The European
06-01-2009, 13:30
If you can't / don't want to change SSH port, I recommend using fail2ban to drop connections when an attack is obvious.
w00tw00t
Published: 2005-11-29,
Last Updated: 2005-11-30 05:49:00 UTC
by Swa Frantzen (Version: 1)
0 comment(s)
Following our request for help, a while ago, we received another submission of somebody finding the following in his web logs:
"GET /w00tw00t.at.ISC.SANS.DFind"
It seems that we forgot to tell our whitehat readers that the search is off. We know what's behind it. It's a web vulnerability scanner that has this fingerprint. Find and use it at your own risk. We at the Internet Storm Center distance ourselves from this tool that is labeled by at least one security company as a hacker tool..
*MY_IP* - - [26/Dec/2008:01:20:00 +0100] "GET /top_secret_nuclear_bunker_access_codes.txt HTTP/1.1" 404 339 "-" "-"
91.121.6.21 - - [21/Dec/2008:21:53:54 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [21/Dec/2008:22:04:25 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [21/Dec/2008:22:16:02 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [21/Dec/2008:22:27:55 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [21/Dec/2008:22:38:41 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [21/Dec/2008:22:49:33 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [21/Dec/2008:23:00:19 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [21/Dec/2008:23:11:20 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [21/Dec/2008:23:21:59 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [21/Dec/2008:23:32:27 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [21/Dec/2008:23:43:30 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:03:51:24 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:04:00:01 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:04:08:22 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:04:16:44 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:04:25:42 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:04:34:10 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:04:42:19 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:04:50:48 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:04:59:27 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:05:07:44 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:05:16:03 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:05:24:23 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:05:32:48 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:05:40:50 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:05:49:13 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:05:57:34 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:06:06:12 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:06:14:25 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:06:22:43 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:06:31:11 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:06:39:26 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:06:47:57 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:06:56:26 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:07:04:59 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:07:13:16 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:07:21:51 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:07:29:54 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:07:38:19 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:07:46:34 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:07:55:05 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:08:03:23 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:08:11:46 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:08:20:18 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:08:28:43 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:08:37:01 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:08:45:13 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:08:53:28 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:09:02:01 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:09:10:30 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:09:18:53 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:09:27:33 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:09:36:40 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:09:45:10 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:09:54:23 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:10:03:02 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:10:12:06 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:10:21:19 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:10:30:18 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:10:39:07 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:10:48:06 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:10:56:45 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:11:05:31 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:11:14:07 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:11:22:52 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:11:31:31 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:11:40:07 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:11:48:58 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:11:57:34 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:12:06:05 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:12:15:01 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:12:23:39 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:12:32:32 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:12:41:32 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:12:51:04 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:13:00:06 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:13:10:38 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:13:19:52 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:13:28:42 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:13:37:50 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:13:47:09 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:13:56:26 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:14:05:40 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:14:15:06 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:14:24:18 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:14:33:18 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:14:42:02 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:14:50:59 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:14:59:53 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-" 91.121.6.21 - - [23/Dec/2008:15:09:01 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 404 339 "-" "-"