Scan 10

The scan for December, 2000.  This month's challenge was to decode two exploits launched against the same honeypot in the same morning


The Challenge:

  1. Can you name the FTP scanning tool?
  2. What does this FTP exploit achieve?  Does it open a port, create a shell, add a user account?
  3. Is the FTP attack successful?
  4. What RPC service is exploited?
  5. Where in the exploit code below does he bind a shell  to port 39168?
  6. What two accounts are created, and what are the UID's?
Bonus Question: What is the password of the first account created?

The Results:

On 17 January, Daniel Martin released an excellent writeup on the Ramen worm, which bears a remarkable resemblance to this attack.

Writeups from the Honeynet Project members

Writeups from the Security Community
The Honeynet Project