2019年5月23日 星期四

從 Web Log 學習系統漏洞 40

web log中一直持續有很多入侵, 大多還是以 phpmyadmin 的漏洞攻擊資料庫

今天的紀錄, 估狗了一下, 這傢伙好像是要測試某種網路攝影機的漏洞, 所以他入侵之後能幹啥? 問題是我沒有裝網路攝影機

221.213.75.144 - - [23/May/2019:15:48:55 +0800] "GET / HTTP/1.1" 200 1829 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko"
221.213.75.144 - - [23/May/2019:15:48:56 +0800] "GET /home.asp HTTP/1.1" 404 206 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko"
221.213.75.144 - - [23/May/2019:15:48:56 +0800] "GET / HTTP/1.1" 200 1829 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko"
221.213.75.144 - - [23/May/2019:15:48:56 +0800] "GET / HTTP/1.1" 200 1829 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko"
221.213.75.144 - - [23/May/2019:15:48:57 +0800] "GET /images/logo.gif HTTP/1.1" 404 213 "-" "-"
221.213.75.144 - - [23/May/2019:15:48:57 +0800] "GET /fdsrwe HTTP/1.1" 404 204 "-" "-"
221.213.75.144 - - [23/May/2019:15:48:59 +0800] "GET /qnfxcjqr HTTP/1.1" 404 226 "-" "-"
221.213.75.144 - - [23/May/2019:15:49:00 +0800] "GET /currentsetting.htm HTTP/1.1" 404 216 "-" "-"
221.213.75.144 - - [23/May/2019:15:49:00 +0800] "GET / HTTP/1.1" 200 1829 "-" "-"
221.213.75.144 - - [23/May/2019:15:49:02 +0800] "GET /winbox.png HTTP/1.1" 404 208 "-" "-"
221.213.75.144 - - [23/May/2019:15:49:02 +0800] "GET /login.html HTTP/1.1" 404 208 "-" "-"
221.213.75.144 - - [23/May/2019:15:49:03 +0800] "GET /device_description.xml HTTP/1.1" 404 220 "-" "-"
221.213.75.144 - - [23/May/2019:15:49:05 +0800] "GET /cgi-bin/user/Config.cgi?.cab&action=get&category=Account.* HTTP/1.1" 404 232 "-" "-"
221.213.75.144 - - [23/May/2019:15:49:05 +0800] "GET /current_config/passwd HTTP/1.1" 404 219 "-" "-"
221.213.75.144 - - [23/May/2019:15:49:07 +0800] "GET / HTTP/1.1" 200 1829 "-" "-"
221.213.75.144 - - [23/May/2019:15:49:08 +0800] "GET / HTTP/1.1" 200 1829 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko"

沒有留言:

張貼留言