Apache atack.

This is a discussion on Apache atack. within the Linux Security forums, part of the System Security and Security Related category; Hy everyone. Lately i've been receiving some strange requests on port 80. I found this in the logs: 218....


Go Back   Usenet Forums > System Security and Security Related > Linux Security

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 05-19-2004
Nuno Paquete
 
Posts: n/a
Default Apache atack.

Hy everyone.
Lately i've been receiving some strange requests on port 80.
I found this in the logs:
218.94.77.207 - - [19/May/2004:14:16:51 +0100] "SEARCH /\x90\x02\xb1\x02\xb
\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1........
.....
.....

This is just a litle bit of the query, in reality it is very longer.
Can someone tell me what is going on?
I've got Slackware 9.1 and Apache-1.3.29-i486-2.
What i think that is strange, is that when i had got Red Hat installed i
never saw this kind of logs.
Is this the exploitation of some known security hole?

Best regards,
Nuno Paquete.
Reply With Quote
  #2 (permalink)  
Old 05-19-2004
Jem Berkes
 
Posts: n/a
Default Re: Apache atack.

> Lately i've been receiving some strange requests on port 80.
> I found this in the logs:
> 218.94.77.207 - - [19/May/2004:14:16:51 +0100] "SEARCH
> /\x90\x02\xb1\x02\xb
> \x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb


I've been getting these recently as well, on all my web servers. I don't
know if it's targeting Apache or another web server (IIS?), but it would be
interesting to know what exactly they're trying to do.

--
Jem Berkes
http://www.sysdesign.ca/
Reply With Quote
  #3 (permalink)  
Old 05-19-2004
Lew Pitcher
 
Posts: n/a
Default Re: Apache atack.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Jem Berkes wrote:

>>Lately i've been receiving some strange requests on port 80.
>>I found this in the logs:
>>218.94.77.207 - - [19/May/2004:14:16:51 +0100] "SEARCH
>>/\x90\x02\xb1\x02\xb
>>\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1 \x02\xb1\x02\xb1\x02\xb

>
>
> I've been getting these recently as well, on all my web servers. I don't
> know if it's targeting Apache or another web server (IIS?), but it

would be
> interesting to know what exactly they're trying to do.


It's a buffer overflow attack, apparently an IIS "WebDav exploit", aimed
at NTDLL.DLL.

See http://www.fatelabs.com/library/fate...l-analysis.pdf for some
of the details.



- --

Lew Pitcher, IT Consultant, Enterprise Application Architecture
Enterprise Technology Solutions, TD Bank Financial Group

(Opinions expressed here are my own, not my employer's)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (MingW32)

iD8DBQFAq5P0agVFX4UWr64RAjtWAJwMcD0F3vhTyl/m/HqtoYCW/6umzgCeLDOg
4xdzhYb35Yw1Mfsa1xXjAh0=
=0YGD
-----END PGP SIGNATURE-----
Reply With Quote
  #4 (permalink)  
Old 05-19-2004
Geoffrey King
 
Posts: n/a
Default Re: Apache atack.

On Wed, 19 May 2004 16:55:29 +0000, Jem Berkes wrote:

>> Lately i've been receiving some strange requests on port 80. I found
>> this in the logs:
>> 218.94.77.207 - - [19/May/2004:14:16:51 +0100] "SEARCH
>> /\x90\x02\xb1\x02\xb
>> \x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb

>
> I've been getting these recently as well, on all my web servers. I don't
> know if it's targeting Apache or another web server (IIS?), but it would
> be interesting to know what exactly they're trying to do.


IIS WebDAV Exploit, I think one of the agobot worms tries to use it to get
into Windows boxes.

--
-Geoff

Reply With Quote
  #5 (permalink)  
Old 05-19-2004
Jem Berkes
 
Posts: n/a
Default Re: Apache atack.

>>> Lately i've been receiving some strange requests on port 80. I found
>>> this in the logs:
>>> 218.94.77.207 - - [19/May/2004:14:16:51 +0100] "SEARCH
>>> /\x90\x02\xb1\x02\xb
>>> \x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\
>>> xb

>>
>> I've been getting these recently as well, on all my web servers. I
>> don't know if it's targeting Apache or another web server (IIS?), but
>> it would be interesting to know what exactly they're trying to do.

>
> IIS WebDAV Exploit, I think one of the agobot worms tries to use it to
> get into Windows boxes.


LOL, so people still try to run http servers Windows :) Good way to kill
your server.

--
Jem Berkes
http://www.sysdesign.ca/
Reply With Quote
  #6 (permalink)  
Old 05-19-2004
ynotssor
 
Posts: n/a
Default Re: Apache atack.

"Jem Berkes" <jb@users.pc9.org> quoted and wrote in message
news:Xns94EE795FD6A55jbuserspc9org@130.179.16.24

>> Lately i've been receiving some strange requests on port 80.
>> I found this in the logs:
>> 218.94.77.207 - - [19/May/2004:14:16:51 +0100] "SEARCH
>> /\x90\x02\xb1\x02\xb
>> \x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb

>
> I've been getting these recently as well, on all my web servers. I
> don't know if it's targeting Apache or another web server (IIS?), but
> it would be interesting to know what exactly they're trying to do.


http://www.linuxquestions.org/questions/history/174552


--
use hotmail for email replies
Reply With Quote
  #7 (permalink)  
Old 05-20-2004
Nuno Paquete
 
Posts: n/a
Default Re: Apache atack.

Thanks guys.

"Nuno Paquete" <nmp@ispgaya.pt> escreveu na mensagem
news:40ab72f9$0$1841$a729d347@news.telepac.pt...
> Hy everyone.
> Lately i've been receiving some strange requests on port 80.
> I found this in the logs:
> 218.94.77.207 - - [19/May/2004:14:16:51 +0100] "SEARCH

/\x90\x02\xb1\x02\xb
> \x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
> \x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
> \x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
> \x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
> \x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
> \x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
> \x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
> \x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
> \x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
> \x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
> \x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
> \x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
> \x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
> \x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1\x02\xb
> \x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02\xb1\x02\xb1........
> ....
> ....
>
> This is just a litle bit of the query, in reality it is very longer.
> Can someone tell me what is going on?
> I've got Slackware 9.1 and Apache-1.3.29-i486-2.
> What i think that is strange, is that when i had got Red Hat installed i
> never saw this kind of logs.
> Is this the exploitation of some known security hole?
>
> Best regards,
> Nuno Paquete.



Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 06:11 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0