Results 1 to 13 of 13

Thread: What is cmd.exe

  1. #1

    Thread Starter
    Frenzied Member
    Join Date
    Aug 2001
    Posts
    1,075

    What is cmd.exe

    I know this is non-vb related but I'm hoping an NT user can answer this for me.

    In the past two days there have been 4775 attempts to download /winnt/system32/cmd.exe and 721 attempts to download /scripts/root.exe from my web site. The IP addresses that are trying all of this are 204.142.159.200 and 64.81.54.39, respectivly. I tried logging on to them with no luck.

    Any ideas why?

    Greg
    Free VB Add-In - The Reference Librarian
    Click Here for screen shot and download link.

  2. #2
    PowerPoster eiSecure's Avatar
    Join Date
    Jul 2000
    Location
    Texas
    Posts
    2,209
    cmd.exe is basically the DOS prompt.

  3. #3
    If you're running IIS (hehe ) get the latest patches from MS and update your virus definitions and scan your computer for viruses.

  4. #4
    PowerPoster eiSecure's Avatar
    Join Date
    Jul 2000
    Location
    Texas
    Posts
    2,209

    Re: What is cmd.exe

    Originally posted by gdebacker
    I know this is non-vb related but I'm hoping an NT user can answer this for me.

    In the past two days there have been 4775 attempts to download /winnt/system32/cmd.exe and 721 attempts to download /scripts/root.exe from my web site. The IP addresses that are trying all of this are 204.142.159.200 and 64.81.54.39, respectivly. I tried logging on to them with no luck.

    Any ideas why?

    Greg
    ...this is part of a hack to gain Admin access to your NT system. They use root.exe to run arbitrary commands on your server, which will change/show the admin's password or create a new admin account.

    The best way to stop this would probably be a firewall and/or setting permissions to the /scripts/root.exe folder.

  5. #5
    Addicted Member
    Join Date
    Jun 2001
    Posts
    183
    They are trying to hack your web server.

    That's bad.

  6. #6
    PowerPoster eiSecure's Avatar
    Join Date
    Jul 2000
    Location
    Texas
    Posts
    2,209
    Originally posted by RyeBread
    They are trying to hack your web server.

    That's bad.
    ...lol...since when would it be good?

  7. #7
    PowerPoster eiSecure's Avatar
    Join Date
    Jul 2000
    Location
    Texas
    Posts
    2,209
    No, renaming the exe doesn't give you root access.

  8. #8
    Addicted Member
    Join Date
    Jun 2001
    Posts
    183
    Originally posted by eiSecure
    ...lol...since when would it be good?
    When it's me!

  9. #9

    Thread Starter
    Frenzied Member
    Join Date
    Aug 2001
    Posts
    1,075
    I suspected it was a potential hack. My web server is hosted by Interland. After I posted here I called there tech support hotline and was told by the recording that they are having many complaints and all operaters are busy. I sat on hold for twenty minutes and gave up.

    I'll try back later and keep an eye on my web site.

    Greg
    Free VB Add-In - The Reference Librarian
    Click Here for screen shot and download link.

  10. #10
    Hyperactive Member FUBAR's Avatar
    Join Date
    Jan 2000
    Posts
    307
    yea dude update your IIS patch or they can make their own dump file, and make your server a backup server for them, or they can take any fiel they want of yours, the reason they are accesssing your cmd.exe is because its a backdoor from IIS which allows them to type in commands in your dos-prompt

  11. #11

    Thread Starter
    Frenzied Member
    Join Date
    Aug 2001
    Posts
    1,075
    Originally posted by FUBAR
    yea dude update your IIS patch or they can make their own dump file, and make your server a backup server for them, or they can take any fiel they want of yours, the reason they are accesssing your cmd.exe is because its a backdoor from IIS which allows them to type in commands in your dos-prompt
    Thanks dude, but 6 people before you answered the question for me and I answered stating that Interland hosts the web site for me and that I had contacted them.

    Greg
    Free VB Add-In - The Reference Librarian
    Click Here for screen shot and download link.

  12. #12
    Fanatic Member BrianHawley's Avatar
    Join Date
    Aug 2001
    Location
    Saudi Arabia
    Posts
    796

    Catch them!

    If you have an IP address the hacks are coming from, you can look it up at:


    http://www.samspade.org/

    Once you know who owns the IP, write to them at abuse@domainname

    Don't be too rude as it may be an ISP, a company or university who does not know about it, or it may be a hacked system being used as a staging post by another IP or hostile software on that system.

    At all events you should COMPLAIN! Most hackers get away with it because nobody bothers to tell their ISP.
    Brian
    (Fighting with the RightToLeft bugs in VS 2005)

  13. #13

    Thread Starter
    Frenzied Member
    Join Date
    Aug 2001
    Posts
    1,075

    Re: Catch them!

    Originally posted by BrianHawley
    If you have an IP address the hacks are coming from, you can look it up at:


    http://www.samspade.org/

    Once you know who owns the IP, write to them at abuse@domainname

    Don't be too rude as it may be an ISP, a company or university who does not know about it, or it may be a hacked system being used as a staging post by another IP or hostile software on that system.

    At all events you should COMPLAIN! Most hackers get away with it because nobody bothers to tell their ISP.
    Thanks for the info. I'll keep that web site handy. I finally contacted Interland and they were aware of the problem and assured me the firewalls were in place and doing their job.

    I'm glad I check my log files every week.

    Greg
    Free VB Add-In - The Reference Librarian
    Click Here for screen shot and download link.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  



Click Here to Expand Forum to Full Width