Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Weird IIS logs (c+dir?!?!?!)

Status
Not open for further replies.

ktigre

MIS
Mar 14, 2002
13
0
0
US
I'm getting a bunch of weird things showing up in my logs. They all start off different but always end in cmd.exe?/c+dir?/d+dir and have no referrer. The IP address that has generated most of the is 61.139.60.89. It doesn't resolve on DNS so I can't get anykind of a name for it. A couple of the other offenders are : 207.88.219.2 and 218.21.77.29. There are more, but those are the ones generating the most hits...

If anyone has any insight to this please let me know. :)

Thanks,
Chris
 
Chris,

Most likely these are machines infected with the nimda virus scanning for other IIS servers to infect. As long as your machine has the appropriate patches there is nothing to worry about.
 
However we use Webtrends to generate reports based upon the IIS logs and get it is critical that these logs be accurate as to whom accesses our sites. other than simply cutting off the IP addresses that are broadcasting at our firewall, is there any way to stop them from occurring?
 
I believe you should be able to setup your firewall to filter this out. What type of firewall are you running?
 
I recommend putting the NIMDA block on your routers. Why have all that traffic hitting your servers? It will really not put much strain on your routers. I run it here and it works great. I used to be 10-20% of our traffic to our site. Also if a new worm comes out it would be very simple to add a rule to block it.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top