Paul
CastleCops Founder
 Joined: Feb 22, 2002 Posts: 27351
|
Posted: Thu Nov 29, 2007 12:22 pm Post subject: [WsIRT#86] OS Disclosure, id Disclosure @AS30968 |
|
|
Attack Alert Full Report: /OS_Disclosure_id_Disclosure_attack86.html Changed status to confirmed attack. IP Converted: 85.249.135.17
dword = 1442416401
hex1 = 0x55f98711
hex2 = 0x55.0xf9.0x87.0x11
oct = 0125.0371.0207.021
This script is used by an attacker, in this case allegedly UNITED ALBANIANS aka ALBOSS PARADISE, to remotely determine system information of web servers that'll give knowledge as to how they can takeover that system illegally. View CIDR AS30968 Report: http://www.cidr-report.org/cgi-bin/as-report?as=30968
"30968 | RU | ripencc | 2004-01-29 | DATAP-AS Infobox company network, hosting service provider,"<br />
Extended information for AS30968:
State/Province:
Country:
Responsible Domain: infobox.ru
Abuse Email: support@infobox.ru
| Quote: | | http://www.dip-kostroma.ru/bak_skompa/themes/runcms/menu/images/.asc/www????? |
|
|