[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Full-disclosure] dorkuid: what's that all about?



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Got strange log entries, not the usual .php crap requests. Found
nothing about it on google. Does someone know, what remote was looking
for?

46.4.208.103 - - [26/Oct/2011:06:29:40 +0000] "GET
/Security/dorkuid=0(root)%20gid=0(root)%20groups=0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel)%0A?
HTTP/1.1" 404 299 "-" "libwww-perl/5.805"

Some kind of backconnect to routed boxes?

hd
- -- 
http://www.halfdog.net/
PGP: 156A AE98 B91F 0114 FE88  2BD8 C459 9386 feed a bee
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAk6nvq0ACgkQxFmThv7tq+5QxgCfbI9jMCc3/+GBFgnK5Sz4L6rD
cJQAnRoxYlzkdGTjXrO+ohTBnr4K5cIU
=w6e6
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/