>Looks a lot like RFP's RDS exploit, using the msadc2.pl script or very similar.
>Details of that are at http://www.wiretrip.net/rfp/p/doc.asp?id=1&iface=2
>Even if it is not, it is obviously a classic 'echo we are leet > index.htm'
>style lame defacement, so chances are they are not particularly skilled.
Yep, this is another lame attempt by T1ku5Rumput, a bush league script-kiddie
if ever there was one.
You'd better get over to the Microsoft site and
patch your IIS pronto, however. Hold onto that log (on read only media)
for future reference...
Cheers,
RGF
Robert G. Ferrell, CISSP
Information Systems Security Officer
National Business Center
U. S. Dept. of the Interior
Robert_G_Ferrell_at_nbc.gov
========================================
Who goeth without humor goeth unarmed.
========================================
Received on Jan 02 2001