Re: Monitored.By.hAcxFtpScan

From: Gene Barlow (btraquer@att.net)
Date: 12/04/02

  • Next message: WhtWlf2001: "User Administration Security Database"
    Date: Wed, 04 Dec 2002 07:30:09 -0700
    From: Gene Barlow <btraquer@att.net>
    To: James McGee <james__mcgee@hotmail.com>, security-basics@securityfocus.com
    
    

    James,

         I've seen the same thing, but it was a few months ago. I setup a
    honeypot on my home DSL line. I can't remember exactly the folder name,
    but it did have the "Monitored.By." part in it. Later, I discovered
    that "they" turned my FTP server into a 0day FTP site - so watch out,
    you may shortly be distributing illegal software and not know it. It
    was a great experience to observe this, just be careful that you don't
    unintentionally do anything illegal. If you like, and I can find them,
    I'll be glad to send you the logs from my old FTP server as well as some
    screen shots of the results I took so you can do some comparison and see
    if you're on the same course my system was...

    Thanks!
    Gene...

    James McGee wrote:

    > I found a un-managed ftp server floating around our network.
    >
    > I am quite sure the machine itself had not been compromised
    > completely, but I found a directory in there with the above name.
    >
    > Has anyone else seen this before?
    >
    > Any help or advice appreciated.
    >
    > Cheers
    >
    > JM
    >
    >
    >
    >
    >
    > _________________________________________________________________
    > MSN 8 helps eliminate e-mail viruses. Get 2 months FREE*.
    > http://join.msn.com/?page=features/virus
    >
    >



    Relevant Pages

    • www.CeBeans.com - new program listings - Jan 5 2009
      ... This program allows a student to use a folder on a secure remote FTP server ... You can view the files on the PocketPC ... points and next round when you knock him down and free man every round after ...
      (microsoft.public.pocketpc)
    • Re: EWF RAM, Compact Flash and log files
      ... >> What are all of the changes required to effectively run the EWF RAM ... Default Shared Documents Folder if standalone and not on a domain. ... change the default content location, not just the logfor IIS FTP Server, ... Can / should this be done without a HDD? ...
      (microsoft.public.windowsxp.embedded)
    • Re: new user questions. (Before I back myself into a corner!)
      ... I get "unknown root shell" warnings as adduser completes.) ... Both users can connect to the ftp server (still stuck at port 21 for now, ... However, each user see's it's own unique homedir folder, exactly as ... their individual data directory 60m for ral and 'Faros' for Faros. ...
      (freebsd-questions)
    • Re: new user questions. (Before I back myself into a corner!)
      ... I get "unknown root shell" warnings as adduser completes.) ... Both users can connect to the ftp server (still stuck at port 21 for now, ... However, each user see's it's own unique homedir folder, exactly as ... permissions are displayed in group of three, ...
      (freebsd-questions)
    • www.CeBeans.com - new program listings - Nov 3 2008
      ... interface for each day you have a folder on the FTP server. ... public or private folder of a secure remote FTP server. ... you knock it past him and 100 bonus and next round when you knock it past ...
      (microsoft.public.pocketpc)