Solved

what does this IIS log tell me...

Posted on 2001-06-06
4
1,652 Views
Last Modified: 2008-02-07
The following entries are found in my IIS log file. Please tell me what does it mean. (NT4 + IIS4) Thanks,

2001-05-19 08:27:14 202.64.252.67 - W3SVC3 SDC1M004 10.2.2.254 GET /scripts/../../winnt/system32/cmd.exe /c+dir 404 3 604 85 150 80 HTTP/1.0 - - -
2001-05-19 08:27:14 202.64.252.67 - W3SVC3 SDC1M004 10.2.2.254 GET /scripts/..\../winnt/system32/cmd.exe /c+dir 404 3 604 85 160 80 HTTP/1.0 - - -
2001-05-19 08:27:15 202.64.252.67 - W3SVC3 SDC1M004 10.2.2.254 GET /scripts/..\../winnt/system32/cmd.exe /c+dir 404 3 604 85 160 80 HTTP/1.0 - - -
2001-05-19 08:27:15 202.64.252.67 - W3SVC3 SDC1M004 10.2.2.254 GET /scripts/../../winnt/system32/cmd.exe /c+dir 404 3 604 85 160 80 HTTP/1.0 - - -
2001-05-19 08:27:16 202.64.252.67 - W3SVC3 SDC1M004 10.2.2.254 GET /scripts/../../winnt/system32/cmd.exe /c+dir 404 3 604 85 150 80 HTTP/1.0 - - -
2001-05-19 08:27:16 202.64.252.67 - W3SVC3 SDC1M004 10.2.2.254 GET /scripts/..\../winnt/system32/cmd.exe /c+dir 404 3 604 85 160 80 HTTP/1.0 - - -
2001-05-19 08:27:18 202.64.252.67 - W3SVC3 SDC1M004 10.2.2.254 GET /scripts/..A../winnt/system32/cmd.exe /c+dir 404 3 604 85 160 80 HTTP/1.0 - - -
2001-05-19 08:27:18 202.64.252.67 - W3SVC3 SDC1M004 10.2.2.254 GET /scripts/..\../winnt/system32/cmd.exe /c+dir 404 3 604 85 160 80 HTTP/1.0 - - -
2001-05-19 08:27:19 202.64.252.67 - W3SVC3 SDC1M004 10.2.2.254 GET /scripts/..o../winnt/system32/cmd.exe /c+dir 404 3 604 85 160 80 HTTP/1.0 - - -
2001-05-19 08:27:19 202.64.252.67 - W3SVC3 SDC1M004 10.2.2.254 GET /scripts/../../winnt/system32/cmd.exe /c+dir 404 3 604 88 140 80 HTTP/1.0 - - -
2001-05-19 08:27:21 202.64.252.67 - W3SVC3 SDC1M004 10.2.2.254 GET /scripts/..????../winnt/system32/cmd.exe /c+dir 404 3 604 91 160 80 HTTP/1.0 - - -
2001-05-19 08:27:21 202.64.252.67 - W3SVC3 SDC1M004 10.2.2.254 GET /scripts/..?????../winnt/system32/cmd.exe /c+dir 404 3 604 94 170 80 HTTP/1.0 - - -
2001-05-19 08:27:22 202.64.252.67 - W3SVC3 SDC1M004 10.2.2.254 GET /scripts/..u?????../winnt/system32/cmd.exe /c+dir 404 3 604 97 140 80 HTTP/1.0 - - -
2001-05-19 08:27:22 202.64.252.67 - W3SVC3 SDC1M004 10.2.2.254 GET /msadc/../../../../../../winnt/system32/cmd.exe /c+dir 404 3 604 114 160 80 HTTP/1.0 - - -
0
Comment
Question by:jians
  • 2
  • 2
4 Comments
 
LVL 5

Accepted Solution

by:
dredge earned 5 total points
ID: 6160688
that means that someone was trying to exploit the UNICODE bug in IIS4.

this was a but that allowed a user to execute command shells through a web page by breaking out of your directory structure by using a unicode error in IIS.

you should install NT Service Pack 6a to fix this problem.
0
 

Author Comment

by:jians
ID: 6161012
Could you point me a link with more details? Thanks!
0
 
LVL 5

Expert Comment

by:dredge
ID: 6161079
http://www.microsoft.com/technet/iis/

I can't seem to find the specific Unicode bug anymore, but it used to be listed on the front page.

Service Pack 6a fixes this problem, though.
0
 

Author Comment

by:jians
ID: 6161249
Thanks a lot!
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

Suggested Solutions

Today I came across an interesting issue that had me pulling my hair out.  I was troubleshooting a new internal web site which uses integrated security instead of anonymous.  When browsing the site from my laptop, I was able to access it with no iss…
When it comes to showing a 404 error page to your visitors, you do not want that generic page to show, and you especially do not want your hosting provider’s ad error page to show either. In this article, I will show you how to enable the custom 40…
It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now