Computing.Net > Forums > Windows Server 2003 > server hack attempts

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

server hack attempts

Reply to Message Icon

Name: bliss
Date: June 25, 2005 at 22:27:09 Pacific
OS: XP Pro SP2
CPU/Ram: Athlon/504MB
Comment:

it seems like my server is getting hacked over and over and over and over..by the same 2 ip address. I have all the security updates available, i have my firewall enabled, im behind a router...
here is an example of the attempts:

67.172.2.184 - - [23/Jun/2005:18:12:18 -0700] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 1011
67.172.2.184 - - [23/Jun/2005:18:12:18 -0700] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 1011
67.172.2.184 - - [23/Jun/2005:18:12:18 -0700] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1011
67.172.2.184 - - [23/Jun/2005:18:12:19 -0700] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 1011
67.172.2.184 - - [23/Jun/2005:18:12:19 -0700] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 236
67.172.2.184 - - [23/Jun/2005:18:12:19 -0700] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 236
67.172.2.184 - - [23/Jun/2005:18:12:20 -0700] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 236
67.172.2.184 - - [23/Jun/2005:18:12:22 -0700] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 236
67.172.2.184 - - [23/Jun/2005:18:12:22 -0700] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 236

this b---tard especially, tries to hack me, every hour atleast.what am i doing wrong?



Sponsored Link
Ads by Google

Response Number 1
Name: Jennifer SUMN
Date: June 26, 2005 at 09:01:16 Pacific
Reply:

I show that IP as being hsd1.ct.comcast.net. Does that help you at all?


0

Response Number 2
Name: jimminy
Date: June 26, 2005 at 14:10:42 Pacific
Reply:

Those are nimda worm scans. See here for more details - in particular, scroll down to the "system footprint" section for a list of log entries you can expect to be generated by nimda.

Any public web server will be subjected to these periodically. The presence of those lines in your log files alone does not indicate that your server has been compromised or that you are the target of a directed attack. There is nothing to worry about as long as your server is patched and secured.

>>this b---tard especially, tries to hack me, every hour atleast

This "b*!@~*&%" is almost certainly an unwitting participant in the attack. His box is compromised and is being used to scan your server, among many thousands of others. Your time would be much better spent securing your systems rather than trying to react every time you are probed for vulnerabilities.

>>what am i doing wrong?

As far as I can see, nothing. You say your system is patched, which is good. That, and securely configuring your OS and daemons, are about 90% of what you need to do. I can recommend a few good mailing lists to subscribe to if you want some good reading on those subjects.


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More


Can't access extended par... exchange server 2003



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows Server 2003 Forum Home


Sponsored links

Ads by Google


Results for: server hack attempts

Server 2003 user profiles problem www.computing.net/answers/windows-2003/server-2003-user-profiles-problem/2393.html

The server freezes www.computing.net/answers/windows-2003/the-server-freezes/8605.html

New Desktop OS www.computing.net/answers/windows-2003/new-desktop-os/81.html