OT: Re: Worm/Virus alert

From: Dan Wright <dtwright_at_uiuc.edu>
Date: Tue Sep 18 13:46:54 2001

OK, I know this is not exactly on-topic, but I thought it was ridiculous
enough to share.

Here's what I get from the logs on my IRIX web server running apache:

> egrep "scripts/\.\..*" access_log | grep "18/Sep/2001" | wc -l
  7273

> egrep "msadc/\.\..*" access_log | grep "18/Sep/2001" | wc -l
  809

> egrep "_vti.*/\.\..*" access_log | grep "18/Sep/2001" | wc -l
  811

so, that's 8,893 bogus MS exploit requests. note too, that those numbers grew
by about 5% in about 5 minutes. Damn, I'm glad I don't run a windows machine
:)

- Dan Wright
(dtwright_at_uiuc.edu)
(http://www.uiuc.edu/~dtwright)

-] ------------------------------ [-] -------------------------------- [-
``Weave a circle round him thrice, / And close your eyes with holy dread,
  For he on honeydew hath fed, / and drunk the milk of Paradise.''
       Samuel Taylor Coleridge, Kubla Khan
Received on Tue Sep 18 2001 - 13:46:54 BST

This archive was generated by hypermail 2.3.0 : Fri Oct 10 2014 - 23:34:25 BST