LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-02-2003, 07:33 AM   #1
Donald1000
Member
 
Registered: Oct 2002
Location: Germany
Distribution: Debian, Non-Linux: Solaris, FreeBSD
Posts: 107

Rep: Reputation: 15
Strange connection!?


If got strange connections in my access_log from the Apache Webserver.
Does anyone know, what it is?

-------------schnipp---------------
80.13.38.X - - [02/Jan/2003:10:10:47 +0100] "\xe3;" 501 - "-" "-"
217.232.150.X - - [02/Jan/2003:10:10:47 +0100] "\xe3K" 501 - "-" "-"
217.187.193.X - - [02/Jan/2003:10:10:52 +0100] "\xe3G" 501 - "-" "-"
217.82.31.X - - [02/Jan/2003:10:10:53 +0100] "\xe3I" 501 - "-" "-"
80.130.124.X - - [02/Jan/2003:10:10:57 +0100] "\xe3@" 501 - "-" "-"
217.230.235.X - - [02/Jan/2003:10:11:07 +0100] "\xe3P" 501 - "-" "-"
217.187.193.X - - [02/Jan/2003:10:11:33 +0100] "\xe3G" 501 - "-" "-"
217.82.31.X - - [02/Jan/2003:10:11:36 +0100] "\xe3I" 501 - "-" "-"
80.130.124.X - - [02/Jan/2003:10:11:38 +0100] "\xe3@" 501 - "-" "-"
217.230.235.X - - [02/Jan/2003:10:11:48 +0100] "\xe3P" 501 - "-" "-"
217.187.193.X - - [02/Jan/2003:10:12:18 +0100] "\xe3G" 501 - "-" "-"
80.130.124.X - - [02/Jan/2003:10:12:24 +0100] "\xe3@" 501 - "-" "-"
217.230.235.X - - [02/Jan/2003:10:12:33 +0100] "\xe3P" 501 - "-" "-"
212.41.70.X - - [02/Jan/2003:10:12:57 +0100] "\xe3O" 501 - "-" "-"
212.144.228.X - - [02/Jan/2003:10:12:58 +0100] "\xe3B" 501 - "-" "-"
212.41.70.X - - [02/Jan/2003:10:13:40 +0100] "\xe3O" 501 - "-" "-"
212.41.70.X - - [02/Jan/2003:10:14:25 +0100] "\xe3O" 501 - "-" "-"
------------------schnapp------------------


Thanks!

Last edited by Donald1000; 01-02-2003 at 05:40 PM.
 
Old 01-03-2003, 03:55 PM   #2
rioguia
Member
 
Registered: Jun 2002
Posts: 411

Rep: Reputation: 30
just a wild shot

just a wild shot from a google search. there is a lot of irrelevant text in the post but if you do a text search for xe3 ou will find references to code blue and
Quote:
this is an exploit that doesnt work. it should be enough of a point in
* the right direction though. the overflow is in get_smtp_reply(), codeblue.c
* is pretty damn poor, there are more!!!
http://archives.neohapsis.com/archiv...2-q3/0037.html

other related references?
http://216.239.37.100/search?q=cache...hl=en&ie=UTF-8
 
Old 01-04-2003, 09:08 PM   #3
tarballedtux
Member
 
Registered: Aug 2001
Location: Off the coast of Madadascar
Posts: 498

Rep: Reputation: 30
Just be glad you run Apache and not II-DEATH
 
Old 01-20-2003, 11:11 AM   #4
Donald1000
Member
 
Registered: Oct 2002
Location: Germany
Distribution: Debian, Non-Linux: Solaris, FreeBSD
Posts: 107

Original Poster
Rep: Reputation: 15
For all, that are interested in: This are connections from clients, that use the peer to peer Software eDonkey. If anybody else have those connections, this is no Worm, Virus or Dos Attack. (Have a look at the eDonkey Protocol)

Greetings
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
FTP connection problems. Strange. Brian Knoblauch Linux - Networking 3 10-13-2005 09:56 AM
Strange Internet connection problem vmp Linux - Networking 2 07-21-2003 07:29 AM
Connection Lost VERY STRANGE Xin(tEb Linux - Networking 0 07-18-2003 07:04 AM
Strange connection error! DarkSTech Linux - Networking 2 03-05-2003 03:57 AM
strange connection problem jamaso Slackware 4 05-08-2002 09:56 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:15 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration