[Zope] msadc exploit?

Graham Chiu gchiu@compkarori.co.nz
Mon, 12 Feb 2001 20:06:12 +1300


I received multiple error reports from my Zope server
tonight, about an object not found at

http://NETSERVER:8080/msadc/..Á%8s../..Á%8s../..Á%8s../winnt/system32/cmd.exe

being called from ip address: 61.156.8.19

This is very odd as my web server is at port 80, and mapped
by NAT to 8080.

I presume that this is some sort of attack on my webserver -
what are they trying to exploit?

--
Graham Chiu