CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 934
Comments: 25
block bottom
spacer spacer

WsIRT(TM)

Webserver Incident Reporting and Termination(TM) Squad

NOTE: Web servers have logs and in those logs is evidence of attempted hacking. For instance, one may notice an attack that calls such a script from a remote server "r57.php??". Its these kinds of attacks we're looking to investigate. For a concrete example, see these reports.

Please do not submit phish, spam, or malware to WsIRT. Only submit attack signatures from web server logs. As this project hasn't officially been publicly launched, we are still reclassifying the tool and its verbiage.

[ How-To / FAQ ]

WsIRT -> Confirmed Attacks | Terminated Attacks


status: confirmed attack

HTTP Response
15 Jul, 2008
02:13:27
HTTP/1.1 404 Not Found
ID1101 (termination link)
Titler57shell
Entry
WsIRT Squad
Reporter
downie
Timestamp18 Dec, 2007 @ 04:03:28
Topic ID211102 - Read/respond to WsIRT commentary.
Handler Note:
22 Dec, 2007
16:43:04
Paul: Please remove this script, it is being used by criminals to take over remote web servers by injection. It gives them shell access.
Handler Note:
22 Dec, 2007
16:43:47
Paul: View CIDR AS3340 Report: http://www.cidr-report.org/cgi-bin/as-report?as=3340

"3340 | EU | ripencc | 1995-03-31 | DataNet Telecommunication Ltd."

Handler Note:
22 Dec, 2007
16:43:48
Paul: Extended information for AS3340:
State/Province:
Country: hu
Responsible Domain: datanet.hu
Abuse Email: abuse@datanet.hu
Handler Note:
22 Dec, 2007
16:45:25
Paul: Generated and sent email attack alert to respective parties.
Fetched URLs

Report for at 18 Dec, 2007 @ 04:03:22


fetched page

at 18 Dec, 2007 @ 04:03:25
MD5 Fingerprint: 07b4494e75af3ccf0cc157728488e84e
SHA1 Fingerprint: 5ce9544b6f1c6820675d27d09d0fc33b2acdfef6
Version 1.0
spacer spacer