|
|||||||||||
|
ano@ano.com ftpd dip.t-dialin.net
From: Owen McCusker <mccusker(at)sonalysts.com>
Date: Wed Nov 06 2002 - 16:50:13 EST
The following sequence occurs:
the file has a repeating pattern to it.
the file size is: 104154 (bytes)
constents look like: (via text editor) .3›;ØÎšŸg3pBØÇ=´g?Ãä?[o¼g‡Ãò?«šgÝÃA?[š\ÃO?[Ã;g3›4?[Ãdr3.............
(maybe encrypted text?)
The users are from dip.t-dial.net, the user RIPE the description includes: Deutsche Telekom AG, Internet Service Provider, CeBIT 99 I am not sure what these users are doing. Maybe they are trying to setup someway to perform "store and forward" services via anonymous FTP. Maybe this is somehow related to the same scheme devised using iroffer ( aka DCC bot). Has anyone else seen this type of activity from dip.t-dialin.net or dipsters for short. ;-)? Owen This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com Received on Wed Nov 6 20:28:53 2002 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:50 EDT |
||||||||||
|
|||||||||||