 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Irregular Expressions &#187; casper unix</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/Irregular-Expressions/tag/casper-unix/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/Irregular-Expressions</link>
	<description>Insight into current security related events and exploits, including virtualization security and tips.</description>
	<lastBuildDate>Sun, 28 Apr 2013 08:00:32 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Casper RFI crack bot &#8211; Part 1</title>
		<link>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/casper-rfi-crack-bot-part-1/</link>
		<comments>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/casper-rfi-crack-bot-part-1/#comments</comments>
		<pubDate>Sat, 21 Aug 2010 03:31:16 +0000</pubDate>
		<dc:creator>Dan O'Connor</dc:creator>
				<category><![CDATA[casper rfi]]></category>
		<category><![CDATA[casper rfi bot]]></category>
		<category><![CDATA[casper unix]]></category>
		<category><![CDATA[rfi bot]]></category>
		<category><![CDATA[unix bot]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/Irregular-Expressions/?p=338</guid>
		<description><![CDATA[If you saw the ISC today (isc.sans.edu) there is a posting about a perl Unix bot making the rounds. http://isc.sans.edu/diary.html?storyid=9430 There is signatures around from emerging threats to detect the bot, if you need them. http://doc.emergingthreats.net/2011176 I have found a server with almost* everything intact so this should be interesting.. First I am going to [...]]]></description>
				<content:encoded><![CDATA[<p>If you saw the ISC today (isc.sans.edu) there is a posting about a perl Unix bot making the rounds.</p>
<p>http://isc.sans.edu/diary.html?storyid=9430</p>
<p>There is signatures around from emerging threats to detect the bot, if you need them. http://doc.emergingthreats.net/2011176</p>
<p>I have found a server with almost* everything intact so this should be interesting..</p>
<p>First I am going to start with the site, the one I found was something like this (I am not going to give the real URL, I have already informed them about this)</p>
<p>http://XXX.XXX/e107_images/casper/</p>
<p>Google found this pretty fast, I would have suspected if you have that much control over a web server you would have started by editing the robo.txt so no one can find your little prize. But then again people can be lazy.</p>
<p>The casper dir has a lot of txt&#8217;s in it, but if you go one level back you see something that&#8217;s really nice.</p>
<pre>-rw-r--r-- 1     2e107_images.rar
drwxr-xr-x 2     casper
-rw-r--r-- 1     e107_images.rar</pre>
<p>Humm, we have the dir named casper and two rar&#8217;s?</p>
<p>A little odd but not totally out of place, whats inside of these bad boy&#8217;s?</p>
<pre>2e107_images.rar
bot.txt
casper2.txt
casper.txt
cmd_kod.txt
def.txt
eggdrop.tar.gz.tar
iso.txt
psy.tar.gz.tar
sat.txt
scan.pl
scan.txt
sh.txt

e107_images.rar
Ckrid1.txt
Ckrid2.txt
iso.txt
myid.jpg
nnee.pl
nnee.txt
php.jpg
scan2.txt
scan.txt</pre>
<p>Ohh pay dirt!</p>
<p>Not only do we have one, but we have two and they seem to be from different sources. A little diff will let us know what is going on.</p>
<pre>Only in 2: bot.txt
Only in 2: casper2.txt
Only in 2: casper.txt
Only in e: Ckrid1.txt
Only in e: Ckrid2.txt
Only in 2: cmd_kod.txt
Only in 2: def.txt
Only in 2: eggdrop.tar.gz.tar</pre>
<p>This is good to know, we will have to come back to that tar.</p>
<p>Next post we will start going through the files and see what the deal is with these two rar&#8217;s is.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/casper-rfi-crack-bot-part-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
