View Single Post

  #7 (permalink)  
Old 10-11-2003
Dexter J
 
Posts: n/a
Default Re: Heads Up - something new I fear..

(corrected reported)

Salutations:

Davide Bianchi wrote:
>
> In alt.apache.configuration Dexter J <lamealameadingdong@lamelamelame.org> wrote:
> > are you running a bone stock install on *nix?.

>
> Nope. Never did. Never will.
>
> Davide


Me either usually - but this one slipped through the cracks as I was
focusing on Code Red/Klez at the time..

Well if anyone is running apache 2.+ and wants to try a test - simply cut
'N paste:

your.server.ip/error/%5c%2e%2e%5clogs%5cinstall.log

or

your.server.ip/error/%5c%2e%2e%5cconf%5chttpd.conf

It's not hard to secure using redirectmatch - but it's closing the barn
door after the fact in my opinion.

Maybe it's just someone rattling doors.. But it's the darned 'maybe'
that bothers me. It's turned up in another AWSTATS file this morning
when I googled:

/error/%5c%2e%2e%5clogs%5cinstall.log

Anyway - that's all I have to offer. Interested if anyone else starts to
see it.

--

J Dexter - webmaster - http://www.dexterdyne.org/
all tunes - no cookies no subscription no weather no ads
no news no phone in - RealAudio 8+ Required - all the Time

Radio Free Dexterdyne Top Tune o'be-do-da-day
Kathy Matea - 455 Rocket
http://www.dexterdyne.org/888/051.RAM