PDA

Archiv verlassen und diese Seite im Standarddesign anzeigen : Komische Zeichen im thttpd.log



Spike05
08.08.02, 15:53
217.82.194.8 - - [28/Jul/2002:21:54:29 +0200] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 0 "" ""
217.82.194.8 - - [28/Jul/2002:21:54:34 +0200] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 0 "" ""
80.136.237.214 - - [31/Jul/2002:22:01:11 +0200] "GET / HTTP/1.1" 200 557 "" "Mozilla/5.0 Galeon/1.2.5 (X11; Linux i686; U;) Gecko/20020623 Debian/1.2.5-0.woo"
80.136.237.214 - - [31/Jul/2002:22:01:11 +0200] "GET /1.gif HTTP/1.1" 200 27097 "http://jp25.dyndns.org/" "Mozilla/5.0 Galeon/1.2.5 (X11; Linux i686; U;) Gecko/20020623 Debian/1.2.5-0.woo"
127.0.0.1 - - [07/Aug/2002:19:48:13 +0200] "GET /debianplanet/backend.php HTTP/1.0" 404 0 "" "gnome-vfs/1.0.5"
211.22.26.186 - - [07/Aug/2002:20:58:34 +0200] "GET /default.ida?NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN HTTP/1.0" 404 0 "" ""
127.0.0.1 - - [07/Aug/2002:21:08:13 +0200] "GET /cgi-bin/mgetmetar.pl?cccc=EDDM HTTP/1.0" 404 0 "" "gnome-vfs/1.0.5"
217.82.75.61 - - [07/Aug/2002:22:05:04 +0200] "HEAD /1.gif HTTP/1.1" 304 0 "http://www.lfs-tipps.de/forums/showthread.php?s=&postid=169#post169" "Mozilla/5.0 Galeon/1.2.5 (X11; Linux i686; U;) Gecko/20020623 Debian/1.2.5-0.woo"
217.82.75.61 - - [07/Aug/2002:22:33:20 +0200] "GET / HTTP/1.1" 200 816 "http://www.lfs-tipps.de/forums/member.php?s=&action=getinfo&userid=6" "Mozilla/5.0 Galeon/1.2.5 (X11; Linux i686; U;) Gecko/20020623 Debian/1.2.5-0.woo"
217.82.75.61 - - [07/Aug/2002:22:33:20 +0200] "GET /4.gif HTTP/1.1" 200 17152 "http://jp25.dyndns.org/" "Mozilla/5.0 Galeon/1.2.5 (X11; Linux i686; U;) Gecko/20020623 Debian/1.2.5-0.woo"
217.82.75.61 - - [07/Aug/2002:22:33:20 +0200] "GET /penguin.gif HTTP/1.1" 200 51793 "http://jp25.dyndns.org/" "Mozilla/5.0 Galeon/1.2.5 (X11; Linux i686; U;) Gecko/20020623 Debian/1.2.5-0.woo"
217.82.75.61 - - [07/Aug/2002:22:35:44 +0200] "GET / HTTP/1.1" 200 632 "http://www.lfs-tipps.de/forums/member.php?s=&action=getinfo&userid=6" "Mozilla/5.0 Galeon/1.2.5 (X11; Linux i686; U;) Gecko/20020623 Debian/1.2.5-0.woo"
127.0.0.1 - - [07/Aug/2002:22:38:47 +0200] "GET /debianplanet/backend.php HTTP/1.0" 404 0 "" "gnome-vfs/1.0.5"
127.0.0.1 - - [07/Aug/2002:22:38:47 +0200] "GET /cgi-bin/mgetmetar.pl?cccc=EDMA HTTP/1.0" 404 0 "" "gnome-vfs/1.0.5"
217.81.95.44 - - [07/Aug/2002:22:48:21 +0200] "GET /Shakira.mp3 HTTP/1.1" 200 112734 "http://jp25.dyndns.org/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Q312461)"
217.82.75.61 - - [07/Aug/2002:23:18:51 +0200] "HEAD / HTTP/1.1" 304 0 "" "Mozilla/5.0 Galeon/1.2.5 (X11; Linux i686; U;) Gecko/20020623 Debian/1.2.5-0.woo"
127.0.0.1 - - [08/Aug/2002:11:59:57 +0200] "GET /debianplanet/backend.php HTTP/1.0" 404 0 "" "gnome-vfs/1.0.5"
217.82.73.111 - - [08/Aug/2002:14:32:07 +0200] "HEAD / HTTP/1.1" 304 0 "" "Mozilla/5.0 Galeon/1.2.5 (X11; Linux i686; U;) Gecko/20020623 Debian/1.2.5-0.woo"
218.5.74.4 - - [08/Aug/2002:14:59:00 +0200] "UNKNOWN UNKNOWN" 400 0 "" ""
127.0.0.1 - - [08/Aug/2002:15:00:03 +0200] "GET /cgi-bin/mgetmetar.pl?cccc=EDDS HTTP/1.0" 404 0 "" "gnome-vfs/1.0.5"
150.208.12.108 - - [08/Aug/2002:15:29:49 +0200] "GET /default.ida?NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN HTTP/1.0" 404 0 "" ""
80.129.249.107 - - [08/Aug/2002:16:17:17 +0200] "GET / HTTP/1.1" 200 632 "http://www.linuxforen.de/forums/showthread.php?threadid=40542" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Q312461)"
80.129.249.107 - - [08/Aug/2002:16:17:20 +0200] "GET /1.gif HTTP/1.1" 200 27097 "http://jp25.dyndns.org/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Q312461)"


Hab die Sachen mal Fett gemacht! Was hat das zu bedeuten?

boxa
08.08.02, 16:33
hier versucht ein mit dem code red infizierter rechner deinen server anzugreifen. keine sorge code red lebt auf windoof servern. am besten du versucht rauszukriegen von wenn die einträge kommen. danach den verantwortlichen aufmerksam machen, dass sein server infiziert ist. es ist schon bedauerlich, dass dieser admin immernoch keine massnahmen gegen code red getroffen hat. ich habe diese einträge übrigens auch mehrmals pro woche. mittlererweile ignoriere ich diese einfach

Spike05
08.08.02, 17:06
Weiß schon das mir Code Red nicht wirklich was anhaben kann! Nur die vielen NNNNNN haben mich ein bißchen stutzig gemacht! Das ich dauern logs von Windoof Rechnern habe die infiziert ist mir ja schon klar!!! :D

Jorge
08.08.02, 18:33
Dadurch wird wohl versucht einen Buffer Overflow oder so was zu erzwingen, wer weiss das schon.

Spike05
08.08.02, 18:41
Solange das mir nichts ausmacht, ist es mir egal!