Click to See Complete Forum and Search --> : annoying hack attempts


squiff
07-08-2002, 09:14 PM
i have a lot of entrys in my apache log that look like the one below.

62.6.100.103 - - [08/Jul/2002:13:09:23 +0100] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 275

it is obviously not doing any harm.

any mean tricks i can play on these people? is it worth notifying their ISP ?

something to scare them off would be nice. what program are they using? a known one or a mere script?

thanks

X_console
07-08-2002, 11:48 PM
It's probably a worm.

manual_overide
07-09-2002, 01:06 AM
Yay for nimda!!

squiff
07-09-2002, 09:20 AM
so you mean these nice folks aren't intentionally trying to breech my web server?

i'll go look up `nimda' on google, methinks

CLL_Sr
07-09-2002, 02:29 PM
Isn't that the Code Red Worm from last year? I think it's never went away. I know it infected alot of DSL routers from Cisco(ie 675 - 678).

manual_overide
07-09-2002, 02:52 PM
no, that's nimda

code red looks for default.ida

CLL_Sr
07-09-2002, 06:38 PM
Thanks for the heads up on that manual_overide. I get them confused. Sorry for the false info folks. :(