Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: [Full-Disclosure] SEARCH web attack |
|---|---|
| Date: | Wed, 31 Mar 2004 14:23:09 -0500 |
Google it: http://www.google.com/search?hl=en&ie=UTF-8&oe=UTF-8&q=SEARCH-%2F%5Cx90%5Cx0 2%C2%B1 This is presumably an attempt to exploit the MS03-007 NTDLL vulnerability via WebDAV. http://archives.neohapsis.com/archives/sf/pentest/2003-03/0109.html http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.jb.h tml http://www.microsoft.com/technet/security/bulletin/MS03-007.mspx Other people have seen the following requests in their web server logs: SEARCH /AAAAAAAAA... or SEARCH /?±±±±±±... -----Original Message----- From: full-disclosure-admin@lists.netsys.com [mailto:full-disclosure-admin@lists.netsys.com] On Behalf Of i.t Consulting Sent: Wednesday, March 31, 2004 1:39 PM To: full-disclosure@lists.netsys.com Subject: [despammed] [Full-Disclosure] SEARCH web attack during March the apache log shows some SEARCH attacks like "SEARCH /\x90\x02±\x02± ... x90\x90" 414 343 "-" "-" see full examples http://thum.ath.cx/Apache/code.414 can someone enlighten me what the wanted result may be? tia
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Full-Disclosure] NOT GOOD: Outlook Express 6 + Internet Explorer 6, Georgi Guninski |
|---|---|
| Next by Date: | Re: [Full-Disclosure] NOT GOOD: Outlook Express 6 + Internet Explorer 6, Valdis . Kletnieks |
| Previous by Thread: | [Full-Disclosure] Re: cdp buffer overflow vulnerability - updated details, Shaun Colley |
| Next by Thread: | [Full-Disclosure] Bugfinder Being Indicted As Criminal ("Counterfeiter") in France, Drew Copley |
| Indexes: | [Date] [Thread] [Top] [All Lists] |