Apache Development
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationApache Development

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old December 31st, 2001, 09:11 AM
pgreen50 pgreen50 is offline
Junior Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2001
Posts: 22 pgreen50 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Security Worry!!!

I have checked my access log on Apache & have found several entries some of which i have placed below. Does this meen that someone has accessed my actual harddrive???

"GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 316

62.254.163.34 - - [31/Dec/2001:06:32:21 +0000] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 315

The IP address is not my own, but may be that of my ISP provider. I am a little confused as i have not really started to promote my web site for people to access as of yet

Worried

Phil

Reply With Quote
  #2  
Old December 31st, 2001, 09:19 AM
freebsd freebsd is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2001
Posts: 5 freebsd User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Have you ever heard of CodeRed?

Reply With Quote
  #3  
Old December 31st, 2001, 09:22 AM
pgreen50 pgreen50 is offline
Junior Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2001
Posts: 22 pgreen50 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
I have heard the term i have full virus protection enabled & have scanned for the virus 1 & 2, not traces Etc found. did the sample of log that i submitted lead you to believe that this is the culprit.

Kind regards


Phil

Last edited by pgreen50 : December 31st, 2001 at 09:30 AM.

Reply With Quote
  #4  
Old December 31st, 2001, 09:30 AM
freebsd freebsd is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2001
Posts: 5 freebsd User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
>> but no nothing about it

Why don't you search google using the exact log entry as your search keyword?

GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 315

>> Could you please explain further

It has been well-explained all over the web.

>> does the sample of log that i submitted lead you to believe that this is the culprit

CodeRed version 2.

Asking such question at this time tells me you are likely first day running a web server. CodeRed has been discovered for age, it's not something new recently.

Finally, just don't worry if you are running Apache.

Reply With Quote
  #5  
Old December 31st, 2001, 09:31 AM
pgreen50 pgreen50 is offline
Junior Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2001
Posts: 22 pgreen50 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
I have done all you have just posted & scanned Etc. I did not mean to waste your time.

Regards

Phil

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationApache Development > Security Worry!!!


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 3 hosted by Hostway
Stay green...Green IT