Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 31 Mar 2004 11:37:22 -0500
From:      "Nick" <nick_fbsd@cogeco.ca>
To:        <freebsd-questions@freebsd.org>
Subject:   RE: Very long URL with malice intended
Message-ID:  <20040331163718.72FAC2036@fep2.cogeco.net>
In-Reply-To: <20040331150847.GA3376@sting.grogsworld.org>

next in thread | previous in thread | raw e-mail | index | archive | help


> -----Original Message-----
> From: owner-freebsd-questions@freebsd.org [mailto:owner-freebsd-
> questions@freebsd.org] On Behalf Of GROG! (Jeff Howie)
> Sent: Wednesday, March 31, 2004 10:09 AM
> To: freebsd-questions@freebsd.org
> Subject: Re: Very long URL with malice intended
> 
> On Sat, 27 Mar 2004 15:50:53 -0600, Jack L. Stone wrote:
> >At 08:28 PM 3.27.2004 +0100, Cordula's Web wrote:
> >>>Within the past couple of weeks, the Apache logs have shown a new
> >>>type of intrusion -- a very, very long URL request...
> >>>
> >>>My question is what syntax can I add, if any, to my httpd.conf to
> >>>redirect such requests..??
> >>>
> >>>65.35.186.74 - - [26/Mar/2004:19:01:04 -0600] "SEARCH
> >>>/\x90\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\...
> >>
> >>Are only SEARCH requests affected, or GET as well?
> 
> Hey all. A question from a heretofore unrevealed skulker :^>. Was this
> question ever answered off-list? My own box is getting hit quite often
> with these & I'm concerned that they might be causing harm. thks
> 
> >The ones I've seen have all been SEARCH....
> 
> Me too.
> 
> thks
> 
> --
> GROG! MMM          Reality is that which, when you stop believing
> thks (o o)         in it, doesn't go away.  -- Philip K. Dick
> --ooO-(_)-Ooo--
> _______________________________________________
> freebsd-questions@freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-questions
> To unsubscribe, send any mail to "freebsd-questions-
> unsubscribe@freebsd.org"


It is an IIS WebDAV exploit from April 2003 (?), apache is not affected, its
just annoying :) (nachi and agobot use this exploit)



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20040331163718.72FAC2036>