RE: Increased IIS scans mainly on 66.0.0.0/8 - Update

From: Richard Gilman (Richard.Gilman@ntn.com)
Date: 08/19/02


Date: Mon, 19 Aug 2002 08:19:12 -0700
From: "Richard Gilman" <Richard.Gilman@ntn.com>
To: <incidents@securityfocus.com>

I did a query of the WEB-IIS cmd.exe access alerts for 8/15 on our
66.0.0.0/8 network and I see 31 sources each send in multiples of 13
attempts. Of the 31 hosts, 3 sources were not from 66/8. One of those
was from wanadoo.fr with 130 hits. The hits can come as fast as 2 per
second, so I assume that it has to be scripted. This is only an
annoyance and does not do anything more that make noise in my logs, but
I think it is some sort of worm because of the fact they all send in
multiples of 13 and it seems that the odds of having 31 script kiddies
running the same script against our site in the same day is fairly low
and over a month we have 448 different sources doing the same thing.
Just an observation if you are interested.

 

Rich

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: BioPerl Range() Issue
    ... and am writing a script to automate the whole process. ... from one of my hits, it sometimes returns an invalid subsequence. ...
    (perl.beginners)
  • Re: TOPcast mp3s gone as of 1:20 PDT
    ... but the script that serves ... them up (and counts the hits on them) blew up earlier today. ... It's blown ...
    (rec.games.pinball)
  • Need a help on this Script
    ... I am a software developer and I have a written a script which will read the ... configuration like to address, subject of the mail and the threshold value. ... port | Hits ...
    (perl.beginners)
  • CGI-Citys CCLOG Script Injection Vulns
    ... CGI-City's CCLOG USER-AGENT and REFERER Script Injection ... CC Log is a very simple logging script which logs the hits to ...
    (Bugtraq)
  • Re: recursive find to display directory
    ... I need to recursively find and display a folder ... > retrurns eight hits, including the files. ... I need a NT script or VB script to return just ...
    (microsoft.public.win2000.cmdprompt.admin)