Snort mailing list archives

Re: New worm going 'round? (fwd)


From: Gordon Ewasiuk <gewasiuk () gnmc net>
Date: Tue, 18 Sep 2001 11:23:17 -0400 (EDT)


From a poster on inet-access...

-G

---------- Forwarded message ----------
Date: Tue, 18 Sep 2001 15:42:48 +0100
Reply-To: list () inet-access net
To: list () inet-access net
Subject: Re: New worm going 'round?

If I tail -f httpd-error.log these errors are going by faster than I can
read! omg!

Same here, the signature requests appear to be

GET /MSADC/root.exe?/c+dir HTTP/1.0
GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0
[...]

Looking more and more like code blue.

http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fsection%3Dexploit%26vid%3D1806



_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: