[Snort-users] A case of beer on 126.96.36.199
jjennings at ...4832...
Fri Feb 22 13:51:02 EST 2002
This week's grand prize goes to 188.8.131.52
For allowing PUT rights on Port 80 (I wonder how many hackers are
Being vulnerable on Port 25 and many other ports...
Anyone need an open relay?
No wonder the guy is spewing Code Reds...
We just ran a port scan and tested the guy.
Some guy running IIS over a DSL connection with a site that is listed as
Just another unsuspecting guy who installed IIS on his home computer and
has no idea of how to protect it.
This message comes just in time as it's 4:45 pm here and I really need a
From: snort-users-admin at lists.sourceforge.net
[mailto:snort-users-admin at lists.sourceforge.net] On Behalf Of Skip
Sent: Friday, February 22, 2002 4:14 PM
To: Scott Taylor
Cc: snort-users at lists.sourceforge.net
Subject: Re: [Snort-users] attack
> So what's the best thing to do with this type of attack? Turn'em in?
> To who? Is there a way I can let them know that I know what their
> doing? Any ideas?
> [**] [1:1256:2] WEB-IIS CodeRed v2 root.exe access [**]
> [Classification: Web Application Attack] [Priority: 1]
> 02/22-10:13:19.830419 184.108.40.206:2122 -> 220.127.116.11:80
> TCP TTL:119 TOS:0x0 ID:56151 IpLen:20 DgmLen:112 DF
> ***AP*** Seq: 0x79EC6CC Ack: 0x21AE2090 Win: 0x4248 TcpLen: 20
Unfortunately, there isn't a lot you can do about these attacks other
defend yourself against them. I have gone as far as firewalling a few
the very persistent servers.
I have tracked down sysadmins of the offending servers in some special
(hospitals, insurance companies, financial institutions, and
The nearly universal response was "I didn't know we were running a web
on that machine!" (a consequence of MS efforts to brag that they have
deployed IIS servers than Apache, but turning on IIS by default). I
that most admins that are actually purposefully using IIS have long
their servers. Most of these admins of these infected systems have no
to do about fixing a problem that they didn't even know that they had,
do contact them, they would probably appreciate info on how to fix
They clearly aren't running any type of IDS or they would have
outbound traffic themselves.
Dr. Everett (Skip) Carter Phone: 831-641-0645 FAX: 831-641-0647
Taygeta Scientific Inc. INTERNET: skip at ...1552...
1340 Munras Ave., Suite 314 WWW: http://www.taygeta.com
Monterey, CA. 93940
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:
More information about the Snort-users