Security Incidents mailing list archives

RE: New Attack / New Vulnerability?


From: "Matthew F. Caldwell" <mattc () guarded net>
Date: Wed, 27 Feb 2002 14:26:39 -0500

Have you verified the remote ends are not anonymous/proxies?

-----Original Message-----
From: Sterling Moses [mailto:sterling () silversoftwareinc com]
Sent: Wednesday, February 27, 2002 12:11 PM
To: incidents () securityfocus com
Subject: New Attack / New Vulnerability?


Is there a new vulnerability out?

We monitor hundreds of financial IIS servers and have noticed many requests
for the following:

GET /_vti_bin/owssvr.dll 404

These requests originate from multiple IP addresses, and hit different
machines on
different networks.

Based on the traffic and number of entries I can guess these are not
targeted attacks, but seem to be opportunistic
in nature.

Any information would be helpful.

Sterling.


----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com


Current thread: