為什么總是有人在做怪! - PCZONE 討論區

返回   PCZONE 討論區 > ▲ ADSL_CABLE_FTTH 寬 頻 上 網 討 論 > -- 防 駭 / 防 毒 版


PCZONE 討論區



通知

-- 防 駭 / 防 毒 版 不論你是使用固定 IP 或是 DHCP 一定都有機會被無聊的駭客入侵 , 來這裡跟大家作防駭以及防毒的心得與資訊分享。

.
為什么總是有人在做怪!
以下我的apache的log
但是,覺得蠻怪的是我是用linux redhat7.3的 確出現有cmd.exe我又沒這個檔@@



[Sat Jun 22 21:34:12 2002] [error] [client 61.157.94.132] File does not exist: /var/www/html/scripts/root.exe
[Sat Jun 22 21:34:16 2002] [error] [client 61.157.94.132] File does not exist: /var/www/html/MSADC/root.exe
[Sat Jun 22 21:34:19 2002] [error] [client 61.157.94.132] File does not exist: /var/www/html/c/winnt/system32/cmd.exe
[Sat Jun 22 21:34:22 2002] [error] [client 61.157.94.132] File does not exist: /var/www/html/d/winnt/system32/cmd.exe
[Sat Jun 22 21:34:25 2002] [error] [client 61.157.94.132] File does not exist: /var/www/html/scripts/..%5c../winnt/system32/cmd.exe
[Sat Jun 22 21:34:28 2002] [error] [client 61.157.94.132] File does not exist: /var/www/html/_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe
[Sat Jun 22 21:34:31 2002] [error] [client 61.157.94.132] File does not exist: /var/www/html/_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe
[Sat Jun 22 21:34:34 2002] [error] [client 61.157.94.132] File does not exist: /var/www/html/msadc/..%5c../..%5c../..%5c/..? ../..? ../..? ../winnt/system32/cmd.exe
[Sat Jun 22 21:34:37 2002] [error] [client 61.157.94.132] File does not exist: /var/www/html/scripts/..? ../winnt/system32/cmd.exe
[Sat Jun 22 21:34:43 2002] [error] [client 61.157.94.132] File does not exist: /var/www/html/scripts/..嶸../winnt/system32/cmd.exe
[Sat Jun 22 21:34:46 2002] [error] [client 61.157.94.132] File does not exist: /var/www/html/scripts/..../winnt/system32/cmd.exe
[Sat Jun 22 21:34:55 2002] [error] [client 61.157.94.132] File does not exist: /var/www/html/scripts/..%5c../winnt/system32/cmd.exe
[Sat Jun 22 21:34:58 2002] [error] [client 61.157.94.132] File does not exist: /var/www/html/scripts/..%2f../winnt/system32/cmd.exe
[Sat Jun 22 21:41:47 2002] [error] [client 61.225.110.98] File does not exist: /var/www/html/env.cgi
[Sat Jun 22 22:06:35 2002] [error] [client 61.32.105.219] File does not exist: /var/www/html/scripts/root.exe
[Sat Jun 22 22:06:35 2002] [error] [client 61.32.105.219] File does not exist: /var/www/html/MSADC/root.exe
[Sat Jun 22 22:06:35 2002] [error] [client 61.32.105.219] File does not exist: /var/www/html/c/winnt/system32/cmd.exe
[Sat Jun 22 22:06:36 2002] [error] [client 61.32.105.219] File does not exist: /var/www/html/d/winnt/system32/cmd.exe
[Sat Jun 22 22:06:36 2002] [error] [client 61.32.105.219] File does not exist: /var/www/html/scripts/..%5c../winnt/system32/cmd.exe
[Sat Jun 22 22:06:36 2002] [error] [client 61.32.105.219] File does not exist: /var/www/html/_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe
[Sat Jun 22 22:06:37 2002] [error] [client 61.32.105.219] File does not exist: /var/www/html/_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe
[Sat Jun 22 22:06:37 2002] [error] [client 61.32.105.219] File does not exist: /var/www/html/msadc/..%5c../..%5c../..%5c/..? ../..? ../..? ../winnt/system32/cmd.exe
[Sat Jun 22 22:06:37 2002] [error] [client 61.32.105.219] File does not exist: /var/www/html/scripts/..? ../winnt/system32/cmd.exe
[Sat Jun 22 22:06:38 2002] [error] [client 61.32.105.219] File does not exist: /var/www/html/scripts/..嶸../winnt/system32/cmd.exe
[Sat Jun 22 22:06:38 2002] [error] [client 61.32.105.219] File does not exist: /var/www/html/scripts/..../winnt/system32/cmd.exe
[Sat Jun 22 22:06:39 2002] [error] [client 61.32.105.219] File does not exist: /var/www/html/scripts/..%5c../winnt/system32/cmd.exe
[Sat Jun 22 22:06:40 2002] [error] [client 61.32.105.219] File does not exist: /var/www/html/scripts/..%2f../winnt/system32/cmd.exe

回覆
校長兼撞鐘

那是病毒試著要攻擊 WEB SERVER , 攻擊的目標不是 Linux or BSD

看那幾行 LOG , 就知道是要攻擊 Windows 下的 IIS SERVER , 可能是 Nimda 病毒
回覆
.

嘿嘿.....找我沒用

QQ"我不是IIS的
回覆
會員

之前也常常發生這種情況....
還一天來3次.照三餐來>.<....
回覆
LJI
北海道的熊

就是有人這麼無聊.....家裡面也用APACHE架了站....只是方便朋友看圖檔
剛剛去看了一下LOG........果然也有人要攻擊我的電腦.....真是夠了..><
回覆
會員

我學校的WebServer使用Win2000中了Nimda,一天到晚沒事就亂搞,所以我的Apache紀錄檔也有一大堆這樣的紀錄,告訴學校網頁主機的負責人,他說我胡說,叫我不要亂講話!唉,上面明明有IP,就是因為這樣學校的電腦我才不想管!可是這樣一來校長、主任又說我不配合,真想有一天要搞死校園網路,反正以他們的程度一定抓不到證據,問題是:他們要怪罪於人似乎不必講證據!真是!@#$%^^
回覆
會員

中了 Nimda 的機器,只要不解毒完成,就會繼續一直在攻擊別人。
不是有人太無聊,是有網管太懶散,主機中毒的都不知道 ......
比較火大時,就給它玩回去,砍它檔案 ....

回覆







 XML   RSS 2.0   RSS 
本站使用 vBulletin 合法版權程式
站務信箱 : [email protected]

本論壇所有文章僅代表留言者個人意見,並不代表本站之立場,討論區以「即時留言」方式運作,故無法完全監察所有即時留言,若您發現文章可能有異議,請 email :[email protected] 處理。