CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

WsIRT(TM)

Webserver Incident Reporting and Termination(TM) Squad

NOTE: Web servers have logs and in those logs is evidence of attempted hacking. For instance, one may notice an attack that calls such a script from a remote server "r57.php??". Its these kinds of attacks we're looking to investigate. For a concrete example, see these reports.

Please do not submit phish, spam, or malware to WsIRT. Only submit attack signatures from web server logs. As this project hasn't officially been publicly launched, we are still reclassifying the tool and its verbiage.

[ How-To / FAQ ]

WsIRT -> Confirmed Attacks | Terminated Attacks


status: confirmed attack

HTTP Response
05 Dec, 2008
00:51:03
HTTP/1.1 404 Not Found
ID892 (termination link)
Titler57shell
Entry
WsIRT Squad
Reporter
Paul
Timestamp16 Dec, 2007 @ 19:14:46
Topic ID210635 - Read/respond to WsIRT commentary.
Handler Note:
17 Dec, 2007
01:42:33
Paul: Consumed following related reports:

[893] http://www.rhinoportail.com/cache/bawoek.cute??
Handler Note:
17 Dec, 2007
01:44:24
Paul: At least two scripts on this server are known as the r57 shell. Attackers are attempting to inject these scripts into remote webservers to compromise them and use them for criminal purposes. Please remove them immediately.
Handler Note:
17 Dec, 2007
01:44:52
Paul: View CIDR AS6893 Report: http://www.cidr-report.org/cgi-bin/as-report?as=6893

"6893 | CH | ripencc | 1997-01-07 | SAITIS-NETWORK Saitis Network"

Handler Note:
17 Dec, 2007
01:44:52
Paul: Extended information for AS6893:
State/Province:
Country:
Responsible Domain: saitis.net
Abuse Email: postmaster@saitis.net
Handler Note:
17 Dec, 2007
01:45:46
Paul: Generated and sent email attack alert to respective parties.
Fetched URLs
Slaves893,

Report for at 16 Dec, 2007 @ 19:17:21


fetched page

at 16 Dec, 2007 @ 19:17:25
MD5 Fingerprint: 45259378888611501449d236cdb4d193
SHA1 Fingerprint: 3d0f3daf617e44f302e0fc320d75a57b53a72776
Version 1.0
spacer spacer