Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member
    Join Date
    Mar 2004
    Posts
    815

    Default Looking for mod_security rule against IIS WebDAV exploit.

    Our servers are being hit with DoS via IIS WebDAV exploit. It runs up the CPU to about 40 until my hogkiller stops apache, etc.

    This is the kind of stuff I see in the apache access_log:


    "SEARCH /\x90\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\" 414 271


    SEARCH /\x90\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\x04H\

    etc. etc. etc.

    I am thinking there must be a mod_security ruleset I can apply against this?

  2. #2
    Member
    Join Date
    Mar 2004
    Posts
    815

    Default

    Okay, I am reading that mod_security will not catch this early enough. So now I am thinking there must be a way to alter the BFD script so that the attacking IP is dropped into the firewall.

    Thoughts/solutions anyone?

  3. #3
    Member
    Join Date
    Mar 2004
    Posts
    815

    Default

    Okay, here apparently is at least one solution (using a redirect) from - http://aplawrence.com/Blog/B1234.html

    Here's the part I just added to httpd.conf, then restarted apache and am hoping for the best:

    # Send MS IIS Exploits to the company who makes them all possible!
    <IfModule mod_rewrite.c>
    RedirectMatch permanent (.*)cmd.exe(.*)$ http://www.microsoft.com
    RedirectMatch permanent (.*)root.exe(.*)$ http://www.microsoft.com
    RedirectMatch permanent (.*)\/_vti_bin\/(.*)$ http://www.microsoft.com
    RedirectMatch permanent (.*)\/scripts\/\.\.(.*)$ http://www.microsoft.com
    RedirectMatch permanent (.*)\/_mem_bin\/(.*)$ http://www.microsoft.com
    RedirectMatch permanent (.*)\/msadc\/(.*)$ http://www.microsoft.com
    RedirectMatch permanent (.*)\/MSADC\/(.*)$ http://www.microsoft.com
    RedirectMatch permanent (.*)\/c\/winnt\/(.*)$ http://www.microsoft.com
    RedirectMatch permanent (.*)\/d\/winnt\/(.*)$ http://www.microsoft.com
    RedirectMatch permanent (.*)\/x90\/(.*)$ http://www.microsoft.com
    RedirectMatch permanent (.*)\/xc9\/(.*)$ http://www.microsoft.com
    RedirectMatch permanent (.*)\/x04H\/(.*)$ http://www.microsoft.com
    </IfModule>

  4. #4
    BANNED
    Join Date
    Jul 2005
    Posts
    537

    Default

    Im seeing these too except just before the log entry i see

    @
    @
    @
    @
    @
    @
    @
    @
    @
    @
    @
    @
    "SEARCH /\x90\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\x c9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9 \xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\x c9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9 \xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\x c9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9 \xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\x c9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9 \xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\x c9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9 \xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\x c9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9 \xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\xc9\\x90\ x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x9 0\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\ x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x9 0\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\ x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x9 0\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\ x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x9 0\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\ x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x9 0\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\ x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x9 0\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\ x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x9 0\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\ x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x9 0\" 414 271

  5. #5
    Member
    Join Date
    Mar 2004
    Posts
    815

    Default

    Quote Originally Posted by jols
    Okay, here apparently is at least one solution (using a redirect) from - http://aplawrence.com/Blog/B1234.html

    Here's the part I just added to httpd.conf, then restarted apache and am hoping for the best:

    # Send MS IIS Exploits to the company who makes them all possible!
    <IfModule mod_rewrite.c>
    RedirectMatch permanent (.*)cmd.exe(.*)$ http://www.microsoft.com
    RedirectMatch permanent (.*)root.exe(.*)$ http://www.microsoft.com
    RedirectMatch permanent (.*)\/_vti_bin\/(.*)$ http://www.microsoft.com
    RedirectMatch permanent (.*)\/scripts\/\.\.(.*)$ http://www.microsoft.com
    RedirectMatch permanent (.*)\/_mem_bin\/(.*)$ http://www.microsoft.com
    RedirectMatch permanent (.*)\/msadc\/(.*)$ http://www.microsoft.com
    RedirectMatch permanent (.*)\/MSADC\/(.*)$ http://www.microsoft.com
    RedirectMatch permanent (.*)\/c\/winnt\/(.*)$ http://www.microsoft.com
    RedirectMatch permanent (.*)\/d\/winnt\/(.*)$ http://www.microsoft.com
    RedirectMatch permanent (.*)\/x90\/(.*)$ http://www.microsoft.com
    RedirectMatch permanent (.*)\/xc9\/(.*)$ http://www.microsoft.com
    RedirectMatch permanent (.*)\/x04H\/(.*)$ http://www.microsoft.com
    </IfModule>

    Just to follow up. This did not work. Any idea where I could insert the above redirects (other than in httpd.conf) to where they would work?

Similar Threads & Tags
Similar threads

  1. Replies: 0
    Last Post: 06-22-2009, 03:00 AM
  2. problem with the RBL rule in Mod_security
    By nitaish in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 06-18-2009, 12:29 PM
  3. a mod_security rule is breaking one script on one account
    By Metro2 in forum cPanel and WHM Discussions
    Replies: 12
    Last Post: 05-03-2008, 04:22 PM
  4. mod_security 2.1.4 and the latest rule set (1.5.1)
    By DReade83 in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 12-19-2007, 01:49 PM
  5. mod_security rule
    By ramakant in forum New User Questions
    Replies: 4
    Last Post: 12-09-2005, 02:55 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube