I just also wanted to add that it appears this simiens crew has been busy as of Feb. 1 sweeping the net for vulnerable Awstats installations, I just banned the IP address 24.226.36.32 for probing my server. I don't run awstats, and I'm glad I don't today.

Here are a few sites that were affected by these recent awstats exploit:
http://jeremy.zawodny.com/blog/archives/004107.html
http://www.russellbeattie.com/notebook/1008284.html
http://www.lin5.com/blogs/index.php/...h_monkey_attac

There seems to be too many more potential victims to this awstats hack

All hands to battlestations, this is digital warfare.


PuRe