Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 19 Sep 2001 16:59:14 +0400
From:      "Vladimir B. Grebenschikov" <vova@express.ru>
To:        "Karsten W. Rohrbach" <karsten@rohrbach.de>
Cc:        "Gib Gilbertson Jr." <gib@tmisnet.com>, freebsd-security@FreeBSD.ORG
Subject:   Re: NIMDA Virus
Message-ID:  <15272.38562.675553.16495@vbook.express.ru>
In-Reply-To: <20010919131752.E52106@mail.webmonster.de>
References:  <F143IQrttDRdNOUivlQ00013ed8@hotmail.com> <5.1.0.14.2.20010918232719.00a6ba90@pop3.norton.antivirus> <20010919131752.E52106@mail.webmonster.de>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
Karsten W. Rohrbach writes:
 > Gib Gilbertson Jr.(gib@tmisnet.com)@2001.09.18 23:30:04 +0000:
 > > Hi All.
 > > 
 > > You might want to check your httpd logs... I checked mine and in less than 
 > > 22 hours they had grown from 0 bytes at log archive time to over 600 meg....
 > > 
 > > Just a heads up.. Accesses are coming in so fast that the log is a blur 
 > > going by..
 > 
 > quick 'fix' for excessive error_log size:
 > 
 > ErrorLog "|exec grep -v 'File does not exist:' >/wherever/error_log"
 > 
 > this will not log any more 404 throwing file not found errors
 
Quick fix for it using very simple netgraph module in attached tarball


[-- Attachment #2 --]
:;ksHr¯8u{~Ď}Q@"Y%KhI%	;o6]LwϴY2p纱${hx(;VT^wpP|bVjGAe]G/dlj|wڏ=5?{/Vm=Y(8E~_T꽃<=c82MӧSb2ӿW$Iɘ0N;Ap3Fv~f,`wv~r<f4N"@Ii%c/8&4||GNhkp%c"\5'0\o9)#&CȢ$̅{XQp`ܱ[iȑXEI?ݹ#pfgBQg:#l؜q p}rݬiv&=z/C;H-F"@}qid<2TG*Bf!lhkwbYhFE%^0
͘ "R0;83;8*y)#ҵX֥ك^w
}W{a45|@i@jf]N;zqAdVOѶLmуvPurd-iyٺjFC)zAH:]oӺ-hGN_7)5ѭ_blֵ&Α	eMWUgh]..6Z(.ࢯC"ހ~@$zD~"A2\K?-LmLw]΅D^&=7M"Af(E`'.I[}g?@CoFOHG4N]Gd:d3b,4Wc7LQM
zWFݤ/O{ro-(>@Ȕu6
[x,[\t:
Z\FY'fݧ-p#\[8zDb:7F7]N/,B %ImY`4:]m\4]7VL[\?ש)+3B|"@X$$&8=SHRe"sz|gcdp^}pl5tCG^4!	COb:4b)+~Q
[Co`H#&1;r臨ͼޕ"b7̏7	n
%RoeT-G3!4½ЎYy|֍
,aE>>a
7a܇lgay	~cn6C]Y/>㭳z+8&',LVxWdAAN>,<?-]$ɂXȻuFr9':˒:cKO`4Pg,!s"v-
3	a0t(v0shQ9ywfB%Ÿ|D-E 9Yv(+OьLRddwh4z
€3hw2hlǚnV:䃔}	bo|Z+琅ۆuկ.&B
"ZD_L]J5,3j_ 3ϰG*Z,|6T)TN)D^HA4‹AkJ¿w>U$CXLS \.b<`;-E7XdI!9B#){\2'MoEZad-'VqB{>W+4;a@Fw+R8" S.d6R'Є۸9|{Ƹ=E'j~pނT{gh+aTj̧rU$CMaPf?D %SK# &‘-s]0|Б3<
"0a3<Ǒ#;tu/3KO6a+*7NBIuxG?
sT1{sAvŚ܃S)w;{{Q$ecGިq}gHZXS:/fBc&^98␞p}W~6xG}v
0]siT.\t(H~ˤУA,	\`>*x8ƙ=_Rr.%/	'Cf.L4f)iwyI0d/o^Xarş1dN0C?RBPI]4c3֤]7Έ$UBUN;lXQj
unH
bi
KUvoߓ]9X=A$}!mӱz)&M(	}w7
l_sMo2JP]!cB?{{<t^|¯t;H"pu=cHJP~9Aȏz<u(W86PBp. bǧc)_?"gˆu_KFJ1ڣ~;5}8dn	G_}sϲ'DFlXXMhƣ9uuI>eW3ߤ%@m~g\?G"DQRzgtLCci`G߮
`PLSHIjj.7WN}ۘ3K%p&2.Ʉ@LxbL̒H,%$Oat92޷.|?UTv/vhY^7>U2GʆyUJ|x"#FAQ`8\.ʲUO$vO#O<m?8r4k1]߈H"nL	\6+g摠C'4AjQĐ"q%c<ԎD)bC@INTd<W죇(S:bs0%qq%ADeUTeNUTeNUTeNUTeNUTeNUTeNUTeNUTeoT|75pX;:\wp_mTOTOTO
}*:,۴A(m*GpfnNX6_v)Nw:?FueR}u!o!/91iG`p"ArPGdgMߓ?8<:>xo_Ug?_*WzO%&
|OaE~OదJv/y.Z0UYs?}#V__
x<d㊄|J^i/a>jmIJs91Xԙ훏`t{ AZPԻWIfԇ.k6_heM6Tk:9:>hv4BB#Sf-on뛫`:?X/F9x3K!e_qvv;1s+$>6a$	4W;mOX/Q
h֎iϟx^<l&ы#1#KZ~tka>W
\J%XMjD03I/<d
!00M!Xw>ݧ3xY>}n?i=!C~8qx,-:␔7f4;`FWgπ#6O&(('Iν3vhOAG-8|ҿ񪂼MSnS8bO?1_FT,RN=rl!a(W^\5TSM5TSM5TSM5TSM5TSM5TSM5TS˵x
[-- Attachment #3 --]

#!/bin/sh

#
# create netgraph nodes
# bind on 77 divert port
#
#  <input(div:77)>--in<ddsdetect>out--<output(div)>
#                       detect
#
ngctl -f - << EOF
mkpeer ddsdetect dummy detect
name .:dummy dds
mkpeer dds: ksocket in inet/raw/divert
msg dds:in bind inet/0.0.0.0:77
mkpeer dds: ksocket out inet/raw/divert
EOF

# check only incoming packets !!! 
# be careful we can't check outgoing packets - 
# it will lead to packets cycle and panic
ipfw add 1 divert 77 tcp from any to any 80 in

# if anybody interested we can analyze detected DDS pakets
nghook -a dds: detect

# after all shutdown netgraph nodes
ngctl shutdown dds:


 
 > /k

--
TSB Russian Express, Moscow
Vladimir B. Grebenschikov, vova@express.ru

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?15272.38562.675553.16495>