Re: FTP scans from wanadoo.fr - MOre info

From: Replugge [Rod] (replugge@alcoholico.org)
Date: 12/18/01


From: "Replugge [Rod]" <replugge@alcoholico.org>
To: incidents@securityfocus.com
Date: 18 Dec 2001 19:58:28 +0100

UFFF .. it seems like this people is looking for iis vulnerabilities all
over the internet.. this look like some mass defacement tools. I
remember a group called poizonb0x used some of those. at least now we
know what they where looking for...

i found some interesting stuff looking around.

"USER ftp" 331 -
"PASS mozilla@" 230 -
"SITE EXEC %020d|%.f%.f|" 500 -

Q: Have there been discovered any vulnerabilities affecting Microsoft's
FTP Services? (If not we probably got a new one).

that looks like some ftp vulnerability on IIS ... i downloaded some
statics made by other users:

Top 5:
  1: t-dialin.net (302 attempts, 30 hosts)
  2: unresolved (280 attempts)
  3: wanadoo.fr (40 attempts, from 10 hosts)
  4: aol.com (30 attempts, from 3 hosts)
  5: telia.com (20 attempts from 1 host)

I believe this could be a mass defacement tool or perhaps we could be
talking about a worm that infects IIS boxes (i don't think so)... lots
of the people have been geting this scans since the beginning of
October.

On Tue, 2001-12-18 at 11:49, dr john halewood wrote:
> There's a distinct pattern to these scans from wanadoo. Looking through some
> logs (I allow anonymous login but with read-only access on one box). I've
> noticed the following:
> the anonymous login password: frequently [A-Z]gpuser@home.com
> an attempt to cd to some directories: /ftproot, /wwwroot, /_vti_bin,
> /_vti_cnf, /cgi-bin, amongst others: the pattern varies, but all requests
> take place within a second, so it's definitely scripted. This is followed by
> an attempt to create a number of directories with a name such as
> 011203022432p, where the first 6 digits are YYMMDD.
>
> Anyone recognise the tool?
>
> Cheers
> john
>
> ----------------------------------------------------------------------------
> This list is provided by the SecurityFocus ARIS analyzer service.
> For more information on this free incident handling, management
> and tracking system please see: http://aris.securityfocus.com
>

-- 

-- /* Rodrigo Gutierrez <rodrigo@trustix.com> Trustix AS - http://www.trustix.com */

---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • CERT Advisory CA-2002-09 Multiple Vulnerabilities in Microsoft IIS
    ... A variety of vulnerabilities exist in various versions of Microsoft ... Some of these vulnerabilities may allow an intruder to execute ... There are a variety of vulnerabilities in Microsoft IIS. ...
    (Cert)
  • Re: Frontpage Security Vulnerability
    ... computer and select to scan for IIS vulnerabilities. ... If you have not done so you should run the IIS Lockdown tool on that server ... > Win2k Server to correct this issue? ...
    (microsoft.public.win2000.security)
  • RE: W32/Nimda.a@mm
    ... I have reapplied the IIS cumulative to all IIS servers ... and am attempting to verify that the server is now protected. ... install the IIS August 15 cumulative patch ... This worm seems to exploit the same vulnerabilities as CodeRed II and ...
    (Focus-Microsoft)
  • Where is the vulnerability?
    ... Is this due to vulnerabilities in IIS, are you saying that because there are possible vulnerabilities in my network? ... I'm more concerned about whether an IIS installation could compromise network security. ... > Think of it this way: If you leave your car at the mall with the keys ...
    (microsoft.public.inetserver.iis)