slade
09-18-2001, 02:16 PM
Three different machines in IP ranges that start 64.x.x.x just hit one of my linux boxes asking for these files: (in approximately the same order)
public_html/scripts/..%2f../winnt/system32/cmd.exe
public_html/scripts/..%5c../winnt/system32/cmd.exe
public_html/scripts/..Á?../winnt/system32/cmd.exe
public_html/scripts/..À¯../winnt/system32/cmd.exe
public_html/scripts/..Á../winnt/system32/cmd.exe
public_html/msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe
public_html/_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe
public_html/_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe
public_html/scripts/..%5c../winnt/system32/cmd.exe
public_html/d/winnt/system32/cmd.exe
public_html/c/winnt/system32/cmd.exe
public_html/MSADC/root.exe
public_html/scripts/root.exe
I'm glad I opted for Linux.
Note: These all were within the last 45 mins. Also, this is log format, so bottom request was first.
public_html/scripts/..%2f../winnt/system32/cmd.exe
public_html/scripts/..%5c../winnt/system32/cmd.exe
public_html/scripts/..Á?../winnt/system32/cmd.exe
public_html/scripts/..À¯../winnt/system32/cmd.exe
public_html/scripts/..Á../winnt/system32/cmd.exe
public_html/msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe
public_html/_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe
public_html/_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe
public_html/scripts/..%5c../winnt/system32/cmd.exe
public_html/d/winnt/system32/cmd.exe
public_html/c/winnt/system32/cmd.exe
public_html/MSADC/root.exe
public_html/scripts/root.exe
I'm glad I opted for Linux.
Note: These all were within the last 45 mins. Also, this is log format, so bottom request was first.
