RE: 'FrogEater'

From: Julien MALGHEM (F0CUQ) (renarat_private)
Date: Wed Apr 25 2001 - 10:00:45 PDT

  • Next message: buschermannat_private: "scan for 109, new worm-variant or simple scan?"

     
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    Hi,
    
    > 04-08-01  12:34PM       <DIR>          .tmp
    > 03-31-01  12:33AM       <DIR>             .FrogEater
    
    This name of directory is offen use to hide it. 
    The files named : .filename are hidden by linux. That's why you have
    this name of directory.
    
    > 03-26-01  05:16AM              1000000 1 Mo
    > 01-02-01  12:05AM              1000000 1.mb.zip
    > 03-30-01  10:26PM              1000000 1000k
    > 03-30-01  11:22PM              1000000 1MB.Test
    
    These files contains usualy arbitrary characters to create a 1 Mb
    file.
    It's only to test your bandwith.
    
    > 03-26-01  05:17AM       <DIR>          FrogEater
    > 04-08-01  12:34PM       <DIR>          TAGGED FrogE
    
    'TAGGED ***' is the name given by the persons who upload on your
    computer.
    Genraly *** is the name of the 'uploader'.
    
    > This looks much like the result of an automated tool that checks
    > for anonymous / world-writable FTP directories.  I assume the
    > 1000000 byte files are attempts to figure out the link speed and /
    > or disk quotas .. ?  The '.tmp' directory is actually named '.tmp  
    >    '.  
    
    Some programs are used to check for anonymous FTP access and most of
    them create the 1 Mb file.
    
    Juste turn off your anonymous ftp access or disable write
    authorisations.
    
    
    Best regards, 
    renar
    
    renarat_private-union.org
    http://www.ref-union.org/security/
    
    
    -----BEGIN PGP SIGNATURE-----
    Version: PGPfreeware 7.0.3 for non-commercial use <http://www.pgp.com>
    
    iQA/AwUBOucCuBy3Y4czlOS2EQL+cwCgnn2qONOPR1kGm4xk4WuGSengHdoAnAgr
    tP9rbs2CpG8asEAexrnyYiNY
    =r1bC
    -----END PGP SIGNATURE-----
    



    This archive was generated by hypermail 2b30 : Wed Apr 25 2001 - 10:03:26 PDT