LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Security (https://www.linuxquestions.org/questions/linux-security-4/)
-   -   Strange connection!? (https://www.linuxquestions.org/questions/linux-security-4/strange-connection-40069/)

Donald1000 01-02-2003 07:33 AM

Strange connection!?
 
If got strange connections in my access_log from the Apache Webserver.
Does anyone know, what it is?

-------------schnipp---------------
80.13.38.X - - [02/Jan/2003:10:10:47 +0100] "\xe3;" 501 - "-" "-"
217.232.150.X - - [02/Jan/2003:10:10:47 +0100] "\xe3K" 501 - "-" "-"
217.187.193.X - - [02/Jan/2003:10:10:52 +0100] "\xe3G" 501 - "-" "-"
217.82.31.X - - [02/Jan/2003:10:10:53 +0100] "\xe3I" 501 - "-" "-"
80.130.124.X - - [02/Jan/2003:10:10:57 +0100] "\xe3@" 501 - "-" "-"
217.230.235.X - - [02/Jan/2003:10:11:07 +0100] "\xe3P" 501 - "-" "-"
217.187.193.X - - [02/Jan/2003:10:11:33 +0100] "\xe3G" 501 - "-" "-"
217.82.31.X - - [02/Jan/2003:10:11:36 +0100] "\xe3I" 501 - "-" "-"
80.130.124.X - - [02/Jan/2003:10:11:38 +0100] "\xe3@" 501 - "-" "-"
217.230.235.X - - [02/Jan/2003:10:11:48 +0100] "\xe3P" 501 - "-" "-"
217.187.193.X - - [02/Jan/2003:10:12:18 +0100] "\xe3G" 501 - "-" "-"
80.130.124.X - - [02/Jan/2003:10:12:24 +0100] "\xe3@" 501 - "-" "-"
217.230.235.X - - [02/Jan/2003:10:12:33 +0100] "\xe3P" 501 - "-" "-"
212.41.70.X - - [02/Jan/2003:10:12:57 +0100] "\xe3O" 501 - "-" "-"
212.144.228.X - - [02/Jan/2003:10:12:58 +0100] "\xe3B" 501 - "-" "-"
212.41.70.X - - [02/Jan/2003:10:13:40 +0100] "\xe3O" 501 - "-" "-"
212.41.70.X - - [02/Jan/2003:10:14:25 +0100] "\xe3O" 501 - "-" "-"
------------------schnapp------------------


Thanks!

rioguia 01-03-2003 03:55 PM

just a wild shot
 
just a wild shot from a google search. there is a lot of irrelevant text in the post but if you do a text search for xe3 ou will find references to code blue and
Quote:

this is an exploit that doesnt work. it should be enough of a point in
* the right direction though. the overflow is in get_smtp_reply(), codeblue.c
* is pretty damn poor, there are more!!!
http://archives.neohapsis.com/archiv...2-q3/0037.html

other related references?
http://216.239.37.100/search?q=cache...hl=en&ie=UTF-8

tarballedtux 01-04-2003 09:08 PM

Just be glad you run Apache and not II-DEATH

Donald1000 01-20-2003 11:11 AM

For all, that are interested in: This are connections from clients, that use the peer to peer Software eDonkey. If anybody else have those connections, this is no Worm, Virus or Dos Attack. ;) (Have a look at the eDonkey Protocol)

Greetings


All times are GMT -5. The time now is 06:47 PM.