Irregular Expressions:

casper rfi bot

1

August 27, 2010  8:33 AM

Casper RFI crack bot – Part 6



Posted by: Dan O'Connor
casper bot perl, casper perl, casper rfi bot, perl bot, www bot

We can do something fun with this,

$defacer     = "def.txt";
less def.txt
<title>-- Hacked bY XXXXXXXX --</title>
Off to Google we go, this won't give an exact number, but we are going to be able to get a count of the number of web servers this guy...

August 22, 2010  9:44 PM

Casper RFI crack bot – Part 5



Posted by: Dan O'Connor
casper perl, casper rfi bot, casper.pl

Some of the sh.txt script seems to be pretty old, calling milw0rm and darkc0de, both sites are no longer up and have not been for a while. There is also a few things worth looking in to here, the script mentions fx29shell.php.  Which is a php shell that can be loaded onto the system. I can...


August 20, 2010  10:31 PM

Casper RFI crack bot – Part 1



Posted by: Dan O'Connor
casper rfi, casper rfi bot, casper unix, rfi bot, unix bot

If you saw the ISC today (isc.sans.edu) there is a posting about a perl Unix bot making the rounds. http://isc.sans.edu/diary.html?storyid=9430 There is signatures around from emerging threats to detect the bot, if you need them. http://doc.emergingthreats.net/2011176 I have found a server...


1

Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to: