Donation/Premium
Survey
WsIRT(TM)
Webs erver Incident Reporting and Termination(TM) Squad
NOTE : Web servers have logs and in those logs is evidence of attempted hacking. For instance, one may notice an attack that calls such a script from a remote server "r57.php??". Its these kinds of attacks we're looking to investigate. For a concrete example, see these reports .
Please do not submit phish , spam , or malware to WsIRT. Only submit attack signatures from web server logs. As this project hasn't officially been publicly launched, we are still reclassifying the tool and its verbiage.
[ How-To / FAQ ]
WsIRT -> Confirmed Attacks |
Terminated Attacks
Select Report Range -------------------- 0-49 status: confirmed attack ID TITLE ENTRY REPORTER TIMESTAMP TOPIC 1186 OS Disclosure, RFI Scanner Public, Simple PHP Injection, id Disclosure http://www.pcr.ac.id/~rina/includes/file/mic. Paul 24 Dec, 2007 @ 04:57:31 211221 1102 C99Shell http://kashiwadaisuke.com/templates_c/contact tetak 19 Dec, 2007 @ 11:36:16 211113 1101 r57shell http://www.netpressz.hu/wap/a.txt downie 18 Dec, 2007 @ 04:03:28 211102 1017 MyShell http://makebuy.50webs.com/admin.php downie 16 Dec, 2007 @ 21:59:19 210717 892 r57shell http://www.rhinoportail.com/cache/bawoek.kece Paul 16 Dec, 2007 @ 19:14:46 210635 863 IRC Bot Shell http://laudanskisucksss.chat.ru/placeholder/i Paul 13 Dec, 2007 @ 00:22:14 210364 723 C99Shell http://fsf.efoot.info/mambots/editors/99.txt downie 10 Dec, 2007 @ 18:21:53 210288 583 Defacing Tool http://br.geocities.com/d4n1loo/tool25.txt?&a Paul 04 Dec, 2007 @ 18:35:35 209642 575 r57shell http://giks.net/php/x/rst.txt?cmd=id Paul 04 Dec, 2007 @ 18:35:35 209646 562 File List Backtool http://www.geocities.com/motoboi777/cmd.tar.g Paul 04 Dec, 2007 @ 18:35:35 209641 533 JA1290shell http://electrobox106.com/7.txt?? Paul 04 Dec, 2007 @ 04:59:59 209649 484 RFI Scanner Public, r57shell http://celebritytemple.com/halle_berry/galler downie 04 Dec, 2007 @ 04:34:30 209588 483 C99Shell, r57shell http://usuarios.lycos.es/mynameiszero/c99.txt Anonymous 03 Dec, 2007 @ 12:44:01 209587 331 C99Shell http://unixsolution.com.br/insecure/priv8/c99 Paul 30 Nov, 2007 @ 19:07:04 209505 273 r57shell http://l1nk3d.kit.net/r57.1?? Paul 29 Nov, 2007 @ 12:11:31 209220 234 id Disclosure http://193.109.188.20/0/templates/rhuk_solarf Paul 28 Nov, 2007 @ 19:39:12 209135 233 Daemon Termination, Evidence Elimination, id Disclosure http://203.166.138.154/manual/vhosts/.,/st? Paul 28 Nov, 2007 @ 19:39:12 209137 187 Qe3shell, r57shell http://kirbyoi.altervista.org/intro/blu.gif?? Paul 28 Nov, 2007 @ 19:39:12 209502 170 C99Shell http://the-sabotage.org/hack/shell/c99.txt? Paul 28 Nov, 2007 @ 19:39:12 209192 139 C99Shell, r57shell http://www.geocities.com/x024_mind/c99.txt? Paul 28 Nov, 2007 @ 19:39:12 209500 129 id Disclosure http://www.madinaedu.gov.sa/safeon.txt?? Paul 28 Nov, 2007 @ 19:39:12 209115 105 OS Disclosure, id Disclosure http://www.sitestorage.info/templates/rhuk_so Paul 28 Nov, 2007 @ 19:39:12 209191 99 OS Disclosure, id Disclosure http://www.trinitymedia.co.za/cache/s.txt?? Paul 28 Nov, 2007 @ 19:39:12 209495 98 id Disclosure http://www.vagrantclan.com/uploads/on.txt? Paul 28 Nov, 2007 @ 19:39:12 209474 94 OS Disclosure, Qe3shell, id Disclosure http://www.zbazaar.com/.ssh/3.jpg?? Paul 28 Nov, 2007 @ 19:39:12 209387 89 OS Disclosure http://zucaina.org/images/wing.jpg? Paul 28 Nov, 2007 @ 19:39:12 209160 87 id Disclosure http://cotine.net/id.txt? Paul 28 Nov, 2007 @ 15:51:33 209170 86 OS Disclosure, id Disclosure http://www.dip-kostroma.ru/bak_skompa/themes/ Paul 28 Nov, 2007 @ 15:51:33 209157 82 OS Disclosure, id Disclosure ftp://80.50.253.90/upload/071011004039p/old? Paul 26 Nov, 2007 @ 19:38:33 208959 80 id Disclosure http://decisepoate.ro/images/id.txt? Paul 26 Nov, 2007 @ 19:38:33 208934 23 id Disclosure http://211.155.235.169/sewam/cmd.txt? Paul 25 Aug, 2007 @ 00:43:06 209040 21 C99Shell http://insidiousdotcom.t35.com/shelly.txt? Paul 24 Aug, 2007 @ 23:41:09 208958 14 Defacing Tool http://englishforbusinessonline.com/tool20.da Paul 24 Aug, 2007 @ 14:43:54 209015 7 id Disclosure http://www.italia-firenze.com/cache/echo.txt? Paul 24 Aug, 2007 @ 14:22:40 208957 3 IRC-WebDownloader, OS Disclosure http://nukedclx.info/php/base? Paul 22 Aug, 2007 @ 21:06:59
Version 1.0