GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Strange visitor on all domains (https://gfy.com/showthread.php?t=230006)

brutus 02-02-2004 02:01 PM

Strange visitor on all domains
 
What this means... today, all of my domains from one server shows on log files the same thing:

[Mon Feb 2 11:40:10 2004] [error] [client 216.220.224.17] File does not exist: /scripts/..%5c%5c../winnt/system32/cmd.exe

I have checked about 100 domains hosted from this server (Apache) with unique IPs and those domains are not all linked anyway... Just few of them. Even unused / empty domains shows same alien on logs.

Cant get any info about: 216.220.224.17

Is this some worm scanning IP space or how this is possible?

 Smokey The Bear  02-02-2004 02:04 PM

Its just someone searching for holes in your system . dont worry they didnt find it.

klinton 02-02-2004 02:07 PM

OrgName: Mid-Maine Communications
OrgID: MIDM
Address: 44 Broadway
City: Bangor
StateProv: ME
PostalCode: 04401
Country: US
NetType: Direct Allocation
NameServer: NS1.MIDMAINE.NET
NameServer: NS2.MIDMAINE.NET
Comment: ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
RegDate: 1999-05-03
Updated: 2002-12-11
OrgTechHandle: BWC7-ARIN
OrgTechName: Cole, Brian W
OrgTechPhone: +1-207-620-9962
OrgTechEmail: [email protected]

klinton 02-02-2004 02:08 PM

Quote:

Originally posted by *Smokey The Bear*
Its just someone searching for holes in your system . dont worry they didnt find it.
exactly, looking for exploits ;).

 Smokey The Bear  02-02-2004 02:08 PM

Yup it looks like just a regular joe. You could call his isp and find out rather quickly.

Just tell them someone from that ip is trying to access your command module.

brutus 02-02-2004 02:09 PM

Ok, thanks. So, no problems at this time :)

 Smokey The Bear  02-02-2004 02:10 PM

Quote:

Originally posted by brutus
Ok, thanks. So, no problems at this time :)
Nope i wouldnt worry about it , i get a few dozen a week on every server.

nathan_f 02-02-2004 02:12 PM

Nobody in particular is trying to get into your box.

It's a worm, I'd wager code red / nimda remnants.


All times are GMT -7. The time now is 05:45 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123