Finding files Found Connected to DBMS TOP: $curr_line = ['server','65.9.216.176','-','-','2001-12-11 07:14:33','GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0','404','304','-','-'] TOP: @templine = [server 65.9.216.176 - - 2001-12-11 07:14:33 GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0 404 304 - -] TOP: $curr_file_name = [httpd_access.log.2001_12_11] TOP: @tmp = [httpd access log 2001 12 11] TOP: $daemon:$logtype = [httpd:access] TOP: $fldcnt: [0] TOP: $fieldcountlimit: [10] TOP: @aux_tables[0] = log_host TOP: @aux_tables[1] = remote_host TOP: @aux_tables[2] = remote_logname TOP: @aux_tables[3] = remote_user TOP: @main_table[4] = date_time TOP: @aux_tables[5] = request TOP: @main_table[6] = last_status TOP: @main_table[7] = bytes_sent TOP: @aux_tables[8] = referrer TOP: @aux_tables[9] = user_agent CHKU: Query constructed: SELECT httpd_access_log_host.log_host, httpd_access_remote_host.remote_host, httpd_access_remote_logname.remote_logname, httpd_access_remote_user.remote_user, httpd_access.date_time, httpd_access_request.request, httpd_access.last_status, httpd_access.bytes_sent, httpd_access_referrer.referrer, httpd_access_user_agent.user_agent FROM httpd_access, httpd_access_log_host, httpd_access_remote_host, httpd_access_remote_logname, httpd_access_remote_user, httpd_access_request, httpd_access_referrer, httpd_access_user_agent WHERE httpd_access.log_host = httpd_access_log_host.id AND httpd_access_log_host.log_host = 'server' AND httpd_access.remote_host = httpd_access_remote_host.id AND httpd_access_remote_host.remote_host = '65.9.216.176' AND httpd_access.remote_logname = httpd_access_remote_logname.id AND httpd_access_remote_logname.remote_logname = '-' AND httpd_access.remote_user = httpd_access_remote_user.id AND httpd_access_remote_user.remote_user = '-' AND httpd_access.date_time = '2001-12-11 07:14:33' AND httpd_access.request = httpd_access_request.id AND httpd_access_request.request = 'GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0' AND httpd_access.last_status = '404' AND httpd_access.bytes_sent = '304' AND httpd_access.referrer = httpd_access_referrer.id AND httpd_access_referrer.referrer = '-' AND httpd_access.user_agent = httpd_access_user_agent.id AND httpd_access_user_agent.user_agent = '-' CHKU: sth_check_unique prepared: DBI::st=HASH(0x82603dc) CHKU: Returned array: ARRAY(0x8257468) TOP: @checkUnique PASSED: server 65.9.216.176 - - 2001-12-11 07:14:33 GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0 404 304 - - ILE: insert_setup_query: SELECT httpd_access_log_host.id, httpd_access_remote_host.id, httpd_access_remote_logname.id, httpd_access_remote_user.id, httpd_access_request.id, httpd_access_referrer.id, httpd_access_user_agent.id FROM httpd_access_log_host, httpd_access_remote_host, httpd_access_remote_logname, httpd_access_remote_user, httpd_access_request, httpd_access_referrer, httpd_access_user_agent WHERE httpd_access_log_host.log_host = 'server' AND httpd_access_remote_host.remote_host = '65.9.216.176' AND httpd_access_remote_logname.remote_logname = '-' AND httpd_access_remote_user.remote_user = '-' AND httpd_access_request.request = 'GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0' AND httpd_access_referrer.referrer = '-' AND httpd_access_user_agent.user_agent = '-' ILE: sth_insert_setup: DBI::st=HASH(0x8266a34) ILE: sth_insert_setup: execute ILE: @insert_setup_array:7 ILE: insert_query: INSERT INTO httpd_access ( id, time_in, log_host, remote_host, remote_logname, remote_user, date_time, request, last_status, bytes_sent, referrer, user_agent ) VALUES ( NULL, NULL, '1', '345', '1', '1', '2001-12-11 07:14:33', '14', '404', '304', '1', '1' ) ILE: fldcnt: 9 ILE: ile_fldcntlmt: 10 Count Report: SELECT COUNT(*) FROM ====================================================================================== CNT: httpd_access: [51685] CNT: httpd_access_log_host: [3] CNT: httpd_access_remote_host: [399] CNT: httpd_access_remote_logname: [1] CNT: httpd_access_remote_user: [1] CNT: httpd_access_request: [127] CNT: httpd_access_referrer: [63] CNT: httpd_access_user_agent: [7] CNT: samba_smb: [25045] CNT: samba_smb_log_host: [4] CNT: samba_smb_facility: [3] CNT: samba_smb_effective: [3] CNT: samba_smb_actual: [2] CNT: samba_smb_module: [6] CNT: samba_smb_source_file: [21] CNT: samba_smb_func: [25] CNT: samba_smb_message: [145] CNT: syslog_std: [831247] CNT: syslog_std_facility: [32] CNT: syslog_std_severity: [14] CNT: syslog_std_log_host: [6] CNT: syslog_std_user: [58] CNT: syslog_std_message: [43894] CNT: syslog_tcpd: [9923] CNT: syslog_tcpd_wrapper: [1] CNT: syslog_tcpd_service: [8] CNT: syslog_tcpd_log_host: [5] CNT: syslog_tcpd_daemon: [14] CNT: syslog_tcpd_remote_name: [322] CNT: syslog_tcpd_remote_user: [18] CNT: syslog_tcpd_remote_info: [332] CNT: syslog_tcpd_remote_address: [316] CNT: syslog_tcpd_local_name: [11] CNT: syslog_tcpd_local_info: [37] CNT: syslog_tcpd_local_address: [11] CNT: login_last: [3702] CNT: login_last_log_host: [4] CNT: login_last_user: [10] CNT: login_last_port: [28] CNT: login_last_origin: [23] CNT: login_last_day_of_week: [7] CNT: login_last_login_status: [4] CNT: login_lastlog: [568] CNT: login_lastlog_log_host: [4] CNT: login_lastlog_user: [20] CNT: login_lastlog_port: [20] CNT: login_lastlog_origin: [8] CNT: login_lastlog_login_status: [2] CNT: login_who_is_on: [26008] CNT: login_who_is_on_log_host: [4] CNT: login_who_is_on_user: [3] CNT: login_who_is_on_port: [20] CNT: login_who_is_on_origin: [9] CNT: login_who_is_on_proc: [168] CNT: Total Database Records: [994401]