avatar
帮我看看我的web log吧# Security - 系统安全
s*r
1
前日网络忽然断了,一问是被学校网管block了
自省一下,最近没down mp3 avi,只是用iis开了http service
查了以下weblog果然有问题,不过看不懂对方在做什么,还请大家看看
这只是一天的
00:24:29 128.8.198.188 HEAD /Default.htm 200
00:24:29 128.8.198.188 HEAD /MSADC/root.exe 404
00:24:29 128.8.198.188 HEAD /PBServer/..%5c..%5c..%5cwinnt/system32/cmd.exe
404
00:24:29 128.8.198.188 HEAD /PBServer/..%5c..%5c..%5cwinnt/system32/cmd.exe
404
00:24:30 128.8.198.188 HEAD /PBServer/..%5c..%5c..%5cwinnt/system32/cmd.exe
404
00:24:32 128.8.198.188 HEAD /PBServer/..%5c..%5c..%5cwinnt/
avatar
a*a
2
Something more in detail? I am interested in knowing it too.

/PBServer/..%5c..%5c..%5cwinnt/system32/cmd.exe
/PBServer/..%5c..%5c..%5cwinnt/system32/cmd.exe
/PBServer/..%5c..%5c..%5cwinnt/system32/cmd.exe
/PBServer/..%5c..%5c..%5cwinnt/system32/cmd.exe
avatar
s*r
3
the mail from school's network admin:
>This host was observed scanning off-campus machines for windows ports 139
and 445. Upon further investigation, I found a suspicious service running on
port 6129.
>
>To prevent further attacks the network to this host has been turned off.
>Once the machine is cleaned/reinstalled file this call into the SECURITY
>workgroup for network access to be restored.
is the 'probe' action related with it?
it seems they can write on my hd.
I have the weblog for these da
avatar
d*o
4
May not be the web service. nowadays, every weblog has such entries unless they
filter on firewalls.
br />
Scan for virus first.
avatar
s*r
5
anyway, it is formatted now.
thanks

【在 d****o 的大作中提到】
: May not be the web service. nowadays, every weblog has such entries unless they
: filter on firewalls.
: br />
: Scan for virus first.

avatar
c*n
6
ft, you don't need to do this.
Set up a firewall and just block the IP.

【在 s*r 的大作中提到】
: anyway, it is formatted now.
: thanks

相关阅读
logo
联系我们隐私协议©2024 redian.news
Redian新闻
Redian.news刊载任何文章,不代表同意其说法或描述,仅为提供更多信息,也不构成任何建议。文章信息的合法性及真实性由其作者负责,与Redian.news及其运营公司无关。欢迎投稿,如发现稿件侵权,或作者不愿在本网发表文章,请版权拥有者通知本网处理。