Today’s little gift…

Someone using a broadband connection in Kiev, Ukraine sent this little gift today:

/var/log/httpd/access_log:178.137.17.213 – – [03/Aug/2011:15:34:49 -0400] “GET /radio-show.php?show=3319++++++++++++++++++++++++++Result:+%E7%E0%F0%E5%E3%E8%F1%F2%F0%E8%F0%EE%E2%E0%EB%E8%F1%FC;+%E2%EE%F8%EB%E8;+%ED%E5+%ED%E0%F8%EB%EE%F1%FC+%F4%EE%F0%EC%FB+%E4%EB%FF+%EE%F2%EF%F0%E0%E2%EA%E8;+%E2%EE%E7%EC%EE%E6%ED%EE,+%F0%E5%E3%E8%F1%F2%F0%E0%F6%E8%FF+%ED%E5+%F3%E4%E0%EB%E0%F1%FC+%28%E2%FB%F1%EB%E0%ED+%EA%EE%E4+%E0%EA%F2%E8%E2%E0%F6%E8%E8+/+%E8%F1%EF%EE%EB%FC%E7%F3%E5%F2%F1%FF+%E4%EE%EF%EE%EB%ED%E8%F2%E5%EB%FC%ED%E0%FF+%E7%E0%F9%E8%F2%E0+/+%F1%E1%EE%E9+%E2+%F0%E0%E1%EE%F2%E5+%F4%EE%F0%F3%EC%E0+/+…%29; HTTP/1.0” 200 23809 “http://streamingradioguide.com/radio-show.php?show=3319++++++++++++++++++++++++++Result:+%E7%E0%F0%E5%E3%E8%F1%F2%F0%E8%F0%EE%E2%E0%EB%E8%F1%FC;+%E2%EE%F8%EB%E8;+%ED%E5+%ED%E0%F8%EB%EE%F1%FC+%F4%EE%F0%EC%FB+%E4%EB%FF+%EE%F2%EF%F0%E0%E2%EA%E8;+%E2%EE%E7%EC%EE%E6%ED%EE,+%F0%E5%E3%E8%F1%F2%F0%E0%F6%E8%FF+%ED%E5+%F3%E4%E0%EB%E0%F1%FC+%28%E2%FB%F1%EB%E0%ED+%EA%EE%E4+%E0%EA%F2%E8%E2%E0%F6%E8%E8+/+%E8%F1%EF%EE%EB%FC%E7%F3%E5%F2%F1%FF+%E4%EE%EF%EE%EB%ED%E8%F2%E5%EB%FC%ED%E0%FF+%E7%E0%F9%E8%F2%E0+/+%F1%E1%EE%E9+%E2+%F0%E0%E1%EE%F2%E5+%F4%EE%F0%F3%EC%E0+/+…%29;” “Mozilla/4.0 (compatible; MSIE 5.5; Windows 95)”

In general, this looks like an attempt at an SQL injection attack…  the typical one is looking to do this:

Request:  /radio-show.php?showid=123;drop table xyz

hoping that the coding takes in the showid and directly executes it as SQL code”

“Select * from radioshows where showid=123;drop table xyz”

the %xx stuff is encoding UTF8 (basically ASCII8) so it is harder to read.  The sequence above makes very little sense.   It looks mostly like a probe to see if that particular page is vulnerable to an injection attack.   “+” inside a GET request becomes a space character.

Should you travel to China or Eastern Europe, you’ll find that this server can’t be reached.   This particular block of IP addresses wasn’t yet blocked.

If you’re curious, program #3319 is Sounds of Sinatra.  I hear he’s big in Ukraine

This entry was posted in About the Guide. Bookmark the permalink.

3 Responses to Today’s little gift…

  1. Parrott says:

    “You send us radio show, we send you Ukrainian bride” fare trade, no?

    When they get tired here, maybe they will move onto the pentagon servers?
    we could send them some Cargill turkey loaf?

  2. 3tooz says:

    Maybe you can send the Ukraine a listen link to a file that takes them to the “blue screen of death” that will erase their hard drive , or redirects them to a Perry Como only station , Im just say’n …

  3. Art Stone says:

    After doing a little more research, this looks more like a probe of Cross Site Scripting (XSS) vulnerabilities. There are several types of XSS, but the basic idea is that javascript is used to trick a browser into executing javascript code from a third party web site. I haven’t studied the topic very much, but the general idea is that this approach allows someone to read your cookies for an unrelated web site (like a bank), or run a malicious script from a third party web site (like the fake antivirus things)

    About Cargill, my local drug store that decided it wanted to go into the grocey business and now doesn’t have a drug store… they don’t have a butcher, but carry prepackaged meat – maybe a year ago, they started carrying Cargill ground beef – it comes double wrapped and inside is filled with nitrogen (or something) so the meat stays red. I suspect it doesn’t actually even need to be refrigerated until it’s opened – the “sell by” date is in months. It’s probably been irradiated and fumigated and Mexican works pick out the bateria one by one by hand. I’ve bought it a couple times – it’s actually not as bad as I expected, at least the taste.

Leave a Reply