lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
From: sf at diffusion.net (sf)
Subject: DCOM WORM - preface

ya i got more questions.

so you are ddosing yourself?   are you complaining cuz this sdbot net is
attacking you?  why is your dns being used?  are you pissing people off
again?

its interesting to see people take the time to make a personal version for
you.




----- Original Message ----- 
From: "morning_wood" <se_cur_ity@...mail.com>
To: "sf" <sf@...fusion.net>; <full-disclosure@...ts.netsys.com>; "0day"
<0day@...hackers.org>
Sent: Friday, August 15, 2003 8:12 PM
Subject: Re: [Full-Disclosure] DCOM WORM - preface


> if you look at the sample you will see those are connect strings of the
> sdbot
> attacking my system from infected systems
>
>
> > jihpt@ nigga2 exploitlabs.com #0sec nigger exploitlabs.com
> > #whore nigger
> exploitlabs.com  <---- server (dns ) to attack
> #0sec <--- chanel to join
> nigger / nigga2 <--- password for the bots
>
> >
> > Proc32.exe
>     ^^^^^^^^---- if you have this you are infected and attacking me
>
>
> > Critical Process Monitor
> > mIRC v6.03 Khaled Mardam-Bey
> ^^^^^^^^^^^^^^^^^^^^^^^^^^^^--------- basic irc interface component in the
> sdbot
>
> >
> >
> > wtf is that supposed to be?
> >
> >
>
> any more questions? try to analyse the info first ok, try looking at the
> sdbot configuration and you will see these things clearly as options.
>
> Donnie Werner
>


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ