<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>[blog.rayfoo] &#187; scanners</title>
	<atom:link href="http://blog.rayfoo.info/tag/scanners/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.rayfoo.info</link>
	<description>Infosec, DFIR, tech geekery, thoughts and whatnot</description>
	<lastBuildDate>Wed, 25 Jan 2012 00:36:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Interesting scanner</title>
		<link>http://blog.rayfoo.info/2010/07/interesting-scanner</link>
		<comments>http://blog.rayfoo.info/2010/07/interesting-scanner#comments</comments>
		<pubDate>Sat, 17 Jul 2010 16:26:26 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Everything]]></category>
		<category><![CDATA[information gathering]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[scanners]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[TODO]]></category>
		<category><![CDATA[web application]]></category>

		<guid isPermaLink="false">http://blog.rayfoo.info/?p=652</guid>
		<description><![CDATA[I know I'm probably the only one in this island that thinks this as interesting, but nevertheless... It's normal for the web server to get scanned by other "inquisitive" people/machines/bots, but this tool looks pretty interesting...  Will dig deeper into this later. The scanners typically try to detect whether I'm running certain vulnerable versions of [...]]]></description>
			<content:encoded><![CDATA[<p>I know I'm probably the only one in this island that thinks this as interesting, but nevertheless...</p>
<p>It's normal for the web server to get scanned by other "inquisitive" people/machines/bots, but this tool looks pretty interesting...  Will dig deeper into this later.</p>
<p>The scanners typically try to detect whether I'm running certain vulnerable versions of web apps for them to exploit.  So when the web app does not exist, guess what happens? <img src='http://blog.rayfoo.info/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>This particular scan was interesting, because of the <span style="color: #ff0000;">user agent</span> field.  Check it out:</p>
<p>200.6.121.56 - - [17/Jul/2010:14:51:06 +0800] "GET /roundcubemail-0.1//bin/msgimport HTTP/1.1" 404 136 "-" "<span style="color: #ff0000;">Toata dragostea mea pentru diavola</span>"<br />
200.6.121.56 - - [17/Jul/2010:14:51:06 +0800] "GET /bin/msgimport HTTP/1.1" 404 136 "-" "Toata dragostea mea pentru diavola"<br />
200.6.121.56 - - [17/Jul/2010:14:51:06 +0800] "GET /wm//bin/msgimport HTTP/1.1" 404 136 "-" "Toata dragostea mea pentru diavola"<br />
200.6.121.56 - - [17/Jul/2010:14:51:06 +0800] "GET /webmail//bin/msgimport HTTP/1.1" 404 136 "-" "Toata dragostea mea pentru diavola"<br />
200.6.121.56 - - [17/Jul/2010:14:51:06 +0800] "GET /webmail2//bin/msgimport HTTP/1.1" 404 136 "-" "Toata dragostea mea pentru diavola"<br />
200.6.121.56 - - [17/Jul/2010:14:51:05 +0800] "GET /rms//bin/msgimport HTTP/1.1" 404 136 "-" "Toata dragostea mea pentru diavola"<br />
200.6.121.56 - - [17/Jul/2010:14:51:05 +0800] "GET /roundcubemail//bin/msgimport HTTP/1.1" 404 136 "-" "Toata dragostea mea pentru diavola"<br />
200.6.121.56 - - [17/Jul/2010:14:51:05 +0800] "GET /mail2//bin/msgimport HTTP/1.1" 404 136 "-" "Toata dragostea mea pentru diavola"<br />
200.6.121.56 - - [17/Jul/2010:14:51:05 +0800] "GET /mail//bin/msgimport HTTP/1.1" 404 136 "-" "Toata dragostea mea pentru diavola"<br />
200.6.121.56 - - [17/Jul/2010:14:51:04 +0800] "GET /mss2//bin/msgimport HTTP/1.1" 404 136 "-" "Toata dragostea mea pentru diavola"<br />
200.6.121.56 - - [17/Jul/2010:14:51:04 +0800] "GET /rc//bin/msgimport HTTP/1.1" 404 136 "-" "Toata dragostea mea pentru diavola"</p>
<p>If anyone knows more about this particular scanner, feel free to comment and share!</p>
<p>Edit (19 Jul): it seems that I've joined <a href="http://www.google.com/search?q=Toata+dragostea+mea+pentru+diavola">the ranks</a> of those who've been scanned one way or another.  Apparently <a href="http://translate.google.com/#auto|en|Toata%20dragostea%20mea%20pentru%20diavola">it is in Romanian</a>, meaning "All my love for the devil".</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.rayfoo.info/2010/07/interesting-scanner/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

