Results 1 to 12 of 12

Thread: GET /w00tw00t.at.ISC.SANS.DFind:)

  1. #1
    Funking Prink! Raz316's Avatar
    Join Date
    Jul 2003
    Location
    Deal, Kent, UK
    Posts
    2,978
    Thanks
    130
    Thanked
    62 times in 52 posts

    GET /w00tw00t.at.ISC.SANS.DFind:)

    So I've had the above twice in the last day (from different IPs) or so (each followed by a load of general requests for phpmyadmin and the like). My Windows 2003 machine running apache is up to date and I'm guessing that as none of the requests were successful (on account of phpmyadmin not being on the server) everything is fine. Right?

    It has spooked me a bit though, do I have to basically live with it? Anyone else had experience with it?

    Ta

  2. #2
    Splash
    Guest

    Re: GET /w00tw00t.at.ISC.SANS.DFind:)

    http://isc.sans.org/diary.html?storyid=900

    Are the ips the same each day? If so is simply blocking them at the firewall an option? Essentially it's someone scanning your server for vulns.

  3. #3
    Gentoo Ricer
    Join Date
    Jan 2005
    Location
    Galway
    Posts
    11,048
    Thanks
    1,016
    Thanked
    944 times in 704 posts
    • aidanjt's system
      • Motherboard:
      • Asus Strix Z370-G
      • CPU:
      • Intel i7-8700K
      • Memory:
      • 2x8GB Corsiar LPX 3000C15
      • Storage:
      • 500GB Samsung 960 EVO
      • Graphics card(s):
      • EVGA GTX 970 SC ACX 2.0
      • PSU:
      • EVGA G3 750W
      • Case:
      • Fractal Design Define C Mini
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • Asus MG279Q
      • Internet:
      • 240mbps Virgin Cable

    Re: GET /w00tw00t.at.ISC.SANS.DFind:)

    http://isc.sans.org/diary.html?storyid=900

    It's a scanner tool. It doesn't execute vunerabilities in and of itself.
    Quote Originally Posted by Agent View Post
    ...every time Creative bring out a new card range their advertising makes it sound like they have discovered a way to insert a thousand Chuck Norris super dwarfs in your ears...

  4. #4
    Funking Prink! Raz316's Avatar
    Join Date
    Jul 2003
    Location
    Deal, Kent, UK
    Posts
    2,978
    Thanks
    130
    Thanked
    62 times in 52 posts

    Re: GET /w00tw00t.at.ISC.SANS.DFind:)

    Cheers you two, sorry I should have been more thorough, I knew it was a scanner thingy but wondered if there was anything I need worry about after that?

    They were from different IP's so I've noted them, but not actually banned anything yet.

  5. #5
    Gentoo Ricer
    Join Date
    Jan 2005
    Location
    Galway
    Posts
    11,048
    Thanks
    1,016
    Thanked
    944 times in 704 posts
    • aidanjt's system
      • Motherboard:
      • Asus Strix Z370-G
      • CPU:
      • Intel i7-8700K
      • Memory:
      • 2x8GB Corsiar LPX 3000C15
      • Storage:
      • 500GB Samsung 960 EVO
      • Graphics card(s):
      • EVGA GTX 970 SC ACX 2.0
      • PSU:
      • EVGA G3 750W
      • Case:
      • Fractal Design Define C Mini
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • Asus MG279Q
      • Internet:
      • 240mbps Virgin Cable

    Re: GET /w00tw00t.at.ISC.SANS.DFind:)

    Naw, it's the application level equivilant of nmap'ing your boxes. If you don't like them doing it, ban 'em. Problem with this is, most of the dodgy kind of scans/attacks tunnel through the vast swaythes of compromised/proxy boxes out there.
    Quote Originally Posted by Agent View Post
    ...every time Creative bring out a new card range their advertising makes it sound like they have discovered a way to insert a thousand Chuck Norris super dwarfs in your ears...

  6. #6
    Senior Member
    Join Date
    Jul 2003
    Location
    Holsworthy, Devon
    Posts
    513
    Thanks
    9
    Thanked
    11 times in 11 posts
    • Ben Rogers's system
      • Motherboard:
      • Asus P8P67 B3
      • CPU:
      • Intel core i5 2500k @ 4400MHz
      • Memory:
      • 12GB DDR3 (8GB Corsair Vengeance 1600MHz)
      • Storage:
      • 60GB OCZ Agility 3 SSD (boot) + 1TB Samsung F3 + 500GB Samsung F1 SATA II
      • Graphics card(s):
      • MSI HD7870 2GB
      • PSU:
      • 650W Coolermaster VX
      • Case:
      • Coolermaster Centurion 5 II
      • Operating System:
      • Windows 7 64 bit SP1
      • Monitor(s):
      • 19" Samsung SyncMaste
      • Internet:
      • 23Mbit / 1.1 Mbit ADSL2

    Re: GET /w00tw00t.at.ISC.SANS.DFind:)

    I always wondered what these requests were for....I often see logs of this from my apache web server.
    E6850@ 3700MHz / 6GB DDR2 / 500GB SATAII / nVidia 7800 GTX / Lian Li Plus7B

  7. #7
    HEXUS.timelord. Zak33's Avatar
    Join Date
    Jul 2003
    Location
    I'm a Jessie
    Posts
    35,176
    Thanks
    3,121
    Thanked
    3,173 times in 1,922 posts
    • Zak33's system
      • Storage:
      • Kingston HyperX SSD, Hitachi 1Tb
      • Graphics card(s):
      • Nvidia 1050
      • PSU:
      • Coolermaster 800w
      • Case:
      • Silverstone Fortress FT01
      • Operating System:
      • Win10
      • Internet:
      • Zen FTC uber speedy

    Re: GET /w00tw00t.at.ISC.SANS.DFind:)

    mayber just unplug your router for about 24 hours.. live without the web for a day. Bet they go away.

    Static IP? If not, just reboot router to get new IP. See if it still occurs.

    Quote Originally Posted by Advice Trinity by Knoxville
    "The second you aren't paying attention to the tool you're using, it will take your fingers from you. It does not know sympathy." |
    "If you don't gaffer it, it will gaffer you" | "Belt and braces"

  8. #8
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts

    Re: GET /w00tw00t.at.ISC.SANS.DFind:)

    Quote Originally Posted by Zak33 View Post
    mayber just unplug your router for about 24 hours.. live without the web for a day. Bet they go away.

    Static IP? If not, just reboot router to get new IP. See if it still occurs.
    It isn't his computer/system that is being scanned specifically - his just happens to be in range. My server gets probed each and every day - some are malformed requests, some are requests for 'speculative' pages (like looking for phpmyadmin, others probe and try to log in through SSH (on one night I had 50,000 attempts. I also get malformed SMTP requests in an attempt to break my mailserver.

    AFIK I'm not specifically targeted, but at some time there is a port scan of my IP addresses, the open ports are noted and that triggers some attacks. If i block the port for 5 minutes or so, they stop, but they return some hours or days later.

    The solution is to keep OS and applications up to date, and to monitor logs for specific directed activity.
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

  9. #9
    Gentoo Ricer
    Join Date
    Jan 2005
    Location
    Galway
    Posts
    11,048
    Thanks
    1,016
    Thanked
    944 times in 704 posts
    • aidanjt's system
      • Motherboard:
      • Asus Strix Z370-G
      • CPU:
      • Intel i7-8700K
      • Memory:
      • 2x8GB Corsiar LPX 3000C15
      • Storage:
      • 500GB Samsung 960 EVO
      • Graphics card(s):
      • EVGA GTX 970 SC ACX 2.0
      • PSU:
      • EVGA G3 750W
      • Case:
      • Fractal Design Define C Mini
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • Asus MG279Q
      • Internet:
      • 240mbps Virgin Cable

    Re: GET /w00tw00t.at.ISC.SANS.DFind:)

    Quote Originally Posted by peterb View Post
    It isn't his computer/system that is being scanned specifically - his just happens to be in range. My server gets probed each and every day - some are malformed requests, some are requests for 'speculative' pages (like looking for phpmyadmin, others probe and try to log in through SSH (on one night I had 50,000 attempts. I also get malformed SMTP requests in an attempt to break my mailserver.

    AFIK I'm not specifically targeted, but at some time there is a port scan of my IP addresses, the open ports are noted and that triggers some attacks. If i block the port for 5 minutes or so, they stop, but they return some hours or days later.

    The solution is to keep OS and applications up to date, and to monitor logs for specific directed activity.
    Yup, you hit the nail squarely on the head here. My router flags a tonne of this crap. Half of it is from China or Russia, the other half of it is from compromised/proxy boxes, probably originating from China or Russia. Yet, nobody puts pressure on either countries to tackle it. All this vunrability canvasing and bot/worm/proxy/spam crap is a total waste of internet capacity. Also, <3 autoblacklisting features and honeypots.
    Quote Originally Posted by Agent View Post
    ...every time Creative bring out a new card range their advertising makes it sound like they have discovered a way to insert a thousand Chuck Norris super dwarfs in your ears...

  10. #10
    Funking Prink! Raz316's Avatar
    Join Date
    Jul 2003
    Location
    Deal, Kent, UK
    Posts
    2,978
    Thanks
    130
    Thanked
    62 times in 52 posts

    Re: GET /w00tw00t.at.ISC.SANS.DFind:)

    Thanks everyone, there were a few scans from the same server but I will think nothing of it.

    I'll keep an eye on logs and running processes just to be sure.

  11. #11
    HEXUS.social member Agent's Avatar
    Join Date
    Jul 2003
    Location
    Internet
    Posts
    19,185
    Thanks
    739
    Thanked
    1,614 times in 1,050 posts

    Re: GET /w00tw00t.at.ISC.SANS.DFind:)

    http://www.projecthoneypot.org/list_of_ips.php?ctry=RU

    That might be useful if you want to block IPs / ranges.

    If you don't use anything from Russia or China, I'd be tempted to block all the major ranges.

  12. #12
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts

    Re: GET /w00tw00t.at.ISC.SANS.DFind:)

    Spotted that entry in my webserver logs this morning. Lots of info on Google confirming that it is a probing attack - some info here

    http://www.hostmyclass.net/kb/entry/17/ (one of many!)
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •