rejetto forum

Strange Log Enteries

0 Members and 1 Guest are viewing this topic.

Offline maverick

  • Tireless poster
  • ****
    • Posts: 1052
  • Computer Solutions
    • View Profile
.
Can anyone tell me what these HFS log enteries might be about?  (I removed the IP address from below).  

xx.xxx.xx.xxx:4483 Requested GET /scripts/..À/../winnt/system32/cmd.exe?/c dir

xx.xxx.xx.xxx:4512 Requested GET /scripts/..À¯../winnt/system32/cmd.exe?/c dir

xx.xxx.xx.xxx:4520 Requested GET /scripts/..Á?../winnt/system32/cmd.exe?/c dir

xx.xxx.xx.xxx:4524 Requested GET /scripts/..%5c../winnt/system32/cmd.exe?/c dir

xx.xxx.xx.xxx:4532 Requested GET /scripts/..%5c../winnt/system32/cmd.exe?/c dir

xx.xxx.xx.xxx:4540 Requested GET /scripts/..%5c../winnt/system32/cmd.exe?/c dir

xx.xxx.xx.xxx:4547 Requested GET /scripts/..%2f../winnt/system32/cmd.exe?/c dir

xx.xxx.xx.xxx:4432 Requested GET /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe?/c dir

xx.xxx.xx.xxx:4474 Requested GET /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe?/c dir

xx.xxx.xx.xxx:4520 Requested GET /scripts/..%5c../winnt/system32/cmd.exe?/c dir

I was online when I got those in a 5 sec period then I shut down the server.  The IP address that those came from was from nobody that was logged in.  Looks like somebody wanted access to my system through DOS.

Any ideas?

maverick
maverick


Offline MarkV

  • Tireless poster
  • ****
    • Posts: 764
    • View Profile
From what I know, the computer trying to contact you is infected with some sort of worm/virus. This worm is trying to exploit a known vulnerability of Windows/IIS to get access to your machine. TMK, HFS has no (known) vulnerability ATM, so sit back and relax.

MarkV
http://worldipv6launch.org - The world is different now.


Anonymous

  • Guest
That looks like someone is trying to hack IIS on your system.

Make sure to stop (set to manual) IIS admin services in the services console in windows.


Anonymous

  • Guest
also make sure to do windows update and update the latest patches...


Offline TGeRi

  • Tireless poster
  • ****
    • Posts: 113
    • View Profile
he is using hfs so he doesn't have to worry about that attempt.


Azag

  • Guest
Quote from: "Anonymous"
That looks like someone is trying to hack IIS on your system.

Make sure to stop (set to manual) IIS admin services in the services console in windows.

 :lol:  :P
Silly hackerz..probably with automated IIS hack tool for penatration testing :roll:
This is all to common but not to worry as was said unless u are running or have IIS set up on ur PC then u need not worry about it. U could report him with a copy of your log(s) to his/her ISP but unless this is same idiot over and over ur probably gonna be wasting your time as most ISP get these type of reports all the time and unless ur a buig business or govt org. than they will ignore it and/or delete ur request sadly and u probably would NOT wasnt to report such things that might get back to ur own ISP (remote chance) because unless u are on a business connection or package, u are most likely violating your own TOS for use with ur ISP if u run any online SERVER or software so be careful NOT to ever tell them and best to 'keep it on the down low'  :twisted:  :lol:
Also if for some reason u have IIS installed on your system and never use or need it then uninstall and save ur self the headache and enjoyy the peace of mind that your more secure without it...
BTW i would never use IIS because it has new security exploits/issues/patches all the time it is crap unless u want to harden it and check for patches/sploits every day this isn't for the lazy or fair of heart...stick w/ HFS it has no exploit issues that i can find that are public as of yet and I look at security sites and pen-test my self all the time.  But always  remember the is no security program or setup or program that is 100% hack proof and there never will be. This much I can say with certainty. Security is a game of cat n mouse and one-up-man-ship so always be on ur toes and don't get cocky thinking ur ever hack proof..just have good security practices and backup things often and on a regular basis. Now breathe easy B)  :lol:  ;)


Offline maverick

  • Tireless poster
  • ****
    • Posts: 1052
  • Computer Solutions
    • View Profile
.
No I have never used or installed IIS on my systems mainly because of all the on-going exploits.  I read up and go to many security sites too.

maverick
maverick