Reply
Old October 24th, 2003 Top | #1
 
Glaanieboy's Avatar
OSNN Veteran Addict
Joined: March 2002
Location: The Netherlands
Posts: 2,626
Reputation: 270
Power: 150

Default Hacking attempt?

I just checked my Apache2 logs and foudn this:
Code:
202.9.*.* - - [24/Oct/2003:21:39:46 +0200] "GET /scripts/nsiislog.dll" 404 306
(part of the IP has been removed for privacy issues)

I traced the IP back to a provider somewhere in India, since I don't know anyone in India and seeing that he/she is trying to access a IIS(?) log script(?), should I block the IP? Or is this normal?
Glaanieboy is offline   Reply With Quote
Old October 24th, 2003 Top | #2
 
SPeedY_B's Avatar
I may actually be insane.
Joined: March 2002
Location: Midlands, England
Posts: 15,800
Reputation: 2877
Power: 307

Default

probably a crawler/robot. As it says, they received a 404 anyway(?), so it shouldn't really matter.

Probably only really worth blocking the IP if it's a repeated event.
SPeedY_B is offline   Reply With Quote
Old October 24th, 2003 Top | #3
 
j79zlr's Avatar
Glaanies script monkey
Joined: February 2003
Location: Chicago
Posts: 2,725
Reputation: 1520
Power: 152

Default

Don't worry, I get these in my 404 logs all the time:

/MSADC/root.exe?/c+dir

/_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir

etc, that is the NIMDA or Code Red trojan, but I'm on FreeBSD so good luck infecting me.
j79zlr is offline   Reply With Quote
Old October 24th, 2003 Top | #4
 
SPeedY_B's Avatar
I may actually be insane.
Joined: March 2002
Location: Midlands, England
Posts: 15,800
Reputation: 2877
Power: 307

Default

*tries really hard* >_<

SPeedY_B is offline   Reply With Quote
Old October 24th, 2003 Top | #5
 
j79zlr's Avatar
Glaanies script monkey
Joined: February 2003
Location: Chicago
Posts: 2,725
Reputation: 1520
Power: 152

Default

j79zlr is offline   Reply With Quote
Old October 25th, 2003 Top | #6
 
X-Istence's Avatar
*
Joined: December 2001
Location: USA
Posts: 6,490
Reputation: 2808
Power: 217

Default

Thats just nimda/code red.

I get about 5,000 of those request a day.
X-Istence is offline   Reply With Quote
Old October 25th, 2003 Top | #7
 
Glaanieboy's Avatar
OSNN Veteran Addict
Joined: March 2002
Location: The Netherlands
Posts: 2,626
Reputation: 270
Power: 150

Default

But it only affects IIS on a Windows machine, right?
Glaanieboy is offline   Reply With Quote
Old October 25th, 2003 Top | #8
 
j79zlr's Avatar
Glaanies script monkey
Joined: February 2003
Location: Chicago
Posts: 2,725
Reputation: 1520
Power: 152

Default

yep
j79zlr is offline   Reply With Quote
Old October 25th, 2003 Top | #9
 
SPeedY_B's Avatar
I may actually be insane.
Joined: March 2002
Location: Midlands, England
Posts: 15,800
Reputation: 2877
Power: 307

Default

Correct

[edit] Beaten to it
SPeedY_B is offline   Reply With Quote
Old October 28th, 2003 Top | #10
Leevoy
 
Leevoy's Avatar
Unregistered
Posts: n/a

Default

Well the most hack attempts I get are from the middle east or asia.

On the other hand I get a few via europe with the user having an asian or middle east server.

Probably better off just blocking their addie for the time being.
  Reply With Quote
Old October 28th, 2003 Top | #11
Bronx Bomber
 
Bronx Bomber's Avatar
Unregistered
Posts: n/a

Default

most of the attempts i get are from brazil. they got a real problem with hackers over there.
then i get the guys who try to hide their identity by using some a different IP. its really annoying.
  Reply With Quote
Old October 28th, 2003 Top | #12
 
Friend of Bill's Avatar
What, me worry?
Joined: April 2002
Posts: 1,572
Reputation: 20
Power: 136

Default

I get em' from several parts of Asia and Brazil mainly, but none have been successful in penetrating my made-in-america defenses.
Friend of Bill is offline   Reply With Quote
Old October 28th, 2003 Top | #13
 
Enyo's Avatar
OSNN Veteran Addict
Joined: February 2003
Posts: 1,338
Reputation: 330
Power: 126

Default

Just some general comments to go out in no particular order:

1) Code Red or Nmida probes (or any worm activity for that matter) are not hacking attempts.

2) You can not be sure of the location of an "attacker" and it not important where they are anyway.

3) Chill out and be happy your protected Blacklist repetitive IPs that cause you grief.
Enyo is offline   Reply With Quote
Old October 28th, 2003 Top | #14
Leevoy
 
Leevoy's Avatar
Unregistered
Posts: n/a

Default

I wonder if they could just send us the honey's from brazil and let the guys go nuke each other with their trojans and leave the chicks to us red blooded sport minded guys
  Reply With Quote

Reply

Bookmarks

Thread Tools

Posting Rules

Similar Threads
Thread Thread Starter Forum Replies Last Post
DoS Attempt on my E-mail kcnychief Windows Desktop Systems 64 March 12th, 2007 1:08am
Another bad phishing attempt vivid_vibe Green Room 3 March 12th, 2005 4:38am
Possible Browser Hijack attempt jw50 Windows Desktop Systems 8 February 17th, 2005 9:52am
My Mix (1st Attempt) Teddy Green Room 29 June 5th, 2004 2:43pm
Help! Screwed up partitioning attempt Bob Sinclar Windows Desktop Systems 4 January 29th, 2002 6:07am