9fans - fans of the OS Plan 9 from Bell Labs
 help / color / mirror / Atom feed
* [9fans] missing cmd.exe
@ 2003-01-22  2:05 Skip Tavakkolian
  2003-01-22 12:25 ` Anthony Mandic
  0 siblings, 1 reply; 4+ messages in thread
From: Skip Tavakkolian @ 2003-01-22  2:05 UTC (permalink / raw)
  To: 9fans

Sure doesn't take long. Somewhat amusing. From httpd log:

--------------------------------------------
LogTime:  Tue, 21 Jan 2003 17:33:40 GMT
ConnTime: Tue, 21 Jan 2003 17:33:40 GMT
RemoteIP: 128.121.239.173
Port: 1976
Reply: 403 Forbidden
Reason: Search not supported
FinalURI: /scripts/..%5c%5c../winnt/system32/cmd.exe
----------
GET /scripts/..%255c%255c../winnt/system32/cmd.exe?/c+dir


~~~~~~~~~~~
Skip Tavakkolian  -- Chief cook and bottle washer
9Netics - Distributed Applications Platform
http://www.9netics.com



^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [9fans] missing cmd.exe
  2003-01-22  2:05 [9fans] missing cmd.exe Skip Tavakkolian
@ 2003-01-22 12:25 ` Anthony Mandic
  2003-01-22 14:33   ` Boyd Roberts
  0 siblings, 1 reply; 4+ messages in thread
From: Anthony Mandic @ 2003-01-22 12:25 UTC (permalink / raw)
  To: 9fans

Skip Tavakkolian wrote:
> 
> Sure doesn't take long. Somewhat amusing. From httpd log:
...
> RemoteIP: 128.121.239.173
> Port: 1976
> Reply: 403 Forbidden
> Reason: Search not supported
> FinalURI: /scripts/..%5c%5c../winnt/system32/cmd.exe
> ----------
> GET /scripts/..%255c%255c../winnt/system32/cmd.exe?/c+dir

	It shouldn't be too hard to develop a script or program
	called cmd.exe to do something fun. I'm surprised Boyd
	hasn't suggested this yet (but maybe I'm jumping the gun,
	so to speak).

-am	© 2003


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [9fans] missing cmd.exe
  2003-01-22 12:25 ` Anthony Mandic
@ 2003-01-22 14:33   ` Boyd Roberts
  2003-01-22 16:33     ` Jack Johnson
  0 siblings, 1 reply; 4+ messages in thread
From: Boyd Roberts @ 2003-01-22 14:33 UTC (permalink / raw)
  To: 9fans

Anthony Mandic wrote:

>It shouldn't be too hard to develop a script or program
>called cmd.exe to do something fun. I'm surprised Boyd
>hasn't suggested this yet ...
>
On reflection, something like Ches' 'jail' would be a cool trick,
but maybe a lot of work.




^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [9fans] missing cmd.exe
  2003-01-22 14:33   ` Boyd Roberts
@ 2003-01-22 16:33     ` Jack Johnson
  0 siblings, 0 replies; 4+ messages in thread
From: Jack Johnson @ 2003-01-22 16:33 UTC (permalink / raw)
  To: 9fans

Boyd Roberts wrote:
> Anthony Mandic wrote:
> 
>> It shouldn't be too hard to develop a script or program
>> called cmd.exe to do something fun. I'm surprised Boyd
>> hasn't suggested this yet ...
>>
> On reflection, something like Ches' 'jail' would be a cool trick,
> but maybe a lot of work.

If you do some checking with Google, you'll find that some people have 
done a number of things on various operating systems when they see these 
kinds of requests come through.

The more interesting (I think) are the ones recognized as the IIS 
codered worm, because if they're knocking on your door it means they're 
already infected, which gives you some more information about the host 
system.

There's a pretty popular script floating around to pop up a notification 
window on the infected host with a warning to the owner that they've 
been infected, along with a handy URL to find out more info.  Others 
noted that it might be a headless box in a closet somewhere, so have 
attempted to modify the script to broadcast a message to the local 
domain/workgroup to let anyone/everyone know that the host is infected.

Some people have attempted to write scripts which go back and kill the 
worm on the infected host.

Here's a random example (Googled):

http://salfter.dyndns.org/codered.shtml

Please note that exploiting an infected host to notify the owner of its 
infection is probably illegal in the United States and any country 
willing to buy U.S. goods rather than produce them.

-Jack



^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2003-01-22 16:33 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2003-01-22  2:05 [9fans] missing cmd.exe Skip Tavakkolian
2003-01-22 12:25 ` Anthony Mandic
2003-01-22 14:33   ` Boyd Roberts
2003-01-22 16:33     ` Jack Johnson

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).