Recently I discovered this in my logs. Note the times and the changing IP addresses. The addresses seem to map back to ARIN APNIC & RIPE. Can anyone shed any light on this?
#Software: Microsoft Internet Information Services 5.0
#Version: 1.0
#Date: 2003-08-18 16:26:12 (11:26:12 central time)
#Fields: date time c-ip cs-username s-sitename s-computername s-ip s-port cs-method cs-uri-stem cs-uri-query sc-status sc-bytes cs-bytes time-taken cs-version cs-host cs(User-Agent) cs(Cookie) cs(Referer)
2003-08-18 16:26:12 210.54.216.202 - W3SVC749 HOMER 65.211.123.68 80 GET /cgi-bin/formmail.pl - 404 4203 109 0 HTTP/1.1 - - 2003-08-18 16:26:22 203.96.111.237 - W3SVC749 HOMER 65.211.123.68 80 GET /cgi-bin/formmail.cgi - 404 4184 152 0 HTTP/1.0 - - 2003-08-18 16:26:24 210.54.216.202 - W3SVC749 HOMER 65.211.123.68 80 GET /cgi-bin/FormMail.pl - 404 4203 109 0 HTTP/1.1 - - 2003-08-18 16:26:42 195.229.241.235 - W3SVC749 HOMER 65.211.123.68 80 GET /cgi-bin/FormMail.cgi - 404 4203 138 0 HTTP/1.1 - - 2003-08-18 16:26:43 195.229.241.235 - W3SVC749 HOMER 65.211.123.68 80 GET /cgi-sys/formmail.pl - 404 4203 137 0 HTTP/1.1 - - 2003-08-18 16:26:44 195.229.241.235 - W3SVC749 HOMER 65.211.123.68 80 GET /cgi-sys/formmail.cgi - 404 4203 138 0 HTTP/1.1 - - 2003-08-18 16:26:45 195.229.241.235 - W3SVC749 HOMER 65.211.123.68 80 GET /cgi-sys/FormMail.pl - 404 4203 137 0 HTTP/1.1 - - 2003-08-18 16:26:50 195.229.241.235 - W3SVC749 HOMER 65.211.123.68 80 GET /cgi-bin/Formmail.pl - 404 4203 137 0 HTTP/1.1 - - 2003-08-18 16:26:52 195.229.241.235 - W3SVC749 HOMER 65.211.123.68 80 GET /cgi-bin/mail.pl - 404 4203 133 0 HTTP/1.1 - - 2003-08-18 16:26:53 195.229.241.235 - W3SVC749 HOMER 65.211.123.68 80 GET /cgi-bin/FORMMAIL.PL - 404 4203 137 0 HTTP/1.1 - - 2003-08-18 16:26:55 210.54.216.202 - W3SVC749 HOMER 65.211.123.68 80 GET /cgi-bin/FormMail.cgi - 404 4203 110 0 HTTP/1.1 - -
Clive
#Software: Microsoft Internet Information Services 5.0
#Version: 1.0
#Date: 2003-08-18 16:26:12 (11:26:12 central time)
#Fields: date time c-ip cs-username s-sitename s-computername s-ip s-port cs-method cs-uri-stem cs-uri-query sc-status sc-bytes cs-bytes time-taken cs-version cs-host cs(User-Agent) cs(Cookie) cs(Referer)
2003-08-18 16:26:12 210.54.216.202 - W3SVC749 HOMER 65.211.123.68 80 GET /cgi-bin/formmail.pl - 404 4203 109 0 HTTP/1.1 - - 2003-08-18 16:26:22 203.96.111.237 - W3SVC749 HOMER 65.211.123.68 80 GET /cgi-bin/formmail.cgi - 404 4184 152 0 HTTP/1.0 - - 2003-08-18 16:26:24 210.54.216.202 - W3SVC749 HOMER 65.211.123.68 80 GET /cgi-bin/FormMail.pl - 404 4203 109 0 HTTP/1.1 - - 2003-08-18 16:26:42 195.229.241.235 - W3SVC749 HOMER 65.211.123.68 80 GET /cgi-bin/FormMail.cgi - 404 4203 138 0 HTTP/1.1 - - 2003-08-18 16:26:43 195.229.241.235 - W3SVC749 HOMER 65.211.123.68 80 GET /cgi-sys/formmail.pl - 404 4203 137 0 HTTP/1.1 - - 2003-08-18 16:26:44 195.229.241.235 - W3SVC749 HOMER 65.211.123.68 80 GET /cgi-sys/formmail.cgi - 404 4203 138 0 HTTP/1.1 - - 2003-08-18 16:26:45 195.229.241.235 - W3SVC749 HOMER 65.211.123.68 80 GET /cgi-sys/FormMail.pl - 404 4203 137 0 HTTP/1.1 - - 2003-08-18 16:26:50 195.229.241.235 - W3SVC749 HOMER 65.211.123.68 80 GET /cgi-bin/Formmail.pl - 404 4203 137 0 HTTP/1.1 - - 2003-08-18 16:26:52 195.229.241.235 - W3SVC749 HOMER 65.211.123.68 80 GET /cgi-bin/mail.pl - 404 4203 133 0 HTTP/1.1 - - 2003-08-18 16:26:53 195.229.241.235 - W3SVC749 HOMER 65.211.123.68 80 GET /cgi-bin/FORMMAIL.PL - 404 4203 137 0 HTTP/1.1 - - 2003-08-18 16:26:55 210.54.216.202 - W3SVC749 HOMER 65.211.123.68 80 GET /cgi-bin/FormMail.cgi - 404 4203 110 0 HTTP/1.1 - -
Clive