Security Incidents mailing list archives

Re: pimpshiz / put i.txt


From: Abe Getchell <agetchel () KDE STATE KY US>
Date: Tue, 10 Oct 2000 16:34:37 -0400

        ...or it could just be that he doesn't want to deface the web site
of someone who has the resources and time to prosecute him.  Most 'no name'
sites will simply restore their pages and count their losses.

Thanks,
Abe

Abe L. Getchell - Security Engineer
Division of System Support Services
Kentucky Department of Education
Voice   502-564-2020x225
E-mail  agetchel () kde state ky us
Web     http://www.kde.state.ky.us/



-----Original Message-----
From: Cashdollar, Larry [mailto:larry.cashdollar () AKAMAI COM]
Sent: Monday, October 09, 2000 1:19 PM
To: INCIDENTS () SECURITYFOCUS COM
Subject: Re: pimpshiz / put i.txt


I have spoken to pimpshiz, and he DOES NOT use the RDS'
sploit.  He does
use
a 0day, but I am unsure of it's nature.  He has defaced all
IIS/NT servers,
so that at least narrows it down.  More logs would be nice though.


If pimpshiz has a 0 day exploit for IIS/NT 4.0 Why is he
defacing these no
name sites?
If we look at attrition I see the sites he has defaced are
low profile.  If
I take a look at netcraft I see that IIS/NT 4.0 is also being
used by nasdaq
and the NFL.  It is my guess that he has a customized RDS'
script which he
probably tweaked a little and calls it 0 day.



Current thread: