From owner-freebsd-isp Sat Apr 7 7:22:54 2001 Delivered-To: freebsd-isp@freebsd.org Received: from surreal.nl (surreal.nl [212.204.236.10]) by hub.freebsd.org (Postfix) with ESMTP id EC53B37B422 for ; Sat, 7 Apr 2001 07:22:51 -0700 (PDT) (envelope-from walter@binity.com) Received: by surreal.nl (Postfix, from userid 666) id 5D4937FE9C; Sat, 7 Apr 2001 16:23:50 +0200 (CEST) Received: from localhost (localhost [127.0.0.1]) by surreal.nl (Postfix) with ESMTP id EEC989EE82; Sat, 7 Apr 2001 16:23:47 +0200 (CEST) Date: Sat, 7 Apr 2001 16:23:47 +0200 (CEST) From: Walter Hop To: Jim Weeks Cc: Subject: Re: Look familiar? In-Reply-To: <3ACF1957.E9177B52@siteplus.net> Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=iso-8859-1 Content-Transfer-Encoding: 8BIT X-Virus-Scanned: This message passed the virus scan (BinityScan 0.9/AVP) Sender: owner-freebsd-isp@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org [in reply to Jim Weeks , 07/04/01] > While checking one of my apache error logs this morning, I find a long > list of the following error. > I was wondering if it makes sense to anyone? I am especially curious > about characters "À¯". > > [Sat Apr 7 05:55:02 2001] [error] [client 207.31.75.150] File does not > exist: > /usr/local/www/data/scripts/..À¯..À¯..À¯..À¯..À¯..À¯..À¯..À¯/winnt/system32/cmd.exe This is the result of someone trying an IIS exploit on your webserver... Since you aren't running Windows, there's no harm done, nothing to worry about. :) -- Walter Hop | +31 6 24290808 | PGP key ID: 0x84813998 To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-isp" in the body of the message