Some 'desparate' hack is trying to break into my machine through my
webserver thinking I'm running some unpatched version of IIS. Fortunately
I'm just playing with Apache. However the 'individual' is fairly persistent
(20 attempts over a 10 minute period). Is there a way to identify the
culprit or at least warn the ISP that they have an issue. Using the Sam
Spade site did not uncover much ..only a reverse dns lookup for IP
69.140.105.5 to pcp04417313pcs.nrockv01.md.comcast.net. My apache error log
list of the attempts follows. For most request for these kinds of files I've
redirected the request to IP 127.0.0.1 (someone suggested a microsoft site
instead

) but there seem to be too many variations to handle all the
kinds of requests for cmd.exe & root.exe. (I'm tempted to serve up a
malicious script page instead.). To reply directly un-mung ( remove _mung)
the email address.
[Sat Jan 24 11:46:13 2004] [error] [client 69.140.105.5] File does not
exist: /webshare/wwwroot/removed_pages/msadc/root.exe
[Sat Jan 24 11:46:23 2004] [error] [client 69.140.105.5] File does not
exist: /webshare/wwwroot/removed_pages/scripts/..%5c/winnt/system32/cmd.exe
[Sat Jan 24 11:46:26 2004] [error] [client 69.140.105.5] File does not
exist:
/webshare/wwwroot/removed_pages/_vti_bin/..%5c/..%5c/..%5c/winnt/system32/cm
d.exe
[Sat Jan 24 11:46:33 2004] [error] [client 69.140.105.5] File does not
exist:
/webshare/wwwroot/removed_pages/_mem_bin/..%5c/..%5c/..%5c/winnt/system32/cm
d.exe
[Sat Jan 24 11:46:36 2004] [error] [client 69.140.105.5] File does not
exist:
/webshare/wwwroot/removed_pages/msadc/..%5c/..%5c/..%5c/..Á/..Á/..Á/winnt
/system32/cmd.exe
[Sat Jan 24 11:46:42 2004] [error] [client 69.140.105.5] File does not
exist: /webshare/wwwroot/removed_pages/scripts/..Á/winnt/system32/cmd.exe
[Sat Jan 24 11:46:49 2004] [error] [client 69.140.105.5] File does not
exist: /webshare/wwwroot/removed_pages/scripts/..À¯/winnt/system32/cmd.exe
[Sat Jan 24 11:46:52 2004] [error] [client 69.140.105.5] File does not
exist: /webshare/wwwroot/removed_pages/scripts/..Áo/winnt/system32/cmd.exe
[Sat Jan 24 11:47:02 2004] [error] [client 69.140.105.5] File does not
exist: /webshare/wwwroot/removed_pages/scripts/..%5c/winnt/system32/cmd.exe
[Sat Jan 24 11:47:05 2004] [error] [client 69.140.105.5] File does not
exist: /webshare/wwwroot/removed_pages/scripts/..%2f/winnt/system32/cmd.exe
[Sat Jan 24 11:53:33 2004] [error] [client 69.140.105.5] File does not
exist: /webshare/wwwroot/removed_pages/msadc/root.exe
[Sat Jan 24 11:53:46 2004] [error] [client 69.140.105.5] File does not
exist: /webshare/wwwroot/removed_pages/scripts/..%5c/winnt/system32/cmd.exe
[Sat Jan 24 11:53:49 2004] [error] [client 69.140.105.5] File does not
exist:
/webshare/wwwroot/removed_pages/_vti_bin/..%5c/..%5c/..%5c/winnt/system32/cm
d.exe
[Sat Jan 24 11:53:52 2004] [error] [client 69.140.105.5] File does not
exist:
/webshare/wwwroot/removed_pages/_mem_bin/..%5c/..%5c/..%5c/winnt/system32/cm
d.exe
[Sat Jan 24 11:53:55 2004] [error] [client 69.140.105.5] File does not
exist:
/webshare/wwwroot/removed_pages/msadc/..%5c/..%5c/..%5c/..Á/..Á/..Á/winnt
/system32/cmd.exe
[Sat Jan 24 11:53:59 2004] [error] [client 69.140.105.5] File does not
exist: /webshare/wwwroot/removed_pages/scripts/..Á/winnt/system32/cmd.exe
[Sat Jan 24 11:54:05 2004] [error] [client 69.140.105.5] File does not
exist: /webshare/wwwroot/removed_pages/scripts/..À¯/winnt/system32/cmd.exe
[Sat Jan 24 11:54:08 2004] [error] [client 69.140.105.5] File does not
exist: /webshare/wwwroot/removed_pages/scripts/..Áo/winnt/system32/cmd.exe
[Sat Jan 24 11:54:18 2004] [error] [client 69.140.105.5] File does not
exist: /webshare/wwwroot/removed_pages/scripts/..%5c/winnt/system32/cmd.exe
[Sat Jan 24 11:54:21 2004] [error] [client 69.140.105.5] File does not
exist: /webshare/wwwroot/removed_pages/scripts/..%2f/winnt/system32/cmd.exe