Hello.
We have received a report of suspicious network activity involving a system under your management. Details have been included at the end of this message.
Please investigate the claim and immediately let us know what you find.
Be sure to include details of actions taken to prevent further abuse.
We look forward to your prompt response.
Abuse Department
BurstNET Technologies, Inc.
-----------------------------------------------------------------------
*** We depend on our clients' assistance in these matters. Please note
that failure to respond to this notice, within 24 hours, may result in
service interruption and a $50.00 fee.
-----------------------------------------------------------------------
BurstNET(tm) BASIC POLICY & SERVICE GUIDELINES (AUP)
https://www.burst.net/policy/terms.shtml
-----------------------------------------------------------------------
LOGFILES ARE ALWAYS IN CEST - clocks synced to ptbtime1.ptb.de
To: netsecdb::netsecdb_hacking
Subject: NETSECDB_HACKING
Date: 2010-07-14 21:08:40
> 144-212-255-222.hostnoc.net - - [14/Jul/2010:21:07:18 +0200] "GET
>
/index.php?q=taxonomy/term//index.php?option=com_rwcards&controller=../../../../../../../../../../../../../../../proc/self/environ%00
> HTTP/1.1" 302 419 "-" "libwww-perl/5.823"
> 144-212-255-222.hostnoc.net - - [14/Jul/2010:21:07:19 +0200] "GET
>
//index.php?option=com_rwcards&controller=../../../../../../../../../../../../../../../proc/self/environ%00
> HTTP/1.1" 302 390 "-" "libwww-perl/5.823"
> 144-212-255-222.hostnoc.net - - [14/Jul/2010:21:07:19 +0200] "GET
>
/index.php?q=taxonomy//index.php?option=com_rwcards&controller=../../../../../../../../../../../../../../../proc/self/environ%00
> HTTP/1.1" 302 414 "-" "libwww-perl/5.823"
>
> showwebsessions.sh
> > > > 222.255.212.173.in-addr.arpa name = 173-212-255-222.hostnoc.net.
> 173.212.255.222
>
---- End forwarded message ---