Ik krijg regelmatig rare gets in mn IIS logfiles te zien. Hieronder een stukje:
15:54:38 ***.***.***.*** /scripts/root.exe
15:54:38 ***.***.***.*** /MSADC/root.exe
15:54:40 ***.***.***.*** /c/winnt/system32/cmd.exe
15:54:40 ***.***.***.*** /d/winnt/system32/cmd.exe
15:54:42 ***.***.***.*** /scripts/..%c../winnt/system32/cmd.exe
15:54:42 ***.***.***.*** /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe
15:54:43 ***.***.***.*** /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe
15:54:44 ***.***.***.*** /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe
15:54:44 ***.***.***.*** /scripts/..Á../winnt/system32/cmd.exe
15:54:46 ***.***.***.*** /scripts/winnt/system32/cmd.exe
15:54:47 ***.***.***.*** /winnt/system32/cmd.exe
15:54:48 ***.***.***.*** /winnt/system32/cmd.exe
15:54:48 ***.***.***.*** /scripts/..%5c../winnt/system32/cmd.exe
15:54:50 ***.***.***.*** /scripts/..%5c../winnt/system32/cmd.exe
15:54:51 ***.***.***.*** /scripts/..%5c../winnt/system32/cmd.exe
15:54:51 ***.***.***.*** /scripts/..%2f../winnt/system32/cmd.exe
Is dat iemand die exploits probeert? of staat er iets open ofzo?
Het rare is dat vandaag al 5 verschillende ip's dit gedaan hebben, lijkt me niet goed
15:54:38 ***.***.***.*** /scripts/root.exe
15:54:38 ***.***.***.*** /MSADC/root.exe
15:54:40 ***.***.***.*** /c/winnt/system32/cmd.exe
15:54:40 ***.***.***.*** /d/winnt/system32/cmd.exe
15:54:42 ***.***.***.*** /scripts/..%c../winnt/system32/cmd.exe
15:54:42 ***.***.***.*** /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe
15:54:43 ***.***.***.*** /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe
15:54:44 ***.***.***.*** /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe
15:54:44 ***.***.***.*** /scripts/..Á../winnt/system32/cmd.exe
15:54:46 ***.***.***.*** /scripts/winnt/system32/cmd.exe
15:54:47 ***.***.***.*** /winnt/system32/cmd.exe
15:54:48 ***.***.***.*** /winnt/system32/cmd.exe
15:54:48 ***.***.***.*** /scripts/..%5c../winnt/system32/cmd.exe
15:54:50 ***.***.***.*** /scripts/..%5c../winnt/system32/cmd.exe
15:54:51 ***.***.***.*** /scripts/..%5c../winnt/system32/cmd.exe
15:54:51 ***.***.***.*** /scripts/..%2f../winnt/system32/cmd.exe
Is dat iemand die exploits probeert? of staat er iets open ofzo?
Het rare is dat vandaag al 5 verschillende ip's dit gedaan hebben, lijkt me niet goed