Is this a hacking attempt?
I have had a website up for less than a month and it is not registered with any search engine. However, other than some friends who have been on it, I have seen many other IPs requesting files that do not exits on the server. On closer inspection, it appeared to be an attempt to hack my webserver. The strings in the log would look something like this:
GET /scripts/winnt/cmd.exe?/c+dir
Now, it looks to me like someone trying to access my C Drive. Is it? Or am I just being paranoid? If it isn't, then why are these people trying to request files that don't exist on a site they couldn't possibly have heard of? Are they just running some program that cycles through IP ranges and pings each one?
Re: Is this a hacking attempt?
YES,
by all means it's a hacking attempt very "on vogue" these days.
we see it on many servers..
if you are running microsoft IIS 4 or 5 server then YOU are concerned, otherwise do not worry.
the hackers attempt to abuse an exploit called unicode on
NT os systems running microsoft IIS servers.
they try to install hiddenly a sort of FTP and/or TFTP server (but not on port 2*)
in order to share files secretly.
they call it "pubstro" for public storage.
verify your open ports and close those that are not allowed.
verify your firewall.
update microsoft IIS server (if you run one)
use commview (that you can download from this site, if it's not already done)
here's more info on pubstro
[url]http://2*6.2**.*7.*00/search?q=cache:*hUbz5Cgw*cC:www.esec.dk/pubstro.pdf+pubstro&hl=en&ie=UTF-8[/url]
[url]http://www.dslreports.com/forum/remark,42425*7~root=security,*~mode=flat[/url]
-----------
fEš·.·šEr