Security Incidents mailing list archives

new worm?


From: "Bassett, Mark" <mbassett () omaha com>
Date: Thu, 22 Apr 2004 15:48:47 -0500

In my apache error logs I'm seeing tons of these:

[Thu Apr 22 14:56:26 2004] [error] [client 147.92.2.13] File does not
exist: /u
sr/local/apache/site/public/\'images/mods/mreg/images/arrows/images/head
er/hdr1
_left_portal_new.gif
[Thu Apr 22 14:56:29 2004] [error] [client 198.26.123.37] File does not
exist: 
/usr/local/apache/site/public/\'images/mods/mreg/metro_nav.gif\
[Thu Apr 22 14:56:37 2004] [error] [client 12.4.195.100] File does not
exist: /
usr/local/apache/site/public/\'images/mods/mreg/metro_nav.gif\
[Thu Apr 22 14:56:44 2004] [error] [client 147.92.2.13] File does not
exist: /u
sr/local/apache/site/public/\'images/mods/mreg/images/arrows/images/arro
ws/arro
w_tan.gif
[Thu Apr 22 14:56:46 2004] [error] [client 147.92.2.13] File does not
exist: /u
sr/local/apache/site/public/\'images/mods/mreg/images/arrows/images/arro
ws/arro
w_off_blue_lt.gif
[Thu Apr 22 14:56:52 2004] [error] [client 147.92.2.13] File does not
exist: /u
sr/local/apache/site/public/\'images/mods/mreg/images/arrows/images/head
er/hdr1
_left_portal_new.gif
[Thu Apr 22 14:56:52 2004] [error] [client 147.92.2.13] File does not
exist: /u
sr/local/apache/site/public/\'images/mods/mreg/images/arrows/images/head
er/hdr2
.gif
[Thu Apr 22 14:56:53 2004] [error] [client 147.92.2.13] File does not
exist: /u
sr/local/apache/site/public/\'images/mods/mreg/images/arrows/images/weat
her/ico

Any idea if there is a new worm out trying this directory traversal type
attack?  We've been getting them for a couple days now, and our apache
service just died on us about 20 minutes ago.  

Mark Bassett
Network Administrator
World media company
Omaha.com
402-898-2079


---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: