Security Basics mailing list archives

WEB-MISC Phorecast remote code execution attempt


From: tyrian2uk () yahoo co uk
Date: 31 Dec 2007 02:26:46 -0000

I receive the same attacktype/ signatures :
WEB-MISC Phorecast remote code execution attempt
for different organization that i monitored from 4 different ip address :
69.50.194.230
82.208.27.78
63.223.69.175
208.73.34.76

when i check the payload from the source 208.x.x.x it show this
http://supercue3.com/screenshots//bius/id.txt


pls advice :


Current thread: