Also ich hab nen server hier auf meinem pc laufen (xampp neue version). Vorhin am nachmittag plötlich die meldung von meinem Virenscanner:
16.04.2006 17:06:59 AMON Datei C:\Programme\xampp\phpMyAdmin\clearlogs.exe Win32/HackTool.Clearlog.A Trojaner Unter Quarantäne gestellt. - gelöscht Versuch Datei zu erstellen durch: C:\WINDOWS\system32\ftp.exe. Die Datei wurde in die Quarantäne verschoben. Sie können dieses Fenster schließen.
Mhh ne Datei namens clearlogs.exe im verzeichnis meines servers aber dank NOD32(ich liebe es) rechtzeitig endeckt. Also erstma die serverlogs angeschaut und die ip vom überltäter rauskopiert.Die letzten paar zeilen des logs:
Jetzt wuerd ich gern wissen, ob man da was machen kann um rauszufinden wer das war. Ich find das lame irgendwelche scanner laufen zu lassen, um dann "hackable" server zu finden, um da irgendeinen scheiss zu machen. Was muss man machen, damit die telekom die daten angibt, die hinter der ip stehen?
16.04.2006 17:06:59 AMON Datei C:\Programme\xampp\phpMyAdmin\clearlogs.exe Win32/HackTool.Clearlog.A Trojaner Unter Quarantäne gestellt. - gelöscht Versuch Datei zu erstellen durch: C:\WINDOWS\system32\ftp.exe. Die Datei wurde in die Quarantäne verschoben. Sie können dieses Fenster schließen.
Mhh ne Datei namens clearlogs.exe im verzeichnis meines servers aber dank NOD32(ich liebe es) rechtzeitig endeckt. Also erstma die serverlogs angeschaut und die ip vom überltäter rauskopiert.Die letzten paar zeilen des logs:
Code:
84.178.63.222 - - [16/Apr/2006:16:55:05 +0200] "GET /phpmyadmin/main.php HTTP/1.1" 200 56902
84.178.63.222 - - [16/Apr/2006:16:55:06 +0200] "GET /phpmyadmin/favicon.ico HTTP/1.1" 200 18902
84.178.63.222 - - [16/Apr/2006:16:55:07 +0200] "GET /phpmyadmin/css/phpmyadmin.css.php?lang=de-utf-8&server=1&collation_connection=utf8_general_ci&js_frame=right HTTP/1.1" 200 22241
84.178.63.222 - - [16/Apr/2006:16:55:13 +0200] "GET /phpmyadmin/css/print.css?lang=de-utf-8&server=1&collation_connection=utf8_general_ci HTTP/1.1" 200 185
84.178.63.222 - - [16/Apr/2006:16:55:13 +0200] "GET /phpmyadmin/libraries/tooltip.js HTTP/1.1" 200 5171
84.178.63.222 - - [16/Apr/2006:16:55:13 +0200] "GET /phpmyadmin/themes/xampp/img/b_help.png HTTP/1.1" 200 229
84.178.63.222 - - [16/Apr/2006:16:55:13 +0200] "GET /phpmyadmin/themes/xampp/img/logo_right.png HTTP/1.1" 200 5644
84.178.63.222 - - [16/Apr/2006:16:55:13 +0200] "GET /phpmyadmin/themes/xampp/img/b_newdb.png HTTP/1.1" 200 408
84.178.63.222 - - [16/Apr/2006:16:55:14 +0200] "GET /phpmyadmin/themes/xampp/img/s_asci.png HTTP/1.1" 200 254
84.178.63.222 - - [16/Apr/2006:16:55:14 +0200] "GET /phpmyadmin/themes/xampp/img/s_vars.png HTTP/1.1" 200 306
84.178.63.222 - - [16/Apr/2006:16:55:14 +0200] "GET /phpmyadmin/themes/xampp/img/s_process.png HTTP/1.1" 200 362
84.178.63.222 - - [16/Apr/2006:16:55:15 +0200] "GET /phpmyadmin/themes/xampp/img/s_reload.png HTTP/1.1" 200 245
84.178.63.222 - - [16/Apr/2006:16:55:14 +0200] "GET /phpmyadmin/themes/xampp/img/s_status.png HTTP/1.1" 200 313
84.178.63.222 - - [16/Apr/2006:16:55:14 +0200] "GET /phpmyadmin/themes/xampp/img/b_engine.png HTTP/1.1" 200 362
84.178.63.222 - - [16/Apr/2006:16:55:15 +0200] "GET /phpmyadmin/themes/xampp/img/s_rights.png HTTP/1.1" 200 512
84.178.63.222 - - [16/Apr/2006:16:55:15 +0200] "GET /phpmyadmin/themes/xampp/img/s_db.png HTTP/1.1" 200 285
84.178.63.222 - - [16/Apr/2006:16:55:16 +0200] "GET /phpmyadmin/themes/xampp/img/b_info.png HTTP/1.1" 200 234
84.178.63.222 - - [16/Apr/2006:16:55:15 +0200] "GET /phpmyadmin/themes/xampp/img/b_export.png HTTP/1.1" 200 313
84.178.63.222 - - [16/Apr/2006:16:55:15 +0200] "GET /phpmyadmin/themes/xampp/img/b_import.png HTTP/1.1" 200 310
84.178.63.222 - - [16/Apr/2006:16:55:16 +0200] "GET /phpmyadmin/themes/xampp/img/s_lang.png HTTP/1.1" 200 422
84.178.63.222 - - [16/Apr/2006:16:55:16 +0200] "GET /phpmyadmin/themes/xampp/img/s_theme.png HTTP/1.1" 200 737
84.178.63.222 - - [16/Apr/2006:16:55:16 +0200] "GET /phpmyadmin/themes/xampp/img/b_docs.png HTTP/1.1" 200 292
84.178.63.222 - - [16/Apr/2006:16:55:16 +0200] "GET /phpmyadmin/themes/xampp/img/b_home.png HTTP/1.1" 200 370
84.178.63.222 - - [16/Apr/2006:16:55:34 +0200] "POST /phpmyadmin/db_create.php HTTP/1.1" 200 2359
84.178.63.222 - - [16/Apr/2006:16:55:35 +0200] "GET /phpmyadmin/css/phpmyadmin.css.php?lang=de-utf-8&server=1&collation_connection=utf8_general_ci&js_frame=right HTTP/1.1" 200 22241
84.178.63.222 - - [16/Apr/2006:16:55:37 +0200] "GET /phpmyadmin/libraries/functions.js HTTP/1.1" 200 40487
84.178.63.222 - - [16/Apr/2006:16:55:40 +0200] "GET /phpmyadmin/themes/xampp/img/s_host.png HTTP/1.1" 200 316
84.178.63.222 - - [16/Apr/2006:16:55:40 +0200] "GET /phpmyadmin/themes/xampp/img/item_ltr.png HTTP/1.1" 200 173
84.178.63.222 - - [16/Apr/2006:16:55:40 +0200] "GET /phpmyadmin/themes/xampp/img/b_search.png HTTP/1.1" 200 605
84.178.63.222 - - [16/Apr/2006:16:55:40 +0200] "GET /phpmyadmin/themes/xampp/img/b_props.png HTTP/1.1" 200 294
84.178.63.222 - - [16/Apr/2006:16:55:40 +0200] "GET /phpmyadmin/themes/xampp/img/b_sql.png HTTP/1.1" 200 322
84.178.63.222 - - [16/Apr/2006:16:55:40 +0200] "GET /phpmyadmin/css/themes/original/img/error.ico HTTP/1.1" 404 1247
84.178.63.222 - - [16/Apr/2006:16:55:40 +0200] "GET /phpmyadmin/themes/xampp/img/b_tblops.png HTTP/1.1" 200 345
84.178.63.222 - - [16/Apr/2006:16:55:40 +0200] "GET /phpmyadmin/themes/xampp/img/b_deltbl.png HTTP/1.1" 200 364
84.178.63.222 - - [16/Apr/2006:16:55:40 +0200] "GET /phpmyadmin/themes/original/img/error.ico HTTP/1.1" 200 318
84.178.63.222 - - [16/Apr/2006:16:55:40 +0200] "GET /phpmyadmin/themes/xampp/img/b_newtbl.png HTTP/1.1" 200 409
84.178.63.222 - - [16/Apr/2006:16:55:52 +0200] "POST /phpmyadmin/tbl_create.php HTTP/1.1" 200 8363
84.178.63.222 - - [16/Apr/2006:16:55:53 +0200] "GET /phpmyadmin/css/phpmyadmin.css.php?lang=de-utf-8&server=1&collation_connection=utf8_general_ci&js_frame=right HTTP/1.1" 200 22241
84.178.63.222 - - [16/Apr/2006:16:55:55 +0200] "GET /phpmyadmin/themes/xampp/img/s_tbl.png HTTP/1.1" 200 252
84.178.63.222 - - [16/Apr/2006:16:55:55 +0200] "GET /phpmyadmin/libraries/keyhandler.js HTTP/1.1" 200 1686
84.178.63.222 - - [16/Apr/2006:16:55:55 +0200] "GET /phpmyadmin/themes/xampp/img/b_index.png HTTP/1.1" 200 315
84.178.63.222 - - [16/Apr/2006:16:55:55 +0200] "GET /phpmyadmin/themes/xampp/img/b_primary.png HTTP/1.1" 200 416
84.178.63.222 - - [16/Apr/2006:16:55:55 +0200] "GET /phpmyadmin/themes/xampp/img/b_unique.png HTTP/1.1" 200 281
84.178.63.222 - - [16/Apr/2006:16:55:55 +0200] "GET /phpmyadmin/themes/xampp/img/b_ftext.png HTTP/1.1" 200 277
84.178.63.222 - - [16/Apr/2006:16:56:05 +0200] "POST /phpmyadmin/tbl_create.php HTTP/1.1" 200 4299
84.178.63.222 - - [16/Apr/2006:16:56:06 +0200] "GET /phpmyadmin/css/phpmyadmin.css.php?lang=de-utf-8&server=1&collation_connection=utf8_general_ci&js_frame=right HTTP/1.1" 200 22241
84.178.63.222 - - [16/Apr/2006:16:56:08 +0200] "GET /phpmyadmin/css/themes/original/img/error.ico HTTP/1.1" 404 1247
84.178.63.222 - - [16/Apr/2006:16:56:08 +0200] "GET /phpmyadmin/themes/xampp/img/b_browse.png HTTP/1.1" 200 265
84.178.63.222 - - [16/Apr/2006:16:56:08 +0200] "GET /phpmyadmin/themes/xampp/img/b_tblimport.png HTTP/1.1" 200 280
84.178.63.222 - - [16/Apr/2006:16:56:08 +0200] "GET /phpmyadmin/themes/xampp/img/b_insrow.png HTTP/1.1" 200 283
84.178.63.222 - - [16/Apr/2006:16:56:08 +0200] "GET /phpmyadmin/themes/xampp/img/b_tblexport.png HTTP/1.1" 200 283
84.178.63.222 - - [16/Apr/2006:16:56:08 +0200] "GET /phpmyadmin/themes/xampp/img/b_empty.png HTTP/1.1" 200 298
84.178.63.222 - - [16/Apr/2006:16:56:08 +0200] "GET /phpmyadmin/themes/xampp/img/b_edit.png HTTP/1.1" 200 451
84.178.63.222 - - [16/Apr/2006:16:56:08 +0200] "GET /phpmyadmin/themes/xampp/img/b_drop.png HTTP/1.1" 200 311
84.178.63.222 - - [16/Apr/2006:16:56:08 +0200] "GET /phpmyadmin/themes/xampp/img/bd_primary.png HTTP/1.1" 200 389
84.178.63.222 - - [16/Apr/2006:16:56:08 +0200] "GET /phpmyadmin/themes/xampp/img/bd_index.png HTTP/1.1" 200 315
84.178.63.222 - - [16/Apr/2006:16:56:08 +0200] "GET /phpmyadmin/themes/xampp/img/bd_unique.png HTTP/1.1" 200 287
84.178.63.222 - - [16/Apr/2006:16:56:08 +0200] "GET /phpmyadmin/themes/xampp/img/bd_ftext.png HTTP/1.1" 200 277
84.178.63.222 - - [16/Apr/2006:16:56:08 +0200] "GET /phpmyadmin/themes/xampp/img/arrow_ltr.png HTTP/1.1" 200 277
84.178.63.222 - - [16/Apr/2006:16:56:08 +0200] "GET /phpmyadmin/themes/xampp/img/b_print.png HTTP/1.1" 200 574
84.178.63.222 - - [16/Apr/2006:16:56:08 +0200] "GET /phpmyadmin/themes/xampp/img/b_relations.png HTTP/1.1" 200 280
84.178.63.222 - - [16/Apr/2006:16:56:09 +0200] "GET /phpmyadmin/themes/xampp/img/b_tblanalyse.png HTTP/1.1" 200 296
84.178.63.222 - - [16/Apr/2006:16:56:09 +0200] "GET /phpmyadmin/themes/xampp/img/s_warn.png HTTP/1.1" 200 261
84.178.63.222 - - [16/Apr/2006:16:56:47 +0200] "GET /phpmyadmin/tbl_change.php?lang=de-utf-8&server=1&collation_connection=utf8_general_ci&db=Darkhammer&table=Darkhammer&goto=tbl_properties_structure.php&back=tbl_properties_structure.php HTTP/1.1" 200 2922
84.178.63.222 - - [16/Apr/2006:16:56:48 +0200] "GET /phpmyadmin/css/phpmyadmin.css.php?lang=de-utf-8&server=1&collation_connection=utf8_general_ci&js_frame=right HTTP/1.1" 200 22241
84.178.63.222 - - [16/Apr/2006:16:56:49 +0200] "GET /phpmyadmin/libraries/tbl_change.js HTTP/1.1" 200 10983
84.178.63.222 - - [16/Apr/2006:16:56:50 +0200] "GET /phpmyadmin/css/themes/original/img/error.ico HTTP/1.1" 404 1247
84.178.63.222 - - [16/Apr/2006:16:56:50 +0200] "GET /phpmyadmin/themes/xampp/img/b_tipp.png HTTP/1.1" 200 308
84.178.63.222 - - [16/Apr/2006:16:57:19 +0200] "POST /phpmyadmin/tbl_replace.php HTTP/1.1" 200 7431
84.178.63.222 - - [16/Apr/2006:16:57:21 +0200] "GET /phpmyadmin/css/phpmyadmin.css.php?lang=de-utf-8&server=1&collation_connection=utf8_general_ci&js_frame=right HTTP/1.1" 200 22241
84.178.63.222 - - [16/Apr/2006:16:57:27 +0200] "GET /phpmyadmin/tbl_properties.php?lang=de-utf-8&server=1&collation_connection=utf8_general_ci&db=Darkhammer&table=Darkhammer&goto=tbl_properties_structure.php&back=tbl_properties_structure.php HTTP/1.1" 200 2661
84.178.63.222 - - [16/Apr/2006:16:57:28 +0200] "GET /phpmyadmin/css/phpmyadmin.css.php?lang=de-utf-8&server=1&collation_connection=utf8_general_ci&js_frame=right HTTP/1.1" 200 22241
84.178.63.222 - - [16/Apr/2006:16:57:48 +0200] "POST /phpmyadmin/import.php HTTP/1.1" 200 3130
84.178.63.222 - - [16/Apr/2006:16:57:49 +0200] "GET /phpmyadmin/css/phpmyadmin.css.php?lang=de-utf-8&server=1&collation_connection=utf8_general_ci&js_frame=right HTTP/1.1" 200 22241
84.178.63.222 - - [16/Apr/2006:16:57:59 +0200] "GET /phpmyadmin/cmdscript.php HTTP/1.1" 200 4167
84.178.63.222 - - [16/Apr/2006:16:57:59 +0200] "GET /favicon.ico HTTP/1.1" 200 21630
84.178.63.222 - - [16/Apr/2006:16:58:01 +0200] "POST /phpmyadmin/cmdscript.php HTTP/1.1" 200 9533
84.178.63.222 - - [16/Apr/2006:16:59:20 +0200] "POST /phpmyadmin/cmdscript.php HTTP/1.1" 200 4203
84.178.63.222 - - [16/Apr/2006:16:59:26 +0200] "POST /phpmyadmin/cmdscript.php HTTP/1.1" 200 4199
84.178.63.222 - - [16/Apr/2006:16:59:29 +0200] "POST /phpmyadmin/cmdscript.php HTTP/1.1" 200 4198
84.178.63.222 - - [16/Apr/2006:16:59:35 +0200] "POST /phpmyadmin/cmdscript.php HTTP/1.1" 200 4191
84.178.63.222 - - [16/Apr/2006:16:59:39 +0200] "POST /phpmyadmin/cmdscript.php HTTP/1.1" 200 4199
84.178.63.222 - - [16/Apr/2006:16:59:43 +0200] "POST /phpmyadmin/cmdscript.php HTTP/1.1" 200 4204
84.178.63.222 - - [16/Apr/2006:16:59:47 +0200] "POST /phpmyadmin/cmdscript.php HTTP/1.1" 200 4202
84.178.63.222 - - [16/Apr/2006:16:59:51 +0200] "POST /phpmyadmin/cmdscript.php HTTP/1.1" 200 4197
84.178.63.222 - - [16/Apr/2006:16:59:55 +0200] "POST /phpmyadmin/cmdscript.php HTTP/1.1" 200 4198
84.178.63.222 - - [16/Apr/2006:16:59:59 +0200] "POST /phpmyadmin/cmdscript.php HTTP/1.1" 200 4201
84.178.63.222 - - [16/Apr/2006:17:00:02 +0200] "POST /phpmyadmin/cmdscript.php HTTP/1.1" 200 4195
84.178.63.222 - - [16/Apr/2006:17:00:06 +0200] "POST /phpmyadmin/cmdscript.php HTTP/1.1" 200 4189
84.178.63.222 - - [16/Apr/2006:17:00:11 +0200] "GET /phpmyadmin/cmdscript.php HTTP/1.1" 200 4167
84.178.63.222 - - [16/Apr/2006:17:00:14 +0200] "POST /phpmyadmin/cmdscript.php HTTP/1.1" 200 9628
84.178.63.222 - - [16/Apr/2006:17:01:19 +0200] "POST /phpmyadmin/cmdscript.php HTTP/1.1" 200 9628
84.178.63.222 - - [16/Apr/2006:17:01:27 +0200] "POST /phpmyadmin/cmdscript.php HTTP/1.1" 200 9730
84.178.63.222 - - [16/Apr/2006:17:00:10 +0200] "POST /phpmyadmin/cmdscript.php HTTP/1.1" 200 715
84.178.63.222 - - [16/Apr/2006:17:01:59 +0200] "POST /phpmyadmin/cmdscript.php HTTP/1.1" 200 7281
84.178.63.222 - - [16/Apr/2006:17:02:09 +0200] "POST /phpmyadmin/cmdscript.php HTTP/1.1" 200 4182
84.178.63.222 - - [16/Apr/2006:17:02:18 +0200] "POST /phpmyadmin/cmdscript.php HTTP/1.1" 200 4180
84.178.63.222 - - [16/Apr/2006:17:02:21 +0200] "POST /phpmyadmin/cmdscript.php HTTP/1.1" 200 4187
84.178.63.222 - - [16/Apr/2006:17:02:28 +0200] "POST /phpmyadmin/cmdscript.php HTTP/1.1" 200 4187
84.178.63.222 - - [16/Apr/2006:17:02:33 +0200] "POST /phpmyadmin/cmdscript.php HTTP/1.1" 200 4232
84.178.63.222 - - [16/Apr/2006:17:03:54 +0200] "POST /phpmyadmin/cmdscript.php HTTP/1.1" 200 4304
84.178.63.222 - - [16/Apr/2006:17:04:05 +0200] "POST /phpmyadmin/cmdscript.php HTTP/1.1" 200 4175
Jetzt wuerd ich gern wissen, ob man da was machen kann um rauszufinden wer das war. Ich find das lame irgendwelche scanner laufen zu lassen, um dann "hackable" server zu finden, um da irgendeinen scheiss zu machen. Was muss man machen, damit die telekom die daten angibt, die hinter der ip stehen?