Author Topic: Malicious IP being blocked? spreading Mozi-elf-worm.  (Read 1298 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Malicious IP being blocked? spreading Mozi-elf-worm.
« Reply #1 on: January 26, 2020, 12:48:33 AM »
Port 8088

Hikvision DVR
HTTP: Support Methods: OPTIONS TRACE GET HEAD POST PUT DELETE

We can see though through a simple test that PUT is not a permitted option.

Quote
HTTP/1.1 405 Method Not Allowed
Date: Sun, 26 Jan 2020 07:34:57 GMT
Server: App-webs
Content-Length: 228
Content-Type: text/html
Connection: close

<!DOCTYPE html>
<html><head><title>Document Error: Method Not Allowed</title></head></title>
<body><h2>Access Error: 405 -- Method Not Allowed</h2>
<p>Method PUT not supported by file handler at this location
</p></body></html>

SSH, Telnet and FTP all appear to be invulnerable from exploits and banner grabbing. MSFConsole (Metaplsoit's) modules failed, as did manual attempts to connect.

Edit: DELETE fails as well.

VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.