Jonax
Programmer
- Aug 22, 2001
- 210
Hi all,
a friend of mine asked showed me his iis-logfile and asked me if I knew just what the **** was going on... I must admit I didn't, but I guess somebody does, so here goes:
His logfile is full of entries like these:
(note: I've stripped the dates and the IPs)
Is this a hack-attempt? A Backdoor? A spider? The server itself?
I tried doing a reverse lookup on the client IP - but to no avail...
I'd realle appreciate any pointers on this, as I would like to help him restore his peace of mind
BTW: It's running on a terminal server...
TIA
Jonax
This is not a bug - it's an undocumented feature...
;-)
a friend of mine asked showed me his iis-logfile and asked me if I knew just what the **** was going on... I must admit I didn't, but I guess somebody does, so here goes:
His logfile is full of entries like these:
Code:
80 GET /winnt/system32/cmd.exe /c+dir 404 -
80 GET /scripts/..%5c../winnt/system32/cmd.exe /c+dir 500 -
Is this a hack-attempt? A Backdoor? A spider? The server itself?
I tried doing a reverse lookup on the client IP - but to no avail...
I'd realle appreciate any pointers on this, as I would like to help him restore his peace of mind
BTW: It's running on a terminal server...
TIA
Jonax
This is not a bug - it's an undocumented feature...
;-)