nanog mailing list archives
RE: What HTTP exploit?
From: "Todd Mitchell - lists" <lists () ciphin com>
Date: Sun, 30 May 2004 16:59:48 -0400
| Behalf Of John Palmer (NANOG Acct) | Sent: May 30, 2004 4:44 PM | | Can anyone identify this http exploit? Seen in the apache logs: | | foo.bar.com | - - [30/May/2004:02:45:28 -0400] "SEARCH | /\x90\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\ | x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb | 1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb | 1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\ | xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\ | xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1 | | etc - and it goes on for about 1200 bytes. This is an older IIS WebDAV exploit. More info at http://www.microsoft.com/technet/security/bulletin/ms03-007.mspx You can mod_rewrite these attempts to /dev/null RedirectMatch permanent (.*)\/x90\/(.*)$ /dev/null Todd --
Current thread:
- What HTTP exploit? John Palmer (NANOG Acct) (May 30)
- RE: What HTTP exploit? Todd Mitchell - lists (May 30)
- Re: What HTTP exploit? Matthew McGehrin (May 30)
- Re: What HTTP exploit? Richard Welty (May 30)
- Re: What HTTP exploit? Suresh Ramasubramanian (May 30)
- <Possible follow-ups>
- Re: What HTTP exploit? Mike Nice (May 31)
- Re: What HTTP exploit? Vinny Abello (May 31)
- Re: What HTTP exploit? Laurence F. Sheldon, Jr. (May 31)
- Re: What HTTP exploit? Paul G (May 31)
- Re: What HTTP exploit? Bob Martin (May 31)
- Re: What HTTP exploit? Jason Dixon (May 31)
- Re: What HTTP exploit? Vinny Abello (May 31)