Scro

Member

Blog Archive

Blog

Internet Flows 3 Comments

This goes on all day long on just one of our FTP servers.

 

000003) 9/18/2007 10:14:46 AM - (not logged in) (203.146.145.180)> Connected, sending welcome message...

(000003) 9/18/2007 10:14:46 AM - (not logged in) (203.146.145.180)> 220 PHXX FTP 1

(000003) 9/18/2007 10:14:47 AM - (not logged in) (203.146.145.180)> USER anonymous

(000003) 9/18/2007 10:14:47 AM - (not logged in) (203.146.145.180)> 331 Password required for anonymous

(000003) 9/18/2007 10:14:47 AM - (not logged in) (203.146.145.180)> PASS ****************

(000003) 9/18/2007 10:14:47 AM - anonymous (203.146.145.180)> 230 Logged on

(000003) 9/18/2007 10:14:47 AM - anonymous (203.146.145.180)> CWD /_vti_pvt/

(000003) 9/18/2007 10:14:47 AM - anonymous (203.146.145.180)> 550 CWD failed. "/_vti_pvt": directory not found.

(000003) 9/18/2007 10:14:48 AM - anonymous (203.146.145.180)> CWD /upload/

(000003) 9/18/2007 10:14:48 AM - anonymous (203.146.145.180)> 550 CWD failed. "/upload": directory not found.

(000003) 9/18/2007 10:14:48 AM - anonymous (203.146.145.180)> CWD /home/

(000003) 9/18/2007 10:14:48 AM - anonymous (203.146.145.180)> 550 CWD failed. "/home": directory not found.

(000003) 9/18/2007 10:14:49 AM - anonymous (203.146.145.180)> CWD /public/

(000003) 9/18/2007 10:14:49 AM - anonymous (203.146.145.180)> 550 CWD failed. "/public": directory not found.

(000003) 9/18/2007 10:14:49 AM - anonymous (203.146.145.180)> CWD /pub/

(000003) 9/18/2007 10:14:49 AM - anonymous (203.146.145.180)> 550 CWD failed. "/pub": directory not found.

(000003) 9/18/2007 10:14:49 AM - anonymous (203.146.145.180)> CWD /temp/

(000003) 9/18/2007 10:14:49 AM - anonymous (203.146.145.180)> 250 CWD successful. "/temp" is current directory.

(000003) 9/18/2007 10:14:50 AM - anonymous (203.146.145.180)> MKD 070918211607p

(000003) 9/18/2007 10:14:50 AM - anonymous (203.146.145.180)> 550 Can't create directory. Permission denied

(000003) 9/18/2007 10:14:50 AM - anonymous (203.146.145.180)> CWD /wwwroot/

(000003) 9/18/2007 10:14:50 AM - anonymous (203.146.145.180)> 550 CWD failed. "/wwwroot": directory not found.

(000003) 9/18/2007 10:14:50 AM - anonymous (203.146.145.180)> CWD /cgi-bin/

(000003) 9/18/2007 10:14:50 AM - anonymous (203.146.145.180)> 550 CWD failed. "/cgi-bin": directory not found.

(000003) 9/18/2007 10:14:51 AM - anonymous (203.146.145.180)> CWD /cgibin/

(000003) 9/18/2007 10:14:51 AM - anonymous (203.146.145.180)> 550 CWD failed. "/cgibin": directory not found.

(000003) 9/18/2007 10:14:51 AM - anonymous (203.146.145.180)> CWD /incoming/

(000003) 9/18/2007 10:14:51 AM - anonymous (203.146.145.180)> 550 CWD failed. "/incoming": directory not found.

(000003) 9/18/2007 10:14:52 AM - anonymous (203.146.145.180)> CWD /in/

(000003) 9/18/2007 10:14:52 AM - anonymous (203.146.145.180)> 550 CWD failed. "/in": directory not found.

(000003) 9/18/2007 10:14:52 AM - anonymous (203.146.145.180)> CWD /_vti_cnf/

(000003) 9/18/2007 10:14:52 AM - anonymous (203.146.145.180)> 550 CWD failed. "/_vti_cnf": directory not found.

(000003) 9/18/2007 10:14:52 AM - anonymous (203.146.145.180)> CWD /_vti_txt/

(000003) 9/18/2007 10:14:52 AM - anonymous (203.146.145.180)> 550 CWD failed. "/_vti_txt": directory not found.

(000003) 9/18/2007 10:14:53 AM - anonymous (203.146.145.180)> CWD /_vti_log/

(000003) 9/18/2007 10:14:53 AM - anonymous (203.146.145.180)> 550 CWD failed. "/_vti_log": directory not found.

(000003) 9/18/2007 10:14:53 AM - anonymous (203.146.145.180)> CWD /anonymous/

(000003) 9/18/2007 10:14:53 AM - anonymous (203.146.145.180)> 550 CWD failed. "/anonymous": directory not found.

(000003) 9/18/2007 10:14:53 AM - anonymous (203.146.145.180)> CWD /outgoing/

(000003) 9/18/2007 10:14:53 AM - anonymous (203.146.145.180)> 550 CWD failed. "/outgoing": directory not found.

(000003) 9/18/2007 10:14:54 AM - anonymous (203.146.145.180)> CWD /tmp/

(000003) 9/18/2007 10:14:54 AM - anonymous (203.146.145.180)> 550 CWD failed. "/tmp": directory not found.

(000003) 9/18/2007 10:14:54 AM - anonymous (203.146.145.180)> CWD /mailroot/

(000003) 9/18/2007 10:14:54 AM - anonymous (203.146.145.180)> 550 CWD failed. "/mailroot": directory not found.

(000003) 9/18/2007 10:14:54 AM - anonymous (203.146.145.180)> CWD /ftproot/

(000003) 9/18/2007 10:14:54 AM - anonymous (203.146.145.180)> 550 CWD failed. "/ftproot": directory not found.

(000003) 9/18/2007 10:14:55 AM - anonymous (203.146.145.180)> CWD /images/

(000003) 9/18/2007 10:14:55 AM - anonymous (203.146.145.180)> 550 CWD failed. "/images": directory not found.

(000003) 9/18/2007 10:14:55 AM - anonymous (203.146.145.180)> CWD /_private/

(000003) 9/18/2007 10:14:55 AM - anonymous (203.146.145.180)> 550 CWD failed. "/_private": directory not found.

(000003) 9/18/2007 10:14:55 AM - anonymous (203.146.145.180)> CWD /usr/

(000003) 9/18/2007 10:14:55 AM - anonymous (203.146.145.180)> 550 CWD failed. "/usr": directory not found.

(000003) 9/18/2007 10:14:56 AM - anonymous (203.146.145.180)> CWD /pub/incoming/

(000003) 9/18/2007 10:14:56 AM - anonymous (203.146.145.180)> 550 CWD failed. "/pub/incoming": directory not found.

(000003) 9/18/2007 10:14:56 AM - anonymous (203.146.145.180)> CWD /public/incoming/

(000003) 9/18/2007 10:14:56 AM - anonymous (203.146.145.180)> 550 CWD failed. "/public/incoming": directory not found.

(000003) 9/18/2007 10:14:56 AM - anonymous (203.146.145.180)> CWD /anonymous/_vti_pvt/

(000003) 9/18/2007 10:14:56 AM - anonymous (203.146.145.180)> 550 CWD failed. "/anonymous/_vti_pvt": directory not found.

(000003) 9/18/2007 10:14:57 AM - anonymous (203.146.145.180)> CWD /anonymous/incoming/

(000003) 9/18/2007 10:14:57 AM - anonymous (203.146.145.180)> 550 CWD failed. "/anonymous/incoming": directory not found.

(000003) 9/18/2007 10:14:57 AM - anonymous (203.146.145.180)> CWD /anonymous/pub/

(000003) 9/18/2007 10:14:57 AM - anonymous (203.146.145.180)> 550 CWD failed. "/anonymous/pub": directory not found.

(000003) 9/18/2007 10:14:58 AM - anonymous (203.146.145.180)> CWD /anonymous/public/

(000003) 9/18/2007 10:14:58 AM - anonymous (203.146.145.180)> 550 CWD failed. "/anonymous/public": directory not found.

(000003) 9/18/2007 10:14:58 AM - anonymous (203.146.145.180)> CWD /usr/incoming/

(000003) 9/18/2007 10:14:58 AM - anonymous (203.146.145.180)> 550 CWD failed. "/usr/incoming": directory not found.

(000003) 9/18/2007 10:14:58 AM - anonymous (203.146.145.180)> disconnected.

(000004) 9/19/2007 22:36:17 PM - (not logged in) (65.37.156.41)> Connected, sending welcome message...

(000004) 9/19/2007 22:36:17 PM - (not logged in) (65.37.156.41)> 220 PHXX FTP 1

(000004) 9/19/2007 22:36:17 PM - (not logged in) (65.37.156.41)> USER anonymous

(000004) 9/19/2007 22:36:18 PM - (not logged in) (65.37.156.41)> 331 Password required for anonymous

(000004) 9/19/2007 22:36:18 PM - (not logged in) (65.37.156.41)> PASS ****************

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> 230 Logged on

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> CWD /RECYCLER/

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> 550 CWD failed. "/RECYCLER": directory not found.

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> CWD /public/

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> 550 CWD failed. "/public": directory not found.

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> CWD /pub/incoming/

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> 550 CWD failed. "/pub/incoming": directory not found.

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> CWD /incoming/

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> 550 CWD failed. "/incoming": directory not found.

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> CWD /_vti_pvt/

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> 550 CWD failed. "/_vti_pvt": directory not found.

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> CWD /pub/

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> 550 CWD failed. "/pub": directory not found.

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> CWD /upload/

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> 550 CWD failed. "/upload": directory not found.

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> CWD /pub/incoming/

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> 550 CWD failed. "/pub/incoming": directory not found.

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> CWD /upload/

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> 550 CWD failed. "/upload": directory not found.

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> CWD /in/

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> 550 CWD failed. "/in": directory not found.

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> CWD /

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> 250 CWD successful. "/" is current directory.

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> MKD 070919221930p

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> 550 Can't create directory. Permission denied

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> CWD /_vti_pvt/

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> 550 CWD failed. "/_vti_pvt": directory not found.

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> CWD /_vti_txt/

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> 550 CWD failed. "/_vti_txt": directory not found.

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> CWD /_vti_log/

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> 550 CWD failed. "/_vti_log": directory not found.

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> CWD /wwwroot/

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> 550 CWD failed. "/wwwroot": directory not found.

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> CWD /anonymous/

(000004) 9/19/2007 22:36:18 PM - anonymous (65.37.156.41)> 550 CWD failed. "/anonymous": directory not found.

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> CWD /public/

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> 550 CWD failed. "/public": directory not found.

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> CWD /outgoing/

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> 550 CWD failed. "/outgoing": directory not found.

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> CWD /temp/

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> 250 CWD successful. "/temp" is current directory.

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> MKD 070919221931p

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> 550 Can't create directory. Permission denied

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> CWD /tmp/

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> 550 CWD failed. "/tmp": directory not found.

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> CWD /anonymous/_vti_pvt/

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> 550 CWD failed. "/anonymous/_vti_pvt": directory not found.

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> CWD /anonymous/incoming/

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> 550 CWD failed. "/anonymous/incoming": directory not found.

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> CWD /mailroot/

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> 550 CWD failed. "/mailroot": directory not found.

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> CWD /ftproot/

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> 550 CWD failed. "/ftproot": directory not found.

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> CWD /anonymous/pub/

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> 550 CWD failed. "/anonymous/pub": directory not found.

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> CWD /anonymous/public/

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> 550 CWD failed. "/anonymous/public": directory not found.

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> CWD /_vti_cnf/

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> 550 CWD failed. "/_vti_cnf": directory not found.

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> CWD /images/

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> 550 CWD failed. "/images": directory not found.

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> CWD /_private/

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> 550 CWD failed. "/_private": directory not found.

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> CWD /cgi-bin/

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> 550 CWD failed. "/cgi-bin": directory not found.

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> CWD /cgibin/

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> 550 CWD failed. "/cgibin": directory not found.

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> CWD /usr/

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> 550 CWD failed. "/usr": directory not found.

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> CWD /usr/incoming/

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> 550 CWD failed. "/usr/incoming": directory not found.

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> CWD /home/

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> 550 CWD failed. "/home": directory not found.

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> CWD /outgoing/

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> 550 CWD failed. "/outgoing": directory not found.

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> CWD /anonymous/pub/

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> 550 CWD failed. "/anonymous/pub": directory not found.

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> CWD /_vti_cnf/

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> 550 CWD failed. "/_vti_cnf": directory not found.

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> CWD /_private/

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> 550 CWD failed. "/_private": directory not found.

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> CWD /anonymous/_vti_pvt/

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> 550 CWD failed. "/anonymous/_vti_pvt": directory not found.

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> CWD /anonymous/public/

(000004) 9/19/2007 22:36:19 PM - anonymous (65.37.156.41)> 550 CWD failed. "/anonymous/public": directory not found.

(000004) 9/19/2007 22:36:20 PM - anonymous (65.37.156.41)> CWD /anonymous/incoming/

(000004) 9/19/2007 22:36:20 PM - anonymous (65.37.156.41)> 550 CWD failed. "/anonymous/incoming": directory not found.

(000004) 9/19/2007 22:36:20 PM - anonymous (65.37.156.41)> CWD /usr/incoming/

(000004) 9/19/2007 22:36:20 PM - anonymous (65.37.156.41)> 550 CWD failed. "/usr/incoming": directory not found.

(000004) 9/19/2007 22:36:20 PM - anonymous (65.37.156.41)> CWD /cgibin/

(000004) 9/19/2007 22:36:20 PM - anonymous (65.37.156.41)> 550 CWD failed. "/cgibin": directory not found.

(000004) 9/19/2007 22:36:20 PM - anonymous (65.37.156.41)> CWD /cgi-bin/

(000004) 9/19/2007 22:36:20 PM - anonymous (65.37.156.41)> 550 CWD failed. "/cgi-bin": directory not found.

(000004) 9/19/2007 22:36:20 PM - anonymous (65.37.156.41)> CWD / /

(000004) 9/19/2007 22:36:20 PM - anonymous (65.37.156.41)> 250 CWD successful. "/ " is current directory.

(000004) 9/19/2007 22:36:20 PM - anonymous (65.37.156.41)> MKD 070919221932p

(000004) 9/19/2007 22:36:20 PM - anonymous (65.37.156.41)> 550 Can't create directory. Permission denied

(000004) 9/19/2007 22:36:20 PM - anonymous (65.37.156.41)> CWD / /

(000004) 9/19/2007 22:36:20 PM - anonymous (65.37.156.41)> 250 CWD successful. "/ " is current directory.

(000004) 9/19/2007 22:36:20 PM - anonymous (65.37.156.41)> MKD 070919221932p

(000004) 9/19/2007 22:36:20 PM - anonymous (65.37.156.41)> 550 Can't create directory. Permission denied

(000004) 9/19/2007 22:36:20 PM - anonymous (65.37.156.41)> CWD / /

(000004) 9/19/2007 22:36:20 PM - anonymous (65.37.156.41)> 250 CWD successful. "/ " is current directory.

(000004) 9/19/2007 22:36:20 PM - anonymous (65.37.156.41)> MKD 070919221932p

(000004) 9/19/2007 22:36:20 PM - anonymous (65.37.156.41)> 550 Can't create directory. Permission denied

(000004) 9/19/2007 22:36:20 PM - anonymous (65.37.156.41)> CWD / /

(000004) 9/19/2007 22:36:20 PM - anonymous (65.37.156.41)> 250 CWD successful. "/ " is current directory.

(000004) 9/19/2007 22:36:20 PM - anonymous (65.37.156.41)> MKD 070919221932p

(000004) 9/19/2007 22:36:20 PM - anonymous (65.37.156.41)> 550 Can't create directory. Permission denied

(000004) 9/19/2007 22:36:20 PM - anonymous (65.37.156.41)> CWD / /

2007-10-01 10:09:41 | 363 Views

Comments

Triavius at Oct 1, 2007.

wow thats all greek to me lol, care to give some insight into those of us who have no idea what that means?

Streetbum at Oct 1, 2007.

Someone tried to log into the PHXX FTP and screw crap up, is what Im getting from it...

Scro at Oct 5, 2007.

It’s for people who hosts FTP sites or other internet server type services. There are literally hundreds of computers canning every system on the internet looking for vulnerabilities. In this case a program finds our FTP server. (Which is used for file downloads etc.) Once they find it they try to upload files to it for later distribution, or try to compromise it for other malicious reasons.

Leave a Comment

You must be logged in to comment