Is Your e3000 Environment Secure? - by Mark Bixby

Is Your e3000 Environment Secure? - HPWorld 2003 page 60August 14, 2003
Apache – check logs for
suspicious activity
§ The /APACHE/PUB/logs/access_log file can indicate suspicious
Microsoft IIS virus activity (Nimda, etc):
12.34.56.78 - - [20/Feb/2003:16:06:41 -0800] "GET
/scripts/root.exe?/c+dir HTTP/1.0" 404 291
12.34.56.78 - - [20/Feb/2003:16:06:41 -0800] "GET
/MSADC/root.exe?/c+dir HTTP/1.0" 404 289
12.34.56.78 - - [20/Feb/2003:16:06:42 -0800] "GET
/c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404
299
12.34.56.78 - - [20/Feb/2003:16:06:42 -0800] "GET
/d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404
299