![]() |
#11 | ||
![]() ![]() ![]() ![]() Join Date: Oct 2003
Location: Ranelagh, Ireland
Posts: 1,577
|
![]() Quote:
-------------------------------------------------- Zupah_Smurf/s722/plugins/plugins/icqpwsteal.dll b _ i r kostak ftp 0 * c Zupah_Smurf/s722/plugins/plugins/icqpwsteal.txt b _ i r kostak ftp 0 * c Zupah_Smurf/s722/plugins/plugins/matrix.dll b _ i r kostak ftp 0 * c <cut> Zupah_Smurf/s722/s7config.cfg b _ i r kostak ftp 0 * c Zupah_Smurf/s722/server.exe b _ i r kostak ftp 0 * c Zupah_Smurf/s722/sin.exe b _ i r kostak ftp 0 * c Zupah_Smurf/s722/sub7.exe b _ i r kostak ftp 0 * c -------------------------------------------------- OK, so what this basically means is that, for some unknown reason, one of the most popular backdoors ever - subseven, was in your directory on the server. OK, so this is how I think the story goes: You had / have sub7 installed on your computer. The intruder connected to your machine and extracted all passwords from your computer (yes, it can do that). Then the guy saw the password for abandonia which I gave you. He then connected to the site using WS_FTP and uploaded sub7 to your directory (that's what the logs show he did). I have absolutely no idea why he did it. After he uploaded sub7 to your directory on the server, he erased everything, and left the sub7 files and directories intact. In fact, that was one of the only things left on the server. However, he wasn't very smart because he thought that by deleting the access.log he would cover his tracks. I filed an abuse complaint to Brittish Telecom. Maybe they'll answer, maybe they wont. Time will tell. One thing is sure - Tom, get some anti-virus software please |
||
![]() ![]() |
|
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
Heroes of Might and Magic II [GoG] | Anonymous | Invalid Requests | 68 | 30-04-2012 06:57 PM |
Who Deleted Topic? | Rogue | Old Suggestions | 48 | 16-04-2006 06:08 PM |
Posts Deleted | Grinder | Blah, blah, blah... | 26 | 26-01-2006 02:59 PM |
Topic Deleted?!?!? | quatroking | Blah, blah, blah... | 17 | 17-02-2005 04:47 PM |
|
|
||
  |