Forum Moderators: open

Message Too Old, No Replies

Microsoft-WebDAV-MiniRedir/5.1.2600

         

xcomm

11:53 am on Jul 12, 2004 (gmt 0)

10+ Year Member



I saw some older posts here about the issue but would like to ask for some news maybe available.

82.161.115.189 - - [10/Jul/2004:04:48:02 +0200] "OPTIONS / HTTP/1.1" 200 16803 "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
221.190.93.228 - - [10/Jul/2004:15:57:19 +0200] "OPTIONS / HTTP/1.1" 200 20788 "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
211.203.151.105 - - [10/Jul/2004:19:44:05 +0200] "OPTIONS / HTTP/1.1" 200 20788 "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
217.84.126.132 - - [10/Jul/2004:19:58:26 +0200] "OPTIONS / HTTP/1.1" 200 20788 "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
217.82.245.232 - - [10/Jul/2004:20:49:29 +0200] "OPTIONS / HTTP/1.1" 200 20788 "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"

217.44.75.31 - - [12/Jul/2004:11:03:48 +0200] "OPTIONS / HTTP/1.1" 200 16456 "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
81.155.190.70 - - [12/Jul/2004:12:50:50 +0200] "OPTIONS / HTTP/1.1" 200 16456 "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
81.155.190.70 - - [12/Jul/2004:13:20:39 +0200] "OPTIONS / HTTP/1.1" 200 16456 "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
81.155.190.70 - - [12/Jul/2004:13:37:48 +0200] "OPTIONS / HTTP/1.1" 200 16456 "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"

Anyone have some idea what this really is as it seems a bunch of this. Is it M$ Frontpage on XP crap horsing arround the Net or is this a more serious treat?

Thank you in advance!
xcomm

fiestagirl

2:58 pm on Jul 12, 2004 (gmt 0)

10+ Year Member



Microsoft Windows 2000 WebDAV Buffer Overflow Vulnerability
[symantec.com...]

[microsoft.com...]

xcomm

8:56 pm on Jul 12, 2004 (gmt 0)

10+ Year Member



Thanks fiestaGirl!

But it does not make much sense to me as this is over a year ago that I'm too readed about this leak in M$ WebDav.

I'm running an Apache/2 at Solaris 9 Sparc and have a real bunch of this requests with "Microsoft-WebDAV-MiniRedir/5.1.2600" the whole day. So I think there must be something else behind as someone looking for IIS leak at an Solaris Apache.

Regards, xcomm