|
|||||||||||
|
RE: Attack(s) caught by Okena
From: Chris Fussell <chrisfussell(at)hotmail.com>
Date: Tue Jun 10 2003 - 17:39:26 EDT
00005753 325f3332 2e444c4c 00... W S 2 _ 3 2 . D L L I can't tell what the rest of the captured buffer in the event log is meant to do, if even related...
-----Original Message-----
Hello everyone..
Dimitri
<start event 1>
Date: 6/10/2003 Time: 1:53:30 AM User: N/A Computer: IISTEST Description: The application 'C:\WINNT\system32\inetsrv\inetinfo.exe' (as user IISTEST\IUSR_IISTEST) tried to call the function LoadLibraryA from a buffer (the return address was 0x45b7b1). The code at this address is '00005753 325f3332 2e444c4c 00ff55f4 8945bce8 07000000 736f636b 657400ff' This either happens when a program uses self-modifying code or when a program has been subverted by a buffer overflow attack. The user chose 'Terminate (no user interaction allowed)'. </end event 1>
<start event 2>
Date: 6/10/2003 Time: 1:53:30 AM User: N/A Computer: IISTEST Description: The application 'C:\WINNT\system32\inetsrv\inetinfo.exe' (as user IISTEST\IUSR_IISTEST) tried to call the function LoadLibraryA from a buffer (the return address was 0x45b7b1). The code at this address is '00005753 325f3332 2e444c4c 00ff55f4 8945bce8 07000000 736f636b 657400ff' This either happens when a program uses self-modifying code or when a program has been subverted by a buffer overflow attack. The program was terminated. </end event 2>
<start event 3>
Date: 6/10/2003 Time: 1:53:32 AM User: N/A Computer: IISTEST Description: The process 'C:\WINNT\system32\inetsrv\inetinfo.exe' (as user NT AUTHORITY\SYSTEM) tried to open/write the file '\\TEST**\MAILSLOT\NET\NETLOGON' and was denied. </end event 3> Received on Wed Jun 11 15:23:42 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:07 EDT |
||||||||||
|
|||||||||||