AW: [squid-users] parseHttpRequest: Unsupported Method 'somestrangestring'

From: mailinglists <mailinglists@dont-contact.us>
Date: Fri, 11 Apr 2003 23:54:54 +0200



> > I got this here in my cache.log.
> > Squid 2.3stable4 is restarting upon it. I think it's some
> kind of an attack.
> >
> > parseHttpRequest: Unsupported method
> 'XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
> XXXXXXXXXXXXXXXXXXXXXX
> >
> XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%u9090%u6858%ucbd3%u7801%u9
> 090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u819
> 0%u00c3%u0003%u8b0
> > 0%u531b%u53ff%u0078%u0000%u00=a'
>
> Looks like a buffer overrun attempt with shellcode

Bugtraq sais there would be a buffer overrrun in squid2.4 stable7 and below.
Looks like it's time for an update.

thanks for the info,
Philipp
Received on Fri Apr 11 2003 - 15:55:43 MDT

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 17:14:57 MST