PDA

View Full Version : Blasterattack



deltatrend
02-22-2004, 10:58 AM
I'm not sure where to post this. I received an email response from a form on my site that looks like this:

Name: blasterattacko@aol.com To: blasterattacko@aol.com From: blasterattacko@aol.com Subject: N03yz(E3ADA67C,Name) ksu7IBhhfJ97zpqsfP5zFJpQQ2QMVAjQN TVQkhGxA67lrXPp .
Company: blasterattacko@aol.com To: blasterattacko@aol.com From: blasterattacko@aol.com Subject: TdLsADJc7(E3ADA67C,Company)8hA3c hQwUxdY40jJ5iqa4Sw54jt21 v8sXhaEyr9BZaqTDbGrQm33ciid7 .
Title: blasterattacko@aol.com To: blasterattacko@aol.com From: blasterattacko@aol.com Subject: OXju8lLC (E3ADA67C,Title)BSqT22G3 0VnkEVk .
Telephone: blasterattacko@aol.com To: blasterattacko@aol.com From: blasterattacko@aol.com Subject: wpAP2Yqh(E3ADA67C,Telephone)apak gSQ5C mzfhght sS3J8cg6AsQVjj7PyOqZJboYLS8NUeCoWSnGZziBXnuJ .
email: blasterattacko@aol.com To: blasterattacko@aol.c
Date: 22 February 2004
Time: 06:54:22 -0000



Has anyone seen this before? I tried to look it up in Google, but the two results are in Russian and Chinese (I think). I suppose it relates to the Blaster worm.

Does this mean that the server is infected? I use one of the top UK hosting companies. I have never heard of a virus that fills in html forms.

matauri
02-23-2004, 11:19 AM
I could be wrong, but I dont think that Blaster was actually run as blasterattacko. So I think someone is just playing games with one of your forms.


Cindy

mikmik
02-23-2004, 11:11 PM
Have you gotten any others?
Some sort of 'dictionary' like attack to hack your server?

What kind of script handles the form, PHP, ASP, Perl, javascript?

I think that Cindy is probably right!