Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




Security Incidents mailing list archives

Re: Recent IRC attacks
From: adam <agraham () lcc net>
Date: Thu, 12 Jul 2001 15:26:23 -0500

our linux box was hit (attempted).... running hybryid.... IRC server and red hat 7.0.... last night (july 11)



At 11:06 AM 7/12/2001 -0500, you wrote:

Anyone seen the recent IRC related attacks?  We were the source
and destination for more than one massive flood yesterday.


The MO so far seems to be:

+ Flood of IP protocol 255 packets from random, poorly admined, Win2K boxen.

  + The attacks seem to be directed almost exclusively at IRC servers.


So far, we've found that the hacked Win2K boxes have the following:

  BackOriface install as

    c:\winnt\java\w.exe

  Also, there was a new executable install as

    c:\winnt\system32\wlogin.exe

  And this was running as a service.


Also, the hacked machines seem to be controlled via IRC.  They're
connecting to rogue IRC servers running on what appear to be hacked
machines on DSL/Cablemodems.


If I had to guess how they got this stuff installed, I'd say that it
was done via IIS.  None of the hacked machines that I've seen were patched
and they were all running IIS.


Paul
--
Paul Dokas                                            dokas () cs umn edu
======================================================================
Don Juan Matus:  "an enigma wrapped in mystery wrapped in a tortilla."


----------------------------------------------------------------------------


This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see:

http://aris.securityfocus.com



----------------------------------------------------------------------------


This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management and tracking system please see:

http://aris.securityfocus.com


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]