
03-29-2002, 09:57 PM
|
|
WHT Addict
|
|
Join Date: Mar 2002
Posts: 146
|
|
Is someone trying to hack me?
I looked at the error logs for my site ( http://www.highboard.com , hosted on site5.com ) and happened to notice than one IP address had seen errors like this:
/home/highboar/public_html/scripts/..À¯../winnt/system32/cmd.exe
about 10 consecutive times within the space of about a minute. It looks suspicious to me, but then I really don't know what it is...
any ideas?
|

03-29-2002, 10:06 PM
|
|
Web Hosting Master
|
|
Join Date: Jan 2002
Location: Melbourne, AU
Posts: 740
|
|
If you're on a linux box, there is no need to worry.
Had a heap of those myself, it's just the 'script kiddies' trying to find something open.
Lats...
|

03-29-2002, 10:33 PM
|
|
Web Hosting Master
|
|
Join Date: Dec 2001
Posts: 1,029
|
|
It's not script kiddies. It's either the Code Red or NIMDA worm trying to propagate. The people that are affected usually don't know their computer is infected and are not trying to intentionally do any damage. This only affects some versions of IIS, so if you're on a UNIX or Linux server, there's nothing to worry about. Just ignore it.
|

03-29-2002, 10:33 PM
|
|
Web Hosting Master
|
|
Join Date: Aug 2001
Posts: 615
|
|
Err... No I think that is the code red virus or nimda. Search the forum for cmd.exe or code red or nimda. You will find similar results.
__________________
So we finish the 18th and he's gonna stiff me. And I say, "Hey, Lama, hey, how about a little something, you know, for the effort, you know?" And he says, 'Oh, there won't be any money. But when you die, on your deathbed, you will receive total consciousness.' So I got that goin' for me, which is nice." --Bill Murray Caddyshack
|

03-30-2002, 03:24 AM
|
|
Junior Guru
|
|
Join Date: Mar 2002
Posts: 189
|
|
Yes, it's NIMDA worm as ToastyX said. If you are in UNIX/LINUX then dont worry. but it is really annoying, when you see lots of attempts made to infect the server.
|

03-30-2002, 06:08 AM
|
|
Junior Guru
|
|
Join Date: Dec 2001
Location: Blackpool, England
Posts: 180
|
|
Yep @ a virus trying to propogate.
Basically this exploits abig dumb ass security hole that microsoft left in iis for many many versions... you can access any file on the computer by doing the 'root exploit' (dont know what its called under M$-oses so ill use the linux term).
So all you NT-hosters beware!!! And move to some sort of *nix host today and sleep more soundly at night  :
|

03-30-2002, 11:25 PM
|
|
Web Hosting Evangelist
|
|
Join Date: Dec 2001
Location: Arizona
Posts: 460
|
|
Yes that is Nimda as everyone said. Don't worry if you're on Unix/Linux. Never got into our Windows servers 
|

04-01-2002, 03:59 PM
|
|
Newbie
|
|
Join Date: Mar 2002
Posts: 7
|
|
i have these on my site too .. its annoying as hell i was actually thinking of creating a small script in that particular location to send something NICE to the user
regards,
n.
|

04-01-2002, 04:21 PM
|
|
Web Hosting Evangelist
|
|
Join Date: Dec 2001
Location: Arizona
Posts: 460
|
|
Quote:
Originally posted by netguy
i have these on my site too .. its annoying as hell i was actually thinking of creating a small script in that particular location to send something NICE to the user 
regards,
n.
|
haha, what did you have in mind?
|

04-01-2002, 06:04 PM
|
|
Web Hosting Master
|
|
Join Date: Nov 2000
Location: Boston, MA (USA)
Posts: 773
|
|
How come everyone makes worms and virii to infect microsoft's software 
|

04-01-2002, 06:50 PM
|
|
Newbie
|
|
Join Date: Mar 2002
Posts: 7
|
|
hmm .. how about take the ip of the user , do a nmap on it , display the results to the guy trying ..so he gets a message like
hello dear.
you are trying to hack me but you have these ports open
regards,
n.
|

04-01-2002, 06:54 PM
|
|
Web Hosting Evangelist
|
|
Join Date: Dec 2001
Location: Arizona
Posts: 460
|
|
Last edited by Maniac; 04-03-2002 at 09:00 PM.
|

04-01-2002, 08:25 PM
|
|
Junior Guru
|
|
Join Date: Oct 2001
Posts: 179
|
|
Quote:
Originally posted by netguy
hmm .. how about take the ip of the user , do a nmap on it , display the results to the guy trying ..so he gets a message like
hello dear.
you are trying to hack me but you have these ports open 
regards,
n.
|
Thats missing the whole point! This is a self propogating WORM.. re-read ToastyX's post. Perhaps something like:
To whom it may concern:
Your server is infected with Code Red / Nimda!
http://linktopatch.microsoft.com
....
|

04-03-2002, 09:01 PM
|
|
Web Hosting Evangelist
|
|
Join Date: Dec 2001
Location: Arizona
Posts: 460
|
|
JDF, that link does not work. Thought I'd tell you..
|

04-03-2002, 09:18 PM
|
|
Web Hosting Master
|
|
Join Date: Dec 2001
Posts: 1,029
|
|
My goodness! You're so literal.  He just used that as an example address.
|
| Thread Tools |
Search this Thread |
|
|
|
| Display Modes |
Linear Mode
|
| Postbit Selector |
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
|
|
|
| Login: |
|
|
| Advertisement: |
|
|
| Web Hosting News: |
|
|
|