Jump to content

Recommended Posts

Posted

OK, whenever I check my Apache access log that I have running, I always end up seeing someone trying to get this:

"/scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir"

What exactly are they trying to do? Access my command prompt? :rolleyes::)


Posted

That's the path for the command prompt in Windows NT or 2000.

If you are running Apache on another platform (usually on Linux), then it won't work.

I guess the hacker thinks you are running IIS rather than Apache...

Posted
If you are running Apache on another platform (usually on Linux), then it won't work.

I guess the hacker thinks you are running IIS rather than Apache...

Nope...I'm on buggy Windows running Apache 2.0.47! :)

Posted

It means your PC has been exploited and he is executing the command to gain root or he is checking to see if someone else has exploited it and hopes to gain access. A lazy hacker.

Posted
It means your PC has been exploited and he is executing the command to gain root or he is checking to see if someone else has exploited it and hopes to gain access. A lazy hacker.

How do I know if my PC's been exploited? :) Check for updates?

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...