IWAP_WWW account showing up on XP boxes, not just IIS?

From: Jeffrey Thomas (jthomas_at_ETAXFN.COM)
Date: 06/28/04

  • Next message: Jeffrey Thomas: "FWIW - incidents.org inquiring on possible IWAP_WWW account added to recent IIS compromised servers"
    Date:         Mon, 28 Jun 2004 12:07:44 -0400
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Do a google on IWAP_WWW, seems there are XP users discovering this account on their PCs suddenly in the last few days.

    http://64.233.161.104/search?q=cache:1Dt5TJOVP6EJ:amazingtechs.com/index.php%3Fshowtopic%3D14414+IWAP_WWW&hl=en

    IWAM_WWW is a legit account (used by IIS in certain cfgs), but never heard of IWAP_WWW so we may be looking at an attempt to hide a malicious account using a slightly modified name of legit accounts. Could be legit, but more checking definitely needed....I'm leaning towards non-legit account.

    J. Thomas

    -----
    NTBugtraq Editor's Note:

    Want to reply to the person who sent this message? This list is configured such that just hitting reply is going to result in the message coming to the list, not to the individual who sent the message. This was done to help reduce the number of Out of Office messages posters received. So if you want to send a reply just to the poster, you'll have to copy their email address out of the message and place it in your TO: field.
    -----


  • Next message: Jeffrey Thomas: "FWIW - incidents.org inquiring on possible IWAP_WWW account added to recent IIS compromised servers"

    Relevant Pages

    • Re: Changed Name & Lost Access
      ... where xxxyyyzzz is the new password for the thomas account. ... internal disk protects you against about 30% of the usual ... backup system is one that has the backup medium kept ...
      (microsoft.public.win2000.general)
    • Re: Userenv errors
      ... it seems like I'm getting these Userenv errors on several PCs, ... account in your domain? ... Windows 2000 Server and Windows ... PLEASE NOTE the newsgroup SECURE CODE and PASSWORD were ...
      (microsoft.public.windows.server.sbs)
    • Re: Windows 95
      ... The issue with upgrading is my admin has legacy apps that will only work with ... Maryville has a number of factory PCs that connect to older equipment and ... which are running Windows 95 and need access to the network. ... his account gets locked out. ...
      (microsoft.public.win2000.networking)
    • Re: My 1.7GHz Celeron runs at 203MHz!
      ... Bert Kinney ... Thomas Jespersen wrote: ... > Then I tried creating a new user account... ... >> Bert Kinney [MS-MVP DTS] ...
      (microsoft.public.windowsxp.perform_maintain)
    • Re: XP Logons and security issues
      ... If the budget allows I highly recommend a real firewall ... account potential productivity improvements for workers. ... spyware it is best if the users of the computers are not also local ... There are around 14 PCs in all. ...
      (microsoft.public.windowsxp.security_admin)

  • Quantcast