Security Incidents mailing list archives

RE: WebDav Worm?


From: "Henderson, Dennis K." <Dennis.Henderson () umb com>
Date: Tue, 17 Feb 2004 07:52:35 -0600

I'm finding that not all servers are getting hit with the entire exploit attempt. Only those servers that give back 
"411 Length required" responses are getting the full hit from the infected host. The non-windows web servers are not 
getting hit at all as they give back a 500 series denied.
 
Perhaps urlscan could calm down the noise by keeping the infected host from sending the complete exploit by denying the 
SEARCH command.
 
Dennis
 
 
On Fri, 2004-02-13 at 09:40, Keith T. Morgan wrote:
Maybe this is old news, or maybe it's scanning pattern is just now
making it to my netblocks, but we're seeing a massive increase in http
connections asking for SEARCH
[...]
Has anyone else been seeing this type of activity increasing?  We've
been seeing so much of it that I have to wonder if it's a worm.

Heh... I asked this too on DShield, but no one cared to respond.

We've seen the same thing, started on Monday I believe, and at first I
thought it was a script kiddie (or just a script) probing for various
offsets/length of NOP sleds, perhaps a universal Swiss-Army exploit
script. But the activity levels increased to that of a worm. It appears,
as mentioned, that it is Nachi.B.

The interesting thing is that of those 20-some packets, a lot of them do
not have shellcode included, just sleds of varying length. Seems like
the code for the WebDAV exploit is broken. Thank God for small favors...
However, it's a noisy bugger. It's approaching the level of pollution of
the SQL Slammer. Unfortunately this one can not be filtered on ISP
routers. Looks like we have to learn to live with an increasing level of
bandwidth wasted on noise like this.

Cheers,
Frank



  _____  

<< This is a digitally signed message part >> 

        -----Original Message----- 
        From: Frank Knobbe [mailto:frank () knobbe us] 
        Sent: Fri 2/13/2004 7:22 PM 
        To: Keith T. Morgan 
        Cc: incidents () securityfocus com 
        Subject: Re: WebDav Worm?
        
        


Current thread: