附上web访问日志被挂马那一部分。记住那两个IP,人渣!!
希望kesion技术人员能够看下,是不是系统漏洞。
挂马的人开始了:
2009-10-01 05:48:52 GET /wzxsftp.rar - - 61.145.165.197 HTTP/1.1 Mozilla/4.0 - 404 0 62
2009-10-01 05:48:53 GET /ftp.rar - - 61.145.165.197 HTTP/1.1 Mozilla/4.0 - 404 0 78
2009-10-01 05:48:53 GET /ftp.rar - - 61.145.165.197 HTTP/1.1 Mozilla/4.0 - 404 0 78
2009-10-01 05:48:53 GET /rcpyflashfxp.rar - - 61.145.165.197 HTTP/1.1 Mozilla/4.0 - 404 0 78
2009-10-01 05:48:53 GET /flashfxp.rar - - 61.145.165.197 HTTP/1.1 Mozilla/4.0 - 404 0 78
2009-10-01 05:48:53 GET /flashfxp.rar - - 61.145.165.197 HTTP/1.1 Mozilla/4.0 - 404 0 78
2009-10-01 05:49:08 GET /pvrtmanage/login.asp - - 221.231.114.10 HTTP/1.1 Mozilla/4.0 - 404 0 390
2009-10-01 05:49:08 GET /manage/login.asp - - 221.231.114.10 HTTP/1.1 Mozilla/4.0 - 404 0 375
2009-10-01 05:49:09 GET /manage/login.asp - - 221.231.114.10 HTTP/1.1 Mozilla/4.0 - 404 0 390
2009-10-01 05:49:09 GET /tfevsu.asp - - 221.231.114.10 HTTP/1.1 Mozilla/4.0 - 404 0 375
2009-10-01 05:49:10 GET /su.asp - - 221.231.114.10 HTTP/1.1 Mozilla/4.0 - 404 0 375
2009-10-01 05:49:10 GET /su.asp - - 221.231.114.10 HTTP/1.1 Mozilla/4.0 - 404 0 390
2009-10-01 05:49:11 GET /rsnjzz.asp - - 221.231.114.10 HTTP/1.1 Mozilla/4.0 - 404 0 390
2009-10-01 05:49:12 GET /zz.asp - - 221.231.114.10 HTTP/1.1 Mozilla/4.0 - 404 0 390
2009-10-01 05:49:12 GET /zz.asp - - 221.231.114.10 HTTP/1.1 Mozilla/4.0 - 404 0 375
2009-10-01 05:49:13 GET /ppznservu.asp - - 221.231.114.10 HTTP/1.1 Mozilla/4.0 - 404 0 375
2009-10-01 05:49:13 GET /servu.asp - - 221.231.114.10 HTTP/1.1 Mozilla/4.0 - 404 0 187
2009-10-01 05:49:14 GET /servu.asp - - 221.231.114.10 HTTP/1.1 Mozilla/4.0 - 404 0 375
2009-10-01 05:49:14 GET /bbs/yypyservu.asp - - 221.231.114.10 HTTP/1.1 Mozilla/4.0 - 404 0 187
2009-10-01 05:49:15 GET /bbs/servu.asp - - 221.231.114.10 HTTP/1.1 Mozilla/4.0 - 404 0 390