Re: WebDav Worm?

From: Frank Knobbe (frank_at_knobbe.us)
Date: 02/14/04

  • Next message: Dennis Opacki: "Re: Something new? bind dos? exploit?"
    To: "Keith T. Morgan" <keith.morgan@terradon.com>
    Date: Fri, 13 Feb 2004 19:22:14 -0600
    
    
    

    On Fri, 2004-02-13 at 09:40, Keith T. Morgan wrote:
    > Maybe this is old news, or maybe it's scanning pattern is just now
    > making it to my netblocks, but we're seeing a massive increase in http
    > connections asking for SEARCH
    > [...]
    > Has anyone else been seeing this type of activity increasing? We've
    > been seeing so much of it that I have to wonder if it's a worm.

    Heh... I asked this too on DShield, but no one cared to respond.

    We've seen the same thing, started on Monday I believe, and at first I
    thought it was a script kiddie (or just a script) probing for various
    offsets/length of NOP sleds, perhaps a universal Swiss-Army exploit
    script. But the activity levels increased to that of a worm. It appears,
    as mentioned, that it is Nachi.B.

    The interesting thing is that of those 20-some packets, a lot of them do
    not have shellcode included, just sleds of varying length. Seems like
    the code for the WebDAV exploit is broken. Thank God for small favors...
    However, it's a noisy bugger. It's approaching the level of pollution of
    the SQL Slammer. Unfortunately this one can not be filtered on ISP
    routers. Looks like we have to learn to live with an increasing level of
    bandwidth wasted on noise like this.

    Cheers,
    Frank

    
    



  • Next message: Dennis Opacki: "Re: Something new? bind dos? exploit?"

    Relevant Pages

    • Re: ssd attacks; worm? and precautionary steps
      ... The script comes with a database ... > or list of usernames and passwords. ... It didn't get very far is it only got into a users account ... The worm tried to see if it had root privileges and when it didn't it ...
      (comp.os.linux.security)
    • Re: [Full-Disclosure] DCOM Worm/scanner/autorooter !!!
      ... i looked at the code and it is NOT a worm. ... It can be deployed on several computers very fast, ... it doesn't have the ability self replicate itself from ... The script contains the hostname, ...
      (Full-Disclosure)
    • Re: [SLE] Advise on Worm/Phishing Emais
      ... I'd like some advise on how to handle worm and phishing emails coming to ... and the method to tell when a phish is a phish ... with a script run, in email, or web, but that's harder with all the ...
      (SuSE)
    • Re: ssd attacks; worm? and precautionary steps
      ... > force script that implements such an attack, but I wonder if the actual ... no response regarding the identity of the worm or script, ... Look like the ssh attacks are pretty common but no one has ...
      (comp.os.linux.security)