RE: WebDav Worm?
From: Henderson, Dennis K. (Dennis.Henderson_at_umb.com)
Date: 02/17/04
- Previous message: Jeffrey Monahan: "Re: Something new? bind dos? exploit?"
- Maybe in reply to: Keith T. Morgan: "WebDav Worm?"
- Next in thread: Keith T. Morgan: "RE: WebDav Worm?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Tue, 17 Feb 2004 07:52:35 -0600 To: "Frank Knobbe" <frank@knobbe.us>, "Keith T. Morgan" <keith.morgan@terradon.com>
I'm finding that not all servers are getting hit with the entire exploit attempt. Only those servers that give back "411 Length required" responses are getting the full hit from the infected host. The non-windows web servers are not getting hit at all as they give back a 500 series denied.
Perhaps urlscan could calm down the noise by keeping the infected host from sending the complete exploit by denying the SEARCH command.
Dennis
On Fri, 2004-02-13 at 09:40, Keith T. Morgan wrote:
> Maybe this is old news, or maybe it's scanning pattern is just now
> making it to my netblocks, but we're seeing a massive increase in http
> connections asking for SEARCH
> [...]
> Has anyone else been seeing this type of activity increasing? We've
> been seeing so much of it that I have to wonder if it's a worm.
Heh... I asked this too on DShield, but no one cared to respond.
We've seen the same thing, started on Monday I believe, and at first I
thought it was a script kiddie (or just a script) probing for various
offsets/length of NOP sleds, perhaps a universal Swiss-Army exploit
script. But the activity levels increased to that of a worm. It appears,
as mentioned, that it is Nachi.B.
The interesting thing is that of those 20-some packets, a lot of them do
not have shellcode included, just sleds of varying length. Seems like
the code for the WebDAV exploit is broken. Thank God for small favors...
However, it's a noisy bugger. It's approaching the level of pollution of
the SQL Slammer. Unfortunately this one can not be filtered on ISP
routers. Looks like we have to learn to live with an increasing level of
bandwidth wasted on noise like this.
Cheers,
Frank
_____
<< This is a digitally signed message part >>
-----Original Message-----
From: Frank Knobbe [mailto:frank@knobbe.us]
Sent: Fri 2/13/2004 7:22 PM
To: Keith T. Morgan
Cc: incidents@securityfocus.com
Subject: Re: WebDav Worm?
- Previous message: Jeffrey Monahan: "Re: Something new? bind dos? exploit?"
- Maybe in reply to: Keith T. Morgan: "WebDav Worm?"
- Next in thread: Keith T. Morgan: "RE: WebDav Worm?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|