A hacker or a corrupt log?

 
Post new topic   Reply to topic    Aprelium Forum Index -> Off Topic Discussions
View previous topic :: View next topic  
Author Message
help!
-


Joined: 02 Feb 2005
Posts: 35

PostPosted: Thu Feb 24, 2005 6:33 pm    Post subject: A hacker or a corrupt log? Reply with quote

Ok the other day i got a request on my server that was totally wierd. I dont have my IP posted on the internet. My DNS provider is screwed up so no domain name. Here was the request.

210.0.186.77 - - [23/Feb/2005:05:52:08 +1133] "GET //cgi-bin/awstats/awstats.pl?configdir=|%20id%20| HTTP/1.1" 404 427
210.0.186.77 - - [23/Feb/2005:05:52:13 +1133] "GET //cgi-bin/awstats.pl?configdir=|%20id%20| HTTP/1.1" 404 427
210.0.186.77 - - [23/Feb/2005:05:52:18 +1133] "GET //cgi/awstats.pl?configdir=|%20id%20| HTTP/1.1" 404 427
210.0.186.77 - - [23/Feb/2005:05:52:19 +1133] "GET / HTTP/1.1" 200 9676


So whats wrong with this? Well i dont have a cgi bin for starts. And i heard on a site that hackers try to get in using long wierd requests.

Plus today i found this in my log.

$n 4n Ln Vn ln n n n n n n n n
o o ,o >o Po fo |o o o o o o o o o
p p (p <p Lp Xp hp p p p p p p q (q @q Rq bq rq ~q q q q q q q r r *r <r Hr Xr hr zr r r r r r r r r s s (s :s Ls Vs ls ~s s s s s s s s t t &t 4t >t Ht Pt Zt bt lt zt t t t t t t t t t t u u u $u 0u :u Fu Nu Xu bu nu |u u u u u u u u u u u u u v v v (v 4v >v Hv Pv Xv `v hv rv zv v v v v v v v v v v v w w w 0w :w Bw Lw Vw `w tw w w w w w w x &x 2x Jx Zx hx xx x x x x x x x
y y ,y <y Ly ^y jy |y y y y y y y y y z z $z 6z Fz \z lz |z z z z z z z z { { ${ 4{ F{ V{ f{ t{ { { { { { { { | | ,| 8| D| Z| h| t| | | | | | | | | } } 2} J} \} p} ~} } } } } } } } ~ ~ $~ 6~ D~ P~ ^~ t~ ~ ~ ~ ~ ~ ~ ~   " : J X b n z            " 0 > J \ n | ր   0 > L X l ~ ʁ ځ  $ 8 F X v ̂ ڂ   $ B P ^ n ҃   . F ` l | Є ܄
& : F X hu|P |V U
X |W6 l jF 9>}uUMj 鬈 P | | 6<   ( ps ps    פ , b  Q -  @T
H M/  V   F % w s@  DŽ 2 b @  P: D ,t  f '  K
 ! U / W  " *     V u%
jh q  M kQ E \ - C wt . n  
 
%  ( K    V ?  * d |a ճ 7 V7 ¤ _i i S El k f f !T a y* Q ͊    5m m >n n $o 6 !i T ,b b 0V
 B ͤ  @    (8 A  ?G .# * C  n  W 
i
0
! J]
 5 * w
}_ (  A* x f m  ` l  4; d# p
u

 i+ d 
 i
3   dT T T T dT T  = A
87 + * M M G G M h M 0 a%   ^   ,_ V  Y  1| o e  T   A p o h yh +   2 +=   8`     } & Z$  %   P    z: . d +N n : * $     ؈  Kl S zB  b6  .w ܏ m N J  N y    bT
m:  < 3:  G   o @ r  x .   f' * I %
)    E E r   _   ;
 
j  w $ V 2?  { ش  V[ P [ a P &] p l ߊ   3 [ [  [ T W b
 K     E   K$ N G
Ю & w   n  c



.
'  q* C(  (

 ` e  F& o


S ^
 G 4
   9 @
Y* %  H ~   z| Oi  mp Ut \   s  [ w$ !& M  H  X; . , ( P   7   < W   l ` j 1  8  M a ! 8  " S 4J S  J J J J J O J zQ I P VQ NP pP P Q 4Q J qO `u a C u Cx }x x u w v x w R S /T /T (X P P Q S
T OT V P P gF F G \D D E E E E H H H H H H C G G B dB !C B K K K K K K H [ M 9 9 ^   P\ [
\ [ n] MJ J kJ J ;   T
H  T@
/ @ T d   9 : 3K   t   1 S z d#
 f !
4 E "
l x9
gk f   x Dx yr Y~ _ u
l O  07  8  
Jy
Kx
   ڝ  ڝ  ( j  ]$
w
 d
 [h um j y c c c BE
 0^
g )p T "O r h y
s     ]   <p o  C $ 0   ݣ  aO  6
[
N SP } W s % y  `D [ , 
 } q R    7  ? ~ ,'

)   p |O X_  #. n  % x (  J a  \1 = \ pO sy  4 K F @ l  R 7 BK - '   h q  W U(
  y ۆ &\ 6 x 5S 4 \ <P P *P { F = F S /` . $<
m K  o
 M L * O+  @M 0 Y P YM 3 kS k
T\     + + ;X
^ JU ^ 7]  n [ 8  \  _ a ? X   ~L (
 9 4 ;  s  4   K+ 
 Я  ~U  N O   3
 D ž   F -, ( 7 Y-
id  w ~   x ) z  +   @  E YK Y iK  T    = 
h 0& Q& y& & & $' D' ( 0( ' ' ' Ɛ    P  Ś 4  N   !,
,
4C
 y - 9 % . L {G  I
rK


N >
N 7O ( 2 <   B1 K_  RR I6 
2|
t   Z/ d ͮ   p 8 { ט  R  9  n  l p = F  X ` ¬
   H ̮ Bo pp

o y < < QJ J  $K x = J 67 9 G _ 
  uE u  }4 9 0e ږ o
3 : ݝ  < x. ;r } Wu
g  p |   ~* {
a  "H i
X *  3 =
 Q E0  aH l ͜ Y      L 
܏  ?   (  
  <  t  = s    و k
J> k M
L:   . = S eS ^ S 4 F

w@
 : .  yK (

j  Z _= P P > d  R k $
  A   n [ '% '%  /  T Z. 4  { Ƣ
*  <   %
    8
d
 A
 A_
 $  \ x

4  + + K +  +   J {k 8
M
{ :9  m u  q r   Yd 8
f 7 p y z /        7I J C t XH _ & " r  ^ U N y < @z I +K ˊ Y x |x sY  Kr Us z n Hr *m v A " FF
H
S
7 1 C

Y  L  ȼ P  |   = ( J ~  ON q U    \  ]T  /      wI         dr   n  l  [ CA  = q   k
J

)  7 
  t
 q q <
Ɇ


<
e
e Ze >
  
{u ^ u 8 ہ Z ^x x x ?L    E u w a a   A*  r v $x z w  % ^  j
_ A f S 5\   )
&
A
~ 5` Z ~ N H  T
5

  l  B       6     ^   Z

 :  R .  B ق } ̉ ނ     0 W~ v [~ ނ Q }  F { G^ | > j?  w 8} | @ Я t  I ~  ۾  B ݼ w Ǽ  W  ]        C m  (  \    ~ |  T i} ?  } f, , , , - %. - i. , , , , - _- |- I, | l} }   T   % T    g ` @ vD E _ n c f B F]

l
 ]
\ '   P{ wg ]x Z
!

{   u 
G _  &  Y ! D P | <S      ( ؖ Nj g t Z  M >2 n  {  p NL  ^L nL  `
, Ԏ  `a q
m [ K ('  9  W   G G K
U
J
>
J ' ׈   !2  / 

'l
X ] R y R u  %E { 2 0
i ji i 0y [
f
@ ej
-
 [
<E {  \ ? M` m S .a n
w
ȍ
v
>
av
4w
lw

, ]  Di  0 k <3 [N - D D fZ E @ e  ׳ w !   M < [ ɒ
; L w h
  + $   K
`| +
F

 b ,U U S / a  7d / $ b C wQ  s   z  z    [N z z -t | $ =! i% ! 
y F NG D ;E F F F F 

F  M H zC
. j  Þ    h
A  o[  Y s E
(^ ;  p g |  < 0
|h
0 B D y  V g q p  
L
!
Mm   g sm y w\ h  &
 O h U
e p     
Z
e $




l PM 

dI 7  N #   G`  4  x  + | q<
 j + } ;   + p B  >, $   6 ^ B^
c  X T S  e R  <  L l x 4   e' " g{  7 N nb o - 1 ?D  G 9    m1 k  Տ j? +g U gT    ܽ = UP P  H   < 9 
< _ V    y C  W H 8F
E
/    b 5 Ն I O  }  0         $  #      )     u h i  f 4 "
- % $   2   n  e j q m Qo !o    <  2 # H         > U      i  "  X  6 ' 1  X    l   q    n  c I  (a 0  $  !    ƿ ƿ §   8`   _ M
  Ge
 s  x r   B % /  KR  V V T N i 

Ħ ޝ
]
]
Š  d    x  $z + %i k
vH { {D <

H 9 +   

y 4 J 



1% L ;
w )  K h# э ^d '  @ e      * D  O  S r%


& l ,% ) < W ۝ w #  D 0E
Ì Ğ o Rs  n 
>_ K L _ |g m m > = Q PQ
_ N j Ck =b  H  y  I   X
A  ͠ >
`

D  l

1
 s
 4          L Y f  c/ x ' _  [j A ( ^
_ f   K m ,  r  g |d /   T( q   * @R o + g    b  \ M u: ~ <I 
] ;  $ _ 4Z *j D ;s  E  ^ K ś М 
  d  b   ^ Q  ,
N ̠    '   /   s  Hx  M O 
a _ Ǎ w     ݗ j | * T  N
pZ  Y @
]  A
]  [ P@
] n
FA p
] zo 2s M  z u8 H%
   RV + U    Z U e  7h i q  
p  v
8  b  b
g a D v  \z = l Nq q   #


 f u h
 & O q q П Y $ 1 - Y;
; ~d
O



Any ideas??
Please Help!!
-Regards, Soldat
Back to top View user's profile Send private message
Systemsoft
-


Joined: 06 Jun 2003
Posts: 59
Location: Krakow, Poland

PostPosted: Thu Feb 24, 2005 10:28 pm    Post subject: Reply with quote

Don't post so long logs in post.

However, this problem would do some third party application.
Also, it can be error on hard disk.
Back to top View user's profile Send private message Send e-mail
k1ll3rdr4g0n
-


Joined: 04 Jul 2004
Posts: 609

PostPosted: Thu Feb 24, 2005 11:07 pm    Post subject: Reply with quote

Weird...

But a error on the hard drive wouldnt generate logs at the top.

I would email Aprelium about it and see what he has to say about it.
_________________
Back to top View user's profile Send private message AIM Address
richardyork
-


Joined: 22 Jun 2004
Posts: 411
Location: United Kingdom

PostPosted: Thu Feb 24, 2005 11:22 pm    Post subject: Reply with quote

do you know that "aprelium" is a he?

if not, thats CENSORED!

lol
_________________
Please SEARCH the forums BEFORE asking questions!
Back to top View user's profile Send private message
aprelium
-


Joined: 22 Mar 2002
Posts: 6800

PostPosted: Thu Feb 24, 2005 11:48 pm    Post subject: Reply with quote

k1ll3rdr4g0n wrote:
Weird...

But a error on the hard drive wouldnt generate logs at the top.

I would email Aprelium about it and see what he has to say about it.

The file could have been opened and written by Abyss Web Server, but for some reason, the rest of the file was filled with junk by a third party application (or even by Windows.)
_________________
Support Team
Aprelium - http://www.aprelium.com
Back to top View user's profile Send private message Send e-mail
help!
-


Joined: 02 Feb 2005
Posts: 35

PostPosted: Fri Feb 25, 2005 12:20 am    Post subject: But what about the IP Reply with quote

But what about the strange request???
Back to top View user's profile Send private message
Axis
-


Joined: 29 Sep 2003
Posts: 336

PostPosted: Fri Feb 25, 2005 5:45 am    Post subject: Reply with quote

It is possible that they were probing for AWSTATS scripts installed on sites to exploit a vulnerability discussed in this thread.

http://www.aprelium.com/forum/viewtopic.php?t=6326

Regards,
Axis
Back to top View user's profile Send private message
goose
-


Joined: 17 Sep 2002
Posts: 608
Location: The Land Of OZ! come here toto!

PostPosted: Fri Feb 25, 2005 6:00 am    Post subject: Reply with quote

looks like the greeks are attacking troy.
_________________
living in an armish paradise.....no gates here!

mawuahahaha :)
Back to top View user's profile Send private message
roganty
-


Joined: 08 Jun 2004
Posts: 357
Location: Bristol, UK

PostPosted: Fri Feb 25, 2005 11:58 am    Post subject: Reply with quote

I have a similar load of gumpf in my log file (at the end)
My computer restarted, even thou i have a new computer windows xp (home) and abyss beta 3, the old restarting problem is still there (http://www.aprelium.com/forum/viewtopic.php?p=25811)
I looked in the cgi error log and found no problems, then i looked in the access log file and there was something similar to what "help!" has posted.
_________________
Anthony R

Roganty
| Links-Links.co.uk
Back to top View user's profile Send private message Visit poster's website
goose
-


Joined: 17 Sep 2002
Posts: 608
Location: The Land Of OZ! come here toto!

PostPosted: Fri Feb 25, 2005 1:08 pm    Post subject: Reply with quote

hmmm the hackers of greece have struck....
_________________
living in an armish paradise.....no gates here!

mawuahahaha :)
Back to top View user's profile Send private message
goose
-


Joined: 17 Sep 2002
Posts: 608
Location: The Land Of OZ! come here toto!

PostPosted: Fri Feb 25, 2005 1:10 pm    Post subject: Reply with quote

im soooo tired of this fluff that i need a holiday.

any where to travel ....where there are no terrorists or hacker viruses. an so on?
_________________
living in an armish paradise.....no gates here!

mawuahahaha :)
Back to top View user's profile Send private message
help!
-


Joined: 02 Feb 2005
Posts: 35

PostPosted: Sun Feb 27, 2005 6:05 pm    Post subject: another request Reply with quote

Ok found this in my lod. Ive seen it on the web before, ISS worm?Hacker?

196.25.174.252 - - [26/Feb/2005:12:52:11 +1133] "GET /scripts/..%255c%255c../winnt/system32/cmd.exe?/c+dir" 400 429
Back to top View user's profile Send private message
richardyork
-


Joined: 22 Jun 2004
Posts: 411
Location: United Kingdom

PostPosted: Sun Feb 27, 2005 10:46 pm    Post subject: Reply with quote

That would be an IIS hacking attempt, but Abyss Web Server is NOT affected by them!! :-)

SeE yOU ArOUnD!!
_________________
Please SEARCH the forums BEFORE asking questions!
Back to top View user's profile Send private message
help!
-


Joined: 02 Feb 2005
Posts: 35

PostPosted: Tue Mar 01, 2005 12:58 am    Post subject: Reply with quote

So what happens?Someone has a program that fires this request at random IP adresses?
_________________
Type one diabetes since January 27, 2004.
*AD*Soldat von der Holle|XO

Hallo bin ich Soldat. Dieses ist mein Profil. Es ist nicht Sie denkt nett? Ich mu gehen. Tschuess. Ein in den amischen Gattern des Paradieses........no hier leben! - goose
Back to top View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Aprelium Forum Index -> Off Topic Discussions All times are GMT + 1 Hour
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB phpBB Group