Author |
Message |
sixonetonoffun
Spouse Contemplates Divorce
data:image/s3,"s3://crabby-images/cd6c2/cd6c2e2741fd0ae19eebfc889b0f297a2eb2b623" alt=""
Joined: Jan 02, 2003
Posts: 2496
|
Posted:
Tue Jun 29, 2004 8:52 pm |
|
If you see a entry like this in your logs:
299.*.*.* - - [06/Jun/2004:10:39:23 -0500] "SEARCH /\x90\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x0
That goes on and on and on!
This is appearently the IIS WebDAV exploit.
Affected Software:
• Microsoft Windows NT 4.0
• Microsoft Windows NT 4.0 Terminal Server Edition
• Microsoft Windows 2000
• Microsoft Windows XP
Not Affected Software:
• Microsoft Windows Server 2003
• *NIX OS's
MS patches available:
http://www.microsoft.com/technet/security/bulletin/ms03-007.mspx
Source of details found here:
http://forums.macosxhints.com/showthread.php?t=22371
http://www.webmasterworld.com/forum39/2173.htm
One interesting way (for apache users) suggested to rid yourself of those entries in your logs was to add something like this to your httpd.conf assumes mod_rewrite enabled. Replace http://www.microsoft.com with where ever you'd like to send these requests.
Code:
<IfModule mod_rewrite.c>
RedirectMatch permanent (.*)cmd.exe(.*)$ http://www.microsoft.com
RedirectMatch permanent (.*)root.exe(.*)$ http://www.microsoft.com
RedirectMatch permanent (.*)\/_vti_bin\/(.*)$ http://www.microsoft.com
RedirectMatch permanent (.*)\/scripts\/\.\.(.*)$ http://www.microsoft.com
RedirectMatch permanent (.*)\/_mem_bin\/(.*)$ http://www.microsoft.com
RedirectMatch permanent (.*)\/msadc\/(.*)$ http://www.microsoft.com
RedirectMatch permanent (.*)\/MSADC\/(.*)$ http://www.microsoft.com
RedirectMatch permanent (.*)\/c\/winnt\/(.*)$ http://www.microsoft.com
RedirectMatch permanent (.*)\/d\/winnt\/(.*)$ http://www.microsoft.com
RedirectMatch permanent (.*)\/x90\/(.*)$ http://www.microsoft.com
</IfModule>
|
We could also do this in htaccess but whats the point?
I posted this because this has come up a few times here either in the chat or the forums. |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
Raven
Site Admin/Owner
data:image/s3,"s3://crabby-images/f1ebe/f1ebec6bf773a9d94054cd575831abd5c29229a5" alt=""
Joined: Aug 27, 2002
Posts: 17088
|
Posted:
Wed Jun 30, 2004 4:48 am |
|
I have tried to trap that fool thing in .htaccess using a regex but haven't been able to find the magic to do it Potentially dDosing MS is an interesting approach but I want to figure out the .htaccess trap and work it into Sentinel data:image/s3,"s3://crabby-images/2dabb/2dabba8c5907cf3f55a360a6d072ddd29e8d360e" alt="RavensScripts" |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
sixonetonoffun
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Wed Jun 30, 2004 10:26 am |
|
Something like this maybe? Seems like a lot of code just to catch this one bugger.
$_SEARCH = $GLOBALS['HTTP_POST_VARS']['SEARCH'] ||
$_SERVER['SEARCH'] ||
$HTTP_GET_VARS['SEARCH'] ||
$_SEARCH;
$querystring = urldecode($querystring);
if(isset($_SEARCH) && stristr($querystring,'x90') OR stristr($querystring,'xb1')) {
if($ab_config['activate_filters'] > 1) {
block_ip($ip, $banuser, $agent, $bantime, $reason, $ab_config['activate_filters']);
} else {
write_mail($remote, $banuser, $bantime, $reason);
Header("Location: index.php");
}
} |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
Raven
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Wed Jun 30, 2004 10:42 am |
|
A regex or preg_match will make it much simpler. I just haven't had time to get back on it data:image/s3,"s3://crabby-images/92c12/92c1280436c38d9d430ded7042e0373008760263" alt="Smile" |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
xfsunolesphp
Regular
data:image/s3,"s3://crabby-images/96ed4/96ed47c372fdf8a30e9de3c3c6deadd54685d804" alt="Regular Regular"
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
Joined: Aug 23, 2003
Posts: 77
|
Posted:
Wed Jun 30, 2004 4:12 pm |
|
Raven wrote: | I have tried to trap that fool thing in .htaccess using a regex but haven't been able to find the magic to do it Potentially dDosing MS is an interesting approach but I want to figure out the .htaccess trap and work it into Sentinel |
i love it, Dos Microsoft. data:image/s3,"s3://crabby-images/eec77/eec7756b745c11a099ff95311a373e729592d673" alt="Laughing" |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
stephen2417
Worker
data:image/s3,"s3://crabby-images/fd5c7/fd5c7602491f7a344d716c8d43e335b3d75bacf8" alt="Worker Worker"
data:image/s3,"s3://crabby-images/ad5a7/ad5a728753086fa2f5ad9ff0e49c52ba48adf97a" alt=""
Joined: Jan 18, 2004
Posts: 244
Location: Bristolville, OH
|
Posted:
Wed Jun 30, 2004 4:16 pm |
|
Heres another solution www.apache.org
EDIT: The apache 2.xx just had a DoS hole that was patched i herd. |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
xfsunolesphp
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Wed Jun 30, 2004 4:24 pm |
|
use redirect, if any1 try to expolit straight to Microsoft. |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
sixonetonoffun
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Wed Jun 30, 2004 8:13 pm |
|
This is fast and kills 2 like birds I know the TRACE is an old exploit but worth inclusion. I think CURL and LADP might use the SEARCH method but thats got to be about it for legitimate uses of it.
RewriteEngine On
RewriteCond %{REQUEST_METHOD} ^TRACE [NC]
RewriteCond %{REQUEST_METHOD} ^SEARCH [NC]
RewriteRule ^.* - [F,L] |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
xfsunolesphp
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Wed Jun 30, 2004 8:21 pm |
|
is there use Redirect in there to point microsoft.com data:image/s3,"s3://crabby-images/eec77/eec7756b745c11a099ff95311a373e729592d673" alt="Laughing" |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
sixonetonoffun
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Wed Jun 30, 2004 8:44 pm |
|
ROFLMAO! No
Change the rewrite rule to
RewriteRule ^.*$ /www.microsoft.com [L]
But don't tell em I had anything to do with it! data:image/s3,"s3://crabby-images/2ebaf/2ebaf51ed440fad0d1a495ea7193c187c8070851" alt="Bang Head" |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
xfsunolesphp
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Wed Jun 30, 2004 8:51 pm |
|
nobody knows it there, do you love it? data:image/s3,"s3://crabby-images/69f4a/69f4a310de8d6f237777787d4925d235705d036c" alt="Wink" |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
Raven
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Wed Jun 30, 2004 8:53 pm |
|
Except that you keep advertizing it data:image/s3,"s3://crabby-images/0d676/0d676fb74f9b7af22cbe7131f0583e2c3b86d95f" alt="Rolling Eyes" |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
sixonetonoffun
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Fri Jul 02, 2004 10:36 am |
|
Hate to bump this thread but I was thinking about this and I think I came up with the simplest solution for Apache users. This should get rid of the huge entries in the Apache logs caused by this WebDav exploit attempt.
Just add this to the htaccess file:
<LimitExcept GET PUT POST>
Require valid-user
</LimitExcept>
or
<LimitExcept GET PUT POST>
deny from all
</LimitExcept>
Which should disallow all request methods except GET PUT POST. My testing with HEAD and TRACE seemed less successful so I'm thinking they are excluded from the LimitExcept directive by default possibly?
This is just a little twist on the Limit clause many of us use.
<Limit GET PUT POST>
Order Allow,Deny
Allow from all
</Limit> |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
stephen2417
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Fri Jul 02, 2004 5:19 pm |
|
Ok YIKES... Im freakin out now, i frogot to do this last night and i wake up to find someone tried it 9 times on me!!!
Same IP and the weirdest thing the IP is comming from the same ISP i have and the same server that my IP comes out of... This could be someone down my freakn road attacking me!!!!!
Im just a little annoyed thats all!!!!!!!!!
Should i report their IP to my ISP? |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
Muffin
Client
data:image/s3,"s3://crabby-images/ac268/ac2683e690d3234614f69cc452b80bc9205f2b14" alt=""
Joined: Apr 10, 2004
Posts: 649
Location: UK
|
Posted:
Fri Jul 02, 2004 5:30 pm |
|
You sure it's not you? rofl |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
stephen2417
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Fri Jul 02, 2004 5:33 pm |
|
No i checked that
And just got attacked with this..
Code:
69.136.173.232 - - [02/Jul/2004:18:04:19 -0400] "GET /default.ida?
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%
ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%
u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a HTTP/1.0"
404 205
|
All im tryin to do is run a lil website out of my house and i get attacked! |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
xfsunolesphp
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Fri Jul 02, 2004 5:36 pm |
|
it appear 404 mean File Not found. |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
Raven
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Fri Jul 02, 2004 5:39 pm |
|
That is ida which only affected microsoft servers and is about 3 years old. Hardly think you have to worry. Look up ida on google. |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
xfsunolesphp
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Fri Jul 02, 2004 5:40 pm |
|
why people use IIS Expolit in apache server? data:image/s3,"s3://crabby-images/2ebaf/2ebaf51ed440fad0d1a495ea7193c187c8070851" alt="Bang Head" |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
stephen2417
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Fri Jul 02, 2004 5:40 pm |
|
Im soo glad i like Apache!!! |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
stephen2417
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Mon Jul 05, 2004 9:51 pm |
|
Six, How can we tell that this is getting forwarded to MS by looking at the logs.
BC i got attacked a lot today and just wanted to make sure its working right. |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
sixonetonoffun
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Mon Jul 05, 2004 10:16 pm |
|
Hmn, good question. I don't know of a browser that lets you change the request method to Search. Sam Spade lets you use delete,options,get,trace and head I think. |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
stephen2417
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Tue Jul 06, 2004 12:54 am |
|
Im sure theres some kinda nasty firefox extension that can do the job.. Ill look arround.. Hell someone made a proxy switcher data:image/s3,"s3://crabby-images/d261e/d261efa8eec0508334d6bb51f845da2ced36a38e" alt="Twisted Evil" |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
stephen2417
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Wed Jul 07, 2004 6:07 am |
|
Ok im just a bit scared.. I keep getting attacked by local IP addresses. So far all comming from Ohio, and near by!!!! Oh and their all comming from Earthlink, that would be my ISP!!!!!!!!!!!!
I don think i need to call the cops yet, yet that is. Maybe i need a body gaurd or something data:image/s3,"s3://crabby-images/b5eb3/b5eb38a0cfb6ac70b3230d33b0fa7ffd5675828c" alt="Mr. Green" |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
sixonetonoffun
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Wed Jul 07, 2004 8:47 am |
|
If its like the other IDA there are probably just a bunch of nimda infected IIS servers in your IP range. Not much ya can do about it really. Just make sure your patched up to date. |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
|