Date: Wed, 19 Sep 2001 16:59:14 +0400 From: "Vladimir B. Grebenschikov" <vova@express.ru> To: "Karsten W. Rohrbach" <karsten@rohrbach.de> Cc: "Gib Gilbertson Jr." <gib@tmisnet.com>, freebsd-security@FreeBSD.ORG Subject: Re: NIMDA Virus Message-ID: <15272.38562.675553.16495@vbook.express.ru> In-Reply-To: <20010919131752.E52106@mail.webmonster.de> References: <F143IQrttDRdNOUivlQ00013ed8@hotmail.com> <5.1.0.14.2.20010918232719.00a6ba90@pop3.norton.antivirus> <20010919131752.E52106@mail.webmonster.de>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --]
Karsten W. Rohrbach writes:
> Gib Gilbertson Jr.(gib@tmisnet.com)@2001.09.18 23:30:04 +0000:
> > Hi All.
> >
> > You might want to check your httpd logs... I checked mine and in less than
> > 22 hours they had grown from 0 bytes at log archive time to over 600 meg....
> >
> > Just a heads up.. Accesses are coming in so fast that the log is a blur
> > going by..
>
> quick 'fix' for excessive error_log size:
>
> ErrorLog "|exec grep -v 'File does not exist:' >/wherever/error_log"
>
> this will not log any more 404 throwing file not found errors
Quick fix for it using very simple netgraph module in attached tarball
[-- Attachment #2 --]
:; ksHr¯8u{~Ď}Q@"Y%KhI% ;o6]LwϴY2p纱${hx(;VT^w pP|bV jGAe]G/dlj|wڏ=5?{/Vm=Y(8E~_T꽃<=c82MӧSb2ӿW$I ɘ0N;Ap3Fv~f,`wv~r<f4N"@Ii%c/8&4||G Nhkp%c"\5'0\o9)#&CȢ$̅{XQp`ܱ[iȑXEI?ݹ#pfgBQg:#lq p}rݬiv&=z/C;H-F"@}qid<2TG*Bf!lhkwbYhFE%^0
͘ "R0;83;8*y)#ҵX֥ك^w
}W{a45|@i@jf]N;zqAdVOѶLmуvPurd-iyٺjFC)zAH:]oӺ-hGN_7)5ѭ_blֵ&Α eMWUgh]..6Z(.ࢯC"ހ~@$zD~"A2\K?-LmLw]΅D^&=7M"Af(E`'.I[}g ?@CoFOHG4N]Gd:d3b,4Wc7LQM
zWFݤ/O{ro-(>@Ȕu6
[x,[\t:
Z\FY'fݧ-p#\[8zDb:7F7]N/,B %ImY`4:]m\4]7VL[\?ש)+3B |"@X$$&8=SHRe"sz|gcdp^}pl5tCG^4! COb:4b)+~Q
[Co`H#&1;r臨ͼޕ"b7̏7 n
%RoeT-G3!4½ЎYy|֍
,aE>>a
7a܇lgay ~cn6C]Y/>㭳z+8&',LVxWdAAN>,<?-]$ɂXȻuFr9':˒:cKO`4Pg,!s"v-
3 a0t(v0shQ9 ywfB%Ÿ|D-E 9Yv(+OьLRdd wh4z
3hw2hlǚnV:䃔} bo|Z+琅ۆuկ.&B
"ZD_L]J5,3j_ 3ϰG*Z,|6T)TN)D^HA4AkJ¿w>U$CXLS \.b<`;-E7XdI!9B#){\2'MoEZad-'VqB{>W+4;a@Fw+R8" S.d6R'Є۸9|{Ƹ=E'j~pނT{gh+aTj̧rU$CMaPf?D %SK# &-s]0|Б3<
"0a3<Ǒ#;tu/3KO6a+*7NBI uxG?
sT1{sAvŚ܃S)w ;{{Q$ecGިq}gHZXS:/fBc&^98␞p}W~6xG}v
0]siT.\t(H~ˤУA, \`>*x8ƙ=_Rr.%/ 'Cf.L4f)iwyI0d/o^Xarş1dN0C?RBPI ]4c3֤]7Έ$UBUN;lXQj
unH
bi
KUvoߓ]9X=A$}!mӱz)&M( }w7
l_sMo2JP] !cB?{{<t^|¯t;H"pu=cHJP~9Aȏz<u(W86PB p. bǧc)_?"gˆu_KFJ1ڣ~;5}8dn G_}sϲ'DFlXXMhƣ9uuI>eW3ߤ%@m~g\?G"DQRzgtLCci`G߮
`PLSHIjj.7WN}ۘ3K%p&2.Ʉ@LxbL̒H,%$Oat92.|?UTv/vhY^7>U2GʆyUJ|x"#FAQ`8\.ʲUO$vO#O<m?8r4k1]߈H"nL \6+g摠C'4AjQĐ"q%c<ԎD)bC@INTd<W죇(S:bs0%qq%ADeUTeNUTeNUTeNUTeNUTeNUTeNUTeNUTeoT|75pX;:\wp_mTOTOTO
}*:,۴A(m*GpfnNX6_v)Nw:?FueR}u!o!/91iG`p"ArPGdgMߓ?8<:>xo_Ug?_*WzO%&
|OaE~OదJv/y.Z0UYs?}#V__
x<d㊄|J^i/a>jmIJs91Xԙ훏`t{ AZPԻWIfԇ.k6_heM6Tk:9:>hv4BB#Sf-on뛫`:?X/F9x3K!e_qvv;1s+$>6a$ 4W;mOX/Q
h֎iϟx^<l&ы#1#KZ~tka>W
\J%XMjD03I/<d
!00M!Xw>ݧ3xY>}n?i=!C~8qx,-:␔7f4;`FWgπ#6O&(('Iν3vhOAG-8|ҿMSnS8bO?1_FT,RN=r l!a(W^\5TSM5TSM5TSM5TSM5TSM5TSM5TS˵ x
[-- Attachment #3 --]
#!/bin/sh
#
# create netgraph nodes
# bind on 77 divert port
#
# <input(div:77)>--in<ddsdetect>out--<output(div)>
# detect
#
ngctl -f - << EOF
mkpeer ddsdetect dummy detect
name .:dummy dds
mkpeer dds: ksocket in inet/raw/divert
msg dds:in bind inet/0.0.0.0:77
mkpeer dds: ksocket out inet/raw/divert
EOF
# check only incoming packets !!!
# be careful we can't check outgoing packets -
# it will lead to packets cycle and panic
ipfw add 1 divert 77 tcp from any to any 80 in
# if anybody interested we can analyze detected DDS pakets
nghook -a dds: detect
# after all shutdown netgraph nodes
ngctl shutdown dds:
> /k
--
TSB Russian Express, Moscow
Vladimir B. Grebenschikov, vova@express.ru
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?15272.38562.675553.16495>
