Forum Moderators: open

Message Too Old, No Replies

msnbot crawling with massive binary strings in URIs

appears to be some buffer overflow vulnerability

         

incrediBILL

4:27 pm on Aug 27, 2008 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Has anyone seen this embedded in your URI?

%C3%83%C6%92%C3%86%E2%80%99%C3%83%E2%80

That's just a small snippet of the start of a very long binary string that msnbot keeps requesting.

For instance:

example.com/my-page-%C3%83%C6%92%C3%86%E2%80%99%C3%83%E2%80....-here.html

The total URIs are about 7K in size and I can't determine if these are just inadvertent UNICODE embedded from a foreign site or if it's binary code, which it looks like to me, and it appears msnbot is being unwittingly utilized to launch some sort of buffer overflow attack.

Both Yahoo and Live has a bunch of sites indexed that have these big binary strings in URIs on pages just waiting to be indexed, so I can see where this is coming from but I can't determine if they are aiming at vulnerable browsers or vulnerable websites and letting the crawlers do their dirty deeds for them.

I've had about 44 requests of this type so far today.

Anyone else seeing this in your log files or have any clue?

[edited by: incrediBILL at 4:30 pm (utc) on Aug. 27, 2008]

wilderness

5:04 pm on Aug 27, 2008 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Bill,
I seem to recall that there is an old and similar thread on this?
No idea what to search on.

Whether it was MSN or another escapes me.

Don

incrediBILL

11:15 pm on Aug 27, 2008 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I actually posted this on the MSN webmaster forum on their crawler page so hopefully someone over there will eventually read it and maybe stop it from happening.