Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Our Archives > General Archives > Servers > apache log with strange entries

 
apache log with strange entries
Thread Tools
Junior Member
Join Date: Nov 2001
Status: Offline
Jul 17, 2003, 12:38 AM
 
I checked my apache log for the first time, and 99.9% of it are these:
/Jul/2003:00:34:07 -0500] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 291
1

24.242.2.66 - - [16/Jul/2003:00:34:08 -0500] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 291
1

24.242.2.66 - - [16/Jul/2003:00:34:08 -0500] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 308
1

24.242.2.66 - - [16/Jul/2003:00:34:08 -0500] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 308
I read on another post that this has something to do with nimda. It is coming from several different IP addresses, with only the recent ones (like within 30 min) replying a ping. Is this a problem? Should I do something about this? Thanks

ben
     
Moderator Emeritus
Join Date: Dec 2000
Location: College Park, MD
Status: Offline
Jul 17, 2003, 01:06 AM
 
It's called idiots with very unpatched servers.
Don't worry about it.
My website
Help me pay for college. Click for more info.
     
Junior Member
Join Date: Nov 2001
Status: Offline
Jul 17, 2003, 08:31 AM
 
oh, so these are deliberate attacks, like some pimply 15yo trying to hack my computer. these are just random worm attacks coming from someone elses affected server. got it.

ben
     
Mac Elite
Join Date: Dec 2001
Location: Atlanta, GA, USA
Status: Offline
Jul 18, 2003, 08:37 AM
 
Originally posted by benbargagliotti:
oh, so these are deliberate attacks, like some pimply 15yo trying to hack my computer. these are just random worm attacks coming from someone elses affected server. got it.
Nimda and code red just randomly pick IPs and try to infect them. They get lucky sometimes and hit a Windows server lacking patches. Boom, another machine is infected, and IT starts sending out attacks to random IPs. It's all very neat from a programming standpoint, but pretty pathetic from a Windows security perspective.

It's all automatic. There's no person at the other end. The virus is self-replicating.
Mac Pro 2x 2.66 GHz Dual core, Apple TV 160GB, two Windows XP PCs
     
 
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 03:55 PM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2