Printer Friendly Version Print this thread
Email this thread to a friend eMail this thread to a friend
Featured Web Site Template

Hundreds More at Free Site Templates.com!

Web Site Partners
Sponsored Links
Jet City Software
 
Whos Here ?
There are 0 guests and 1 members in the forums right now.
Reflects user activity within the last 5 minutes
Moderator(s): OAC, flyingrose
Member Message

Oipete
Joined: Nov 28, 2002
# Posts: 15

View the profile for Oipete Send Oipete a private message

Posted: 2003-Jun-04 10:42
Edit Message Delete Message Reply to this message

Hi, could anyone tell me how to stop all the cmd.exe requests causing all the error logs in my reports. Is there any way to stop what is, I imagine, hackers trying to get access to my root folders etc.
Any help would be much appreciated.
Thanks



excell
Staff
Joined: Mar 19, 2001
# Posts: 14513

View the profile for excell Send excell a private message

Posted: 2003-Jun-04 15:42
Edit Message Delete Message Reply to this message

moved from Professional SEO Issues



crash
Staff
Joined: Dec 02, 2003
# Posts: 10626

View the profile for crash Send crash a private message

Posted: 2003-Jun-04 16:59
Edit Message Delete Message Reply to this message

It's a virus probing your server looking for a way in. I don't think you can stop the requests as you'd have to have control of the box performing the requests but you might be able to block the IP or notifiy the sender that they have a virus.



Prowler
Staff
Joined: Aug 14, 2000
# Posts: 1827

View the profile for Prowler Send Prowler a private message

Posted: 2003-Jun-19 02:07
Edit Message Delete Message Reply to this message

The easy solution would be to use the .htaccess feature of the powerful Apache server. Use something like the following to serve a minimum size file:

RewriteEngine On
RewriteBase /
RewriteRule .*.exe? nimda.html

The above directives should be saved as plain text under the name of .htaccess and located in the root directory.




Curious_Mark
Joined: Dec 02, 2001
# Posts: 2142

View the profile for Curious_Mark Send Curious_Mark a private message

Posted: 2003-Jun-19 05:46
Edit Message Delete Message Reply to this message

What exactly does the above do Prowler?

smile



Prowler
Staff
Joined: Aug 14, 2000
# Posts: 1827

View the profile for Prowler Send Prowler a private message

Posted: 2003-Jun-29 03:47
Edit Message Delete Message Reply to this message

I am sorry for the delay. The above 'traps' any request to *.exe file and then sends a small nimda.html. This file can have a tracking script embedded in it. smile


You are not permitted to post messages in this forum or topic, because of one or more of the following reasons:
  1. You have not yet logged in, or registered properly as a member
  2. You are a member, but no longer have posting rights.
  3. This is a private forum, for which you do not have permissions.

If you are a recent member, it's possible that you simply have not yet confirmed your account. Please check your email for a message entitled 'JimWorld Forums: Confirm Your Account' and follow the instructions contained within.

If you cannot find this message, click here to Re-Send it.

If you are still experiencing problem, please read the Login Assistance Article for some advice on what may be causing your login not to work properly.

Switch to Advanced Editor and ... Create a New Topic or Reply to this Thread

New posts Forum is locked
© 1995  ·  iWeb, Inc  ·  DBA JimWorld Productions