Re: [security-elvandar] "access_log?hello" ?

From: Salvatore Poliandro (jello_at_vanished.net)
Date: 07/28/03

  • Next message: tEA-TiME: "Re: Exploit for Windows RPC may be in the wild!"
    To: "Remko Lodder" <remko@elvandar.org>, "Christine Kronberg" <Christine_Kronberg@genua.de>
    Date: Sun, 27 Jul 2003 18:08:22 -0400
    
    

    -- OM--
    From: "Remko Lodder" <remko@elvandar.org>
    Subject: Re: [security-elvandar] "access_log?hello" ?
    > I dont recognise this as a particular script that is running against
    > your host.
    > Although it could be a custom made script that just sends a lot of
    > characters (or a lot of hello's)
    > to your host, trying to overflow it.
    >
    > My best guess is that it's the overflow option,
    > But i am interested now.. so when anyone else has a opinion...

    An Overflow to accomplish what? I see no shellcode in that string, Other
    then crashing the web server on the other end, what could be its use? Could
    It be a tool to look in the log files of webservers for previous
    compromises? http://www.analog.cx/ creates the product that makes the logs
    in the /logs/active/ I see no mention of any compromises in thier site.

    Sal

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: tEA-TiME: "Re: Exploit for Windows RPC may be in the wild!"

    Relevant Pages

    • Re: [security-elvandar] "access_log?hello" ?
      ... I dont recognise this as a particular script that is running against ... to your host, trying to overflow it. ... My best guess is that it's the overflow option, ... Has anyone else this kind of requests? ...
      (Incidents)
    • Re: [security-elvandar] "access_log?hello" ?
      ... It could be an overflow attack to the access_log script which he/she ... With that he might get access to some logging OR access to the webserver ... >in the /logs/active/ I see no mention of any compromises in thier site. ...
      (Incidents)
    • Re: internet proxy
      ... Is it possible to create separate shortcuts to IE - one with 'proxy server ... This script gets used when you enable the "Automatically ... connect to the host so no proxy would get used. ...
      (microsoft.public.windowsxp.general)
    • Re: How do I insert a cgi script into Publisher page?
      ... is not where I host my website. ... If your ISP supports cgi and has a form handling program then a form ... You must tell the server what e mail address you want the form results ... any where else you so desire or an auto redirect script with a delay. ...
      (microsoft.public.publisher.webdesign)
    • Re: SAFE MODE,fopen, and chmod
      ... The files going into the users/ folder are created by the "apache" user. ... I have a free php hosting account with an account name 'sample'. ... The host is "running in SAFE MODE", where, it seems that for fopen, mkdir and many other functions, a check is done for the UID of the script-running process to be the same as the UID of each resource concernedand only if the UIDs match, is the function allowed to work successfully. ... The same script has in the prior lines created the directory ...
      (comp.lang.php)