CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 934
Comments: 25
block bottom
spacer spacer

WsIRT(TM)

Webserver Incident Reporting and Termination(TM) Squad

NOTE: Web servers have logs and in those logs is evidence of attempted hacking. For instance, one may notice an attack that calls such a script from a remote server "r57.php??". Its these kinds of attacks we're looking to investigate. For a concrete example, see these reports.

Please do not submit phish, spam, or malware to WsIRT. Only submit attack signatures from web server logs. As this project hasn't officially been publicly launched, we are still reclassifying the tool and its verbiage.

[ How-To / FAQ ]

WsIRT -> Confirmed Attacks | Terminated Attacks


status: confirmed attack

HTTP Response
15 Jul, 2008
02:13:14
HTTP/1.1 502 Proxy Error
ID723 (termination link)
TitleC99Shell
Entry
WsIRT Squad
Reporter
downie
Timestamp10 Dec, 2007 @ 18:21:53
Topic ID210288 - Read/respond to WsIRT commentary.
Handler Note:
12 Dec, 2007
00:40:20
Paul: This is the c99 shell script written in PHP that attackers are attempting to inject into remote webservers, and if successful, compromises such servers for their nefarious uses. Please remove immediately.

This particular c99's footer: Modded by Shadow & Preddy | http://rootshell-security.net RootShell Security Group.
Handler Note:
12 Dec, 2007
00:41:43
Paul: View CIDR AS41186 Report: http://www.cidr-report.org/cgi-bin/as-report?as=41186

"41186 | FR | ripencc | 2006-06-27 | ISPFR-AS ISPFR"

Handler Note:
12 Dec, 2007
00:41:44
Paul: Extended information for AS41186:
State/Province:
Country:
Responsible Domain: ispfr.net
Abuse Email: tech@ispfr.net
Handler Note:
12 Dec, 2007
00:43:08
Paul: Generated and sent email attack alert to respective parties.
Fetched URLs

Report for at 10 Dec, 2007 @ 18:21:49


fetched page

at 10 Dec, 2007 @ 18:21:52
MD5 Fingerprint: 6c484397e36c8219205a1e95c8014908
SHA1 Fingerprint: a3d5bd47e4e7d969e10d0b449eb4dffbc178f746
Version 1.0
spacer spacer