系统安全之Bat文件自定义入侵检测脚本
上一篇 / 下一篇 2008-03-27 21:21:09 / 个人分类:系统安全
Time/t>>IIS-Scan.logFind/i"需要查找的字符"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.log
上面这个Bat可以很方便的查找IIS6.0的日志文件里的入侵数据。我们都知道Windows2003Server的IIS里面有个专有的“Httperr”这个文件夹,专门记录相关的错误。当然,如果你用扫描软件对服务器进行扫描的话,肯定都会被记录在这里。这个Bat文件使用了Find.exe命令。
@Cd/Rem********AutoScanIIS6.0LogFilesBywww.Reistlin.com********Rem********Scaning...Please...Waiting...********@EchoOffTime/t>>IIS-Scan.logFind/i".."C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logFind/i"//"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logFind/i"//"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logFind/i"windows"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logFind/i"private"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logFind/i"printer"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logFind/i"session"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logFind/i"admin"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logFind/i"winnt"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logFind/i"null"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logFind/i"boot"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logFind/i"www"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logFind/i"asa"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logFind/i"mdb"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logFind/i"dat"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logFind/i"bat"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logFind/i"rpc"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logFind/i"bin"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logFind/i"vti"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logFind/i"doc"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logFind/i"cgi"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logFind/i"log"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logFind/i"iis"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logFind/i"ida"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logFind/i"idc"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logFind/i"idq"C:/WINDOWS/system32/LogFiles/Httperr/*.*>>IIS-Scan.logStartIIS-Scan.log
Time/t>>Port.logNetstat-NA-PTcp600>>Port.log
Time/t>>3389.logNetstat-n-ptcp|Find":3389">>3389.log
相关阅读:
- 如何彻底删除WINDOWS2000默认共享 (月亮丝, 2008-3-27)
- RamaCMSLang参数本地文件包含漏洞 (月亮丝, 2008-3-27)
导入论坛 引用链接 收藏 分享给好友 推荐到圈子 管理 举报

