Security Basics mailing list archives

RE: Unusual Activity


From: "dave kleiman" <dave () isecureu com>
Date: Sat, 14 Feb 2004 10:38:15 -0500

Graydon,

Try checking your web servers (on a regular basis) yourself.

A good tools is http://www.nstalker.com/products/nstealth/download.php .

That is the free version, you can also purchase the full version with
up-to-date databases in it.

It is a handy tool to have around, and will probably find that and a few
other holes in them.



_____________________________________
Dave Kleiman, CISSP, MCSE, CISM, CIFI
www.SecurityBreachResponse.com

"High achievement always takes place in the framework of high expectation."
Jack Kinder




-----Original Message-----
From: Graydon McKee [mailto:graydon.s.mckee.iv () orcmacro com] 
Sent: Friday, February 13, 2004 11:45
To: security-basics () securityfocus com
Subject: Unusual Activity


Hello All, 
            I'm seeing some unusual activity.  One of our web servers it
sending emails via a feedback page that proport to come from
333-333-3333test () test999 com.  These messages have various things in the
From Field: 
 
From: "..\\..\\..\\..\\..\\..\\..\\..\\..\\..\\boot.ini" <> 
From: "..\\..\\..\\..\\..\\..\\..\\..\\..\\..\\etc\\passwd" <> 
From: "\\\\'/bin/cat /etc/passwd\\\\'" <>
 
88 of these messages were generated in under a minute so I'm pretty sure
that someone is running a script against this page but I am having problems
finding out exactly what is being run and what exploit is being looked for.
Something tells me that this should be pretty simple but for some reason I
can't put my finger on it.  Does anyone have any ideas or suggestions that
would help me out here?  
 
Thanks
 
Graydon S McKee IV - GSEC
Firewall/Security Administrator
ORC Macro - Macro International
11785 Beltsville Drive
Calverton, Maryland 20705
301-572-0583 Fax: 301-572-0982
 



---------------------------------------------------------------------------
Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection

Protect your network with the comprehensive security solution that
integrates six applications for ease of use and lower TCO.

Firewall - Virus protection - Spam protection - URL blocking - VPN
- Wireless security.

Download 30-day evaluation at:
http://www.astaro.com/php/contact/securityfocus.php
----------------------------------------------------------------------------


Current thread: