Has anyone heard of this one?

What they do is to copy:

index.php .cfm .htm .html .asp
default.php .cfm .htm .html .asp

to the root folder of every web site.

I can't find much on it on the web. I thought I had figured it to be
an old servu ftp server hack so I upgraded about 3 weeks ago but today
upon reboot it happened again.

Yes a totally patch win2k server.


Thanks

Re: Hacked by tugr@ by Frank

Frank
Tue Jan 04 16:28:08 CST 2005

Check your server for application that has known holes.

There are several applications out there that have known holes which allow
hacker to upload asp scripts which overwrites index file.


"John Cesta" <lists@lookwww.com> wrote in message
news:v3mlt0hrhlte26ud6ulduattmosrj37kek@4ax.com...
>
>
> Has anyone heard of this one?
>
> What they do is to copy:
>
> index.php .cfm .htm .html .asp
> default.php .cfm .htm .html .asp
>
> to the root folder of every web site.
>
> I can't find much on it on the web. I thought I had figured it to be
> an old servu ftp server hack so I upgraded about 3 weeks ago but today
> upon reboot it happened again.
>
> Yes a totally patch win2k server.
>
>
> Thanks
>
>



Re: Hacked by tugr@ by John

John
Tue Jan 04 16:50:50 CST 2005

On Tue, 4 Jan 2005 14:28:08 -0800, "Frank Cheung" <nospam@nospam.org>
wrote:

>Check your server for application that has known holes.

Oh thanks...I didn't know that!? ;))

>There are several applications out there that have known holes which allow
>hacker to upload asp scripts which overwrites index file.


>
>
>"John Cesta" <lists@lookwww.com> wrote in message
>news:v3mlt0hrhlte26ud6ulduattmosrj37kek@4ax.com...
>>
>>
>> Has anyone heard of this one?
>>
>> What they do is to copy:
>>
>> index.php .cfm .htm .html .asp
>> default.php .cfm .htm .html .asp
>>
>> to the root folder of every web site.
>>
>> I can't find much on it on the web. I thought I had figured it to be
>> an old servu ftp server hack so I upgraded about 3 weeks ago but today
>> upon reboot it happened again.
>>
>> Yes a totally patch win2k server.
>>
>>
>> Thanks
>>
>>
>


Re: Hacked by tugr@ by jeff

jeff
Tue Jan 04 17:09:31 CST 2005

On Tue, 04 Jan 2005 17:58:51 GMT, John Cesta <lists@lookwww.com>
wrote:

>Has anyone heard of this one?
>
>What they do is to copy:
>
>index.php .cfm .htm .html .asp
>default.php .cfm .htm .html .asp
>
>to the root folder of every web site.
>
>I can't find much on it on the web. I thought I had figured it to be
>an old servu ftp server hack so I upgraded about 3 weeks ago but today
>upon reboot it happened again.
>
>Yes a totally patch win2k server.

There are hundreds of ways to copy files to even a totally patched
server, the simplest of wich would be to log in as the administrator
and do so. Of course, this means that someone knows your
administrator password, which bypasses any security patch you can put
in place.

Without knowing how it happened your wisest course is to flatten the
box and reinstall from scratch. Check securityadmin.info for further
security hints and tactics.

Jeff

Re: Hacked by tugr@ by Frank

Frank
Tue Jan 04 18:08:21 CST 2005

This was the one which affected us

http://www.security-corporation.com/advisories-026.html


"John Cesta" <lists@lookwww.com> wrote in message
news:n77mt0lo34firkjd67e364d0a96a5tbjqt@4ax.com...
> On Tue, 4 Jan 2005 14:28:08 -0800, "Frank Cheung" <nospam@nospam.org>
> wrote:
>
>>Check your server for application that has known holes.
>
> Oh thanks...I didn't know that!? ;))
>
>>There are several applications out there that have known holes which allow
>>hacker to upload asp scripts which overwrites index file.
>
>
>>
>>
>>"John Cesta" <lists@lookwww.com> wrote in message
>>news:v3mlt0hrhlte26ud6ulduattmosrj37kek@4ax.com...
>>>
>>>
>>> Has anyone heard of this one?
>>>
>>> What they do is to copy:
>>>
>>> index.php .cfm .htm .html .asp
>>> default.php .cfm .htm .html .asp
>>>
>>> to the root folder of every web site.
>>>
>>> I can't find much on it on the web. I thought I had figured it to be
>>> an old servu ftp server hack so I upgraded about 3 weeks ago but today
>>> upon reboot it happened again.
>>>
>>> Yes a totally patch win2k server.
>>>
>>>
>>> Thanks
>>>
>>>
>>
>