LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-30-2001, 12:58 PM   #1
plisken
Member
 
Registered: Dec 2001
Location: Scotland
Distribution: Slackware 9.1-15 RH 6.2/7, RHEL 6.5 SuSE 8.2/11.1, Debian 10.5
Posts: 516

Rep: Reputation: 32
Question access.log:Possible Hack attempt?


Please find below a few lines from my access.log file from apache:

.62.245.144.38 - - [30/Dec/2001:06:34:32 +0000] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 286
62.245.144.38 - - [30/Dec/2001:06:34:32 +0000] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 286
62.245.144.38 - - [30/Dec/2001:06:34:32 +0000] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 303
62.245.144.38 - - [30/Dec/2001:06:34:32 +0000] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 303


Could some one shed some light on this, is this an attempted attack of some form?

Thanks

Harry
 
Old 12-30-2001, 01:15 PM   #2
bluecadet
Member
 
Registered: Oct 2001
Distribution: MD81 RH71
Posts: 555

Rep: Reputation: 30
that's just code red / blue trying to attack M$'s IIS server. Every running apache in the world probably logs at least 5 of those attacks every single day.

i've had at least 12 so far today. i'd guess some prominent servers get literally thuosands every day at the moment.

don't worry about it. just laugh.

Last edited by bluecadet; 12-30-2001 at 01:19 PM.
 
Old 01-03-2002, 05:58 AM   #3
Linux_Native
LQ Newbie
 
Registered: Jan 2002
Location: SA
Distribution: RH7.1(Sea Wolf)
Posts: 10

Rep: Reputation: 0
Haha!!

Sit back .. and enjoy the fact that you run linux
 
Old 01-03-2002, 04:53 PM   #4
weblion
Member
 
Registered: Jun 2001
Location: Antarctica.
Distribution: Slackware
Posts: 78

Rep: Reputation: 15
Damn. Okay, third try.
I'm actually running Apache via Windows until I get my other computer working and Apache set up under linux on this comp. And in the 3 days since it went online, there have been no reports of the virus.
 
Old 01-04-2002, 01:31 AM   #5
anoop_chandran
Member
 
Registered: Nov 2001
Distribution: Redhat 7.0 ,mandrake 8.0 ,Redhat 7.2
Posts: 99

Rep: Reputation: 15
hi,
let me tell u that my apache access.log contains so many of these lines .. . bluecadet said he had 12 so far .. does each line in the log file indicate an attack?or a bunch of lines ....?how do u get that..

we have a IP in the log is it of any use ...?
 
Old 01-04-2002, 02:40 PM   #6
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Yes Anoop_chandran, each complete line represents one request made to that server, so each line can be considered an attack.

An IP address can be a spoofed address or a compromised host (human or by worm) or if they're stupid, their real addy.

If you wanted to do The Good Thing you could fire off a warning message to their upstream provider notifying them of the intrusion attempts.
Just don't expect any replies, cuz the adm staff usually is too busy doin Other Important Things, and since those stupid wintendo firewalls started making automated attack notifications noone (at ISP's) really bothers with them.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Apache logs - Hack attempt or not? lawadm1 Linux - Software 6 11-05-2004 11:53 PM
log: attempt to access beyond end of device 360 Linux - General 1 09-18-2003 07:52 PM
Mandrake crashes when I attempt to access /mnt? fakeaddress9102 Linux - Newbie 3 09-06-2003 09:59 PM
newbie question: do these logs show a hack attempt lucastic Linux - Security 4 08-13-2003 08:07 AM
not linux related, had a hack attempt neo77777 General 13 03-22-2002 04:57 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:38 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration