blank>Kirbyna 3.5</a> | version ".$version." ]---o
Handler Note:
03 Dec, 2007
01:14:35
Paul: View CIDR AS36351 Report: http://www.cidr-report.org/cgi-bin/as-report?as=36351

"36351 | US | arin | 2005-12-12 | SOFTLAYER - SoftLayer Technologies Inc."

Handler Note:
03 Dec, 2007
01:14:35
Paul: Extended information for AS36351:
State/Province: tx
Country: us
Responsible Domain: softlayer.com
Abuse Email: abuse@softlayer.com
Handler Note:
03 Dec, 2007
01:14:35
Paul: This script bills itself as r57, but it looks like a qe3 instead, modified by "Kirbyna".

This file is being injected by attackers into exploitable web servers which then gives them direct shell access to it. Please remove immediately.
Handler Note:
03 Dec, 2007
01:14:56
Paul: Generated and sent email attack alert to respective parties.
Fetched URLs

Report for at 28 Nov, 2007 @ 19:50:26


fetched page

at 28 Nov, 2007 @ 19:50:27
MD5 Fingerprint: 125cd015d7f0b53b43f3acb18dac7ec8
SHA1 Fingerprint: 473fccf14f34f175ec032a763dbdd344b0a17005
Version 1.0
spacer spacer