Beste tweakers wat moet ik doen.
Ineens werd mijn internet verbinding traag, ik dacht nou we zitten vast veel mensen op mij website. Toen ik in eens een hele grote logfile zag dacht ik HELP.
Nu is mijn vraag hoe moet ik hem blocken zonder dat ik mijn website offline zet. In de standaard firewall van windows kun je toch geen IP blocken toch?
Ik gebruik als router een Wanadoo Livebox, als systeem gebruik ik Windows 2003 ook met firewall aan. Alle update's mijn geinstalleerd.
Logfile:
09:33:49 /index.php 82.59.61.17
09:33:54 /scripts/root.exe 82.59.61.17
09:33:55 /scripts/1337.exe 82.59.61.17
09:33:55 /scripts/nvprotect.exe 82.59.61.17
09:34:01 /msadc/1337.exe 82.59.61.17
09:34:05 /iisadmpwd/1337.exe 82.59.61.17
09:34:16 /scripts/war.exe 82.59.61.17
09:34:22 /scripts/test.exe 82.59.61.17
09:34:24 /scripts/sys.exe 82.59.61.17
09:34:25 /scripts/superlol.exe 82.59.61.17
09:34:30 /scripts/spooler.exe 82.59.61.17
09:34:31 /scripts/spool.exe 82.59.61.17
09:34:32 /scripts/some.exe 82.59.61.17
09:34:34 /scripts/update.exe 82.59.61.17
09:34:34 /scripts/sky.exe 82.59.61.17
09:34:36 /scripts/sklp.exe 82.59.61.17
09:34:38 /scripts/shell.exe 82.59.61.17
09:34:39 /scripts/serverdata.exe 82.59.61.17
09:34:50 /scripts/sensepost.exe 82.59.61.17
09:34:55 /scripts/mumu.exe 82.59.61.17
10:15:23 /iissamples/..o../..o../winnt/system32/cmd.exe 82.59.61.17
10:15:23 /iissamples/..ü€€€€¯../..ü€€€€¯../winnt/system32/cmd.exe 82.59.61.17
10:15:24 /iissamples/..ø€€€¯../..ø€€€¯../winnt/system32/cmd.exe 82.59.61.17
10:15:24 /iissamples/..ð€€¯../..ð€€¯../winnt/system32/cmd.exe 82.59.61.17
10:15:29 /iissamples/..à€¯../..à€¯../winnt/system32/cmd.exe 82.59.61.17
10:15:30 /iissamples/..Á¯../..Á¯../winnt/system32/cmd.exe 82.59.61.17
10:15:30 /iissamples/..Áœ../..Áœ../winnt/system32/cmd.exe 82.59.61.17
10:15:35 /iissamples/..À¯../..À¯../winnt/system32/cmd.exe 82.59.61.17
10:15:56 /iissamples/..%2f..%2fwinnt/system32/cmd.exe 82.59.61.17
10:15:56 /iissamples/..%2f..%2f..%2f..%2fwinnt/system32/cmd.exe 82.59.61.17
10:15:58 /iissamples/..%2e..%2ewinnt/system32/cmd.exe 82.59.61.17
10:15:58 /iissamples/..%5c..%5cwinnt/system32/cmd.exe 82.59.61.17
10:16:02 /iissamples/..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe 82.59.61.17
10:16:15 /iissamples/.%2e/.%2e/.%2e/.%2e/winnt/system32/cmd.exe 82.59.61.17
10:16:17 /iissamples/.%2e/.%2e/winnt/system32/cmd.exe 82.59.61.17
10:16:21 /iishelp/..ü€€€€¯../..ü€€€€¯../winnt/system32/cmd.exe 82.59.61.17
10:16:26 /iishelp/..ø€€€¯../..ø€€€¯../winnt/system32/cmd.exe 82.59.61.17
10:16:30 /iishelp/..ð€€¯../..ð€€¯../winnt/system32/cmd.exe 82.59.61.17
10:16:32 /iishelp/..à€¯../..à€¯../winnt/system32/cmd.exe 82.59.61.17
10:16:35 /iishelp/..Á¯../..Á¯../winnt/system32/cmd.exe 82.59.61.17
Toch behoorlijk verdacht dacht ik zo
Ineens werd mijn internet verbinding traag, ik dacht nou we zitten vast veel mensen op mij website. Toen ik in eens een hele grote logfile zag dacht ik HELP.
Nu is mijn vraag hoe moet ik hem blocken zonder dat ik mijn website offline zet. In de standaard firewall van windows kun je toch geen IP blocken toch?
Ik gebruik als router een Wanadoo Livebox, als systeem gebruik ik Windows 2003 ook met firewall aan. Alle update's mijn geinstalleerd.
Logfile:
09:33:49 /index.php 82.59.61.17
09:33:54 /scripts/root.exe 82.59.61.17
09:33:55 /scripts/1337.exe 82.59.61.17
09:33:55 /scripts/nvprotect.exe 82.59.61.17
09:34:01 /msadc/1337.exe 82.59.61.17
09:34:05 /iisadmpwd/1337.exe 82.59.61.17
09:34:16 /scripts/war.exe 82.59.61.17
09:34:22 /scripts/test.exe 82.59.61.17
09:34:24 /scripts/sys.exe 82.59.61.17
09:34:25 /scripts/superlol.exe 82.59.61.17
09:34:30 /scripts/spooler.exe 82.59.61.17
09:34:31 /scripts/spool.exe 82.59.61.17
09:34:32 /scripts/some.exe 82.59.61.17
09:34:34 /scripts/update.exe 82.59.61.17
09:34:34 /scripts/sky.exe 82.59.61.17
09:34:36 /scripts/sklp.exe 82.59.61.17
09:34:38 /scripts/shell.exe 82.59.61.17
09:34:39 /scripts/serverdata.exe 82.59.61.17
09:34:50 /scripts/sensepost.exe 82.59.61.17
09:34:55 /scripts/mumu.exe 82.59.61.17
10:15:23 /iissamples/..o../..o../winnt/system32/cmd.exe 82.59.61.17
10:15:23 /iissamples/..ü€€€€¯../..ü€€€€¯../winnt/system32/cmd.exe 82.59.61.17
10:15:24 /iissamples/..ø€€€¯../..ø€€€¯../winnt/system32/cmd.exe 82.59.61.17
10:15:24 /iissamples/..ð€€¯../..ð€€¯../winnt/system32/cmd.exe 82.59.61.17
10:15:29 /iissamples/..à€¯../..à€¯../winnt/system32/cmd.exe 82.59.61.17
10:15:30 /iissamples/..Á¯../..Á¯../winnt/system32/cmd.exe 82.59.61.17
10:15:30 /iissamples/..Áœ../..Áœ../winnt/system32/cmd.exe 82.59.61.17
10:15:35 /iissamples/..À¯../..À¯../winnt/system32/cmd.exe 82.59.61.17
10:15:56 /iissamples/..%2f..%2fwinnt/system32/cmd.exe 82.59.61.17
10:15:56 /iissamples/..%2f..%2f..%2f..%2fwinnt/system32/cmd.exe 82.59.61.17
10:15:58 /iissamples/..%2e..%2ewinnt/system32/cmd.exe 82.59.61.17
10:15:58 /iissamples/..%5c..%5cwinnt/system32/cmd.exe 82.59.61.17
10:16:02 /iissamples/..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe 82.59.61.17
10:16:15 /iissamples/.%2e/.%2e/.%2e/.%2e/winnt/system32/cmd.exe 82.59.61.17
10:16:17 /iissamples/.%2e/.%2e/winnt/system32/cmd.exe 82.59.61.17
10:16:21 /iishelp/..ü€€€€¯../..ü€€€€¯../winnt/system32/cmd.exe 82.59.61.17
10:16:26 /iishelp/..ø€€€¯../..ø€€€¯../winnt/system32/cmd.exe 82.59.61.17
10:16:30 /iishelp/..ð€€¯../..ð€€¯../winnt/system32/cmd.exe 82.59.61.17
10:16:32 /iishelp/..à€¯../..à€¯../winnt/system32/cmd.exe 82.59.61.17
10:16:35 /iishelp/..Á¯../..Á¯../winnt/system32/cmd.exe 82.59.61.17
Toch behoorlijk verdacht dacht ik zo