----- Original Message -----
From: "Ryan Linux" <[EMAIL PROTECTED]>


> Dear All,
>
> Di webserver saya terdapat access log spt dibwah ini :
>
> 202.99.47.215 - - [12/Apr/2002:15:04:09 +0700] "GET
/scripts/root.exe?/c+dir
> HTT
> P/1.0" 404 291
> 202.99.47.215 - - [12/Apr/2002:15:04:14 +0700] "GET /MSADC/root.exe?/c+dir

> Apakah log apakah tersebut suatu virus ? Jika ya bagaimana
menanggulanginya
> ?
>

Itu memang virus yang menginfeksi IIS pada komputer 202.99.47.215, kemudian
berusaha menulari webserver anda, dan tentu saja tidak mungkin bisa.


regards
aris

sumber:
http://httpd.apache.org/docs/misc/FAQ-D.html#codered
Why do I have weird entries in my logs asking for default.ida and cmd.exe?

The host requesting pages from your website and creating those entries is a
Windows machine running IIS that has been infected by an Internet worm such
as Nimda or Code Red. You can safely ignore these error messages as they do
not affect Apache.



-- 
Utk berhenti langganan, kirim email ke [EMAIL PROTECTED]
Informasi arsip di http://www.linux.or.id/milis.php3

Kirim email ke