Odd weblog record: CONNECT%00.....

Odd weblog record: CONNECT%00.....

Post by J N Katzman-TC » Fri, 19 Jul 2002 22:28:03



Hi,

After getting used to Nimda/Codered and all the other "common" attacks,
this just popped up in my log files.

66.107.89.130 - - [16/Jul/2002:23:18:25 -0400] "(bad request line)
CONNECT%00mx01.hotmail.com:25 /%00%00%00%00P/1.0" 400 2177

Does anyone have a clue as to what vulnerability, or worm/virus, this
might be associated with ?

TIA

Joel Katzman
TCM Integrated Systems, Inc
Freeport NY

 
 
 

Odd weblog record: CONNECT%00.....

Post by Matt Scarboroug » Sat, 20 Jul 2002 04:05:05


On Thu, 18 Jul 2002 09:28:03 -0400, J N Katzman-TCM wrote

Quote:> Hi,

> After getting used to Nimda/Codered and all the other "common" attacks,
> this just popped up in my log files.

> 66.107.89.130 - - [16/Jul/2002:23:18:25 -0400] "(bad request line)
> CONNECT%00mx01.hotmail.com:25 /%00%00%00%00P/1.0" 400 2177

> Does anyone have a clue as to what vulnerability, or worm/virus, this
> might be associated with ?

The attacker hopes you are running a mis-configured proxy that would allow her to send
mail, i.e., CONNECT through IIS/ISA to mx01.hotmail.com on port 25 and send some
(probably) SPAM.

Matt Scarborough 2002-07-18

 
 
 

Odd weblog record: CONNECT%00.....

Post by J N Katzman-TC » Sat, 20 Jul 2002 05:13:01


Matt,

Thanks for the info

Joel

 
 
 

1. How to replace ODBCJT32.dll ver. 4.00.6019.00 with 3.50.3602.00?

Hi there!

One silly question: How can I downgrade Microsoft Access
driver ODBCJT32.dll ver. 4.00.6019.00 to version
3.50.3602.00?

If I just copy it to Winnt\system32, something brings
original version back after few seconds. What is
this "something"? How to stop it?

My W2K workstation should communicate with Access
database, located in eldery WinNT computer. This new
version jams hubs and slows the system itself.

2. SolidWorks & Solid Edge Crack ?

3. Error 26 27 00 00

4. ODS STARTPAGE= option - bug & workaround

5. 83 00 00 01 8F, anybody seen this ?

6. VidCell PD Digitizer help

7. Can not play wac in IE 5.00.3315.00

8. Ack! Dead GS XTAL and motherboard

9. Windows Media Player 9.00.00.2980

10. RDP v5.00 client does not connect from NT4.0

11. TS Client does not get TS Scan Code Mapper change. (code 3B 00 = 00 00 - disable

12. NT4.00 workstations not able to log onto domain after workign for 1 week.

13. ODBCJT32.DLL Ver. 4.00.5303.01