Welcome to the JaguarPC Community
JaguarPC
Sales: (888) 338-5261
Support: (888)-551-3050
Results 1 to 6 of 6

This is a discussion on Latest visitors URL /\x90\x02\xb1\x02\xb1\ in the Shared & Semi-Dedicated forum
I have no idea what this is and was wondering if someone might be able to inform me. For about the past month my "Latest ...

  1. #1
    JPC Member
    Join Date
    Jan 2002
    Posts
    3

    Latest visitors URL /\x90\x02\xb1\x02\xb1\

    I have no idea what this is and was wondering if someone might be able to inform me.

    For about the past month my "Latest Visitor" page has been filled with "visits" to the following URL which continues for about 50 Page downs

    /\x90\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02 \xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02 \xb1\x02\xb1\x02\xb1. . .
    etc. etc. for about 50 page downs
    and ending with
    \x90\x90\x90\x90\x90\x90\x90\x90\x90\x90 \x90\x90\x90\x90\x90\x90\x90\x90\x90\x90 \x90\x90\x90\x90\x90\x90\x90\x90\x90\x90 \x90\x90\x90\x90\x90\x90\x90\x90\x90\x90 \x90\x90\x90\x90\x90\x90"
    Host: 69.73.42.222 (varies)
    Http Code : 343
    Date: Apr 06 00:39:20
    Http Version: 414
    Size in Bytes: "-"
    Referer: -

    No idea what this is. I've been here for over 2 years and I never saw this up until about a month ago.

    Thanks,
    Norb
    www.bankert.org

  2. #2
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    It's shellcode. If this is the one I'm thinking about, it's an old NT4 DCOM exploit that's been revived. Actually, it's part of a reverse shellcode generator, but it only works remotely on W2K/XP servers.

    As far as *NUX servers are concerned, it appears that hackers are also trying to use this to cause string overflows in form inputs, such as search boxes and logins. To my knowledge, they haven't been successful at this, other than to fill your logs with pages full of nonsense.

    If you're tired of seeing it in your logs, ban the offending IP[s].
    Last edited by Vin DSL; 04-06-2004 at 01:48 AM.
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  3. #3
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  4. #4
    Jag Veteran
    Join Date
    Oct 2003
    Location
    Location: Location:
    Posts
    633
    Thanks for the link, Vin

  5. #5
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    My pleasure!
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  6. #6
    JPC Senior Member
    Join Date
    Nov 2003
    Posts
    63
    Originally posted by Vin DSL

    If you're tired of seeing it in your logs, ban the offending IP[s].
    I just did that , what are the odds , that its some poor shmuck that had his dsl or cable account hacked.

    Not that it matters a whole hill of beans , just curious.

    Tux

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •