Full Disclosure mailing list archives

Re: http://xfteam.net/fedor.c - Anyone seen this before??


From: "kang () insecure ws" <kang () insecure ws>
Date: Mon, 24 Nov 2003 11:43:46 +0100

bah...

$INFO['sql_driver']                   =       'mySQL';
$INFO['sql_host']                     =       'localhost';
$INFO['sql_database']                 =       'xfteam_ivbd1';
$INFO['sql_pass']                     =       'FuE7sPjIwm';
$INFO['sql_port']                     =       '';
$INFO['sql_tbl_prefix']                       =       'ibf_';
$INFO['sql_user']                     =       'xfteam_ivbd1';



telnet xfteam.net 3306
Trying 69.56.243.146...
Connected to xfteam.net.
Escape character is '^]'.
0
4.0.15-standard )n*$r7W0,,
Connection closed by foreign host.


also, see
http://xfteam.net/remote.php?&c=v&d=%2Fhome%2Fxfteam%2Fpublic_html%2F&f=strings.txt
about the things they are looking for
and
http://xfteam.net/remote.php?&c=v&d=%2Fhome%2Fxfteam%2Fpublic_html%2F&f=google.jpg&ftype=2&fnot=1
about the scan they are doing

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: