Off-topic Talk Where overpaid, underworked S2000 owners waste the worst part of their days before the drive home. This forum is for general chit chat and discussions not covered by the other off-topic forums.

Computer Hack Question

Thread Tools
 
Old Jul 25, 2001 | 05:39 PM
  #1  
ScottB's Avatar
Thread Starter
Registered User
20 Year Member
 
Joined: Oct 2000
Posts: 1,490
Likes: 0
From: Santa Clarita, CA
Default Computer Hack Question

While perusing some logs on my home server, I noticed several attempts to hack in. From the looks of it, it was unsuccessful, however, I'd appreciate it if someone could look at the following and let me know.

Thanks a lot of the help!




20:51:27 213.175.32.246 GET /scripts/../../winnt/system32/cmd.exe 404
20:51:30 213.175.32.246 GET /msadc/../../../../../../winnt/system32/cmd.exe 200
20:51:31 213.175.32.246 GET /msadc/../../../../../../winnt/system32/cmd.exe 200
20:51:32 213.175.32.246 GET /msadc/../../../../../../winnt/system32/cmd.exe 502
20:51:33 213.175.32.246 GET /msadc/../../../../../../winnt/system32/cmd.exe 502
20:51:34 213.175.32.246 GET /msadc/../../../../../../winnt/system32/cmd.exe 502
20:51:34 213.175.32.246 GET /msadc/../../../../../../winnt/system32/cmd.exe 502


04:24:28 204.0.69.15 GET /scripts/../../winnt/system32/cmd.exe 404

21:34:58 211.152.241.1 GET /scripts/../../winnt/system32/cmd.exe 404
21:34:58 211.152.241.1 GET /scripts/..../winnt/system32/cmd.exe 404
21:35:02 211.152.241.1 GET /scripts/..../winnt/system32/cmd.exe 404
21:35:02 211.152.241.1 GET /scripts/../../winnt/system32/cmd.exe 404
21:35:06 211.152.241.1 GET /scripts/../../winnt/system32/cmd.exe 404
21:35:09 211.152.241.1 GET /scripts/..../winnt/system32/cmd.exe 404
21:35:09 211.152.241.1 GET /scripts/..
Reply
Old Jul 25, 2001 | 05:51 PM
  #2  
DaveZ's Avatar
Registered User
 
Joined: Mar 2001
Posts: 2,170
Likes: 0
From: Richmond
Default

Looks like they were trying to take advantage of a
Reply
Old Jul 25, 2001 | 06:10 PM
  #3  
ScottB's Avatar
Thread Starter
Registered User
20 Year Member
 
Joined: Oct 2000
Posts: 1,490
Likes: 0
From: Santa Clarita, CA
Default

I had recently made sure to run the Windows update, so I am confident that IIS is fully patched.

However, does it look like this person was successful?

Thanks.
Reply
Old Jul 25, 2001 | 06:37 PM
  #4  
DaveZ's Avatar
Registered User
 
Joined: Mar 2001
Posts: 2,170
Likes: 0
From: Richmond
Default

Yeah, sorry, I didn't mean to give the impression that you had been hacked - I should have made it more clear that from what I saw, this was merely the type of attack attempted. I can't tell from the log files for sure, but it just looks like a file traveral probe - checking to see what's available. I believe the sadmind worm changes some web pages to read "Hacked by Chinese".

I'm not a security professional, just a former IIS webmaster, so someone else might have better info.
Reply
Old Jul 25, 2001 | 06:43 PM
  #5  
s2kmtl's Avatar
Registered User
20 Year Member
 
Joined: Nov 2000
Posts: 178
Likes: 0
Default

I head up KPMG's IRM dept in Montreal (Information Risk Management). I specialize in this type of stuff. PM me if you have any questions and I would be glad to help a fellow S2K'er.

I specialize in 'ethical hacking' so yes, from what I can see they were definately trying to hack you.

No, I do not think they were successfull because if they were, you would have see more commands.

IE they are trying the same thing over again.

IF it was successfull, you would see them using FTP/TFTP to try and upload trojans or use NETCAT to get a command prompt on your box.


Robert
Reply
Old Jul 25, 2001 | 08:38 PM
  #6  
ScottB's Avatar
Thread Starter
Registered User
20 Year Member
 
Joined: Oct 2000
Posts: 1,490
Likes: 0
From: Santa Clarita, CA
Default

Thanks a lot guys, I really appreciate this. This community is the best place to turn to when you need a pro.
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Officer_down
Off-topic Talk
5
Mar 30, 2005 06:37 AM
VTEC_Junkie
Off-topic Talk
2
Dec 1, 2004 07:57 PM
MeTh222
Off-topic Talk
3
Aug 24, 2004 09:07 PM
VisualEchos
Off-topic Talk
8
Feb 2, 2003 09:34 AM




All times are GMT -8. The time now is 09:46 PM.