RE: strange ftp site

From: David E. Mollico Jr (dmollico_at_MOLLICO.com)
Date: 10/30/03

  • Next message: David Gillett: "RE: [inbox] RE: Bogus DNS traffic"
    Date: Thu, 30 Oct 2003 10:25:29 -0600
    To: "info hunter" <sp3ct0r@yahoo.com>, <incidents@securityfocus.com>
    
    

    I would stay very far away from this website. It looks like those dll's
    have interaction with the kernel file. I'd build a test computer and run
    it on there to see what It will do.

    -----Original Message-----
    From: info hunter [mailto:sp3ct0r@yahoo.com]
    Sent: Thursday, October 30, 2003 9:24 AM
    To: incidents@securityfocus.com
    Subject: strange ftp site

    Excuse my ignorance but need some help here.

    Anyone know anything about this ftp site ftp://66.159.219.196

    Noticed a firewall log showing a system hitting this address . Their
    seems to be an exe and and some dll's. When running the exe a dialog
    box named test pops up and displays the text "if you can see this, email
    eric".

    Sam spade showed a badly configured dns. Would appreciate any input on
    this. It may be completly benign or maybe even just legit. Just seems
    strange or I may be just paranoid.

    ------------------------------------------------------------------------

    ---
    Network with over 10,000 of the brightest minds in information security
    at the largest, most highly-anticipated industry event of the year.
    Don't miss RSA Conference 2004! Choose from over 200 class sessions and
    see demos from more than 250 industry vendors. If your job touches
    security, you need to be here. Learn more or register at
    http://www.securityfocus.com/sponsor/RSA_incidents_031023
    and use priority code SF4.
    ------------------------------------------------------------------------
    ----
    ---------------------------------------------------------------------------
    Network with over 10,000 of the brightest minds in information security
    at the largest, most highly-anticipated industry event of the year.
    Don't miss RSA Conference 2004! Choose from over 200 class sessions and
    see demos from more than 250 industry vendors. If your job touches
    security, you need to be here. Learn more or register at
    http://www.securityfocus.com/sponsor/RSA_incidents_031023
    and use priority code SF4.
    ----------------------------------------------------------------------------
    

  • Next message: David Gillett: "RE: [inbox] RE: Bogus DNS traffic"

    Relevant Pages

    • RE: New Trojan
      ... Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ... Learn more or register at ... and use priority code SF4. ...
      (Incidents)
    • RE: New Trojan
      ... > There are tools available to let you see and manipulate an Alternate Data Stream. ... > Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ... Learn more or register at ...
      (Incidents)
    • Re: strange ftp site
      ... >Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ... Learn more or register at ... >and use priority code SF4. ...
      (Incidents)
    • RE: clients TCP port 256 hammered by several hosts
      ... Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ... Learn more or register at ... and use priority code SF4. ...
      (Incidents)
    • RE: CEH and Intense School
      ... Q-How many times has this course been delivered ... You want more than 4 to know the bugs are ironed out in labs and so on. ... Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ...
      (Pen-Test)