Last night, HITME began to pick up various sources scanning for a new file in the RoundCube Webmail product. The file “list.js” is being scanned for by the Toata bot and low levels of port 80 scans matching these probes are ongoing. SANS and the project owners have been informed.
No exploitation has been observed by us thus far in relationship to these scans, but cataloging is ongoing. Intent of the attacker is currently unknown, as is the vulnerability, if any, present in the file.
Following are the signatures captured from one host:
XXX received an alert from 88.191.50.206 at 2009-01-15 19:55:41 on port 80
Alert Data: GET /rc/program/js/list.js HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Toata dragostea mea pentru diavola
Host: xx.xx.xx.xx
Connection: Close
XXX received an alert from 88.191.50.206 at 2009-01-15 19:55:39 on port 80
Alert Data: GET /roundcubemail/program/js/list.js HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Toata dragostea mea pentru diavola
Host: xx.xx.xx.xx
Connection: Close
XXX received an alert from 88.191.50.206 at 2009-01-15 19:55:38 on port 80
Alert Data: GET /roundcube/program/js/list.js HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Toata dragostea mea pentru diavola
Host: xx.xx.xx.xx
Connection: Close
XXX received an alert from 88.191.50.206 at 2009-01-15 19:55:36 on port 80
Alert Data: GET /webmail/program/js/list.js HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Toata dragostea mea pentru diavola
Host: xx.xx.xx.xx
Connection: Close
XXX received an alert from 88.191.50.206 at 2009-01-15 19:55:35 on port 80
Alert Data: GET /email/program/js/list.js HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Toata dragostea mea pentru diavola
Host: xx.xx.xx.xx
Connection: Close
Once again, users of RoundCube Webmail are urged to ensure they are doing additional levels of monitoring, staying current on all patches/updates and taking other precautions. Consider removing RoundCube from Internet exposure until these and other ongoing issues are mitigated.