Date: Wed, 31 Mar 2004 11:37:22 -0500 From: "Nick" <nick_fbsd@cogeco.ca> To: <freebsd-questions@freebsd.org> Subject: RE: Very long URL with malice intended Message-ID: <20040331163718.72FAC2036@fep2.cogeco.net> In-Reply-To: <20040331150847.GA3376@sting.grogsworld.org>
next in thread | previous in thread | raw e-mail | index | archive | help
> -----Original Message----- > From: owner-freebsd-questions@freebsd.org [mailto:owner-freebsd- > questions@freebsd.org] On Behalf Of GROG! (Jeff Howie) > Sent: Wednesday, March 31, 2004 10:09 AM > To: freebsd-questions@freebsd.org > Subject: Re: Very long URL with malice intended > > On Sat, 27 Mar 2004 15:50:53 -0600, Jack L. Stone wrote: > >At 08:28 PM 3.27.2004 +0100, Cordula's Web wrote: > >>>Within the past couple of weeks, the Apache logs have shown a new > >>>type of intrusion -- a very, very long URL request... > >>> > >>>My question is what syntax can I add, if any, to my httpd.conf to > >>>redirect such requests..?? > >>> > >>>65.35.186.74 - - [26/Mar/2004:19:01:04 -0600] "SEARCH > >>>/\x90\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\... > >> > >>Are only SEARCH requests affected, or GET as well? > > Hey all. A question from a heretofore unrevealed skulker :^>. Was this > question ever answered off-list? My own box is getting hit quite often > with these & I'm concerned that they might be causing harm. thks > > >The ones I've seen have all been SEARCH.... > > Me too. > > thks > > -- > GROG! MMM Reality is that which, when you stop believing > thks (o o) in it, doesn't go away. -- Philip K. Dick > --ooO-(_)-Ooo-- > _______________________________________________ > freebsd-questions@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-questions > To unsubscribe, send any mail to "freebsd-questions- > unsubscribe@freebsd.org" It is an IIS WebDAV exploit from April 2003 (?), apache is not affected, its just annoying :) (nachi and agobot use this exploit)
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20040331163718.72FAC2036>