CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9466.22 of $21422.68
left sidedonated so farneed $11956.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 917
Comments: 22
block bottom
spacer spacer

WsIRT(TM)

Webserver Incident Reporting and Termination(TM) Squad

NOTE: Web servers have logs and in those logs is evidence of attempted hacking. For instance, one may notice an attack that calls such a script from a remote server "r57.php??". Its these kinds of attacks we're looking to investigate. For a concrete example, see these reports.

Please do not submit phish, spam, or malware to WsIRT. Only submit attack signatures from web server logs. As this project hasn't officially been publicly launched, we are still reclassifying the tool and its verbiage.

[ How-To / FAQ ]

WsIRT -> Confirmed Attacks | Terminated Attacks


status: confirmed attack

HTTP Response
15 May, 2008
16:20:31
HTTP/1.1 404 Not Found
ID1186 (termination link)
TitleOS Disclosure, RFI Scanner Public, Simple PHP Injection, id Disclosure
Entry
WsIRT Squad
Reporter
Paul
Timestamp24 Dec, 2007 @ 04:57:31
Topic ID211221 - Read/respond to WsIRT commentary.
Handler Note:
24 Dec, 2007
05:02:54
Paul: mic.txt, if successfully injected into a susceptible web server, will attempt to download an RFI Scanner:

############################################################################
# RFI Scanner
# Public Version Pitbull :)
#
# This one contains the following engines :
# Google, UOL, Libero, MSN, AllTheWeb, ASK, AOL, UOL, Lycos, FireBall, Yahoo
#
# Yahoo is Fixxed ;)
#
############################################################################

Found at http://www.pcr.ac.id/~rina/includes/file/x.txt
Handler Note:
24 Dec, 2007
05:05:00
Paul: If x.txt is successfully downloaded and executed, there are a couple variables pointing to:

http://www.lasiestamadrid.com//portal/images/zoom/PEASCH/sample.jpg?
http://trimedia-online.net/ihmank/id.txt?

There is also a server connection to lelakibiasa.indoirc.net on port 6667 using the nick "PcrX- followed by a random number.
Handler Note:
24 Dec, 2007
05:09:42
Paul: channel and hacked by karawanghack (karawanghackerlink)

Simple PHP Injection - *nix & *BSD OnLy
Handler Note:
24 Dec, 2007
05:09:57
Paul: Consumed following related reports:

[1032] http://www.pcr.ac.id/~rina/includes/file/37.txt??
[1121] http://www.pcr.ac.id/~rina/includes/db/mc2.txt??
[1187] http://www.pcr.ac.id/~rina/includes/file/all.txt??
[1188] http://www.pcr.ac.id/~rina/includes/db/mix.txt??
[1189] http://www.pcr.ac.id/~rina/includes/db/max.txt??
[1190] http://www.pcr.ac.id/~rina/includes/db/gb.txt??
[1191] http://www.pcr.ac.id/~rina/includes/db/gab.txt??
[1192] http://www.pcr.ac.id/~rina/includes/db/gab.txt?
[1193] http://www.pcr.ac.id/~rina/includes/db/37.txt??
Handler Note:
24 Dec, 2007
05:11:55
Paul: http://www.pcr.ac.id/~rina/includes/file/37.txt?? attempts to download http://www.pcr.ac.id/~rina/includes/file/xx.txt which is the rfi scanner. In it is a URL: http://www.pcr.ac.id/~rina/includes/file/37.txt?
Handler Note:
24 Dec, 2007
05:14:36
Paul: http://www.pcr.ac.id/~rina/includes/db/mc2.txt?? calls http://www.pcr.ac.id/~rina/includes/db/x.txt

http://www.pcr.ac.id/~rina/includes/file/all.txt?? calls http://www.pcr.ac.id/~rina/includes/file/x.txt

Handler Note:
24 Dec, 2007
05:16:23
Paul: http://www.pcr.ac.id/~rina/includes/db/gab.txt? calls http://www.pcr.ac.id/~rina/includes/db/z.txt
Handler Note:
24 Dec, 2007
05:17:29
Paul: All these files found in this report are setup to permit attackers compromise of remote webservers by injecting them. Please remove them immediately.
Handler Note:
24 Dec, 2007
05:21:07
Paul: View CIDR AS42237 Report: http://www.cidr-report.org/cgi-bin/as-report?as=42237

"42237 | ES | ripencc | 2007-01-23 | INTERDOMINIOS Grupo Interdominios S.A."

Handler Note:
24 Dec, 2007
05:21:07
Paul: Extended information for AS42237:
State/Province:
Country:
Responsible Domain: interdominios.com
Abuse Email: admin@interdominios.com
Handler Note:
24 Dec, 2007
05:21:35
Paul: View CIDR AS32392 Report: http://www.cidr-report.org/cgi-bin/as-report?as=32392

"32392 | US | arin | 2004-04-26 | OPENTRANSFER-ECOMMERCE - Ecommerce Corporation"

Handler Note:
24 Dec, 2007
05:21:35
Paul: Extended information for AS32392:
State/Province: ky
Country: us
Responsible Domain: ecommerce.com
Abuse Email: abuse@ecommerce.com
Handler Note:
24 Dec, 2007
05:22:05
Paul: View CIDR AS4795 Report: http://www.cidr-report.org/cgi-bin/as-report?as=4795

"4795 | ID | apnic | 1996-10-30 | INDOSAT2-ID INDOSATM2 ASN"

Handler Note:
24 Dec, 2007
05:22:05
Paul: Extended information for AS4795:
State/Province:
Country: id
Responsible Domain: indosat.net.id
Abuse Email: abuse@indosat.net.id
Handler Note:
24 Dec, 2007
05:24:36
Paul: Generated and sent email attack alert to respective parties.
Fetched URLs
Slaves1032, 1121, 1187, 1188, 1189, 1190, 1191, 1192, 1193,

Report for at 24 Dec, 2007 @ 05:02:54


fetched page

at 24 Dec, 2007 @ 05:02:08
MD5 Fingerprint: 4348b36aacad9ca93c5a977901697b92
SHA1 Fingerprint: b491a1cf2686ae4d91a05ed323132030f0800d58

fetched page

at 24 Dec, 2007 @ 05:04:58
MD5 Fingerprint: 14cbf8536c6b068b95910e711244ddc1
SHA1 Fingerprint: ba13c24227a75aa9ea39e93ea17938dbc962b0da

fetched page

at 24 Dec, 2007 @ 05:05:15
MD5 Fingerprint: b6ec1f9a0bbb8439d45162203f435076
SHA1 Fingerprint: a586fcb9035fea2ffd379270758b5bc1fefe8175

fetched page

at 24 Dec, 2007 @ 05:05:35
MD5 Fingerprint: 616562be88caa4a2319a7b3f16231552
SHA1 Fingerprint: 090ed1b9ea85b159af776eafecfdd2c9cd4d80f7

fetched page

at 24 Dec, 2007 @ 05:06:39
MD5 Fingerprint: 14cbf8536c6b068b95910e711244ddc1
SHA1 Fingerprint: ba13c24227a75aa9ea39e93ea17938dbc962b0da

fetched page

at 24 Dec, 2007 @ 05:11:55
MD5 Fingerprint: 98952f368bf1cb4c04ba8f71d554ceb5
SHA1 Fingerprint: 40deb134652774358d34de7fa523b7be2820ce51

fetched page

at 24 Dec, 2007 @ 05:14:36
MD5 Fingerprint: 3a1c9ba7c903dae30b998f7ad4c3fd68
SHA1 Fingerprint: e3a7d108a6143eaaf433b38d914e58f1436eda09

fetched page

at 24 Dec, 2007 @ 05:16:23
MD5 Fingerprint: d41d8cd98f00b204e9800998ecf8427e
SHA1 Fingerprint: da39a3ee5e6b4b0d3255bfef95601890afd80709
Version 1.0
spacer spacer