IWETHEY v. 0.3.0 | TODO
1,095 registered users | 0 active users | 0 LpH | Statistics
Login | Create New User
IWETHEY Banner

Welcome to IWETHEY!

New Initial thoughts
1. it's some kind of buffer overflow exploit.
2. That doesn't fly with me, because the majority of it (i.e. the stuff that'd get left on the stack) is 0x9, over and over again.
3. Someone's web browser/spider/wget/curl/thing broke and broke hard.
4. I'm making it up now. I don't really have a clue.


Peter
[link|http://www.debian.org|Shill For Hire]
[link|http://www.kuro5hin.org|There is no K5 Cabal]
[link|http://guildenstern.dyndns.org|Blog]
New Not 0x9 by x90 not that is should matter
then ended with

414 351 "-" "-"

New I get those about every 10 minutes at my default webserver
www.gregfolkert.net gets at least 6 of those an hour. Typically.

I took a look, it is the more recent IIS or MSSQL Worm variants... or still another one of the old ones. And yes, it is trying to over-flow the folder traversal thinger or some such crap.

Funny, it just falls off apache like water off a ducks back.
--
[link|mailto:greg@gregfolkert.net|greg],
[link|http://www.iwethey.org/ed_curry|REMEMBER ED CURRY!] @ iwethey

Give a man a match, he'll be warm for a minute.
Set him on fire, he'll be warm for the rest of his life!
     WTF is this? - (pwhysall) - (4)
         Counts - (jbrabeck) - (3)
             Initial thoughts - (pwhysall) - (2)
                 Not 0x9 by x90 not that is should matter - (jbrabeck)
                 I get those about every 10 minutes at my default webserver - (folkert)

Oh, freddled gruntbuggly! Thy micturations are unto me!
34 ms