RE: [SLUG] Rise in IIS scans

From: Craig Zeigler (craig@caffeine-addict.com)
Date: Tue Dec 31 2002 - 20:02:51 EST


I haven't seen any rise in the number of those scans. My logs are
alsways full of them... at least 30 per hour. Thankfully they use almost
no bandiwdth. Then again, i've got my logging turned waaay up.

-----Original Message-----
From: Matt [mailto:matthew@textbox.net]
Sent: Tuesday, December 31, 2002 6:50 PM
To: SLUG
Subject: [SLUG] Rise in IIS scans

I figure this is just (insert IIS worm here) making it's
rounds again but I wanted to see if anyone else has a somewhat
noticable increase in port 80 and 137 scans. My logs have been
filling pretty fast...like I have to clear them every other day:

24.xxx.xxx.xxx - - [31/Dec/2002:14:06:25 -0500] "GET
/scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 288
24.xxx.xxx.xxx - - [31/Dec/2002:14:06:27 -0500] "GET
/scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 305
24.xxx.xxx.xxx - - [31/Dec/2002:14:06:36 -0500] "GET
/scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 305

and so on....

Matt <matthew@textbox.net>
Textbox Networks



This archive was generated by hypermail 2.1.3 : Fri Aug 01 2014 - 19:59:07 EDT