Frank
Tue Jan 04 18:08:21 CST 2005
This was the one which affected us
http://www.security-corporation.com/advisories-026.html
"John Cesta" <lists@lookwww.com> wrote in message
news:n77mt0lo34firkjd67e364d0a96a5tbjqt@4ax.com...
> On Tue, 4 Jan 2005 14:28:08 -0800, "Frank Cheung" <nospam@nospam.org>
> wrote:
>
>>Check your server for application that has known holes.
>
> Oh thanks...I didn't know that!? ;))
>
>>There are several applications out there that have known holes which allow
>>hacker to upload asp scripts which overwrites index file.
>
>
>>
>>
>>"John Cesta" <lists@lookwww.com> wrote in message
>>news:v3mlt0hrhlte26ud6ulduattmosrj37kek@4ax.com...
>>>
>>>
>>> Has anyone heard of this one?
>>>
>>> What they do is to copy:
>>>
>>> index.php .cfm .htm .html .asp
>>> default.php .cfm .htm .html .asp
>>>
>>> to the root folder of every web site.
>>>
>>> I can't find much on it on the web. I thought I had figured it to be
>>> an old servu ftp server hack so I upgraded about 3 weeks ago but today
>>> upon reboot it happened again.
>>>
>>> Yes a totally patch win2k server.
>>>
>>>
>>> Thanks
>>>
>>>
>>
>