Chinaz.com - ÖйúÕ¾³¤Õ¾

ÄäÃûͶ¸å Ͷ¸åÖ¸ÄÏ RSS¶©ÔÄ Õ¾³¤×ÊѶͨ¸æ:
ËÑË÷: ÄúµÄλÖãºÖ÷Ò³>·þ Îñ Æ÷>°²È«·À»¤>ÔĶÁ×ÊѶ£º´Ó·þÎñÆ÷µÄ¼Ç¼ѰÕҺڿ͵ÄÖëË¿Âí¼£

´Ó·þÎñÆ÷µÄ¼Ç¼ѰÕҺڿ͵ÄÖëË¿Âí¼£

2008-04-23 16:16:36 À´Ô´:ÐÂÔÆ ×÷Õß:ØýÃû ¡¾´ó ÖРС¡¿ ÆÀÂÛ£º0 Ìõ

·ÖÎö¹ý³Ì
¡¡¡¡
ÍøÒ³·þÎñÆ÷°æ±¾ÊǺÜÖØÒªµÄÐÅÏ¢£¬ºÚ¿ÍÒ»°ãÏÈÏòÍøÒ³·þÎñÆ÷Ìá³öÒªÇó£¬È÷þÎñÆ÷Ëͻر¾ÉíµÄ°æ±¾ÐÅÏ¢¡£Ö»Òª°Ñ¡¸HEAD / HTTP/1.0¡¹Õâ¸ö×Ö·û´®Óó£¼ûµÄnetcat utility£¨Ïà¹Ø×ÊÁÏÍøÖ·£ºhttp://www.l0pht.com/~weld/netcat/£©ºÍOpenSSL binary£¨Ïà¹Ø×ÊÁÏÍøÖ·£ºhttp://www.openssl.org/£©Ë͵½¿ª·Å·þÎñÆ÷µÄͨѶ¶Ë¿Ú¾Í³ÉÁË¡£×¢Òâ¿´ÏÂÃæµÄʾ·¶£º
C:>nc -n 10.0.2.55 80
HEAD / HTTP/1.0
HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Sun, 08 Mar 2001 14:31:00 GMT
Content-Type: text/html
Set-Cookie: ASPSESSIONIDGQQQQQPA=IHOJAGJDECOLLGIBNKMCEEED; path=/
Cache-control: private
¡¡¡¡
ÕâÖÖÐÎʽµÄÒªÇóÔÚIISºÍApacheµÄ¼Ç¼ÎļþÖлáÉú³ÉÒÔϼǼ£º
IIS: 15:08:44 11.1.2.80 HEAD /Default.asp 200 
Linux: 11.1.2.80 - - [08/Mar/2001:15:56:39 -0700] "HEAD / HTTP/1.0" 200 0 
¡¡¡¡
ËäÈ»ÕâÀàÒªÇóºÏ·¨£¬¿´ËÆºÜÆ½³££¬²»¹ýÈ´³£³£ÊÇÍøÂç¹¥»÷µÄǰ×àÇú¡£access_logºÍIISµÄ¼Ç¼ÎļþûÓбíÃ÷Õâ¸öÒªÇóÊÇÁ¬µ½SSL·þÎñÆ÷»¹ÊÇÒ»°ãµÄÍøÒ³·þÎñÆ÷£¬¿ÉÊÇApacheµÄ ssl_request_logºÍssl_engine_log£¨ÔÚ/usr/local/apache/logsĿ¼Ï£©ÕâÁ½¸ö¼Ç¼Îļþ¾Í»á¼Ç¼ÊÇ·ñÓÐÁª»úµ½SSL·þÎñÆ÷¡£Çë¿´ÒÔϵÄssl_request_log¼Ç¼Îļþ£º
[07/Mar/2001:15:32:52 -0700] 11.1.1.50 SSLv3 EDH-RSA-DES-CBC3-SHA "HEAD / HTTP/1.0" 0 
¡¡¡¡
µÚÈýºÍµÚËĸö×ֶαíʾ¿Í»§¶ËʹÓõÄÊÇÄÄÖÖ¼ÓÃÜ·½Ê½¡£ÒÔϵÄssl_request_log·Ö±ð¼Ç¼´ÓOpenSSL¡¢ Internet ExplorerºÍNetscape¿Í»§¶Ë³ÌÐò·¢³öµÄÒªÇó¡£
[07/Mar/2001:15:48:26 -0700] 11.1.1.50 SSLv3 EDH-RSA-DES-CBC3-SHA "GET / HTTP/1.0" 2692
[07/Mar/2001:15:52:51 -0700] 10.0.2.55 TLSv1 RC4-MD5 "GET / HTTP/1.1" 2692
[07/Mar/2001:15:54:46 -0700] 11.1.1.50 SSLv3 EXP-RC4-MD5 "GET / HTTP/1.0" 2692
[07/Mar/2001:15:55:34 –0700] 11.1.2.80 SSLv3 RC4-MD5 “GET / HTTP/1.0” 2692
       
ÁíÍâºÚ¿Íͨ³£»á¸´ÖÆÒ»¸öÍøÕ¾£¨Ò²¾ÍÊÇËùνµÄ¾µÉäÍøÕ¾¡££©£¬À´È¡µÃ·¢¶¯¹¥»÷ËùÐèÒªµÄÐÅÏ¢¡£ÍøÒ³Ô­Ê¼ÂëÖеÄÅú×¢×ֶγ£ÓÐĿ¼¡¢ÎļþÃûÉõÖÁÃÜÂëµÄÓÐÓÃ×ÊÁÏ¡£¸´ÖÆÍøÕ¾³£ÓõŤ¾ß°üÀ¨´°¿ÚϵͳµÄTeleport Pro£¨ÍøÖ·£ºhttp://www.tenmax.com/teleport/pro/home.htm£©ºÍUnixϵͳµÄwget£¨ÍøÖ·£ºhttp://www.gnu.org/manual/wget/£©¡£ÔÚÕâÀïÎÒΪ´ó¼Ò·ÖÎöwgetºÍTeleportProÕâÁ½¸öÈí¼þ¹¥»÷ÍøÒ³·þÎñÆ÷ºó¼Ç¼ÎļþÖеÄÄÚÈÝ¡£ÕâÁ½¸öÈí¼þÄÜÈ«Ãæ¿ìËÙËÑѰÕû¸öÍøÕ¾£¬¶ÔËùÓй«¿ªµÄÍøÒ³Ìá³öÒªÇó¡£Ö»Òª¼ì²éһϼǼÎļþ¾ÍÖªµÀ£¬Òª½âÒë¾µÉäÕâ¸ö¶¯×÷ÊǺܼòµ¥µÄÊ¡£ÒÔÏÂÊÇIISµÄ¼Ç¼Îļþ£º
16:28:52 11.1.2.80 GET /Default.asp 200
16:28:52 11.1.2.80 GET /robots.txt 404
16:28:52 11.1.2.80 GET /header_protecting_your_privacy.gif 200
16:28:52 11.1.2.80 GET /header_fec_reqs.gif 200
16:28:55 11.1.2.80 GET /photo_contribs_sidebar.jpg 200
16:28:55 11.1.2.80 GET /g2klogo_white_bgd.gif 200
16:28:55 11.1.2.80 GET /header_contribute_on_line.gif 200
×¢£º11.1.2.80Õâ¸öÖ÷»úÊÇUnixϵͳµÄ¿Í»§¶Ë£¬ÊÇÓÃwgetÈí¼þ·¢³öÇëÇó¡£
16:49:01 11.1.1.50 GET /Default.asp 200
16:49:01 11.1.1.50 GET /robots.txt 404
16:49:01 11.1.1.50 GET /header_contribute_on_line.gif 200
16:49:01 11.1.1.50 GET /g2klogo_white_bgd.gif 200
16:49:01 11.1.1.50 GET /photo_contribs_sidebar.jpg 200
16:49:01 11.1.1.50 GET /header_fec_reqs.gif 200
16:49:01 11.1.1.50 GET /header_protecting_your_privacy.gif 200
×¢£º11.1.1.50ϵͳÊÇ´°¿Ú»·¾³µÄ¿Í»§¶Ë£¬ÓõÄÊÇTeleportPro·¢³öÇëÇó¡£
¡¡¡¡
×¢Ò⣺ÒÔÉÏÁ½¸öÖ÷»ú¶¼ÒªÇórobots.txtÕâ¸öµµ£¬ÆäʵÕâ¸öµµ°¸ÊÇÍøÒ³¹ÜÀíÔ±µÄ¹¤¾ß£¬×÷ÓÃÊÇ·ÀÖ¹wgetºÍTeleportProÕâÀà×Ô¶¯×¥ÎļþÈí¼þ¶ÔÄ³Ð©ÍøÒ³´ÓÊÂץȡ»òËÑѰµÄ¶¯×÷¡£Èç¹ûÓÐÈËÌá³örobots.txtµµµÄÒªÇ󣬳£³£´ú±íÊÇÒª¾µÉäÕû¸öÍøÕ¾¡£µ«£¬TeleportProºÍwgetÕâÁ½¸öÈí¼þ¶¼¿ÉÒÔ°ÑÒªÇórobots.txtÕâ¸öÎļþµÄ¹¦ÄÜÈ¡Ïû¡£ÁíÒ»¸öÕì²â¾µÉ䶯×÷µÄ·½Ê½£¬ÊÇ¿´¿´ÓÐûÓÐͬһ¸ö¿Í»§¶ËIP·´¸´Ìá³ö×ÊÔ´ÒªÇó¡£
       
ºÚ¿Í»¹¿ÉÒÔÓÃÍøÒ³Â©¶´»üºËÈí¼þ£ºWhisker£¨ÍøÖ·£ºhttp://www.wiretrip.net/£©£¬À´Õì²éÍøÒ³·þÎñÆ÷ÓÐûÓа²È«ºóÃÅ£¨Ö÷ÒªÊǼì²éÓÐûÓÐcgi-bin³ÌÐò£¬ÕâÖÖ³ÌÐò»áÈÃϵͳ²úÉú°²È«Â©¶´£©¡£ÒÔÏÂÊÇIISºÍApacheÍøÒ³·þÎñÆ÷ÔÚÖ´ÐÐWhiskerºó²úÉúµÄ²¿·Ö¼Ç¼Îļþ¡£
IIS£º
13:17:56 11.1.1.50 GET /SiteServer/Publishing/viewcode.asp 404
13:17:56 11.1.1.50 GET /msadc/samples/adctest.asp 200
13:17:56 11.1.1.50 GET /advworks/equipment/catalog_type.asp 404
13:17:56 11.1.1.50 GET /iisadmpwd/aexp4b.htr 200
13:17:56 11.1.1.50 HEAD /scripts/samples/details.idc 200
13:17:56 11.1.1.50 GET /scripts/samples/details.idc 200
13:17:56 11.1.1.50 HEAD /scripts/samples/ctguestb.idc 200
13:17:56 11.1.1.50 GET /scripts/samples/ctguestb.idc 200
13:17:56 11.1.1.50 HEAD /scripts/tools/newdsn.exe 404
13:17:56 11.1.1.50 HEAD /msadc/msadcs.dll 200
13:17:56 11.1.1.50 GET /scripts/iisadmin/bdir.htr 200
13:17:56 11.1.1.50 HEAD /carbo.dll 404
13:17:56 11.1.1.50 HEAD /scripts/proxy/ 403
13:17:56 11.1.1.50 HEAD /scripts/proxy/w3proxy.dll 500
13:17:56 11.1.1.50 GET /scripts/proxy/w3proxy.dll 500
Apache£º
11.1.1.50 - - [08/Mar/2001:12:57:28 -0700] "GET /cfcache.map HTTP/1.0" 404 266
11.1.1.50 - - [08/Mar/2001:12:57:28 -0700] "GET /cfide/Administrator/startstop.html HTTP/1.0" 404 289
11.1.1.50 - - [08/Mar/2001:12:57:28 -0700] "GET /cfappman/index.cfm HTTP/1.0" 404 273
11.1.1.50 - - [08/Mar/2001:12:57:28 -0700] "GET /cgi-bin/ HTTP/1.0" 403 267
11.1.1.50 - - [08/Mar/2001:12:57:29 -0700] "GET /cgi-bin/dbmlparser.exe HTTP/1.0" 404 277
11.1.1.50 - - [08/Mar/2001:12:57:29 -0700] "HEAD /_vti_inf.html HTTP/1.0" 404 0
11.1.1.50 - - [08/Mar/2001:12:57:29 -0700] "HEAD /_vti_pvt/ HTTP/1.0" 404 0
11.1.1.50 - - [08/Mar/2001:12:57:29 -0700] "HEAD /cgi-bin/webdist.cgi HTTP/1.0" 404 0
11.1.1.50 - - [08/Mar/2001:12:57:29 -0700] "HEAD /cgi-bin/handler HTTP/1.0" 404 0
11.1.1.50 - - [08/Mar/2001:12:57:29 -0700] "HEAD /cgi-bin/wrap HTTP/1.0" 404 0
11.1.1.50 - - [08/Mar/2001:12:57:29 -0700] "HEAD /cgi-bin/pfdisplay.cgi HTTP/1.0" 404 0 
¡¡¡¡
´ó¼ÒÒªÕì²âÕâÀ๥»÷µÄ¹Ø¼ü£¬¾ÍÔÚÓÚ´Óµ¥Ò»IPµØÖ··¢³ö´óÁ¿µÄ404 HTTP״̬´úÂ롣ֻҪעÒâµ½ÕâÀàÐÅÏ¢£¬¾Í¿ÉÒÔ·ÖÎö¶Ô·½ÒªÇóµÄ×ÊÔ´£»ÓÚÊÇËüÃÇ¾Í»áÆ´ÃüÒªÇóÌṩ cgi-bin scripts£¨Apache ·þÎñÆ÷µÄ cgi-bin Ŀ¼£»IIS·þÎñÆ÷µÄ scriptsĿ¼£©¡£
¡¡¡¡
С½á
¡¡¡¡
ÍøÒ³Èç¹û±»ÈË̽·Ã¹ý£¬×Ü»áÔڼǼÎļþÁôÏÂʲôÏßË÷¡£Èç¹ûÍøÒ³¹ÜÀíÔ±¾¯¾õÐÔ¹»¸ß£¬Ó¦¸Ã»á°Ñ·ÖÎö¼Ç¼Îļþ×÷Ϊ׷²éÏßË÷£¬²¢ÇÒÔÚ¼ì²éºó·¢ÏÖÍøÕ¾ÕæµÄÓЩ¶´Ê±£¬¾ÍÄÜÔ¤²â»áÓкڿ͹¥»÷ÍøÕ¾¡£
¡¡¡¡
½ÓÏÂÀ´ÎÒÒªÏò´ó¼Òʾ·¶Á½ÖÖ³£¼ûµÄÍøÒ³·þÎñÆ÷¹¥»÷·½Ê½£¬·ÖÎö·þÎñÆ÷ÔÚÊܵ½¹¥»÷ºóºÚ¿ÍÔڼǼÎļþÖкۼ£¡£
¡¡¡¡
£¨1£©MDAC¹¥»÷

¡¡¡¡MDAC¹¥»÷·¨¿ÉÒÔÈÃÍøÒ³µÄ¿Í»§¶ËÔÚIISÍøÒ³·þÎñÆ÷ÉÏÖ´ÐÐÃüÁî¡£Èç¹ûÓÐÈË¿ªÊ¼¹¥»÷IIS·þÎñÆ÷£¬¼Ç¼Îļþ¾Í»á¼ÇÏ¿ͻ§¶ËÔø¾­ºô½Ðmsadcs.dllÎĵµ£º
17:48:49 12.1.2.8 GET /msadc/msadcs.dll 200
17:48:51 12.1.2.8 POST /msadc/msadcs.dll 200 
¡¡¡¡
£¨2£©ÀûÓÃԭʼÂë©¶´
¡¡¡¡µÚ¶þÖÖ¹¥»÷·½Ê½Ò²ºÜÆÕ±é£¬¾ÍÊÇ»áÓ°ÏìASPºÍJavaÍøÒ³µÄ±©Â¶Ô­Ê¼Âë©¶´¡£ ×îÍí±»·¢Ïֵݲȫ©¶´ÊÇ +.htr ³ô³æ£¬Õâ¸öbug»áÏÔʾASPԭʼÂë¡£ Èç¹ûÓÐÈËÀûÓÃÕâ¸ö©¶´¹¥»÷£¬¾Í»áÔÚIISµÄ¼Ç¼ÎļþÀïÃæÁôÏÂÕâЩÏßË÷£º
17:50:13 11.1.2.80 GET /default.asp+.htr 200 
¡¡¡¡
ÍøÒ³³£»áÖ»ÈÃÓÐȨÏÞµÄʹÓÃÕß½øÈë¡£½ÓÏÂÀ´ÎÒÃÇÒªÈø÷λ¿´ ApacheµÄaccess_log¼Ç¼Îļþ»áÔڵǼʧ°ÜʱÁôÏÂʲôÏßË÷£º
12.1.2.8 - user [08/Mar/2001:18:58:29 -0700] "GET /private/ HTTP/1.0" 401 462 
       
×¢£ºµÚÈýÀ¸ÀïÃæµÄʹÓÃÕßÃû³ÆÊÇ¡¸user¡¹¡£»¹ÓÐҪעÒâHTTPµÄ״̬´úºÅÊÇ401£¬´ú±í·Ç·¨´æÈ¡¡£

Tags£º·þÎñÆ÷   ºÚ¿Í  
ÔðÈα༭£ºÉêÈðÈð
  • ÇëÎÄÃ÷²ÎÓëÌÖÂÛ£¬½ûÖ¹ÂþÂî¹¥»÷¡£ Óû§Ãû£º £¨ÐÂ×¢²á£© ÃÜÂ룺 ÄäÃû£º
    ÆÀÂÛ×ÜÊý£º Ìõ [ ²é¿´È«²¿ ] ÍøÓÑÆÀÂÛ
    ¹ØÓÚÎÒÃÇ - ÁªÏµÎÒÃÇ - ¹ã¸æ·þÎñ - ÓÑÇéÁ´½Ó - ÍøÕ¾µØÍ¼ - °æÈ¨ÉùÃ÷ - È˲ÅÕÐÆ¸ - °ïÖú