[Dshield] New IIS directory traversal worm, or just a tool sig?
BarkerJr at ClanCdG.com
Thu Nov 7 21:04:10 GMT 2002
Gets actually specifying a server hostname are proxy checks, I
believe. My guess is that someone is trying to make web server/proxies
hack into a government web server.
> One identical to this at the end of September, 2 in late October, 4
> since November 1. No two from the same source. Looks like Nimda to
> but you're right, it looks like a different twist.
> -----Original Message-----
> From: James C Slora Jr [mailto:Jim.Slora at phra.com]
> Sent: Monday, November 04, 2002 12:50 PM
> To: list at dshield.org
> Subject: [Dshield] New IIS directory traversal worm, or just a tool
> Since Friday, I have seen this from nine different addresses. IIS
> traversal attack is on the local system - not an HTTP CONNECT. The
> is being specified as "ww.tk.gov" (not a real public host), but this
> window dressing on the attack.
> Anyone else seen this?
More information about the list