Forum Moderators: phranque

Message Too Old, No Replies

Nimda stuff?

GET /msadc/Samples/SELECTOR/showcode.asp

         

pendanticist

7:46 pm on Nov 4, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Had these crop up in my logs just a bit ago.

64.229.96.213 - - [04/Nov/2003:06:00:35 -0800] "GET /msadc/Samples/SELECTOR/showcode.asp?source=/msadc/Samples/SELECTOR/showcode.asp HTTP/1.1" 403 480 "-" "Java/1.4.1_02"
64.229.96.213 - - [04/Nov/2003:06:00:35 -0800] "GET /msadc/Samples/SELECTOR/showcode.asp?source=/msadc/Samples/SELECTOR/showcode.asp HTTP/1.1" 403 480 "-" "Java/1.4.1_02"
64.229.96.213 - - [04/Nov/2003:06:00:35 -0800] "GET /msadc/Samples/SELECTOR/showcode.asp?source=/msadc/Samples/SELECTOR/showcode.asp HTTP/1.1" 403 480 "-" "Java/1.4.1_02"
64.229.96.213 - - [04/Nov/2003:06:00:35 -0800] "GET /msadc/Samples/SELECTOR/showcode.asp?source=/msadc/Samples/SELECTOR/showcode.asp HTTP/1.1" 403 480 "-" "Java/1.4.1_02"

Did a bit of digging and found these two mentions.

http*//atstake.com/research/advisories/1999/showcode.txt

http*//lists.virus.org/dshield-0211/msg00238.html

I'm not too concerned with the Java or the fact that they've already received a healthy 403.

Would just like to understand the whole picture.

  • What do these entries tell you?

  • That the visitor is infected?

  • Trying to view ASP files?

  • Or, is the part that says it provides the ability to view any text file on the server the part I should be concerned with?

    Thanks.

    Pendanticist.

  • hakre

    1:07 am on Nov 6, 2003 (gmt 0)

    WebmasterWorld Senior Member 10+ Year Member



    hi pendanticist,

    i know that the showcode.asp url is a method to gain access to a system where an iis webserver is running (reading files) - it's very old.

    i would assume that it is a scan wether the system accessable that way or not. so i would take number 4 ;).

    but it's hard to say wether it is a virus, a script or a 'real person' who is trying.

    never the less, if showcode.asp is located on that server, remove it or better: update iis and remove the whole (mdac) samples.

    - hakre

    pendanticist

    1:22 pm on Nov 7, 2003 (gmt 0)

    WebmasterWorld Senior Member 10+ Year Member



    Thanks, hakre.

    I think that's something my host server handles, as I know very little about them and therefore can not delete or rename.

    Since I have no aps pages then I gather there isn't much for me to worry about...

    Long as it isn't viral in nature, I'm good-to-go.

    Pendanticist.

    hakre

    7:19 am on Nov 8, 2003 (gmt 0)

    WebmasterWorld Senior Member 10+ Year Member



    if the host isn't windows, you don't even have to worry about that at all. either if so, if it's properly managed you're good to go.