Re: ftp warez server snake ?

From: Bob User (bob_at_catch23.kicks-ass.net)
Date: 12/08/04

  • Next message: Andrew Smith: "Re: ftp warez server snake ?"
    To: "Andreas Putzo" <andreas@inferno.nadir.org>
    Date: Tue, 7 Dec 2004 20:30:09 -0500
    
    

    Most of the rootkits I run into that spread via IRC and shares seem to use
    the Serv-U FTP server, for what it's worth. Most all IRC rootkits seem to
    answer identd also, there are a million of 'em out there, probably it's a
    typical ServU-mIRC modified kit.

    ----- Original Message -----
    From: "Andreas Putzo" <andreas@inferno.nadir.org>
    To: <incidents@securityfocus.com>
    Sent: Tuesday, December 07, 2004 4:14 PM
    Subject: ftp warez server snake ?

    > Hello,
    >
    > today i found an ftp server listening on port 5800 on a windows box.
    > Anonymous login is not allowed. I tried a few name/pass combos without
    luck.
    > I believe, it's a pubstro used for warez, but i don't have physical access
    to
    > confirm this.
    >
    > # ftp 194.xx.x.xx 5800
    > Connected to 194.xx.x.xx.
    > 220 Snake Server
    > Name (194.xx.x.xx:root): snake
    > 331 User name okay, need password.
    > Password:
    > 530 Not logged in.
    > Login failed.
    > Remote system type is habe.
    > ftp>
    >
    > There is also an auth server listening, providing me this:
    >
    > # nc 194.xx.x.xxx 113
    >
    > : USERID : UNIX : ekwaxtjm
    >
    >
    > I googled a bit, but found nothing useful.
    >
    > Anyone recognize this one?
    >
    >
    > regards,
    > Andreas
    >
    >


  • Next message: Andrew Smith: "Re: ftp warez server snake ?"

    Relevant Pages

    • RE: FTP and ISA setup
      ... Please follow the instruction described on the following KB to enable external clients to access your FTP server. ... Local port: Fixed port ... Change the EnablePortAttack value to 1. ...
      (microsoft.public.windows.server.sbs)
    • Re: Is this a 3-Leg Perimeter scenario?
      ... Do you mean the FTP server is hosted on the ... This newsgroup only focuses on SBS technical issues. ... The detailed network diagram. ...
      (microsoft.public.windows.server.sbs)
    • Re: Microsoft FTP Server problem on W2K?
      ... client (rather than another server, as in proxy transfer), the IP address ... port) currently in use on the control connection. ... >the remote FTP server was, at least at a TCP level, prepared to accept the ...
      (microsoft.public.inetserver.iis.security)
    • Re: How to develop FTP Server On PPC?
      ... FTP server due to licensing restrictions. ... the server portions (there's no FTP client to my knowledge on CE), ... © 2003 Microsoft Corporation. ...
      (microsoft.public.windowsce.embedded.vc)
    • Re: Security Problem...
      ... This has happened before on other installations of ... I checked the IIS web server and FTP server logs and the only IP address is ... As far as my Firewall logs, ...
      (microsoft.public.security)