Security Basics mailing list archives

Re: strange httpd error log response


From: Ricardo Oliva <ricardo () zoology ubc ca>
Date: Wed, 9 Jun 2004 13:12:30 -0700

Hi Ralph,

This is actually a quite old one. This is just the entry on Apache's access_log file for exploit attempts on the IIS WebDAV service.

It does not affect Apache at all and you should not worry too much about it, but it can be a problem for log analyzers and web statistics applications.

I have tried to use Apache's customized logging for avoiding those messages from showing up in my log files but had no luck. So used old shell scripting for doing that once a month before some statistics software use the data.

Hope this helps.

All the best,
--
Ricardo Oliva
Core Systems Administrator
Zoology Department
University of British Columbia
Ph.: 604-822-3882
E-mail: ricardo () zoology ubc ca

On 9-Jun-04, at 5:28 AM, Ralph Brown wrote:


I have recently overhauled my server, and am now using Fedora Core 2. With it came the newest version of Logwatch, 5.1. I have used Logwatch with RH 9.X, and was very happy with it. After running Logwatch a few times, I am getting the following message (report to root). I do not understand it and wonder if it is a bug, setting error, or ? Please advise and/or explain.
--------------------------------------------------
 --------------------- httpd Begin ------------------------
A total of 4 unidentified 'other' records logged
SEARCH / \x90\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02 \xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02 \xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02 \xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02 \xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02 \xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02 \xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02 \xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02 \xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02 \xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02 \xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02 \xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02 \xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02 \xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x 02 \xb1\x0... (this repeats numerous times...)
---------------------------------------------------
Suggestions please. Thank you in advance!
Ralph
"Forget world peace...
Try using your turnsignal"
~~~~~~~~~~~~~~~~~~~~
Ralph Brown
rbrown () policing net


----------------------------------------------------------------------- ---- Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 offany course! All of our class sizes are guaranteed to be 10 students or lessto facilitate one-on-one interaction with one of our expert instructors.Attend a course taught by an expert instructor with years of in-the-fieldpen testing experience in our state of the art hacking lab. Master the skillsof an Ethical Hacker to better assess the security of your organization.Visit us at:http://www.infosecinstitute.com/courses/ ethical_hacking_training.html ----------------------------------------------------------------------- -----



---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off any course! All of our class sizes are guaranteed to be 10 students or less to facilitate one-on-one interaction with one of our expert instructors. Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. Master the skills of an Ethical Hacker to better assess the security of your organization. Visit us at: http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------


Current thread: