[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: strange http log entry



James Sinnamon a écrit :

Dear firewallers,

I found a two unusual "SEARCH" records on my apache httpd access.log.

They start as follows:

144.132.111.231 - - [10/Jul/2004:11:38:24 +1000] "SEARCH
/\x90\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\
\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\
\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\\
x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\
\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\
\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\
\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\
\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\\
..

Each record is roughly 8180 characteres in length.

Does anyone know what might be going on? Is it perfctly innocent
... or is someone up to no good?  Can anyone suggest another
mailing list on which to pursue this if this is not the right place to ask?

The two query records in full are at:

 http://www.sos.cable.nu/SEARCH-qry-log-rec.txt

TIA

James

this exploit is an attack for IIS, the default server of microsoft...
be quiet with apache, caudium, boa and other linux servers...



Reply to: