<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hack attempts ?? in Operating System - Linux</title>
    <link>https://community.hpe.com/t5/operating-system-linux/hack-attempts/m-p/2710075#M90045</link>
    <description>Looks like code red, we had the same entries in our logs a while go, check for outgoing connections from your server as it usually tries to bounce out to windows servers, we had a couple of calls and had to pull the plug on the server till it was sorted.&lt;BR /&gt;&lt;BR /&gt;Cheers&lt;BR /&gt;&lt;BR /&gt;George</description>
    <pubDate>Thu, 25 Apr 2002 13:03:36 GMT</pubDate>
    <dc:creator>George_Dodds</dc:creator>
    <dc:date>2002-04-25T13:03:36Z</dc:date>
    <item>
      <title>Hack attempts ??</title>
      <link>https://community.hpe.com/t5/operating-system-linux/hack-attempts/m-p/2710071#M90041</link>
      <description>Thanks to all your help I finally have my LAN connected to the Internet through my Linux server which is running the Apache server. Within minutes of getting Apache on-line I noticed what looks like hack attempts. Example:&lt;BR /&gt;66.189.91.28 - - [23/Apr/2002:23:42:01 -0500] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 284 "-" "-"&lt;BR /&gt;&lt;BR /&gt;Does anyone know what that is ?</description>
      <pubDate>Wed, 24 Apr 2002 13:19:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/hack-attempts/m-p/2710071#M90041</guid>
      <dc:creator>Vernon Brown_2</dc:creator>
      <dc:date>2002-04-24T13:19:53Z</dc:date>
    </item>
    <item>
      <title>Re: Hack attempts ??</title>
      <link>https://community.hpe.com/t5/operating-system-linux/hack-attempts/m-p/2710072#M90042</link>
      <description>Definitely a hack attempt.  Probably nimda or one of the code reds.&lt;BR /&gt;&lt;BR /&gt;Ron&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://research.digitalrice.com/knowledge/notes_nimda.html" target="_blank"&gt;http://research.digitalrice.com/knowledge/notes_nimda.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.faqts.com/knowledge_base/view.phtml/aid/11984/fid/276" target="_blank"&gt;http://www.faqts.com/knowledge_base/view.phtml/aid/11984/fid/276&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 24 Apr 2002 14:52:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/hack-attempts/m-p/2710072#M90042</guid>
      <dc:creator>Ron Kinner</dc:creator>
      <dc:date>2002-04-24T14:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: Hack attempts ??</title>
      <link>https://community.hpe.com/t5/operating-system-linux/hack-attempts/m-p/2710073#M90043</link>
      <description>Thanks Ron; I'll go to the URL's you posted and start researching.</description>
      <pubDate>Wed, 24 Apr 2002 15:43:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/hack-attempts/m-p/2710073#M90043</guid>
      <dc:creator>Vernon Brown_2</dc:creator>
      <dc:date>2002-04-24T15:43:46Z</dc:date>
    </item>
    <item>
      <title>Re: Hack attempts ??</title>
      <link>https://community.hpe.com/t5/operating-system-linux/hack-attempts/m-p/2710074#M90044</link>
      <description>Hack city.&lt;BR /&gt;&lt;BR /&gt;There are several attacks out there that attempt to exploit a weakness in unpatched IIS (windoze) servers. Both Nimda and Code Red attempt to get the web server to run the CMD.EXE shell, and if they can get a response back on the attempt, go on to attempt various nefarious things. &lt;BR /&gt;&lt;BR /&gt;While neither of these viruses are threats to the commercial world (unless there's still someone out there running unpatched systems) they are running fairly freely through the illiterati that have constant internet connections and no concept of nor concern for security.  I was seeing about 100 attempts per day until I got tired of all the logging and decided to black list every address that attempted the attack. My firewall takes a LONNNG time to start up now :) but my logs stay small.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.securityfocus.com" target="_blank"&gt;http://www.securityfocus.com&lt;/A&gt; is a pretty good resource for info on current threats.&lt;BR /&gt;&lt;BR /&gt;Best Regards&lt;BR /&gt;&lt;BR /&gt;Mark</description>
      <pubDate>Wed, 24 Apr 2002 22:38:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/hack-attempts/m-p/2710074#M90044</guid>
      <dc:creator>Mark Fenton</dc:creator>
      <dc:date>2002-04-24T22:38:13Z</dc:date>
    </item>
    <item>
      <title>Re: Hack attempts ??</title>
      <link>https://community.hpe.com/t5/operating-system-linux/hack-attempts/m-p/2710075#M90045</link>
      <description>Looks like code red, we had the same entries in our logs a while go, check for outgoing connections from your server as it usually tries to bounce out to windows servers, we had a couple of calls and had to pull the plug on the server till it was sorted.&lt;BR /&gt;&lt;BR /&gt;Cheers&lt;BR /&gt;&lt;BR /&gt;George</description>
      <pubDate>Thu, 25 Apr 2002 13:03:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/hack-attempts/m-p/2710075#M90045</guid>
      <dc:creator>George_Dodds</dc:creator>
      <dc:date>2002-04-25T13:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: Hack attempts ??</title>
      <link>https://community.hpe.com/t5/operating-system-linux/hack-attempts/m-p/2710076#M90046</link>
      <description>Thanks for your responses !&lt;BR /&gt;My GET requests for cmd.exe are more like 1000 per day now. I grep'ed them into a text file and sent it to abuse@centurytel.net. All of my hits are coming from the CenturyTel DSL network.</description>
      <pubDate>Thu, 25 Apr 2002 13:56:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/hack-attempts/m-p/2710076#M90046</guid>
      <dc:creator>Vernon Brown_2</dc:creator>
      <dc:date>2002-04-25T13:56:55Z</dc:date>
    </item>
  </channel>
</rss>

