I&U Home > うにまま(仮) ・  謎ログの友 ・  パスワードコレクション ・  FormMail Scanners

謎ログ

ハッカー・不正侵入にはウイルスバスター2004で対策!
全国のアルバイト情報 - 楽天仕事市場

  • ここには2003年の謎ログがあります。2003年以降の謎ログはlogwatch.htmlにあります。
  • 謎ログをカテゴリに分類してみました。
  • [all] [apache] [exploit] [ftp] [robot] [webalizer] [SEO_SPAM] [others]

    inazuma 

    pl1051.nas926.o-tokyo.nttpc.ne.jp - - [29/Dec/2003:02:00:39 +0900] "GET /mokko/w64_06.gif HTTP/1.1" 200 1838 "http://inazuma/content?Type=Data&KIND=&PARAM=&QUERY=網戸+張替え&WATCH=&EXTRA=&URL=http://iandu.s7.xrea.com/mokko/amido.html" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
    pl1051.nas926.o-tokyo.nttpc.ne.jp - - [29/Dec/2003:02:00:39 +0900] "GET /mokko/arrowu_1.gif HTTP/1.1" 200 944 "http://inazuma/content?Type=Data&KIND=&PARAM=&QUERY=網戸+張替え&WATCH=&EXTRA=&URL=http://iandu.s7.xrea.com/mokko/amido.html" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
    

    /_vti_bin/_vti_aut/author.exe 

    a212-113-164-98.netcabo.pt - - [27/Dec/2003:06:40:33 +0900] "POST /_vti_bin/_vti_aut/author.exe HTTP/1.0" 302 210 "-" "MSFrontPage/4.0"
    a212-113-164-98.netcabo.pt - - [27/Dec/2003:06:40:33 +0900] "POST /_vti_bin/_vti_aut/author.exe HTTP/1.0" 302 210 "-" "MSFrontPage/4.0"
    a212-113-164-98.netcabo.pt - - [27/Dec/2003:06:40:33 +0900] "POST /_vti_bin/_vti_aut/author.dll HTTP/1.0" 302 210 "-" "MSFrontPage/4.0"
    
    http://www.google.co.jp/search?q=cache:9_BiW8r3eD8J:www.hostnexus.com/forum/showthread.php%3Fthreadid%3D1999+/_vti_bin/_vti_aut/author.exe&hl=ja&ie=UTF-8
    http://www.google.co.jp/search?q=cache:m66_Mw0KdgEJ:www.lec.netnfu.ne.jp/textpj/lmsinfo/fp/security.htm+/_vti_bin/_vti_aut/author.exe&hl=ja&lr=lang_ja&ie=UTF-8

    "Mozilla/4.0 compatible ZyBorg/1.0 Dead Link Checker (wn.zyborg@looksmart.net; http://www.WISEnutbot.com)" 

    216.88.158.142 - - [25/Dec/2003:00:51:29 +0900] "GET /~genome/links.html HTTP/1.1" 200 6280 "-" "Mozilla/4.0 compatible ZyBorg/1.0 Dead Link Checker (wn.zyborg@looksmart.net; http://www.WISEnutbot.com)"
    
     $ for i in 12 11 10 09 08 07 06
     > do
     > grep "Dead Link Checker" 2003.$i.* | wc
     > done
         343    7203   78967
          39     837    8917
          53    1120   12023
          35     735    7931
           0       0       0
           0       0       0
           0       0       0
     $ 
    

    backlinks.seguru.net 

    64.239.138.76 - - [25/Dec/2003:04:52:10 +0900] "GET / HTTP/1.1" 200 1427 "backlinks.seguru.net/?link-popularity" "Mozilla/5.0 (compatible; Konqueror/2.2.2; Linux 2.2.19; i686)"
    

    goo から Wget されたら 

    202.229.44.68 - - [15/Dec/2003:10:48:13 +0900] "GET /%7Emyhome/index.html HTTP/1.0" 200 2506 "-" "Wget/1.8.2"
    
    Name:    kids06.goo.ne.jp
    Address:  202.229.44.68
    Aliases:  68.44.229.202.in-addr.arpa
    

    usage/bookmarks を探す理由 

    193.55.10.104 - - [02/Dec/2003:01:30:43 +0900] "GET /~ppp/pppkey.html HTTP/1.0" 200 3736 "bookmarks" "Mozilla/4.5 [fr] (Macintosh; U; PPC)"host)
    133.39.9.117 - - [06/Dec/2003:18:56:15 +0900] "GET /%7Eggggg/index.html HTTP/1.0" 200 2080 "bookmarks" "Mozilla/4.7 [ja] (Macintosh; U; PPC)"
    

    UAにランダムな文字列を入れてくるブラウザ 

    adsl-211-228-28.mia.bellsouth.net - - [22/Nov/2003:15:47:54 +0900] "GET /unimama/logwatch.html HTTP/1.1" 200 101684 "-" "nyuspswpddxWmuskco dityxp"
    adsl-211-228-28.mia.bellsouth.net - - [22/Nov/2003:17:56:16 +0900] "GET /unimama/logwatch.html HTTP/1.1" 200 101684 "-" "leymisgaoVmjsnxb lbmocpsiqsaVi"
    adsl-211-228-28.mia.bellsouth.net - - [22/Nov/2003:22:54:06 +0900] "GET /unimama/logwatch.html HTTP/1.1" 200 50536 "-" "plvipnrc9Aq9kdAxgfuuyxxr"
    

    HEAD /xyzzy 

    wooster.netcraft.com - - [19/Nov/2003:22:30:51 +0900] "HEAD / HTTP/1.1" 200 0 "http://www.netcraft.com/survey/" "Mozilla/4.0  (compatible; Netcraft Web Server Survey)"
    wooster.netcraft.com - - [19/Nov/2003:22:30:55 +0900] "HEAD /xyzzy HTTP/1.0" 302 0 "http://www.netcraft.com/survey/" "Mozilla/4.0 (compatible; Netcraft Web Server Survey)"
    

    逆アクセスログランキングを狙った検索エンジンスパム 

    141.85.3.130 - - [17/Nov/2003:04:34:29 +0900] "GET / HTTP/1.0" 200 955 "http://www.saulem.com/" "MSIE 6.0"
    141.85.3.130 - - [17/Nov/2003:11:10:10 +0900] "GET / HTTP/1.0" 200 955 "http://www.bongohome.com/" "MSIE 6.0"
    141.85.3.130 - - [17/Nov/2003:17:49:41 +0900] "GET / HTTP/1.0" 200 955 "http://www.akksess.com/" "MSIE 6.0"
    141.85.3.130 - - [18/Nov/2003:00:53:42 +0900] "GET / HTTP/1.0" 200 955 "http://www.kwlablog.com/" "MSIE 6.0"
    217.73.164.106 - - [18/Nov/2003:10:57:55 +0900] "GET / HTTP/1.0" 200 955 "http://www.jennifersblog.com/" "MSIE 6.0"
    

    FunWebProducts 

    195.93.32.8 - - [17/Nov/2003:00:59:35 +0900] "GET /~tttt/html/TT5.dmel0.mas.135.html HTTP/1.0" 200 2912 "XXXX:++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++" "Mozilla/4.0 (compatible; MSIE 5.5; AOL 8.0; Windows NT 5.0; FunWebProducts)" 
    

    偶然なんだろうけれど 

    Nov 17 11:43:15 myhost ftpd[25380]: FTPD: connection from defense-4-81-57-92-161.fbx.proxa at Mon Nov 17 11:43:15 2003
    Nov 17 11:43:15 myhost ftpd[25380]: <--- 220 
    Nov 17 11:43:15 myhost ftpd[25380]: myhost FTP server () ready.
    Nov 17 11:43:16 myhost ftpd[25380]: FTPD: command: USER anonymous^M
    Nov 17 11:43:16 myhost ftpd[25380]: <--- 331 
    Nov 17 11:43:16 myhost ftpd[25380]: Guest login ok, send ident as password.
    Nov 17 11:43:16 myhost ftpd[25380]: FTPD: command: PASS Igpuser@home.com^M
    Nov 17 11:43:16 myhost ftpd[25380]: <--- 230 
    Nov 17 11:43:16 myhost ftpd[25380]: Guest login ok, access restrictions apply.
    Nov 17 11:43:17 myhost ftpd[25380]: FTPD: command: CWD /pub/^M
    Nov 17 11:43:17 myhost ftpd[25380]: <--- 250 
    Nov 17 11:43:17 myhost ftpd[25380]: CWD command successful.
    Nov 17 11:43:18 myhost ftpd[25380]: FTPD: command: MKD 031117034322p^M
    Nov 17 11:43:18 myhost ftpd[25380]: <--- 550 
    Nov 17 11:43:18 myhost ftpd[25380]: 031117034322p: Permission denied.
    	:
    	:
    Nov 17 11:43:28 myhost ftpd[25380]: FTPD: command: CWD /home/^M
    Nov 17 11:43:28 myhost ftpd[25380]: <--- 550 
    Nov 17 11:43:28 myhost ftpd[25380]: /home/: No such file or directory.
    Nov 17 11:43:29 myhost ftpd[25380]: <--- 221 
    Nov 17 11:43:29 myhost ftpd[25380]: You could at least say goodbye.
    Nov 17 12:08:29 myhost ftpd[25516]: FTPD: connection from pD9ED3888.dip.t-dialin.net at Mon Nov 17 12:08:29 2003
    Nov 17 12:08:29 myhost ftpd[25516]: <--- 220 
    Nov 17 12:08:29 myhost ftpd[25516]: myhost FTP server () ready.
    Nov 17 12:08:30 myhost ftpd[25516]: FTPD: command: USER anonymous^M
    Nov 17 12:08:30 myhost ftpd[25516]: <--- 331 
    Nov 17 12:08:30 myhost ftpd[25516]: Guest login ok, send ident as password.
    Nov 17 12:08:31 myhost ftpd[25516]: FTPD: command: PASS Igpuser@home.com^M
    Nov 17 12:08:31 myhost ftpd[25516]: <--- 230 
    Nov 17 12:08:31 myhost ftpd[25516]: Guest login ok, access restrictions apply.
    Nov 17 12:08:31 myhost ftpd[25516]: FTPD: command: CWD /pub/^M
    Nov 17 12:08:31 myhost ftpd[25516]: <--- 250 
    Nov 17 12:08:31 myhost ftpd[25516]: CWD command successful.
    Nov 17 12:08:32 myhost ftpd[25516]: FTPD: command: MKD 031117041022p^M
    Nov 17 12:08:32 myhost ftpd[25516]: <--- 550 
    Nov 17 12:08:32 myhost ftpd[25516]: 031117041022p: Permission denied.
    	:
    	:
    

    自分の物でもないのに 

    219.117.176.252 - - [16/Nov/2003:00:21:50 +0900] "OPTIONS / HTTP/1.1" 200 - "-" "Microsoft Data Access Internet Publishing Provider Protocol Discovery" 
    219.117.176.252 - - [16/Nov/2003:00:21:50 +0900] "OPTIONS /%7Eppp HTTP/1.1" 301 322 "-" "Microsoft Data Access Internet Publishing Provider Protocol Discovery" 
    219.117.176.252 - - [16/Nov/2003:00:21:50 +0900] "OPTIONS /%7Eppp/ HTTP/1.1" 200 - "-" "Microsoft Data Access Internet Publishing Provider Protocol Discovery" 
    219.117.176.252 - - [16/Nov/2003:00:21:51 +0900] "GET /_vti_inf.html HTTP/1.1" 404 294 "-" "Mozilla/2.0 (compatible; MS FrontPage 5.0)" 
    219.117.176.252 - - [16/Nov/2003:00:21:51 +0900] "POST /_vti_bin/shtml.exe/_vti_rpc HTTP/1.1" 404 308 "-" "MSFrontPage/5.0" 
    219.117.176.252 - - [16/Nov/2003:00:21:52 +0900] "OPTIONS / HTTP/1.1" 200 - "-" "Microsoft Data Access Internet Publishing Provider Protocol Discovery" 
    219.117.176.252 - - [16/Nov/2003:00:21:52 +0900] "OPTIONS /%7Eppp HTTP/1.1" 301 322 "-" "Microsoft Data Access Internet Publishing Provider Protocol Discovery" 
    219.117.176.252 - - [16/Nov/2003:00:21:52 +0900] "OPTIONS /%7Eppp/ HTTP/1.1" 200 - "-" "Microsoft Data Access Internet Publishing Provider Protocol Discovery" 
    219.117.176.252 - - [16/Nov/2003:00:21:53 +0900] "GET /_vti_inf.html HTTP/1.1" 404 294 "-" "Mozilla/2.0 (compatible; MS FrontPage 5.0)" 
    219.117.176.252 - - [16/Nov/2003:00:21:53 +0900] "POST /_vti_bin/shtml.exe/_vti_rpc HTTP/1.1" 404 308 "-" "MSFrontPage/5.0" 
    219.117.176.252 - - [16/Nov/2003:00:21:53 +0900] "OPTIONS / HTTP/1.1" 200 - "-" "Microsoft Data Access Internet Publishing Provider Protocol Discovery" 
    219.117.176.252 - - [16/Nov/2003:00:21:53 +0900] "OPTIONS /%7Eppp/whatppp-j.html HTTP/1.1" 200 - "-" "Microsoft Data Access Internet Publishing Provider Protocol Discovery" 
    219.117.176.252 - - [16/Nov/2003:00:21:53 +0900] "GET /_vti_inf.html HTTP/1.1" 404 294 "-" "Mozilla/2.0 (compatible; MS FrontPage 5.0)" 
    219.117.176.252 - - [16/Nov/2003:00:21:54 +0900] "POST /_vti_bin/shtml.exe/_vti_rpc HTTP/1.1" 404 308 "-" "MSFrontPage/5.0" 
    219.117.176.252 - - [16/Nov/2003:00:21:54 +0900] "GET /~ppp/whatppp-j.html HTTP/1.1" 304 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.0.3705)" 
    219.117.176.252 - - [16/Nov/2003:00:21:55 +0900] "GET /~ppp/IMG/logoM.gif HTTP/1.1" 304 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.0.3705)" 
    219.117.176.252 - - [16/Nov/2003:00:22:19 +0900] "PROPFIND /%7Eppp HTTP/1.1" 301 322 "-" "Microsoft-WebDAV-MiniRedir/5.1.2600" 
    219.117.176.252 - - [16/Nov/2003:00:22:19 +0900] "PROPFIND /~ppp/ HTTP/1.1" 405 324 "-" "Microsoft-WebDAV-MiniRedir/5.1.2600" 
    219.117.176.252 - - [16/Nov/2003:00:22:19 +0900] "PROPFIND /%7Eppp HTTP/1.1" 301 322 "-" "Microsoft-WebDAV-MiniRedir/5.1.2600" 
    219.117.176.252 - - [16/Nov/2003:00:22:20 +0900] "PROPFIND /~ppp/ HTTP/1.1" 405 324 "-" "Microsoft-WebDAV-MiniRedir/5.1.2600" 
    219.117.176.252 - - [16/Nov/2003:00:22:20 +0900] "OPTIONS / HTTP/1.1" 200 - "-" "Microsoft-WebDAV-MiniRedir/5.1.2600" 
    219.117.176.252 - - [16/Nov/2003:00:22:20 +0900] "PROPFIND /%7Eppp HTTP/1.1" 301 322 "-" "Microsoft-WebDAV-MiniRedir/5.1.2600" 
    219.117.176.252 - - [16/Nov/2003:00:22:20 +0900] "PROPFIND /~ppp/ HTTP/1.1" 405 324 "-" "Microsoft-WebDAV-MiniRedir/5.1.2600" 
    

    検索エンジンはなぜ usage/bookmarks を探すのか? 

    216.39.48.112 - - [25/Oct/2003:12:10:43 +0900] "GET /~ppp/usage/bookmarks HTTP/1.1" 404 301 "-" "Scooter/3.2"
    64.68.82.170 - - [25/Oct/2003:19:19:10 +0900] "GET /~ppp/usage/bookmarks HTTP/1.0" 404 289 "-" "Googlebot/2.1 (+http://www.googlebot.com/bot.html)"
    64.68.82.18 - - [25/Oct/2003:19:22:16 +0900] "GET /~ppp/usage/bookmarks HTTP/1.0" 404 289 "-" "Googlebot/2.1 (+http://www.googlebot.com/bot.html)" 
    64.68.82.136 - - [25/Oct/2003:22:07:12 +0900] "GET /~ppp/usage/bookmarks HTTP/1.0" 404 289 "-" "Googlebot/2.1 (+http://www.googlebot.com/bot.html)"
    

    msnbot/0.11 (+http://search.msn.com/msnbot.htm) 

    204.95.98.252 - - [04/Nov/2003:04:04:04 +0900] "GET /%7Eggggg/mailto/:gggg-admin/@mydomain.xxx.xxx.xxx.xxx HTTP/1.0" 404 321 "-" "msnbot/0.11 (+http://search.msn.com/msnbot.htm)"
    

    なぜうちに? 

    211.152.11.8 - - [02/Nov/2003:00:45:37 +0900] "GET /images2001/regobauble-b.gif HTTP/1.1" 404 308 "-" "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)" 
    211.152.11.8 - - [02/Nov/2003:01:43:45 +0900] "GET /images2001/clear.gif HTTP/1.1" 404 301 "-" "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)" 
    211.152.11.8 - - [02/Nov/2003:02:55:35 +0900] "GET /images2001/menu-filler3.jpg HTTP/1.1" 404 308 "-" "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)" 
    	:
    	:
    

    ten.com 

    そうじゃなくて・・・ 

    128.255.116.124 - - [09/Oct/2003:01:30:44 +0900] "GET /~ppp/cgi-bin/PPP/PPPseqen.pl.cgi?A900534 > PPP_SEQUENCES/A900534.txt" 400 377 "-" "-" 
    128.255.116.124 - - [09/Oct/2003:01:30:44 +0900] "GET /~ppp/cgi-bin/PPP/PPPseqen.pl.cgi?A900756 > PPP_SEQUENCES/A900756.txt" 400 377 "-" "-" 
    

    お初にお目にかかったので:mkd _K4e 

    Oct  8 23:57:25 myhost ftpd[12560]: FTPD: connection from pD9E40E3F.dip.t-dialin.net at Wed Oct  8 23:57:25 2003
    Oct  8 23:57:25 myhost ftpd[12560]: <--- 220 
    Oct  8 23:57:25 myhost ftpd[12560]: myhost FTP server () ready.
    Oct  8 23:57:25 myhost ftpd[12560]: FTPD: command: user anonymous^M
    Oct  8 23:57:25 myhost ftpd[12560]: <--- 331 
    Oct  8 23:57:25 myhost ftpd[12560]: Guest login ok, send ident as password.
    Oct  8 23:57:25 myhost ftpd[12560]: FTPD: command: pass anon@ymo.us^M
    Oct  8 23:57:25 myhost ftpd[12560]: <--- 230 
    Oct  8 23:57:25 myhost ftpd[12560]: Guest login ok, access restrictions apply.
    Oct  8 23:57:26 myhost ftpd[12560]: FTPD: command: mkd _K4e^M
    Oct  8 23:57:26 myhost ftpd[12560]: <--- 550 
    Oct  8 23:57:26 myhost ftpd[12560]: _K4e: Permission denied.
    Oct  8 23:57:26 myhost ftpd[12560]: FTPD: command: pwd^M
    Oct  8 23:57:26 myhost ftpd[12560]: <--- 257 
    Oct  8 23:57:26 myhost ftpd[12560]: "/" is current directory.
    Oct  8 23:57:26 myhost ftpd[12560]: FTPD: command: cwd pub^M
    Oct  8 23:57:26 myhost ftpd[12560]: <--- 250 
    Oct  8 23:57:26 myhost ftpd[12560]: CWD command successful.
    Oct  8 23:57:27 myhost ftpd[12560]: FTPD: command: mkd _K4e^M
    Oct  8 23:57:27 myhost ftpd[12560]: <--- 550 
    Oct  8 23:57:27 myhost ftpd[12560]: _K4e: Permission denied.
    Oct  8 23:57:27 myhost ftpd[12560]: FTPD: command: pwd^M
    Oct  8 23:57:27 myhost ftpd[12560]: <--- 257 
    Oct  8 23:57:27 myhost ftpd[12560]: "/pub" is current directory.
    Oct  8 23:57:28 myhost ftpd[12560]: FTPD: command: cwd public/incoming^M
    Oct  8 23:57:28 myhost ftpd[12560]: <--- 550 
    Oct  8 23:57:28 myhost ftpd[12560]: public/incoming: No such file or directory.
    Oct  8 23:57:28 myhost ftpd[12560]: FTPD: command: mkd _K4e^M
    Oct  8 23:57:28 myhost ftpd[12560]: <--- 550 
    Oct  8 23:57:28 myhost ftpd[12560]: _K4e: Permission denied.
    Oct  8 23:57:28 myhost ftpd[12560]: FTPD: command: pwd^M
    Oct  8 23:57:28 myhost ftpd[12560]: <--- 257 
    Oct  8 23:57:28 myhost ftpd[12560]: "/pub" is current directory.
    Oct  8 23:57:29 myhost ftpd[12560]: FTPD: command: cwd pub/incoming^M
    Oct  8 23:57:29 myhost ftpd[12560]: <--- 550 
    Oct  8 23:57:29 myhost ftpd[12560]: pub/incoming: No such file or directory.
    Oct  8 23:57:29 myhost ftpd[12560]: FTPD: command: mkd _K4e^M
    Oct  8 23:57:29 myhost ftpd[12560]: <--- 550 
    Oct  8 23:57:29 myhost ftpd[12560]: _K4e: Permission denied.
    Oct  8 23:57:29 myhost ftpd[12560]: FTPD: command: pwd^M
    Oct  8 23:57:29 myhost ftpd[12560]: <--- 257 
    Oct  8 23:57:29 myhost ftpd[12560]: "/pub" is current directory.
    Oct  8 23:57:30 myhost ftpd[12560]: FTPD: command: cwd incoming^M
    Oct  8 23:57:30 myhost ftpd[12560]: <--- 550 
    Oct  8 23:57:30 myhost ftpd[12560]: incoming: No such file or directory.
    Oct  8 23:57:30 myhost ftpd[12560]: FTPD: command: mkd _K4e^M
    Oct  8 23:57:30 myhost ftpd[12560]: <--- 550 
    Oct  8 23:57:30 myhost ftpd[12560]: _K4e: Permission denied.
    Oct  8 23:57:30 myhost ftpd[12560]: FTPD: command: pwd^M
    Oct  8 23:57:30 myhost ftpd[12560]: <--- 257 
    Oct  8 23:57:30 myhost ftpd[12560]: "/pub" is current directory.
    Oct  8 23:57:31 myhost ftpd[12560]: FTPD: command: cwd upload^M
    Oct  8 23:57:31 myhost ftpd[12560]: <--- 550 
    Oct  8 23:57:31 myhost ftpd[12560]: upload: No such file or directory.
    Oct  8 23:57:31 myhost ftpd[12560]: FTPD: command: mkd _K4e^M
    Oct  8 23:57:31 myhost ftpd[12560]: <--- 550 
    Oct  8 23:57:31 myhost ftpd[12560]: _K4e: Permission denied.
    Oct  8 23:57:32 myhost ftpd[12560]: FTPD: command: pwd^M
    Oct  8 23:57:32 myhost ftpd[12560]: <--- 257 
    Oct  8 23:57:32 myhost ftpd[12560]: "/pub" is current directory.
    Oct  8 23:57:32 myhost ftpd[12560]: FTPD: command: cwd _vti_pvt^M
    Oct  8 23:57:32 myhost ftpd[12560]: <--- 550 
    Oct  8 23:57:32 myhost ftpd[12560]: _vti_pvt: No such file or directory.
    Oct  8 23:57:32 myhost ftpd[12560]: FTPD: command: mkd _K4e^M
    Oct  8 23:57:32 myhost ftpd[12560]: <--- 550 
    Oct  8 23:57:32 myhost ftpd[12560]: _K4e: Permission denied.
    Oct  8 23:57:33 myhost ftpd[12560]: FTPD: command: pwd^M
    Oct  8 23:57:33 myhost ftpd[12560]: <--- 257 
    Oct  8 23:57:33 myhost ftpd[12560]: "/pub" is current directory.
    Oct  8 23:57:33 myhost ftpd[12560]: FTPD: command: cwd _vti_txt^M
    Oct  8 23:57:33 myhost ftpd[12560]: <--- 550 
    Oct  8 23:57:33 myhost ftpd[12560]: _vti_txt: No such file or directory.
    Oct  8 23:57:33 myhost ftpd[12560]: FTPD: command: mkd _K4e^M
    Oct  8 23:57:33 myhost ftpd[12560]: <--- 550 
    Oct  8 23:57:33 myhost ftpd[12560]: _K4e: Permission denied.
    Oct  8 23:57:34 myhost ftpd[12560]: FTPD: command: pwd^M
    Oct  8 23:57:34 myhost ftpd[12560]: <--- 257 
    Oct  8 23:57:34 myhost ftpd[12560]: "/pub" is current directory.
    	:
    	:
    Oct  8 23:57:54 myhost ftpd[12560]: FTPD: command: cwd usr^M
    Oct  8 23:57:54 myhost ftpd[12560]: <--- 550 
    Oct  8 23:57:54 myhost ftpd[12560]: usr: No such file or directory.
    Oct  8 23:57:54 myhost ftpd[12560]: FTPD: command: mkd _K4e^M
    Oct  8 23:57:54 myhost ftpd[12560]: <--- 550 
    Oct  8 23:57:54 myhost ftpd[12560]: _K4e: Permission denied.
    Oct  8 23:57:55 myhost ftpd[12560]: FTPD: command: pwd^M
    Oct  8 23:57:55 myhost ftpd[12560]: <--- 257 
    Oct  8 23:57:55 myhost ftpd[12560]: "/pub" is current directory.
    Oct  8 23:57:55 myhost ftpd[12560]: FTPD: command: cwd usr/incoming^M
    Oct  8 23:57:55 myhost ftpd[12560]: <--- 550 
    Oct  8 23:57:55 myhost ftpd[12560]: usr/incoming: No such file or directory.
    Oct  8 23:57:55 myhost ftpd[12560]: FTPD: command: mkd _K4e^M
    Oct  8 23:57:55 myhost ftpd[12560]: <--- 550 
    Oct  8 23:57:55 myhost ftpd[12560]: _K4e: Permission denied.
    Oct  8 23:57:56 myhost ftpd[12560]: FTPD: command: pwd^M
    Oct  8 23:57:56 myhost ftpd[12560]: <--- 257 
    Oct  8 23:57:56 myhost ftpd[12560]: "/pub" is current directory.
    Oct  8 23:57:56 myhost ftpd[12560]: FTPD: command: cwd home^M
    Oct  8 23:57:56 myhost ftpd[12560]: <--- 550 
    Oct  8 23:57:56 myhost ftpd[12560]: home: No such file or directory.
    Oct  8 23:57:56 myhost ftpd[12560]: FTPD: command: mkd _K4e^M
    Oct  8 23:57:56 myhost ftpd[12560]: <--- 550 
    Oct  8 23:57:56 myhost ftpd[12560]: _K4e: Permission denied.
    Oct  8 23:57:57 myhost ftpd[12560]: lost connection
    

    だ〜か〜ら〜弾いたって言ってるの 

    203.162.167.98 - - [02/Oct/2003:14:18:16 +0900] "GET /unimama/httpscan.txt HTTP/1.0" 200 30853 "http://www.google.com.vn/search?q=PDG_Cart/order.log&hl=vi&lr=&ie=UTF-8&start=70&sa=N" "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)"
    203.162.167.98 - - [02/Oct/2003:14:19:34 +0900] "GET /cgi-bin/adpassword.txt HTTP/1.0" 302 210 "-" "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)"
    203.162.167.98 - - [02/Oct/2003:14:20:04 +0900] "GET /cgi-bin/Admin_files/order.log HTTP/1.0" 302 210 "-" "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)"
    

    /jf74kd 

    217.187.217.152 - - [30/Sep/2003:13:35:20 +0900] "GET /jf74kd HTTP/1.0" 404 278 "-" "-"
    
    Name:    dsdf-d9bbd998.pool.mediaWays.net
    Address:  217.187.217.152
    

    internal-gopher-xxxxx 

    Sep 30 06:11:39 myhost ftpd[9226]: FTPD: connection from gate2.sssss.org at Tue Sep 30 06:11:39 2003
    Sep 30 06:11:39 myhost ftpd[9226]: <--- 220 
    Sep 30 06:11:39 myhost ftpd[9226]: myhost FTP server () ready.
    Sep 30 06:11:39 myhost ftpd[9226]: FTPD: command: USER anonymous^M
    Sep 30 06:11:39 myhost ftpd[9226]: <--- 331 
    Sep 30 06:11:39 myhost ftpd[9226]: Guest login ok, send ident as password.
    Sep 30 06:11:39 myhost ftpd[9226]: FTPD: command: PASS anonymous@^M
    Sep 30 06:11:39 myhost ftpd[9226]: <--- 230 
    Sep 30 06:11:39 myhost ftpd[9226]: Guest login ok, access restrictions apply.
    Sep 30 06:11:39 myhost ftpd[9226]: FTPD: command: TYPE I^M
    Sep 30 06:11:39 myhost ftpd[9226]: <--- 200 
    Sep 30 06:11:39 myhost ftpd[9226]: Type set to I.
    Sep 30 06:11:40 myhost ftpd[9226]: FTPD: command: MDTM pub/ppp/internal-gopher-unknown^M
    Sep 30 06:11:40 myhost ftpd[9226]: <--- 500 
    Sep 30 06:11:40 myhost ftpd[9226]: 'MDTM pub/ppp/internal-gopher-unknown': command not understood.
    Sep 30 06:11:40 myhost ftpd[9226]: FTPD: command: SIZE pub/ppp/internal-gopher-unknown^M
    Sep 30 06:11:40 myhost ftpd[9226]: <--- 500 
    Sep 30 06:11:40 myhost ftpd[9226]: 'SIZE pub/ppp/internal-gopher-unknown': command not understood.
    Sep 30 06:11:40 myhost ftpd[9226]: FTPD: command: PORT xxx,xxx,xxx,12,15,116^M
    Sep 30 06:11:40 myhost ftpd[9226]: <--- 200 
    Sep 30 06:11:40 myhost ftpd[9226]: PORT command successful.
    Sep 30 06:11:40 myhost ftpd[9226]: FTPD: command: RETR pub/ppp/internal-gopher-unknown^M
    Sep 30 06:11:40 myhost ftpd[9226]: <--- 550 
    Sep 30 06:11:40 myhost ftpd[9226]: pub/ppp/internal-gopher-unknown: No such file or directory.
    Sep 30 06:11:41 myhost ftpd[9226]: FTPD: command: CWD pub/ppp/internal-gopher-unknown^M
    Sep 30 06:11:41 myhost ftpd[9226]: <--- 550 
    Sep 30 06:11:41 myhost ftpd[9226]: pub/ppp/internal-gopher-unknown: No such file or directory.
    Sep 30 06:11:41 myhost ftpd[9226]: <--- 221 
    Sep 30 06:11:41 myhost ftpd[9226]: You could at least say goodbye.
    

    組み合わせの妙 

    210.51.181.114 - - [06/Sep/2003:16:12:55 +0900] "\x04\x01" 501 - "-" "-" 
    210.51.181.114 - - [06/Sep/2003:16:13:15 +0900] "\x05\x01" 501 - "-" "-" 
    210.51.181.114 - - [06/Sep/2003:16:13:16 +0900] "CONNECT 65.54.166.99:25 HTTP/1.1" 405 321 "-" "-" 
    210.51.181.114 - - [06/Sep/2003:18:54:18 +0900] "\x04\x01" 501 - "-" "-" 
    210.51.181.114 - - [06/Sep/2003:18:54:38 +0900] "\x05\x01" 501 - "-" "-" 
    210.51.181.114 - - [06/Sep/2003:18:54:39 +0900] "CONNECT 65.54.252.99:25 HTTP/1.1" 405 321 "-" "-"
    

    スキャンスクリプト 

    212.179.35.101 - - [02/Sep/2003:09:47:05 +0900] "GET / HTTP/1.0" 200 3923 "-" "-" 
    212.179.35.101 - - [02/Sep/2003:09:47:05 +0900] "GET / HTTP/1.0" 200 3923 "-" "-" 
    212.179.35.101 - - [02/Sep/2003:09:47:05 +0900] "GET /cgi-bin/ HTTP/1.0" 403 284 "-" "-" 
    212.179.35.101 - - [02/Sep/2003:09:47:05 +0900] "GET /cgi-bin/ HTTP/1.0" 403 284 "-" "-" 
    

    IE の文字コード判定を惑わせるページ 

    219.140.57.34 - - [30/Aug/2003:11:36:49 +0900] "GET /+AH4-ggg/cgi-bin/IMG/lblue.gif HTTP/1.1" 404 317 "http://mydomain.xxx.xxx.xxx/~ggg/cgi-bin/mas.pl.cgi?org=anab0&gene=icd" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)"
    219.140.57.34 - - [30/Aug/2003:11:36:49 +0900] "GET /+AH4-ggg/cgi-bin/IMG/blue.gif HTTP/1.1" 404 316 "http://mydomain.xxx.xxx.xxx/~ggg/cgi-bin/mas.pl.cgi?org=anab0&gene=icd" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)" 
    219.140.57.34 - - [30/Aug/2003:11:36:50 +0900] "GET /+AH4-ggg/cgi-bin/IMG/orange.gif HTTP/1.1" 404 318 "http://mydomain.xxx.xxx.xxx/~ggg/cgi-bin/mas.pl.cgi?org=anab0&gene=icd" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)" 
    

    sitecheck.internetseer.com 

    66.150.40.66 - - [21/Aug/2003:02:11:37 +0900] "HEAD / HTTP/1.1" 200 0 "-" "sitecheck.internetseer.com (For more info see: http://sitecheck.internetseer.com)"
    66.150.40.76 - - [19/Aug/2003:16:30:53 +0900] "GET /robots.txt HTTP/1.1" 200 187 "-" "sitecheck.internetseer.com (For more info see: http://sitecheck.internetseer.com)"
    

    "GET /NULL.printer" 

    24.123.170.99 - - [08/Aug/2003:07:27:47 +0900] "GET /NULL.printer" 404 - "-" "-"
    

    Webalizer を利用した検索エンジンスパム?(2) 

    212.123.66.62 - - [04/Aug/2003:12:56:10 +0900] "GET /~ppp/usage/usage_200307.html HTTP/1.1" 200 0 "http://www.top-penis-enlargement.com/" "Mozilla/2.0 (compatible; MSIE 3.0; AOL 4.0; Windows 3.1)"
    211.114.118.254 - - [04/Aug/2003:12:57:50 +0900] "GET /~ppp/usage/usage_200307.html HTTP/1.0" 200 0 "http://www.top-penis-enlargement.com/" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98)"
    200.175.48.244 - - [04/Aug/2003:13:03:16 +0900] "GET /~ppp/usage/usage_200307.html HTTP/1.0" 200 0 "http://www.top-penis-enlargement.com/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"
    

    Webalizer を利用した検索エンジンスパム? 

    ヘンなロボット 

    210.155.159.198 - - [05/Aug/2003:13:46:54 +0900] "GET /~ggggg/ftp.embl-ebi.ac.uk/pub/databases/ HTTP/1.0" 404 313 "-" "Infoseek SideWinder/2.0B (Linux 2.4 i686)" 
    

    トネリング狙い 

    12.218.107.176 - - [04/Aug/2003:18:28:57 +0900] "CONNECT smtp.rol.ru:25 HTTP/1.0" 405 309 "-" "-" 
    12.218.107.176 - - [04/Aug/2003:18:28:59 +0900] "CONNECT smtp.rol.ru:25 HTTP/1.0" 405 309 "-" "-" 
    12.218.107.176 - - [04/Aug/2003:18:29:00 +0900] "CONNECT smtp.rol.ru:25 HTTP/1.0" 405 309 "-" "-" 
    

    ヘンなロボット? 

    61.214.65.109 - - [31/Jul/2003:20:54:12 +0900] "GET /sssss~/ HTTP/1.1" 404 294 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    61.214.65.109 - - [31/Jul/2003:20:55:41 +0900] "GET /sssss~pub/ HTTP/1.1" 404 297 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    61.214.65.109 - - [31/Jul/2003:20:56:09 +0900] "GET /pub.sssss~/ HTTP/1.1" 404 298 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    61.214.65.109 - - [31/Jul/2003:20:56:19 +0900] "GET /publish.sssss~/ HTTP/1.1" 404 302 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    61.214.65.109 - - [31/Jul/2003:20:58:03 +0900] "GET /sssss~ HTTP/1.1" 404 293 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    61.214.65.109 - - [31/Jul/2003:20:58:12 +0900] "GET /sssss~/ HTTP/1.1" 404 294 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    61.214.65.109 - - [31/Jul/2003:20:58:26 +0900] "GET /pub.sssss~/ HTTP/1.1" 404 298 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    

    "GET /scripts/nsiislog.dll" - MS03-019の脆弱性を狙った攻撃 

    211.181.212.10 - - [16/Jul/2003:08:56:32 +0900] "GET /scripts/nsiislog.dll" 404 - "-" "-"
    80.139.104.127 - - [21/Jul/2003:10:47:04 +0900] "GET /scripts/nsiislog.dll" 404 - "-" "-"
    158.130.69.145 - - [21/Jul/2003:19:43:02 +0900] "GET /scripts/nsiislog.dll" 404 - "-" "-"
    208.253.238.235 - - [25/Jul/2003:08:59:56 +0900] "GET /scripts/nsiislog.dll" 404 - "-" "-"
    133.5.222.19 - - [28/Jul/2003:07:58:45 +0900] "GET /scripts/nsiislog.dll" 404 - "-" "-" 
    217.215.48.37 - - [28/Jul/2003:20:46:38 +0900] "GET /scripts/nsiislog.dll" 404 - "-" "-"
    

    UA偽装ロボット 

    66.237.60.61 - - [25/Jul/2003:16:02:00 +0900] "GET /robots.txt HTTP/1.0" 200 187 "-" "Gaisbot/3.0+(robot@gais.cs.ccu.edu.tw;+http://gais.cs.ccu.edu.tw/robot.php)" 66.237.60.61 - - [25/Jul/2003:20:16:29 +0900] "GET /&quot;&gt; HTTP/1.0" 404 290 "-" "Gaisbot/3.0+(robot@gais.cs.ccu.edu.tw;+http://gais.cs.ccu.edu.tw/robot.php)"

    Nikto/1.30によるスキャン 

    212.92.77.254 - - [24/Jul/2003:01:31:16 +0900] "GET / HTTP/1.1" 200 3923 "-" "libwhisker/1.6"
    212.92.77.254 - - [24/Jul/2003:01:31:17 +0900] "GET /Nikto-1.30-nexWS82JrkAwEdao7u.htm HTTP/1.1" 404 317 "-" "Mozilla/4.75 (Nikto/1.30 )"
    212.92.77.254 - - [24/Jul/2003:01:31:17 +0900] "GET / HTTP/1.1" 200 3923 "-" "Mozilla/4.75 (Nikto/1.30 )"
    212.92.77.254 - - [24/Jul/2003:01:31:18 +0900] "GET /cgi.cgi/ HTTP/1.1" 403 296 "-" "Mozilla/4.75 (Nikto/1.30 )"
    

    proxy judge 

    142.177.228.186 - - [22/Jul/2003:17:28:26 +0900] "GET http://blackmarket.jp/cgi-bin/jeno/env/prxjdg.cgi HTTP/1.0" 404 299 "-" "Mozilla/3.0 (compatible)" 
    142.177.228.186 - - [22/Jul/2003:22:59:30 +0900] "GET http://blackmarket.jp/cgi-bin/jeno/env/prxjdg.cgi HTTP/1.0" 404 299 "-" "Mozilla/3.0 (compatible)"
    

    PHPスクリプトをさぐる動き 

    217.162.194.164 - - [17/Jul/2003:21:42:02 +0900] "GET / HTTP/1.0" 200 3923 "-" "-" 
    217.162.194.164 - - [17/Jul/2003:21:42:05 +0900] "GET /index.php HTTP/1.0" 404 281 "-" "-" 
    217.162.194.164 - - [17/Jul/2003:21:42:05 +0900] "GET /main.php HTTP/1.0" 404 280 "-" "-" 
    217.162.194.164 - - [17/Jul/2003:21:42:08 +0900] "GET /test.php HTTP/1.0" 404 280 "-" "-" 
    217.162.194.164 - - [17/Jul/2003:21:42:08 +0900] "GET /phpinfo.php HTTP/1.0" 404 283 "-" "-"
    217.162.194.164 - - [17/Jul/2003:21:42:08 +0900] "GET /index.php3 HTTP/1.0" 404 282 "-" "-" 
    
    Name:    dclient217-162-194-164.hispeed.ch
    Address:  217.162.194.164
    

    "GET //r/n. HTTP/1.1" 

    61.209.171.119 - - [30/Jun/2003:20:32:58 +0900] "GET //r/n. HTTP/1.1" 404 286 "-" "Microsoft URL Control - 6.00.8862"
    

    "LINK / HTTP/1.1" 

    163.152.159.70 - - [27/Jun/2003:20:47:39 +0900] "LINK / HTTP/1.1" 501 337 "-" "Mozilla/4.0 (compatible; MSIE 5.0; Win32)"
    163.152.159.70 - - [28/Jun/2003:12:56:09 +0900] "LINK / HTTP/1.1" 501 337 "-" "Mozilla/4.0 (compatible; MSIE 5.0; Win32)"
    163.152.159.70 - - [28/Jun/2003:13:11:29 +0900] "LINK / HTTP/1.1" 501 337 "-" "Mozilla/4.0 (compatible; MSIE 5.0; Win32)"
    	・
    	・
    	・
    163.152.159.70 - - [29/Jun/2003:20:24:57 +0900] "LINK / HTTP/1.1" 501 337 "-" "Mozilla/4.0 (compatible; MSIE 5.0; Win32)"
    163.152.159.70 - - [29/Jun/2003:20:42:48 +0900] "LINK / HTTP/1.1" 501 337 "-" "Mozilla/4.0 (compatible; MSIE 5.0; Win32)"
    163.152.159.70 - - [29/Jun/2003:21:00:18 +0900] "LINK / HTTP/1.1" 501 337 "-" "Mozilla/4.0 (compatible; MSIE 5.0; Win32)"
    

    "GET /w3c/p3p.xml HTTP/1.1" 

    "GET /w3c/p3p.xml HTTP/1.1" 404 295 "-" "P3P Client" 
    

    "GET /cfdocs/expeval/ExprCalc.cfm" Cold Fusion のサンプルスクリプトを狙った攻撃 

    212.202.40.10 - - [26/Jun/2003:07:10:26 +0900] "GET /cfdocs/expeval/ExprCalc.cfm HTTP/1.0" 404 299 "-" "-"
    

    メール送信スクリプトを狙う攻撃 

    211.233.27.208 - - [26/Jun/2003:02:07:56 +0900] "POST /cgi-bin/sendmail.cgi HTTP/1.0" 404 289 "http://mydomain.xxx.xxx.xxx/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Q12484)"
    192.148.139.178 - - [26/Jun/2003:02:07:56 +0900] "POST /cgi-bin/sendmail.asp HTTP/1.0" 404 289 "http://mydomain.xxx.xxx.xxx/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Q12484)"
    200.66.32.37 - - [26/Jun/2003:02:07:56 +0900] "POST /cgi-bin/formmail.cgi HTTP/1.0" 404 289 "http://mydomain.xxx.xxx.xxx/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Q12484)"
    200.69.230.233 - - [26/Jun/2003:02:07:57 +0900] "POST /cgi-bin/form2mail.cgi HTTP/1.0" 404 290 "http://mydomain.xxx.xxx.xxx/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Q12484)"
    63.198.100.250 - - [26/Jun/2003:02:07:57 +0900] "POST /cgi-bin/formmail.pl HTTP/1.0" 404 288 "http://mydomain.xxx.xxx.xxx/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Q12484)"
    64.168.236.162 - - [26/Jun/2003:02:07:57 +0900] "POST /cgi-bin/mailto HTTP/1.0" 404 283 "http://mydomain.xxx.xxx.xxx/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Q12484)"
    200.192.53.130 - - [26/Jun/2003:02:07:57 +0900] "POST /cgi-bin/formmail.php HTTP/1.0" 404 289 "http://mydomain.xxx.xxx.xxx/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Q12484)"
    195.6.74.31 - - [26/Jun/2003:02:07:58 +0900] "POST /cgi-bin/email.cgi HTTP/1.0" 404 286 "http://mydomain.xxx.xxx.xxx/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Q12484)"
    212.251.71.129 - - [26/Jun/2003:02:07:58 +0900] "POST /cgi-bin/FormMail.pl HTTP/1.0" 404 288 "http://mydomain.xxx.xxx.xxx/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Q12484)"
    209.158.167.98 - - [26/Jun/2003:02:07:59 +0900] "POST /cgi-bin/sendmail.pl HTTP/1.0" 404 288 "http://mydomain.xxx.xxx.xxx/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Q12484)"
    209.220.23.4 - - [26/Jun/2003:02:08:00 +0900] "POST /cgi-bin/form2mail.pl HTTP/1.0" 404 289 "http://mydomain.xxx.xxx.xxx/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Q12484)"
    

    "SEARCH / HTTP/1.1" 

    203.15.69.139 - - [24/Jun/2003:07:17:12 +0900] "SEARCH / HTTP/1.1" 501 344 "-" "-"
    

    パスワードリストによる攻撃 

    Jun 22 09:44:47 myhost ftpd[24002]: FTPD: connection from APlessis-Bouchard-101-2-1-53.w19 at Sun Jun 22 09:44:47 2003
    Jun 22 09:44:47 myhost ftpd[24002]: <--- 220 
    Jun 22 09:44:47 myhost ftpd[24002]: myhost FTP server () ready.
    Jun 22 09:44:47 myhost ftpd[24002]: FTPD: command: USER admin
    Jun 22 09:44:47 myhost ftpd[24002]: <--- 331 
    Jun 22 09:44:47 myhost ftpd[24002]: Password required for admin.
    Jun 22 09:44:48 myhost ftpd[24002]: FTPD: command: PASS 
    Jun 22 09:44:48 myhost ftpd[24002]: <--- 530 
    Jun 22 09:44:48 myhost ftpd[24002]: Login incorrect.
    Jun 22 09:44:48 myhost ftpd[24002]: <--- 221 
    Jun 22 09:44:48 myhost ftpd[24002]: You could at least say goodbye.
    Jun 22 09:44:48 myhost ftpd[23970]: lost connection
    
    Jun 22 09:43:51 myhost ftpd[23970]: FTPD: connection from APlessis-Bouchard-101-2-1-53.w19 at Sun Jun 22 09:43:51 2003
    Jun 22 09:43:55 myhost ftpd[23971]: FTPD: connection from APlessis-Bouchard-101-2-1-53.w19 at Sun Jun 22 09:43:55 2003
    	・
    	・
    	・
    Jun 22 09:44:45 myhost ftpd[24000]: FTPD: connection from APlessis-Bouchard-101-2-1-53.w19 at Sun Jun 22 09:44:45 2003
    Jun 22 09:44:47 myhost ftpd[24002]: FTPD: connection from APlessis-Bouchard-101-2-1-53.w19 at Sun Jun 22 09:44:47 2003
    

    イタズラじゃないみたいだけど 

    131.107.163.50 - - [01/May/2003:13:57:18 +0900] "GET /~ggg-old/xxxxxx HTTP/1.1" 404 304 "-" "MicrosoftPrototypeCrawler (How's my crawling? mailto:newbiecrawler@hotmail.com)" 
    131.107.163.50 - - [01/May/2003:13:57:23 +0900] "GET /~ggg-old/yyyyyy HTTP/1.1" 404 304 "-" "MicrosoftPrototypeCrawler (How's my crawling? mailto:newbiecrawler@hotmail.com)" 
    

    しつこいスキャン 

    217.227.77.239 - - [30/Mar/2003:00:11:55 +0900] "HEAD / HTTP/1.0" 200 0 "-" "-" 
    217.227.77.239 - - [30/Mar/2003:00:11:56 +0900] "GET /.pl HTTP/1.0" 404 275 "-" "-" 
    217.227.77.239 - - [30/Mar/2003:00:11:57 +0900] "GET /....../etc/hosts HTTP/1.0" 404 288 "-" "-" 
    

    間違ってるじゃん 

    218.68.216.7 - - [25/Feb/2003:08:50:09 +0900] "GET http://cancerres.aacrjournals.org/cgi/content/full/63/2/541 HTTP/1.1" 404 309 "-" "Mozilla/5.0 (compatible; MSIE 5.01; Windows 98)"
    218.68.216.7 - - [25/Feb/2003:12:49:06 +0900] "GET http://cancerres.aacrjournals.org/cgi/content/full/63/2/541 HTTP/1.1" 404 309 "-" "Mozilla/5.0 (compatible; MSIE 5.01; Windows 98)"
    
    218.68.216.7 - - [25/Feb/2003:12:49:17 +0900] "GET http://www.ncbi.nlm.nih.gov/HTTP/1.1" 200 3923 "-" "Mozilla/5.0 (compatible; MSIE 5.01; Windows 98)"
    218.68.216.7 - - [25/Feb/2003:13:01:31 +0900] "GET http://www.ncbi.nlm.nih.gov/HTTP/1.1" 200 3923 "-" "Mozilla/5.0 (compatible; MSIE 5.01; Windows 98)"
    218.68.216.7 - - [25/Feb/2003:13:21:40 +0900] "GET http://www.ncbi.nlm.nih.gov/HTTP/1.1" 200 3923 "-" "Mozilla/5.0 (compatible; MSIE 5.01; Windows 98)"
    

    anonymous@ftp.adobe.com 

    Feb 11 22:04:16 myhost ftpd[22755]: FTPD: connection from modemcable241.215-130-66.que.mc. at Tue Feb 11 22:04:16 2003
    Feb 11 22:04:16 myhost ftpd[22755]: <--- 220 
    Feb 11 22:04:16 myhost ftpd[22755]: myhost FTP server () ready.
    Feb 11 22:04:16 myhost ftpd[22755]: FTPD: command: USER anonymous@ftp.adobe.com
    Feb 11 22:04:16 myhost ftpd[22755]: <--- 331 
    Feb 11 22:04:16 myhost ftpd[22755]: Password required for anonymous@ftp.adobe.com.
    Feb 11 22:04:16 myhost ftpd[22755]: FTPD: command: PASS 
    Feb 11 22:04:16 myhost ftpd[22755]: <--- 530 
    Feb 11 22:04:16 myhost ftpd[22755]: Login incorrect.
    Feb 11 22:04:17 myhost ftpd[22755]: lost connection
    


    I&U Home > うにまま(仮) ・  謎ログの友 ・  パスワードコレクション ・  FormMail Scanners