LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-26-2003, 09:29 AM   #1
Robert0380
LQ Guru
 
Registered: Apr 2002
Location: Atlanta
Distribution: Gentoo
Posts: 1,280

Rep: Reputation: 47
new stuff in web logs, strange


this looks like some kind of exploit for IIS or whatever but i have a lot of this in my httpd access_log:

Code:
ip.address.was.here - - [25/Sep/2003:15:20:35 -0400] "OPTIONS / HTTP/1.1" 200 - "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
ip.address.was.here- - [25/Sep/2003:15:20:38 -0400] "OPTIONS / HTTP/1.1" 200 - "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
ip.address.was.here - - [25/Sep/2003:15:20:41 -0400] "PROPFIND / HTTP/1.1" 405 244 "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
ip.address.was.here - - [25/Sep/2003:15:22:11 -0400] "OPTIONS / HTTP/1.1" 200 - "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
ip.address.was.here - - [25/Sep/2003:15:22:11 -0400] "OPTIONS / HTTP/1.1" 200 - "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
ip.address.was.here - - [25/Sep/2003:15:22:11 -0400] "PROPFIND / HTTP/1.1" 405 244 "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
ip.address.was.here - - [25/Sep/2003:15:22:12 -0400] "OPTIONS / HTTP/1.1" 200 - "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
ip.address.was.here- - [25/Sep/2003:15:22:12 -0400] "OPTIONS / HTTP/1.1" 200 - "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
ip.address.was.here - - [25/Sep/2003:15:22:12 -0400] "PROPFIND / HTTP/1.1" 405 244 "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
ip.address.was.here - - [25/Sep/2003:15:28:05 -0400] "OPTIONS / HTTP/1.1" 200 - "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
ip.address.was.here - - [25/Sep/2003:15:28:05 -0400] "OPTIONS / HTTP/1.1" 200 - "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
ip.address.was.here - - [25/Sep/2003:15:28:08 -0400] "PROPFIND / HTTP/1.1" 405 244 "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
ip.address.was.here - - [25/Sep/2003:15:43:33 -0400] "OPTIONS / HTTP/1.1" 200 - "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
ip.address.was.here - - [25/Sep/2003:15:43:33 -0400] "OPTIONS / HTTP/1.1" 200 - "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
ip.address.was.here- - [25/Sep/2003:15:43:33 -0400] "PROPFIND / HTTP/1.1" 405 244 "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
ip.address.was.here - - [25/Sep/2003:15:49:39 -0400] "OPTIONS / HTTP/1.1" 200 - "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"

i know it's not hurting my box at all, but because i help to administer this network (tech-support really), i'd like to know what that is so i can take any needed action to clean those systems if need be.
 
Old 09-27-2003, 05:33 AM   #2
phoeniXflame
Member
 
Registered: Feb 2003
Location: Somewhere, UK
Distribution: Slack, OpenBSD, Debian, SuSE
Posts: 189

Rep: Reputation: 30
could be random webdav scans, shouldnt worry too much, my perimeter ids picks up scans like that on a daily basis, I assume performed by script kiddies scanning huge ip blocks for vunerable systems
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
HELP ! very strange apache logs ! qwijibow Linux - Security 2 09-15-2004 10:24 PM
Strange FTP logs dominant Linux - Security 1 08-24-2004 01:46 AM
Strange Apache LOGs... TheIrish Linux - Security 3 02-10-2004 01:15 PM
strange logs NSKL Slackware 2 10-24-2003 05:10 AM
Strange stuff in 2.6.x-tests Oxagast Linux - Software 1 08-03-2003 10:06 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:18 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration