Forum Moderators: mack

Message Too Old, No Replies

Strange requests in my error log.

I can't understand the page requests.

         

Sami_boy

9:10 am on May 13, 2003 (gmt 0)

10+ Year Member



My error log is filling up with requests like:

/msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir
/_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir
mod.php?mod=mainpage&op=edit_mainpage
index.php?menu=1&PHPSESSID=ec4af5b9c4142e75df45604dc3772f1e
/c/winnt/system32/cmd.exe?/c+dir
/default.ida?XX...XX%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a

And over a million other failed requests. And they keep on coming! What should I do, my ISP is taking my site
offline.

This site is hosted with a new fresh (never used before) domain, and (until to days ago) I belived only myself and a few friends, my ISP and a few other had knowledge of the site. It is not listed with any directory or search engine. All spiders are blocked with robots.txt

Please, give me some good advice.

rharri

11:11 am on May 13, 2003 (gmt 0)

10+ Year Member



It looks like the script-kiddies are hitting your site with stuff designed for Windows. Your host needs to install software to block, by IP, when this happens (something like portsentry). Does your server have a Linux OS?

Sami_boy

3:43 pm on May 13, 2003 (gmt 0)

10+ Year Member



Hello,

Yes, my host does run Linux. My host has taken my site down, and he don't want my business anymore. So I am now moving to a new host. When I explaied the problem they suggested that I just leave all that unwanted traffic to them, they will even give me a montly discount if it continues!

Happy days!

requiem

5:56 pm on May 14, 2003 (gmt 0)

10+ Year Member



One question. Why would anyone want to buy junk requests?
It doesn' make any sense.

PsychoTekk

7:38 pm on May 14, 2003 (gmt 0)

10+ Year Member



the request for default.ida origins from a code red virus infected webserver.
requests that contain cmd.exe/root.exe are from a nimda virus infected one.

if your webserver is an apache, just set up redirect rules in your .htaccess
file for urls containing "cmd.exe", "root.exe" and "default.ida".
this way your error.log will be eased