Sorry to disappoint, but that’s nothing! - You should see my logs.
If we are only talking about HTTP logs, I see the same exact patterns of hits so regularly I just skip over them - I find its nice to see something different, like someone trying stuff by hand rather than just automated tools.
I’ve seen the following:
Password attempts on my telnet server.
Connections to 138, 139.
Someone connecting to my back orifice honeypot, who I net sent a message back to and ended up chatting to.
Mail relay testes on 110.
I also put up some of the attacks ive seen a while back at
http://www.rootsecur...oneypot_log.txt )
My logs for yesterday…
#Software: Microsoft Internet Information Services 5.1
#Version: 1.0
#Date: 2002-11-05 00:00:39
#Fields: time c-ip cs-method cs-uri-stem sc-status
10:56:57 81.86.152.11 GET /scripts/root.exe 404
10:56:57 81.86.152.11 GET /MSADC/root.exe 404
10:56:57 81.86.152.11 GET /c/winnt/system32/cmd.exe 500
10:56:57 81.86.152.11 GET /d/winnt/system32/cmd.exe 404
10:56:57 81.86.152.11 GET /scripts/..%5c../winnt/system32/cmd.exe 404
10:56:58 81.86.152.11 GET /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
10:56:58 81.86.152.11 GET /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
10:56:58 81.86.152.11 GET /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe 404
10:56:58 81.86.152.11 GET /scripts/..Á../winnt/system32/cmd.exe 404
10:56:58 81.86.152.11 GET /scripts/winnt/system32/cmd.exe 404
10:56:59 81.86.152.11 GET /winnt/system32/cmd.exe 404
10:56:59 81.86.152.11 GET /winnt/system32/cmd.exe 404
10:56:59 81.86.152.11 GET /scripts/..%5c../winnt/system32/cmd.exe 404
10:56:59 81.86.152.11 GET /scripts/..%5c../winnt/system32/cmd.exe 404
10:57:00 81.86.152.11 GET /scripts/..%5c../winnt/system32/cmd.exe 404
10:57:00 81.86.152.11 GET /scripts/..%2f../winnt/system32/cmd.exe 404
11:05:18 81.86.152.11 GET /scripts/root.exe 404
11:05:18 81.86.152.11 GET /MSADC/root.exe 404
11:05:18 81.86.152.11 GET /c/winnt/system32/cmd.exe 500
11:05:18 81.86.152.11 GET /d/winnt/system32/cmd.exe 404
11:05:18 81.86.152.11 GET /scripts/..%5c../winnt/system32/cmd.exe 404
11:05:18 81.86.152.11 GET /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
11:05:18 81.86.152.11 GET /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
11:05:19 81.86.152.11 GET /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe 404
11:05:19 81.86.152.11 GET /scripts/..Á../winnt/system32/cmd.exe 404
11:05:19 81.86.152.11 GET /scripts/winnt/system32/cmd.exe 404
11:05:19 81.86.152.11 GET /winnt/system32/cmd.exe 404
11:05:19 81.86.152.11 GET /winnt/system32/cmd.exe 404
11:05:19 81.86.152.11 GET /scripts/..%5c../winnt/system32/cmd.exe 404
11:05:20 81.86.152.11 GET /scripts/..%5c../winnt/system32/cmd.exe 404
11:05:20 81.86.152.11 GET /scripts/..%5c../winnt/system32/cmd.exe 404
11:05:20 81.86.152.11 GET /scripts/..%2f../winnt/system32/cmd.exe 404
13:18:03 81.86.105.27 GET /scripts/root.exe 404
13:18:03 81.86.105.27 GET /MSADC/root.exe 404
13:18:04 81.86.105.27 GET /c/winnt/system32/cmd.exe 500
13:18:04 81.86.105.27 GET /d/winnt/system32/cmd.exe 404
13:18:06 81.86.105.27 GET /scripts/..%5c../winnt/system32/cmd.exe 404
13:18:06 81.86.105.27 GET /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
13:18:07 81.86.105.27 GET /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
13:18:07 81.86.105.27 GET /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe 404
13:18:09 81.86.105.27 GET /scripts/..Á../winnt/system32/cmd.exe 404
13:18:09 81.86.105.27 GET /scripts/winnt/system32/cmd.exe 404
13:18:09 81.86.105.27 GET /winnt/system32/cmd.exe 404
13:18:10 81.86.105.27 GET /winnt/system32/cmd.exe 404
13:18:10 81.86.105.27 GET /scripts/..%5c../winnt/system32/cmd.exe 404
13:18:11 81.86.105.27 GET /scripts/..%5c../winnt/system32/cmd.exe 404
13:18:11 81.86.105.27 GET /scripts/..%5c../winnt/system32/cmd.exe 404
13:18:13 81.86.105.27 GET /scripts/..%2f../winnt/system32/cmd.exe 404
13:50:52 81.86.179.17 GET /scripts/root.exe 404
13:50:53 81.86.179.17 GET /MSADC/root.exe 404
13:50:54 81.86.179.17 GET /c/winnt/system32/cmd.exe 500
13:50:54 81.86.179.17 GET /d/winnt/system32/cmd.exe 404
13:50:54 81.86.179.17 GET /scripts/..%5c../winnt/system32/cmd.exe 404
13:50:55 81.86.179.17 GET /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
13:50:55 81.86.179.17 GET /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
13:50:55 81.86.179.17 GET /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe 404
13:50:57 81.86.179.17 GET /scripts/..Á../winnt/system32/cmd.exe 404
13:50:57 81.86.179.17 GET /scripts/winnt/system32/cmd.exe 404
13:50:58 81.86.179.17 GET /winnt/system32/cmd.exe 404
13:50:58 81.86.179.17 GET /winnt/system32/cmd.exe 404
13:51:00 81.86.179.17 GET /scripts/..%5c../winnt/system32/cmd.exe 404
13:51:00 81.86.179.17 GET /scripts/..%5c../winnt/system32/cmd.exe 404
13:51:02 81.86.179.17 GET /scripts/..%5c../winnt/system32/cmd.exe 404
13:51:05 81.86.179.17 GET /scripts/..%2f../winnt/system32/cmd.exe 404
14:29:03 81.86.105.27 GET /scripts/root.exe 404
14:29:03 81.86.105.27 GET /MSADC/root.exe 404
14:29:03 81.86.105.27 GET /c/winnt/system32/cmd.exe 500
14:29:03 81.86.105.27 GET /d/winnt/system32/cmd.exe 404
14:29:03 81.86.105.27 GET /scripts/..%5c../winnt/system32/cmd.exe 404
14:29:04 81.86.105.27 GET /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
14:29:04 81.86.105.27 GET /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
14:29:04 81.86.105.27 GET /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe 404
14:29:04 81.86.105.27 GET /scripts/..Á../winnt/system32/cmd.exe 404
14:29:04 81.86.105.27 GET /scripts/winnt/system32/cmd.exe 404
14:29:06 81.86.105.27 GET /winnt/system32/cmd.exe 404
14:29:06 81.86.105.27 GET /winnt/system32/cmd.exe 404
14:29:06 81.86.105.27 GET /scripts/..%5c../winnt/system32/cmd.exe 404
14:29:06 81.86.105.27 GET /scripts/..%5c../winnt/system32/cmd.exe 404
14:29:07 81.86.105.27 GET /scripts/..%5c../winnt/system32/cmd.exe 404
14:29:07 81.86.105.27 GET /scripts/..%2f../winnt/system32/cmd.exe 404
15:07:03 81.86.105.27 GET /scripts/root.exe 404
15:07:03 81.86.105.27 GET /MSADC/root.exe 404
15:07:03 81.86.105.27 GET /c/winnt/system32/cmd.exe 500
15:07:06 81.86.105.27 GET /d/winnt/system32/cmd.exe 404
15:07:06 81.86.105.27 GET /scripts/..%5c../winnt/system32/cmd.exe 404
15:07:06 81.86.105.27 GET /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
15:07:06 81.86.105.27 GET /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
15:07:06 81.86.105.27 GET /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe 404
15:07:06 81.86.105.27 GET /scripts/..Á../winnt/system32/cmd.exe 404
15:07:07 81.86.105.27 GET /scripts/winnt/system32/cmd.exe 404
15:07:07 81.86.105.27 GET /winnt/system32/cmd.exe 404
15:07:07 81.86.105.27 GET /winnt/system32/cmd.exe 404
15:07:07 81.86.105.27 GET /scripts/..%5c../winnt/system32/cmd.exe 404
15:07:07 81.86.105.27 GET /scripts/..%5c../winnt/system32/cmd.exe 404
15:07:08 81.86.105.27 GET /scripts/..%5c../winnt/system32/cmd.exe 404
15:07:08 81.86.105.27 GET /scripts/..%2f../winnt/system32/cmd.exe 404
15:24:02 81.86.105.27 GET /scripts/root.exe 404
15:24:02 81.86.105.27 GET /MSADC/root.exe 404
15:24:02 81.86.105.27 GET /c/winnt/system32/cmd.exe 500
15:24:02 81.86.105.27 GET /d/winnt/system32/cmd.exe 404
15:24:02 81.86.105.27 GET /scripts/..%5c../winnt/system32/cmd.exe 404
15:24:02 81.86.105.27 GET /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
15:24:02 81.86.105.27 GET /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
15:24:03 81.86.105.27 GET /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe 404
15:24:03 81.86.105.27 GET /scripts/..Á../winnt/system32/cmd.exe 404
15:24:03 81.86.105.27 GET /scripts/winnt/system32/cmd.exe 404
15:24:03 81.86.105.27 GET /winnt/system32/cmd.exe 404
15:24:03 81.86.105.27 GET /winnt/system32/cmd.exe 404
15:24:05 81.86.105.27 GET /scripts/..%5c../winnt/system32/cmd.exe 404
15:24:05 81.86.105.27 GET /scripts/..%5c../winnt/system32/cmd.exe 404
15:24:05 81.86.105.27 GET /scripts/..%5c../winnt/system32/cmd.exe 404
15:24:05 81.86.105.27 GET /scripts/..%2f../winnt/system32/cmd.exe 404
15:48:40 81.86.125.124 GET /scripts/root.exe 404
15:48:40 81.86.125.124 GET /MSADC/root.exe 404
15:48:40 81.86.125.124 GET /c/winnt/system32/cmd.exe 500
15:48:40 81.86.125.124 GET /d/winnt/system32/cmd.exe 404
15:48:41 81.86.125.124 GET /scripts/..%5c../winnt/system32/cmd.exe 404
15:48:41 81.86.125.124 GET /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
15:48:41 81.86.125.124 GET /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
15:48:41 81.86.125.124 GET /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe 404
15:48:42 81.86.125.124 GET /scripts/..Á../winnt/system32/cmd.exe 404
15:48:42 81.86.125.124 GET /scripts/winnt/system32/cmd.exe 404
15:48:42 81.86.125.124 GET /winnt/system32/cmd.exe 404
15:48:42 81.86.125.124 GET /winnt/system32/cmd.exe 404
15:48:43 81.86.125.124 GET /scripts/..%5c../winnt/system32/cmd.exe 404
15:48:43 81.86.125.124 GET /scripts/..%5c../winnt/system32/cmd.exe 404
15:48:43 81.86.125.124 GET /scripts/..%5c../winnt/system32/cmd.exe 404
15:48:43 81.86.125.124 GET /scripts/..%2f../winnt/system32/cmd.exe 404
16:18:54 81.86.125.124 GET /scripts/root.exe 404
16:18:54 81.86.125.124 GET /MSADC/root.exe 404
16:18:54 81.86.125.124 GET /c/winnt/system32/cmd.exe 500
16:18:54 81.86.125.124 GET /d/winnt/system32/cmd.exe 404
16:18:55 81.86.125.124 GET /scripts/..%5c../winnt/system32/cmd.exe 404
16:18:55 81.86.125.124 GET /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
16:18:55 81.86.125.124 GET /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
16:18:55 81.86.125.124 GET /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe 404
16:18:57 81.86.125.124 GET /scripts/..Á../winnt/system32/cmd.exe 404
16:18:57 81.86.125.124 GET /scripts/winnt/system32/cmd.exe 404
16:18:57 81.86.125.124 GET /winnt/system32/cmd.exe 404
16:18:57 81.86.125.124 GET /winnt/system32/cmd.exe 404
16:18:58 81.86.125.124 GET /scripts/..%5c../winnt/system32/cmd.exe 404
16:18:58 81.86.125.124 GET /scripts/..%5c../winnt/system32/cmd.exe 404
16:18:58 81.86.125.124 GET /scripts/..%5c../winnt/system32/cmd.exe 404
16:18:58 81.86.125.124 GET /scripts/..%2f../winnt/system32/cmd.exe 404
16:48:24 81.86.105.27 GET /scripts/root.exe 404
16:48:26 81.86.105.27 GET /MSADC/root.exe 404
16:48:26 81.86.105.27 GET /c/winnt/system32/cmd.exe 500
16:48:28 81.86.105.27 GET /d/winnt/system32/cmd.exe 404
16:48:29 81.86.105.27 GET /scripts/..%5c../winnt/system32/cmd.exe 404
16:48:30 81.86.105.27 GET /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
16:48:31 81.86.105.27 GET /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
16:48:33 81.86.105.27 GET /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe 404
16:48:34 81.86.105.27 GET /scripts/..Á../winnt/system32/cmd.exe 404
16:48:35 81.86.105.27 GET /scripts/winnt/system32/cmd.exe 404
16:48:36 81.86.105.27 GET /winnt/system32/cmd.exe 404
16:48:37 81.86.105.27 GET /winnt/system32/cmd.exe 404
16:48:38 81.86.105.27 GET /scripts/..%5c../winnt/system32/cmd.exe 404
16:48:42 81.86.105.27 GET /scripts/..%5c../winnt/system32/cmd.exe 404
16:48:43 81.86.105.27 GET /scripts/..%5c../winnt/system32/cmd.exe 404
16:48:44 81.86.105.27 GET /scripts/..%2f../winnt/system32/cmd.exe 404
17:18:53 81.86.152.11 GET /scripts/root.exe 404
17:18:53 81.86.152.11 GET /MSADC/root.exe 404
17:18:53 81.86.152.11 GET /c/winnt/system32/cmd.exe 500
17:18:53 81.86.152.11 GET /d/winnt/system32/cmd.exe 404
17:18:54 81.86.152.11 GET /scripts/..%5c../winnt/system32/cmd.exe 404
17:18:54 81.86.152.11 GET /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
17:18:54 81.86.152.11 GET /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
17:18:54 81.86.152.11 GET /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe 404
17:18:55 81.86.152.11 GET /scripts/..Á../winnt/system32/cmd.exe 404
17:18:55 81.86.152.11 GET /scripts/winnt/system32/cmd.exe 404
17:18:55 81.86.152.11 GET /winnt/system32/cmd.exe 404
17:18:55 81.86.152.11 GET /winnt/system32/cmd.exe 404
17:18:56 81.86.152.11 GET /scripts/..%5c../winnt/system32/cmd.exe 404
17:18:56 81.86.152.11 GET /scripts/..%5c../winnt/system32/cmd.exe 404
17:18:56 81.86.152.11 GET /scripts/..%5c../winnt/system32/cmd.exe 404
17:18:58 81.86.152.11 GET /scripts/..%2f../winnt/system32/cmd.exe 404
17:40:35 81.86.105.27 GET /scripts/root.exe 404
17:40:35 81.86.105.27 GET /MSADC/root.exe 404
17:40:35 81.86.105.27 GET /c/winnt/system32/cmd.exe 500
17:40:36 81.86.105.27 GET /d/winnt/system32/cmd.exe 404
17:40:36 81.86.105.27 GET /scripts/..%5c../winnt/system32/cmd.exe 404
17:40:40 81.86.105.27 GET /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
17:40:40 81.86.105.27 GET /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 404
17:40:40 81.86.105.27 GET /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe 404
17:40:40 81.86.105.27 GET /scripts/..Á../winnt/system32/cmd.exe 404
17:40:41 81.86.105.27 GET /scripts/winnt/system32/cmd.exe 404
17:40:41 81.86.105.27 GET /winnt/system32/cmd.exe 404
17:40:41 81.86.105.27 GET /winnt/system32/cmd.exe 404
17:40:41 81.86.105.27 GET /scripts/..%5c../winnt/system32/cmd.exe 404
17:40:42 81.86.105.27 GET /scripts/..%5c../winnt/system32/cmd.exe 404
17:40:42 81.86.105.27 GET /scripts/..%5c../winnt/system32/cmd.exe 404
17:40:42 81.86.105.27 GET /scripts/..%2f../winnt/system32/cmd.exe 404
19:07:31 217.199.175.99 HEAD /index.htm 200
19:43:30 217.199.175.99 HEAD /index.htm 200
20:22:08 217.199.175.99 HEAD /index.htm 200
21:09:35 205.158.204.222 GET / 400