#Software: Microsoft Internet Information Services 5.0 #Version: 1.0 #Date: 2002-08-12 01:27:21 #Fields: date time c-ip cs-username s-ip s-port cs-method cs-uri-stem cs-uri-query sc-status cs(User-Agent) 第3行记录了IIS启动的时间,第4行说明了每条记录的格式说明。 2002-07-18 09:53:52 10.152.8.17 - 10.152.8.2 80 GET /index.htm - 200 Mozilla/4.76+[en]+(X11;+U;+Linux+2.4.2-2+i686) 2002-07-18 09:53:58 10.152.8.13 - 10.152.8.2 80 GET /MyHomepage/Nethief_Notify.htm - 404 INTERNET 2002-08-10 05:13:11 61.159.35.180 - 61.181.60.164 80 GET /bbs/ - 302 Mozilla/4.0+(compatible;+MSIE+5.0;+Windows+98;+DigExt) 2002-06-28 08:17:33 127.0.0.1 - 127.0.0.1 2285 GET / - 401 Mozilla/4.0+(compatible;+MSIE+6.0b;+Windows+NT+5.0) 2002-07-16 01:10:51 10.152.8.17 - 10.152.8.2 80 GET /seek/images/ip.gif - 200 Mozilla/5.0+(X11;+U;+Linux+2.4.2-2+i686;+en-US;+0.7) +Gecko/20010316
#Software: Microsoft Internet Information Services 5.0 #Version: 1.0 #Date: 2002-07-24 01:32:07 #Fields: time cip csmethod csuristem scstatus 03:15:20 210.12.195.3 [1]USER administator 331 (IP地址为210.12.195.2用户名为administator的用户试图登录) 03:16:12 210.12.195.2 [1]PASS - 530 (登录失败) 03:17:04 210.12.195.2 [1]USER bright 331 (IP地址为210.12.195.2用户名为bright的用户试图登录) 03:17:06 210.12.195.2 [1]PASS - 530 (登录失败) 03:17:29 210.12.195.2 [1]USER lzy 331 (IP地址为210.12.195.2用户名为lzy的用户试图登录) 03:17:30 210.12.195.2 [1]PASS - 530 (登录失败) 03:19:16 210.12.195.2 [1]USER administrator 331 (IP地址为210.12.195.2用户名为administrator的用户试图登录) 03:19:24 210.12.195.2 [1]PASS - 230 (登录成功) 03:19:49 210.12.195.2 [1]MKD brght 550 (新建目录失败) 03:25:26 210.12.195.2 [1]QUIT - 550 (退出FTP程序)
13:46:07 127.0.0.1 GET /scripts/..\../winnt/system32/cmd".exe 401 13:46:07 127.0.0.1 GET /scripts/..\../winnt/system32/cmd".exe 200 如果有人曾经执行过copy、del、echo、.bat等具有入侵行为的命令时,会有以下类似的记录: 13:47:37 127.0.0.1 GET /scripts/..\../winnt/system32/cmd".exe 401 13:47:37 127.0.0.1 GET /scripts/..\../winnt/system32/cmd".exe 502