Security Incidents mailing list archives
RE: Cobalt Scan
From: Sven Carstens <s.carstens () gmx de>
Date: Mon, 30 Jul 2001 11:55:52 +0200 (CEST)
Hi there, I noticed the IP adress is (probably) the same and it reverses to: Name: ariston.netcraft.com Address: 195.92.95.61
I've made the double check and used netcraft to examine one of my servers. The results are different from the request for cobalt-images seen so far: wooster.netcraft.com - - [27/Jul/2001:13:07:03 +0200] "HEAD / HTTP/1.1" 200 0 "http://www.netcraft.com/survey/" "Mozilla/4.0 (compatible; Netcraft Web Server Survey)" jumble.netcraft.com - - [28/Jul/2001:23:57:51 +0200] "HEAD / HTTP/1.0" 200 0 "http://www.netcraft.com/survey/" "Mozilla/4.0 (compatible; Netcraft Web Server Survey)"
Appearantly somebody just used netcraft to see more information about your server :) So no worries :)
So it isn't the normal probe that everbody can use, but something special. Speculations about the intended usage of the data are left to the reader. CU Sven ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
Current thread:
- Cobalt Scan Ryan W. Maple (Jul 26)
- <Possible follow-ups>
- RE: Cobalt Scan Jeroen Wesbeek (Jul 29)
- RE: Cobalt Scan Sven Carstens (Jul 30)
- RE: Cobalt Scan Tom Laermans (Jul 30)
- RE: Cobalt Scan Sven Carstens (Jul 30)