Printer Friendly Version Print this thread
Email this thread to a friend eMail this thread to a friend
Featured Web Site Template

Hundreds More at Free Site Templates.com!

Web Site Partners
Sponsored Links
Jet City Software
 
Whos Here ?
Reflects user activity within the last 5 minutes
Moderator(s): OAC, flyingrose
Member Message

debunked
Joined: Jan 22, 2004
# Posts: 97

View the profile for debunked Send debunked a private message

Posted: 2004-May-11 20:24
Edit Message Delete Message Reply to this message

This is on our awstats logs a few times this month:
/scripts/..%c1%1c../winnt/system32/cmd.exe

it is under our pages not found list.

Thanks




Webmaster-Toolkit.com
Joined: Jul 18, 2002
# Posts: 1098

View the profile for Webmaster-Toolkit.com Send Webmaster-Toolkit.com a private message

Posted: 2004-May-11 20:32
Edit Message Delete Message Reply to this message

Looks like the slammer worm having a try at your server



unreviewed
Joined: Dec 07, 2000
# Posts: 6776

View the profile for unreviewed Send unreviewed a private message

Posted: 2004-May-11 21:33
Edit Message Delete Message Reply to this message

debunked, WT is correct. There are thousands of infected computers out there. Many are running old copies of IIS, installed by default and not even in use as web servers.

Every web master will see those type of entry's on a daily bases. Nothing you can do about it. You can start blocking IP's, but that gets old pretty quick, not to mention your server must take the time to compare all incoming traffic with your growing database of blocked IP's.

Besides, what they are designed to look for and exploit, is no longer a threat with any up to date system. That's not to say new ones can't harm you, but you can usually tell an old one, and other ineffective requests, by the fact that they generate a 404 error code.



Webmaster-Toolkit.com
Joined: Jul 18, 2002
# Posts: 1098

View the profile for Webmaster-Toolkit.com Send Webmaster-Toolkit.com a private message

Posted: 2004-May-11 22:28
Edit Message Delete Message Reply to this message

Thanks unreviewed for explaining it better than I ever could smile

I personally get hundreds of such access a day, yet I'm on a linux server - you'd think the virus author could at least add some sort of check on what software the server is using - sloppy programming mr virus writer rolleyeys


You are not permitted to post messages in this forum or topic, because of one or more of the following reasons:
  1. You have not yet logged in, or registered properly as a member
  2. You are a member, but no longer have posting rights.
  3. This is a private forum, for which you do not have permissions.

If you are a recent member, it's possible that you simply have not yet confirmed your account. Please check your email for a message entitled 'JimWorld Forums: Confirm Your Account' and follow the instructions contained within.

If you cannot find this message, click here to Re-Send it.

If you are still experiencing problem, please read the Login Assistance Article for some advice on what may be causing your login not to work properly.

Switch to Advanced Editor and ... Create a New Topic or Reply to this Thread

New posts Forum is locked
© 1995  ·  iWeb, Inc  ·  DBA JimWorld Productions